Privacy Policy
Last updated 17 August 2026
lucina is operated by Noam Eilon. This policy explains what the app collects, why, who processes it, and how to delete it. If anything here is unclear, email [email protected].
What we collect
Account
You can sign in with an email address and password, with Sign in with Apple, or with Sign in with Google. We store your email address; passwords are held by our authentication provider and are never visible to us. If you use Sign in with Apple, Apple may give us a private relay address instead of your real one; that works fine, and we never receive your Apple ID password. If you use Sign in with Google, Google tells us the email address on your Google account. Password reset emails are sent by our authentication provider.
Your name choices
Every swipe you make — keep or pass — is stored against your account. This is what the app is for: it powers your lists, and it is how a match is detected when you and your partner both keep the same name. Your passes are never shown to your partner. Names you add yourself, and any note you attach to them, are stored the same way.
Your couple link
If you pair with a partner, we store the link between your two accounts so matches can be computed and so a single subscription can cover you both.
Subscription status
We store whether your subscription is active and when it ends, together with the purchase records our subscription provider sends us. Payment is handled entirely by Apple through the App Store — we never see or store your card details.
Push notifications
If you allow notifications, we store a device push token so we can tell you about a new match or a family vote. To deliver a notification, its text passes through our push provider and then through Apple's or Google's notification service — and that text names the matched name, or the nickname of the family member who voted. Revoking the permission in your phone's settings stops the notifications; the stored token itself is removed when you delete your account.
Analytics
Product analytics are off by default. They are collected only if you switch on Product analytics from your profile in the app, and you can switch it back off at any time. When enabled, we record which features you use — for example that a swipe happened, or that a family page was created with a certain number of names. We never send the names you swipe on, your matches, the contents of a family page, your email address or your location.
These events are linked to your account, not anonymous: we send them with your account identifier so that one person's usage can be told apart from another's. Turning the setting off stops new events being sent.
Family pages
When you publish a shortlist for relatives to vote on, we store the names on that list, the passcode protecting it, and each participant's chosen nickname, votes and comments. The passcode is stored in a form we can show you again in the app, so treat it as a shared code rather than a password. The page is not listed anywhere and is excluded from search engines — anyone with the link and the passcode can view it, so share both carefully. Deleting the page deletes the votes and comments with it. Family members who vote do not need an account, and we do not ask them for an email address.
Diagnostics and server logs
If the app crashes we receive a technical error report to help fix it. These reports are about the failure, not about you: your account is identified in them only by a one-way hash, never by your email address. Our servers also write a line per request, in which client IP addresses are truncated before they are written. Those lines stay on the server that produced them and are discarded when it is replaced by a new deployment; we do not ship them anywhere else.
Who processes your data
- Supabase — database, authentication and account emails.
- Apple — App Store payments, Sign in with Apple, and iOS push delivery.
- Google — Sign in with Google, and Android push delivery.
- RevenueCat — subscription status.
- Expo — push notification delivery.
- PostHog — product analytics, only if you opt in.
- Sentry — crash and error diagnostics.
- Cloudflare — serving this website and routing app traffic.
We do not sell your data, and we do not use it for advertising.
Where your data is held
Our database is hosted in the European Union, and so is our crash reporting. Our product analytics provider stores its data in the United States, and the other processors listed above operate in the United States or globally, so your data may be transferred outside the EU.
Deleting your data
You can delete your account from your profile in the app. This removes your account, your swipes, your lists and your saved push tokens.
Two deliberate exceptions, both about not destroying someone else's work:
- Deleting your account does not destroy your partner's history. Names you added together, and matches you both made, remain available to them, with your authorship detached. This includes the text of any note you wrote on a name you added: once that name has matched, the note is part of what the two of you matched on, so it stays readable by your partner after your account is gone, with your authorship detached in the same way. We think losing a shared shortlist because someone else closed their account would be worse than the alternative.
- A family page you published on your own is deleted with your account. A family page that belongs to a couple you are part of is not deleted: it and its votes stay with the couple, so delete it from the app first if you want it gone.
One technical record also survives, for a different reason. Each time your partner swipes, our server keeps its own answer to that request so that it can repeat that answer safely if the app asks again after a dropped connection. That record belongs to your partner's account, not yours, so your deletion does not reach it. If the answer announced a match, it holds the name that matched and any note written on it, frozen as it was at the time. Nothing in the app displays these records, and we can clear them, but nothing clears them on a schedule today.
We also keep a limited set of security and payment records — for example administrative audit entries and the purchase notifications sent to us by our subscription provider — which may still contain your account identifier after your account is deleted. Deletion does not cancel a subscription; that is done through Apple.
Deleting the app without deleting your account does not delete your data.
How long we keep things
Nothing attached to your account is deleted on a timer, so most of these are criteria rather than fixed periods:
- Everything attached to your account — the account record, your swipes, your lists, your couple link, your subscription record and your push tokens — is kept for as long as your account exists. We do not delete accounts for inactivity, and we do not expire your swipe history.
- The things that stay with your partner when you delete your account — a matched name you added, the note you wrote on it, and the stored answers to their own swipes, all described under Deleting your data above — are kept for as long as their account exists, on the same terms as the rest of their data.
- A family page is kept until you delete it. Closing a page stops the voting but keeps its names, votes and comments; only deleting the page removes them.
- Two of our own records also deliberately outlive your account, because they are records of things that happened rather than descriptions of you: administrative audit entries, and the purchase notifications our subscription provider sends us. We keep these indefinitely for security, accounting and fraud prevention. They identify you by account identifier only.
- Short-lived caches of your data, which we use to keep the app fast, expire on their own within a day at most, and are cleared immediately when you delete your account.
- Our database provider keeps backups of the whole database for a short period, so data can survive in a backup for a few days after you delete it before ageing out.
- Crash reports and, if you opted in, analytics events are held by those providers under their own retention schedules. We do not set a shorter one than they provide.
Your rights
Wherever you live, and in particular if you are in the EU or UK, you can ask us to:
- Give you access to the data we hold about you.
- Correct anything we hold that is wrong. Email us and we will fix it.
- Delete your data. You can do this yourself from your profile in the app; the exceptions above are the only things that survive it.
- Object to, or restrict, a particular use. Product analytics are the clearest case: they are off unless you turn them on, and the same setting turns them off again.
- Receive a portable copy of your data. There is no self-service export in the app yet, so email us and we will put one together for you.
Email [email protected] to exercise any of these. If you think we have handled your data badly, you can also complain to the data protection supervisory authority for the country you live in.
Children
lucina is not directed at children and is not intended for use by anyone under 13.
Changes
If this policy changes materially we will update the date at the top and, where the change affects how your data is used, tell you in the app.