Privacy policy
Last updated:
Lysena is designed to know as little about you as possible. This page explains what data the website and the app process, where it goes and what your rights are. The data controller and contact details are at the bottom of the page.
In short
- The app checks everything on your phone. Messages, notifications, links and installed apps are never sent to us or anyone else.
- The website uses no cookies. We count visits anonymously, as totals only, and you can ask us not to count you.
- If you join the beta we store your email, type of phone, language and the time you gave consent. Only to invite you to the beta.
The website
Browsing
The website uses no cookies, neither ours nor anyone else’s, and contains no advertising or third-party content. Fonts and images are served from our own domain.
If you pick the light or dark theme, the choice is saved only in your browser (in the site’s local storage, not in a cookie) and is not sent to us. To remove it, pick “Automatic”.
The website is hosted by Cloudflare, Inc. To deliver the pages and protect them from attacks, Cloudflare processes the IP address and technical data of each request (for example the time and the page requested) and keeps them for a limited time. We keep no visit logs. Legal basis: our legitimate interest in running the website securely (Art. 6(1)(f) GDPR).
Visit statistics
To understand how many people visit the website and where they come from, we use Cloudflare Web Analytics, the statistics tool of the company that hosts the website. For each page view it records the page (without the address parameters), the website you came from, the country, the type of device, the browser, the operating system and the loading times. It uses no cookies or other data stored in your browser and does not recognise you from one visit to the next: we only see totals, for example “120 visits from Google this week”. Cloudflare keeps the full data for 7 days, then only a sample; our dashboard shows it for 6 months.
These are anonymous, aggregate statistics for a single website: for this reason, as the guidelines of the Italian data protection authority (Garante per la protezione dei dati personali, 10 June 2021) allow, we do not ask for consent with a banner. Legal basis: our legitimate interest in understanding how much interest the project raises (Art. 6(1)(f) GDPR).
If you do not want to be counted, untick “Count my visits too” at the bottom of every page: the choice is saved only in your browser, like the theme. If your browser sends the Global Privacy Control or Do Not Track signal, we do not count you. Without JavaScript, visits are not counted.
Beta signup
If you fill in the beta form we process:
- your email address;
- your type of phone (Android or iPhone);
- the language of the website;
- the date and time of your consent.
Why: to invite you to test the app and write to you only about that. Legal basis: your consent (Art. 6(1)(a) GDPR), which you can withdraw at any time by writing to us. How long: until the beta ends, or earlier if you ask. Giving us your email is optional, but without it we cannot invite you.
The data is stored in a Supabase database hosted in the European Union (Frankfurt). Your IP address is only used, for a few seconds, to limit repeated attempts from the same device: it is not stored. You must be at least 14 years old to sign up.
The Lysena app
What stays on your phone
To protect you, Lysena reads notifications from messaging apps, links, the list of installed apps and the network status, only after you turn on the feature and grant the permission. All checks happen on your phone, with an AI model that runs locally. This content is never sent to us or to third parties.
On your phone, Lysena stores alerts, the activity log and settings in encrypted storage, excluded from automatic iCloud and Google backups. Alerts and events delete themselves after 30 or 90 days, as you prefer. For a scam message we only keep the sender, the link’s domain and the category, not the full text.
What the app downloads
The app downloads the AI model, the model catalog and lists of dangerous websites from our server. Your phone downloads the whole lists: the links you check are never sent to the server.
Account (optional)
The app works without an account. If you create one for the Family group, we process your email address or your Apple or Google identifier. Legal basis: providing the service you asked for (Art. 6(1)(b) GDPR). The data is hosted by Supabase in the European Union and we keep it until you delete the account. You can delete your account in the app or by following the instructions on the Delete your account page.
Family group
Phones in the group only exchange events, for example “blocked a phishing link”, never content such as messages, photos or history. Events are encrypted from one phone to another: our server forwards them but cannot read them. Members of the group can always see what is shared.
Error reports and anonymous statistics
Only if you agree in the app, and you can change your mind at any time:
- error reports help us fix crashes. In test (beta) versions they are handled by Sentry with data in the European Union and never contain texts, links, names or model answers. The public version contains no Sentry: we only receive the crash reports that Google and Apple collect if you chose to share them with developers in your phone’s settings;
- anonymous statistics tell us which features are used and how fast the models are, without device identifiers. They are handled by Aptabase with data in the European Union.
Legal basis: your consent (Art. 6(1)(a) GDPR).
Who processes data on our behalf
These providers process data only on our instructions, as data processors:
- Cloudflare for hosting the website, the anonymous visit statistics and delivering the app’s files;
- Supabase for accounts, the beta list and encrypted Family forwarding;
- Sentry for error reports from test versions;
- Aptabase for the app’s anonymous statistics.
Supabase, Sentry and Aptabase store the data in the European Union. Cloudflare is a US company and handles requests on its worldwide network: data that reaches the United States is covered by its certification under the EU‑U.S. Data Privacy Framework and by standard contractual clauses. If another provider processes technical data outside the EU, it does so with the safeguards required by the GDPR, such as standard contractual clauses.
Your rights
You can ask us at any time to access your data, correct it, delete it, restrict its use, receive it in a readable format or object to its processing. Where processing is based on consent, you can withdraw it without affecting what was done before. We reply within 30 days.
If you believe your data is processed incorrectly, you can lodge a complaint with the Italian Data Protection Authority (Garante per la protezione dei dati personali) or the authority of your country.
Changes
If we change this policy we update the date at the top of the page. If the changes affect data you have already shared, we let you know first.