Last updated: 15 September 2026
LightScout ("we", "our", or "us") operates the LightScout mobile application and the website at lightscout.app. This policy explains how we collect, use, and protect your information.
Location data: When you use location-based features, the app accesses the location you choose or permit and sends it to our service providers to generate a photography guide. Location details may form part of a guide you save to your account. You can control device location permission in iOS Settings.
Camera and experience preferences: Your selected camera type and experience level are used to personalise guides and may be sent to our service providers as part of a guide request.
AI Scout requests and Google Gemini: To create a Scout, LightScout sends Google Gemini the place you choose, which can include its name or address, precise coordinates and search area; the Scout type, date, time and time zone; your camera type and photography experience; your language and measurement settings; and weather, sunrise, sunset, sun direction, golden-hour and blue-hour details calculated for that place and time. Google services also receive the authenticated account identifier needed to process the request through the Firebase and Google Cloud authorisation route; that identifier is not embedded in the text prompt given to the model. The Scout prompt does not include your name or email address. Google Gemini uses these details to create the photography plan you requested.
In LightScout 2.7.0, LightScout asks for explicit permission before the first such request. Choosing Not now lets you continue browsing. Withdrawing permission in LightScout Settings blocks new Google Gemini requests; Scouts you already saved remain available. Withdrawal cannot recall a request that has already been sent or delete provider-held records by itself.
Purchase information: In-app purchases are processed by Apple through the App Store. We do not collect or store payment details.
Website waitlist: If you join the weekly-report or Android waitlist, we store the email address you submit and the page source in Supabase so we can send those updates. You can unsubscribe from an email or ask us to delete the address.
Website analytics: We use Cloudflare Web Analytics to measure aggregate website traffic, such as pageviews, referrers, browser or device category, and approximate country. It is privacy-focused and does not use cookies or collect visitors' personal data. We do not send email addresses, precise locations, account identifiers, or free-text search terms to website analytics.
App analytics and attribution vary by app version. LightScout 2.5.0 (build 9), which may remain installed after a later version is released, uses AppsFlyer's standard iOS SDK for App Store attribution. After sign-in, this version supplies the LightScout account identifier as the AppsFlyer customer user ID, may collect AppsFlyer installation identifiers and Apple's advertising or vendor identifiers when available, records the new-account, completed-scout and completed-purchase conversion signals, and passes the AppsFlyer identifier to RevenueCat. This build did not disable AppsFlyer integrated-partner sharing before the service started. We therefore treat its User ID, Device ID and Product Interaction data as linked and used for advertising attribution and measurement. It is not used by LightScout to personalise advertising.
LightScout 2.6.0–2.7.1 use AppsFlyer Strict for bounded App Store attribution. They do not send the raw LightScout account identifier to AppsFlyer, disable advertising-identifier and vendor-identifier collection for AppsFlyer before start, and block AppsFlyer integrated-partner sharing. Product analytics uses a server-issued pseudonymous identifier and bounded product events rather than an account identifier, location, report or free-text values.
Purchases and Device ID in LightScout 2.6.0 and later. RevenueCat administers subscriptions, one-time credit packs, entitlements and purchase restoration. Its iOS SDK independently sends Apple's vendor identifier (IDFV) as a Device ID with its backend requests for purchases and App Functionality. Removing the app's former AppsFlyer-to-RevenueCat forwarding does not mean that RevenueCat receives no device identifier. We do not use this RevenueCat identifier for cross-company tracking.
Optional app analytics in LightScout 2.7.0–2.7.1: LightScout keeps Firebase Analytics and AppsFlyer collection off unless you choose Share usage analytics. If allowed, these services may receive app-use events; device and app information, including approximate location derived from network information; purchase and subscription events; camera type; photography experience; and an app-scoped account identifier. We use this information to understand activation, reliability and marketing effectiveness. Scout content, selected places, searches and precise coordinates are not included in these analytics events. This choice does not affect app features or purchases.
Optional app analytics in LightScout 2.7.2 builds with “Share usage analytics”: LightScout keeps Firebase Analytics disabled in this version. If you choose Share usage analytics, the app sends app-use events, app information, purchase and subscription events, camera type and photography experience to PostHog's EU service and keeps the existing optional AppsFlyer Strict attribution behaviour. PostHog receives no session replay or screen auto-capture, Scout content, searches, place details, location or precise coordinates. PostHog geoIP processing is disabled. Events before sign-in may be connected to later activity only through a random, server-issued analytics identifier; this is not your LightScout account ID, and no prior Google Analytics or pre-consent event export is joined to it. Firebase Crashlytics and the authenticated Firebase/Google route used for AI Scout generation remain separate from optional product analytics.
You can withdraw this choice at any time in LightScout Settings. In 2.7.2, withdrawal stops future PostHog uploads, drops unsent PostHog events queued on the device, cancels local uploads, resets the analytics correlation state and does not require account deletion. It cannot recall an event already sent or an upload already accepted by a provider. Refusing analytics remains in force across upgrades; an old accepted decision must be renewed under the optional “Share usage analytics” control in Settings. For 2.7.0–2.7.1 choices, the version-specific Firebase behaviour described above applies. Contact support@lightscout.app for a broader data-rights request.
Product statistics in builds with “Help improve LightScout”: This setting is on by default, including before sign-in. An earlier explicit refusal remains off after an upgrade. No separate device-analytics opt-in is required in builds whose disclosure mentions funnel progress and feature reach. The app measures feature use, activation, purchase-flow outcomes, return visits and reliability solely to improve LightScout. Each installation calculates ordered onboarding, activation and purchase funnel progress; daily, weekly and monthly feature reach; sessions; daily returns through 90 days and weekly returns through 12 weeks; and repeat successful Scout use. Results include bounded performance ranges, app version/build, plan, photography preferences and controlled feature/outcome categories. The device retains only the summary state needed for these calculations, not an action history or analytics identifier. Observation windows renew after 90 days on the next relevant use and distinguish initial from continuing measurement. Calendar-period summaries are replaced when the period changes. This includes existing installations after an upgrade and is not a count of new downloads or identified people.
Counts pass through LightScout's endpoint hosted by Supabase before reaching PostHog's EU service. The endpoint does not forward the device's IP address, cookies, account credentials or device headers to PostHog, and does not log analytics request contents. Supabase necessarily receives network information to deliver and secure the request. PostHog receives population statistics with person-profile creation and geoIP processing disabled. We use these statistics solely to assess and improve the app; we do not construct individual behavioural profiles or join these statistics to account, advertising or purchase records. Existing individual data from earlier builds remains subject to the earlier disclosures and deletion process.
Statistical contributions are grouped by UTC day, release channel, cohort or calendar period and controlled categories. They go through LightScout's first-party relay to PostHog's EU service. No account or installation identifier, device fingerprint, session identifier, searches, selected places, Scout content, photographs or locations enter this statistical transport. Delivery references prevent duplicate uploads and are not reused across statistical rows. The relay does not forward client IP addresses, cookies or request headers; PostHog person profiles and geoIP processing are disabled. Unsent contributions remain bounded and expire after at most 14 UTC days. The figures describe how installations use the app; LightScout cannot open an installation's activity history or join these contributions to account, advertising or other-service data. Earlier counter builds calculated only fixed day-1, day-7 and day-28 cohorts. Earlier builds that offered a separate Device usage analytics choice could send retained installation histories after permission; updated builds stop that mode and discard its unsent events. An existing deletion reference remains locally available in Settings for requests about previously sent data and is never used for new collection. Device backups can carry local statistical state and preferences. Turning off Help improve LightScout stops future statistics, clears unsent contributions and local calculation state, and does not affect features or purchases. It cannot recall an upload already accepted by a provider.
These builds do not start AppsFlyer's individual attribution collection. When product statistics are enabled in an App Store installation, the app registers install attribution through Apple's SKAdNetwork mechanism. Apple controls the privacy thresholds, delays and information included in those postbacks; copies use the configured AppsFlyer receiving endpoint. This is limited install attribution, not cross-app profiling or a user-level marketing journey. Turning off Help improve LightScout stops future counter collection and registration attempts and removes unsent counters. It cannot recall a request or Apple attribution already registered. App features, purchases, account processing, Gemini permission and reliability diagnostics remain separate.
App reliability diagnostics: In normal production releases, LightScout uses Google Firebase Crashlytics independently of the optional usage-analytics choice. Crashlytics receives crash reports and bounded non-fatal diagnostics used to find and fix reliability problems. These reports can include stack traces; app version; device model, architecture and operating-system details; relevant process, memory and storage state; a Crashlytics installation or session identifier; and developer logs or fixed diagnostic fields associated with the failure. LightScout's custom account diagnostic is limited to a fixed processing stage and bounded error type; it does not deliberately add your name, email address, Scout prompt, selected place or precise coordinates. Crash and Other Diagnostic Data are linked and used for App Functionality, not advertising or cross-company tracking. Firebase states that Crashlytics keeps crash stack traces and associated installation identifiers for 90 days before starting removal from live and backup systems. Withdrawing optional usage analytics or deleting your LightScout account does not itself recall Crashlytics reports already sent. Contact support@lightscout.app for a broader data-rights request.
We use the information described above to provide, secure, measure and improve LightScout, including the version-specific attribution described above. We do not sell or rent personal data, and we do not use it to personalise third-party advertising. Build 9's attribution sharing is disclosed above; LightScout 2.6.0 and later block AppsFlyer integrated-partner sharing.
Account data, saved guides, credits, and website waitlist submissions are stored using Supabase. Guide requests are processed by our AI and infrastructure providers. We use HTTPS encryption for data in transit and service-level access controls.
In LightScout 2.6.0 through 2.7.1, when analytics collection is enabled and you sign in, LightScout uses a server-issued random analytics identifier to recognise your activity across your devices. It is not your account ID and does not encode it. Activity before sign-in remains app-instance or session based and is not joined to your later account. Google Analytics event data is retained for two months and user data for up to 14 months, with the user-data period reset by new activity. In LightScout 2.7.2 builds with “Share usage analytics”, PostHog stores the bounded individual events described above in its EU project. Builds with “Help improve LightScout” send the basic aggregate counters described above unless the separate Device usage analytics setting is allowed. That setting sends installation-level events without an account mapping. Neither a historical analytics acceptance nor acceptance of basic statistics grants permission for this mode. Automatic expiry is not currently enforced for PostHog event data. You can contact us to request deletion of data associated with your analytics identifier. Withdrawal cannot recall data already sent.
Google AI processing: Scout requests are processed through LightScout's authenticated server route and Google Cloud's Vertex AI Gemini service. Google's service terms state that customer data is not used to train or fine-tune AI or machine-learning models without prior permission. Google's published Gemini models cache project-isolated copies of inputs, generated outputs and derived data in memory, not at rest, for up to 24 hours to improve service performance; the production project currently uses this default cache setting. Request-response logging is not configured for the production Gemini model. If Google's automated safeguards flag suspicious activity and the account is within abuse-monitoring scope, Google may retain the flagged prompt for up to 90 days solely to investigate abuse. Google states that this material is not used to train or fine-tune models. LightScout does not promise zero provider retention. Withdrawing in-app permission stops future Scout requests; it does not recall an in-flight request or by itself delete provider-held cache or logs.
Generated Scout responses: LightScout stores each completed generated Scout response in a private account-linked server run record so the same paid result can be returned after a retry, interrupted connection or relaunch. This happens even when you do not separately save the Scout in the app. A restricted service-only quality process may read one response ephemerally for a bounded sample or reported issue; the review interface does not return the account owner or request identity. Generated run responses currently have no separate scheduled expiry and remain until the associated LightScout profile or account is deleted. Deleting the account cascades those private run records. Separately saved Scouts remain subject to the save and deletion controls shown in the app.
Retention and deletion of attribution and purchase identifiers: The verified Google Analytics retention periods stated above are unchanged. We have not destination-verified a custom retention or deletion period for legacy AppsFlyer identifiers or RevenueCat purchase/device mappings, so this policy does not invent one or claim those vendor-held records are immediately deleted. Deleting a LightScout account removes LightScout account data and our active analytics-identity mapping through the documented deletion route; it does not delete Apple's purchase records. We will update this policy after any vendor-side containment, retention or deletion change is separately authorised and verified in its destination.
LightScout uses the following third-party services:
We use these providers only for the purposes described in this policy and require them, through their applicable service terms and data-processing arrangements, to protect personal data to the same or an equivalent standard. LightScout remains responsible for telling you what is sent and why, obtaining required permission, and responding to data-rights requests we control. A provider may retain or delete data under the specific limits described above and its applicable terms.
You can request deletion of any data associated with your account by contacting us at support@lightscout.app. You can revoke location permissions at any time through your device settings.
You can change Google Gemini permission and the build-specific product-statistics or optional usage-analytics setting separately in LightScout Settings. These controls stop future requests or collection; they do not automatically recall data already sent. You can request deletion of your LightScout account in the app and contact support@lightscout.app about provider data-rights requests. Apple purchase records are controlled by Apple and are not deleted when a LightScout account is deleted.
For privacy-related questions, contact us at support@lightscout.app.