Lomari
Lomari Privacy Policy
Controller
The controller responsible for the processing described here is VML Development GmbH, Rugenbarg 35j, 22549 Hamburg, Germany (Amtsgericht Hamburg, HRB 166547, VAT ID DE 340365764). Represented by Sergey Pikalev.
For access, correction, export or deletion requests, and for any other question about this policy, write to info@vml-development.com.
What we process
Account identifier, display name, family membership and role, physical device identifier, device name, app version and build, battery level and charging state, coarse motion state (moving, stationary, or unknown), push notification tokens, message content, safety zones, and precise location — the latter only while location sharing is switched on for that account or dependent child device.
Why
To operate the family safety features you asked for: showing the last known position of consenting family members, delivering messages and alarms, and notifying parents about safe-zone events. We do not sell personal data, do not use location for advertising, and do not track users across other companies' apps or websites.
How long we keep it
| Data | Retention |
|---|---|
| Last known location (one point per device) | replaced by each new point; deleted after 7 days |
| Debug/TestFlight movement history | up to 7 days only while internal diagnostics are enabled for development or TestFlight; disabled in public production unless this policy and App Store privacy labels are updated first |
| Safe-zone events | 30 days |
| Audit and configuration events (no coordinates) | 90 days |
| Delivery diagnostics (no message content, no tokens) | 14 days |
| Device-uploaded local diagnostic logs (no coordinates or tokens) | 14 days |
| Messages | until the account or the family space is deleted |
| Sessions | until expiry, at most 30 days |
| US parent verification record (outcome and timestamps only, never a card number) | while the account exists; deleted with the account |
The product map uses only the latest known location: a new position atomically replaces the previous one there. Public production does not keep a route or movement history. During internal development or TestFlight debugging we may temporarily keep a short movement history to diagnose background delivery reliability; it is shown only in diagnostics and must stay disabled in public production unless the legal and App Store privacy disclosures are updated first. Our database provider retains point-in-time backups for up to 30 days for disaster recovery; those backups are not used to reconstruct movement history and expire automatically.
Encryption
Data is encrypted in transit (TLS) and encrypted at rest by our infrastructure providers. This is not end-to-end encryption: our servers can technically access coordinates and message content in order to deliver them.
Processors
Cloudflare (API and database), Supabase (account authentication), and Apple (Sign in with Apple, push notifications, Location Push Service) process data on our behalf under data processing agreements. Stripe processes card details for United States parent verification only (see below); those details are entered on Stripe's own page and never reach us.
Consent and parental controls
Adults switch their own location sharing on and off. For dependent child devices, a parent can switch app-level location sharing on or off, and may also temporarily pause updates to save battery. This does not grant iOS system permissions: Always and Precise Location are still controlled on the device. A person whose location is shared can always see in the app that sharing is active and who requested their position.
Children
A parent or legal guardian confirms guardianship when inviting a child; we record that confirmation with a timestamp and the version of the consent text. The applicable age of digital consent differs by country and is applied accordingly.
United States: verifiable parental consent (COPPA)
If your App Store account is in the United States, the Children's Online Privacy Protection Act requires your verifiable consent before we collect anything from your child's device. This section is that notice.
Consent is required, and nothing is collected without it
Until verification succeeds, we do not let you create a child invitation, and no location, device, or message data from your child's device reaches us.
What we collect from your child's device, once sharing is on
Precise location; device name, model and app version; battery level and charging state; and any messages your child sends inside your family space.
How each category is used
Location: shown to the family members you authorize, and to trigger the arrival and safe-zone alerts you configure. Device information: to keep the family map and diagnostics accurate. Messages: delivered to their intended recipients inside your family space. None of it is used for advertising, sold, or used to train AI models.
Who receives it, and why
The only recipients of your child's location and messages are the members of your own private family space — people you invited or who invited you. Sharing location within the family is the entire service you are requesting, so this disclosure is integral to it. We do not disclose your child's data to advertisers, data brokers, or anyone outside your family space.
You may consent to our collecting and using your child's data without consenting to this disclosure only where the disclosure is not integral to the service. Because sharing within the family is the service, we do not offer a version of Lomari that collects a child's location but withholds it from the family: if you do not want a device's location shared with the family, do not enable sharing for that device.
How we verify you are the parent
The Rule (16 CFR 312.5(b)(2)(ii)) permits verification through a payment card or online payment system that provides notification of each discrete transaction to the primary account holder. You enter your card on our payment provider's own secure page — never in this app, never on our servers. We create a temporary authorization of USD 1.00 and cancel it immediately: it is never captured, you are never charged, and nothing is purchased. Your card number is never sent to us and never stored by us.
What we keep about the verification
Only the outcome (succeeded or failed), the times it was started and completed, the version of the consent and notice texts you were shown, an opaque reference supplied by the payment provider, and the App Store storefront country that told us to ask. See our data retention policy below for how long. No card number, no card network reference beyond the payment provider's own opaque identifier, and no other payment details are ever stored by us.
Your rights as the verifying parent
You may review the categories of data we hold about your child, request its deletion, stop further collection, and withdraw your consent at any time — see "Your rights" below and the controls in Settings. Withdrawing consent stops further collection from your children's devices and prevents new child invitations. We record that you withdrew consent and when, so the history of what was permitted stays accurate; we do not silently erase the fact that consent once existed. To make a request that this notice does not cover a self-service control for, contact us using the details in "Your rights" below — we verify that a request comes from the account that gave consent before acting on it.
We did not collect any separate contact information from you solely to seek this consent: verification uses your existing signed-in account and the payment provider's own page directly.
This notice is also published as our online notice under 16 CFR 312.4(d). Our written, published data-retention policy is in the "How long we keep it" section above and in the retention document referenced in "Your rights."
Website lomari.app
Our website uses no cookies, no third-party analytics and stores nothing on your device. To understand which campaigns bring visitors, our own server records for each page view and each click on the App Store button: the page and language, the campaign parameters in the address (utm_source, utm_medium, utm_campaign, utm_content, utm_term), the domain of the referring website, the country derived from your IP address, and a coarse device class (phone, tablet or desktop and its operating system). The IP address itself is not stored, no identifier is created and visits cannot be linked to a person or to each other. The legal basis is our legitimate interest in measuring our marketing (Art. 6(1)(f) GDPR); the browser signals “Do Not Track” and “Global Privacy Control” are respected. The data is kept in Cloudflare Workers Analytics Engine for 3 months and then deleted. When you tap the App Store button, Apple receives the campaign name in the link; Apple’s own privacy policy applies from there.
Your rights
You can access, correct, export and delete your data, including a child's data if you are their verified parent. Account deletion is available in the app and removes membership, devices, locations, zones, messages, tokens and consents. To review the specific personal information collected from your child, request its deletion, or stop further collection without deleting the account, contact info@vml-development.com; we authenticate the request against your verified-parent record before acting on it. You may also lodge a complaint with your local supervisory authority.
Not an emergency service
Lomari depends on iOS, Apple Push Notification service, network availability and battery. It cannot guarantee delivery or availability and is not a substitute for the emergency services.
Last updated: 10 September 2026.