Privacy policy
Last updated: 25 August 2026 · Version 1.0
The short version. LottaLou keeps a private journal of your family. We use your data to run the app and for nothing else. We do not sell it, we do not advertise against it, and there is no analytics or tracking SDK in the app. Recordings go to a speech-to-text provider on EU infrastructure to be turned into text; transcript text goes to an AI provider only to be tidied up and titled. You can delete your account, and your entries and photos, from inside the app.
Contents
1. Who we are
LottaLou is built and operated by Anne Albert, trading as annealbert.dev, a sole proprietorship (eenmanszaak) registered in the Netherlands.
- Controller: Anne Albert (annealbert.dev)
- Address: Dreischorstraat 26D, 3086 PB Rotterdam, the Netherlands
- KvK number: 76456080
- Email: privacy@lottalou.com
We are the controller for the personal data described here. We are not required to appoint a Data Protection Officer and have not appointed one; privacy questions go to the address above.
2. What this covers
This policy covers the LottaLou mobile app for iOS and Android, this website at lottalou.com, and the email we send you. Third-party services we rely on are listed in section 6; where you leave our app for a service of their own (the App Store, Google Play), their privacy policy applies to that part.
3. What we collect
Account
- Email address and, if you set one, your name and profile picture.
- A password, stored only as a cryptographic hash — or, if you use Sign in with Apple, the identifier and email Apple returns (which may be a private relay address).
- Your subscription status and its expiry date.
- Your time zone, and whether you have finished onboarding.
- Usage counters we need to enforce plan limits — recording seconds used, transcription and AI requests per day.
Journals
- The journal's name, type, cover colour, display font and transcription language.
- For a child journal: the child's name and date of birth, both of which you enter yourself.
Entries
- The transcript of your recording, the tidied version, and the title.
- The date, time and length of the recording.
- Milestones and life events you choose to record — a first, a quote, a celebration — and anything else you decide to put in an entry.
- Photos and videos you attach.
Sharing
- Who is a member of which journal, in what role, and who invited them.
- Invitations you create — either addressed to an email address you type in, or as a shareable link that anyone holding it can redeem until it expires.
Technical
- Crash and error reports: what went wrong, where in the code, the app version and the device model. These are configured to exclude request bodies, cookies, headers and device names, and long values are truncated.
- Server logs for each request our backend handles — the account identifier, what was asked for, whether it succeeded and the size of an uploaded recording — kept for security, abuse prevention and working out why something broke.
- Standard hosting logs at our providers, including IP address.
What we do not collect
- No advertising identifiers, no third-party analytics, and no behavioural tracking SDK is present in the app.
- No location data. We never ask for the location permission.
- No contacts. Invitations use email addresses you type in yourself; we do not read your address book.
- No payment card details. Purchases are handled by Apple or Google, and we only receive the resulting subscription status.
Permissions the app asks for
- Microphone — to record an entry, and audio for video.
- Camera — to take a photo or video for an entry.
- Photo library — to attach pictures you already have.
- Notifications — asked for during setup, for reminders. We do not currently send any, and refusing costs you nothing.
Each is asked for at the point it is needed, and each can be withdrawn in your device settings.
On Android the app also declares a set of lower-level permissions that the audio-recording library needs in order to work — access to Bluetooth audio devices, audio settings, a foreground service while recording, and keeping the screen awake. They are used for recording and nothing else. Google Play lists them in full on the app's page.
What is stored on your phone
So the app opens instantly and works without a signal, a copy of your recent journal data — entries, titles, transcripts and member lists — is cached in the app's own storage on the device for up to seven days, along with anything you entered during setup. Audio recordings also remain in the app's storage after they have been transcribed. All of it is removed when the app's data is cleared or the app is deleted.
4. Data about children
LottaLou is a journal about children, written by adults. The account holder must be 18 or over. There are no accounts for children and the app is not directed at them.
That said, the content is largely personal data about a child: their name, date of birth, photographs, video, quotes and milestones — plus whatever else you choose to write down. A journal is free-form, so some of what ends up in it may count as health data under the GDPR, which is a special category requiring extra care. We do not ask for it; the point is that if you record it, it is treated with that care.
You provide this data as the child's parent or legal guardian, or with that person's permission, and you are responsible for having the authority to do so — including for anyone else who appears in a photo or recording. We process it only to provide the journal to you and the people you have invited. We never use it to train AI models, we never use it for advertising, and we never sell or rent it. Where a provider processes it on our behalf, we select the service and the plan so that their terms forbid them from training on it either.
Because these are children's photographs, media is held in private storage and is reachable only through signed links that expire after one hour.
5. Why, and on what legal basis
| Purpose | Data | Legal basis (GDPR art. 6) |
|---|---|---|
| Creating and securing your account | Email, password hash, Apple identifier, settings | Performance of a contract (6(1)(b)) |
| Storing and showing your journals and entries | Journals, entries, transcripts, photos, video | Performance of a contract (6(1)(b)) |
| Turning your recording into text | Audio recording, resulting transcript | Performance of a contract (6(1)(b)) |
| Suggesting a title and cleaning up the transcript | Transcript text | Performance of a contract (6(1)(b)) |
| Sharing a journal with family you invite | Membership records, invited email address | Performance of a contract (6(1)(b)) |
| Handling subscriptions and enforcing plan limits | User identifier, subscription status, usage counters | Performance of a contract (6(1)(b)) |
| Keeping the service working and secure | Crash reports, error logs, server logs | Legitimate interests (6(1)(f)) — a stable, non-abused service |
| Storing special-category content you choose to add | Anything in an entry that counts as health data | Your explicit consent (9(2)(a)), given by entering it |
| Waitlist and product emails | Email address | Consent (6(1)(a)) — withdrawable at any time |
6. Who processes it
We use a small number of providers to run the service. They act on our instructions under a data processing agreement, and each receives only what its job requires.
| Provider | What it does | What it receives | Where |
|---|---|---|---|
| Supabase | Database, authentication, file storage, server functions | Everything stored in your account: profile, journals, entries, transcripts, photos and video | EU |
| Soniox | Speech-to-text | Your audio recording and the transcript produced from it | EU |
| Google (Gemini API) | Tidying a transcript, suggesting a title and photo-book captions | Transcript text only. No audio, no photos, no account details | United States / global |
| RevenueCat | Subscription management | Your account identifier and purchase status, plus the device and country information their SDK collects | United States |
| Sentry | Crash and error monitoring | Error details, app version, device model; the account identifier on errors raised by our own server functions | EU (Germany) |
| Resend | Sending invitation and account emails | The recipient's email address and the message | United States |
| Apple & Google | App distribution, in-app purchases, Sign in with Apple | Purchase and account data under their own policies | Global |
| Expo (EAS) | Building the app | Build metadata; no journal content | United States |
| Cloudflare | Hosting this website and the waitlist | Requests to the site, and the email address you submit | Global edge network |
We do not sell personal data and we do not share it with advertisers or data brokers. Each provider above is used on a plan whose terms prohibit it from using customer content to improve or train its own models.
Beyond this list, we disclose data only where the law requires it, or where it is necessary to establish or defend a legal claim.
7. Recordings and AI
This is the part people ask about, so here it is in detail.
- The recording is sent for transcription when you finish it — over an encrypted connection, through our own server function, to Soniox. That happens before you decide whether to keep the entry, so discarding one afterwards does not undo the transcription.
- We do not keep the audio. There is no audio storage in our backend; only the resulting text is saved to your entry, and the copy held by Soniox is deleted as soon as the transcript comes back. One copy does survive: the recording stays in the app's own storage on your phone until the app's data is cleared.
- What the AI provider gets is text. Once an entry has been transcribed, the transcript — not the audio, not your photos, not your account details — is sent to Google's Gemini API to suggest a title and to take out filler words and false starts. Both run automatically, on every entry.
- The original transcript is always kept, so you can read back what you actually said and return to it.
- No training. We do not use your recordings, transcripts or photographs to train models, and the providers above are used on plans whose terms forbid them from doing so.
- AI is not perfect. Transcription and tidy-up can get words wrong. Check anything you care about, and correct it — the entry is editable.
8. Sharing and invitations
A journal is private until you invite someone. You can invite them in two ways: by email address, which we store and send the invitation to, or as a shareable link. A shareable link is a bearer link — anyone who has it can join the journal until it expires — so send it only to the person it is meant for.
Once someone accepts, they become a member: they can read the journal's entries and media and, depending on the role you gave them, add their own.
Members can see each other. Everyone in a journal can see the name and profile picture of every other member.
Only invite people who would expect to be invited. Members can see the content shared with them, including photographs of your child, and what they do with it afterwards is outside our control.
An invitation sent by email shows the recipient who sent it — your name, or the first part of your email address if you have not set one.
You can remove a member or revoke an invitation at any time; invitation codes and shareable links also expire on their own.
Exporting a journal as a photo book builds a PDF on your device, with the photos embedded in it, and hands it to your phone's share sheet. Where it goes from there — email, a cloud drive, a print shop — is your choice, and outside our control.
9. Transfers outside the EEA
Some providers listed above are established in, or process data in, the United States. Where personal data leaves the EEA, we rely on the European Commission's Standard Contractual Clauses, on an adequacy decision such as the EU–US Data Privacy Framework where the provider is certified under it, or on both. You can ask us for details of the safeguards in place for a specific provider.
10. How long we keep it
- Your journals and entries — for as long as your account exists. That is the point of the product.
- Deleted entries — an entry you delete is marked deleted and disappears from the app immediately. The underlying row and its media are removed when you delete your account.
- Your account — deleting it from inside the app removes your profile, the journals you own and their entries, and every photo and video file in storage. Where you have added entries to someone else's journal, you choose during deletion whether those go too; if you keep them, they stay in that journal with your name detached from them.
- On your phone — the cached copy described in section 3 clears itself after seven days, and goes entirely when you clear the app's data or delete the app.
- Backups — our database is backed up daily, and those backups are kept for seven days before rolling off. So text you delete may survive in a backup for up to a week. Photos and video are not part of the database backup: when they are deleted from storage, there is no other copy.
- Crash reports — kept for up to 90 days.
- Records we must keep — invoices and tax records for the seven years Dutch law requires.
- Audio at our transcription provider — deleted as soon as the transcript comes back, as part of the same job.
- At our other providers — deletion in the app does not reach data already held by Google, RevenueCat, Sentry or Resend; each applies its own retention period. Ask us and we will pass on an erasure request where the provider supports one.
11. Security
- Everything travels over TLS.
- Data is encrypted at rest at our storage and database providers.
- Photos and video sit in a private bucket. They are served through signed links valid for one hour, and are not publicly addressable.
- Database access is governed by row-level security, so one account cannot read another's journals.
- Session tokens are held in the device's secure keychain or keystore.
- The keys for the services that see your content — speech-to-text and AI — exist only as server-side secrets. The app never holds them, and reaches those services only through our own server functions.
- The cached copy on your phone is protected by the operating system's own app sandbox rather than by separate encryption. If your device is unlocked, that cache is readable in the same way the app itself is.
No system is perfectly secure. If a breach occurs that is likely to present a risk to you, we will notify the Dutch Data Protection Authority within 72 hours and tell you directly where the law requires it.
12. Your rights
Under the GDPR you can ask us to:
- Access — give you a copy of your personal data.
- Rectify — correct anything wrong.
- Erase — delete your data ("right to be forgotten").
- Restrict — pause processing while a dispute is resolved.
- Port — hand over your data in a machine-readable format, or send it to another provider.
- Object — stop processing based on our legitimate interests.
- Withdraw consent — at any time, without affecting what was lawful before.
Email privacy@lottalou.com and we will answer within one month. Deleting your account, which does most of this immediately, is available in the app's settings.
If you think we have handled your data badly, you can complain to the Dutch Data Protection Authority (Autoriteit Persoonsgegevens, autoriteitpersoonsgegevens.nl) or to the supervisory authority where you live. We would rather you told us first.
13. This website
lottalou.com sets no cookies, runs no analytics and embeds no tracking pixels. Web fonts are loaded from Google Fonts, which means your browser makes a request to Google's servers and Google sees your IP address for that request.
If you join the waitlist, we store the email address you submit, the time you submitted it, and nothing else, in order to write to you once when the app is ready. We do not pass it to anyone. Ask us and we will delete it.
Our host, Cloudflare, keeps short-lived request logs for security and abuse prevention.
14. Changes
We will update this policy when the app changes. The date at the top always reflects the current version. For a change that materially affects you we will tell you in the app or by email before it takes effect; continuing to use LottaLou afterwards means the new version applies.
15. Contact
Anne Albert (annealbert.dev)
Dreischorstraat 26D, 3086 PB Rotterdam, the Netherlands
KvK 76456080
privacy@lottalou.com