Lull is built on a simple promise: your evening is your evening. We've designed the app so that almost nothing leaves your device. This policy explains what data is involved, where it lives, and the choices you have.
The app stores the following locally on your device only:
None of the items above are sent to Lull's servers. We do not operate a server that receives them.
Stories are generated entirely on-device by a local templated grammar engine. There is no LLM call, no cloud generation, and no network access required to read you a bedtime story. Lull works in airplane mode.
The Companion's replies are produced by a local rule-based engine. Your messages and the engine's replies stay on your device. Clearing the conversation in Settings → Companion → Clear conversation deletes the local store.
If you opt into the Pro+ voice clone feature, a 30-second voice sample is recorded with your microphone. The audio is processed on your device and the resulting voice profile is stored in your private iCloud Keychain — accessible only to you. Lull does not receive your recording or your voice profile.
Lull may request read-only access to sleep stages so it can fade the story out 5 minutes after you reach a non-awake stage. Sleep data is read on-device and used only for that purpose. We do not store, copy, or transmit the data.
All purchases go through Apple's StoreKit. We never see your payment information. Apple shares with us only an anonymous indication that you have an active entitlement.
Lull is not directed at children under 13. We do not knowingly collect data from children.
If we ever materially change this policy we'll bump the date above and post a notice in-app for the next launch.
Questions or concerns: hello@lull.app