Privacy policy

LoveLust Privacy Policy

The LoveLust Company SL built LoveLust with privacy as its foundation. This policy explains what data the app processes, how, where, and the rights you have under the General Data Protection Regulation (GDPR).

LoveLust is for users who are 18 years of age or older.

Last updated: 2026-08-20

1. What Stays On Your Device

Everything you record in LoveLust is kept on your device, in encrypted storage (Section 7):

  • Sexual activity, partners, contraception and notes.
  • Cycle and reproductive health: bleeding days and levels, symptoms and pain scores, cycle and bleeding lengths, predicted period, ovulation and fertile-window dates, and pregnancy or ovulation test results.
  • STI screenings, treatments and results, medications, doses and reminders.
  • Photos you attach to a partner, and your profile details.

All of it is special category data under GDPR Art. 9. The lawful basis is your explicit consent under Art. 9(2)(a), given through a separate opt-in (default off) and withdrawable at any time (Section 6).

This data:

  • is never sent to our servers. Not to our backend, not to our analytics, not in crash reports;
  • is never sold, and never shared with advertisers;
  • is computed on your device: every cycle prediction, safety reading and statistic is calculated locally;
  • goes to Apple HealthKit (iOS) or Health Connect (Android) only if you turn that integration on;
  • goes into the optional encrypted cloud backup only if you turn that on (Section 3).

The one thing you write that does leave the device is a survey answer, and only if you choose to answer a survey. See Section 2.

2. What Leaves Your Device

Your account record

LoveLust has no login. To deliver notifications and unlock what you have paid for, the app sends to our backend:

  • an internal account identifier, which is not your name and not derived from anything you entered,
  • your language, platform (iOS/Android) and app version,
  • your push-notification token, if notifications are on,
  • your subscription status, so paid features unlock on your devices,
  • your notification and communication preferences, and which topics (store, games, toys, cycle) you asked to hear about,
  • which survey rewards have already been granted to this account, so a reward is not paid twice.

No activity, partner, cycle, medication or screening data is ever sent to this backend. Lawful basis: performance of the service you asked for, Art. 6(1)(b), and your consent for communications, Art. 6(1)(a). You can have this record deleted (Section 5).

Surveys, if you answer one

Surveys are optional and run on a service of ours, separate from the app's backend. If you complete one:

  • your answers are stored without any identifier: no account id, no device id. The stored record holds the survey, its version, your language, a timestamp, and the answers themselves;
  • separately, our backend records that this account earned that survey's reward, so it is granted once. That record holds the account identifier and the survey, never your answers;
  • some questions accept free text, so please do not type anything into them you would not want stored. Nothing from your journal, cycle log, partners or medications is attached to a submission.

Diagnostics and crash reports

We use Firebase Crashlytics (Google) and Sentry (EU data region) to receive crashes and error diagnostics: the error, a stack trace, and device and OS information collected by the SDKs. Neither is given your account identifier, and Sentry runs with personal data collection off, no session replay and no user identity. We use Firebase Remote Config (Google) for feature flags, which involves a configuration request carrying standard device information. Lawful basis: legitimate interest in a working app, Art. 6(1)(f).

Product analytics

We use Aptabase for anonymous, aggregate analytics. Nothing is collected until you turn analytics on, with five exceptions that fire regardless because the app cannot be operated safely without them:

  • the app being opened (with the device language),
  • the record that you granted analytics consent, and the record that you asked for your data to be deleted, both kept so we can show a rights request was honoured,
  • two storage-integrity signals: that a storage migration completed, and that a device clock was far enough out to disturb cloud sync.

Nothing else. Once you consent, analytics covers screens visited, feature counts and settings changes. Analytics touching intimate or health data is a separate explicit opt-in and, whatever you consent to, no cycle content is ever sent to analytics: no bleeding day, no symptom, no pain score, no predicted date, no test result. Events never carry names, notes, free text, contacts, locations, birth dates or any direct identifier, only counts, booleans and bounded categories. See Aptabase's Privacy Policy.

Purchases

In-app purchases are managed by RevenueCat, which processes an account identifier, transaction identifiers and purchase history to validate and restore subscriptions. We never receive your card details. See RevenueCat's Privacy Policy.

Content the app downloads

The games catalog comes from our content service, and this policy, the terms and the FAQ are fetched from this site so what you read in the app is always the published version. Both are read-only downloads that carry no identifier, though as with any web request the server sees the connection.

3. Cloud Backup (optional, premium)

If you enable encrypted cloud backup, your activity, partner, cycle, medication, settings and photo data is encrypted on your device with a key derived from your passphrase, before upload to your own Google Drive or iCloud, in a private app folder.

We cannot decrypt your cloud backup; only you hold the passphrase. Keep it safe: if you lose it, the backup cannot be recovered. Our servers never receive the backup or the passphrase.

4. Where Data Is Stored

On your device, encrypted (Section 7). Our servers hold only the account record and, unlinked from it, any survey answers you submitted. The optional cloud backup lives in your own Google Drive or iCloud, encrypted before it leaves the device.

5. Retention and Deletion

Local data is kept until you delete it. You can:

  1. Settings → Storage → Clear all data: erases all local data, and asks our backend to delete your account record at the same time.
  2. Delete your cloud backup separately: clearing local data does not remove it. Go to Settings → Cloud storage, sign out and delete the remote backup. We keep it until you do, so you can restore after reinstalling.
  3. Uninstall the app: removes local data only. The cloud backup and the backend record remain; use steps 1 and 2 first, or contact us.
  4. Survey answers cannot be deleted individually, because they are not stored with anything that identifies you. Answers you have not yet submitted are still on your device.

6. Your GDPR Rights

  • Art. 13/14, Transparency: the controller and its contact details are in Section 10.
  • Art. 15, Access: request a copy of the personal data we hold, which is the account record. Your local data is exportable in-app.
  • Art. 16, Rectification: correct data in-app, or contact us.
  • Art. 17, Erasure: delete local, cloud and backend data in-app (Section 5); contact us for anything left.
  • Art. 20, Portability: export everything as machine-readable JSON via Settings → Storage → Export data.
  • Art. 7(3), Withdraw consent: withdraw analytics or intimate-data consent at any time in Settings → Privacy, without deleting anything. Withdrawal is as easy as consenting.
  • Art. 21, Object / Art. 18, Restriction: contact us.

To exercise any right, use Section 10. We respond within 30 days.

7. Security

Local data is encrypted on your device with AES-256. The key is generated on your device at install, is different for every installation, and is held in the operating system's secure key storage (iOS Keychain, Android Keystore). The optional cloud backup is encrypted on your device before upload, with a key derived from your passphrase.

Two deliberate exceptions, both local to your device:

  • what an iOS widget or the Apple Watch app displays is written to a container shared with those extensions, outside the encrypted store, because a widget has to be able to read it. Keep this in mind when choosing which widget to place on a home or lock screen. Discreet notifications, in Settings, control what reminders show;
  • a photo being viewed is decrypted to a temporary file, which is deleted when the app goes to the background.

No system is completely secure. We apply industry practice and cannot guarantee absolute security.

8. Third Parties

We do not sell your data. We use no advertising networks.

Where we are trying to get to

Some of the above is not where we want to end up. LoveLust ships the Firebase SDK (Google) for crash reporting and feature flags, and that SDK also carries Google Analytics for Firebase, which collects standard app-usage data of its own once it is present. None of it receives anything you record, and none of it is given your account identifier, but it is more of Google than a privacy-first app should need.

We intend to remove these Google dependencies: to keep crash reporting on Sentry alone, to move feature flags to our own service, and to drop Google Analytics for Firebase entirely. We are saying so here rather than after the fact, and this section will say what actually changed when it does. No date is promised; the work is real and it is not done.

Reports you export as a PDF, and anything you share from the app, leave through your own device's share sheet, to wherever you send them. That is outside our control.

9. Age Restriction

LoveLust is for users 18 or older. If you believe a minor has used the app, contact us and we will delete the associated data.

10. Data Controller and Contact

  • Controller: The LoveLust Company SL
  • Registered address: Calle Huesa del Común 2, 2C, 50011, Zaragoza, Spain
  • Data protection contact: [email protected]
  • Data Protection Officer: Abel Candelario Vallejo
  • Supervisory authority: you may lodge a complaint with your local Data Protection Authority. In Spain, that is the Agencia Española de Protección de Datos (aepd.es).

11. Changes to This Policy

We may update this policy. The app reads it from this site, so what you see in the app is always the current version. Material changes are notified in-app with an updated date and a summary. We will not treat continued use alone as acceptance of a material change affecting consent; where consent is required, we ask again.

Changelog

  • 2026-08-20: named the cycle module and its data. Added Sentry, the surveys service, the games catalog and the in-app document fetch. Described the five events that fire before analytics consent. Corrected what the account record holds, how the backend record is deleted, and the two places local data is not encrypted. Named the Firebase dependency and our intent to be rid of it, and dropped the service hostnames from the public text.
  • 2026-05-15: first published.