Lanteon

Privacy Policy

Last updated: 17 August 2026

One policy covers both the Lanteon app and this website, lanteon.app. They collect different things, so every section below says which one it means.

Who we are

Lanteon is run by The Software Engineer Ltd, a company registered in England and Wales, company number 13408115, registered office 4th Floor, Silverstream House, Fitzroy Street, London W1T 6EB. We are registered with the ICO, registration number ZC208439. We are the data controller for the app and for this website. You can about anything in this policy, including any request under your rights below.

What data we collect

On this website. If you join the waitlist, we store your email address and the date you signed up. If you ask to test the app on the beta page, we also store what you tell us there: whether you are on iPhone or Android, who you said you would share your number with, their email address if you gave us one, and your answer about how you handle screen time today. That form runs a Cloudflare Turnstile check first, to keep bots off it. Turnstile sees your IP address and how your browser behaves on the page, long enough to decide you are a person. It does not set a tracking cookie and it is not used for advertising. We also run Umami, a self-hosted analytics tool, to see which pages people read. It collects page views, referrer URLs, browsers, operating systems, device types and country of origin. It does not use cookies, does not store your IP address and does not track you across other websites. It also counts what people do here: joining the waitlist, joining the beta (and which platform they picked), unsubscribing, which page sections come into view, how far down the page someone scrolls, presses of the buttons that lead to signing up, and starting to fill in the signup form. It counts the event, not who did it. When we are showing more than one version of the front page, which one you see is worked out from your IP address and your browser, mixed together for that one request and then dropped. Nothing is stored on your device, and no cookie is set.

In the app: your account. We store the account identity and contact details you give us, including details Apple supplies when you sign in, and the sign-in credentials issued for your account. Apple can give us a private relay address instead of your real email address. When it does, Apple passes our account emails on and we never see your real address. You can edit your account details. We verify an email change before it becomes the email used to sign in. We also store the handle you pick, which is the name other people see.

In the app: your screen time. The app tracks time only on the apps you pick. It never tracks your whole phone. For the apps you track, we collect how much time you spent, per app per day, and send it to our server.

How tracked apps are identified depends on your device. On Android, each tracked app is recorded by its package name (for example com.instagram.android). On iPhone, Apple does not tell us which apps you picked: we receive an approximate daily total for your tracked set under an anonymous id, and the app names shown to the people you share with are the ones you type in yourself.

In the app: who you follow and who follows you. We store the people you follow and the people who follow you, follow requests waiting on an answer, anyone you have blocked, and any invite codes you create or redeem.

In the app: your settings. Which apps you chose to track, how much of your numbers your followers can see, and whether your profile is private or public. Your device owns these; we keep a copy so a reinstall or a second device gets them back.

In the app: devices and sign-ins. An id for each device you install the app on, whether it is an iPhone or an Android phone, and a notification token if you turn notifications on. For each sign-in we store the IP address and the app or browser version it came from. We use these to sync your data, send the notifications you asked for, and protect your account. We do not use them to track you across other apps or websites.

In the app: crashes and diagnostics. We use Sentry, a crash-reporting service, to find and fix problems. If the app crashes or runs slowly, Sentry receives a report of what the app was doing at the time, your device model and your OS version. It also receives the app's own logs, and a masked screen recording of a small random sample of sessions, plus any session where an error happens. Masked means text and images are blacked out on your phone before anything is sent, so the recording shows which screens you moved through, not your numbers and not anything you typed. If you send us feedback from Settings, Sentry carries what you wrote, and your contact details if you added them. None of this is tied to your account: your name, email and handle do not go with it. Separate from Sentry, our server keeps a short-lived log of the requests it handles, held by Cloudflare, so we can trace faults.

On your phone, and nowhere else. The app keeps its own copy of your usage in a database inside the app's private storage, and your sign-in token in the device keychain. On iPhone, the part of the system that measures your app use hands results to Lanteon inside Apple's own sandbox on your device.

What the app never touches. It does not read your messages, browsing or search history, contacts, location, photos, health data, or the content of anything you do on your phone. It only measures time. We do not collect special category data, which is the law's term for things like health, race, religion, politics or sex life. There are no advertising or tracking SDKs in the app, we do not use your device's advertising identifier, and we never join what we hold to data about you from other companies' apps or websites.

No automated decisions. We do not profile you and we do not make any decision about you by automated means that has a legal or similarly significant effect.

Why we collect it

On this website. If you joined the waitlist, we use your email only to tell you when Lanteon ships, or for major updates. If you asked to test the app, we use your email to send you a beta invite, and the rest of what you told us to run the beta: to invite you and your friend together, and to know how many people are waiting on each platform. Nothing else, and the only other companies that touch it are the providers listed below who store it for us. We use analytics in aggregate to understand which pages people read. We will not email you marketing unless you asked us to.

In the app. We use your usage data for one purpose: accountability. The followers you approved see how much time you spent on the apps you are trying to cut down. That is the product. We do not use it for advertising, profiling, or anything else. Your account, devices and settings are there to run the app: to sign you in, sync your data across your devices, send the notifications you asked for, send sign-in codes, verify account email changes, and keep your account safe. Crash reports, logs, screen recordings and feedback are there to fix the app.

Who we share it with

We do not sell your data. We do not share it with advertisers or data brokers. Nobody sees your numbers unless you let them. On a private account, the default, only the followers you approve see them. On a public account, anyone who follows you sees them, and you can block anyone. Either way, you choose how much your followers see: the full per-app breakdown, app names without numbers, or just the total. Until you choose, they see just the total.

A few companies run parts of Lanteon for us. Each handles only what its job needs, acts on our instructions under a contract, and cannot use your data for anything of its own.

  • Cloudflare hosts this website and the app's API, stores waitlist and beta signups, keeps the API's server logs, runs the Turnstile bot check, and sends account sign-in and verification emails
  • Neon runs the database behind the app
  • Sentry holds crash reports, app logs, masked screen recordings and feedback, on its EU servers
  • Expo delivers push notifications to your device
  • Apple handles Sign in with Apple, and passes on our email if you chose a private relay address

Website analytics run on Umami on our own server, not on a third-party analytics service.

We would also hand data over if the law required it, for example under a court order. If Lanteon is ever sold or merged, your data would move with it, and we would tell you before that happened.

Where we store it

App data. Your account, your usage records, your follows and followers, and your settings sit in a Postgres database in Frankfurt, Germany, inside the EEA.

Diagnostics. Crash reports, app logs, masked screen recordings and feedback sit with Sentry on servers in the EU. Sentry's staff and subcontractors can reach them from outside the EU, under the standard clauses described below.

Website and account email data. Analytics sit on our own server in Germany, inside the EEA. Waitlist and beta signups, and the account contact, verification, message and delivery data needed to verify an email address and sign you in, are processed through Cloudflare's network. This can involve processing outside the UK and the EEA. Website signups never hold app or usage data.

Sending data abroad. For the EEA, the UK government has decided the protection there is equivalent to our own, so no extra step is needed. Where a provider moves data further afield, including push notifications through Expo, sign-in through Apple, and Sentry's staff and subcontractors outside the EU, we rely on the standard data protection clauses in that provider's data processing terms, which are the contract terms UK law recognises for this. You can for a copy of the terms that cover any particular transfer.

How we keep it safe

Everything between your phone and our server travels over an encrypted connection, and the database is encrypted where it is stored. Your sign-in token lives in your device's keychain, the part of the phone built for secrets. Every request for your data is checked against your own account first, and what your followers see is filtered by the sharing setting you picked, on the server, not in the app.

Access to the live database is limited to people who need it to run the service. No security is perfect, and we will not pretend otherwise. If a breach ever puts you at risk, we will tell you and the ICO as the law requires.

How long we keep it

On this website. Waitlist emails are kept until you unsubscribe. What you tell us on the beta page is kept until the beta ends or you ask us to remove it, whichever comes first.

In the app. Your account, your usage records, your follows and followers, and your settings are kept while your account exists. A sign-in session, and the IP address and app version stored with it, lasts as long as you keep using Lanteon: each use pushes its expiry out again. It goes when you sign out, or a short fixed time after you stop. Sign-in codes and account email-change links expire shortly after we send them. Cloudflare keeps delivery records and, when preview is on, message content for the short time needed to send and secure those emails. We do not add separate delivery analytics or a recipient-event store. Invite codes expire a short time after you make them, and you can revoke one sooner.

Diagnostics. Sentry keeps crash reports, logs, screen recordings and feedback for a fixed period it sets, measured in months, then deletes them on its own. The server logs Cloudflare keeps for us are held for a few days.

Backups. Our database provider keeps a short rolling window of history, measured in hours, so the database can be rewound after a failure. Anything you delete can survive in that window, and is gone for good once it passes.

Deleting your account

You can delete your account in the app, under Settings. It removes your account identity and contact details, handle, settings, device records, notification tokens, sign-ins, follow and block list, invite codes, and per-app usage records. We also cut the Sign in with Apple link.

Deletion removes what others could see of you, not just your own view. The totals your followers see are worked out from your records each time they are read, so once the records are gone there is no stored copy left behind. We keep nothing for research or analytics.

Two things outlive the delete. If you redeemed someone else's invite code, that code stays in their own list so it cannot be used twice; the link to you is stripped from it and it holds nothing about you. And anything already deleted can sit in the rolling backup window described above until that window passes. Diagnostics are separate: nothing in Sentry is tied to your account to begin with, and it ages out of Sentry on its own.

Deleting the app on its own does not delete your account. Use Settings first, or and we will do it.

Children

Lanteon is rated 13+ and is not meant for children under 13. Do not make an account if you are under 13. We do not knowingly collect data from anyone under 13, and if we find out we have, we delete that account and its data. If you are a parent or guardian and think your child has signed up, and we will remove it.

If someone gave us your email

The beta page asks people who they would share their number with, and lets them give that person's email address. So we may hold your address because a friend put it there, not because you signed up. We use it for one thing: to invite the two of you to the beta together. We do not add you to the waitlist, we do not pass it on, and when we first email you we say who named you.

The unsubscribe page only clears addresses that signed up themselves, so it will not find yours. and we will delete it, and tell you what we held.

Your rights

Under UK GDPR, you have the right to:

  • Take your email off both lists at any time on the unsubscribe page. One request removes your waitlist email and your beta signup, whether you are on one list or both
  • Access your data, and we will confirm what we have and send you a copy
  • Correct anything we hold that is wrong. You can change your account details and settings in the app; for anything else, including your handle
  • Delete your data, the unsubscribe page removes your email and your beta signup, and deleting your account removes your app data
  • Withdraw consent to our emails at any time, on the unsubscribe page. That does not undo what we did with it beforehand
  • Object to anything we do on a legitimate interest, and ask us to limit how we use your data while we look into it
  • Take your data with you in a machine-readable format, or have us send it straight to another service where that is possible
  • Complain to the ICO if you are unhappy with how we have handled your data

Ask us for any of these and we will answer within one month. It costs you nothing. We may ask you to prove who you are first, so we do not hand your data to someone else. If you are unhappy with our answer, tell us before you go to the ICO and we will try to put it right.

Changes

If we make significant changes to this policy, we will note it at the top and, where the change matters to you, tell you in the app or by email before it takes effect. The current version was last updated on 17 August 2026.