This policy explains what Levity collects, why, how we protect it, and the choices you have. Levity is an iOS app that is one quiet home for your day: your calendar, workouts, meals, journals, routines, and a small circle of people you choose. We have written this in plain language because your day is personal and you deserve to understand exactly how it is handled.
1. Who we are
Levity is operated by Mindroot Ltd, a company registered in England and Wales with company number 16543299, whose registered office is at 71-75 Shelton Street, London, England, WC2H 9JQ. Mindroot Ltd is the data controller for the personal data described in this policy. We are registered with the Information Commissioner’s Office as a data protection fee payer, registration reference ZB958997. If anything here is unclear, email [email protected].
2. Who this applies to
Levity is intended for people aged 17 and over (see “Children” below). This policy applies to the Levity iOS app and to this website.
3. What we collect
Account and identity
Levity supports Sign in with Apple only. When you sign in, Apple gives us a stable, app-specific user identifier and, depending on your choice, your name and an email address (which may be Apple’s private relay address). We create a profile for you: your chosen username, display name, and optional avatar. We never receive or store your Apple ID password, and we never ask for a phone number.
Your day
What you put into Levity so the app can work: plans, tasks, workouts, meals, recipes, routines, journals, notes, and timelapse photographs. This content is private by default and much of it lives on your device first. It only becomes visible to others when you deliberately share it with your circle.
Messages
Messages and the photographs in them are end-to-end encrypted: they are sealed on your phone and our server stores ciphertext it cannot read. Every message expires within a week at most, and expired content is deleted from our storage, not just hidden. A “one look” photograph is deleted when it is opened. The encryption keys live in your device’s keychain and do not leave it; the app states its current limits in plain words where they matter.
Your circle
Friendships are mutual. People are suggested through the friendship graph (friends of your friends, ranked by how many you have in common), never through your address book. Whether you can be found at all is controlled by one switch in the app.
Contacts and your phone’s calendar
If you choose to invite someone, your address book is read on the device only to address the invitation. Nothing from your contacts is uploaded to us. If you choose to show your phone’s calendar, it is read on the device through Apple’s EventKit, read-only, and is never uploaded.
Steps, weight and height
If you choose to show your steps, they are read from Apple Health on the device, read-only. Levity never writes to Health, and your step counts are not sent anywhere by the app; the only exception is a figure you deliberately put on a card and share yourself. Your body records, weight and height, are stored on your phone only. There is no server column for a body and none is planned.
Meal scanning and drafted content
If you use the Pro features that read a plate from a photograph, draft a list from a sentence, or write a journal page from your week, that photograph, sentence or digest is sent through our server to OpenAI to produce the answer, and is used only to answer that request. The free logging path sends nothing anywhere: your photo and your numbers stay in your record.
Subscriptions
Levity Plus and Levity Pro are billed by Apple under your Apple ID. Entitlements are managed through RevenueCat. We never see or store your payment details.
Notifications and presence
If you allow notifications, we hold a device token to deliver them. Whether a notification shows the content of a message on your lock screen is your setting. Presence (who is around, typing, read marks) is symmetric: if you turn yours off, you stop broadcasting and stop seeing everyone else’s at the same moment.
4. What we do not do
- No advertising, and no advertising identifiers.
- No selling or renting your data, ever. The subscription is the business model.
- No tracking you across other apps and websites.
- No phone numbers, and no address book uploads.
5. Our lawful bases
UK data protection law (the UK GDPR and the Data Protection Act 2018) requires a lawful basis for each use of personal data. Ours are:
- Performing our contract with you: creating your account, storing what you put into Levity, delivering messages and shares to the people you chose, and honouring your subscription.
- Legitimate interests: keeping the Service secure, preventing abuse and spam, and understanding at an aggregate level whether the Service works. We weigh these against your rights, and we do not use analytics brokers or ad networks.
- Consent: the optional readings you switch on yourself, such as notifications, and the Pro features that send a photograph or a sentence to be read. Contacts, your phone’s calendar and Health are read on the device under Apple’s own permission sheets and are not uploaded, as described above. You can withdraw consent at any time in the app or in iOS Settings.
- Legal obligation: keeping what the law requires us to keep, and answering lawful requests.
6. Who processes data for us
We use a small number of processors to run the service, each only for its job: Apple (sign in, billing, push notifications), Supabase (database, storage and realtime hosting), RevenueCat (subscription entitlements), and OpenAI (only when you ask for a scan or a drafted piece of writing). We do not use analytics brokers or ad networks.
7. International transfers
Some of our processors operate infrastructure outside the United Kingdom, including in the United States. Where personal data leaves the UK, we rely on safeguards recognised by UK law: the UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses, or an adequacy decision where one applies. Messages travel as ciphertext wherever the servers are.
8. Retention and deletion
Messages expire within a week at most and are deleted from storage, including the photographs behind them. Your own records (workouts, journals, meals and the rest) are kept until you delete them or your account. Deleting your account, in the app or by emailing [email protected], removes your data, not just your login. In the app: your face in the masthead, Edit, then Delete account at the foot.
9. Security
Everything travels encrypted in transit. Messages are additionally end-to-end encrypted as described above, local files holding message content use iOS file protection, and encryption keys are held in the device keychain and excluded from cloud backups. No system is perfect; where our encryption has limits, the app says so in plain words rather than implying more than it delivers.
10. Your rights
Under the UK GDPR you have the right to access your personal data, to correct it, to delete it, to restrict or object to some processing, to port what you gave us to another service, and to withdraw consent where consent is the basis. Email [email protected] and a real person will help, free of charge and normally within one month.
You also have the right to complain to the UK supervisory authority, the Information Commissioner’s Office, at ico.org.uk or by calling 0303 123 1113. We would appreciate the chance to help first, but you do not have to give us one.
11. Children
Levity is not directed to children and is intended for people aged 17 and over. If you believe a child has created an account, contact us and we will delete it.
12. Changes to this policy
If we change this policy in a meaningful way, we will update the date at the top and, for significant changes, say so in the app. Continued use after a change means you accept the updated policy.
13. Contact
Email [email protected], or write to Mindroot Ltd, 71-75 Shelton Street, London, England, WC2H 9JQ.