Privacy Policy Lighten Journey™
Last updated: August 23, 2026
1. Who we are
Lighten Journey is developed and operated by Mayanfa, a French société par actions simplifiée with a sole shareholder (SASU), registered with the Paris Trade and Companies Register under number 103 704 961 R.C.S. Paris (EUID: FR7501.103704961), with its registered office at 30 rue des Cordelières, 75013 Paris, France ("Mayanfa," "we," "us," or "our").
For the purposes of applicable data-protection laws, including the EU General Data Protection Regulation ("GDPR") and the UK GDPR, Mayanfa is the controller of the personal data described in this Privacy Policy. French law, including the Loi Informatique et Libertés, also applies.
Privacy contact: support@mayanfa.com
2. Scope
This Privacy Policy explains how we collect, use, disclose, retain, and protect personal data when you use the Lighten Journey mobile application, contact support, or otherwise interact with the Lighten Journey service.
3. Personal data we process
Lighten Journey has no accounts and asks you for no personal details. There is no sign-up, no password, no email address, and no name. You are not asked to type anything into the app at any point. What follows is the whole of what we process.
Session identifier. The first time you open the app it creates an anonymous session and receives a random identifier from our authentication provider. That identifier is not derived from you, your device, or anything you have told us, and it is the only thing your data is stored against. The app shows it to you as your "Support ID" so that you can quote it if you contact us. Our authentication provider records the date the session was created, and our subscription provider records your subscription status against the same identifier.
Your journey record. When you complete a guided session, we record that you completed it, which session it was, the date and time, and the life stage you selected from the four options offered. That is the entire record. There is no title, no note, and no free text of any kind: earlier versions of the app allowed you to name a released memory, that field has been removed, and names stored by those versions are deleted. The record is stored on servers operated by our hosting provider on our behalf, so that your journey is preserved and shown back to you. It is used for nothing else. It is not used for advertising, profiling, analytics, or the training of artificial-intelligence models, and it is not routinely accessed by our team. See section 5.
Usage and technical data. The app records a small number of events to understand whether the service works: completion of the introduction, views of the subscription screen, the start, success or cancellation of a subscription purchase, the start and completion of a guided release session, and the opening and completion of a wound audio session. These events carry no information about you and no information about which wound you opened — only that one was. They are recorded against your session identifier and an app-instance identifier. Our analytics and crash-reporting providers additionally collect the app version, device model, operating system and version, language, an approximate country derived from your IP address, timestamps, and — when the app fails — diagnostic logs and crash reports including the state of the device at the time.
Subscription and transaction data. The subscription product selected, subscription status, purchase or transaction identifiers, renewal or expiration information, and the storefront used. Apple or Google processes the payment. We do not receive your full payment-card or banking details.
Support communications. If you write to us, we process your email address, the Support ID you quote, and the information you include, including any attachments or technical details needed to investigate a request. Your email address reaches us only because you wrote to us from it; the app never asks for it and never sends it to us.
We do not ask for and do not knowingly collect your name, your postal address, your telephone number, your precise location, your contacts, your photographs, or biometric data.
4. How we collect data
We collect personal data:
automatically from the app and device when you use Lighten Journey;
from Apple or Google when they confirm a subscription transaction or entitlement;
from you, if and when you choose to contact support; and
from the service providers identified in section 7.
5. Why we process personal data and our legal bases
Where the GDPR or UK GDPR applies, we rely on the following legal bases:
Performance of a contract: to create and maintain your anonymous session, provide access to the app and audio sessions, keep and display your journey record, verify subscription status, and provide support.
Legitimate interests: to protect the app and users, prevent fraud and abuse, diagnose failures, and improve reliability using proportionate technical information. We do not rely on this basis where your rights and interests override ours.
Consent: where required for optional analytics or notifications. You may withdraw consent at any time without affecting processing that occurred before withdrawal.
Legal obligations: to comply with applicable accounting, tax, consumer-protection, security, and lawful-request obligations.
Sensitive personal data. The app is deliberately built so that nothing you write about a memory is sent to us, because there is nothing to write. What we hold is that a session was completed, when, and which of four life stages you selected — no description, no content, and nothing about your health. We do not consider that record to be special-category data under Article 9 GDPR, and we do not ask you for anything that would be. We nonetheless treat it as confidential: it is stored under rules that restrict every record to the session that created it, it is never analysed, never used for advertising or profiling, never used to train artificial-intelligence models, and you can delete all of it at any time as described in section 10.
6. How we use personal data
We use personal data to:
create and maintain your anonymous session;
deliver audio sessions and keep your journey record;
verify and manage subscription access;
respond to support and privacy requests;
maintain security, prevent fraud, and troubleshoot technical problems;
understand high-level use of the app and improve its reliability, where permitted; and
comply with legal obligations.
We do not sell personal data. We do not use your journey record for advertising, ad targeting, profiling, data brokerage, or the training of artificial-intelligence models. We do not share personal data for cross-context behavioural advertising, and the app contains no advertising software and no advertising identifier. We do not send marketing email from the app; the newsletter on our website is separate and requires your consent.
7. Service providers and disclosures
We disclose personal data only as necessary to providers acting on our behalf, to Apple or Google in connection with subscriptions, during a lawful business transaction, or where required by law. Our providers may process information only for the services they provide to us and under contractual confidentiality and data-protection obligations.
Authentication — Google Firebase Authentication: Provided by Google Ireland Limited, Ireland, and Google LLC, United States. Processes a randomly generated session identifier. No name, email address, or profile information is required for authentication.
Database and hosting — Google Cloud Firestore: Provided by Google Ireland Limited, Ireland, and Google LLC, United States. Stores your session identifier, subscription status, completed-session record, and selected life stage. No memory titles, personal notes, or descriptions of your memories are collected.
Analytics — Google Analytics for Firebase: Provided by Google Ireland Limited, Ireland, and Google LLC, United States. Processes usage events, your session identifier, an app-instance identifier, and device and app characteristics.
Crash reporting — Firebase Crashlytics: Provided by Google Ireland Limited, Ireland, and Google LLC, United States. Processes crash reports, stack traces, device and app information, and your session identifier.
Subscription management — RevenueCat, Inc., United States: Processes your session identifier, subscription product, purchase and transaction identifiers, subscription status, and storefront information.
App stores and payment — Apple Inc. and Google LLC, United States: Process purchase and entitlement information and manage payments through their respective platforms.
Customer support — Google Workspace: Provided by Google Ireland Limited, Ireland. Processes the content of your support correspondence and the email address you voluntarily use to contact us.
Push notifications: none. The app does not send push notifications and contains no push-notification service.
No other software development kit in the app transmits personal data to a third party. Information the app keeps on your device only — whether you have already read the Heal a Wound introduction, which daily reflection you are on, a copy of your journey record so that the app works without a connection, and the key material used to decrypt the audio — stays on the device and is not sent to us. Deleting your data in the app clears it, and so does deleting the app.
8. International transfers
Mayanfa and its providers may process data outside your country, including outside the European Economic Area or the United Kingdom. Where required, we rely on an adequacy decision, on approved standard contractual clauses, or on the UK International Data Transfer Addendum. Your session identifier and journey record are stored in Google's European Union multi-region (eur3). Transfers to RevenueCat, Inc. in the United States are covered by standard contractual clauses. Information about relevant safeguards may be requested at support@mayanfa.com.
9. Data retention
We retain personal data only for as long as necessary for the purposes described above and as required by law:
Session identifier and subscription flags: For as long as the session exists. Deleted when you delete your data in the app;
Journey record: Deleted from our database immediately when you delete your data in the app;
Usage analytics: 14 months from collection;
Crash and diagnostic logs: 90 days;
Subscription and transaction records: 10 years, as required by French accounting and tax law;
Support communications: 3 years after our last exchange with you; and
Backups: We do not maintain long-term backups of the database. Our provider retains an internal version-history window of one hour, after which deleted content is unrecoverable.
10. Deleting your data
You can delete everything yourself in the app, under Profile → Delete Account. Your journey record and your session are deleted from our database, and the anonymous session itself is removed, so nothing remains that is linked to you — except information we must retain to comply with law, resolve disputes, prevent fraud, or enforce our agreements, such as the transaction records described in section 9.
Because there is no account, no password, and no email address, this is irreversible and we cannot recover your journey record afterwards, or move it to another device. The same is true if you delete the app or change device. An active subscription can be restored on a new device with "Restore Purchase"; the journey record cannot.
Deleting your data does not automatically cancel an Apple App Store or Google Play subscription. Subscriptions must be cancelled separately in the relevant store account settings.
11. Your privacy rights
Depending on where you live, you may have the right to:
request access to personal data we hold about you;
request correction of inaccurate data;
request deletion of personal data;
restrict or object to certain processing;
receive certain data in a portable format;
withdraw consent where processing is based on consent;
opt out of the sale or sharing of personal information or targeted advertising, where applicable; and
appeal a refusal of a privacy request, where applicable law provides that right.
Identifying your data. Because we hold no name, email address, or other identifier for you, we cannot link a request to your data unless you give us the "Support ID" shown in the app under Profile. Copy it before you delete the app, because we cannot recover it afterwards. Where we genuinely cannot identify the data you are asking about, Article 11 GDPR does not require us to comply with an access, correction, deletion, restriction or portability request; we will say so rather than guess. Deleting your data in the app requires no request and no identification at all, and is the fastest route.
We will not discriminate against you for exercising a privacy right. To submit a request, contact support@mayanfa.com and state the right you wish to exercise. You may also use an authorised agent where applicable law permits it. We respond within one month, as required by the GDPR.
If you are in France, you may lodge a complaint with the Commission Nationale de l'Informatique et des Libertés (CNIL), www.cnil.fr. If you are elsewhere in the EEA, you may complain to the data-protection authority in your country. If you are in the United Kingdom, you may complain to the Information Commissioner's Office. We encourage you to contact us first so that we can try to resolve your concern.
12. California and other US state notices
Where US state privacy laws apply to Mayanfa, residents may have rights to know, access, correct, delete, or obtain a copy of personal information, and to opt out of its sale, sharing, or use for targeted advertising. Mayanfa does not sell personal information, does not share it for cross-context behavioural advertising, and does not use it for targeted advertising. To exercise a right, contact support@mayanfa.com.
13. Children
Lighten Journey is intended only for people aged 18 or older and is not directed to children. We do not knowingly collect personal data from children. If you believe a child has provided personal data, contact support@mayanfa.com so that we can investigate and delete it where required.
14. Security
We use administrative, technical, and organisational safeguards designed to protect personal data:
all traffic between the app and our providers is encrypted in transit using TLS;
data stored with our hosting provider is encrypted at rest;
database rules restrict every record to the session that owns it, so one user cannot read another's data;
the guided audio recordings are encrypted with AES-256, and the decryption key is held in the device's secure storage rather than in the app itself; and
access to production systems is restricted to those who need it.
No method of electronic transmission or storage is completely secure, and we cannot guarantee absolute security.
15. Automated decision-making
We do not use personal data to make decisions that produce legal or similarly significant effects through solely automated processing.
16. Changes to this policy
We may update this Privacy Policy to reflect changes to Lighten Journey, our providers, or applicable law. We will update the "Last updated" date and provide additional notice where required. Material changes will apply prospectively unless the law permits otherwise.
17. Contact
Mayanfa — SASU
103 704 961 R.C.S. Paris — EUID FR7501.103704961
30 rue des Cordelières, 75013 Paris, France
Email: support@mayanfa.com
