The short version
- Images never leave your device. Object detection runs locally on your iPhone.
- Only the resulting label (like "date" or "cup") is sent to find a Hadith.
- 5 separate consent toggles — analytics, personalization, cloud sync, etc. All opt-in.
- You can export or delete everything from the in-app Data Dashboard. Always.
- We're a 2-person team. We don't sell data. There's nothing to sell.
Data we collect
Lightio collects data only based on what you do in the app and which consent toggles you've enabled. Here's everything, in one place:
| Data type | What & where |
|---|---|
| Essential Required |
Images you capture (processed locally only), detection results (object labels), history of detected objects, and saved favorites. All stored on your device. |
| Analytics Opt-in |
Anonymous usage information — feature usage frequency, session duration, crash reports. Used only to improve stability and performance. |
| UI Personalization Opt-in |
Theme choices, layout adjustments, and other interface preferences. Tailors how the app looks for you. |
| Data Personalization Opt-in |
Gender and birth date you voluntarily provide, used to tailor Hadith relevance. Your birth date is converted to an age-group bucket (your exact date is never used for ranking), and a minimum age of 13 is enforced. Requires UI Personalization to be active. A phone number is optional contact info only — never required, never verified, never used for SMS or marketing. |
| Preferred Language Opt-in |
The Hadith translation language you pick in Settings (signed-in users only). English is the default — no language data leaves your device until you make a selection. Stored in your Firebase Firestore profile and also applied to prayer-reminder notification text. |
| Cloud Storage Opt-in |
Securely backed-up history and favorites for cross-device sync via Firebase Firestore. Images themselves are never part of cloud backup. |
| Prayer & Location Opt-in |
City, country, coordinates, and time zone — detected when you enable Prayer Reminders and refreshed automatically when you open the app if you've moved (one-shot only, no background tracking). Stored in your Firebase Firestore profile. Notifications scheduled on-device. The app also keeps a small local list of recently-shown hadith identifiers per prayer time so notifications surface fresh reflections instead of repeating — no personal data, never leaves your device. |
By default, only the Essential category is active. Everything else is off until you turn it on in Privacy & Data settings.
How we use your data
Provide core functionality
Detect objects in your images using on-device machine learning. Find relevant Hadiths by sending the resulting label (not the image) to our search service. Maintain your local history and favorites.
Improve the app
If you opt into Analytics, we analyze usage patterns to find bugs, identify popular features, and prioritize work. All anonymous.
Tailor your experience
UI Personalization remembers your theme and layout preferences. Data Personalization uses your gender and age-group bucket to suggest more relevant Hadiths. Your Preferred Language, if set, is applied to AI summaries and prayer-reminder notifications.
Enable cross-device features
Cloud Storage securely syncs your history and favorites between your iPhones and iPads. Prayer Reminders use your location to calculate accurate times locally.
Third-party services
Lightio integrates with a small, intentional set of third-party services. Every one is named here:
- OpenAI — Hadith search and AI-generated summaries. We send detected object text labels and, only when Data Personalization is on, your gender, age-group bucket (never your exact birth date), and preferred language so results can be ranked. Never your image, email, phone, or history.
- Apple (Sign in with Apple, APNS, Core ML, MapKit) — authentication, push notifications, on-device ML, and location services.
- Apple WeatherKit — used for two purposes inside Prayer Reminders: (1) sunrise, solar noon, and sunset times shown beneath Today's Schedule, and (2) current weather conditions to enrich hadith reflection search at prayer-time notifications (e.g. surfacing rain-related hadiths when it's raining). Both use the latitude and longitude already stored in your prayer profile — no additional personal data is sent. Legal attribution and data sources are linked in-app beneath the Sun Today section.
- Firebase Authentication — accounts and sign-in via email/password and Sign in with Apple. Passwords are handled entirely by Firebase. No phone sign-in or SMS verification.
- Firebase Firestore — cloud database storing your profile (gender, birth date, email, optional phone, preferred language, prayer location) and, with Cloud Storage consent, your synced history & favorites. Images are never stored — only text data.
- Firebase Cloud Messaging — server-side delivery of push notifications you've opted into.
- Firebase Crashlytics — anonymized crash reports (stack trace, device model, OS version) plus your Firebase user ID for correlation when signed in. No detection history, favorites, profile fields, or message content is collected.
We do not use advertising SDKs, third-party analytics trackers, social media pixels, or marketing automation tools.
Your GDPR rights
Under the GDPR (and similar regulations like CCPA, PDP, and PIPL), you have the following rights — all exercisable directly inside the app:
Right to access
View all data Lightio has stored about you — in the Data Dashboard.
Right to rectify
Correct inaccurate profile or preference data at any time.
Right to erasure
"Right to be forgotten" — delete everything with one tap.
Right to restrict
Pause processing of any specific data category via consent toggles.
Right to portability
Export your data as a standard JSON file you can take anywhere.
Right to object
Decline any optional processing without losing core functionality.
Data security
We take the security of your data seriously:
- All data is encrypted during transmission (TLS 1.3) and at rest.
- Our APIs run on hardened, regularly-patched cloud infrastructure.
- Access to backend systems is limited to authorized personnel and audited.
- We regularly review our security practices against industry standards.
In the event of a data breach affecting your personal data, we will notify you within 72 hours as required by GDPR.
Data retention
We keep your data only as long as needed to provide the service:
- History Stored locally on your device until you delete it or clear your history.
- Favorites Stored locally until you remove them or delete all user data.
- User profile Retained until you clear your profile or delete all user data.
- Cloud backup If consented, retained in Firebase Firestore until you disable Cloud Storage for that data type.
- Analytics Aggregated and anonymized; raw events deleted within 90 days.
- Crash reports Retained for 90 days for diagnosis, then automatically purged.
When you delete data through the app, it is permanently removed from your device and, where applicable, our cloud systems.
Children's privacy
Lightio is not intended for children under 13 years of age. We do not knowingly collect personal information from children under 13. If you believe a child has provided us with personal data, please contact us so we can promptly remove it.
Changes to this policy
We may update this Privacy Policy from time to time. We will notify you of any material changes by:
- Posting the new policy on this page with an updated "Last updated" date.
- Showing an in-app notification before the changes take effect, where required.
You can review previous versions of this policy at any time by contacting us.
Contact us
Questions about your privacy?
We respond personally — usually within 48 hours. There's no support ticket queue, just two people.
hello@yogie.id