Privacy Policy

What this policy covers

This Privacy Policy describes how Lyra ("Lyra", "we", "us") collects, uses, and protects information when you use the Lyra Mac application and the website at heylyra.co.uk.

The short version

What you write stays on your Mac unless a specific feature sends a specific thing for a specific job — and every one of those is listed on this page with its off switch.

Everyday corrections are processed on-device. The cloud features — cloud rewrites on the trial and Pro, reply drafting, and voice profiles if you switch them on — send only what is listed below, and Local-Only mode turns them all off. We collect the minimum information needed to provide accounts and subscriptions: your email address (from Google sign-in) and your subscription status. We do not store what you type or what Lyra rewrites. How Lyra uses the cloud is the canonical account of exactly which features run where, and what our server sees. The website has one optional advertising cookie, which stays off unless you accept it.

Information we collect

When you sign in:

When you subscribe:

Payment details (card number, billing address, etc.) are processed and stored by our payment processor, Stripe. We never see or store payment information. See "Subprocessors" below.

Information we do not collect

We do not collect, store, or transmit:

Everyday corrections happen locally on your Mac using a model that is downloaded to your device on first launch. Once downloaded, your everyday corrections need no internet connection and work fully offline. The cloud features simply pause when you are offline, and are disabled entirely in Local-Only mode. How Lyra uses the cloud lists them and sets out exactly what each one sends.

We do send usage telemetry, which is described in the next section. It never contains any of the things listed above.

Usage telemetry

Lyra sends usage events to our backend so I can see whether the app works: which features fired and how often (e.g. "rewrite accepted", counts per day), app version, macOS version, your Mac's RAM size and which local model tier you're on. These events are linked to your account so I can debug your specific issue when you write to me. Telemetry never includes what you type: no message text, no keystrokes, no document content, no recipient names.

It is on by default and you can switch it off: Lyra → Settings → Privacy → Share anonymous usage counts. With it off, no usage events are sent at all. This is a separate switch from Local-Only mode, which governs the cloud writing features.

Cookies and the website

The Lyra app itself uses no cookies — it is not a browser. This section is about heylyra.co.uk only.

Always on. We use Vercel Web Analytics to count page views. It sets no cookies, stores nothing on your device, and cannot follow you to other sites, so there is no consent to give and nothing to switch off.

Only if you accept. When we run ads on Reddit, we would like to know which of them actually bring people here. If you accept the cookie banner, we load Reddit's advertising pixel. It sets a _rdt_uuid cookie in your browser and reports to Reddit that a page was visited, a download was started, or a sign-in was completed. Reddit handles what it receives as its own controller, under its own privacy policy, and may use it to measure our campaigns and build advertising audiences. It never receives what you write in Lyra, your email address, or your account details.

If you accept, the same conversions are also reported to Reddit from our own server rather than only from your browser, because ad blockers and Safari's tracking rules stop a good half of browser reports from arriving. That server-side report contains the same events and, alongside them, your browser's user-agent string, the click identifier from the Reddit ad you arrived through, and your IP address hashed with SHA-256 before it leaves our server — never in the clear. It still carries no email address, no account details, and nothing you have written.

Nothing is loaded, no cookie is set and no server-side report is sent before you accept. If you decline, the pixel is never fetched at all and nothing is reported. You can change your answer whenever you like using the Cookies link at the foot of any page.

How we use the information we do collect

We never sell your information, and nothing from the app — your account, your telemetry, your writing — is used for advertising or profiling. The single exception lives on this website and only with your consent: the Reddit advertising pixel described in Cookies and the website, which measures our ad campaigns.

Where your information is stored

Account and subscription data is stored in Supabase, a managed database service. Supabase processes this data on our behalf. Storage is in the EU (Ireland region).

The Lyra model, your corpus of sent messages, and any voice profiles Lyra has derived live on your Mac, in ~/Library/Application Support/Lyra/. None of it is synced to a server or backed up by us. If you switch voice profiles on, a small sample of your sent messages for one contact is sent for classification and the resulting label is stored back on your Mac — How Lyra uses the cloud describes that in full.

Subprocessors

We use the following processors to operate Lyra:

Each processor is bound by their own privacy policy and our agreement with them. Reddit is the odd one out: it is not processing data on our behalf but acting as its own controller of what its pixel collects, which is why it only runs with your consent.

How long we keep your data

We keep your account information for as long as your Lyra account is active. If you delete your account (see Data Controls), we delete your account and subscription records within 30 days, except where retention is required by law (for example, tax records related to past payments).

Your rights

Depending on where you live, you may have rights to:

See the Data Controls page or email founder@heylyra.co.uk to exercise these rights.

Children

Lyra is not directed at children under 13 (under 16 in the EEA and UK). We do not knowingly collect data from children. If you believe a child has signed up, contact us and we will delete the account.

Changes to this policy

We may update this Privacy Policy. Material changes will be announced via email to your account address and on this page. The "Last updated" date at the top reflects the most recent change.

Contact

For privacy questions or to exercise your rights, email founder@heylyra.co.uk.

Lyra is operated by CODE NINJA COACHING LIMITED, United Kingdom.