Skip to content
ByteVoid
  • Apps
  • About
  • Contact

Latelight - Privacy Policy

Last updated: July 1, 2026

This policy describes how the Latelight iOS app handles your data. Latelight is published by ByteVoid SASU ("we", "our", "us"). The bytevoid.io website has a separate privacy policy at /legal/privacy.

Latelight is a self-reflection tool. It is not therapy, not a medical service, and not a substitute for professional support.

What we collect

On your device (stays on your device)

  • Your relationship content. The people you add, the messages you write, the conversations Latelight has with you, and the Portraits it generates. All of this is stored on your device in encrypted form. We do not have access to it. We cannot read it.
  • Encryption keys. A master key is generated on your device on first launch and stored in the iOS Keychain. It never leaves your device.
  • App preferences. Your settings, onboarding state, and acknowledgment of the medical disclaimer. Stored locally.

Sent off your device (only when you use AI features)

  • Message content for AI processing. When you send a message to Latelight, the message text plus relevant context (the person you are writing about, recent conversation) is sent to our authenticated proxy server, which forwards it to our large language model providers, OpenAI and Google, for the AI response (see Third parties below). The proxy does not store your messages after processing. Each provider's standard API data handling applies during the request.
  • A device authentication token. On first launch, your device generates a random identifier and registers it with our auth server. The server returns a token that authorizes AI requests. This token is not linked to your identity or any personal information.

Subscription and payment

  • Apple handles all payment processing. When you subscribe, Apple processes the transaction. We receive a subscription status (active, expired) from Apple via StoreKit, not your payment details. We do not see your credit card, billing address, or Apple ID.

What we do NOT collect

  • We do not collect analytics on your in-app content (no tracking of what you write, who you add, or what the AI says).
  • We do not have a server-side database of your relationship data.
  • We do not sell, rent, or share your data with advertisers, data brokers, or third parties for marketing.
  • The app does not contain Meta Pixel, Google Analytics, or any third-party analytics SDKs that track user content.

How we use what we collect

The encrypted on-device data lets the app function. The AI proxy routes your messages to generate responses. The auth token lets us validate requests came from a registered device, preventing abuse. The subscription status tells the app whether you have access to premium features.

We do not profile you, train AI models on your content, or use your data for anything beyond running the app.

Third parties (sub-processors)

  • Apple Inc. (USA). App distribution, payment processing, StoreKit subscriptions, iCloud backup of encrypted device data if you have iCloud backup enabled.
  • OpenAI, L.L.C. (USA). Large language model provider via our proxy. Processes your message content and relevant context to generate AI chat responses and conversation summaries. OpenAI's API terms apply. Content sent through the API is not used to train its models by default.
  • Google LLC (USA). Large language model provider via our proxy. Processes your message content to extract relationship facts and classify text for the AI features. Google's API terms apply to this processing.
  • Railway Corp. (USA). Hosting for our authentication proxy and AI relay server. Stores only your device identifier and IP address for anti-abuse. See How long we keep data below.

We do not use Plausible, Resend, or Meta Pixel inside the Latelight iOS app. Those are used only on the bytevoid.io website.

International data transfers

ByteVoid SASU is established in France. The sub-processors listed above (Apple, OpenAI, Google, Railway) are established in the United States, so using Latelight's cloud features involves transferring limited data outside the European Economic Area. These transfers rely on the safeguards required by Chapter V of the GDPR: the EU-US Data Privacy Framework and/or the European Commission's Standard Contractual Clauses, depending on the provider.

Encryption details

Sensitive content (messages, person details, Portraits, conversation history) is encrypted on your device before being written to storage. The encryption key lives in the iOS Keychain. Plaintext copies are cleared from memory once encryption completes. If your device is locked, the data is protected by iOS Data Protection. If you reinstall the app, prior encrypted data is wiped along with the keychain entry; there is no recovery path because there is no cloud copy.

How long we keep data

Data stored on your device stays there until you delete it. It remains for as long as the app is installed and is removed when you delete the relevant item in the app, use "Delete Account and Data" in Settings, or delete the app. Because there is no cloud copy, deleted on-device data cannot be recovered.

On our servers we hold only your device identifier and the IP address of the request. These are used to authenticate requests and prevent abuse, and are kept only for a limited period for that purpose, not indefinitely. Your message content passes through our proxy only for the length of each request and is not stored on our servers.

Your rights

You can email [email protected] at any time to:

  • Ask what information we hold about you (in practice, this is your device authentication token and your subscription status). We do not hold your conversation content.
  • Request deletion. We will delete your auth token and any associated server-side records.
  • Withdraw consent for AI processing (you can also stop using the AI features in the app at any time; deleting the app removes all on-device data).

European Economic Area and United Kingdom (GDPR / UK GDPR). You have the rights above plus the right to data portability, the right to object to processing, and the right to lodge a complaint with your supervisory authority. In France, that is the CNIL. In the UK, the ICO.

California (CCPA / CPRA). You have the right to know what personal information we collect, request deletion, and opt out of "sale" or "sharing" of personal information. We do not sell personal information.

Canada (PIPEDA + provincial laws). You have the rights above. In Quebec, Law 25 grants specific rights regarding automated processing.

Australia (Privacy Act 1988 + APPs). You have the rights above. You can also lodge a complaint with the OAIC.

Children

Latelight is for users 17 years of age and older. We do not knowingly collect data from anyone under 17. If you believe a minor has used Latelight, please contact us and we will delete the associated device records.

Information about other people you mention

When you write about another person in Latelight, what you write stays on your device, encrypted. We do not see it. Because the AI processes your messages, our third-party AI providers (OpenAI and Google) may briefly process descriptions of others as part of generating a response, but those messages are not stored by the providers beyond their standard request handling.

You are responsible for being thoughtful about what you write about others. Do not share information about another person (medical, financial, sexual, immigration status, or other sensitive categories) without their informed consent.

Data controller

The data controller is ByteVoid SASU, 9 rue des Colonnes, 75002 Paris, France. Contact: [email protected].

Data breaches

If a personal data breach affects data we hold, we will notify the CNIL, our lead supervisory authority in France, within 72 hours of becoming aware of it, as required by the GDPR. Where a breach is likely to result in a high risk to your rights and freedoms, we will also inform affected users without undue delay. Because your relationship content is encrypted on your device and is never stored on our servers, a breach of our systems would expose only your device identifier and IP address, not your conversations or the people you write about.

Changes to this policy

We may update this policy. The "last updated" date at the top reflects any changes. Material changes will be surfaced in the app on next launch.

Contact

For questions about this policy, email [email protected].

© 2026 ByteVoid SASU · Paris, France
  • Mentions légales
  • Privacy (website)
  • Terms (website)
  • Latelight Terms
  • Contact