Privacy Policy

Privacy Policy

Last updated: September 19, 2026

1. Introduction

1. Introduction

This Privacy Policy (“Policy”) describes how Lisia S.r.l. (“Lisia”, “we”, “us” or “our”) collects, uses, shares and protects your personal information when you use the Lisia mobile application, the lisia.io websites, our APIs, and any related service (together, the “Platform”). It explains what choices you have, the legal bases on which we rely, and how to contact us.

Lisia is a wellness-and-creator super-app: it lets people follow daily habits (movement, mindfulness, sleep, nutrition, sustainability), join communities, watch and broadcast live sessions, chat with an AI wellness assistant called Loopi, and subscribe to creators. This Policy reflects every one of those features.

2. Scope of this Privacy Policy

2. Scope of this Privacy Policy

This Policy applies to personal information processed when you create a Lisia account, browse content, post in communities, watch or host live streams, send direct messages, talk to Loopi, redeem or spend credits, subscribe to Lisia Pro or Pro+, follow or get followed, or otherwise interact with the Platform.

It does not apply to: personal information processed in the course of employment or contracting with Lisia, third-party services you reach through external links, or services Lisia integrates with that have their own privacy notices (Apple, Google, Stripe, Resend, OpenAI, Amazon Web Services, etc.).

3. Personal Information We Collect

3. Personal Information We Collect

Information you give us directly:

• Account identifiers — full name, username, email, password (hashed), date of birth.

• Profile content — avatar photo, bio, hometown, interests, language.

• Authentication tokens from Apple, Google or Facebook when you choose social sign-in.

• Content you create — community posts, comments, reactions, saved items, direct messages (including media attachments and voice notes), chat conversations with Loopi, live-room titles and tags.

• Live-stream telemetry you generate when you host or watch a stream (Amazon IVS session id, viewer counts, chat messages, reminders set).

• Wellness preferences, goals, time-available, level, dislikes — used to personalise recommendations.

• Communications — emails or in-app support messages, surveys, contest entries.

• Payment-related data when you subscribe — managed entirely by Apple In-App Purchase or Google Play Billing during the launch window; we receive only an opaque transaction identifier confirming the purchase.

Information we collect or derive automatically:

• Device data — IP address, device model, OS version, push-notification token, app version, time zone, language.

• Usage data — screens visited, taps, video views, watch time, sessions completed, posts read, search queries, intent classification results (used to route Loopi answers).

• Approximate location — derived from your IP address. We do not collect precise GPS location unless you explicitly grant it for a feature that requires it (e.g. attending an in-person event).

• Credit ledger — every credit earned, granted, spent or refunded is logged in a transaction ledger so we can show your balance and history.

• Inferences — we may draw inferences (e.g. “interested in sleep”) from the activity above to personalise your feed and Loopi answers.

Information from third parties:

• If you sign in with Apple, Google or Facebook, we receive the basic profile fields you authorise (typically name, email, avatar).

• If you accept a referral link, we record the referrer’s user id so we can credit the welcome bonus.

• If you contact us through our customer-service vendors, those vendors share the message and your contact details.

4. How and Why We Use Your Information

4. How and Why We Use Your Information

We process personal information to:

• Provide the Platform — authenticate you, render your feed, deliver direct messages and notifications, host and play live streams via Amazon IVS, store and serve media via Amazon S3 and CloudFront.

• Power Loopi, our AI wellness assistant — your messages to Loopi (plus a short context window from the conversation) are sent to OpenAI for inference under a zero-retention data-processing agreement; we ground Loopi’s answers in public Lisia content (top videos, programs, creators, communities, upcoming live streams) so recommendations are factually accurate.

• Operate the credit economy — debit and credit your balance, log transactions, gate paid features (Loopi messages on the free tier, Pro/Pro+ subscriptions), distribute the welcome bonus, attribute referral rewards.

• Deliver push notifications — when someone sends you a direct message, mentions you, reacts to your post or your favourite creator goes live, we use your Expo push token to deliver a lock-screen banner.

• Personalise content and recommendations — we use the wellness preferences and engagement signals above to rank videos, programs, creators, communities and live streams for you.

• Send transactional and (with your consent) marketing emails — receipts, security alerts, weekly digests via Resend.

• Detect and prevent fraud, abuse, spam and policy violations — including manual or automated review of reports.

• Comply with legal obligations and respond to lawful requests.

• Improve the Platform — aggregated analytics, A/B testing, crash reporting.

Legal bases (GDPR): performance of our Terms of Service (contract), your consent (where required, e.g. precise location or marketing emails), our legitimate interests in operating, securing and improving the Platform, and compliance with legal obligations.

5. How We Disclose and Share Personal Information

5. How We Disclose and Share Personal Information

We share personal information only as described here:

• Service providers — Amazon Web Services (RDS PostgreSQL, S3, CloudFront, Lambda, IVS, SNS, EventBridge in the us-east-1 region), Supabase (authentication and realtime channels), OpenAI (Loopi inference), Expo (push token delivery), Resend (transactional email), and the App Store / Google Play (payment processing). Each provider is contractually limited to processing your data only as instructed by Lisia.

• Other Platform users — your username, avatar, bio, public posts, comments, reactions, follower/following counts, and live-stream metadata are visible to other users. Direct messages are visible only to the conversation participants. Loopi conversations are private to you.

• Creators you subscribe to — receive your username, avatar and the amount of credits attributed to their share of the subscription, so they can recognise and acknowledge you.

• Aggregated or anonymised data — we may share statistics that do not identify any individual.

• Business transfers — in a merger, acquisition or sale of assets, your data may be transferred subject to this Policy.

• Compliance and rights enforcement — courts, regulators or law-enforcement when legally required, and our advisors when defending our rights.

We do not sell your personal information for monetary value, and we do not share it with advertising networks for cross-context behavioural advertising.

6. International Data Transfers

6. International Data Transfers

Lisia is based in Milan, Italy. Our cloud infrastructure runs primarily in Amazon Web Services’ US East (N. Virginia) region; some authentication and realtime services run in Supabase’s EU (Frankfurt) region. When personal information is transferred outside the European Economic Area, we rely on the European Commission’s Standard Contractual Clauses and Amazon Web Services’ GDPR-compliant data-processing addendum to safeguard your rights. You can request a copy of the safeguards at info@lisia.io.

7. Live Streams, Communities and User-Generated Content

7. Live Streams, Communities and User-Generated Content

When you go live, post to a community, comment, react or set a reminder, that content is visible to the audience you choose: public live rooms are visible to all logged-in users; community posts are visible to the community’s members; subscriber-only posts are visible only to your paying subscribers. Live streams are broadcast via Amazon IVS and recorded for a configurable retention period so we can compute analytics and serve replays. Your live chat messages are stored alongside the session.

Do not share content that you do not have the rights to share, that is illegal, or that violates our Community Guidelines. Reports can be filed in-app; we may remove content and suspend accounts when our policies are breached.

8. Loopi, the AI Wellness Assistant

8. Loopi, the AI Wellness Assistant

Loopi is a chat experience powered by OpenAI’s GPT family of models. When you send a Loopi message:

• Your message and a short scroll-back of the conversation are sent to OpenAI for inference, together with a system prompt that grounds the assistant in public Lisia content.

• OpenAI is contractually prohibited from training models on your messages and from retaining them beyond the request window.

• We store the conversation on Lisia’s database so you can revisit it.

• Loopi messages may be debited from your credit balance or counted against your plan’s daily free quota; every charge or quota use is logged in your credit ledger.

Do not share medical, legal, financial or safety-critical personal information with Loopi. For health concerns please consult a qualified professional.

9. Push Notifications

9. Push Notifications

After you sign in we ask for permission to send notifications. If you grant it, we store your Expo push token alongside your profile and use it to deliver lock-screen banners when, for example, someone sends you a direct message, a creator you follow goes live, your subscription renews, or a community you joined posts new content. You can disable push notifications at any time in your device settings or in Account → Notifications.

10. Children’s Privacy

10. Children’s Privacy

Lisia is not directed to children under 13 and we do not knowingly collect personal information from children under that age. Users between 13 and 16 in countries with a higher data-protection age may need parental consent under local law. If you are a parent or guardian and believe we have collected information from your child, please contact info@lisia.io and we will delete it.

11. Data Retention

11. Data Retention

We retain personal information only as long as needed to provide the Platform and meet our legal obligations:

• Account profile data — for as long as your account is active.

• Posts, comments, live-stream metadata — until you or we delete the content; deletions cascade across replies and reactions.

• Direct messages — until you delete them; deleted-for-everyone messages are removed for all participants.

• Loopi conversations — for the lifetime of your account unless you delete them in app.

• Credit ledger and subscription records — at least seven (7) years for accounting, tax and fraud-detection purposes, even after account closure, as required by Italian law.

• Push tokens — until the device unregisters or the token expires.

• Server logs and security telemetry — typically up to 90 days, longer when required to investigate an incident.

When you delete your account, your profile, posts, messages and Loopi conversations are removed within 30 days, except where law requires longer retention.

12. Your Privacy Rights

12. Your Privacy Rights

Subject to applicable law you have the right to: access the personal information we hold about you; correct inaccurate data; delete your data; restrict or object to certain processing; portability of data you provided; withdraw a previously-given consent; lodge a complaint with your local data-protection authority (in Italy, the Garante per la protezione dei dati personali).

You can exercise most of these directly in the app (Account → Settings → Privacy → Edit Profile, Download My Data, Delete Account). For other requests email info@lisia.io. We will verify your identity through the email address on file before responding, typically within 30 days.

13. Security

13. Security

Personal information is encrypted in transit (TLS 1.2+) and at rest (AES-256 on Amazon RDS, S3 and CloudFront). Database access is restricted to a private VPC; production credentials are stored in AWS Secrets Manager and rotated. Authentication tokens use ES256-signed JWTs with short lifetimes. We monitor the Platform with CloudWatch alarms and respond to incidents promptly. No system is perfectly secure: please use a unique, strong password and enable two-factor authentication where available.

14. Cookies and Similar Technologies

14. Cookies and Similar Technologies

The mobile app uses platform-level storage (Apple’s NSUserDefaults / Android’s SharedPreferences and the device’s secure keychain) to store your session, preferences and small caches. The lisia.io marketing website uses essential cookies for session management and, with your consent, analytics cookies to understand traffic. We do not use cookies for cross-site behavioural advertising. You can manage cookies through your browser settings.

15. Third-Party Sign-In and Integrations

15. Third-Party Sign-In and Integrations

You can choose to sign in to Lisia with Apple, Google or Facebook. We receive only the basic profile fields you approve in their consent screen (typically full name, email and avatar). Their handling of your data on their side is governed by their own privacy policies. We strongly encourage you to review them. Lisia also displays links to external content (e.g. partner brands, embedded videos); those destinations have their own privacy notices.

16. Changes to this Policy

16. Changes to this Policy

We will update this Policy from time to time. The “last updated” date at the top reflects the most recent change. When changes are material (for example a new processor, a new category of data, or a new purpose) we will notify you in-app and, where legally required, request your consent before applying them.

17. Contact Us

17. Contact Us

If you have questions, comments or want to exercise a right under this Policy, contact us at:

Lisia S.r.l., Milano (MI), Italy Email: info@lisia.io

For data-protection complaints in the European Union you may also contact the Garante per la protezione dei dati personali (www.garanteprivacy.it).

Lisia (Lisia S.r.l.) — info@lisia.io