Light Technologies
Privacy Policy
Application: Playlight
Version: App Store submission edition
Effective Date: September 5, 2026
Last Updated: September 5, 2026
Operator: Light Technologies
Contact: hello@playlight.app
Plain English Summary
Your data is private. We never sell personal data, rent it, give it to data brokers, or use it for third-party advertising. Playlight stores only the account, device, security, and manually entered life-management information needed to provide the Service. Optional AI suggestions use OpenAI or DeepSeek only after you choose to use the feature and give permission for the described data transfer. The detailed sections below explain every category, provider, purpose, retention period, and deletion choice.
The sections below provide the complete detail behind that summary. If anything is unclear, contact us at hello@playlight.app and we will explain it in plain terms.
1. Who We Are
Playlight is a life-management and productivity application operated under the name Light Technologies from Islamabad, Pakistan. This Privacy Policy applies to the Playlight mobile application and associated website (together, the “Service”).
By creating an account and using the Service, you confirm that you have read and understood this policy. If you do not agree, please discontinue use immediately.
2. What Information We Collect and Why
We collect information needed to operate Playlight, secure accounts, deliver notifications and email, provide optional AI features, and improve the Service. We do not collect data for third-party advertising.
2.1 Account and Profile Data
Collected when you register or update your profile:
- Email address - account identity, login, and essential service messages.
- Full name, username, and phone number - profile and account personalisation (where you provide them).
- Date of birth - age eligibility and account records.
- Password and security flags - password is stored as a secure hash; we also store verification timestamps, MFA status, password-change time, login counters, lockout state, and account status.
- Sign-in provider records - if you use Google or Sign in with Apple, we store the provider identity, provider user ID, email/claims needed to link the account, and related linking metadata. Email and password authentication is also available.
2.2 Authentication and Security Data
- Pending registration records (email, display name, password hash, OTP hashes, attempt/resend counts, registration device ID, platform, app version, and push token).
- Refresh sessions (hashed tokens, issue/expiry/revocation data, IP address, and user-agent).
- Password-reset tokens (token hash, expiry/use timestamps, requested IP, and user-agent).
- Login history and security events (email and optional user ID, IP address, user-agent, success/failure, event type/reason, and optional approximate location such as country, region, city, or coordinates when geo-IP enrichment is enabled).
2.3 Device and Notification Data
- Device ID, platform (iOS, Android, or web), and app version.
- Expo push token and notification-enabled state.
- Last-seen and device-revocation timestamps.
We use this data to deliver push notifications, keep sessions secure, and revoke lost or unused devices.
2.4 User-Created Life-Management Data
Content you voluntarily create in the app, which may include:
- Tasks, schedules, priorities, completion times, and task events.
- Work projects, statuses, subtasks, and work-activity metadata.
- Habits and habit-entry history.
- Wealth folders and transactions (amount, currency, merchant/source, payment method, references, notes, and dates).
- Time allocations, departments, planned hours, and notes.
- Arcs, yearly goals, status, and priority.
- Notes, titles, content, types, and source metadata.
- Problems, impacts, severity, and resolution dates.
Depending on what you enter, this content can reveal health, mental-health, financial, employment, relationship, identity, or other sensitive information. Do not enter information you are not comfortable storing in Playlight or that the Service cannot safely support.
2.5 AI Conversations, Memories, Insights, and Derived Data
If you use AI features, we may store and process:
- Chat sessions, titles, messages (user and assistant), status, and timestamps.
- Agent routing outputs, evidence, draft actions, metadata, errors, provider/model, and usage metadata.
- Rolling chat summaries and agent memories (value, category, confidence, expiry).
- Draft-action payloads, reasons, results, and confirmation preferences.
- Generated insight reports and your feedback on them.
- Content chunks and embeddings derived from your content for retrieval (when embedding is enabled).
- AI usage logs (provider, model, feature, status, token counts, estimated cost, and errors).
AI context builders may use your profile, tasks, notes, habits, arcs, time allocations, wealth data, prior insights, memories, and chat context to generate responses.
2.6 Product Operation and Diagnostics
The current app does not use third-party analytics or crash-reporting SDKs. Our servers process limited first-party operational information—such as request time, route, status, app version, and error details—to deliver, secure, and troubleshoot the Service. We do not use this information for advertising or cross-app tracking.
2.7 Support and Communications Data
- Messages you send to hello@playlight.app (support, feedback, deletion requests).
- If you join the website waitlist, your email address, submission source, time, and limited request/security log information. We use it only to send the promised launch notice and operate the form. We delete the waitlist record within 30 days after that notice is sent, or earlier if you ask us to.
- Transactional emails we send (OTP verification, welcome, password reset) and related delivery metadata.
2.8 Technical, Log, and Optional Geo-Location Data
- Request logs (method, URL, status, duration, request ID) and operational error logs.
- Approximate location derived from IP address through geo-IP enrichment (country, region, city, and approximate coordinates). We do not request GPS-level precise location for this purpose.
3. How We Use Your Information
We use personal data for the following purposes:
- Provide the Service: create and maintain your account; store and display life-management content. Legal basis (GDPR): performance of a contract (Art. 6(1)(b)).
- Authenticate and secure accounts: login, session management, MFA, lockout protection, abuse prevention, and security event review. Legal basis: contract and legitimate interests (Art. 6(1)(b) and (f)).
- Email delivery: OTP, welcome, and password-reset messages. Legal basis: contract (Art. 6(1)(b)).
- Push notifications: deliver alerts you enable and manage device tokens. Legal basis: contract and, where required, consent (Art. 6(1)(b) or (a)).
- AI suggestions and insights: when you choose an AI feature and give permission, process the message and selected account context with OpenAI or DeepSeek to return suggestions, draft actions, memories, and insights. Legal basis: consent and performance of the Service you requested (Art. 6(1)(a) and (b)).
- Embeddings and retrieval: create and store content chunks/embeddings to improve AI retrieval when that feature is enabled. Legal basis: contract / legitimate interests (Art. 6(1)(b) or (f)).
- Operational reliability: maintain security, diagnose errors, and keep the Service working without third-party analytics or advertising SDKs. Legal basis: contract and legitimate interests (Art. 6(1)(b) and (f)).
- Support and service improvement: respond to requests and diagnose issues. Legal basis: legitimate interests (Art. 6(1)(f)).
- Legal compliance: respond to lawful requests and enforce our terms. Legal basis: legal obligation and legitimate interests (Art. 6(1)(c) and (f)).
4. Who We Share Your Information With
We do not sell your personal data. We do not share it with advertisers or data brokers for commercial advertising. We use service providers (processors) to operate Playlight. The production Service uses the following providers:
- Database infrastructure (Supabase on AWS): stores account and product data. See supabase.com/privacy.
- Vercel: website hosting and related request delivery and security logs.
- Resend: transactional and waitlist email delivery (address, message content, and delivery metadata).
- Google and Apple: identity-provider sign-in; provider ID, email/claims for account linking.
- Expo / push infrastructure: device and push-token delivery metadata for notifications.
- OpenAI and DeepSeek: receive the prompt and selected context required for an AI feature after your permission, and return model output. OpenAI may also process text used to create retrieval embeddings.
- ipgeolocation.io: IP address for approximate location enrichment used for account security.
- Google Fonts: serves website font files and receives ordinary web-request information such as IP address and user-agent.
We may also disclose information if required by law, court order, or a valid governmental request, or where we believe in good faith that disclosure is necessary to protect our rights or the safety of our users.
We require every provider that processes personal data for us to protect it to the same or an equivalent standard promised in this Policy and required by applicable law and Apple's App Review Guidelines. Providers may process data only to deliver their contracted service, unless law requires otherwise.
5. International Data Transfers
Light Technologies operates internationally. Your data may be processed by vendors whose infrastructure is located in the United States or other countries outside your own. Those countries may have data protection laws that differ from those in your jurisdiction.
Where required by applicable law - including the GDPR for users in the European Economic Area - we rely on appropriate safeguards such as data processing agreements and, where applicable, Standard Contractual Clauses (SCCs) approved by the European Commission.
6. Data Security and Retention
6.1 How We Protect Your Data
We implement the following security measures to protect your information:
- All data transmitted between your device and our servers is encrypted using TLS/HTTPS.
- Passwords and sensitive tokens are stored in securely hashed formats using industry-standard algorithms. Plain-text passwords are never stored or accessible.
- Database and admin access is restricted to authorised personnel using role-based access controls.
No method of electronic transmission or storage is 100% secure. While we take reasonable precautions, we cannot guarantee absolute security against all threats.
6.2 How Long We Keep Your Data
- Account and profile data: retained while your account is active. After a verified deletion request, active devices and sessions are revoked and user-owned account records are permanently deleted or anonymised within 30 days.
- Product content: retained while your account is active, then deleted or anonymised within 30 days of a verified account-deletion request.
- AI chats, summaries, memories, insights, embeddings, and AI usage logs: retained while needed to provide the AI features you use, then deleted or anonymised with other user-owned records within 30 days of a verified account-deletion request.
- Consent records: retained while needed to record and respect your choices and for a limited audit period after withdrawal or account deletion where required by law.
- Login / security events and geo-IP data: ordinarily retained for up to 90 days. A narrowly limited record may be retained longer when reasonably necessary for an active security investigation, fraud prevention, or a legal obligation.
- Devices and refresh sessions: devices remain until revoked or deleted; refresh sessions are cleaned up according to configured retention (default about 30 days for expired, revoked, or consumed sessions).
- Password-reset and pending registration records: short-lived; password-reset tokens are cleaned up according to configured retention (default about 7 days).
- Technical / operational logs: retained for a limited operational period (typically up to 90 days unless a longer period is required for security investigation).
- Backups and vendor-held copies: encrypted backups and processor copies may persist for up to 30 additional days after the account-data purge before automatic expiry. They are isolated from ordinary use and are not restored except for disaster recovery or security purposes.
- Legal holds: we may retain specific data longer where required by applicable law or a valid legal order.
7. Your Rights and Choices
Your personal data remains yours. Depending on your location, you have the following rights. We respond to verifiable requests within 30 days.
- Access: Request a copy of the personal data we hold about you.
- Correction: Request that we correct any inaccurate or incomplete information.
- Deletion: Request deletion of your account and associated data by emailing hello@playlight.app or using our Delete Account or Data page. The fastest route is Settings → Account → Delete Account in the app. We acknowledge website requests within about 2 business days, verify account ownership, revoke active sessions, and permanently delete or anonymise user-owned records within 30 days. We email you when processing is complete. Security, audit, backup, and legally required records may be retained only as described in Section 6.2.
- Data Portability: Request a structured, machine-readable copy of the data you have provided to us.
- Restriction: Request that we limit processing of your data under certain circumstances.
- Objection: Object to processing based on our legitimate interests.
- Withdraw Consent: Where processing is based on your consent (for example AI processing or notification choices), withdraw it at any time without affecting the lawfulness of prior processing. Use the relevant in-app setting or contact hello@playlight.app. Declining AI permission prevents the related content from being sent to an AI provider.
- Lodge a Complaint: If you are in the EEA or UK, you have the right to lodge a complaint with your local Data Protection Authority. We encourage you to contact us first so we can resolve your concern directly.
To exercise any of these rights, contact us at hello@playlight.app.
8. Cookies, Local Storage, and Tracking
Playlight does not use third-party advertising cookies or ad identifiers to track you across other apps or websites. The Service uses local storage needed to keep you signed in and remember preferences.
The current app does not include third-party advertising, analytics, or crash-reporting SDKs. Limited first-party operational logs described in Section 2.6 are used only to deliver, secure, and troubleshoot Playlight—not to track you across apps or websites.
9. Children’s Privacy
Playlight is not intended for anyone under the age of 13, or under 16 in the European Economic Area. We collect date of birth / age-eligibility information at registration to help enforce this rule. Users who do not meet eligibility requirements should not create an account.
We do not knowingly collect personal data from children below these thresholds. If we discover that such data has been inadvertently collected, we will delete it. If you believe a child has registered, please contact us at hello@playlight.app.
10. Advertising and AI Processing
Advertising: The app contains no advertisements and does not use third-party advertising SDKs or ad networks. We do not collect or share data for third-party advertising or marketing profiling.
AI processing: Playlight includes optional AI chat, memory, draft-action, insight, and retrieval features. Before the first transfer, the app explains what will be sent and asks for your explicit permission. When you choose a feature, the relevant message and selected account content are sent to OpenAI or DeepSeek to produce a suggestion. Providers may process data outside your country. We never sell AI conversation content or use it for advertising.
- AI features are optional. Playlight does not send manually entered content to OpenAI or DeepSeek unless you have permitted AI processing and invoked or enabled the related AI feature. You can withdraw that permission through the relevant app setting.
- Generated insights, memories, embeddings, and usage logs are stored as described in Section 2.5 and retained under Section 6.2.
- We configure OpenAI and DeepSeek as service processors and instruct them to process submitted data only to provide the requested feature. Their handling is also governed by the contractual and privacy terms applicable to the production service.
Material changes to AI providers, data collection, or deletion behaviour will be reflected in an updated Privacy Policy and, where appropriate, an in-app notice before they take effect.
11. Changes to This Policy
We may update this Privacy Policy as the Service evolves. When we make material changes, we will:
- Update the “Last Updated” date at the top of this document.
- Publish the revised policy at our designated public URL before the changes take effect.
- Send an in-app notification for any change that affects your rights or introduces new data practices.
Your continued use of the Service after notification constitutes acceptance of the updated policy. If you do not agree, you may request account deletion and discontinue use.
12. Contact Us
For any questions about this policy, to exercise your data rights, or to request account deletion, please contact us:
Operator: Light Technologies
Application: Playlight
Email: hello@playlight.app
Telephone: +92 336 519 2688
Address: Ardium, Hub Commercial Plaza #97, Phase 8, Bahria Town, Islamabad, Pakistan
Deletion requests: playlight.app/delete
App Store submission edition - Version 2.0 - Last updated September 5, 2026