Privacy policy

Last updated: 25 August 2026 · Version 1.0

The short version. LottaLou keeps a private journal of your family. We use your data to run the app and for nothing else. We do not sell it, we do not advertise against it, and there is no analytics or tracking SDK in the app. Recordings go to a speech-to-text provider on EU infrastructure to be turned into text; transcript text goes to an AI provider only to be tidied up and titled. You can delete your account, and your entries and photos, from inside the app.

1. Who we are

LottaLou is built and operated by Anne Albert, trading as annealbert.dev, a sole proprietorship (eenmanszaak) registered in the Netherlands.

We are the controller for the personal data described here. We are not required to appoint a Data Protection Officer and have not appointed one; privacy questions go to the address above.

2. What this covers

This policy covers the LottaLou mobile app for iOS and Android, this website at lottalou.com, and the email we send you. Third-party services we rely on are listed in section 6; where you leave our app for a service of their own (the App Store, Google Play), their privacy policy applies to that part.

3. What we collect

Account

Journals

Entries

Sharing

Technical

What we do not collect

Permissions the app asks for

Each is asked for at the point it is needed, and each can be withdrawn in your device settings.

On Android the app also declares a set of lower-level permissions that the audio-recording library needs in order to work — access to Bluetooth audio devices, audio settings, a foreground service while recording, and keeping the screen awake. They are used for recording and nothing else. Google Play lists them in full on the app's page.

What is stored on your phone

So the app opens instantly and works without a signal, a copy of your recent journal data — entries, titles, transcripts and member lists — is cached in the app's own storage on the device for up to seven days, along with anything you entered during setup. Audio recordings also remain in the app's storage after they have been transcribed. All of it is removed when the app's data is cleared or the app is deleted.

4. Data about children

LottaLou is a journal about children, written by adults. The account holder must be 18 or over. There are no accounts for children and the app is not directed at them.

That said, the content is largely personal data about a child: their name, date of birth, photographs, video, quotes and milestones — plus whatever else you choose to write down. A journal is free-form, so some of what ends up in it may count as health data under the GDPR, which is a special category requiring extra care. We do not ask for it; the point is that if you record it, it is treated with that care.

You provide this data as the child's parent or legal guardian, or with that person's permission, and you are responsible for having the authority to do so — including for anyone else who appears in a photo or recording. We process it only to provide the journal to you and the people you have invited. We never use it to train AI models, we never use it for advertising, and we never sell or rent it. Where a provider processes it on our behalf, we select the service and the plan so that their terms forbid them from training on it either.

Because these are children's photographs, media is held in private storage and is reachable only through signed links that expire after one hour.

5. Why, and on what legal basis

Purpose Data Legal basis (GDPR art. 6)
Creating and securing your account Email, password hash, Apple identifier, settings Performance of a contract (6(1)(b))
Storing and showing your journals and entries Journals, entries, transcripts, photos, video Performance of a contract (6(1)(b))
Turning your recording into text Audio recording, resulting transcript Performance of a contract (6(1)(b))
Suggesting a title and cleaning up the transcript Transcript text Performance of a contract (6(1)(b))
Sharing a journal with family you invite Membership records, invited email address Performance of a contract (6(1)(b))
Handling subscriptions and enforcing plan limits User identifier, subscription status, usage counters Performance of a contract (6(1)(b))
Keeping the service working and secure Crash reports, error logs, server logs Legitimate interests (6(1)(f)) — a stable, non-abused service
Storing special-category content you choose to add Anything in an entry that counts as health data Your explicit consent (9(2)(a)), given by entering it
Waitlist and product emails Email address Consent (6(1)(a)) — withdrawable at any time

6. Who processes it

We use a small number of providers to run the service. They act on our instructions under a data processing agreement, and each receives only what its job requires.

Provider What it does What it receives Where
Supabase Database, authentication, file storage, server functions Everything stored in your account: profile, journals, entries, transcripts, photos and video EU
Soniox Speech-to-text Your audio recording and the transcript produced from it EU
Google (Gemini API) Tidying a transcript, suggesting a title and photo-book captions Transcript text only. No audio, no photos, no account details United States / global
RevenueCat Subscription management Your account identifier and purchase status, plus the device and country information their SDK collects United States
Sentry Crash and error monitoring Error details, app version, device model; the account identifier on errors raised by our own server functions EU (Germany)
Resend Sending invitation and account emails The recipient's email address and the message United States
Apple & Google App distribution, in-app purchases, Sign in with Apple Purchase and account data under their own policies Global
Expo (EAS) Building the app Build metadata; no journal content United States
Cloudflare Hosting this website and the waitlist Requests to the site, and the email address you submit Global edge network

We do not sell personal data and we do not share it with advertisers or data brokers. Each provider above is used on a plan whose terms prohibit it from using customer content to improve or train its own models.

Beyond this list, we disclose data only where the law requires it, or where it is necessary to establish or defend a legal claim.

7. Recordings and AI

This is the part people ask about, so here it is in detail.

8. Sharing and invitations

A journal is private until you invite someone. You can invite them in two ways: by email address, which we store and send the invitation to, or as a shareable link. A shareable link is a bearer link — anyone who has it can join the journal until it expires — so send it only to the person it is meant for.

Once someone accepts, they become a member: they can read the journal's entries and media and, depending on the role you gave them, add their own.

Members can see each other. Everyone in a journal can see the name and profile picture of every other member.

Only invite people who would expect to be invited. Members can see the content shared with them, including photographs of your child, and what they do with it afterwards is outside our control.

An invitation sent by email shows the recipient who sent it — your name, or the first part of your email address if you have not set one.

You can remove a member or revoke an invitation at any time; invitation codes and shareable links also expire on their own.

Exporting a journal as a photo book builds a PDF on your device, with the photos embedded in it, and hands it to your phone's share sheet. Where it goes from there — email, a cloud drive, a print shop — is your choice, and outside our control.

9. Transfers outside the EEA

Some providers listed above are established in, or process data in, the United States. Where personal data leaves the EEA, we rely on the European Commission's Standard Contractual Clauses, on an adequacy decision such as the EU–US Data Privacy Framework where the provider is certified under it, or on both. You can ask us for details of the safeguards in place for a specific provider.

10. How long we keep it

11. Security

No system is perfectly secure. If a breach occurs that is likely to present a risk to you, we will notify the Dutch Data Protection Authority within 72 hours and tell you directly where the law requires it.

12. Your rights

Under the GDPR you can ask us to:

Email [email protected] and we will answer within one month. Deleting your account, which does most of this immediately, is available in the app's settings.

If you think we have handled your data badly, you can complain to the Dutch Data Protection Authority (Autoriteit Persoonsgegevens, autoriteitpersoonsgegevens.nl) or to the supervisory authority where you live. We would rather you told us first.

13. This website

lottalou.com sets no cookies, runs no analytics and embeds no tracking pixels. Web fonts are loaded from Google Fonts, which means your browser makes a request to Google's servers and Google sees your IP address for that request.

If you join the waitlist, we store the email address you submit, the time you submitted it, and nothing else, in order to write to you once when the app is ready. We do not pass it to anyone. Ask us and we will delete it.

Our host, Cloudflare, keeps short-lived request logs for security and abuse prevention.

14. Changes

We will update this policy when the app changes. The date at the top always reflects the current version. For a change that materially affects you we will tell you in the app or by email before it takes effect; continuing to use LottaLou afterwards means the new version applies.

15. Contact

Anne Albert (annealbert.dev)
Dreischorstraat 26D, 3086 PB Rotterdam, the Netherlands
KvK 76456080
[email protected]