Privacy Policy
Last updated: 10 October 2026
The short version
- Your journal is private. Only the family members you invite can see it.
- We don’t sell your data, show ads, or use your memories to train AI.
- Voice notes are transcribed on your phone. The recording isn’t sent anywhere to do this.
- No analytics or advertising trackers in the app — only crash reports, without your content.
- You can delete your account and your journals at any time, right in the app.
1. Who we are
Laterly is an app for parents to keep voice notes, letters, photos and videos for their child to open later. This policy explains what personal data we handle when you use the Laterly app, the guest pages on getlaterly.com and this website, and what we do with it.
The controller of your personal data is Websitters sp. z o.o., ul. Aleksandra Hercena 10, 50-453 Wrocław, Poland, entered in the National Court Register (KRS) under number 0000946109 by the District Court for Wrocław-Fabryczna in Wrocław, VI Commercial Division, NIP (tax ID) PL8992915384, REGON 521002056, share capital PLN 20,000 (“Laterly”, “we”, “us”). You can reach us at [email protected] about anything in this policy.
2. Who Laterly is for
Laterly accounts are for adults: parents, co-parents and the family members they invite. Children don’t have accounts and don’t use the app. The journal is about a child and written for them by the adults in their life.
Because a journal is about a child, it naturally contains information about them, such as their name, birth date, photos and stories. You decide what goes in. Please only add content you have the right to share, including photos or recordings of other people.
3. What we collect
| Data | Examples | Where it comes from |
|---|---|---|
| Account | Email address, name, password (stored only as a secure hash), your relation to the child (e.g. mom, dad) | You, when you sign up |
| Journal details | Child’s name, birth date, journal title, the age they might open it, important days such as birthdays | You, during setup and in settings |
| Memories | Voice recordings and their transcripts, letters and notes, photos, videos, titles, dates, tags, favorites | You and your family members |
| Family | Who belongs to a journal and their role (owner, co-parent, contributor), invitations you send | You and the people you invite |
| Guest contributions | The name a guest types, and the photo, video, voice note or message they send through a family event link | Guests who use an event link or QR code |
| Reminders | Which days and what time you want a gentle reminder, and your time zone | You |
| Subscription | Your plan, whether you’re in a trial, renewal and expiry dates, the store you bought through. We never see your card or payment details. | Apple App Store or Google Play, through RevenueCat |
| Technical | Sign-in events, IP address and device information in server logs, kept for security | Your device, automatically |
| Crash reports | When the app crashes or hits an error: what went wrong in the code, device model, system and app version. Never your memories, names or messages. | The app, automatically |
| Notifications | A push token for your phone, and whether you want family notifications | Your device, if you allow notifications |
On your device only. Some things never reach us: the Face ID / passcode lock setting, the transcription process itself (Apple’s on-device speech recognition), and reminder notifications, which your phone schedules locally.
Permissions. The app asks for the microphone (to record voice notes), photos and camera (to add pictures and videos), speech recognition (to transcribe on your phone) and notifications (for reminders). Each one is optional and you can change it in your phone’s settings at any time.
4. What we don’t do
- We don’t sell or rent personal data, and we don’t share it for advertising.
- We don’t show ads.
- We don’t use your memories, recordings or photos to train AI models, ours or anyone else’s.
- We don’t include third-party analytics, advertising or tracking SDKs in the app. The only outside tool in the app is crash reporting, which helps us fix bugs.
- We don’t look at your journal. Our team only accesses your content if you ask us to for support, or if the law requires it.
5. Why we use your data
| Purpose | Legal basis (GDPR) |
|---|---|
| Running Laterly: your account, storing and showing your journal, sharing it with your family, guest uploads you approve, reminders | Performing our contract with you (Art. 6(1)(b)) |
| Your subscription and plan limits | Performing our contract with you (Art. 6(1)(b)) |
| Keeping Laterly secure, preventing abuse and fixing problems | Our legitimate interest in a safe, working service (Art. 6(1)(f)) |
| Service emails, such as confirming your email or resetting your password | Performing our contract with you (Art. 6(1)(b)) |
| Microphone, photos, speech recognition and notifications on your phone | Your consent, which you give and can withdraw in your phone’s settings (Art. 6(1)(a)) |
| Keeping records the law requires | Legal obligation (Art. 6(1)(c)) |
Photos, recordings and stories about your family can be sensitive. We treat everything in a journal as confidential, whatever it contains.
6. Who can see your journal
- Owners and co-parents can see, add, edit and delete everything in the journal and manage who has access.
- Contributors (for example grandparents you invite) can see the journal and add memories.
- Guests who open a family event link only see the event title and date and the child’s name, as you entered it. They can send something, but they can’t see the journal. Nothing a guest sends is kept until a parent approves it. If a parent declines, the message and files are deleted.
- Memories you mark as hidden are still visible to the family. The setting only affects what the child will see later.
Anyone with an event link can open the guest page while the link is active, so share it only with people you trust. You choose how long the link stays open.
7. Service providers
We use a small number of companies to run Laterly. They process data only on our instructions and under data processing agreements.
| Provider | What for | Where |
|---|---|---|
| Supabase | Database, file storage, sign-in and service emails | European Union (Ireland) |
| Sentry | Crash and error reports, without journal content | European Union (Germany) |
| Expo (650 Industries) | Delivering push notifications to your phone through Apple. It receives the push token and the notification text, such as “Grandma sent something for Alexander”. | United States |
| RevenueCat | Managing subscriptions. It receives an anonymous account ID and purchase information from the store, never your journal. | United States |
| Apple and Google | App distribution and payments, under their own privacy policies | Worldwide |
| Hetzner | Hosting getlaterly.com and the guest pages | European Union (Finland) |
When data is transferred outside the European Economic Area, we rely on the European Commission’s Standard Contractual Clauses or an adequacy decision, such as the EU–US Data Privacy Framework.
8. How long we keep data
- Your journal stays as long as your account does. You can delete any memory at any time.
- When you delete your account in the app (You → Privacy → Delete account), every journal you own on your own is deleted along with all its memories and files. A journal you share with a co-parent stays with them, and your access is removed.
- Declined guest contributions are deleted when a parent declines them.
- Backups and logs are kept for a limited time for recovery and security, and deleted data disappears from them within 30 days.
- Subscription records are kept as long as the law requires for accounting.
9. Your rights
Depending on where you live, including in the EU and UK, you have the right to:
- access the personal data we hold about you and get a copy of it;
- correct it if it’s wrong (most of it you can edit in the app yourself);
- delete it (you can delete your account in the app);
- receive your data in a portable format;
- restrict or object to some uses of it;
- withdraw consent at any time, for example by turning off a permission;
- complain to a data protection authority. In Poland that is the President of the Personal Data Protection Office (UODO, uodo.gov.pl). You can also contact the authority where you live.
To use any of these rights, email [email protected] from the address on your account. We’ll reply within one month.
California residents: we don’t sell or share personal information as the CCPA defines it, and we don’t use sensitive personal information to infer anything about you.
10. Security
Data is encrypted in transit (TLS) and at rest by our hosting provider. Files are kept in private storage and only shown through short-lived links to members of your family. Access rules in our database mean each family can only reach its own data. Inside the app, you can add a Face ID or passcode lock. No system is perfectly secure, so if we ever learn of a breach affecting you, we’ll tell you and the authorities as the law requires.
11. Changes to this policy
If we change this policy in a way that matters, we’ll tell you in the app or by email before the change applies. The date at the top always shows the latest version.
12. Contact
Questions, requests or worries: [email protected].