Home

Privacy Policy

Lately (lately.today) · Effective date: July 18, 2026 · Last updated: July 18, 2026

What This App Does

Lately helps you share your week in photos with the people you choose. You select photos on your phone, the app compiles them into a weekly digest, and sends that digest as an email through your Gmail account. That's it.

This privacy policy explains what data the app touches, where that data lives, and what we — the developer — do and do not have access to. The short version: your data stays on your phone and in your Gmail account. We don't run servers. We don't collect your data. We don't have a database with your information in it.

What Data the App Accesses

Your Gmail account (send only). The app requests permission to send email on your behalf using Google's Gmail API. This is the only Gmail permission the app requests. The app cannot read your emails, search your inbox, access your contacts, or view your Gmail settings. The permission scope is gmail.send.

Photos you select. When you choose photos for your weekly digest, the app accesses only the specific photos you pick through your phone's system photo picker (the Android Photo Picker, which operates in a secure process outside the app's control). The app does not have access to your full photo library and cannot browse your photos in the background.

What the app does NOT access. The app does not read your email inbox. It does not access your phone contacts. It does not access your location. It does not access your camera directly — you take photos with your normal camera app and select them later. EXIF metadata, which can contain location data embedded in photos, is stripped during compression before any photo leaves your device.

What Data Is Stored on Your Device

All app data lives on your phone, in the app's private storage area, sandboxed by the operating system so other apps cannot access it. This includes:

Photos you've selected for the current week's digest, plus a compressed archive of previously sent digests (up to approximately 12 weeks of history, after which older images are automatically purged).

Recipient email addresses — the people you've chosen to send your digest to. These are entered by you and stored only on your device.

OAuth authentication tokens — the credentials that allow the app to send email through your Gmail account, stored in your phone's encrypted, hardware-backed secure storage. The app never sees or stores your Gmail password.

App settings — your preferred digest day, notification preferences, and display name.

What Data Leaves Your Device

Emails you send. When the app sends your weekly digest, it transmits the compiled email — including your selected, compressed photos as attachments — to the Gmail API over an encrypted HTTPS connection. Gmail then delivers that email to the recipients you chose. This is functionally identical to composing and sending an email yourself: the email travels through Google's infrastructure, not ours.

Nothing else. The app contains no analytics, no crash-reporting service, no advertising SDKs, and no trackers. No data is sent to the developer, because the developer operates no servers. No data is sent to advertising networks or data brokers. No data is shared with any third party beyond the email delivery described above.

What the Developer Does NOT Collect

This is worth stating plainly. The developer of Lately:

Does not operate servers or a backend. There is no developer-controlled system that receives, processes, or stores your data. The app operates entirely on your device and communicates only with Google's Gmail API, to send the emails you ask it to send.

Does not maintain user accounts. There is no Lately account. Your identity in the app is your Gmail address, authenticated directly with Google. The developer has no database of users, no login system, and no record of who has installed the app.

Does not collect, sell, or share personal data. The developer never receives your photos, your recipient list, or your email content. None of it passes through any system the developer controls. We cannot sell what we do not have.

Data Security

On your device, all app data is stored in the app's sandboxed directory, encrypted by your phone's operating system (the default on modern Android devices). OAuth tokens are stored separately in hardware-backed encrypted storage.

In transit, all communication with the Gmail API occurs over HTTPS with TLS encryption. Once delivered, your emails are protected by Gmail's security infrastructure, including SPF and DKIM signing handled automatically by Google.

Authentication uses Google's OAuth 2.0 protocol, the industry standard for secure API authorization.

Data Retention and Deletion

While you use the app, it retains your selected photos, a rolling archive of recent digests (approximately 12 weeks), your recipient list, your settings, and your OAuth tokens — all on your device.

When you delete the app, all data stored by the app is deleted by the operating system. There is no server-side data to request deletion of, because none exists. Emails previously sent through the app remain in your Gmail "Sent" folder and in your recipients' inboxes — standard emails under your control, like any other email you've sent.

You can revoke Gmail access at any time in your Google Account settings (Security → Third-party apps with account access). Revoking access immediately prevents the app from sending further emails.

Children's Privacy

Lately is not directed at children under 13 and does not knowingly collect personal information from children under 13. Because the app stores data only on the device and the developer collects no user data, there is no server-side data to delete; removing the app from a device removes all app data.

Changes to This Policy

If this privacy policy is updated, the revised version will be posted at this page with an updated date. For material changes — particularly any change to what data the app accesses — we will notify users through the app or the app store update notes.

Contact

Questions about this policy or the app's data practices: hello@lately.today · lately.today

Summary

QuestionAnswer
Does the app read my emails?No. Send-only permission.
Does the app access my contacts?No.
Does the app track my location?No. EXIF location data is stripped from photos.
Does the app have a backend server?No. All processing happens on your device.
Does the app contain analytics or trackers?No. None.
Does the developer have my data?No. There are no servers and no collection.
What happens when I delete the app?All app data on your device is deleted.
Who can see my photos?Only the recipients you choose.