← Back to trylungo.com

Privacy Policy

Last updated: 4 September 2026

Controller under the GDPR

Luke Bickenbach

Dresdnerstraße 19/14

1200 Vienna, Austria

Email: hello@trylungo.com

This Privacy Policy covers the Lungo app on iOS and Android, trylungo.com, the waitlist, and enquiries sent to us. It explains which personal data we process, for which purposes, and your rights.

Lungo’s profile and progress features work locally on your device. Cloud backup is voluntary and switched off by default. Independently of cloud backup, Lungo stores a minimal pseudonymous consent record with Firebase after you make your choices; no profile, smoking, vaping, or craving data is sent for this purpose.

Lungo does not show advertising, sell personal data, or use your smoking, vaping, or craving data for advertising tracking.

1. Data processed by Lungo

a) Profile and progress data

Setup requires consumption, cost, and quit-date information appropriate to your selected smoking or vaping mode. These details enable progress and savings calculations. Motivation text and additional entries are voluntary. We process in particular:

  • the date you stopped smoking or vaping
  • previous cigarette or vape use, pack and pod sizes, and hits per pod
  • prices and currency used to calculate money saved
  • your optional motivation text
  • check-ins, check-in days, and streak
  • cravings and relapses including time, trigger, optional free text, mood, intensity, outcome, and use of the breathing exercise
  • Coach situations, strategies, helpfulness feedback, and saved strategies
  • XP, level, Smoke Buddy, item, trophy, and budget states
  • app settings such as language, currency, and reminder status
  • timestamps of your privacy acknowledgement, health-data consent, optional cloud or analytics activation, and Terms acceptance

b) Local storage

The native app stores your app data in protected device storage using Expo SecureStore. On Android, SecureStore data is removed when the app is uninstalled. On iOS, Keychain data may survive an uninstall and become available again after reinstalling an app with the same bundle ID. To delete your data reliably, use “Reset data” or “Delete account” in Settings before uninstalling.

For iPhone Home Screen widgets, after onboarding Lungo keeps an additional local copy of the quit date, consumption and price values needed to calculate savings, currency, language, and buddy appearance in storage shared by the app and widget. This copy is outside the Keychain. The widget feature itself does not send this data to a server. Account identifiers, craving histories, and free text are not copied into widget storage. Signing out, resetting the app, or deleting the account clears the personal widget copy. A widget you add displays your progress on the Home Screen, where other people looking at the screen can see it.

c) Health-related data

Information about smoking or vaping, cravings, and relapses may reveal information about your health and may constitute special categories of personal data under Article 9 GDPR. Lungo processes it only after your express consent during onboarding and solely to provide the features you request.

2. Pseudonymous consent record

During setup and when optional usage analytics changes, Cloud Firestore stores an immutable consent record under your Firebase user ID with a server timestamp. Without a signed-in account, a pseudonymous Firebase guest account is created for this purpose. After sign-in, the same identifier may be associated with your Apple or Google account; it is then not an independent or anonymous installation identifier.

The record contains the Firebase user ID, server timestamp, language, versions of the Terms, Privacy Policy, health-data and analytics consent, and your consent choices. It contains no smoking quantities, vaping use, cravings, relapses, or free text. Setup cannot be completed without transmitting this minimal record; an internet connection is therefore required even for local setup.

This record is used solely to document the giving or changing of consent under Articles 7(1) and 5(2) GDPR. It does not enable cloud backup. Unless you separately select cloud backup, profile and progress data remains on your device.

3. Optional Firebase cloud backup

Cloud backup is optional and disabled by default. Without it, profile and progress data remains on your device and all core Lungo features continue to work.

If you enable cloud backup, the profile and progress data listed in section 1 is linked to the pseudonymous Firebase ID and stored in Cloud Firestore so it can be backed up, restored, and synchronised across devices.

You may voluntarily choose Sign in with Apple or Google Sign-In during setup or later. Depending on the provider, Lungo additionally processes the provider-specific ID, your email or relay address, and any name you share. Sign-in credentials are managed by the relevant sign-in service. Guest user IDs and linked data are also personal data.

Firebase also processes technical data such as IP address, device or instance identifiers, and timestamps for authentication, synchronisation, operation, and security.

4. Lungo Plus, RevenueCat, and app stores

Lungo uses RevenueCat to display and manage Lungo Plus offers and to purchase, restore, and verify entitlements. RevenueCat processes a pseudonymous app user ID, technical device information, the last time the app was used, offered products, purchase and subscription status, entitlements, and Apple receipts or Google purchase tokens. Opening the Lungo Plus screen may also record a paywall impression.

When cloud backup is enabled, Lungo uses the pseudonymised identifier “firebase:<user ID>”. Without cloud backup, RevenueCat generates its own random app user ID. Health-related profile, craving, or Coach content is not sent to RevenueCat.

Payments are handled exclusively by the Apple App Store or Google Play. We do not receive complete payment or credit-card details. Apple or Google process purchase and payment data as independent controllers. RevenueCat also uses purchase data for aggregated revenue and subscription analytics; Lungo does not perform behavioural analytics on your health data.

Deleting a Lungo account does not automatically end an active store subscription. You must separately cancel it in your Apple or Google store account. Statutory or store-mandated retention of transaction records remains unaffected.

5. Optional pseudonymous usage analytics with Firebase Analytics

Firebase Analytics is off by default and is not required to use Lungo. Only after your voluntary consent does Google process app and device information such as operating system, app version, language, usage timestamps, and an app-instance identifier to improve the app. We also set your Firebase user ID as the Analytics user ID to match events to the consent record. For signed-in users, this identifier can be linked to their Lungo account.

Lungo sends views of predefined screen areas and onboarding completion. The Analytics SDK also collects automatic events, such as first app use, sessions, engagement duration, app updates, and, where applicable, in-app purchase events. Our Analytics events contain no entered smoking, vaping, craving, mood, relapse, or health data, free text, email addresses, or names. Advertising IDs, personalised advertising, and remarketing are not used.

You can withdraw consent at any time in Settings > Pseudonymous usage analytics. Lungo then stops further collection and clears the Analytics user ID on the device. This does not automatically delete previously transmitted individual events; the retention periods below and your right to erasure apply. Previously anonymised, aggregated statistics can no longer be attributed to a person.

6. Local notifications

Lungo only uses local notifications scheduled on your device, for example for daily check-ins or unlocked milestones. No push token is created and no Firebase notification infrastructure is used. Permission status and reminder preference remain on your device. You can disable notifications in Lungo or in system settings at any time.

7. Sharing, external links, and support

If you use Share, Lungo temporarily creates a progress card and passes it to your operating system’s share sheet. Data is only sent to a selected service after your action in the share sheet and is then governed by that service’s terms.

Lungo contains links to external information sites and to Apple or Google. Only after you open such a link may the provider process technical connection data such as IP address, device, operating system, and time. Those external services are governed by their own privacy notices.

When you email us, we process your sender address, message, any attachments, and necessary delivery metadata to handle your enquiry. Messages to hello@trylungo.com are forwarded through Cloudflare Email Routing to our Gmail inbox at Google. Cloudflare processes the message during forwarding; Google processes it as our mailbox provider. Please limit your message to the information needed for your enquiry.

8. Website and technical deletion service

Cloudflare Pages delivers the website. During a visit, Cloudflare processes necessary connection data such as IP address, requested address, browser and device information, timestamp, and response status. This supports delivery, troubleshooting, and abuse prevention based on our legitimate interest in a secure, available service under Article 6(1)(f) GDPR.

Deletion requests from the app also use a Cloudflare Worker. It verifies a Firebase sign-in credential for cloud accounts or the random RevenueCat customer identifier for local use and forwards the corresponding deletion to RevenueCat. The IP address is used to limit requests per minute. The legal basis is Article 6(1)(c) in conjunction with Article 17 GDPR; abuse prevention relies on Article 6(1)(f) GDPR.

The deletion service does not maintain its own customer database. Credentials and request contents are used only to process the request and are not written to our application logs. Technical Cloudflare Worker logs are retained for no more than seven days. Beyond this, connection data is kept only as needed for the particular transmission or to investigate and prevent a security incident; it is deleted or anonymised when that purpose ends.

The website uses no analytics or advertising cookies and no analytics scripts. Font files are served locally. Savings calculator and craving timer inputs are processed in the browser and are not sent to us as a profile. Strictly necessary device access falls under the exception in section 165(3) of the Austrian Telecommunications Act 2021; displaying the website does not require tracking consent.

9. Waitlist and email delivery

If you join the waitlist, we process your email address to send a waitlist confirmation and release announcement through Brevo. The legal basis is your consent under Article 6(1)(a) GDPR and section 174 of the Austrian Telecommunications Act 2021. Signing up is voluntary; without your email address and consent, we cannot send these messages.

Cloudflare D1 also stores the signup time, consent version, waitlist position, synchronisation time, and eligibility for a promised early-supporter item. Position and eligibility management fulfils that promise under Article 6(1)(b) GDPR; the consent record fulfils Article 6(1)(c) in conjunction with Articles 7(1) and 5(2) GDPR.

We do not record whether you open our emails or which links you click in them. Brevo processes the sending, delivery, error, and unsubscribe information needed to deliver messages and respect your email preferences.

You can unsubscribe at any time using the unsubscribe link in waitlist emails or by contacting hello@trylungo.com. Further waitlist emails then stop; prior processing remains lawful. Unsubscribing does not automatically waive an early-supporter item already promised to you.

Active waitlist and delivery data is needed until the release announcement and fulfilment of a promised item, then deleted within 30 days. If you unsubscribe earlier, contact data no longer needed is removed within 30 days. Only information still needed to fulfil an item promise is retained until fulfilment. A minimal consent and unsubscribe record may then be retained for up to three years for proof obligations or specific legal claims; it is not used for further advertising emails.

10. Voluntary and required information

There is no statutory obligation to provide us with personal data. Information required for your chosen service is nevertheless necessary to perform it: without setup information and health-data consent, personalised core features cannot be used; without account details, account-based restoration and synchronisation are unavailable. Without purchase and entitlement data, Lungo Plus cannot be unlocked or restored. Support or deletion requests require enough information to respond and, where necessary, securely match your data.

Cloud backup, usage analytics, additional free text, notifications, and waitlist signup are voluntary. Declining them does not prevent other local use of the app. After withdrawal of health-data consent, features dependent on that consent can no longer be used.

11. Purposes and legal bases

  • Providing local app features: Article 6(1)(b) GDPR; for health-related data, additionally your express consent under Article 9(2)(a) GDPR.
  • Documenting your consent choices: compliance with our proof and accountability obligations under Article 6(1)(c) in conjunction with Articles 7(1) and 5(2) GDPR.
  • Optional cloud backup and synchronisation: your consent under Article 6(1)(a) and, for health data, Article 9(2)(a) GDPR.
  • Optional pseudonymous usage analytics: your consent under Article 6(1)(a) GDPR and, where information is stored on or accessed from your device, section 165(3) of the Austrian Telecommunications Act 2021.
  • Optional Apple or Google sign-in: performance of the account and recovery service you request under Article 6(1)(b) GDPR.
  • Purchases, subscriptions, restoration, and entitlement verification: performance of a contract under Article 6(1)(b) GDPR.
  • Security, fraud prevention, and technical operation: our legitimate interest in a secure and functional app under Article 6(1)(f) GDPR.
  • Contract-related support and pre-contractual enquiries: Article 6(1)(b) GDPR. Fulfilling privacy rights: Article 6(1)(c) in conjunction with Articles 12–22 GDPR. Other enquiries: our legitimate interest in answering incoming messages under Article 6(1)(f) GDPR.

You can withdraw consent at any time with effect for the future. This does not affect processing carried out before withdrawal. You can disable pseudonymous usage analytics directly in Settings. You can withdraw health-data consent by deleting your data; Lungo must then be set up again. Cloud data can be removed by resetting data or deleting your account.

12. Recipients and processors

  • Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, and Google LLC, USA — Firebase Authentication and Cloud Firestore for the pseudonymous consent record and when cloud backup is enabled or you initiate a sign-in.
  • Google Ireland Limited and Google LLC, USA — Firebase Analytics, only after pseudonymous usage analytics is enabled.
  • RevenueCat, Inc., 1032 E Brandon Blvd #3003, Brandon, FL 33511, USA — management and verification of in-app purchases and entitlements.
  • Apple Distribution International Ltd., Hollyhill Industrial Estate, Cork, Ireland — Apple sign-in and App Store purchases as an independent controller.
  • Google Ireland Limited — Google Sign-In and Gmail; Google Commerce Limited, Ireland — Google Play purchases. Google’s privacy information applies to its independently controlled sign-in, communication, and store services.
  • Cloudflare, Inc., USA — website delivery, the waitlist database, forwarding incoming email, and technical handling of RevenueCat deletion requests.
  • Sendinblue SAS (Brevo), France — contact management and waitlist email delivery.

We do not sell personal data or disclose your app content for third-party advertising. These providers receive only the data needed for their respective services. Their privacy terms and transfer safeguards are described below.

13. Transfers outside the EEA

Our Cloud Firestore database is located in Frankfurt (europe-west3); the Cloudflare D1 waitlist database is restricted to the EU. This does not mean that all processing by Google or Cloudflare takes place exclusively in the EU. Authentication, Analytics, email services, technical connection data, and RevenueCat in particular may require processing in the USA or other countries outside the EEA.

You can request explanations and a copy of the applicable safeguards from hello@trylungo.com. Third-party rights and confidential information may be redacted.

14. Retention and deletion

  • Local app data remains until you reset or delete it in Lungo. Note the potential iOS Keychain persistence after uninstalling.
  • We keep pseudonymous consent records for the duration of the processing based on them and generally for no more than three years afterwards where still required to meet statutory proof obligations or to establish, exercise, or defend legal claims.
  • Firebase profile and progress data remains while cloud backup or your Lungo account exists. “Reset data” removes synchronised app data; “Delete account” additionally removes the Firebase account.
  • Firebase Analytics: The Analytics property applies a retention period of no more than 14 months to user- and event-level data. If reset on new activity is enabled, the period for user-level data restarts with each activity. Google deletes expired data in scheduled cycles. Anonymised, aggregated standard reports are not subject to this period. Withdrawal stops new collection; you can additionally ask us to delete attributable historical data.
  • When you reset data or delete an account, Lungo also initiates deletion of the securely matched RevenueCat customer record. RevenueCat or the stores may continue to retain transaction records where required by law or continuing store rules.
  • Support: Messages are normally deleted no later than six months after final resolution. Where particular content is still necessary for a legal obligation or a specific legal claim, its use is restricted to that purpose and it is deleted once no longer needed. Evidence of completed privacy requests is retained for up to three years where still necessary.
  • Firebase Authentication: Google states that technical IP logs are retained for a few weeks. After account deletion is initiated, Google removes other authentication data from live and backup systems within up to 180 days.
  • Apple and Google determine retention for store, payment, and sign-in data they process as independent controllers.

You can reset local data in Settings and delete an existing Lungo account directly in the app. Matching RevenueCat customer data is also submitted for deletion. You can also request deletion at https://trylungo.com/delete-account/ or by emailing hello@trylungo.com. The page explains which information may be needed to match pseudonymous purchase data.

15. Your rights

  • access to your personal data (Article 15 GDPR)
  • rectification of inaccurate data (Article 16 GDPR)
  • erasure of your data (Article 17 GDPR)
  • restriction of processing (Article 18 GDPR)
  • data portability (Article 20 GDPR)
  • objection to processing based on legitimate interests (Article 21 GDPR)
  • withdrawal of consent with effect for the future (Article 7(3) GDPR)

To exercise these rights, email hello@trylungo.com. We may request information needed to verify your identity or securely match you to a pseudonymous record.

16. Right to complain

You may complain to a data protection authority, particularly in the Member State of your residence, workplace, or the alleged infringement. Our competent authority is:

Austrian Data Protection Authority

Barichgasse 40–42, 1030 Vienna, Austria

Phone: +43 1 52 152-0

Email: dsb@dsb.gv.at

Web: www.dsb.gv.at

17. No advertising or legally significant profiling

Lungo does not use your data for personalised advertising and does not make solely automated decisions with legal or similarly significant effects under Article 22 GDPR. Personal Coach suggestions are derived from your entries solely to provide app functionality.

18. Data security

Cloud transfers use TLS encryption. Firestore security rules restrict access to data under a user ID to the authenticated account associated with that ID. Lungo uses protected SecureStore storage on the device. However, no technical system can guarantee absolute security.

19. Minimum age and health disclaimer

Lungo is intended exclusively for adults. You must be at least 18 years old to use the App; people under the age of 18 may not use Lungo, even with the consent of a parent or guardian. Lungo is not a medical device and does not replace medical, psychological, or therapeutic advice. If you experience health concerns or need help quitting, consult a qualified professional.

20. Changes and current version

We update this Privacy Policy when features, providers, or legal requirements change. We will provide appropriate notice of material changes and request renewed consent where required. The current version is available in the app and at https://trylungo.com/privacy/.