Back

Privacy Policy

Privacy Policy — Lyrio. Effective date and last updated: March 5, 2026.

This English text is a courtesy translation; the Portuguese version of this Privacy Policy is the one that legally governs and prevails in case of any discrepancy.

This Policy explains how we handle personal data in Lyrio, in compliance with the LGPD (Lei nº 13.709/2018, Brazil's General Data Protection Law).

1) Controller and contact

  • Controller: Blessed Byte
  • CNPJ: 55.358.516/0001-02
  • Address: Rua Rio Grande do Norte, 1435, sala 708, pavimento 7, Savassi, Belo Horizonte/MG, CEP 30130-138
  • Privacy e-mail: [email protected]
  • Support channel: [email protected]
  • Data Protection Officer (DPO): Not applicable at this time

2) Principles: data minimization and privacy by default

Lyrio was designed to minimize data collection. In the current version:

  • blocking rules (apps/categories) are stored locally on the device;
  • Lyrio uses Screen Time to enforce restrictions;
  • Lyrio does not use a VPN/DNS/Proxy and does not inspect traffic content to enforce blocking.

3) What data we collect

We may collect and process the following categories:

A) Account data

  • e-mail address (required)
  • name (optional, if you provide it)
  • credentials (password stored securely, as a hash)
  • account status information (active/inactive)

B) Subscription data (Apple)

  • subscription status (active/expired)
  • transaction/purchase and product identifiers (as returned by Apple)

We do not collect card data. Payments are processed by Apple.

C) Technical and diagnostic data (minimal)

  • device model, iOS version, App version, language
  • error/crash events and stability metrics if a diagnostic tool is enabled

D) Support data

  • the content of the message you send to support
  • attachments you choose to share (e.g., screenshots)

E) Screen Time operating signals (where applicable)

To provide support and indicate whether protections are active, we may process signals such as:

  • whether protections/settings are enabled or disabled
  • the type of restriction configured (per app/category)

By default, we do not collect browsing history, visited URLs, page content, messages, photos or keystrokes.

4) Purposes of processing

We process data in order to:

  • create and manage your account
  • provide and keep the App running
  • validate and manage your subscription and paid features
  • respond to support requests
  • prevent fraud and abuse and improve security
  • comply with legal/regulatory obligations

5) Legal bases (LGPD)

In general, we rely on:

  • Performance of a contract (to deliver the service you requested)
  • Legitimate interests (security, fraud prevention, low-impact improvement of the App)
  • Consent (where applicable, for example, for non-essential analytics)
  • Legal/regulatory obligation (where required)

6) Use by minors

Lyrio may be used by minors under supervision. In those cases:

  • the account and the purchase must be made by a parent or legal guardian;
  • we seek to minimize data;
  • we encourage supervision and responsible configuration.

7) Data sharing

We do not sell personal data. We may share data only when necessary with:

  • Apple (payment/subscription processing and related validations)
  • infrastructure and service providers, as needed for Lyrio to work (for example: Firebase/Google for authentication and backend, e-mail, customer support, and diagnostic or analytics tools when enabled)
  • authorities, under a legal obligation or court order, or to protect rights and safety.

8) International transfers

If any provider processes data outside Brazil, we will adopt contractual safeguards and measures compatible with the LGPD.

9) Retention and deletion

We keep data for as long as necessary for these purposes:

  • account data: while the account is active and for up to 12 months after it is closed, unless a longer legal obligation applies
  • support data: for up to 12 months
  • technical/diagnostic data: for up to 90 days
  • legal/financial records: as required by law

Note: blocking rules stay on the device. If you delete the App or restore the device, those settings may be lost.

10) Security

We apply technical and organizational measures such as encryption in transit, access controls and the principle of least privilege. No system is 100% secure, but we work to reduce risk.

11) Your rights as a data subject (LGPD)

You may request:

  • confirmation of processing and access
  • correction
  • anonymization, blocking or deletion (where applicable)
  • portability (where applicable)
  • information about data sharing
  • withdrawal of consent (where applicable)

Requests: [email protected]

12) Updates to this Policy

We may update this Policy. Material changes will be communicated in the App and/or by e-mail.