Privacy Policy
Effective date: August 11, 2026
Layora (“the App”) is developed by Aswin Karunakaran Kalarickal (“we,” “us,” “our”). This policy explains what data the App collects, why, and what stays on your device.
Summary
The short version: your late-night Brain Dump entries never leave your phone. What does leave your phone is limited to account basics (so you can sign back in), anonymous usage analytics, crash reports, and anything you deliberately submit through the feedback form.
Information We Collect
Account information
When you sign in with Google or Apple, or choose “Explore as Guest,” we create an account record containing:
- Your sign-in provider (Google, Apple, or anonymous/guest)
- Your name and email address, if your sign-in provider shares them (guest accounts have neither)
- Account timestamps (created, last updated)
This is stored in our Firebase database, tied to a unique account ID. Your trial/subscription status is tracked separately by our paywall provider, Superwall — see “Third-Party Services” below — and is not stored in our own database. A truncated version of this ID is shown in-app under Settings → About as a “Support ID” so you can reference your account when contacting us — it identifies your account, not you personally.
Brain Dump entries — stored locally only
Anything you type into the Anxious mode's Brain Dump, and everything visible in your Morning Vault, is stored only on your device, in a local database. It is never transmitted to us or to any server, and we have no way to read it. Deleting the app, or deleting an entry in the Morning Vault, deletes it for good.
Feedback you submit
If you use Settings → Send Feedback, the text you write is sent to us along with your account ID, the platform (iOS/Android), and your app version. This is a one-way submission: once sent, it can't be edited, read back, or deleted through the app. We use it solely to read and respond to feedback, including via an internal Slack notification to our team.
Subscription & trial data
Some features require a free trial or paid subscription, managed by our paywall provider, Superwall. If you're signed in with a real account (not a guest), Superwall associates your subscription/trial status with your account ID. Purchases themselves are handled directly by Apple's or Google's app store billing system (StoreKit / Play Billing) — we don't collect or see your payment details.
Usage & analytics data
We use PostHog to understand how the App is used — for example, which sign-in method you used, which mode you selected, whether a session was completed or exited early, and similar milestone events. These events carry counts, durations, and true/false flags — never the content of anything you typed. If you're signed in with a real account (not a guest), these events are associated with your account ID so we can see a coherent journey across sessions; guest sessions are not identified. Signing out disassociates future events from your account.
Crash & diagnostic data
We use Firebase Crashlytics to automatically collect crash reports (stack traces, device model, OS version) if the App encounters an error, so we can fix it. Reports are tied to your account ID only if you're signed in with a real account.
Notification & reminder preferences
Whether you've turned on evening reminders, and the reminders themselves, are scheduled entirely on your device using your operating system's local notification system. This preference is stored locally on your device and is not sent to us.
What we don't collect
The App does not access your camera, microphone, contacts, photo library, or location, and does not request any permission to do so.
How We Use Information
We use the information above to: operate your account and sync your trial/subscription status, respond to feedback you send us, understand and improve how the App is used, and diagnose and fix crashes.
Third-Party Services
The App relies on the following third parties to provide its functionality. Each processes only the data described above, in the categories relevant to their service:
- Google Firebase (Authentication, Firestore database, Remote Config, Crashlytics, Cloud Functions) — account data, feedback submissions, crash reports, and feature-flag delivery.
- Google Sign-In and Sign in with Apple — used only if you choose those sign-in options; we receive your name/email from them if you grant it.
- PostHog — usage analytics, as described above.
- Superwall (and, underneath it, Apple's App Store / Google Play billing) — manages the free trial and subscription paywall, and your subscription/trial status, as described above.
- Slack — receives a notification (your feedback text and account ID) when you submit feedback, for our internal team's visibility.
We do not sell your data, and we do not share it with third parties for their own advertising purposes.
Data Retention
We retain your account record for as long as your account exists — you can delete it yourself at any time via Settings → Delete account, which removes it immediately. Brain Dump entries are retained only on your device, for as long as you choose to keep them (and are cleared automatically when you delete your account). Feedback submissions are retained independently of your account, as needed to comply with legal obligations or respond to what you sent us.
Your Rights and Choices
You can permanently delete your account at any time from Settings → Delete account in the App. This immediately removes your account record from our database and clears the Brain Dump entries stored on your device — no need to contact us first. Feedback you've previously submitted is kept separately and isn't removed by this action, since it's a one-way submission not linked back to a live account (see “Feedback you submit” above).
If you no longer have the App installed, you can request the same account deletion at layora.app/delete-account.
Depending on where you live, you may also have other rights — for example, to access or correct your account data, or to request removal of a specific feedback submission. To exercise these, contact us using the details below.
Children's Privacy
The App is not directed at children under 13, and we do not knowingly collect information from children under 13.
Data Security
We rely on Firebase's infrastructure and access controls to protect the data we hold, and Firestore's security rules restrict account and feedback data to the account that created it. No method of storage or transmission is 100% secure, but we work to protect your information using industry-standard practices.
Changes to This Policy
We may update this policy as the App changes. We'll update the effective date above when we do.
This Website
Everything above describes the Layora mobile app. layora.app — the website you're reading this on — handles data separately and far more narrowly:
- A popup inviting you to closed testing stores a flag in your browser's local storage once you dismiss or act on it, so it doesn't reappear. This stays on your device and is never sent to us.
- If you use layora.app/delete-account to delete your account without the App installed, signing in with Google briefly creates an authenticated session in your browser (via Firebase Authentication) so we can verify it's really you before processing the deletion — this is required to complete the action you requested.
This website does not use cookies, and does not run any analytics or advertising trackers.
Contact Us
Questions about this policy or your data: mail@foxtris.com