Privacy Notice
Last updated: May 5, 2026
1. Who we are
This Privacy Notice describes how L. Laurén Oy ("Lovelier", "we", "us"), a company registered in Finland, processes personal data when you use Lovelier (the "Service") at lovelier.dev. For the purposes of EU/UK data protection law, L. Laurén Oy is the data controller of your personal data.
2. Data we collect
- Account data — your email address and (if you sign in with Google) your Google account ID and basic profile details.
- Habit content — the habits, schedules, completion logs, and notes you create in the Service.
- Device & usage data — IP address, browser type, device type, pages viewed, and basic interaction events used for security and product improvement.
- Support communications — messages you send us when you contact support.
- Payment data — when you purchase a subscription or lifetime plan, payment is handled by Paddle. We do not see or store your card details. We receive transaction metadata (plan, status, period dates) from Paddle to manage your entitlement.
3. Why we use your data and the legal basis
- To provide the Service — creating your account, syncing your habits, and showing your insights (legal basis: performance of a contract).
- To process payments and entitlements — through Paddle as our Merchant of Record for sale, subscription management, payments, tax compliance, and invoicing (performance of a contract / legal obligation).
- To keep the Service secure — preventing fraud, abuse, and security incidents (legitimate interests).
- To improve the Service — understanding how features are used in aggregate (legitimate interests).
- To respond to support requests — answering your questions (legitimate interests).
- To send service emails — important account or transactional notifications (performance of a contract). We do not send marketing emails without your consent.
4. Who we share data with
We share personal data only with the following categories of recipients:
- Paddle — our Merchant of Record for sale of the product, subscription management, payments, tax compliance, and invoicing.
- Service providers and subprocessors — including our hosting, database, and authentication provider (Supabase) and our application hosting (Cloudflare).
- Professional advisers — such as legal and accounting advisers, where strictly necessary.
- Authorities — where required by law or to protect our rights.
We do not sell your personal data.
5. International transfers
Some of our service providers process data outside the EU/EEA (for example, in the United States). When this happens, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses or adequacy decisions to protect your data.
6. Data retention
We keep your personal data for as long as you have an active account and for a limited period afterwards as needed for legal, tax, accounting, or fraud-prevention purposes. When data is no longer needed, it is deleted or anonymized. You can delete your data at any time from within the app.
7. Your rights
Subject to applicable law, you have the right to access, rectify, erase, restrict, or object to processing of your personal data, the right to data portability, and the right to withdraw any consent you have given. You also have the right to lodge a complaint with your local data protection authority. In Finland, this is the Office of the Data Protection Ombudsman (tietosuoja.fi). We aim to respond to verified requests within one month.
To exercise your rights, email us at hello@lovelier.dev.
8. Security
We implement appropriate technical and organisational measures to protect your data, including encryption in transit, access controls, and database-level row security. No system is perfectly secure, so please use a strong password and let us know immediately if you suspect any unauthorised access to your account.
9. Cookies and local storage
We use strictly necessary cookies and browser local storage to keep you signed in, remember your preferences (theme, settings), and store your habits when you are not signed in. We do not use advertising cookies. You can clear cookies and local storage at any time from your browser settings.
10. Changes to this notice
We may update this Privacy Notice from time to time. If changes are material, we will notify you in the app or by email. The "Last updated" date at the top reflects the latest revision.
11. Contact
For privacy questions or requests, email hello@lovelier.dev. For payment-related privacy matters, you can also contact Paddle at paddle.net.