Privacy Policy

Last updated: October 2026

Lilium is a family photo and video service operated by the individual developer operating Lilium ("we", "us"). Lilium is a product name, not an incorporated company. Contact support@liliumapp.com about this policy or your information. You retain ownership of your content. We do not sell personal information, use family media for advertising, or use your uploads or face-reference images to train machine-learning models. This policy describes the service's data processing and does not replace any separate consent required by law.

1. Information processed

Account and family information: account identifiers, name, email, optional profile image, family membership and roles, invitations, and support correspondence. Content you provide: photos, videos, captions, dates, child profiles (including name, birth date and optional avatar), and associated metadata. Media may include faces, voices, location or other sensitive details, including EXIF location information where present. Avoid including addresses, school details or other identifying information you do not wish recipients to see. Face recognition: selected face-reference crops are used to recognize an enrolled child. The numeric face signatures are generated and kept on your device. Reference-image cloud backup is described in Section 4. Payments and notifications: subscription status, product and transaction references, and device push tokens. Apple or Google processes store payments; we do not receive your payment-card details. Location labels: when you import from your photo library, the coordinates embedded in a photo (where present) are converted into a place name on your device using your phone's operating-system geocoding service (provided by Apple or Google under their terms), and the label is stored with the memory. We do not request or track your live device location. Diagnostics and analytics: device and operating-system information, app version, timestamps, usage events and error/performance information. These can be linked to an account identifier. Network addresses may be processed by service providers and used to derive approximate location. Mobile session replay is disabled. On the liliumapp.com website a sample of visits may be recorded as a masked session replay (text you type is never captured); no analytics or replay runs on share pages or invitation pages, whose addresses contain a secret. We do not intentionally include memory media, captions, child names or family names in analytics event properties. App performance and crash diagnostics (launch and screen timings, screen names, device model, operating-system and app version, language, battery and network state, and crash reports) are sent to Expo against a random installation identifier. We do not link that identifier to your account, but it is not anonymous: it stays on your device until you uninstall the app and may be restored from a device backup. We cannot match it to an account, so we cannot locate these diagnostics by account. Expo also receives your IP address and retains these diagnostics for at least 60 days. Import matching: account/family-scoped pseudonymous references help identify library items already imported without retaining the raw device-library identifier. A reference does not itself retrieve your photo.

2. Purposes and legal bases

We process information to authenticate accounts, operate family workspaces, import and organize media, deliver user-directed sharing, manage subscriptions and notifications, answer requests, and maintain reliability and security. Where the GDPR or UK GDPR applies, contractual processing covers the adult account holder's requested service. Legitimate interests may support proportionate reliability, security, abuse prevention and service improvement, subject to the rights of affected people, especially children. We rely on legal obligations where processing or preservation is required. Where consent or a special-category condition is required, it must be established separately; accepting these Terms or an operating-system permission is not a blanket consent to all processing. You may object to processing based on legitimate interests and withdraw consent where consent is the basis. Contact support@liliumapp.com. Device notification permissions can also be withdrawn in system settings.

3. Family access and public sharing

Family OWNER and ADMIN roles can manage members and family content. VIEWER members can see memories marked FAMILY. A PRIVATE memory is available to family OWNER/ADMIN roles; PRIVATE does not mean visible only to its uploader. An authorized administrator can create a public share page. Anyone receiving or being forwarded the link can access the shared content without a Lilium account. Recipients may download, copy, screenshot or redistribute what they see. Media is delivered through object-storage and video-delivery URLs. Treat those URLs as sensitive: revoking a share page or removing a member does not necessarily invalidate media URLs already obtained, and cannot retrieve independent downloaded copies. Lilium does not provide end-to-end encrypted sharing. These limitations also matter when choosing reference-image backup.

4. Face recognition and reference backup

Face recognition is optional and runs on your phone. Reference photographs are used to generate numeric face signatures and compare them with faces in your photos and sampled video frames. Your library is not uploaded for recognition, and numeric face signatures remain on the device. Only memories you choose to save are uploaded; choosing Save all also saves matching memories found during that scan. Check matches before saving or sharing. Manual memory creation and sharing remain available. The separate in-app consent screen is temporarily unavailable in the current testing build. This policy and general signup terms do not replace any consent or authorization required by applicable law. Only enroll a child or process media when you have the necessary authority and permissions, including for other people appearing in that media. Reference-photo cloud backup is a separate optional setting, off by default. When you enable it, your family's reference photographs are stored through Cloudflare R2 so authorized family administrators can download them and generate signatures on their own devices. Numeric face signatures are not uploaded. These are sensitive photographs, not anonymous data. The media-link limitations in Section 3 apply. When you save a memory from a scan, the app sends, with each photo, where it found faces and, for an enrolled child it recognised, that child's profile identifier, so recaps can prefer and frame photos of your child. These positions and links are stored with the photo on our servers; numeric face signatures are never uploaded. They are removed from the photos you uploaded when you turn off face recognition, and with the photos themselves. Turn off face recognition in its settings to stop scanning, erase local enrollment, remove the face positions and child links from your uploads, and request deletion of the family's cloud reference backups. Turning off only backup preserves on-device recognition. This control cannot remotely erase local setup on other devices or independently downloaded copies. Original library items, ordinary memory uploads and saved tags are not erased by this control. Local enrollment is kept while recognition is enabled and is erased on turn-off or sign-out. Removing a child or losing administrator access also requires affected enrollment cleanup when the device reconnects. Cloud backups are kept while enabled and queued for deletion on turn-off, child deletion or applicable account deletion. Scheduled physical cleanup follows expiry of outstanding upload URLs, normally within 30 days, subject to provider retries and legally required preservation. Historical consent receipts, where present, are retained with the membership until applicable account or membership erasure; this temporary flow does not create a new consent receipt. Keeping signatures on-device does not by itself exempt biometric processing from applicable law. Family administration is not proof of guardianship. Respect custody restrictions and the rights of the child and other guardians. Contact support@liliumapp.com about consent, objections, purpose completion or deletion requests.

5. Children and safety

Lilium accounts are intended for adults who are at least 18 and have reached the age of majority where they live. Child profiles represent children in family media; they are not child login accounts. Adults must have lawful authority to provide and share a child's information. Access to a family workspace does not establish guardianship or override a custody order. We do not knowingly permit accounts operated by children. Contact support@liliumapp.com if you believe a child is using an account or their information was provided without appropriate authority. We assess requests concerning a child's privacy, including requests from authorized guardians, according to applicable law. We prohibit child sexual exploitation, grooming and other unlawful or harmful use. Report concerns to safety@liliumapp.com; do not email suspected illegal imagery. Provide an in-app location or link and a description sufficient to locate the concern. If someone is in immediate danger, contact emergency services. The service is not an emergency-response or child-monitoring service. We may review reported content, restrict access, preserve relevant evidence and disclose information when required by law or appropriate to address imminent harm. Where U.S. reporting requirements apply, apparent child-exploitation offenses are handled under applicable reporting and preservation law. We do not promise that every upload is scanned or that all harmful content will be detected. Notice may be withheld where legally prohibited or where permitted and necessary to protect an investigation or person.

6. Service providers and international processing

Providers used to operate Lilium include Clerk (identity), Prisma Postgres (application records), Cloudflare R2 (media objects), Bunny (video processing/delivery), RevenueCat (subscriptions), Novu (notifications), Sentry (diagnostics), Expo (app performance and crash diagnostics), PostHog (analytics), and Vercel (website/API hosting and associated diagnostics). Apple and Google also process information under their own store and platform terms: sign-in, purchases, push notifications and the on-device geocoding described in Section 1. Face detection on your device uses Google's ML Kit library and the face-signature model runs locally through ONNX Runtime; neither sends your photos or signatures to us or to Google, although on Android the ML Kit model may be downloaded through Google Play services. Information may be processed outside your country, including through global delivery networks. The protections and transfer arrangements depend on the provider, service configuration, your location and applicable law. Contact support@liliumapp.com for information about the providers and transfer safeguards applicable to your information. We do not authorize providers to use family media for their own advertising or model training. We may also disclose information to comply with valid legal process, protect legal rights or address security and safety incidents. If operation of Lilium transfers to another operator, we will provide any notice, choice or consent required by applicable law before materially different processing.

7. Security

We use encrypted network connections and access controls in the application. Third-party infrastructure also processes and stores information. No online service can promise absolute confidentiality, uninterrupted availability or freedom from data loss; the media-link limitations in Section 3 are important. Protect your sign-in credentials and invite only people you trust. Notify support@liliumapp.com of suspected account compromise or security issues. If a personal-data incident requires notification, we will follow the applicable standards and deadlines, including notification to affected individuals without undue delay where required and supervisory-authority notification within 72 hours where GDPR Article 33 applies.

8. Account deletion and retention

Request account deletion in Settings → Delete Account, or use the instructions at liliumapp.com/account/delete. Deletion removes your account, comments, reactions, your authored memory text and your uploaded media, including uploads previously shared with a family. A shared container may remain to hold other members' independent uploads. Shared child profiles and enrollment used by remaining family members are not automatically removed merely because one member leaves; contact us about your authority to request their removal. Families with no remaining members have their content and child-reference backups queued for deletion. Deletion disables account activity and queues processor cleanup. Media objects, derivatives and eligible deleted database records are removed by scheduled jobs. Physical media cleanup normally starts after seven days, with a target of completing routine erasure within 30 days. This is not a guaranteed recovery window. Provider failures may require retries; we will explain material delays in responding to a verified request. Face-reference crops marked for deletion are eligible for the next cleanup run. Deleted child profiles and their inline avatars are removed after reference-object cleanup, subject to lawful preservation. Independent copies held by recipients and media uploaded by other people are outside the account-deletion operation. A minimal account-deletion record prevents delayed identity events from recreating the account and tracks outstanding cleanup. Billing, security, dispute and legally preserved records may be retained where necessary and lawful. Identified analytics and diagnostic records are not anonymous merely because they use an account ID; requests concerning these records are handled through support@liliumapp.com. Truly anonymous aggregate statistics may be retained. Backups and provider-managed logs have their own deletion/expiry cycles. We do not guarantee that every provider backup disappears at the instant an account is deleted. Preserved material is retained for the applicable legal period and is not restored to ordinary user access through account deletion. Deleting an account does not cancel an Apple or Google subscription.

9. Privacy rights and requests

Depending on applicable law, you may request access, correction, erasure, portability, restriction, or objection to processing, withdraw consent, and complain to a competent data-protection authority. We do not sell personal information or share it for cross-context behavioral advertising. We will not unlawfully discriminate against you for exercising privacy rights. Contact support@liliumapp.com and describe the request. We may reasonably verify identity and, for a child or another person, your authority to act. Do not send unnecessary identity documents or children's media by email. We respond within applicable legal deadlines and explain any permitted extension or refusal. Individual media can also be downloaded through the app; contact us for a broader data-access request.

10. Changes and contact

We will update the date above when this policy changes and provide appropriate notice of material changes. A policy update or continued use does not substitute for fresh consent where consent is required, or authorize a retroactive incompatible use of information. Privacy and account requests: support@liliumapp.com. Safety reports: safety@liliumapp.com. This policy does not limit your mandatory rights or prevent complaints to regulators.