lil friends lil friends

Privacy Policy

Effective date: July 18, 2026

This policy explains what information Lil Friends, LLC ("we," "us," "our" — the data controller, where laws use that term) collects when you use the lil friends mobile app and the website at https://lilfriends.app, how we use it, who we share it with, and the rights you have. If you have questions, contact hello@lilfriends.app.

Summary

1. Information we collect

Information you provide:

Information created by using the app:

Information collected automatically:

Information from third parties: sign-in providers (Apple, Google) supply your email address and a sign-in token. Payment infrastructure (RevenueCat, Apple, Google) supplies subscription status and purchase events, never card numbers.

2. How we use information, and our legal bases

Where the GDPR or UK GDPR applies, each use has a legal basis:

Camera, photo library, and notification access work only with permissions you grant through your operating system and can be revoked in device settings.

3. Data, purposes, and retention

CategoryPurposeLegal basisRetentionShared with
Guest/account ID; email and name (if linked)Account administration; keeping creations across devicesContractUntil account deletionSupabase (hosting); Apple/Google (sign-in)
Uploaded pet photosPortrait generation, retries, regenerationContractUntil account deletion (deleting one portrait keeps its source photo, which is shared across retries and regenerations)Supabase; our AI provider (US, per generation)
Prompts and scene choicesGeneration; moderation of custom textContract; legitimate interestsLife of the portraitSupabase; our AI provider (US)
Generated portraits and thumbnailsDisplay, saving, sharingContractUntil you delete the portrait or accountSupabase
Pet profilePersonalizationContractUntil account deletionSupabase
Feedback flagsQuality assurance, including human review (Section 4)Legitimate interestsUntil the flagged portrait or account is deletedSupabase
Subscription, credits, purchase ledgerPaid features; preventing double-grants; recordkeepingContract; legal obligationUntil account deletion (Apple, Google, and RevenueCat keep their own transaction records)RevenueCat, Apple, Google, Supabase
Device ID + perk ledger; hashed sign-in identityAnti-fraudLegitimate interestsKept after account deletion (Section 6)Supabase
Push tokenService notificationsContract (with OS permission)Until invalid or account deletionExpo (relay), Apple, Google
Usage analytics eventsService improvementLegitimate interests7 yearsPostHog (US)
Masked session replayService improvementLegitimate interests30 daysPostHog (US)
Crash reportsDebuggingLegitimate interests90 daysSentry (US)
Server logsSecurity, debuggingLegitimate interestsAbout 7 daysSupabase
Website analytics cookiesSite usage measurementLegitimate interests7 years (event data)PostHog (US)

4. Human review of flagged portraits

If you tap the feedback (thumbs-down) button on a portrait:

Using the feedback button is optional.

5. AI generation

To create a portrait, we send your uploaded photo and the scene prompt to our AI image-generation provider, a US-based service, which returns the generated image. Custom scene text is first checked by the provider's content-moderation service and rejected if it violates safety rules.

The provider's API terms state that content submitted through its API is not used to train its models. The provider may keep API content briefly for abuse monitoring under its own policies. We do not use your photos, prompts, or portraits to train AI models.

Generated portraits are stored privately and shown only to your account. Locked portraits carry a watermark until unlocked.

6. Retention and deletion

7. Cookies, tracking, and analytics choices

In the app: the app does not use cookies. It includes SDKs for analytics and session replay (PostHog) and crash reporting (Sentry), and uses on-device storage for your session, preferences, and the device ID described above. There are no advertising SDKs, no use of the advertising identifier (IDFA/AAID), and no tracking across other companies' apps or websites.

On the website: lilfriends.app uses cookies and similar technologies for PostHog analytics to measure site usage. They are not used for advertising, and no third party gets access to them for its own purposes. You can block or delete cookies in your browser settings. Because we do not sell personal information or share it for advertising, there is no "sale" or "sharing" to opt out of, and the site does not respond to Do Not Track or Global Privacy Control signals.

Opting out of analytics: email hello@lilfriends.app and we will exclude you from analytics and session replay going forward and delete the analytics data associated with you. We honor these requests regardless of where you live.

8. When we share information

We share personal information only with:

We do not sell personal information and do not share it for cross-context behavioral advertising.

9. International transfers

We are a US company. Our database and storage run on AWS in Oregon, and the providers above process data in the United States. If you use lil friends from the EU, UK, Switzerland, or elsewhere, your information is transferred to the US.

These providers maintain their own transfer safeguards: several are certified under the EU–US Data Privacy Framework (with UK and Swiss extensions), and their standard service terms incorporate the EU's Standard Contractual Clauses for customer data — for example, the cloud platform hosting our database applies its data-processing terms, including those clauses, to all customers. Contact hello@lilfriends.app for details.

10. Your rights

Depending on where you live, you may have the right to: access the personal information we hold about you and receive a copy in a portable format; correct inaccurate information; delete your information; object to or restrict certain processing (including analytics based on legitimate interests); withdraw consent where processing is based on consent; and complain to your local data protection authority (EU: edpb.europa.eu; UK: ico.org.uk).

Portrait deletion and account deletion are available directly in the app (Section 6). For other requests, email hello@lilfriends.app from the email linked to your account so we can verify you. We respond within the time your local law requires (one month under GDPR; 45 days under California law). We may decline requests we cannot verify or that the law permits us to decline — including for the anti-fraud records in Section 6 — and will explain why. You may act through an authorized agent where the law provides; we will verify the agent's authority. We do not discriminate against anyone for exercising privacy rights.

11. California residents (CCPA/CPRA)

In the last 12 months we collected these categories of personal information: identifiers (account ID, device ID, email if linked, IP address); commercial information (purchases, subscriptions, credits); internet or electronic network activity (app usage, masked session replays, website analytics); audio/visual information (uploaded photos, generated portraits); approximate geolocation (from IP); and inferences only to the extent of product analytics. Sources, purposes, and recipients are described in Sections 1–3 and 8.

We do not sell personal information or share it for cross-context behavioral advertising, and we have no actual knowledge of selling or sharing the personal information of anyone under 16. We do not use or disclose sensitive personal information beyond what is necessary to provide the service.

California residents have the rights to know/access, delete, correct, limit certain uses, non-discrimination, and use of an authorized agent, exercisable as described in Section 10. Because there is no sale or sharing, there is nothing to opt out of; per Section 7, the website does not respond to Do Not Track or GPC signals.

12. Other regions

This policy applies globally, and we honor the rights your local law provides — including Brazil's LGPD, Canada's PIPEDA, and Australia's Privacy Act — exercisable as described in Section 10.

13. Security

Photos and portraits are stored in private buckets readable only by your account, and portrait images are served through short-lived signed links. Custom prompts are moderated before generation. Access to production systems is limited to authorized people. No system is perfectly secure, and we cannot guarantee absolute security. If a breach affects you, we will notify you as the law requires.

14. Children

lil friends is not directed at children under 13, and we do not knowingly collect personal information from them. The app does not ask for your age. If you believe a child under 13 has used lil friends, contact hello@lilfriends.app and we will delete the associated information. Users under the age of majority should use lil friends only with a parent or guardian's consent.

15. Changes to this policy

We may update this policy. For material changes, we will give notice in the app or by other reasonable means before they take effect and update the date above. Where the law requires consent to a change, we will ask for it.

16. Contact

Lil Friends, LLC
7601 Cooper Ln, Bldg 23
Austin, TX 78745, USA
Email: hello@lilfriends.app
Website: https://lilfriends.app

We have not appointed a Data Protection Officer or an EU/UK representative. If that changes, we will list them here.