Privacy Policy

Version 2.5.0 · effective August 26, 2026

Your privacy is important to us. This policy explains what data we collect and how we use it.

It covers the Lila mobile app and this website. Where the two differ, the difference is called out.

Lila is built to hold personal things — what you meant to do, what you care about, what you believe. That is the point of it, and it is also why this document is longer and plainer than most. Where a section describes something you have to switch on, it says so.

1. Who is responsible

Lila is operated by Furkan Efe Genç, a sole proprietorship registered in Türkiye, who is the data controller for the information described here.

Registered address: Ahlatlıbel Mahallesi, 1859. Cadde, No 44/32, Çankaya, Ankara, Türkiye.

You can reach us about anything in this policy (including access, correction and deletion requests) at hello@hellolila.app.

2. Data we collect

Almost everything below is data you give us by using Lila. We do not buy data about you, and we do not build a profile of you from other sites.

Some of these only exist if you turn on the feature that needs them. Nothing in this list is collected in the background without a switch you can see.

  • Account information. Your email address and name, and the identifier from Google or Apple if you sign in that way. Passwords are stored only as a hash.
  • Voice recordings you create, for as long as it takes to transcribe them.
  • Reminder content and schedules.
  • Chat conversations with Lila.
  • Memories and context Lila derives from your conversations. The things it remembers so it can be useful later.
  • Workspace content you create: notes, intentions, goals, habits and daily plans.
  • Beliefs and practices, if you choose to tell Lila about them, so it can respect them. See section 3 — this is sensitive data and it has its own rules.
  • Birth date, and birth time and place if you enter them for astrology features. Time and place of birth are precise enough to identify a person, so we treat them with the same care as section 3 data.
  • Photos, files and documents you add yourself, and what Lila reads out of them.
  • Places you ask Lila to remember. If you tell it to save your home or your office, that place’s coordinates are stored so the app can recognise when you arrive. Where you are at any moment stays on the phone — the comparison happens there, not here.
  • Device information needed for push notifications, including your notification token, plus a record of which notifications were delivered.
  • Subscription status. Payments are taken by Apple or Google; we never see your card details.
  • Diagnostics: crash reports and error traces, so we can fix what breaks.
  • Usage analytics, which are optional and can be turned off in the app.
  • Anything a mini-app you build collects. See section 7.

3. Sensitive data, and the consent it needs

Some information carries extra protection in law: beliefs, health, ethnicity, political opinion, trade union membership, biometrics, sex life and sexual orientation, and — under Turkish law — criminal convictions, appearance and dress, and association membership.

Lila asks for some of this on purpose, because an assistant that does not know you fast during Ramadan, or that schedules a reminder through your prayer time, is not respecting you. But that is our reason, not your obligation.

So the rule is: we do not collect any of it unless you have separately and explicitly agreed to that specific category. Not a general terms checkbox — a distinct yes, for that category, which you can withdraw at any time in Settings. Withdrawing stops future use and deletes what was stored under it.

Two honest caveats. First, if you mention something sensitive in an ordinary chat message, it is stored as part of that conversation, because we cannot detect it reliably enough to strip it out and pretending otherwise would be a false promise. Second, sensitive categories are never used to target advertising, are never sold, and are never shared with anyone outside the providers in section 12.

Every read of data in these categories is written to an internal access log — which category and which record, never the content — so that an audit can show what was looked at and when.

4. How we use your data

Each purpose below is a thing the product actually does. We do not use your content for advertising, and we do not sell it.

  • To provide the reminder service and deliver notifications at the right time.
  • To transcribe voice recordings and extract what you asked for.
  • To assemble your briefings and give Lila the context that makes its answers useful.
  • To respect what you have told us about your beliefs and practices, where you have consented to that under section 3.
  • To run your account and your subscription.
  • To keep the service secure. Rate limiting and abuse prevention.
  • To diagnose crashes and errors.
  • To answer you when you contact support.
  • To see what tends to help people generally, Lila counts whether a kind of Moment was acted on, dismissed, or let pass — grouped by time of day and language, and only where at least fifty people are in the same group. Message text is not used, and the counts hold nothing that identifies you. You can stop contributing in Settings → Privacy & Data; future counts then do not read you, and counts already published hold no identifier of you, so there is nothing in them to remove.

5. AI processing

Lila does not train any AI model of its own. There is no model anywhere in this product that has learned from your data.

We send your text and audio to AI providers to get an answer back. Today those are Groq, which runs the language model behind chat and transcribes your voice, and OpenAI, which is the fallback for both and also produces the numerical representations that let Lila search your own memories. Both are contractually bound not to train on what we send them.

By default, Lila only routes your data to providers that do not train on it. That is not a promise made in prose — it is the default in the code, it removes every training provider from the chain rather than only the first one, and turning it off is a deliberate choice you make in Settings under Enhanced privacy. One provider we have configured, Google Gemini, does train on free-tier data, which is exactly why the default keeps it out of the chain.

When a request needs current information from the web, the search terms derived from your request are sent to our search provider. Your conversation itself is not.

AI output can be wrong. Lila is a tool for organising your life, not a source of professional, medical, legal or religious advice.

6. Voice and emotion

If you turn on the emotion feature, Lila estimates a mood, an energy level and a speaking rate from the sound of your voice — not only from your words — so it can adjust its tone.

We are telling you this plainly because it is the kind of thing you should be told plainly. Inferring emotion from a voice is inference from biometric data, and under the EU AI Act a system that does it has to say so to the person using it. That obligation applied from 2 August 2026.

What this is not: it is not a diagnosis, it is not a measure of your mental health, it is never used to decide what you are shown or charged, and it is never shared with anyone. The estimate is approximate and is often simply wrong.

You can turn it off, and off means the audio is transcribed and nothing about your tone of voice is derived from it.

7. Apps you build inside Lila

Lila lets you build small apps of your own inside it. That is a genuinely open-ended capability, and we would rather explain how we keep it honest than publish a list of categories that your first app makes out of date.

Before a mini-app can run, it declares which kinds of data it needs, drawn from the same fixed registry of categories this policy uses. You see that declaration and you approve it. An app cannot read a category it did not declare.

If a mini-app asks for a category from section 3, it needs the separate explicit consent described there — building it yourself does not bypass that gate.

Mini-apps you build run for you. We do not use their contents for anything else, and nothing about them is shared with other users unless you deliberately publish it.

8. Accounts you connect

Some data reaches Lila only because you deliberately connect a source. Nothing in this section happens unless you complete that connection, and you can disconnect at any time.

  • Google Calendar. If you connect it, we cache your upcoming events so briefings can prepare you for them and reminders can avoid clashing with them. The cache is kept for 30 days.
  • Gmail. If you connect it, we cache the messages Lila needs to triage for 7 days.
  • Sources you add yourself, such as a web page to monitor. We fetch and store their content, not anything about you.
  • Every access to your Google data is logged for 90 days so you and we can audit it.

9. What Lila does not do today

It matters as much what is switched off as what is on. As of the effective date of this policy:

  • Lila does not read your calendar to work out whether you are busy and should not be interrupted. That capability exists in the code and is deliberately disabled.
  • Lila does not listen for a wake word and does not listen in the background. Recording starts when you start it.
  • Lila does not send unprompted proactive notifications. The engine that would decide when to speak up runs without delivering anything to you.
  • Lila does not track your location continuously. Nothing runs in the background reporting where you are, and your position is never streamed to us.
  • Lila does not act on your Gmail on your behalf.
  • Lila does not use your data to train any AI model, ours or anyone else’s.
  • We do not sell your data, and we do not use it for advertising.

10. How long we keep it

Data with a fixed lifetime is deleted automatically when it expires. You do not have to ask.

DataKept for
Voice recordings (the audio itself)Deleted as soon as transcription finishes
Reminders, notes, goals, memoriesUntil you delete them, or delete your account
Beliefs and other sensitive dataUntil you withdraw consent, or delete your account
Birth date, time and placeUntil you remove them, or delete your account
Emotion estimatesNot stored beyond the conversation they were made in
Mini-apps you build, and their dataUntil you delete the app, or delete your account
Chat conversations30 days on Free and Pro
Briefing records30 days
Notification delivery records30 days
Cached calendar events30 days
Cached email7 days
Log of access to your Google data90 days
Log of access to sensitive data90 days
Log of actions Lila performed for you90 days
Workspace change history, used for undo90 days
Anti-abuse device records12 months

11. Where your data is stored

Lila’s servers, database and cache all run on Railway in the United States, in the region Railway calls us-west2. If you are in Türkiye, the EU or the UK, your data leaves your country when you use Lila. We would rather say that in one sentence than bury it.

Most of the providers in section 12 are also in the United States. PostHog, which handles the optional usage analytics, is on its European infrastructure. Apple and Google operate globally.

We are working through the formal transfer paperwork each jurisdiction requires — the standard contracts Turkish law asks for, and the clauses EU and UK law ask for. Where that work is not finished we say so here rather than implying otherwise; this section is updated as each one is completed, and the version stamp at the top of this page changes with it.

12. Who processes data with us

We do not sell your data. We share it only with the providers that run the service, when the law requires it, or with your consent. These are the providers Lila uses today.

This table is generated from the service’s own configuration, and a test fails if the two disagree — so it cannot quietly go out of date the way such tables usually do.

ProviderWhat it doesWhat it can see
RailwayRuns the Lila server, the AI service, the database and the cacheEverything stored in or passing through the service
CloudflareHosts this websiteRequests to the website
GroqRuns the language model behind chat, and transcribes voiceAudio you record and text sent for processing
OpenAILanguage model fallback, embeddings, and transcription fallbackAudio you record and text sent for processing
TavilyWeb search, when a request needs itSearch terms derived from your request
Open-MeteoWeather forecasts, when you ask for oneA position rounded to roughly a kilometre, and nothing else about you
ExpoDelivers push notificationsNotification text and your device token
OneSignalPush notification delivery and schedulingNotification text, your device token, and delivery outcome
Apple (APNs)Carries notifications to iPhonesNotification payload and device token
Google (FCM)Carries notifications to Android phonesNotification payload and device token
ResendSends transactional emailYour email address and the message
RevenueCatTracks subscription statusA pseudonymous app user id and purchase state
AppleSign in with Apple, and App Store billingThe identifier Apple issues for your account
GoogleSign-in, and Calendar or Gmail only if you connect themWhatever the connection you granted covers
SentryCrash and error diagnosticsTechnical error data
PostHogProduct analytics on European infrastructure, which you can turn offEvents about how the app is used, never your content

13. Your rights

You have the right to access your data, correct it, export it, delete it, and object to processing. Turkish law adds the rights set out in KVKK (Law No. 6698); EU and UK law add the rights set out in the GDPR. We apply all of them to everyone.

Most of this you can do yourself, immediately, without asking us:

  • Access and export. Settings → Privacy & Data → Download my data. You get a file containing your memories, reminders, preferences and conversations.
  • Correct or delete a memory. Settings → Memory. Open a memory to edit it, or choose to forget it.
  • Withdraw consent for a sensitive category. Settings → Privacy & Data. Withdrawal takes effect immediately and deletes what was held under it.
  • Opt out of analytics. From the Settings screen, or ask us to do it.
  • Delete everything. See section 14.
  • If you would rather we did it, email hello@hellolila.app from the address on your account.
  • If you think we have got this wrong, you can complain to your data protection authority: the Kişisel Verileri Koruma Kurumu in Türkiye, your national authority in the EU, or the ICO in the UK.

14. Deleting your account

You can permanently delete your Lila account and all associated data in one of two ways:

  • In the app: Settings → Account → Delete Account. This performs a full deletion of your account and all linked data.
  • No access to the app? Email hello@hellolila.app from the address registered to your account. We will delete your account and data within 30 days.
  • What gets deleted: your account, reminders, chat conversations, memory and context data, workspace content, mini-apps you built, sensitive data held under section 3, cached calendar and email, notification history, and the link to your subscription.
  • Cancelling the subscription itself is done separately through Apple or Google.

15. Age

You must be at least 18 years old to use Lila. It is not intended for children, and we do not knowingly collect data from anyone under 18.

The floor is 18 everywhere, with no country-by-country variation. That is deliberately stricter than the law requires in most places. Lila asks about beliefs, birth data and tone of voice, and it lets you build things that collect more — none of which we want to be defending a thirteen-year-old’s consent to.

If you believe someone under 18 has given us personal data, email hello@hellolila.app and we will delete it.

16. This website

This website sets no cookies and stores nothing on your device. There is no cross-site tracking, no advertising network and no fingerprinting.

We do count anonymous events (a page being viewed, a button being pressed) so we can tell whether what we wrote is understood. Those events carry the page, the language you are reading in, and where the link came from. They do not carry your name, your email address, an identifier that survives the page, or anything you type.

If you join the early-access list, we keep the address you gave us and the language you were reading in, so that we write to you in it. If you tell us in your own words what you would use Lila for, or give us a name to call you by, we keep those as well — both are optional and the list works without them. Where a link tells us which campaign or which site brought you here, we keep that too. If you later create an account with the same address, what you told us here is carried into it, so that Lila can pick the thread up instead of asking you again; you can delete it from inside the app. Every message we send carries a link that removes you, and that link deletes the record and everything you wrote with it, rather than marking it inactive.

If you ask Lila something in the chat on this site, that question — and the last few messages of the same conversation — are sent to a language model running on Cloudflare’s network, so that it can answer in the language you are reading. The model is given passages from this website and nothing about you. We write none of it down: no log, no database entry, no analytics event. The exchange lives in the page and is gone when you close it.

17. Changes to this policy

When this policy changes, the version number and effective date at the top of this page change with it. Material changes are announced in the app before they take effect.

If a change widens what we collect or what we do with it, we ask again rather than assuming your previous agreement carries over.

18. Contact

For privacy questions or data requests: hello@hellolila.app

For anything else: hello@hellolila.app