Privacy Policy

Last updated: August 2026

Lilium is built around one promise: your family's memories belong to your family. This policy explains what we collect, how we use it, and the controls you have. Our commitment to you: • You own your photos, videos, and captions at all times. • Memories stay within your family unless an administrator deliberately creates a public share link. • We will never sell your personal information.

1. Information we collect

We collect the minimum data required to run the service. From you, directly: • Name and email address (via our identity and authentication provider). • Photos, videos, captions, and metadata you upload. • Information about your children you choose to add (name, birth date, optional avatar). • Face reference images: if you use face recognition, the small face-crop images you select to enroll a child (see "Face recognition and reference images"). The underlying biometric face signature is generated and kept only on your device and is never uploaded. • Invitations you send to family members. • Subscription and billing details if you upgrade to a paid plan (processed by Apple, Google, and our subscription management provider, we do not store card numbers). Automatically: • Device type, OS version, and app version for crash diagnostics. • Pseudonymous usage events (such as screens opened and actions completed) tied to your account identifier so we can understand reliability and improve the product. We do not record app sessions or the contents of your memories in analytics. • A keyed, pseudonymous reference for library items you add or scan. This helps us recognize an item already uploaded without storing your device's raw Photos or MediaStore identifier. The reference is scoped to your account and family and cannot be used to retrieve the media itself. • Push notification tokens so we can deliver alerts you opt into.

2. Lawful bases (EEA / UK users)

If you are in the European Economic Area or the United Kingdom, we rely on the following lawful bases under the GDPR (and UK GDPR) to process your personal data: • Performance of a contract: to operate the Lilium service you signed up for, including hosting your memories and powering family workspaces. • Legitimate interests: to keep Lilium safe, including detection of child sexual abuse material (CSAM) and prevention of fraud, abuse, and security incidents. Our interest in protecting children and the integrity of the service is balanced against your privacy rights, and we keep the processing minimal and proportionate. • Legal obligation: to report apparent CSAM and other child-exploitation offenses to the National Center for Missing & Exploited Children (NCMEC) under 18 U.S.C. § 2258A and the REPORT Act of 2024, and to respond to valid legal process. • Consent: to send you push notifications. You can withdraw consent at any time in your device settings or in Settings → Notifications. You have the right to object to processing based on legitimate interests, to withdraw consent at any time without affecting prior processing, and to lodge a complaint with your supervisory authority.

3. How we use your information

We use your information to: • Provide and operate the Lilium service. • Deliver notifications you have enabled. • Process subscription purchases. • Investigate bugs, abuse, and security incidents. • Detect, prevent, and respond to illegal content, in particular child sexual abuse material (CSAM), and other violations of our Terms. • Communicate important service announcements. To keep Lilium safe we use automated tools (including hash-matching against databases of known illegal imagery, and machine-learning classifiers) and, when necessary, human review by trained safety personnel to analyze uploaded photos and videos. We do not use your photos or videos to train machine-learning models, and we do not sell your personal information or share it with advertisers.

4. Who can see your memories

Memories are visible only to members of the family (or "workspace") where they were uploaded. Family admins can invite, remove, and assign roles to members. Viewers can only see memories marked as FAMILY visibility; PRIVATE memories remain visible only to OWNER/ADMIN roles. An owner or administrator may create a public share link for a memory. Anyone who receives that link can view the shared memory until the link is revoked, and people may retain copies they downloaded while it was active. If you remove a family member, they lose family access going forward, but any copies they previously downloaded remain on their device.

5. Children's information and child safety

You may add children to your family workspace and associate memories with them. This information is provided by you and visible only to members of your family. We do not knowingly collect information directly from anyone under the age of 13. Lilium is intended for use by adults age 18 or older, and by using Lilium you confirm that you have the right to share any information about a child that you upload. We do not engage in behavioral advertising and we do not profile children. We do not build advertising profiles, run targeted ads, or share information about children with advertisers, ad networks, or data brokers, and we do not allow third parties to do so through Lilium. Lilium has zero tolerance for child sexual abuse material (CSAM), grooming, trafficking, or any other sexual exploitation of minors. Consistent with U.S. federal law (18 U.S.C. § 2258A and the REPORT Act of 2024): • We use industry-recognized tools to detect apparent CSAM on the service. • When we become aware of apparent CSAM or other apparent child-exploitation offenses, we remove the content, suspend the responsible account, preserve the content and related records for at least one (1) year, and report to the National Center for Missing & Exploited Children (NCMEC) CyberTipline, as required by law. • We cooperate with NCMEC and law enforcement and may provide them with content, account data, and activity logs without prior notice to the affected user, as permitted and required by law. If you believe Lilium is being misused to harm a child, email safety@liliumapp.com immediately. If a child is in immediate danger, contact local law enforcement first. If you believe we have inadvertently collected information from a child under 13 that we should not have, please contact support@liliumapp.com.

6. Face recognition and reference images

Lilium includes an optional face-recognition feature that helps you find all the photos of a child across your library. You teach it by choosing a few photos of your child; from each one Lilium creates a small cropped image of the child's face (a "reference image"). Two different things come out of enrollment, and we treat them very differently: • The face signature (the biometric part) stays on your device. To recognize a face, Lilium converts it into a mathematical signature (a numeric "embedding"). This signature is created and stored only on your device, is never uploaded to our servers, and is regenerated locally from your reference images if you reinstall or set up a new device. We do not receive, store, or have any access to it. • The reference images are backed up to keep your setup working. So your enrollment survives reinstalling the app, signing in on a new device, or the periodic sign-out required for security, and so it can sync across your own family's devices, the small reference face-crop images are stored in Lilium's private, per-family cloud storage. They are served only over short-lived, signed links and are accessible only to members of your family. Reference-image backup is on by default. You can turn it off at any time in Settings → Face recognition. Turning it off deletes the reference images we hold in the cloud; your on-device setup keeps working. How we limit this: • Purpose limitation. Reference images are used only to restore and sync your family's face-recognition setup. We do not use them for advertising, and we do not use them to train machine-learning models. • Family-only access. Reference images live in storage namespaced to your family and are never shared with other families or third parties, except the media-storage vendor that hosts them for us under contract (see the section on where your data is stored). • Deletion. Reference images are deleted when you turn off backup, when you remove the associated child, or when you delete your account, subject to the backup and safety-preservation windows described in the retention section. A note on sensitive data. Some laws, including the EU/UK GDPR and U.S. state biometric-privacy laws such as the Illinois Biometric Information Privacy Act (BIPA), treat face data as sensitive. We have deliberately designed this feature to keep the biometric identifier, the face embedding, on your device and out of our systems, so that what we store in the cloud is limited to ordinary photographs of your child. The same children already appear in the memory photos you upload; reference images are not a new category of subject, only a smaller, purpose-built crop. Where consent is required for this processing, we ask for it, you can withdraw it at any time by turning the feature off, and we do not sell or share this data.

7. Where your data is stored and who processes it

Lilium relies on a small number of vendors to operate the service. Each is bound by a written data-processing agreement, may only use your data to provide services to Lilium, and is described below: • A media object storage provider (United States): encrypted object storage for the photos and videos you upload. • A video delivery and storage provider (United States): encoding and streaming of video memories you upload. • An identity and authentication provider (United States): authentication, sign-in, and user identity management. • A subscription management provider (United States): subscription and entitlement records. Apple and Google process the actual payments; we do not see your card numbers. • A notification delivery provider (United States / European Union): delivery of push notifications you opt into. • A crash reporting and error monitoring provider (United States): crash and performance diagnostics linked to an opaque account identifier for support and incident investigation. • A product analytics provider (United States): pseudonymous interaction events linked to an account identifier. Mobile session replay is disabled, and we do not send memory photos, captions, child names, or family names as analytics properties. • A managed database provider hosted on regulated infrastructure in the United States: application records (family, memberships, memory metadata). Our vendors are contractually bound to protect your data and may only use it to provide services to Lilium. For users in the EEA or UK, we rely on Standard Contractual Clauses (SCCs) and the UK International Data Transfer Addendum to transfer data to our US-based vendors, together with supplementary technical and organizational measures (encryption in transit and at rest, access controls, and audit logging).

8. Security

We use industry-standard practices to protect your information: encrypted transport (TLS) for every API request, encrypted storage at rest, access controls on administrative systems, and audit logging of sensitive operations. No system is perfectly secure. We encourage you to use a strong, unique password for your Lilium account. If we discover a security incident affecting your data, we will notify you without undue delay and within 72 hours of becoming aware of the incident if it presents a high risk to you, in line with GDPR Article 34. We will also notify supervisory authorities and other regulators where required by law.

9. Your rights and controls

You can: • View and edit your profile, children, and memories from within the app. • Export copies of your media by tapping "Download" on any memory. For a complete export of everything we hold about you, email support@liliumapp.com; we fulfill export requests within 30 days, extendable to 90 days if the request is complex (we will tell you in advance if we need the extension). • Remove individual memories or children at any time. • Delete your entire account from Settings → Delete Account. This permanently deletes your sign-in credentials, push subscriptions, your customer record with our subscription management provider, and any video metadata held by our video delivery provider, and the personal records you own (children records you added solo, memories you authored privately). Memories you authored that are shared with a family are anonymized: the content remains with the family, but your name is removed from the authorship record. Residents of California, the European Union, the UK, and other jurisdictions may have additional rights, including the right to request a copy of the personal data we hold about you, to correct it, to restrict or object to processing, or to have it deleted. To exercise these rights, email support@liliumapp.com. California residents: We do not sell your personal information, and we do not share it for cross-context behavioral advertising. You have the right to know what personal information we hold about you, to delete it, to correct it, and to limit our use of sensitive personal information. To exercise these rights, email support@liliumapp.com. We will not discriminate against you for exercising any of these rights.

10. Data retention

We keep your information for as long as your account is active. When you delete your account we remove your personal identifiers. Backups may persist for up to 30 days before being permanently purged. Soft-deleted Child profiles are retained for up to 30 days before permanent deletion to support account-recovery flows (e.g. if you remove a child by mistake, an admin can restore the profile within that window). Memory and Media records you have deleted are scheduled for permanent removal from our object storage and video delivery providers within 30 days. Face reference images are retained while face-recognition backup is enabled. When you turn backup off, remove the associated child, or delete your account, the cloud copies are scheduled for permanent deletion within 30 days. The on-device face signature is removed locally when you delete the associated child or the app's data. Safety and law-enforcement preservation described above overrides these windows where it applies. Pseudonymous device-media references are removed when the linked media or memory is deleted, when you leave or are removed from that family, or when you delete your account. They are not retained for safety review because they do not identify media content. Anonymized or aggregated analytics data may be retained indefinitely. Content and records that are the subject of a safety or law-enforcement report, for example, material reported to the NCMEC CyberTipline, are preserved for at least one (1) year from the date of the report (and longer where law requires), even if you delete the underlying memory or your account. These preserved records are access-restricted to trained safety personnel and, where applicable, disclosed only to NCMEC and law enforcement.

11. Law enforcement and safety disclosures

We may access, preserve, and disclose your information, including account details, content, and activity logs, without prior notice to you when we have a good-faith belief that doing so is necessary to: • Comply with U.S. law, including 18 U.S.C. § 2258A and the REPORT Act of 2024. • Respond to valid legal process (subpoena, court order, search warrant). • Cooperate with the NCMEC CyberTipline and with investigations by law enforcement. • Prevent or address fraud, abuse, security incidents, or imminent harm to any person, especially a child. In the specific case of apparent child sexual exploitation, U.S. law prohibits us from tipping off the suspected user, so a silent removal and report may occur without any notification to the uploader.

12. Changes to this policy

We may update this policy from time to time. When we make a meaningful change we will post a notice inside the app and update the "Last updated" date above. Continued use of Lilium after the effective date of a revision means you accept the revised policy. This Privacy Policy is incorporated into and forms part of the Lilium Terms of Service. Any dispute relating to this policy is subject to the dispute-resolution, binding-arbitration, and class-action and jury-trial waiver provisions in the Terms of Service, except where applicable data-protection law gives you a non-waivable right to bring a complaint before a supervisory authority or court.

13. Contact

Privacy questions or requests: support@liliumapp.com. Trust & Safety reports (including suspected child-safety issues): safety@liliumapp.com. We aim to respond to privacy requests within 5 business days; safety reports are triaged on an expedited basis.
Privacy Policy | Lilium | Lilium