Privacy Policy
Last updated 2 September 2026
Lenara is a sleep app made by one person. It asks for as little as it can, keeps it in one place and sells none of it. This page says exactly what is collected, why, where it goes and how to get rid of it.
Who is responsible
Mehmet Ozay, an individual developer, is the data controller for Lenara. Contact: mehmetozay94@gmail.com.
What we collect
| Data | Why | Legal basis |
|---|---|---|
| Account identifier and email address | So your library, subscription and progress follow you to a new device | Performance of a contract |
| Display name and profile photo, if your provider gives one | Shown to you on the Profile screen and nowhere else | Performance of a contract |
| Favourites, playlists, listening history and streak | The features themselves; they are the product | Performance of a contract |
| Daily listen count for free accounts | To apply the free daily limit fairly | Performance of a contract |
| Subscription status and renewal date | To know whether to unlock Pro | Performance of a contract |
| Chosen language, appearance, narration and reminder time | To give you the app you set up | Performance of a contract |
| Notification topic for your language | To send announcements in a language you read | Consent, withdrawn by turning notifications off |
| Crash reports and basic diagnostics | To find what broke | Legitimate interest in a working app |
What we do not collect
- No advertising identifiers, no ad networks, no tracking across other apps or websites.
- No location, contacts, photos, microphone or health data. The app never asks for these permissions.
- No payment details. Apple processes payments; we receive only whether a subscription is active and when it ends.
- No device push token is stored on our side — announcements are sent to a language topic, not to individuals.
- Nothing is sold, rented or shared for anyone else's marketing. Ever.
Who processes data for us
| Service | What it handles | Where |
|---|---|---|
| Google Firebase | Sign-in, database, functions, notifications, crash reports | European Union |
| RevenueCat | Subscription state | United States |
| Apple | Payment, Sign in with Apple | Global |
| Cloudflare R2 | Audio file storage and delivery | Global edge network |
Each of these acts on our instructions under a data processing agreement. Transfers outside the European Economic Area rely on the European Commission's standard contractual clauses.
Audio files
Audio is served through links that expire after fifteen minutes and are issued only to a signed-in account. The storage provider sees the request but not who you are.
How long we keep it
- Account data — until you delete your account.
- Listening history and statistics — until you delete your account, or the history from the app.
- Daily listen counters — reset every day, kept at most thirty days.
- Crash reports — ninety days.
- Subscription records — as long as tax law requires them.
Your rights
If you are in the European Economic Area or the United Kingdom you have the right to access your data, correct it, delete it, restrict or object to its processing, and receive it in a portable form. Under California law you have the right to know what is collected and to ask for deletion, and the right to opt out of sale — which is not needed here, because nothing is sold.
How to exercise them
Write to mehmetozay94@gmail.com from the address on the account. We answer within thirty days. There is no charge. If you are unhappy with the answer you may complain to your national data protection authority.
Children
Lenara is not directed at children under thirteen and we do not knowingly collect their data. If you believe a child has created an account, write to us and it will be removed.
Security
Traffic is encrypted in transit. Database rules allow an account to read and write only its own records, and the subscription field can be written only by the server — not by the app on your phone.
Changes
If this policy changes in a way that affects you, the date at the top changes and the app shows a notice on next launch. Past versions are in the public repository's history.