Privacy Policy
Lampway · Last updated: August 16, 2026
Summary: Lampway is built around a Circle — your private shared space, which can be just you (solo), a family, or a small group. A signed-in Solo plan may also have a separate private Solo archive tied to that account. Data you enter (names, birthdays, reflections, quiz progress, memories, and approved transcripts) is stored in its intended private Circle or Solo scope so it syncs between your devices. Optional Family Audio and Ask Your Memories features process only the recordings, transcripts, questions, and bounded source snippets needed to provide those features. We don’t show ads. We don’t sell your data. We don’t use Google Analytics, Meta Pixel, or any third-party ad trackers. We do use PostHog for anonymized product analytics and Sentry for crash reports. Neither one receives the content of your reflections, prayers, journal entries, or God moments. See Sections 1 and 5 below for the full detail.
What is a Circle? A Circle is a private shared space. It can be solo (just you), a family (parents and children reading together), or a group (a few adults, like a small group or study). A private Solo archive is a separate account-level store and is not a Circle. Throughout this policy, “your Circle” means whichever Circle you set up. We use the word “family” only where we’re specifically talking about children and parental consent.
1. What we collect
Information you provide
- Names and birthdays you enter for the people in your Circle during setup (birthdays are used only to pick age-appropriate quiz content).
- Avatar choices you pick for people in your Circle — an icon color and up to two display initials — stored so every device shows the same roster.
- Admin PIN you set to lock owner-only actions.
- Reflections, journal entries, prayer requests, gratitude notes, and discussion responses you and others in your Circle type into the app.
- Quiz scores, reading progress, saved verses and highlights, memory-verse practice, streaks, and badges.
- Private Solo archive (signed-in Solo plans). Personal progress, notes, memories, reflections, searches, and related Solo records may be stored in a separate account-level archive. It is private to that signed-in account and is not the same as a solo Circle or shared Circle data.
- Voice dictation (optional). If you use device dictation to enter text instead of typing, your browser or operating system may process a short audio snippet through its own speech service. Lampway receives the resulting text, which is saved like anything you type. Device dictation is optional, and you can always type instead.
- Family Audio and Memory Helper recordings (optional beta/paid features). If an entitled owner or admin chooses to record a family conversation, discussion, or gathering, Lampway uploads the temporary raw audio to private object storage so it can be transcribed. Everyone present should know recording is happening before it starts. The transcript is shown for review before anything becomes a saved memory. Raw audio is deleted after transcription succeeds, when you cancel or discard, after retry exhaustion, or by the storage lifecycle backstop if cleanup fails.
- Transcripts and approved memories. Approved transcripts, summaries, saved memories, reflections, and related metadata are stored in your Circle so you can search and revisit them. Unapproved temporary transcript assets are deleted after the review flow is saved, discarded, or expires.
- Ask Your Memories questions. If you use Ask Your Memories, Lampway sends your question plus a bounded set of already-visible source snippets to our server-side answer provider. It does not send your whole Circle archive, does not search every private item, and should cite the sources it used.
- Optional recovery email address (opt-in only). If you choose to add one, we store it so you can send yourself a recovery link if you ever lose your join code. We store both the plaintext address (so you can view and remove it in settings) and a hashed version used as a lookup key. It is used only for recovery — never for marketing — and is not shared with third parties.
- Account sign-in (Sign in with Apple or Google). If you create an account to own a Circle, you can sign in with Apple or Google. We receive your email address — with Sign in with Apple this may be Apple’s private relay address — and, if you share it, your name, to create your account and let you recover it across devices. We never receive your Apple or Google password. This is used only to operate your account — never for marketing — and is not shared with third parties.
Information collected automatically
- Anonymous device identifier (a Firebase-issued random ID) so your Circle can sync between devices. Not linked to your real-world identity.
- Crash and error reports (via Sentry) so we can fix problems. These do not include the content of your journal entries, reflections, prayers, or names.
- Usage events (via PostHog) — which screens you visit, which features you use. We mask text inputs and sensitive fields so the content you type is not recorded.
- Notification token (if you opt in) so we can send daily-reading reminders.
2. What we do NOT collect
- You can join a Circle by code without any account. Creating a Circle requires signing in with Apple or Google (see Section 1); joining never does. We do not require your phone number, and a separate recovery email is always optional.
- We do not use your email for marketing, and we do not share it with third parties.
- We do not collect your location.
- We do not access your contacts, photos, or camera.
- We do not sell any data to advertisers or third parties.
- We do not show third-party ads.
3. How we use your data
- To provide the app: syncing your Circle’s progress across devices, picking age-appropriate content, tracking streaks and badges.
- To send daily-reading and streak reminders (only if you opt in to notifications).
- To transcribe optional recordings, create reviewable memory drafts, and delete temporary raw-audio assets according to the lifecycle described here.
- To answer Ask Your Memories questions from bounded, already-visible Scripture, waymark, memory, transcript, and reflection snippets.
- To fix bugs and improve the app, using anonymized crash reports and usage analytics.
4. Children
Lampway can be used solo, as a family, or as a small group. When a Circle includes children, it is intended for use under parental supervision. Before setup, the adult using the app is asked to confirm they are the parent or legal guardian of any children whose information is added to the Circle. By checking that box, you provide consent for the limited collection described in this policy on behalf of those children, as the Children’s Online Privacy Protection Act (COPPA) requires for children under 13.
Children’s data (names, birthdays, reflections, quiz scores, and any approved family memories that include them) is stored only within your Circle’s private account. We do not sell it, do not use it for advertising, and do not make it public. Children do not create separate public accounts — all data stays under the parent-controlled Circle.
If you use Family Audio in a Circle that includes children, the adult owner/admin is responsible for confirming that they are the parent or legal guardian, that children are supervised, and that everyone present knows recording is happening. Do not use Family Audio to secretly record anyone.
Parents can, at any time:
- Review all data stored by opening the app on any device signed in with your Circle’s join code.
- Edit or delete individual members from the app’s settings.
- Delete your entire Circle and all its data directly in the app, from Settings → “Delete Circle & all data” (you confirm by typing your join code). You can also request deletion by contacting us (see Section 9).
5. Where data is stored
- Google Firebase (Realtime Database and Cloud Firestore) — your Circle’s data (names, birthdays, reflections, quiz progress, Personal Scroll lighting state, optional recovery email) and, for signed-in Solo plans, the separate private Solo archive. Circle access is gated to authorized members; the private Solo archive is scoped to its signed-in account. We are gradually migrating some records from Realtime Database to Cloud Firestore; during the migration, the same Circle data may be written to both. Access rules on both are intended to enforce the same private scope.
- Cloudflare R2 or equivalent private object storage — temporary raw-audio and transcript assets for optional Memory Helper / Family Audio flows.
- AssemblyAI or equivalent transcription provider — temporary access to optional recording audio so it can be transcribed.
- Anthropic or equivalent answer-processing provider — bounded Ask Your Memories questions and source snippets, when you choose to use Ask.
- RevenueCat — subscription status and entitlement records if paid plans are enabled for your platform.
- Sentry — anonymized crash reports.
- PostHog — anonymized usage events (text inputs masked).
- Your device — a local cache so the app works offline. Cleared when you uninstall.
6. Your join code and security
When you set up the app you receive a join code (for example, a3k7p2qm). Anyone with this code can join your Circle and see or edit its contents. Treat it like a password: only share it with people you want in your Circle. If you believe your code has been shared outside your Circle, contact us to reset.
7. Data retention
Your Circle’s saved data stays in our database until you delete it. Uninstalling the app clears your local cache but does not automatically delete cloud data — other devices with your join code can still access it. Temporary raw-audio assets are deleted after transcription succeeds, cancel/discard, retry exhaustion, or the storage lifecycle backstop. Approved transcripts and memories remain saved until you delete them or delete your Circle. To fully delete your Circle and all its data, use Settings → “Delete Circle & all data” in the app, or contact us as described in Section 9.
Your private Solo archive has a separate deletion lifecycle. When you request its deletion in Settings, the archive becomes unavailable in the app and you have a 30-day recovery period in which to restore access. If you do not restore it, its active-database copy is deleted after 45 days. Cleanup runs daily, so actual deletion may occur near day 46. Deleting the private Solo archive does not delete any Circle or shared Circle records.
System backups follow their normal retention cycle: we keep the last 30 nightly snapshots, the last 12 monthly snapshots, and the last 5 yearly snapshots. Backups are not selectively purged for one account, so data you delete stays inside any snapshot taken before you deleted it, and leaves our systems when that snapshot expires — which for a yearly snapshot can be up to five years. Snapshots are encrypted, access-restricted, and used only to recover from a failure or data-loss incident; we do not read them to answer questions about your data.
8. Third parties
We use the following third-party services only for the purposes described in Section 5. We use Resend, an email delivery service, to send account and recovery emails, notes from the founder, and messages you send us through in-app feedback or support. Specifically, that covers: recovery links if you have opted in and request one, weekly family reports if you have opted in, inactivity notices before an account is archived, notes we send you as the people who make Lampway, and feedback you send us together with the internal summaries we send ourselves.
9. Contact and data deletion requests
To request deletion of your Circle or private Solo archive, access the data we hold about you, or ask any privacy question, contact us at: support@onelampway.com
We respond to verified requests within 30 days.
10. Changes to this policy
If we make material changes, we will post the updated policy here and update the "Last updated" date at the top. Continued use of the app after changes means you accept the updated policy.
← Back to app