The short version
Lucy has no accounts. We never ask for your name, email address, phone number or a password, and there is nothing to sign up for.
We do not track you across other apps or websites, we do not use the advertising identifier, and we do not sell or share your data with data brokers or advertisers. You will never see an "Allow tracking?" prompt from this app, because there is nothing to allow.
Almost everything the app knows about you stays on your phone.
1. Who we are
Contact: https://lucystretch.com/contact
2. What stays only on your device
The following never leaves your phone. It is stored locally and is deleted when you delete the app:
- Your setup answers — where you feel tight, how long you have, where you will be stretching, when you are likely to do it, and whether you have tried stretching before. These are used to order suggestions, and nothing else.
- Saved routines and any stretch durations you have adjusted.
- Your reminder time and whether reminders are on.
- Your appearance preference (light or dark).
We never see any of it.
3. What we do collect
3.1 An anonymous identifier
On first launch the app creates an anonymous account with our backend provider, Supabase. This produces a random identifier (a UUID).
It is not linked to your name, email address, Apple ID or device. We cannot use it to identify you, and nobody has told us who you are — there is no field in the app in which to tell us.
Its only purpose is to let your record of completed days survive reinstalling the app.
3.2 Which days you completed a routine
When you finish a routine, we store:
| Field | Example |
|---|---|
| the anonymous identifier | a4cd514c-… |
| which routine | unstick_your_neck |
| the date | 2026-08-24 |
| how many seconds it took | 184 |
That is the entire record. No time of day, no location, no device details, and nothing about how the movement went.
3.3 Usage analytics
We use PostHog to understand how the app is used — which screens are opened, which routines are started and completed, whether the paywall was shown and dismissed. Events are attached to the anonymous identifier above.
PostHog also collects standard technical attributes: device model, operating system version, app version and locale.
Analytics are disabled entirely in development builds. They run only in the released app.
3.4 Subscription status
If you subscribe, RevenueCat tells us whether your subscription is active so the app can unlock paid routines.
Payment is processed by Apple. We never receive or store your card details, billing address, or Apple ID.
4. What we do not collect
To be explicit, because fitness apps commonly do collect these and Lucy does not:
- ❌ Name, email address, phone number, password
- ❌ Health or fitness data from Apple Health — the app has no HealthKit integration
- ❌ Data from a watch or any wearable
- ❌ Motion or step data
- ❌ Location, at any precision
- ❌ Camera, microphone, photos or contacts
- ❌ The advertising identifier (IDFA)
- ❌ Anything shared with advertisers or data brokers
5. Why we process it, and on what basis
| What | Why | Legal basis (GDPR) |
|---|---|---|
| Anonymous identifier | So progress survives reinstalling | Legitimate interests |
| Completed days | The feature itself — your streak | Legitimate interests |
| Analytics | Understanding what to improve | Legitimate interests |
| Subscription status | Unlocking what you paid for | Performance of a contract |
We do not use your data to make automated decisions with legal or similarly significant effects.
6. Who else is involved
| Provider | What they handle |
|---|---|
| Supabase | Anonymous identity, completed-day records |
| PostHog | Usage analytics |
| RevenueCat | Subscription status |
| Apple | App distribution and all payment processing |
Each processes data under its own terms. We do not sell data to anyone, and none of these is an advertising network.
7. How long we keep it
Completed-day records are kept while the app is in use, so your history remains accurate. Analytics events are retained under PostHog's configured retention period.
You can delete everything at any time — see below.
8. Deleting your data
Settings → Delete Account & Data.
This is available without paying and without an account. It:
- deletes your anonymous user and every completed-day record from our backend
- clears all locally stored data on your device
It is permanent and cannot be undone. Deletion is performed against the identity proved by your session — nobody can trigger deletion of anyone else's data.
Deleting the app without using this option removes everything local, but leaves the anonymous backend record.
9. Your rights
Depending on where you live, you may have rights to access, correct, delete, export, or restrict processing of your data, and to object to it.
Because Lucy holds no information that identifies you, we may be unable to locate records relating to you without the anonymous identifier from your device — we cannot search by name or email, since we hold neither. Contact https://lucystretch.com/contact and we will help where we can.
You may also complain to your local data protection authority.
10. Children
Lucy is not directed at children and we do not knowingly collect data from them.
11. Changes
We will update this policy when our practices change, and will say so in the app where the change is material. The version you accepted is recorded.
12. Contact
https://lucystretch.com/contact