Which app this covers. This Privacy Policy applies to the Lucilla fitness app (Android package com.lucilla.app) — step challenges and step matches, the AI journal (macros, exercise and journal), wearable and health integrations, the social feed, vids, rooms and streams, creator subscriptions, and the USDC wallet as used in that app.
Local deals, the map of businesses and rewards, reward claiming and redemption, business reward campaigns, and the Lucilla assistant by text message (SMS / WhatsApp) are part of the separate Ask Lucilla app (com.lucilla.rewards), which has its own Privacy Policy. Both apps use the same Lucilla account, so information stored on your account (such as your name, username, profile photo and wallet address) is shared between them.
1. Introduction
Welcome to Lucilla ("we," "our," or "us"). We are committed to protecting your privacy and personal information. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our mobile application and services.
2. Information We Collect
2.1 Personal Information
We collect information that you provide directly to us, including:
- Account information (name, email address, phone number)
- Profile information (username, profile picture, date of birth)
- Payment information (processed securely through third-party payment processors)
2.2 Health & Fitness Data
With your explicit consent, we collect:
- Step count data from Health Connect, Apple Health, Samsung Health, Google Fit, or the Google Health API (Fitbit and Google Pixel Watch)
- Activity data for fitness challenges and tracking
- Location data for paid-match eligibility checks and nearby-people discovery (only with your permission — see Section 2.6)
2.3 Wearable & Fitness Device Data
When you connect a wearable or fitness device to Lucilla, we collect:
- Step count data from connected wearables and phone pedometers
- Device type and model (e.g., Fitbit Charge 6, Apple Watch Series 9, Garmin Forerunner)
- Sync method (native sync via HealthKit/Health Connect/Fitbit API/Garmin Health API, or bridge sync via companion apps like Garmin Connect, Zepp, Polar Flow, COROS, Huawei Health)
- Device accuracy tier classification
- Health Connect permissions and connected data sources (Android)
- HealthKit permissions and connected data sources (iOS)
- Workout and activity session data for intraday match verification
How We Use Wearable Data:
- To verify step counts in competitions and determine winners
- To enforce device eligibility rules for paid matches (8% maximum error rate)
- To detect potential cheating or data manipulation
- To provide personalized health insights (with your consent)
- We do not sell your health or fitness data to third parties
- Wearable data is stored securely and encrypted at rest
Disconnecting Your Wearable: You can disconnect your wearable device at any time through the app settings. Please note that disconnecting a wearable will prevent your participation in matches that require that device as a verified step source.
2.3a Third-Party Wearable & Health Platform Integrations
Lucilla integrates with the following third-party wearable and health platforms to read fitness data on your behalf, only after you have granted explicit permission via the platform's official authorization flow (OAuth, HealthKit, Health Connect, or equivalent):
- Apple HealthKit (iOS) — Apple Watch and iPhone
- Health Connect (Android) — aggregator for Google Fit, Samsung Health, Fitbit, and other Android health apps
- Google Health API — Fitbit devices and Google Pixel Watch (Google's replacement for the Fitbit Web API)
- Fitbit Web API — Fitbit and Google Pixel Watch (being retired by Google in September 2026 and replaced by the Google Health API above)
- Google Fit REST API — Wear OS and Android phones
- Samsung Health SDK — Galaxy Watch and Galaxy phones
- Garmin Health API (Garmin Connect Developer Program) — Garmin watches, cycling computers, and fitness trackers
Data we read from these wearable APIs:
- Daily and intraday step counts
- Workout and activity sessions (start time, end time, sport type, duration, distance)
- Heart rate samples during active workouts and step matches
- Calories burned during activity
- Active minutes and exercise time
What we can read depends on the platform. On Android, Lucilla reads only steps and exercise sessions from Health Connect; heart rate, calories and other metrics come only from platforms that provide them to us, such as Apple HealthKit on iOS or the Fitbit and Google Health cloud APIs.
Purpose of collection. Lucilla reads the data above for the sole purpose of (1) validating fitness challenge and step-match results, (2) calculating USDC prize eligibility, and (3) displaying your activity back to you inside the Lucilla app. We do not sell wearable data to third parties, do not use it for advertising, and do not share it with enterprise partners in identifiable form.
Garmin Health API specific notice. Health and activity data obtained through the Garmin Health API (steps, activities, heart rate, calories, intensity minutes, daily summaries) is used exclusively to verify step matches, validate fitness challenge results, and award USDC prizes inside the Lucilla app. Garmin data is stored encrypted at rest, accessed only by authorized backend services on a need-to-process basis, and is never sold, rented, or licensed to third parties. You can disconnect your Garmin account at any time from Settings > Connected Devices > Garmin in the Lucilla app, which immediately revokes our OAuth token with Garmin and stops all further data ingestion. You can additionally request deletion of all Garmin-derived data we have stored by emailing legal@lucilla.ca — we will purge it within 30 days, subject only to the transaction-record retention described in the Data Retention & Deletion section (which applies only to records linked to a settled USDC transaction).
Apple HealthKit Notice: Health data obtained from Apple HealthKit is used solely to provide and improve App features. We do not use HealthKit data for advertising, and we do not share HealthKit data with third parties except as required to operate the App or as required by law.
Google Health API specific notice. Health and activity data obtained through the Google Health API (steps, including intraday step data, workouts, heart rate, calories, sleep, and daily summaries from Fitbit devices and Google Pixel Watch) is used exclusively to verify step matches, validate fitness challenge results, and award USDC prizes inside the Lucilla app. We request only the read-only scope https://www.googleapis.com/auth/googlehealth.activity_and_fitness.readonly and request no write scopes. Google Health data is stored encrypted at rest, accessed only by authorized backend services on a need-to-process basis, and is never sold, rented, or licensed to third parties, and is never used for advertising. Lucilla's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. You can disconnect at any time from Settings > Connected Devices in the Lucilla app, or revoke access directly at https://myaccount.google.com/permissions, which immediately revokes our OAuth token and stops all further data ingestion. You can additionally request deletion of all Google Health–derived data we have stored by emailing legal@lucilla.ca — we will purge it within 30 days, subject only to the transaction-record retention described in the Data Retention & Deletion section (which applies only to records linked to a settled USDC transaction).
Fitbit Web API specific notice. Health and activity data obtained through the Fitbit Web API (steps, intraday step data, workouts, heart rate, calories, sleep, daily summaries) is used exclusively to verify step matches, validate fitness challenge results, and award USDC prizes inside the Lucilla app. Fitbit data is stored encrypted at rest, accessed only by authorized backend services on a need-to-process basis, and is never sold, rented, or licensed to third parties. You can disconnect your Fitbit account at any time from Settings > Connected Devices > Fitbit in the Lucilla app, which immediately revokes our OAuth token with Fitbit (and your authorization is also manageable from https://www.fitbit.com/settings/applications) and stops all further data ingestion. You can additionally request deletion of all Fitbit-derived data we have stored by emailing legal@lucilla.ca — we will purge it within 30 days, subject only to the transaction-record retention described in the Data Retention & Deletion section (which applies only to records linked to a settled USDC transaction).
Google Fit / Health Connect specific notice. Health and activity data obtained through the Google Fit REST API and the Android Health Connect platform (from Health Connect: steps and exercise sessions only) is used exclusively to verify step matches, validate fitness challenge results, and award USDC prizes inside the Lucilla app. Google-derived data is stored encrypted at rest, accessed only by authorized backend services on a need-to-process basis, and is never sold, rented, or licensed to third parties. Lucilla's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. You can disconnect Google Fit at any time from Settings > Connected Devices > Google Fit (or revoke access at https://myaccount.google.com/permissions), and you can revoke Health Connect read permissions at any time from your Android device's Health Connect settings. You can additionally request deletion of all Google-derived data we have stored by emailing legal@lucilla.ca — we will purge it within 30 days, subject only to the transaction-record retention described in the Data Retention & Deletion section (which applies only to records linked to a settled USDC transaction).
Samsung Health specific notice. Health and activity data obtained from Samsung Health (via Health Connect or the Samsung Health SDK on Galaxy Watch and Galaxy phone surfaces — steps and exercise sessions) is used exclusively to verify step matches, validate fitness challenge results, and award USDC prizes inside the Lucilla app. Samsung Health data is stored encrypted at rest, accessed only by authorized backend services on a need-to-process basis, and is never sold, rented, or licensed to third parties. You can disconnect Samsung Health at any time from Settings > Connected Devices > Samsung Health in the Lucilla app, and you can additionally revoke Lucilla's read permission inside the Samsung Health app or via Android Health Connect at the OS level. You can request deletion of all Samsung-derived data we have stored by emailing legal@lucilla.ca — we will purge it within 30 days, subject only to the transaction-record retention described in the Data Retention & Deletion section (which applies only to records linked to a settled USDC transaction).
2.3b Shareable Health Data
You may optionally share certain health data with the Lucilla community:
- Step activity — daily or challenge-period step counts
- Meal logs (macros) — food diary entries you choose to post
- Exercise logs — workouts, sets, reps, distance, heart rate
- Journal entries — AI-assisted journal content you explicitly choose to share
All health sharing is opt-in and user-initiated. Nothing is shared automatically. You control visibility (public, followers, groups, or paid subscribers only) and may delete shared posts at any time.
Step counts inside challenges you join. Lucilla's step challenges, step matches, tournaments and group challenges are competitive by design, so your step count for that challenge period is visible to the other participants in it, including on leaderboards and result screens. This applies to step data read from a connected wearable, including data obtained through the Google Health API. Visibility is limited to the participants of challenges you have chosen to enter — your step counts are not shown to other users outside those challenges, are not published on your public profile, are never sold or licensed to third parties, and are never used for advertising. Joining a challenge is entirely voluntary, and you can take part in Lucilla without connecting a wearable or entering any challenge.
Web community feed (lucilla.ca) is force-anonymized. When you opt a journal / macros / exercise entry into the public community feed that powers lucilla.ca, the server strips your username, user ID, and profile picture at read time so web visitors see the content without being able to identify you. This is a one-way transformation handled server-side. The only de-anonymization path is an admin-only audit endpoint used exclusively for legal-hold or law-enforcement requests — ordinary staff and other users cannot resolve an anonymized entry back to an account.
Enhanced Profile paid subscriptions are the ONLY identified share path. Inside the app, a user may enable a creator subscription on their Enhanced Social Profile (Profile > Creator Pricing). Paid subscribers then see that creator's live macros / exercise / journal feed with full identity attached. Non-subscribers (including strangers, followers, friends, or people the creator follows — depending on the audience tier the creator chose) see a paywall stub plus at most aggregate daily-total teasers. This is a direct creator-to-subscriber relationship facilitated by Lucilla; the platform fee follows the creator's subscription tier. Server-side rules at Users/{uid}/journal_entries block every non-owner read path from reaching raw data without going through the getCreatorTrackingView / getNetworkTrackingFeed Cloud Functions, which enforce the subscription / audience tier.
2.3c Voice & Audio
- Voice commands to the AI assistant (FAB) are processed in real time via Google Gemini Live API and are not stored beyond the active session
- Voice entries you dictate into the journal are sent to Google Gemini (Vertex AI) to be transcribed and turned into journal, meal or exercise entries
- Food photos you add to the journal, and videos you record or choose for form analysis (up to 30 seconds), are uploaded to our cloud storage so they can be processed; pose detection for form analysis runs on your device
- Voice posts and audio you publish to your social feed are stored only when you explicitly post them
- Audio transmitted in live Spaces or Streams is processed in real time
You can revoke microphone access at any time in your device Settings.
2.3d Biometric Data (Passkey / Face ID / Fingerprint)
We never receive or store your biometric data. When you set up your Lucilla Smart Wallet via WebAuthn passkey, authentication happens entirely on your device through Apple or Google's secure enclave. We only receive a cryptographic token confirming successful authentication — your fingerprint or face data never leaves your device.
2.4 Wallet & Transaction Data
For users utilizing our USDC wallet features:
- Blockchain wallet addresses
- Transaction history (stored on public blockchain)
- Payment receipts and subscription records
- Wallet balance at the time of transactions such as match entries and prize payouts (used for fraud prevention and platform integrity)
2.5 Device Information
We collect information about the device you use to access Lucilla, including:
- Device model and manufacturer
- Operating system and version
- App version
- Unique device identifiers
- Mobile network information
This information helps us provide a consistent experience, troubleshoot issues, and ensure platform security.
2.6 Location Data
The fitness app uses your device location only for the features below, and only with your permission:
- Paid step-match eligibility: when you enter or queue for a paid match, we collect your GPS coordinates (latitude, longitude, accuracy, altitude, speed and heading) together with your country and state or province, to confirm you are in a jurisdiction where paid matches are permitted (see Section 13)
- Nearby people discovery: if you use discovery to find fitness partners near you, your approximate location (coordinates and city) is saved to your profile so that nearby users can be suggested
- One-time lookups: detecting your country, choosing a location, location-based search, and a delivery address for grocery orders
The Android app does not request background location permission (ACCESS_BACKGROUND_LOCATION), and the fitness app does not record GPS routes. We do not sell your location data and do not use it for advertising profiles. You can decline or revoke location permission at any time in your device settings; paid matches and nearby discovery will then be unavailable, but all other features remain accessible.
Location-based rewards, reward zones and business offers are part of the Ask Lucilla app; see the Ask Lucilla Privacy Policy.
2.7 Challenge, Points & Referral Data
- Matches, challenges, tournaments and group challenges you join, their results and any prizes you win
- Fitness points and leaderboard positions
- Sponsored or group challenge contributions you fund
- Referral code activity (codes you shared and codes used by others)
2.8 Automatically Collected Information
- Usage data (features used, time spent, interactions) via Firebase Analytics, including your subscription tier, whether you have a wallet, your wearable type and your identity-verification tier
- Log data (IP address, crash reports, performance data). Crash and performance reports are collected by Firebase Crashlytics and Sentry; Sentry reports are associated with your user ID and email address
- Session duration and navigation patterns
- Search queries within the app
2.9 Fraud Prevention & Platform Integrity Data
To maintain a fair and secure platform for all users, we collect and process:
- Fraud prevention signals: We use proprietary technology to detect and prevent fraudulent activity, including multi-account abuse, step-count manipulation and location spoofing. These systems operate on anonymized data and do not identify specific individuals.
- Behavioral patterns: Match and transaction velocity, timing patterns, and usage signals that help distinguish genuine users from automated or fraudulent activity
2.10 Identity Verification Data
When identity verification is required (for example for paid matches or when winnings reach a verification threshold — see Section 9 and the Terms of Service), we collect photos of your government ID, a selfie and a face-liveness check, proof of address where required, and tax information. ID and selfie checks are processed with Google Gemini (Vertex AI), and the face-liveness check is performed with Amazon Web Services (AWS Face Liveness).
2.11 Creator & Room Advertising Data
If you run ads in voice and video rooms, we collect your ad campaign configuration (targeted creators, categories, minimum audience size and regions) and impression and click counts. Room ads are not targeted using health or fitness data.
3. How We Use Your Information
We use your information to:
- Provide and maintain our services
- Process transactions and send transaction notifications
- Enable fitness challenges and step-based competitions
- Distribute USDC prizes and process payments
- Personalize your experience with AI-powered features
- Send important service updates and security alerts
- Improve our app through analytics and research
- Comply with legal obligations and prevent fraud
- Ensure fair competition and prevent step-count manipulation and location spoofing
- Power content discovery and personalized recommendations
SMS / Text Messaging Program & Consent
The Lucilla fitness app uses your mobile phone number to verify your account and to send security and multi-factor authentication codes. It does not enroll you in marketing text messages.
Lucilla's conversational text-message service (SMS and WhatsApp at +1 (314) 237-4046) is part of Ask Lucilla, and is described in full in the Ask Lucilla Privacy Policy and Ask Lucilla Terms. If you text that number or opt in at lucilla.app/sms, you consent to receive text messages from Lucilla related to that service. Message and data rates may apply. Message frequency varies. You can reply STOP at any time to opt out, or HELP for help.
No mobile information will be shared with third parties or affiliates for marketing or promotional purposes. Information sharing with subcontractors in support services, such as customer service, is permitted. All other use case categories exclude text-messaging opt-in data and consent; this information will not be shared with any third parties.
Your consent to receive text messages from Lucilla, and the mobile phone number you provide for that purpose, are never sold or rented and are not shared with third parties or affiliates for their own marketing.
4. Data Sharing and Disclosure
4.1 We Share Your Information With:
- Service Providers: Firebase and Google Cloud (including Vertex AI Gemini models for AI features), Circle (USDC wallets), Coinbase (buying and selling USDC), LiveKit (voice and video rooms and streams), Sentry (crash reporting), Amazon Web Services (face-liveness checks), health data providers
- Payment Processors: Stripe (subscriptions and paid entries purchased on lucilla.app)
- Other users: content you choose to share, creator subscribers you grant access to, and your step counts inside challenges you join (see Section 2.3b)
- Legal Requirements: When required by law or to protect our rights
4.2 Data Ownership & Usage
Lucilla, Inc. owns and retains all data generated through your use of the platform. We use this data to operate, improve, and personalize our services.
- We do not currently sell your personal data to any third parties
- We may analyze anonymized usage patterns and activity data to improve our services and platform features
- In the future, we may engage in partnerships that involve sharing aggregated, anonymized data — we will notify users in advance and update these terms accordingly
- We do not share your health data without explicit consent
- We do not use your data for third-party advertising without permission
- Reward claims and what businesses receive when you claim are covered by the Ask Lucilla Privacy Policy
- You always retain the right to export or delete your personal data
5. Health & Fitness Data Privacy
Lucilla is a consumer wellness app, not a healthcare provider, health plan, or healthcare clearinghouse. We collect everyday fitness and wellness information you choose to share — such as step counts, heart rate, and the meals, exercise, and notes you log in your journals — to power your activity tracking and challenges. Lucilla is not a covered entity under HIPAA, and the information you provide here is consumer wellness data, not protected health information (PHI) governed by HIPAA. We protect it with strong security measures:
- Encrypted in transit and at rest
- Stored on secure, access-controlled cloud infrastructure
- Only accessible by you and the services you authorize
- Never sold, and never used for advertising
- You can delete your health and fitness data at any time
6. Blockchain & Cryptocurrency Disclosures
Lucilla integrates cryptocurrency functionality for match prizes, tips, creator subscriptions and payments. Important disclosures:
6.0 How Your Wallet and Payments Work
Your Lucilla wallet is a non-custodial smart wallet that you create and control with a passkey on your device, using Circle's modular wallet infrastructure. Lucilla never receives your passkey and cannot move funds out of your wallet. USDC moves on the Base blockchain between users' own wallets and Lucilla smart contracts. Apart from the specific flows below, Lucilla does not hold, transmit or exchange customers' funds on their behalf:
- Match escrow: USDC you commit to a paid step match is held by a Lucilla smart contract until the match settles, and Lucilla's servers submit the settlement transaction that pays the winner. Lucilla's smart contracts are upgradeable and administered by a multi-signature wallet controlled by Lucilla, whose administrative functions can recover tokens held by the contracts.
- Device signing key: if you authorize it, the app creates a signing key that stays on your device and lets you approve in-app payments without a passkey prompt each time. Lucilla's servers submit those signed transactions and pay the network fee; they cannot sign for you.
- Referral earnings are paid to your wallet from a wallet operated by Lucilla.
- Sponsored challenge prizes may be paid by transfer from the sponsoring business's wallet, which for enterprise businesses is a Circle wallet that Lucilla manages on the business's behalf.
- Network fees for supported in-app transactions are sponsored through Circle and billed to Lucilla.
6.1 USDC Stablecoin
- USDC is a digital stablecoin pegged to the US Dollar, issued by Circle Internet Financial
- USDC transactions are recorded on the Base blockchain (Ethereum Layer 2), a public ledger
- While wallet addresses are pseudonymous, blockchain data is permanent and publicly visible
- We do not control or have the ability to modify blockchain data once recorded
6.2 Cryptocurrency Risks
IMPORTANT: Cryptocurrency involves significant risks:
- Volatility Risk: While USDC is designed to maintain a 1:1 peg with USD, no guarantee exists that this peg will always be maintained
- Regulatory Risk: Cryptocurrency regulations vary by jurisdiction and may change. You are responsible for compliance with your local laws
- Irreversibility: Blockchain transactions cannot be reversed once confirmed. Sending to wrong addresses results in permanent loss
- Custodial Risk: Wallets are non-custodial; you are solely responsible for safeguarding your wallet credentials
- Smart Contract Risk: Smart contracts may contain bugs or vulnerabilities
- Network Risk: Blockchain networks may experience congestion, delays, or outages
6.3 Not Financial Advice
Lucilla does not provide investment, financial, tax, or legal advice. Any cryptocurrency features are provided "as-is" for prize and payment purposes only. Consult qualified professionals for financial decisions.
6.4 Jurisdiction & Geographic Restrictions
While Lucilla's core features (health tracking, social, Step Matches) are available worldwide, certain cryptocurrency services have geographic restrictions:
- Coinbase On/Off-Ramp: Buying and selling USDC with regular currency is provided by Coinbase and is available only where Coinbase supports it. See Coinbase supported countries.
- Wallet & P2P Transfers: Self-custodial crypto wallets and peer-to-peer transfers are available worldwide where not prohibited by local law.
- User Responsibility: You are responsible for ensuring compliance with local regulations regarding cryptocurrency use in your jurisdiction.
Data Retention & Deletion Schedule
Lucilla retains personal data only as long as necessary to provide the service, comply with legal obligations, resolve disputes, and enforce agreements. When you request deletion of your account at lucilla.app/delete-account or in the app, we email you a link to confirm; once confirmed, your account enters a 30-day grace period and is then deleted. Some financial records are kept afterwards for as long as applicable law requires. The table below lists what we keep.
| Data category | After account deletion |
|---|---|
| Profile (name, photo, username, bio, email, phone, DOB) | Deleted |
| Social posts, journal entries, chat messages, notifications | Deleted |
| Step / activity / sleep data | Deleted |
| Profile photos and uploaded media stored under your account | Deleted |
| Push tokens, device identifiers | Deleted |
| Login (Firebase Authentication) | Deleted |
| Wallet address(es), USDC transaction records, paid match records, and the name, email, phone and date of birth linked to them | Kept in a locked retention store for as long as applicable law requires, then deleted |
| On-chain transaction hashes and wallet balances | Permanent — the Base blockchain is public and immutable |
| Aggregated analytics (no personal identifiers) | Indefinite |
The retention store. Records that must be kept are moved into a locked store that ordinary staff cannot access. You can no longer see or control them, but they exist to meet legal, tax, dispute and audit obligations until the retention period ends, after which a scheduled process permanently deletes them.
Your rights. GDPR (EU), CCPA (California), and Canadian privacy law all grant a right to erasure. That right is subject to a legal-obligation exception (GDPR Article 17(3)(b); CCPA § 1798.105(d)) which is what the retention above relies on. You may always request a copy of your retained records by emailing legal@lucilla.ca. If you believe your data has been retained longer than necessary, or you want to dispute the retention, contact the same address — we respond within 30 days.
Partial data deletion. You may request deletion of specific data categories without deleting your whole account (social posts, journal, step history, device identifiers, subscription tracking) via /delete-data. Match history and transaction records cannot be partially deleted; they are handled only through full account deletion and the retention described above.
7. Your Rights & Choices
You have the right to:
- Access: Request a copy of your personal data
- Correction: Update inaccurate information
- Deletion: Delete your account and associated data
- Data Portability: Export your data in a machine-readable format
- Opt-Out: Disable location tracking, push notifications, or marketing emails
7.1 California Residents (CCPA/CPRA)
If you are a California resident, you have additional rights under the California Consumer Privacy Act and the California Privacy Rights Act:
- Right to Know: You can request details about the categories and specific pieces of personal information we have collected about you
- Right to Delete: You can request deletion of your personal information, subject to certain legal exceptions
- Right to Opt-Out of Sale: We do not sell your personal information. If this changes, we will provide a "Do Not Sell My Personal Information" mechanism
- Right to Non-Discrimination: We will not discriminate against you for exercising your privacy rights
- Right to Correct: You can request correction of inaccurate personal information
- Right to Limit Use of Sensitive Personal Information: You can limit how we use sensitive personal information (such as precise geolocation) to purposes necessary for providing services
To exercise these rights, contact us at legal@lucilla.ca. We will respond within 45 days.
7.2 European Users (GDPR)
If you are located in the European Economic Area, United Kingdom, or Switzerland, you have the following rights under the General Data Protection Regulation:
- Right to Access: Obtain a copy of your personal data
- Right to Rectification: Correct inaccurate or incomplete data
- Right to Erasure ("Right to be Forgotten"): Request deletion of your personal data
- Right to Restrict Processing: Limit how we process your data
- Right to Data Portability: Receive your data in a structured, machine-readable format
- Right to Object: Object to processing based on legitimate interests or for direct marketing
- Right to Withdraw Consent: Withdraw consent at any time for processing based on consent
Legal Bases for Processing:
- Contract: To provide our services to you
- Legal Obligation: Tax reporting, KYC/AML compliance
- Legitimate Interest: Fraud prevention, service improvement, platform security
- Consent: Marketing communications, optional data sharing, location-based features
To exercise these rights, contact our Data Protection contact at legal@lucilla.ca.
7.3 Canadian Users (PIPEDA)
Canadian users have rights under the Personal Information Protection and Electronic Documents Act, including the right to access, correct, and withdraw consent for the collection and use of personal information.
7.4 Other Jurisdictions
Residents of Virginia, Colorado, Connecticut, Nevada, and other states with consumer privacy laws have rights similar to those described above under their respective state laws. Contact us to exercise these rights.
8. Data Retention
We retain your information for as long as your account is active or as needed to provide services:
- Account data: Until you delete your account
- Health data: Deleted when your account is deleted
- Transaction records and identity-verification records: As long as applicable law requires
- Paid-match location checks: see Section 13
- Blockchain transactions: Permanent (immutable on-chain)
9. Children's Privacy & Age-Based Access
Lucilla is not directed to children under 13. We do not knowingly collect personal information from anyone under the minimum age that applies in their jurisdiction: 13 in the United States (COPPA), 14 in most Latin American countries, 15 in France, and 16 in Germany and most EU member states (GDPR-K). If we learn a user is under the applicable minimum age, we will delete the account and associated data.
Paid step-match competitions require users to be at least 18 years old, with a higher minimum where local age-of-majority law requires it: 19+ in Canada (British Columbia, New Brunswick, Newfoundland & Labrador, Nova Scotia, Northwest Territories, Nunavut, Yukon) and in Alabama & Nebraska (US); 20+ in Thailand; 21+ in Honduras, Puerto Rico, and Mississippi (US). Age is verified in two stages:
- At point of entry: when a user selects a monetary commitment on the Set Game Mode screen, the app reads their stored date of birth and blocks the selection if they are under 18 or have not added a date of birth yet. Free matches remain available to all ages.
- At identity verification: when cumulative annual winnings reach the identity-verification threshold (currently USD 600, aligned with the US IRS 1099-MISC trigger), the user is required to upload a government ID. Our automated document verification reads the real date of birth off the ID.
If the ID shows the user is under 18:
- New paid-match entry is blocked going forward. Free matches and social features remain available.
- Matches already in progress complete normally — it would be unfair to cancel on opponents who entered in good faith.
- USDC already credited to the user's wallet from prior matches remains with the user. Lucilla does not and cannot reverse settled on-chain transactions.
- The user may re-verify at any time via Account Settings → Identity Verification. A successful re-verification showing 18+ immediately restores paid-match access. This is a compliance hold, not a permanent ban.
- Appeals for mis-identification may be sent to social@lucilla.ca.
10. Security
Lucilla runs on Google Cloud and Firebase and uses Circle for wallets; these providers maintain independent security certifications such as SOC 2 and ISO 27001. Data is encrypted in transit (TLS) and at rest by these providers. Access to production systems is restricted and logged. We also use:
- Secure authentication (OAuth sign-in, passkeys, device biometrics, and multi-factor codes)
- App integrity checks to confirm requests come from the genuine app
- Role-based access controls for internal data access
11. International Users
Your data may be transferred to and processed in countries outside your residence, primarily the United States and Canada. We ensure appropriate safeguards are in place for international transfers, including standard contractual clauses where required.
App distribution footprint: The Lucilla app is currently distributed to approximately 145 countries on the Apple App Store and approximately 157 countries on the Google Play Store. Countries currently excluded from one or both stores due to US sanctions, regulatory restrictions, or pending local registrations include (non-exhaustive): Afghanistan, Algeria, Belarus, Bhutan, Brazil, Brunei, China mainland, Cuba, Egypt, India, Iran, Iraq, North Korea, Libya, Madagascar, Malawi, Mauritania, Morocco, Nepal, Pakistan, Russia, South Korea (App Store only), Syria, Türkiye (App Store only), Venezuela, and certain small-island territories. The authoritative list for your region is the regional Apple App Store or Google Play Store listing. EU/EEA users are served via Lucilla's appointed EU representative where required by the Digital Services Act.
12. Transaction Data & Fraud Monitoring
To prevent fraud and financial crime, screen for sanctions, and comply with applicable law, we collect and monitor transaction data.
Data Collected
For financial transactions in the app, we collect:
- Transaction Details: Amount, currency (USDC), timestamp, transaction hash
- Wallet Information: Sender and recipient wallet addresses
- User Identification: User IDs, usernames, display names
- Geographic Location: City, state, country, latitude/longitude coordinates
- Device Information: IP address, device type, operating system
- Transaction Metadata: Transaction type (send, match entry, subscription, etc.), memos, related IDs
- Risk Assessment: Automated risk scores and flags
Purpose of Collection
- Screen for Sanctions: Block transactions involving sanctioned persons and jurisdictions
- Prevent Fraud: Monitor for fraudulent transactions, unusual patterns and account takeovers
- Risk Assessment: Assign risk scores and flag high-risk transactions for review
- Legal Obligations: Respond to lawful requests and meet the requirements of applicable law
Automated Decision Making
We use automated systems to make real-time decisions about your transactions:
- Risk Scoring: Every transaction receives an automated risk score (0-100) based on multiple factors
- Transaction Blocking: High-risk transactions (score of 95 or above) are automatically blocked
- Identity Verification Triggers: Transactions over $1,000 automatically trigger identity verification requirements
- Velocity Limits: Automated enforcement of hourly (10) and daily (50) transaction limits
- Flagging: Transactions with scores of 50 or above are flagged for review
Your Rights: You have the right to contest automated decisions by contacting legal@lucilla.ca. We will review flagged transactions manually upon request.
Data Retention
Transaction records, identity-verification documents, risk assessments and related communications are retained for as long as applicable law requires, including after you delete your account. Blockchain records are permanent.
Data Sharing
- Law Enforcement and Regulators: pursuant to valid legal process or where applicable law requires
- Service Providers: cloud infrastructure (Google Cloud / Firebase) and security services, under confidentiality obligations
We do NOT sell your transaction data, share it for marketing purposes, or provide it to unauthorized parties.
Your Data Protection Rights
- Access: Request copies of your transaction data
- Correction: Request correction of inaccurate information
- Explanation: Request explanation of risk scores and automated decisions
- Appeal: Contest transaction blocks or account suspensions
Limitations: We cannot delete transaction data that applicable law requires us to keep, modify blockchain records (which are immutable), or remove data subject to active investigations.
13. Location Data for Compliance
For users attempting to enter a paid step-match, Lucilla collects real-time GPS location to verify the user is in a jurisdiction where paid skill-based contests are legal. The GPS coordinates are:
- Used only at the moment of match entry — not continuously tracked.
- Stored temporarily for legal-compliance audit (rolling 90 days).
- Not shared with third parties except in response to a valid legal request.
- Never used for advertising, targeting, or analytics.
Users may decline location permission, in which case the paid match feature will be unavailable. All other Lucilla features remain accessible without location data.
14. Cookies and Tracking
Our mobile app may use:
- Analytics SDKs for usage statistics
- Crash reporting tools
- Push notification services
We do not use cookies for advertising purposes. Our web properties (lucilla.app, enterprise dashboard) may use essential cookies for authentication and session management.
15. User-Generated Content & Moderation
Lucilla includes user-generated content (UGC) in the form of social feed posts, chat messages in 1v1/duo/squad match rooms, social rooms and live spaces, vids, and profile media. We operate the following layered moderation system:
15.1 Pre-Publication Content Filtering
Before a post or chat message is published we run automated filters that block:
- Hate speech, slurs, and discriminatory language
- Threats of violence, dox threats, and harassment
- Explicit sexual content and child sexual abuse material (zero tolerance)
- Crypto / USDC scam patterns (seed-phrase requests, impersonation giveaways)
- Spam, mass-posting, and rate-limit violations
15.2 Reporting (Post-Publication)
Every post and profile has a Report button that lets any user submit a report with one of these categories: spam, harassment, hate speech, violence or threats, nudity or sexual content, illegal activity, self-harm, scam or fraud, misinformation, or other.
Reports are stored immutably and reviewed by our moderation team. The reporting system is rate-limited (no more than 20 reports per user per 24 hours) to prevent coordinated brigading.
15.3 Automatic Takedown Thresholds
- 3 valid reports in a 30-day window: post is automatically hidden from the feed pending human moderator review.
- 10 valid reports in a 30-day window: post is automatically removed; even direct links no longer render the content.
- Human review SLA: we aim to review every auto-hidden post within 24 hours.
15.4 Blocking
Every profile has a Block button. Blocking another user hides their posts, severs any follow relationship in both directions, and prevents direct messaging. Blocks are bilateral and enforced server-side.
15.5 Data Written by Moderation Actions
When you file a report we record your Lucilla account ID, the reported post ID, the reason category, and the timestamp. When you block a user we record the block timestamp and the two account IDs. This data is retained for the life of the account and deleted on account deletion. Appeals for moderation decisions may be sent to social@lucilla.ca.
16. Changes to This Policy
We may update this Privacy Policy periodically. We will notify you of significant changes via email or in-app notification. Continued use after changes constitutes acceptance.
17. Contact Us
For questions about this Privacy Policy, GDPR / PIPEDA / CCPA rights requests, and data-deletion requests:
- Email: legal@lucilla.ca
- Website: lucilla.app
- Legal notices: Lucilla, Inc., c/o Sebastian Borjas, s.borjas@lucilla.ca
For abuse reports, UGC moderation, and in-app support: social@lucilla.ca.
For the Ask Lucilla app and the Lucilla text-message service, see the Ask Lucilla Privacy Policy and the Rewards legal documents.
To exercise any of your data rights, contact us at the email above. We will respond within 30 days (or 45 days for CCPA requests).