Privacy Policy

Effective 19 August 2026 · hello@hellolo.app

Who we are

LO (hellolo.app) is a family-memory app operated from the United Kingdom. We are the data controller for the personal information described in this policy. You can reach us about anything privacy-related at hello@hellolo.app.

Our promise, in plain words.

Your family's memories belong to your family. We never sell personal information, we show no advertising, and we never use your photos, voice recordings, letters, or your child's information to train AI models — ours or anyone else's.

Everything LO knows about your child comes from you, their parent or guardian. You can edit or delete any of it — or your whole account — at any time, from inside the app.

The information we collect

About you

About your child — provided by you

Photos

Your photo library stays on your device. When you add a photo to LO, we store its details — when and where it was taken, and quality signals such as whether faces are visible — not the picture itself. The images you see in LO are displayed from your own device.

To write captions and stories, a photo is sent over an encrypted connection to our AI provider (Google Vertex AI), processed, and not retained by LO's servers — we store only the resulting caption and description. See "How we use AI" below.

Voice recordings

When you record a voice note or letter, the audio is transcribed by our transcription provider (OpenAI) over an encrypted connection. If you save the note, the recording is kept privately with it so you can listen back; if you don't save, it is discarded. Deleting a note deletes its audio.

Face information — only with your explicit consent

Covered fully in its own section below. LO never creates face data without you agreeing first.

Collected automatically

The LO app uses no advertising or tracking technology, no third-party analytics profiles, and does not track you across other apps or websites. This website can use Google Analytics — but only if you say yes to it. See Cookies and analytics.

Cookies and analytics

Until you tell us otherwise, this website sets no cookies at all. There is no advertising cookie, no tracking pixel, and nothing that follows you to other websites. Google Analytics is off, and the code that would load it is never fetched.

Separately from Google Analytics, our host Cloudflare counts visits for us in a privacy-preserving way: no cookies, no fingerprinting, and no personal data stored — it tells us how many people visited and how fast the pages loaded, never who anyone is. Because nothing is stored on your device and no one is identified or tracked, this does not require consent and cannot be used to follow you anywhere.

If you choose Allow analytics in the banner at the bottom of the page, we load Google Analytics so we can see how many people visit and how they found us. It sets two first-party cookies:

CookieWhat it doesHow long it lasts
_gaTells one browser apart from another so visits can be countedUp to 2 years (Google's default)
_ga_H1BSMMZVDNKeeps the state of a single visitUp to 2 years (Google's default)

Our lawful basis is your consent (UK GDPR Article 6(1)(a), and Regulation 6 of PECR for storing anything on your device). Nothing is stored and nothing is loaded before you choose. Declining costs you nothing — the site works identically either way.

To change your mind, at any time, use the Cookie Settings link in the footer of any page. It reopens the banner so you can switch analytics on or off. Turning it off stops any further collection; you can also clear the cookies in your browser.

Google acts as our data processor for this, under Google's data processing terms. We have not enabled any of Google's advertising features: advertising storage is switched off permanently and is never turned on, even when you allow analytics, so your visit is never used to build an advertising profile. Google Analytics anonymises IP addresses as standard.

We remember your choice in your browser's local storage so we do not have to ask again. That record holds only the word "granted" or "denied" — never anything that identifies you.

The waitlist

If you join the waitlist on this website, we keep your email address for one purpose: telling you when LO launches. Our lawful basis is your consent — the form says exactly what you're signing up for, and joining is the agreement. You can change your mind at any time: use the unsubscribe link in anything we send, or email hello@hellolo.app, and we'll delete your address. Waitlist emails are sent for us by Resend.

Your child's information

LO exists to hold memories of your child. Everything LO knows about them — their name, their birthday, the photos, the things they've said — comes from you, their parent or guardian, and is visible only within your account. You are in control: you can edit or delete any single memory, or delete your child's entire record, at any time.

We designed LO with children's best interests in mind. Children's information is never used for advertising, never profiled for commercial purposes, never sold, and never used to train AI.

LO accounts are for adults (18+). We do not knowingly collect information directly from children, and children cannot create accounts. If we learn a child has created an account, we will delete it.

Face information (biometric data)

If you turn on face recognition, LO analyzes photos on your device and creates a numerical summary of each face — a "face print" — so we can suggest who appears in your photos ("Is this Nana?"). Face prints are biometric data under UK GDPR (special-category data, Article 9), which is why they never leave your phone. Here is exactly how we treat them:

Face tagging can include other people in your photos — grandparents, friends. Please only tag people with their agreement.

How we use AI

LO uses AI to turn what you capture into keepsakes: photo captions, story text, slideshow narration, tidied-up transcripts of voice notes and letters, and gentle context (for example, understanding from your notes that your child is in a dinosaur phase, so captions feel true to them). To do this:

We never use your content to train AI models, and we do not permit our providers to. AI-generated text is always editable by you.

Why we process your information (lawful bases)

InformationPurposeLawful basis (UK GDPR)
Account & subscription detailsProviding LO, signing you in, managing membershipContract (Art. 6(1)(b))
Your child's information, photos details, notes, letters, voice recordingsCreating and keeping your family's memories; generating captions, stories and slideshowsContract (Art. 6(1)(b))
Face prints (kept on your device)Suggesting who appears in your photosExplicit consent (Art. 6(1)(a) + Art. 9(2)(a))
Time zone & push tokenDelivering notifications at the right timeContract / consent (you choose whether to allow notifications)
Crash & error reportsKeeping LO working and secureLegitimate interests (Art. 6(1)(f))
Emails we send (sign-in codes, account notices)Operating your accountContract

We do not rely on consent for anything except face recognition, notifications, this website's analytics cookies, and the waitlist emails you ask us for — and we never send third-party marketing.

Who we share information with

We share personal information only with the service providers below, only so they can provide their service to us, and never for their own purposes:

ProviderWhat they do for LOWhere
SupabaseDatabase, authentication and storage hostingLondon, UK (AWS eu-west-2)
Google Cloud (Vertex AI)AI caption and story generationEU data storage; processing may occur globally
OpenAIVoice transcriptionUnited States
AppleSign in with Apple, notifications, paymentsGlobal
RevenueCatSubscription managementUnited States
ResendSending sign-in, account, and waitlist emailsEU sending region
SentryCrash and error reportingEU (Germany)
CloudflareServing this website, security checks, and privacy-preserving visit counts (no cookies, no personal data stored)Global edge
Google AnalyticsWebsite visit statistics — only if you allow analyticsGlobal

We may also disclose information if the law requires it. We never sell personal information, and we never share it with advertisers or data brokers.

International transfers

Your family's data lives primarily in London, United Kingdom. Where a provider processes data outside the UK (for example OpenAI and RevenueCat in the United States, or Google's global AI processing), we rely on the UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses, alongside the providers' own safeguards.

How long we keep your information

Deleting your data

Deletion is self-service, inside the app: My Account → Settings lets you delete a single tagged person (immediate), a child's entire record, or your whole account (both with the 30-day grace period, and reinstatable during it). Account deletion also deletes your sign-in identity and, if you used Sign in with Apple, revokes it with Apple. You can also email hello@hellolo.app and we will do it for you.

Security

All data is encrypted in transit and at rest. Access to your family's data is enforced row-by-row at the database level — every request is checked against your signed-in identity, so no other account can read your family's memories. Photo pixels never leave your device except transiently for AI captioning, as described above.

Your rights

Under UK GDPR (and EU GDPR where it applies) you have the right to access, correct, delete, restrict, or object to our processing of your personal information, the right to data portability, and the right to withdraw consent (for face recognition) at any time. Most of these you can exercise directly in the app; for anything else, email hello@hellolo.app. We respond to all legitimate requests within one month.

US privacy rights

If you live in California or another US state with a consumer-privacy law: we do not sell or share personal information as those laws define it, and we do not use sensitive personal information beyond providing LO's features. You have the right to know, correct, and delete the personal information we hold — the in-app tools and email address above are how to exercise them. We do not discriminate against anyone for exercising privacy rights.

Complaints

If you're unhappy with how we've handled your information, please contact us first at hello@hellolo.app — we'd like the chance to put it right. You also have the right to complain to the UK Information Commissioner's Office at ico.org.uk or on 0303 123 1113.

Changes to this policy

If we make material changes, we'll tell you in the app before they take effect. The date at the top is the version currently in force.

LO · hellolo.app · hello@hellolo.app