Privacy Policy
Last Updated: July 24, 2026
Quick Summary: We collect minimal data to provide meditation services. Your meditation content is private. We use OpenAI for AI features and Firebase for authentication. We don't sell your data.
1. Information We Collect
1.1 Account Information
When you create an account, we collect:
- Email address - For authentication and communication
- Display name - Optional, for personalization
- Password - Encrypted and stored securely via Firebase Authentication
- Authentication provider data - If you sign in with Google or Apple
1.2 Meditation Data
To provide personalized meditation experiences, we collect:
- Meditation preferences - Voice selection, pacing, music choices
- Meditation scripts - Generated content for your sessions
- Usage statistics - Number of meditations completed, session duration
- Mood tracking data - Self-reported emotional state (optional)
- Audio files - Generated meditation audio (stored temporarily)
1.3 Conversation Data
When using AI conversation features:
- Voice recordings - Processed in real-time and not permanently stored
- Conversation transcripts - Used to generate personalized meditations
- Emotional context - Detected from conversations to personalize content
Note: Voice conversations are processed via OpenAI's Realtime API. See section 4 for third-party data sharing.
1.4 Technical Information
We automatically collect:
- Device information - Browser type, operating system, device model
- Usage data - Pages viewed, features used, time spent
- IP address - For security and geographic analysis
- Cookies - For session management and preferences (see Cookie Policy)
- Error logs - Via Sentry for debugging (includes user context)
1.5 Payment Information
For paid subscriptions:
- Billing information - Processed securely by LemonSqueezy (not stored by us)
- Transaction history - Subscription status, payment dates
- Refund requests - For customer support
2. How We Use Your Information
2.1 Service Delivery
- Generate personalized meditation scripts and audio
- Provide AI-powered conversation features
- Sync your preferences across devices
- Track your meditation progress and streaks
2.2 Service Improvement
- Analyze usage patterns to improve features
- Debug technical issues via error tracking (Sentry)
- Train machine learning models to improve meditation quality
- A/B test new features (anonymized data)
2.3 Communication
- Send account-related emails (verification, password reset)
- Notify you of service updates or changes
- Send marketing emails (you can opt-out anytime)
- Respond to support requests
2.4 Legal Compliance
- Comply with legal obligations
- Protect against fraud and abuse
- Enforce our Terms of Service
3. Data Storage and Security
3.1 Where Your Data is Stored
- Firebase (Google Cloud) - User authentication, profiles, meditation history
- AWS S3 (US-West-2) - Audio files, meditation scripts
- ElastiCache Redis - Temporary session data (ephemeral)
- OpenAI - Processed temporarily for AI features (see section 4)
3.2 Security Measures
- End-to-end encryption for data in transit (HTTPS/TLS)
- Encrypted storage for sensitive data at rest
- Secure authentication via Firebase (industry standard)
- Regular security audits and updates
- Access controls and monitoring
- Automated backups (Firebase, AWS)
3.3 Data Retention
- Account data - Retained while your account is active
- Meditation sessions - Stored indefinitely for your history
- Audio files - Deleted after 30 days (or sooner if deleted manually)
- Temporary data - Deleted after 24 hours (Redis cache)
- Error logs - Retained for 90 days (Sentry)
- Deleted accounts - Permanently removed within 30 days
4. Third-Party Data Sharing
We share data with the following third parties to provide our services:
4.1 OpenAI
Purpose: Generate meditation scripts, process voice conversations, text-to-speech
Data Shared: Conversation transcripts, emotional context, meditation preferences
Privacy: OpenAI does not use your data to train their models. Data is processed in real-time and not stored permanently by OpenAI.
Policy: Openai.com/privacy
4.2 Firebase (Google)
Purpose: Authentication, database, analytics
Data Shared: Email, password (hashed), profile data, usage analytics
Policy: Firebase Privacy Policy
4.3 Amazon Web Services (AWS)
Purpose: Audio file storage, content delivery, backend infrastructure
Data Shared: Audio files, meditation scripts, technical logs
Policy: AWS Privacy Policy
4.4 LemonSqueezy
Purpose: Payment processing, subscription management
Data Shared: Email, billing information, subscription status
Policy: LemonSqueezy Privacy Policy
4.5 Sentry
Purpose: Error tracking and debugging
Data Shared: Error logs, user context (email, ID), browser information
Policy: Sentry Privacy Policy
We do NOT sell or rent your personal data. Your meditation content,
conversations, and health data are never shared with advertisers. On our public website
only, and only with your consent, we use advertising cookies to measure our own marketing
(see Section 6.3).
5. Your Privacy Rights
5.1 Access and Portability
- View all data associated with your account
- Download your meditation history and preferences
- Export data in machine-readable format (JSON)
5.2 Correction and Deletion
- Update your profile information anytime
- Delete individual meditation sessions
- Delete your entire account (Settings → Account → Delete Account)
5.3 Opt-Out Rights
- Unsubscribe from marketing emails (link in every email)
- Disable analytics tracking (Settings → Privacy)
- Opt-out of data used for ML training (contact support)
5.4 GDPR Rights (EU Users)
If you're in the EU, you have additional rights:
- Right to be forgotten (complete data deletion)
- Right to data portability
- Right to restrict processing
- Right to object to processing
- Right to lodge a complaint with supervisory authority
5.5 CCPA Rights (California Users)
California residents have the right to:
- Know what personal information is collected
- Know if personal information is sold or disclosed
- Say no to the sale of personal information
- Access personal information
- Request deletion of personal information
- Not be discriminated against for exercising rights
Note: We do NOT sell personal information.
6. Cookies and Tracking
6.1 Essential Cookies
- Authentication tokens - Keep you logged in
- Session cookies - Remember your preferences during a session
- CSRF tokens - Protect against cross-site attacks
6.2 Analytics Cookies
- Firebase Analytics - Track usage patterns (anonymized)
- Sentry - Error tracking and performance monitoring
6.3 Advertising Cookies (website only, with consent)
On our public website (lullme.app) — including shared-meditation pages — we ask for
your consent before setting any advertising cookies. If you accept, we use the
Meta Pixel to measure how people discover Lull and to reach similar
audiences with our ads. Events shared are limited to page activity (a shared meditation
was opened, played, or finished, and whether the App Store link was tapped) — never the
content of any meditation, and never anything from inside the app. If you decline, no
advertising cookies are set. See the
Meta Privacy Policy.
6.4 Managing Cookies
You can control cookies via:
- Browser settings (block all cookies)
- Our cookie consent banner (customize preferences)
- Settings → Privacy → Manage Cookies
Note: Disabling essential cookies may break core functionality.
7. Children's Privacy
Lull is intended for users 18 years and older. We do not knowingly collect data from children under 18. If we discover we have collected data from a child, we will delete it immediately.
If you believe a child has provided us data, contact us at: [email protected]
8. International Data Transfers
Lull is based in the United States. If you access our service from outside the US, your data may be transferred to and processed in the US, where privacy laws may differ from your country.
EU-US Data Transfers: We use Standard Contractual Clauses (SCCs) and services that comply with GDPR requirements (Firebase, AWS).
9. Changes to This Policy
We may update this Privacy Policy periodically. Changes will be effective immediately upon posting. We'll notify you of material changes via:
- Email notification to your registered address
- In-app banner when you next log in
- Updated "Last Modified" date at the top
Continued use of Lull after changes constitutes acceptance of the updated policy.
10. Contact Us
11. Additional Information
11.1 Do Not Track (DNT)
We respect browser "Do Not Track" signals. When DNT is enabled, we will not track your activity for analytics purposes (authentication cookies remain active).
11.2 Data Breach Notification
In the unlikely event of a data breach, we will:
- Notify affected users within 72 hours
- Provide details of what data was compromised
- Explain steps we're taking to address the breach
- Offer guidance on protecting your account
11.3 Third-Party Links
Our service may contain links to third-party websites. We are not responsible for the privacy practices of those sites. Please review their privacy policies.
11.4 California Shine the Light Law
California residents can request information about data shared with third parties for direct marketing purposes. We do not share data for marketing purposes.
© 2026 Lull. All rights reserved.
Terms of Service | Privacy Policy