LotusfoldBack to home

Last updated · May 8, 2026

Privacy Policy

Lotusfold is built on a simple promise: what you write here is yours. This page describes what we collect, why we collect it, and the choices you have. If anything below is unclear, write to us at hello@lotusfold.com.

What we collect

Account details. When you create an account, we store your email address, a display name you choose, and an authentication token. If you sign in with Google, we receive your email and profile photo from Google.

Reflection content. The questions you answer inside Lotusfold are stored encrypted at rest. Until both partners submit a section, your answers are visible only to you. After a mutual reveal, both partners can read each other's answers within that shared space.

Couple metadata. If you pair with a partner, we link your accounts via a shared couple record so the submit-to-reveal mechanic works. Either partner can dissolve the link in Settings.

Operational logs. We log error events and basic request metadata (URL, status code, anonymized IP) for security and reliability. We do not log the contents of your reflections.

What we do with it

  • Run the product you signed up for.
  • Authenticate you and protect your account.
  • Send essential transactional email (password reset, partner invites). We do not send marketing email without an explicit opt-in.
  • Diagnose bugs, prevent abuse, and improve the experience.

What we do not do

  • We do not sell your data. Ever.
  • We do not use your reflection content to train AI models.
  • We do not share your data with advertising networks.
  • We do not read your reflections except as required to fix a specific bug you report, and never without your consent.

Your rights

You can export your data, correct it, or delete your account at any time from Settings. Account deletion removes your reflection content within 30 days. Backups are purged within 90 days. If you paired with a partner, your shared sections are anonymized on deletion so your partner's view of their own work remains intact.

Cookies

We use a single first-party cookie to keep you signed in. We do not use third-party advertising cookies. We use minimal, privacy-respecting analytics to understand which features are used — never linked to a specific user.

Subprocessors

We rely on Google Cloud (Firebase Authentication, Firestore) and Vercel (hosting, edge network). All data is stored in regions chosen for low latency and strong privacy regimes.

EU / UK / California rights

If you reside in the EU, UK, or California, you have additional rights under the GDPR, UK GDPR, and CCPA — including the right to access, rectify, port, restrict, and delete your personal data, and the right to object to certain processing. We honor these rights regardless of where you live. To exercise them, write to hello@lotusfold.com and we'll respond within 30 days. We do not sell or “share” personal information as those terms are defined under California law.

Retention

We retain account data while your account is active. Reflection content is deleted within 30 days of account deletion. Operational logs are retained for up to 90 days, then purged.

Changes

If we materially change this policy, we'll notify you by email and inside the product before the change takes effect.

Contact

Privacy questions, takedown requests, and data exports go to hello@lotusfold.com.


See also: Terms of Use