Legal / Privacy
Updated August 25, 2026

Email us

Overview

This Privacy Policy explains how LxAppFactory (“we”, “us”, “our”) collects, uses, and shares information when you use our mobile applications, including TimeTokens, LxDiscover, PaceBeep, PantryReady, and Fifty Ten (collectively, the “Apps”).

Different Apps and features may use different permissions and services. If a section below does not apply to the App or feature you are using, it will not apply to you.

1) Who is responsible for your data (Data Controller)

Controller: LxAppFactory
Contact email: support@lxappfactory.pt

If you are contacting us about privacy, please include “Privacy” in the subject line.

2) Information we collect

A) Information you provide

  • Support communications: If you email us, we receive the information you send (such as your email address and message content). We use this to respond and provide support.

B) Information collected automatically

Depending on the App and your settings, we may collect:

  • Device and app information: device model, OS version, app version, language, and similar technical data.
  • Usage and interaction data (Analytics): events such as screen views and feature usage (e.g., opening a detail page, tapping restore purchase). We aim to avoid collecting direct identifiers (like your name) in analytics events.
  • Crash and diagnostics data: error reports, stack traces, and related diagnostic information to help us fix bugs and improve stability.
  • Approximate location from IP (via third parties): Some third-party services may infer approximate location from your IP address for security/analytics purposes.

C) TimeTokens family data

TimeTokens is a family planning and timer app configured by a parent or guardian. It does not require an online account or provide cloud sync. The following information is handled as described below:

  • On-device family content: child profile names and age bands, avatar choices, tasks, rewards, rules, notes, TimeToken balances, timer sessions, history, the parent PIN, and the recovery key are stored in the App’s private storage on the device. This content is not uploaded to or accessible by LxAppFactory.
  • Optional task photos: if a parent enables photo evidence and a user chooses to take a photo, the photo is stored only in the App’s private storage on the device. It is not uploaded to LxAppFactory. Parents can choose whether a photo is deleted after review and can delete retained photos in the App.
  • Optional product analytics: analytics is off by default. If a parent enables it, TimeTokens sends an anonymous installation identifier and limited events about the Premium paywall and subscription actions to PostHog. Event properties are restricted to the plan, billing period, platform, app version, consent state, and a coarse error category. Child profile details, tasks, rewards, notes, photos, PINs, recovery keys, and timer or history content are not included.
  • Crash diagnostics: TimeTokens may send filtered crash reports to Sentry so we can diagnose errors and improve reliability. Reports may include the app version, build, platform, a sanitised error category, and technical stack information. They are configured not to include user identifiers, family content, screenshots, view hierarchies, or interaction recordings.
  • Subscriptions: TimeTokens uses RevenueCat to validate purchases, restore purchases, and determine whether Premium is active. RevenueCat receives an anonymous App User ID and purchase history. TimeTokens does not enable RevenueCat advertising attribution and disables its automatic device-identifier collection. It does not send names, email addresses, or child profile information to RevenueCat.

D) Fifty Ten timer data

Fifty Ten does not require an account or provide cloud sync. Its timer state and settings—including the current phase, remaining time, selected number of cycles, and alarm preference—are stored in the App’s private storage on your device. This information is not uploaded to or accessible by LxAppFactory.

In configured release builds, Fifty Ten may send crash reports to Sentry so we can diagnose errors and improve reliability. Crash reporting is configured not to send personal data, screenshots, view hierarchies, session recordings, breadcrumbs, interaction traces, or application logs.

E) Location data (LxDiscover features)

If you use location-based features in LxDiscover, and you grant permission:

  • Foreground location may be used to show your position on the map and to calculate proximity to places.
  • Background location may be used only if you enable background proximity alerts (for example, “Near a site” alerts). This allows the operating system to monitor geofences and trigger local notifications.

We design LxDiscover so that precise location calculations for proximity alerts happen on your device. We do not intentionally store a history of your precise location on our servers.

F) Notifications

  • Local notifications: Some features schedule notifications on your device (e.g., proximity alerts). These are generated on-device.
  • Push notifications (if enabled): If you opt in to push notifications, our push provider may process a device token and related identifiers required to deliver notifications.

TimeTokens and Fifty Ten use local timer notifications only. They do not send a push-notification device token to LxAppFactory or a push provider.

G) Purchases and subscriptions

If you purchase a subscription or other in-app purchase:

  • Payments are processed by the Apple App Store or Google Play (depending on your device).
  • We may use a subscription management provider (such as RevenueCat) to validate receipts and determine entitlement status (e.g., whether Premium is active).

We do not receive your full payment card information. The stores and their processors handle payment details.

H) Maps

If an App displays maps (e.g., LxDiscover), map functionality is provided by platform map services (such as Apple Maps or Google Maps). These providers may collect and process information (such as IP address and location) under their own privacy policies.

3) How we use information

We use information to:

  • Provide and operate the Apps and features (including location-based features and notifications, if enabled).
  • Process purchases and restore purchases; maintain Premium entitlement status.
  • Improve the Apps (analytics and diagnostics).
  • Provide customer support and respond to your requests.
  • Protect the Apps, prevent abuse, and maintain security.

4) Legal bases (EEA/UK users)

Where the GDPR/UK GDPR applies, we rely on:

  • Contract (to provide the Apps and paid features you request).
  • Consent (for optional analytics, push notifications, and location permissions where required; you can withdraw consent by changing your settings).
  • Legitimate interests (to maintain security, prevent abuse, and improve reliability), where such interests are not overridden by your rights.

5) Sharing and third-party processors

We share information only as needed to operate the Apps, including with service providers that process data on our behalf. Depending on configuration and your opt-in choices, these may include:

  • Apple App Store / Google Play (payments, subscription management)
  • RevenueCat (subscription status/receipt validation)
  • Sentry (crash reporting and diagnostics)
  • PostHog (product analytics; disabled when you opt out in-app, if available)
  • OneSignal (push notification delivery, if enabled)
  • Apple Maps / Google Maps (map display and related functionality, if used)

For TimeTokens specifically, the relevant processors are the Apple App Store, RevenueCat, Sentry, and—only after a parent opts in to analytics—PostHog. TimeTokens does not use OneSignal or map services.

For Fifty Ten specifically, the relevant diagnostic processor is Sentry when crash reporting is configured in a release build. Fifty Ten does not use product analytics, OneSignal, map services, or a subscription-management provider; its transition alarms are scheduled locally on the device.

These providers may process certain technical identifiers (such as IP address, device identifiers, and app activity) to provide their services.

We may also share information:

  • To comply with law or respond to lawful requests.
  • To protect rights, safety, and security (including investigating fraud or abuse).
  • In connection with a merger, acquisition, or asset sale (you will be notified where required by law).

6) International data transfers

Some service providers may process data outside your country (including outside the EEA/UK). Where required, we use appropriate safeguards (such as Standard Contractual Clauses) or rely on other lawful transfer mechanisms.

7) Data retention

We retain information only for as long as necessary for the purposes described in this policy:

  • Support emails are kept as long as needed to resolve your request and for reasonable recordkeeping.
  • Diagnostics and analytics are retained according to the settings and retention policies of our providers and our operational needs.
  • TimeTokens family content and optional task photos remain on the device until a user deletes them, removes the App, or an in-app retention rule deletes them. Subscription records are retained by Apple and RevenueCat as needed to operate subscriptions, restore purchases, prevent fraud, and meet legal obligations.
  • Fifty Ten settings and active timer data remain on the device until they are overwritten or the App is removed. Any crash reports sent to Sentry are retained according to our diagnostic retention settings and Sentry’s applicable policies.

8) Your choices and rights

In-app and device controls

  • Location: You can grant/deny location permissions and disable background location in your device settings. You can also disable location-based features in-app where available.
  • Notifications: You can enable/disable notifications in your device settings.
  • Analytics: Where available, you can opt out of analytics in the App’s settings.
  • TimeTokens family data: Parents can delete retained task photos or delete all family data from within TimeTokens. Removing the App also removes its locally stored family data, subject to device backups managed by the device owner or platform provider.
  • Fifty Ten timer data: You can remove locally stored settings and timer data by uninstalling the App, subject to device backups managed by you or your platform provider.

Privacy rights (where applicable)

Depending on your location, you may have rights such as access, correction, deletion, portability, restriction, objection, and the right to withdraw consent.

To exercise your rights, contact us at support@lxappfactory.pt. We may need to verify your request.

9) Children

Except for TimeTokens’ family features described below, the Apps are not directed to children under 13 (or the minimum age required in the relevant jurisdiction).

TimeTokens is intended for families and includes a child-facing mode. A parent or guardian configures the family space, creates child profiles, controls the parent PIN, chooses available tasks and rules, and manages purchases. Names entered for child profiles, age bands, tasks, notes, photos, balances, and history remain on the device and are not collected by LxAppFactory. Optional analytics and filtered diagnostics are designed to exclude child and family content.

If you believe that personal information from a child has been transmitted to us—for example, through a support message—contact us and we will take appropriate steps to investigate and delete it where required.

10) Security

We use reasonable administrative, technical, and organizational measures designed to protect information. No method of transmission or storage is 100% secure.

11) Changes to this policy

We may update this Privacy Policy from time to time. We will update the “Last updated” date above and, where required, provide additional notice.