Light Technologies
Privacy Policy
Application: Playlight
Version: Phase 1 - MVP Release (Backend-aligned patch)
Effective Date: May 21, 2026
Last Updated: August 10, 2026
Entity: Light Technologies
Contact: hello@playlight.app
Plain English Summary
Playlight stores the account, device, security, and life-management information needed to operate the service. If you use AI features, we send the relevant message and selected account content to the configured AI provider to generate responses or insights. We may also process product-activity events, security telemetry, notification data, and service emails. We do not sell personal data or use it for third-party advertising. See the detailed sections below for vendors, retention, AI processing, analytics, and deletion.
The sections below provide the complete detail behind that summary. If anything is unclear, contact us at hello@playlight.app and we will explain it in plain terms.
1. Who We Are
Playlight is a life management and productivity application developed and operated by Light Technologies. This Privacy Policy applies to the Playlight mobile application and any associated website (together, the “Service”).
By creating an account and using the Service, you confirm that you have read and understood this policy. If you do not agree, please discontinue use immediately.
2. What Information We Collect and Why
We collect information needed to operate Playlight, secure accounts, deliver notifications and email, provide optional AI features, and improve the Service. We do not collect data for third-party advertising.
2.1 Account and Profile Data
Collected when you register or update your profile:
- Email address - account identity, login, and essential service messages.
- Full name, username, and phone number - profile and account personalisation (where you provide them).
- Date of birth - age eligibility and account records.
- Password and security flags - password is stored as a secure hash; we also store verification timestamps, MFA status, password-change time, login counters, lockout state, and account status.
- Sign-in provider records - if you use Google (or Apple when enabled), we store the provider identity, provider user ID, email/claims needed to link the account, and related linking metadata.
2.2 Authentication and Security Data
- Pending registration records (email, display name, password hash, OTP hashes, attempt/resend counts, registration device ID, platform, app version, and push token).
- Refresh sessions (hashed tokens, issue/expiry/revocation data, IP address, and user-agent).
- Password-reset tokens (token hash, expiry/use timestamps, requested IP, and user-agent).
- Login history and security events (email and optional user ID, IP address, user-agent, success/failure, event type/reason, and optional approximate location such as country, region, city, or coordinates when geo-IP enrichment is enabled).
2.3 Device and Notification Data
- Device ID, platform (iOS, Android, or web), and app version.
- Expo push token and notification-enabled state.
- Last-seen and device-revocation timestamps.
We use this data to deliver push notifications, keep sessions secure, and revoke lost or unused devices.
2.4 User-Created Life-Management Data
Content you voluntarily create in the app, which may include:
- Tasks, schedules, priorities, completion times, and task events.
- Work projects, statuses, subtasks, and work-activity metadata.
- Habits and habit-entry history.
- Wealth folders and transactions (amount, currency, merchant/source, payment method, references, notes, and dates).
- Time allocations, departments, planned hours, and notes.
- Arcs, yearly goals, status, and priority.
- Notes, titles, content, types, and source metadata.
- Problems, impacts, severity, and resolution dates.
Depending on what you enter, this content can reveal health, mental-health, financial, employment, relationship, identity, or other sensitive information. Do not enter information you are not comfortable storing in Playlight or that the Service cannot safely support.
2.5 AI Conversations, Memories, Insights, and Derived Data
If you use AI features, we may store and process:
- Chat sessions, titles, messages (user and assistant), status, and timestamps.
- Agent routing outputs, evidence, draft actions, metadata, errors, provider/model, and usage metadata.
- Rolling chat summaries and agent memories (value, category, confidence, expiry).
- Draft-action payloads, reasons, results, and confirmation preferences.
- Generated insight reports and your feedback on them.
- Content chunks and embeddings derived from your content for retrieval (when embedding is enabled).
- AI usage logs (provider, model, feature, status, token counts, estimated cost, and errors).
AI context builders may use your profile, tasks, notes, habits, arcs, time allocations, wealth data, prior insights, memories, and chat context to generate responses.
2.6 Product Analytics and Activity Events
When product analytics is enabled, we may collect activity events such as event name, schema version, timestamps, source/actor type (user, AI, system, or support), session ID, platform, app version, route, module, entity type/ID, and related properties. Events may be linked to your account and used for personal timelines and product improvement. Authorised administrators may review aggregated and user-level analytics.
Analytics collection is gated by a global product-analytics setting. Where a consent record is required, you can withdraw consent in Settings when that control is available. Contact hello@playlight.app if you need help withdrawing consent or deleting analytics events associated with your account.
2.7 Support and Communications Data
- Messages you send to hello@playlight.app (support, feedback, deletion requests).
- Transactional emails we send (OTP verification, welcome, password reset) and related delivery metadata.
2.8 Technical, Log, and Optional Geo-Location Data
- Request logs (method, URL, status, duration, request ID) and operational error logs.
- Crash and diagnostic information from the client where available.
- Approximate location derived from IP address when geo-IP enrichment is enabled (country, region, city, and optionally latitude/longitude).
3. How We Use Your Information
We use personal data for the following purposes:
- Provide the Service: create and maintain your account; store and display life-management content. Legal basis (GDPR): performance of a contract (Art. 6(1)(b)).
- Authenticate and secure accounts: login, session management, MFA, lockout protection, abuse prevention, and security event review. Legal basis: contract and legitimate interests (Art. 6(1)(b) and (f)).
- Email delivery: OTP, welcome, and password-reset messages. Legal basis: contract (Art. 6(1)(b)).
- Push notifications: deliver alerts you enable and manage device tokens. Legal basis: contract and, where required, consent (Art. 6(1)(b) or (a)).
- AI generation and insights: when you use AI features, process messages and selected account context with the configured provider to return answers, draft actions, memories, and insights. Legal basis: contract and, where required, consent (Art. 6(1)(b) or (a)).
- Embeddings and retrieval: create and store content chunks/embeddings to improve AI retrieval when that feature is enabled. Legal basis: contract / legitimate interests (Art. 6(1)(b) or (f)).
- Product analytics: understand feature usage, engagement, and reliability when analytics is enabled. Legal basis: consent and/or legitimate interests (Art. 6(1)(a) or (f)), depending on configuration and jurisdiction.
- Support and service improvement: respond to requests and diagnose issues. Legal basis: legitimate interests (Art. 6(1)(f)).
- Legal compliance: respond to lawful requests and enforce our terms. Legal basis: legal obligation and legitimate interests (Art. 6(1)(c) and (f)).
4. Who We Share Your Information With
We do not sell your personal data. We do not share it with advertisers or data brokers for commercial advertising. We use service providers (processors) to operate Playlight. Depending on which features are enabled in production, recipients may include:
- Database / hosting (Supabase on AWS): stores account and product data. See supabase.com/privacy.
- Resend: transactional email (address, message content, delivery metadata). See resend.com/legal/privacy-policy.
- Google (and Apple when enabled): identity-provider sign-in; provider ID, email/claims for account linking.
- Expo / push infrastructure: device and push-token delivery metadata for notifications.
- AI providers (as configured): Groq, OpenAI, Google Gemini, and/or DeepSeek may receive prompts, selected context, and return model outputs. OpenAI may also receive text for embeddings when embedding is enabled. Review each provider’s privacy and retention terms for the model in use.
- ipgeolocation.io: IP address for approximate location enrichment when geo-IP is enabled.
- Logging / monitoring platforms: request metadata, identifiers, and operational errors needed to run the Service.
We may also disclose information if required by law, court order, or a valid governmental request, or where we believe in good faith that disclosure is necessary to protect our rights or the safety of our users.
5. International Data Transfers
Light Technologies operates internationally. Your data may be processed by vendors whose infrastructure is located in the United States or other countries outside your own. Those countries may have data protection laws that differ from those in your jurisdiction.
Where required by applicable law - including the GDPR for users in the European Economic Area - we rely on appropriate safeguards such as data processing agreements and, where applicable, Standard Contractual Clauses (SCCs) approved by the European Commission.
6. Data Security and Retention
6.1 How We Protect Your Data
We implement the following security measures to protect your information:
- All data transmitted between your device and our servers is encrypted using TLS/HTTPS.
- Passwords and sensitive tokens are stored in securely hashed formats using industry-standard algorithms. Plain-text passwords are never stored or accessible.
- Database and admin access is restricted to authorised personnel using role-based access controls.
No method of electronic transmission or storage is 100% secure. While we take reasonable precautions, we cannot guarantee absolute security against all threats.
6.2 How Long We Keep Your Data
- Account and profile data: retained while your account is active. After a verified deletion request, the account is first marked deleted (devices revoked); permanent purge of user-owned records follows our deletion workflow.
- Product content: retained while your account is active. Soft-deleted accounts retain related records until purged or anonymised under our deletion process.
- AI chats, summaries, memories, insights, embeddings, and AI usage logs: retained while needed to provide AI features and for a limited period after deletion requests, subject to purge of user-owned AI records.
- Analytics events and consent records: retained while analytics is enabled and as needed for product analysis; subject to deletion or anonymisation after consent withdrawal or account deletion where required.
- Login / security events and geo-IP data: retained for security, abuse prevention, and audit purposes. Some security records may be retained longer than ordinary account content, including after soft deletion, where needed for security or legal reasons.
- Devices and refresh sessions: devices remain until revoked or deleted; refresh sessions are cleaned up according to configured retention (default about 30 days for expired, revoked, or consumed sessions).
- Password-reset and pending registration records: short-lived; password-reset tokens are cleaned up according to configured retention (default about 7 days).
- Technical / operational logs: retained for a limited operational period (typically up to 90 days unless a longer period is required for security investigation).
- Backups and vendor-held copies: encrypted backups and processor copies may persist for a limited period after deletion (typically up to about 30 additional days) before expiry, subject to vendor practices.
- Legal holds: we may retain specific data longer where required by applicable law or a valid legal order.
7. Your Rights and Choices
You own your data. Depending on your location, you have the following rights. We will respond to all verifiable requests within 30 days.
- Access: Request a copy of the personal data we hold about you.
- Correction: Request that we correct any inaccurate or incomplete information.
- Deletion: Request deletion of your account and associated data by emailing hello@playlight.app or using our Delete Account or Data page. We acknowledge requests within about 2 business days. Deletion currently begins as an account soft-delete (status marked deleted; devices revoked). We then process purge or anonymisation of user-owned records according to our deletion workflow. Security, audit, backup, and legally required records may be retained as described in Section 6.2.
- Data Portability: Request a structured, machine-readable copy of the data you have provided to us.
- Restriction: Request that we limit processing of your data under certain circumstances.
- Objection: Object to processing based on our legitimate interests.
- Withdraw Consent: Where processing is based on your consent (for example certain analytics or notification choices), withdraw it at any time without affecting the lawfulness of prior processing. Use in-app settings where available, or contact hello@playlight.app.
- Lodge a Complaint: If you are in the EEA or UK, you have the right to lodge a complaint with your local Data Protection Authority. We encourage you to contact us first so we can resolve your concern directly.
To exercise any of these rights, contact us at hello@playlight.app.
8. Cookies, Local Storage, and Tracking
Playlight does not use third-party advertising cookies or ad identifiers to track you across other apps or websites. The Service uses local storage needed to keep you signed in and remember preferences.
Separately, when product analytics is enabled, the app may send first-party activity events described in Section 2.6. That is product telemetry for operating and improving Playlight, not third-party advertising tracking.
9. Children’s Privacy
Playlight is not intended for anyone under the age of 13, or under 16 in the European Economic Area. We collect date of birth / age-eligibility information at registration to help enforce this rule. Users who do not meet eligibility requirements should not create an account.
We do not knowingly collect personal data from children below these thresholds. If we discover that such data has been inadvertently collected, we will delete it. If you believe a child has registered, please contact us at hello@playlight.app.
10. Advertising and AI Processing
Advertising: The app contains no advertisements and does not use third-party advertising SDKs or ad networks. We do not collect or share data for third-party advertising or marketing profiling.
AI processing: Playlight includes optional AI chat, memory, draft-action, insight, and retrieval features. When you use these features, relevant messages and selected account content are sent to the configured AI provider (which may include Groq, OpenAI, Google Gemini, and/or DeepSeek, depending on production configuration). Providers may process data outside your country. We do not sell AI conversation content for advertising.
- You can choose not to use AI features. Content you never send to AI chat is not included in chat prompts, though other AI jobs (such as insights or embeddings) may still use selected life-management data when those features are enabled for your account.
- Generated insights, memories, embeddings, and usage logs are stored as described in Section 2.5 and retained under Section 6.2.
- Provider model-training and retention practices are governed by each provider’s terms; we configure providers as processors where contracts allow and instruct them to use data only to provide the service.
Material changes to AI providers, analytics defaults, or deletion behaviour will be reflected in an updated Privacy Policy and, where appropriate, an in-app notice before they take effect.
11. Changes to This Policy
We may update this Privacy Policy as the Service evolves. When we make material changes, we will:
- Update the “Last Updated” date at the top of this document.
- Publish the revised policy at our designated public URL before the changes take effect.
- Send an in-app notification for any change that affects your rights or introduces new data practices.
Your continued use of the Service after notification constitutes acceptance of the updated policy. If you do not agree, you may request account deletion and discontinue use.
12. Contact Us
For any questions about this policy, to exercise your data rights, or to request account deletion, please contact us:
Entity: Light Technologies
Application: Playlight
Email: hello@playlight.app
Deletion requests: playlight.app/delete
Phase 1 (MVP) - Version 1.1 - Last updated August 10, 2026