Privacy Policy
Last updated: September 15, 2026
This policy explains how Vinay handles information when you use Little Lift on iOS, Android, and the web. You can explore default topics without an account. Signing in and AI personalization are optional.
Information we handle
- Account details: your email address, Firebase user ID, sign-in credentials handled by Firebase Authentication, and authentication/session information. Passwords are not part of your Little Lift library or sent to the AI provider.
- Your content: saved affirmations, personal deck names, the context you submit, generated statements, visualization and action cues, edits, card positions, and related timestamps.
- Preferences and credits: your sound selection, credit balance, and generation records such as completion/refund status and timestamps.
- Technical information: our hosting and service providers may process IP addresses, request details, device/browser information, and security logs. Production request limiting uses a hash derived from an IP address and short-lived counters.
What you write may reveal sensitive information about health, relationships, beliefs, or other personal matters. Include only what you want processed. Please do not submit passwords, payment details, identity documents, or someone else’s private information.
Notifications
If you enable notifications in the native app, Firebase Cloud Messaging and Apple Push Notification service process device registration identifiers to deliver messages. We store your device token, platform, registration ID, and update time with your account. Messages are general and do not include your personal affirmation text. You can turn notifications off in Settings; signing out removes that device registration, and account deletion removes all registrations. Native push uses hosted Firebase even when account development uses emulators.
What stays on your device
Bookmarks are stored using IndexedDB. Personal decks, their context, card position, and preferences use localStorage. Default topics and bundled music do not need an AI request. These storage mechanisms support the service; we do not use advertising cookies or add advertising/analytics trackers.
Signing in uploads your local library to your account and enables background sync. “Sync now” requests an upload immediately. Signing out restores the guest library previously kept on that device. This means signing out does not erase all local words. Other people who can access your device or browser may be able to read local content.
How we use information
We use account information to authenticate you, recover access, and connect your library across devices. We use your content to display and save your affirmations and, when requested, generate personalized cards. We use credit records and technical information to operate the service, prevent abuse, troubleshoot failures, and respond to support requests. We do not sell personal information or use your content for targeted advertising.
AI personalization and service providers
After you explicitly select “Agree and generate,” your entered context and relevant topic/card text go to our backend and its AI service. The integration uses OpenRouter and OpenAI. Requests are restricted to OpenAI endpoints with training/data-collection routing disabled; generation fails if an allowed endpoint is unavailable. This is not a zero-retention service: providers may retain data under their security, abuse-prevention, and service policies. Do not assume an AI request remains solely on your device. Your account email and password are not included in the generation prompt.
Google Firebase provides account authentication and cloud storage in hosted deployments. OpenRouter and OpenAI process AI requests. Hosting providers process network requests, and Upstash Redis is used for production request limits when configured. Local development uses Firebase emulators instead of the hosted Firebase service. We do not log AI prompts or responses in our application server. Training restrictions do not erase past requests or prevent all retention; OpenRouter account logging settings and providers’ technical/security metadata are separate. We do not promise that all technical metadata is immediately erased.
Read OpenAI’s Privacy Policy, Firebase’s privacy information and OpenRouter’s Privacy Policy. The provider list and processing arrangements must be reviewed and updated if the deployed service changes.
Purchases
Apple or Google processes native payments. RevenueCat validates store purchases using your Firebase account identifier, product and transaction information, purchase/refund status, country, currency, and technical app information. We do not receive your card number. Your Firebase profile holds your shared credit balance. We do not send your affirmation text or personal context to RevenueCat. Read RevenueCat’s Privacy Policy.
Audio, permissions, and exports
The speaker uses your device/browser speech service. Some voices may process text online under that service’s policy. Background music is bundled with the app. Little Lift does not request microphone, camera, contacts, or precise location access.
Export includes deck titles and saved affirmation text, not your original context or account metadata. On native apps, you choose where to send the file using the system share sheet; its temporary app-cache file is removed after sharing finishes. Exported copies and copies sent to another app remain under your control.
Content reports
“Report this card” sends the card text, selected reason, and any details you add to our review queue. Your original deck context is not automatically included. Signed-in reports are associated with your account and are removed with it. Guest reports are not linked to a Little Lift account. Reports expire after 90 days plus the database’s expiry-processing delay. Contact us to request earlier removal.
Retention and deletion
Local content remains until you delete it, reset the relevant deck, clear app/browser data, or uninstall the app, subject to your operating system’s backup behavior. Cloud libraries and account/credit records remain while the account exists; this version has no automatic account-expiry schedule. Uninstalling the app or clearing browser data does not delete cloud data.
You can remove individual bookmarks, clear saved words, delete a personal deck, or reset a personalized topic. While signed in, those changes sync to your account when connected. A reset does not remove separately bookmarked cards. Unsynced devices, guest copies, backups, and files you exported can retain separate copies.
Open Settings → Delete account and confirm your password to permanently remove your Firebase sign-in, cloud library, context, reports, preferences, generation records, and unused credits. This also clears Little Lift’s local and guest library on the device used to complete deletion. Deletion finishes when confirmation appears; if it fails, retry. You can also visit our account-deletion page or contact us for help or a request to remove specific data. We verify ownership for support requests and respond within 30 days.
Account deletion also requests deletion of your RevenueCat customer record, which RevenueCat processes asynchronously. Store payment records remain under Apple’s or Google’s policies. To prevent purchase replay and handle refunds, we retain a minimal receipt ledger containing hashed transaction/account identifiers, product, store, environment, credit adjustments, and timestamps after account deletion. It contains no email, affirmation text, or context.
A security marker containing one-way hashes of the former account ID and deletion-authorizing token, deletion state, and expiry date blocks delayed saves from recreating deleted accounts. Completed markers expire after 30 days plus database expiry-processing time; incomplete deletion markers remain until completion. They contain no email, words, or context. We do not intentionally retain deleted cloud libraries in application backups. External provider security logs and infrastructure backups have their own retention schedules, which must be verified for the hosted service before release.
Delete your account or request data deletion
Your choices and rights
You can use default topics without signing in, choose what context to submit, edit or remove saved words, export your saved affirmations, and decline AI processing before each request. Declining does not affect default topics. Depending on where you live, you may have rights to access, correct, delete, restrict, or object to processing of your information, obtain a portable copy, withdraw consent, or complain to a privacy regulator. Contact us to make a request. Withdrawal does not undo processing already performed.
Security and international processing
Hosted account access uses authentication and server-side access checks. Release builds require an HTTPS backend; emulator builds can use local HTTP connections for testing. These measures do not make any system completely secure. Service providers may process information outside your country, with applicable contractual and legal protections to be confirmed for the production deployment.
Age and wellbeing
Little Lift is intended for adults aged 18 and over. We do not knowingly seek information from children. Contact us if you believe a child has provided information. The app is for reflection and general wellbeing, not diagnosis, therapy, emergency monitoring, or a guarantee that an imagined outcome will occur.
Changes and contact
We may update this policy as the service changes. We will revise the date above and provide additional notice or request consent where required for material changes.
For support, privacy questions, or requests concerning your information, contact Vinay at vinay@littlelift.app. Please identify Little Lift and your account email, but never send your password.