Privacy Policy
Last Updated: April 13, 2026
At YourFriendBl , we build calm, useful, and privacy‑first software, including our application “Lysta — AI Grocery & Lists” (“Lysta”). This Privacy Policy explains how we collect, use, store, and share information when you use our services and when you connect your Google account or other sign‑in providers.
This Policy applies to:
- The Lysta mobile apps (iOS and Android)
- Any future Lysta web experience
- Backend services and APIs operated by YourFriendBl that Lysta communicates with
If you do not agree with this Policy, please do not use our services.
1. Information We Collect
We collect the following categories of information:
1.1 Information you provide to us
- Account details: Name or nickname, Email address, Password (if you register with email/password)
- Profile information: Optional avatar or profile image, Language and region preferences
- In‑app content: Lists, items, notes, reminders, and groups you create; Shared lists and group membership information; Feedback or support messages sent to us
1.2 Google user data (when you sign in with Google)
If you choose to sign in with your Google account, Lysta uses Google OAuth to access limited Google user data. Depending on your consent, we may access:
- Basic Google profile information: Your Google account ID, Name, Email address, Profile photo (if available)
We do not access your Gmail content, Google Drive files, Calendar data, Contacts, or other Google products unless explicitly described and consented to in an updated version of this Policy.
Lysta uses Google user data strictly for:
- Authenticating your identity
- Creating and managing your Lysta account
- Showing your name and avatar inside the app
- Security, fraud prevention, and abuse detection (for example, preventing fake accounts or abusive sign‑ups)
1.3 Automatically collected information
When you use Lysta, we may automatically collect:
- Device information: Device model, operating system version, app version, language and region
- Log and usage information: Timestamps of app actions (e.g., log‑in, list updates), IP address and basic network information (used only for security and to diagnose connectivity issues)
- Crash and performance data: Error logs and performance metrics used to make the app more stable
We do not collect more information than needed to operate and secure the service.
2. How We Use Your Information
We use the information described above for the following purposes:
- Providing and operating the service
- Create and maintain your Lysta account
- Sync your lists, items, groups, and preferences between devices
- Provide AI‑assisted features (e.g., suggestions) using anonymized/aggregated data where possible
- Using Google user data
- Authenticate you via Google Sign‑In
- Pre‑fill your profile (name, email, avatar)
- Link your Lysta account to your Google identity so you can easily sign in on other devices
- Protect accounts from abuse, fraud, and unauthorized access
- Improving and securing the service
- Analyze aggregated usage patterns to understand what features are helpful
- Monitor for suspicious or abusive behavior
- Debug crashes and fix technical issues
- Communication
- Send important account notifications (security alerts, password reset)
- Respond to support messages
- Send transactional emails related to your account or subscription
We do not use Google user data or your grocery lists to build advertising profiles or to show behavior‑based ads.
3. How We Share Information
We do not sell your personal data.
We may share information in the following limited cases:
- Service providers / processors: We use trusted third‑party services to host and operate Lysta (for example, authentication, database, file storage, analytics). These providers may process your data on our behalf and only under our instructions.
- Google user data:
- Google user data accessed via OAuth remains subject to Google’s APIs Terms of Service and the Google API Services User Data Policy.
- We do not share Google user data with third parties except: As necessary to provide the Lysta service (e.g., storing your Google account ID/token in our authentication backend), or as required by law, legal process, or to protect users’ safety and the security of our systems.
- Legal and safety reasons: We may disclose information if we believe in good faith that it is necessary to:
- Comply with applicable law or legal process
- Enforce our Terms of Service
- Detect, prevent, or address fraud, abuse, or security issues
- Protect the rights, property, or safety of users, YourFriendBl, or others
- Business transfers: If we are involved in a merger, acquisition, or asset sale, your information may be transferred as part of that transaction, subject to this Policy.
4. Data Storage and Retention
- We store your data on secure cloud infrastructure (for example, managed services such as Firebase).
- We retain your account information and content for as long as your account is active.
- If you delete your account or request deletion:
- We will delete or anonymize personal data that we are not legally required to keep.
- Some backup copies may persist for a limited period in secure backups.
For Google user data:
- Tokens and identifiers used for Google authentication are stored securely.
- If you disconnect Lysta from your Google account or delete your Lysta account, we will stop using and will delete or anonymize associated Google user data, except as needed for security logs or legal obligations.
5. Your Rights and Choices
Depending on your location, you may have rights such as:
- Access the personal data we hold about you
- Correct inaccurate or incomplete information
- Delete your account and associated data, subject to legal retention requirements
- Object to or restrict certain types of processing
- Export your data where technically feasible
To exercise these rights, contact us at support@yourfriendbl.com.
Google account controls
You can also:
- Revoke Lysta’s access to your Google account at any time via your Google Account’s Security settings.
- Choose not to use Google Sign‑In and instead use other login methods (where available, such as email/password).
6. Children’s Privacy
Lysta is not intended for children under 13 without parental consent.
- Children under 13 may use the service only with the permission and supervision of a parent or legal guardian.
- If we learn that we have collected personal information from a child under 13 without proper consent, we will delete that information.
If you believe a child under 13 has provided us data improperly, please contact us at support@yourfriendbl.com.
7. International Transfers
Your information may be processed and stored on servers located in countries other than your own. Where required by law, we take appropriate measures to ensure that international data transfers comply with applicable data protection rules.
8. Changes to This Policy
We may update this Privacy Policy from time to time.
- We will update the “Last Updated” date at the top of this page.
- For material changes, we may provide additional notice (for example, inside the app).
We encourage you to review this Policy periodically.
9. Contact Us
If you have questions or concerns about this Privacy Policy or how we handle your data, contact:
YourFriendBl
Email: support@yourfriendbl.com