Lanternly — Privacy Policy

Last updated: 11 September 2026

Lanternly is an alarm clock that asks you questions from your own notes. This policy explains what happens to those notes, and to everything else the app touches.

It is written to be read. Where a sentence here says the app does not do something, that is a claim about the code, and the code is written so the claim stays true.


Who we are

Lanternly is made by Karama Ltd, a company registered in England and Wales.

For the parts of the app that involve us at all, Karama Ltd is the data controller.


The short version


What stays on your device

All of the following is stored only in the app's own storage on your phone. We have no copy and no way to obtain one:

If you delete the app, all of it goes with it. We cannot restore it, because we never had it.

Photographs, files and videos

When you photograph a page, choose an image, import a file or import a video, the app reads the text out of it and keeps only that text.


What leaves your device

1. Question generation

Questions are written by an AI model running on a server, from the text of the note you saved. There is no other way the app writes them, so this is not optional: it is the thing you are paying for. The app shows you exactly what this involves, naming the company, before the first note is sent, and this section says the same.

Only at the moment you save a note or ask for more questions:

Our lawful basis for this is that it is necessary to provide the service you have asked for (UK GDPR Article 6(1)(b)) — an alarm that quizzes you on your notes cannot exist without turning the notes into questions. If you do not want a note processed this way, do not save it in Lanternly. Text already sent cannot be retrieved by us, because we never held it.

Please do not put things in your notes that you would not want processed this way — someone else's medical details, for instance. A note you never save is never sent anywhere.

2. Device attestation — so the service is not abused for free

The question-generation service costs us money per request and has no login to protect it. To stop it being drained by someone who is not using the app, every request is signed using Apple's App Attest, which proves the request came from a genuine, unmodified copy of Lanternly.

This means our server stores, for each installation:

What Why
An App Attest key identifier and its public key To verify future requests came from the same installation
A signature counter To detect and refuse replayed requests
The date first seen and last seen To retire installations that stop being used
The app version and Apple's attestation environment To distinguish real installs from development builds
A hashed identifier plus a per-day request count To enforce the daily limit

This identifier is generated by Apple, is specific to this app on this device, and is not the advertising identifier. It cannot be linked to you by name — we have no name — but because it persists, we treat it as personal data and it is covered by the rights below.

Our lawful basis is legitimate interests (UK GDPR Article 6(1)(f)): preventing fraud and abuse of a paid service. We consider this proportionate because the alternative — making people create accounts — would collect considerably more about them.

The daily counters are deleted after 7 days. Attestation challenges are deleted after 1 hour. Installation records are kept while the installation is in use and removed once it has not been seen for 12 months.

3. Notifications

Alarms and reminders are scheduled on your device by iOS. They are not push notifications, we do not operate a notification server, and no notification token is sent to us.

4. Subscriptions

Lanternly is sold as an auto-renewing subscription through Apple's App Store. Apple processes the payment and holds your payment details, your Apple ID and your purchase history; we receive none of them. What the app receives from Apple is a signed receipt saying whether this installation has an active subscription, and when it renews or ends. That is stored on your phone and used only to unlock the features you paid for.

You manage, cancel or request a refund for a subscription through Apple (Settings → your name → Subscriptions on your iPhone), not through us, because we have no record of who bought what.

5. Anonymous usage analytics — only if you switch them on

To find out where people get stuck — which onboarding screen they leave on, whether alarms get set, whether notes get saved — the app can send anonymous usage events to PostHog, hosted in the EU. This is off until you turn it on; the app asks once, after the tour, and Settings has the switch.

6. Feedback you send us

If you use "Contact support" in Settings, it opens your own email app with a message addressed to support@karama.uk. We receive whatever you choose to send, and your email address, and we keep it only for as long as it takes to deal with your message.

"Suggest a feature" in Settings opens our public ideas board at lanternly.featurebase.app in your browser. That board is a separate website run by Featurebase; the app sends it nothing about you, and anything you post or vote on there is governed by Featurebase's own privacy policy. You can read and vote without the app, and nothing on the board is linked to your alarms, notes or subscription.


Who else is involved

Who What they do Where
Supabase Hosts our server function and the small database described above London, United Kingdom
Mistral AI Writes questions from note text, when question generation is on EU (France)
PostHog Receives anonymous usage events, only when analytics is switched on EU (Germany)
Featurebase Hosts the public ideas board, only if you choose to open it EU / US (their site, not the app)
Apple Operates App Attest, the App Store and subscription billing. Reading text out of photos, files and videos happens on your phone and Apple receives nothing from it

We do not use crash reporting, attribution or advertising services of any kind, and the only analytics is the opt-in one described above.


International transfers

Our processing takes place in the UK and the EU. Where personal data is transferred outside the UK, it is protected by the UK's adequacy regulations for the EEA, or by the International Data Transfer Addendum to the European Commission's Standard Contractual Clauses.


Children

Lanternly is not aimed at children under 13 and we do not knowingly collect anything from them. The app has no account, no profile, no messaging, no social features and no advertising.


Your rights

Under UK GDPR you have the right to access, correct, erase, restrict, object to and port your personal data, and to withdraw any consent you have given (which here means the optional analytics).

In practice, most of this you can do yourself and instantly:

For the device attestation records described above, write to support@karama.uk. Please note the honest limitation: those records are not linked to any name or email, so to erase a specific installation's record we would need something identifying it, which practically means deleting the app — which is why the record is removed after 12 months of not being seen.

If you are unhappy with how we have handled your data you can complain to the Information Commissioner's Office at ico.org.uk/concerns, or by calling 0303 123 1113.


Changes

If this policy changes in a way that affects what happens to your data, the app will tell you before the change takes effect. The date at the top always shows when it was last revised.


Contact

support@karama.uk — Karama Ltd, 483 Green Lanes, London, N13 4BS, United Kingdom