Liloo — Privacy Policy
Last updated: 2026-09-02 Contact: privacy@liloosafespace.com
This Privacy Policy explains what data the Liloo mobile application
(application ID com.liloosafespace.app) and the website at
liloosafespace.com process, for what
purposes, on what legal basis, with whom the data is shared, and how you
can control it.
What Liloo is. Liloo is a communication-skills training app. You hold a conversation with AI characters that play the role of difficult interlocutors (for example, a conflict-prone relative or an aggressive colleague) so you can safely rehearse handling tense situations. The app also includes a "Training" mode and audio meditations. For an AI character to reply, the text of your message is sent to our servers and to a third-party language-model provider (see Section 4).
1. Who processes your data (data controller)
The data controller is FOP Rudenko Yevheniia Yevhenivna (an individual entrepreneur registered in Ukraine), the developer and operator of the Liloo app.
For any privacy question, to exercise your rights, or to request deletion, contact:
Email: privacy@liloosafespace.com
2. Data we collect
| Category | Details |
|---|---|
| Account identifiers | An anonymous user identifier or your email address, depending on how you sign in. Authentication is handled by Firebase Authentication and supports anonymous sign-in, email/password, Google Sign-In, and Apple Sign-In. When you sign in with Google or Apple, we receive your name and email address from that provider. |
| Profile and avatar data | Details you provide about yourself and your interlocutor to set up a dialogue (e.g. gender, age, your role in the situation, a short situation brief), plus the name and settings of the AI character (avatar). |
| Conversation content | The text of the messages you type in your dialogue with an AI character, and the AI's replies. This is stored linked to your account. |
| Dictation audio and recognized text | Current iOS and Android versions use the device's system speech-recognition service. Depending on the device and its settings, Apple, Google, Samsung or another installed system provider may process audio locally or through its own network; Liloo does not receive or store that audio. Earlier supported mobile versions may upload dictation audio to Firebase and OpenAI for transcription when local recognition is unavailable. The web test-drive does not offer dictation. In every version, recognized text remains editable and is processed like an ordinary message only if you choose to send it. |
| Photos (camera / gallery) | An image you capture with the camera or select from your gallery for an avatar. It is uploaded to cloud storage and associated with your avatar. |
| Device push tokens and timezone | If you allow push notifications, we store your device's Firebase Cloud Messaging push token (in the push_tokens field on your account) and your device timezone (used to respect notification quiet-hours) so we can deliver notifications. |
| Technical, crash and moderation logs | Technical data needed to run the service (such as conversation and message identifiers), crash/error diagnostics and stack traces, and records of safety-system triggers and reports you submit. |
| Product usage and Android install attribution | A random Liloo installation identifier, app version, language, screen and funnel events (for example, onboarding completed, scenario started or paywall shown). On Android, the app reads Google Play Install Referrer once to obtain allowlisted campaign parameters and install/click timestamps. A Google Ads click identifier, when present, is converted to a one-way hash before storage. Message text, the Android advertising ID and the complete raw referrer are not included. |
| Website reports and support correspondence | If you use the website report form, we process your name, optional email address, subject, message, page URL, IP address and browser user-agent so we can investigate and reply. |
| Friend invitations | When a registered user asks Liloo to invite a friend, we process the friend's name, email address, an optional personal note, the inviter's identity, and technical delivery/interaction outcomes (provider acceptance, destination-server acceptance, open, link visit, bounce, complaint or opt-out). |
We do not access your contacts and we do not collect your location or an advertising identifier. The app requests permissions for the camera (avatar photo), the microphone and iOS speech recognition (system dictation), and notifications (push) — each used only for that feature.
3. Purposes and legal basis
We process your data to:
- Provide the core feature — generate the AI character's replies to your messages, the "Training" mode, and meditations.
- Support dictation — convert speech into editable text that you can review before sending.
- Store your avatars, dialogues and history — so you can continue sessions and track progress.
- Manage subscriptions — process in-app purchases and your subscription entitlement.
- Keep the service safe — detect crisis situations (e.g. mentions of self-harm), harmful or prohibited content, and attempts to bypass a character's safeguards, and handle reports you submit about AI replies.
- Send notifications — deliver push notifications where you have consented.
- Diagnose crashes and errors — use technical diagnostics to maintain app reliability and investigate failures.
- Measure acquisition and product activation — understand which install sources lead to onboarding, dialogue practice and subscriptions, using first-party product events without conversation text.
- Respond to website reports and support requests — investigate the issue, prevent duplicate or recurring problems, and contact you when you provide an email address.
- Deliver a friend-requested invitation — send the initial invitation and limited reminders, show their technical outcome to the inviter, attribute a later registration when the same normalized email is used, and honor a recipient's opt-out. Receiving an invitation does not create an account.
Legal basis — your consent. Processing is based on the consent you give by using the app and granting the relevant permissions (camera, microphone, speech recognition, notifications). You can withdraw consent at any time (see Section 6 and Section 7). Some processing is also necessary to provide the service you request.
4. Sharing with third parties (processors)
To run the app we use third-party providers that process data on our behalf. Your conversation content leaves your device and is processed by these services:
| Provider | What it processes |
|---|---|
| Google Firebase / Google Analytics / Google Ads (Google LLC) | Authentication (Firebase Auth), the database of dialogues and profiles (Firestore), storage of avatar photos (Storage), push notifications (Cloud Messaging), crash/error reporting (Crashlytics), and — after the user accepts the app's legal documents, unless disabled in the app — pseudonymous campaign measurement and conversion events. |
| Apple / Android system speech provider (Apple, Google, Samsung or another provider installed on the device) | Optional dictation audio and the resulting text when you use voice input. Processing may occur locally or on the provider's network according to the device, provider and account settings. Liloo does not receive or store this audio in current app versions. |
| OpenAI | Processing of your conversation text by a language model to generate the AI character's replies and, for earlier supported mobile versions only, transcription of dictation audio when the device's local recognizer is unavailable. |
| Mailjet (Sinch) | Delivery and technical status tracking of transactional email, including password resets and friend invitations. Processes the recipient name/email and delivery/interaction outcomes. |
| RevenueCat (RevenueCat, Inc.) | Subscription and in-app purchase management. Processes your user identifier (Firebase UID) and purchase data. |
| DigitalOcean (DigitalOcean, LLC) | Hosting of the backend (the API at api.liloosafespace.com and the PostgreSQL database) that stores conversations, profiles, and moderation records. |
| Atlassian (Trello and Jira) | Issue tracking for website reports and product feedback. A report may include the name, optional email, subject, message, page URL, IP address and browser user-agent described above. |
We do not sell your personal data. Sharing is limited to the processors above and to cases required by law.
Where your data is hosted and international transfers
The backend application and the primary database are hosted on DigitalOcean in London, United Kingdom (LON1 region).
Some processors operate on their own infrastructure, which may be located in the United States. In particular, Firebase (Google) and OpenAI process data on Google's and OpenAI's own infrastructure, which may be located in the United States. Where data is transferred internationally, such transfers rely on those providers' standard contractual safeguards.
Website analytics and cookies
The website at liloosafespace.com uses Google
Analytics 4 and Google Ads (Google LLC) to understand how visitors use
the site and to measure the results of our advertising campaigns. Analytics and
advertising cookies and any related storage are disabled by default — they
are loaded only after you accept them in the cookie banner shown on your first
visit. We run Google Consent Mode: if you decline, the analytics and
advertising signals (analytics_storage, ad_storage, ad_user_data,
ad_personalization) stay denied and no such cookies are set. You can change
your choice later through Cookie settings in the website footer, or clear
or block cookies in your browser at any time.
In the mobile app, pseudonymous Google measurement remains disabled until you accept the app's legal documents and continue past the first screen. This is the same on Android and on iOS. It then starts: Firebase Analytics creates a random app-instance identifier and Liloo may send Google Analytics and Google Ads only approved technical event/conversion names (such as registration, dialogue start, activation, trial or purchase) and their timestamps. We do not send an advertising ID, Firebase UID, email, profile data, scenario/persona names or dialogue text for this purpose; ad personalisation remains disabled. You can turn measurement off under About the app on either platform, which prevents future exports. Liloo's first-party product analytics remains separate. Android also reads Google Play Install Referrer once for campaign measurement, and Firebase Crashlytics is used for crash/error diagnostics as disclosed above.
Crisis-safety signals and moderation review
Liloo checks dialogue text in real time for self-harm risk so it can stop the role-play and show a reviewed response and local support resources. This safety check always runs. A critical event is retained for authorised human moderation with the source message, internal account and conversation identifiers, matched safety trigger, direction (user input or AI output), time, system action, review status and moderator notes. It is used only for safety review, incident response and improving the safety filter; it is not exported to Google Analytics or Google Ads and is not used for advertising or personalisation. Critical-event data is removed through the normal account-deletion flow or on a verified privacy request to privacy@liloosafespace.com.
See the separate Consumer Health Data Privacy Policy for the complete categories, sources, processors, retention and rights notice.
5. Data retention
We keep your data only for as long as needed for the purposes above. The schedule below sets out how long each category is retained:
- Account, profile, avatar and device-timezone data — kept while the account is active; erased within 30 days after you delete your account.
- Conversations and messages — kept while the account is active; erased within 30 days after account deletion.
- Account-linked crisis-safety events — kept while needed for safety review, no longer than 90 days, and erased with account deletion or an earlier verified privacy request.
- Dictation audio — current app versions do not store it in Liloo infrastructure; the system speech provider handles it according to the device and provider settings. Earlier supported versions process audio uploaded to Liloo's transcription path ephemerally and delete it immediately after transcription. Recognized text follows the conversation lifecycle above only if you send it.
- Push notification tokens — kept until you disable notifications or delete your account.
- Website reports and support correspondence — kept while the issue is investigated and for as long as reasonably needed to identify duplicate or recurring problems; server log copies follow the 90-day log schedule below.
- Friend invitations — kept with the inviter's account so the inviter can
see the result and receive the promised referral bonus. They are deleted when
the inviter deletes the account. An invited person can stop later mail from
the invitation or ask
privacy@liloosafespace.comto delete contact data. - Purchase and subscription records — retained for up to 3 years after the transaction to meet accounting and tax obligations, even after account deletion, then erased.
- Server logs and diagnostics — up to 90 days. Backups are purged within 30 days.
When you delete your account, your data is removed as described in Section 6, except minimal records we are required to keep by law or to prevent abuse.
6. Account and data deletion
You can delete your account directly in the app: Profile → Delete profile.
On confirmation, the app records the deletion request (a to_delete marker)
and deletes your Firebase Authentication user. This automatically triggers a
server-side cascade cleanup:
- your dialogues and messages are deleted;
- your avatars and their associated storage files (including photos) are deleted;
- associated backend data (PostgreSQL) is purged.
If you cannot use the in-app option or want to confirm deletion, email privacy@liloosafespace.com.
7. Your rights
Depending on your jurisdiction (including under the GDPR) you have the right to:
- access your data and obtain a copy;
- correct inaccurate data;
- delete your data (see Section 6);
- withdraw consent you previously gave (including by revoking camera, microphone, and notification permissions in your device settings);
- restrict or object to processing;
- lodge a complaint with a data protection supervisory authority.
To exercise these rights, contact privacy@liloosafespace.com.
8. Reporting AI content
Liloo deliberately simulates verbal conflict, so AI replies may contain sharp lines and mild profanity by design — that is part of the training scenario. If an AI reply seems genuinely offensive or inappropriate, you can report it directly from within the app. The report reaches us and is used for moderation and to improve our safety systems.
9. Children and eligibility
You must be at least 17 years old to use Liloo. The app is rated 17+ (mature content) and is not directed to children. It contains simulated conflict content with mature, mild-profanity dialogue and is intended for an adult audience. If you believe a person under 17 has provided us with their data, email privacy@liloosafespace.com and we will delete it.
10. Security
All network traffic between the app and our services is encrypted in transit using HTTPS/TLS. Firestore access is governed by per-user, owner-based security rules, and the backend API uses token-based authentication. Data at rest is protected by the underlying infrastructure of our processors (Google Firebase and DigitalOcean).
11. Changes to this policy
We may update this Policy. For material changes we will update the date at the top of this page and, where appropriate, notify you in the app.
FOP Rudenko Yevheniia Yevhenivna (individual entrepreneur, Ukraine) · privacy@liloosafespace.com · Last updated 2026-09-02
