Privacy Policy
Lull is a nightly wind-down journal. It has no accounts, no login, and no server of ours. This policy explains in plain language what stays on your phone and what doesn’t.
The short version
- Nothing you write is ever sent to us. Not the text, not a preview, not a hash. We cannot read your journal.
- There is no account. We never ask for your name, email, or phone number.
- We do record how the app is used — which screens you reach, whether you finish the ritual — under a random identifier that isn’t linked to who you are.
- Payments are handled entirely by Apple. We never see your card details.
What stays on your device
Everything you write in Lull — your reflections, your intentions for tomorrow — along with your bedtime, your reminder preferences, and your streak, is stored on your iPhone.
Your nightly reminders are scheduled locally by iOS on your device. They are not push notifications, so nothing about your bedtime is sent over the internet in order to remind you.
iCloud sync (Lull Pro)
If you subscribe to Lull Pro, your journal syncs across your devices using Apple’s CloudKit. Your entries are stored in your own private iCloud database, tied to your Apple Account. This is not our database and we have no access to it — Apple does not give developers the ability to read a user’s private CloudKit data. That sync is governed by Apple’s Privacy Policy.
On the free tier, Lull does not sync at all. Your journal stays on that one device.
The identifier we use
Because Lull has no login, we have no idea who you are — but we still need some way to tell one install apart from another, or we couldn’t answer basic questions like “do people who finish the ritual come back the next night?”
So the app generates a random identifier when you first launch it. It is not your name, your email, your Apple Account, or your device’s advertising ID. It exists only inside Lull, and it is the same identifier our subscription provider uses, so that we can tell whether a subscriber behaves differently from someone on the free tier.
The analytics and crash data below are recorded against that identifier, which means they form a profile of this install over time. We want to be precise about that rather than hide behind the word “anonymous”: the data is not linked to your identity, but it is linked to itself.
What we collect
Product analytics (PostHog)
Lull records the steps you take through the app so we can see where it works and where it doesn’t. Concretely, that includes:
- Progress through onboarding, and whether you allowed notifications.
- When a ritual is started, which phase you reached, whether you finished or left, and how long it took.
- Whether a reminder or the home-screen button opened the ritual — and if it was a reminder, which of the three.
- When the subscription screen is shown, where it was opened from, and whether it led to a purchase.
- Alongside every one of the above: your bedtime hour, your current streak, whether you’re on Pro, whether notifications are enabled, and how many days ago you installed the app.
What is never included is anything you wrote. No prompt text, no intentions, no preview, no hash. Where we record something about your writing at all, it is a count or a length — how many of the three prompts you filled in, how many characters in total. We can tell that you wrote 180 characters. We have no way to know what they said.
Screen recording and session replay are switched off entirely.
Crash and error reports (Sentry)
If Lull crashes or hits an error, we receive a diagnostic report containing your device model, iOS version, app version, and a technical stack trace of what went wrong. It is configured not to attach personally identifying information, and it never includes journal content.
Subscriptions and payments (RevenueCat and Apple)
If you subscribe, Apple processes the payment. We never receive your card number or billing address. Our subscription provider records which plan you chose, its price and currency, and whether the subscription is currently active — against the same random identifier described above, not against your name or your Apple Account.
About IP addresses
Any app that talks to the internet necessarily reveals your device’s IP address to the servers it contacts. The providers above receive your IP as part of that connection, and may use it to infer coarse, country-level location or to block abuse. We do not use it to identify you.
Where this data goes
PostHog, Sentry, and RevenueCat process the data described above on their own servers, which may be located in the United States. Nothing you write in your journal is part of it.
We do not sell your data, we do not share it with advertisers, and Lull does not track you across other apps or websites.
Deleting your data
Because Lull has no account, there is no account to delete — and nothing you have written is sitting on a server of ours to begin with.
- Your journal on this device: delete Lull from your iPhone, and the journal is deleted with it.
- Your journal in iCloud (Pro): open the iOS Settings app, tap your name, then iCloud → Manage Account Storage → Lull → Delete. This erases the synced copy from your iCloud account.
- Your analytics and crash data: email us and we will delete it. Please get in touch before you delete the app if you can — the random identifier lives on your device, so once Lull is removed there is no longer any way for us to find your records and erase them.
Children
Lull is not directed at children under 13, and we do not knowingly collect information from them.
Changes to this policy
If this policy changes, the updated version will be posted on this page with a new effective date. Material changes will also be noted in the app’s App Store release notes.
Contact
Questions about this policy, or a deletion request? Email booya.pannachai@gmail.com.