Back to LastLit

Privacy policy

Draft, under legal review.

Last updated: 6 October 2026

This policy explains what LastLit collects, why, who helps us run it, how long we keep things, and what you can do about it. It covers the LastLit app (iPhone, Android and app.lastlit.com), this website (lastlit.com) and the waitlist.

LastLit is run by [TO CONFIRM: legal name of the company or person], [TO CONFIRM: postal address]. For anything about your data, email support@lastlit.com.

The short version

What we collect, and why

What Why
Username It's how other people see you next to your photos and notes.
Email address To sign you in, and to reach you about your account.
Date of birth To check you are 18 or over when you sign up. We store it with your account.
Password To sign you in. We only ever store a scrambled version (a bcrypt hash), never the password itself.
Photos and captions To show your photo to people while it's lit, and to show your past photos to you on your Me screen. Before a photo is stored, our server copies it without its metadata: no location, camera details or other EXIF data. The app also shrinks it to at most 2048 pixels and saves it as a JPEG first.
Spotlight notes and links When your photo holds the spotlight, you can add a note and one link. A moderator reads it before anyone else sees it.
Votes (Keep or Fade) and skips To count each window's result. Nobody else can see how you voted: the owner sees only the totals. We also record which photos the feed has shown you, so you can vote on them and aren't shown the same one twice in a window. That record is deleted when the window ends.
Reports and blocks To review photos people report, and to keep the people you block out of your feed (and you out of theirs). The person you report is never told who reported them.
Moderation results Every photo is checked automatically before anyone sees it. We keep the scores the check returns (for example, how likely a photo is to contain nudity), never the image itself, so we can see why a photo was let through or turned away.
Notifications So your inbox can show what happened to your photos (kept, faded, in the spotlight, notes approved or rejected).
Push token If you allow notifications on your phone, the app sends us a token that lets us send them to that device. You can turn each kind off in Settings, and signing out removes the token for that device.
Settings Your notification choices.
Account status If a moderator suspends or closes your account for breaking our rules, we record that, when, and why, so the decision can be enforced and reviewed.
IP address When you aren't signed in, we use your IP address to limit how many requests can come from one place (rate limiting), which stops abuse. We hold it only in the server's memory for a few minutes. We don't write it to our own logs. Our hosting providers may log it separately (see "Who helps us run LastLit").
Waitlist sign-ups On the website, you can join the waitlist with your email and a username. We store the email, the username we hold for you, when you agreed and which version of this policy you agreed to, which of the two forms on the page you used, and the campaign tag if you came from one of our links. We use it to hold your username and to tell you when LastLit launches.
Website page views We count page views on lastlit.com with Vercel Web Analytics. It uses no cookies, and we remove the private token from unsubscribe links before a view is counted.

On your device, the app keeps your sign-in token (in the phone's secure storage, or your browser's local storage on the web) and a few small preferences, such as which results you've already seen. Neither the app nor the website sets cookies.

We don't collect your contacts, your location, or your photo library. When you share a photo you pick it with your phone's own picker, and the app only ever sees the one photo you choose.

Who can see what

Who helps us run LastLit

We use these services to run LastLit. They process data only to provide their service to us.

Service What it does for us What it handles
MongoDB Atlas Our database Everything in the table above, apart from the images themselves and website page views
Railway Runs our server (api.lastlit.com) Every request to the server, including IP addresses
Vercel Hosts this website and the web app Website visits, page views (Web Analytics), IP addresses
Cloudinary Stores and delivers photos, and checks each new photo automatically Photos, and the moderation scores
Amazon Rekognition (through Cloudinary) The automatic check for nudity, violence and similar content Each new photo, as it's checked
Expo (with Apple and Google) Delivers push notifications to your phone Your push token and the notification's text

[TO CONFIRM: the regions where each service stores data, and the safeguards for transfers outside the UK or EEA, such as Standard Contractual Clauses.]

We don't send email yet. When we do, it will be through an email provider we'll add to this list first. [TO CONFIRM: email provider.]

How long we keep things

Your rights

Wherever you live, you can:

We'll reply within one month. We may ask you to confirm the request comes from your account's email address, so nobody else can ask for your data.

If you're in the UK or the EEA (GDPR)

We rely on these legal bases:

[TO CONFIRM: these legal bases, and whether we need an EU or UK representative.]

You also have the right to object to processing based on legitimate interests, to ask us to restrict processing, and to complain to your local data protection authority (in the UK, the Information Commissioner's Office).

If you're in California (CCPA)

We don't sell or share your personal information, as the CCPA defines those words, and we don't use it for targeted advertising. You have the right to know what we collect and why (this policy), to delete it, and to correct it, as described above. We won't treat you differently for using these rights.

Age

LastLit is for people 18 and over. You confirm your date of birth when you sign up, and we turn away anyone under 18. If we learn an account belongs to someone under 18, we'll delete it. If you think someone under 18 is using LastLit, report their photo with "Someone under 18", or email support@lastlit.com.

Changes to this policy

When this policy changes, we'll post the new version here and change the date at the top. If you're on the waitlist, we record which version you agreed to. [TO CONFIRM: how we'll tell people about important changes.]

Contact

support@lastlit.com