Home/Privacy Policy

Privacy Policy

Last updated: 6 August 2026

Introduction

LightScout ("we", "our", or "us") operates the LightScout mobile application and the website at lightscout.app. This policy explains how we collect, use, and protect your information.

Information We Collect

Location data: When you use location-based features, the app accesses the location you choose or permit and sends it to our service providers to generate a photography guide. Location details may form part of a guide you save to your account. You can control device location permission in iOS Settings.

Camera and experience preferences: Your selected camera type and experience level are used to personalise guides and may be sent to our service providers as part of a guide request.

Purchase information: In-app purchases are processed by Apple through the App Store. We do not collect or store payment details.

Website waitlist: If you join the weekly-report or Android waitlist, we store the email address you submit and the page source in Supabase so we can send those updates. You can unsubscribe from an email or ask us to delete the address.

Website analytics: We use Vercel Web Analytics to measure pageviews and the following actions: call-to-action impressions, App Store clicks, waitlist starts/successes/failures, and outbound map clicks. Measurement may include the page route, CTA placement, referrer, browser/device category, approximate country, and the allowlisted campaign fields utm_source, utm_medium, utm_campaign, and utm_content. We strip other query fields before analytics is sent and do not put email addresses, precise locations, account identifiers, or free-text search terms in analytics events. Vercel Web Analytics is cookieless.

App analytics and attribution vary by app version. LightScout 2.5.0 (build 9), which may remain installed after a later version is released, uses AppsFlyer's standard iOS SDK for App Store attribution. After sign-in, this version supplies the LightScout account identifier as the AppsFlyer customer user ID, may collect AppsFlyer installation identifiers and Apple's advertising or vendor identifiers when available, records the new-account, completed-scout and completed-purchase conversion signals, and passes the AppsFlyer identifier to RevenueCat. This build did not disable AppsFlyer integrated-partner sharing before the service started. We therefore treat its User ID, Device ID and Product Interaction data as linked and used for advertising attribution and measurement. It is not used by LightScout to personalise advertising.

LightScout 2.6.0 (build 11) uses AppsFlyer Strict for bounded App Store attribution. It does not send the raw LightScout account identifier to AppsFlyer, disables advertising-identifier and vendor-identifier collection for AppsFlyer before start, and blocks AppsFlyer integrated-partner sharing. Its product analytics uses a server-issued pseudonymous identifier and bounded product events rather than account, location, report or free-text values.

Purchases and Device ID in LightScout 2.6.0. RevenueCat administers subscriptions, one-time credit packs, entitlements and purchase restoration. Its iOS SDK independently sends Apple's vendor identifier (IDFV) as a Device ID with its backend requests for purchases and App Functionality. Removing the app's former AppsFlyer-to-RevenueCat forwarding does not mean that RevenueCat receives no device identifier. We do not use this RevenueCat identifier for cross-company tracking.

How We Use Your Information

We use the information described above to provide, secure, measure and improve LightScout, including the version-specific attribution described above. We do not sell or rent personal data, and we do not use it to personalise third-party advertising. Build 9's attribution sharing is disclosed above; build 11 blocks AppsFlyer integrated-partner sharing.

Data Storage and Security

Account data, saved guides, credits, and website waitlist submissions are stored using Supabase. Guide requests are processed by our AI and infrastructure providers. We use HTTPS encryption for data in transit and service-level access controls.

In LightScout 2.6.0 (build 11), when you sign in, LightScout uses a server-issued random analytics identifier to recognise your activity across your devices. It is not your account ID and does not encode it. Activity before sign-in remains app-instance or session based and is not joined to your later account. For this build, Google Analytics event data is retained for two months and user data for up to 14 months, with the user-data period reset by new activity.

Retention and deletion of attribution and purchase identifiers: The verified Google Analytics retention periods stated above are unchanged. We have not destination-verified a custom retention or deletion period for legacy AppsFlyer identifiers or RevenueCat purchase/device mappings, so this policy does not invent one or claim those vendor-held records are immediately deleted. Deleting a LightScout account removes LightScout account data and our active analytics-identity mapping through the documented deletion route; it does not delete Apple's purchase records. We will update this policy after any vendor-side containment, retention or deletion change is separately authorised and verified in its destination.

Third-Party Services

LightScout uses the following third-party services:

Your Rights

You can request deletion of any data associated with your account by contacting us at support@lightscout.app. You can revoke location permissions at any time through your device settings.

Contact

For privacy-related questions, contact us at support@lightscout.app.