Privacy policy
Last updated: 11 June 2026 · Version 2026-06-11
This privacy policy describes how Lommely processes personal data in connection with Lommely. Contact: jesper.bromose [at] hotmail [dot] com.
1. Who we are
Lommely is a digital service for families where parents manage children's pocket money, chores, and payouts. We are the data controller for the information you and your family create in the service.
2. What data we process
- Parent accounts: email, password (encrypted), consent to terms and privacy policy, session data.
- Child accounts: name, username, optional email, password (encrypted), transaction history, chores, and pocket money settings.
- Family data: family name, links between parents and children.
- Technical data: essential session cookie for login (
lp_session).
3. Purpose and legal basis
- Providing and securing the service (contract, GDPR Art. 6(1)(b)).
- Processing children's data is based on parental responsibility and consent as required under GDPR Art. 8 and applicable law.
- Legal compliance and security (Art. 6(1)(c) and 6(1)(f)).
4. Retention
Data is kept while your account is active. Sessions expire after 30 days. Expired and revoked sessions are deleted automatically within up to 90 days. You can delete child profiles or your account in the app; see section 7.
5. Processors and transfers
We use the following subprocessors (hosting in the EU where possible):
- Railway — database (PostgreSQL) and API/worker hosting.
- Vercel — web app hosting.
Transfers outside the EU/EEA only occur with a valid transfer mechanism (e.g. SCC).
6. Your rights
You have the right to access, rectification, erasure, restriction, data portability, and objection. Contact us to exercise these rights. You may lodge a complaint with your supervisory authority.
7. Deletion
The main parent can delete child profiles or the entire account under account settings in the app. For other requests (including data portability), contact us.
8. Security
Passwords are hashed with Argon2. Sessions are stored as cryptographic hashes. Communication uses HTTPS in production.
9. Changes
For material changes we update the date and version and inform you where required.