Privacy Policy
Last updated: 11 September 2026
Linometry ("the app") is made by LA BRANDS LTD ("we", "us"), a company registered in the United Kingdom. We are the data controller for the personal data described in this policy. We take a simple view of privacy: we collect the minimum needed to run a colouring app well, we never sell your data, and we show no advertising.
Contact for anything privacy-related: luke@la-brands.com
1. What we collect and why
| Data | Why we collect it | Legal basis (UK GDPR) |
|---|---|---|
| Email address, display name, password (stored as a salted hash — we can never read it) | Creating and securing your account; syncing artwork across your devices | Contract (Art. 6(1)(b)) |
| Sign-in identifiers from Google or Apple (a token identifying your account; we receive your email and, with Apple, an optional name) | Letting you sign in without a password | Contract |
| Your artwork, projects, palettes, gallery posts, comments and likes | The core service: saving, syncing and (only when you choose to publish) sharing your work | Contract |
| Purchase and subscription status (processed by Google Play / Apple and RevenueCat — we never see your card details) | Unlocking Premium on your account and honouring purchases across devices | Contract |
| Basic usage events (e.g. app opened, page opened, page completed, purchase made) tied to a per-install analytics id and, once you have an account, your account id; processed in the EU by PostHog | Understanding which content and features are used, where people get stuck, and whether changes we make help — so we can improve the app | Legitimate interests (Art. 6(1)(f)) |
| Onboarding answers, if you choose to give them: what you like colouring, which hand you draw with, age band, gender, why you're here and how long you usually have | Personalising your library and tools (for example a simpler toolset for colouring with children) and understanding which kinds of users the app serves well. Every question is skippable; you can change the derived settings in the app at any time. | Consent (you choose to answer); legitimate interests for aggregate product analysis |
| AI prompt safety records: if a prompt is declined by our content filter, we keep the category of the refusal and the prompt text with your account | Enforcing our content rules — repeated refusals can be charged and, after several, lead to loss of AI access (see the Terms) | Legitimate interests (keeping the service safe and lawful) |
| Crash reports (device model, OS version, app version, stack trace; processed by Sentry) | Finding and fixing bugs and crashes | Legitimate interests |
| Support messages: what you write to us from Settings → Get help or by email, your name and email address if you give them, and (from the app) the app version, update and device model so we can help without asking | Answering your question and fixing what you reported | Legitimate interests / contract (you asked us for help) |
| Diagnostic reports: when the app detects a problem (a crash, an unusually slow page load, running out of memory) it may send us one short technical log of what the app was doing — timings, memory figures, which screen and page were open, the app version and the same per-install id as the usage events. Never your artwork, strokes, photos or typed text. At most one per app session. Switch it off in Settings → Send diagnostics. | Finding and fixing problems before people have to report them | Legitimate interests (you can opt out at any time) |
| Photos you choose to import (including a profile picture, if you set one) | Creating colouring pages, spiral portraits or palettes from your photos, and showing your profile picture — only photos you explicitly pick | Contract |
| Push notification token, app language and timezone offset | Delivering the notifications you have enabled (for example the daily free page or replies to your posts), in your language, at sensible local hours. Every kind of notification can be switched off in the app, or entirely in your device settings. | Legitimate interests; consent via your device's notification permission |
| Date of birth (only if you join the gallery) | A one-time age check — the gallery is for users aged 16 and over. Never shown to anyone. | Legal obligation / legitimate interests (age assurance) |
| Colouring streak and activity dates; searches you make in the library | Showing your streak, improving search and deciding which pages to add next | Legitimate interests |
| Text prompts you type into the AI page creator | Generating the colouring page you asked for (see section 2) | Contract |
We do not collect your precise location, contacts, or advertising identifiers. We make no automated decisions about you with legal or similarly significant effects, and we do not sell or rent personal data to anyone.
2. Photos you import and AI-created pages
When you use the creator tools, the photo you pick is uploaded to our server, converted into a colouring page or palette, and the result is stored with your account. The generated page is private to your account unless you publish artwork made from it. You can delete any created page or project at any time, which removes the associated images from our storage.
When you use the AI page creator, the text prompt you type is sent to our AI image provider (currently OpenAI) to generate the page. Prompts are not linked to your name or email by the provider — they receive only the text needed to draw the picture. Before a prompt is used it is checked against our content rules by an automated filter, which includes OpenAI's moderation service; declined prompts are recorded against your account as described in section 1 and are not used to generate anything. Profile pictures are cropped and resized on our server and stored with your account until you remove them or delete your account.
3. Payments
Purchases are processed by Google Play (and, on Apple devices, the App Store). We use RevenueCat to validate purchases and manage subscription status. We receive confirmation that a purchase happened, the product purchased, and its expiry date — never your payment card, bank details or billing address.
4. Who we share data with (processors)
- Railway — hosts our server and database (EU region).
- RevenueCat — purchase validation and subscription management.
- Google — Google sign-in and Google Play billing.
- Apple — Apple sign-in and App Store billing (on Apple devices).
- Sentry — crash and error reporting.
- Expo — delivery of push notifications to your device.
- OpenAI — generating AI colouring pages from prompts you type, and checking prompts against content rules.
- PostHog — product analytics (EU-hosted); receives the usage events, onboarding answers and subscription status described above, never your email or artwork.
- Cloudflare — storage and delivery of page images and your synced artwork (R2 object storage and CDN).
Each processor only receives what it needs to do its job, under its own data-processing terms. Some processors are based outside the UK/EEA (for example in the United States); transfers rely on adequacy decisions or standard contractual clauses.
5. How long we keep data
- Account & artwork: for as long as your account exists.
- Gallery posts: until you delete them or your account.
- Usage events: 90 days in our database; aggregated analytics in PostHog for as long as the account exists.
- Library searches: 180 days.
- Crash reports: up to 90 days.
- Support messages: 2 years after the last message (deleted with your account if it was tied to one).
- Diagnostic reports: the report files are kept until replaced by newer ones (typically days); a one-line record of when and why one was sent is kept for 90 days.
- Server logs (request id, route, status, timing and a partly masked IP address): up to 30 days.
Deleting your account (Settings → Delete account) permanently removes your account record, synced artwork, palettes, gallery posts, comments and likes, push tokens, onboarding answers, AI prompt safety records and date of birth from our systems. Artwork stored locally on your device stays on your device. Backups age out within 30 days. You can also request deletion without the app installed — see Delete your account.
6. Your rights
Under UK GDPR you can ask us to:
- access a copy of the personal data we hold about you;
- correct inaccurate data;
- delete your data ("right to be forgotten") — also available in-app;
- restrict or object to processing based on legitimate interests;
- receive your data in a portable format — also available in-app (Settings → Download my data gives you a JSON file of everything we hold).
Email luke@la-brands.com and we will respond within one month. You also have the right to complain to the UK Information Commissioner's Office (ico.org.uk).
7. Children
Linometry is a general-audience colouring app. Creating an account requires agreeing to our terms; children under 13 should only use the app with a parent or guardian's consent and supervision. We do not knowingly collect personal data from children under 13 without such consent — if you believe this has happened, contact us and we will delete it. The community gallery is restricted to users aged 16 and over and is locked behind a one-time date-of-birth check; every other part of the app has no social features, no chat and no advertising.
8. Security
All traffic between the app and our servers is encrypted (HTTPS). Passwords are stored only as salted hashes. Access to production systems is limited to LA BRANDS LTD personnel who need it. No system is perfectly secure, but if we ever discover a breach affecting your personal data we will notify you and the ICO as required by law.
9. Changes to this policy
If we make material changes we will update the date above and, for significant changes, notify you in the app. Continued use after changes take effect means you accept the updated policy.