The short version
This Privacy Policy explains how Jean Canales (“we”, “us”) handles information in Lookback. You can contact us at jean@spenser.app.
Effective date: October 9, 2026
Lookback has no accounts. Your location, motion, trip history and settings stay on your phone. Optional calls and lock-screen features need a small amount of information on our server.
We don’t sell or share personal data for advertising, show ads, track you across other apps or websites, or use data brokers. We send information to the service providers below only to run the features described here.
What stays on your phone
- Your child’s first name, if you add one. We do not receive it except for the lock-screen request explained below.
- Your trip history. This includes when you parked, how each check-in was cleared, and a place name.
- Location and motion data. Lookback uses these on your phone to notice when a drive ends and you walk away. They are not sent to us. To show a place name in History, your phone asks Apple’s location service to turn parking coordinates into an address. Apple’s privacy policy covers that service.
- Your settings. These stay on your phone.
Lookback doesn’t use your camera, microphone, contacts or photos.
What is sent to our server
Our server uses Supabase for its database and functions, and Upstash for short-lived counters and lock-screen features. It receives what these features need:
A random device ID
The first time the app talks to our server, it creates a random device ID and a secret. We store the secret only as a hash. The ID is not linked to your name or Apple ID.
Your phone number, if you set up calls
We receive your US phone number, when you verified it, and the consent you agreed to:
“If you don’t confirm the back seat after you park, Lookback will call this number with an automated message. You can turn this off anytime.”
We use the number only to text you a one-time verification code and to call you when a check-in goes unanswered. “Stop calling me” in the app deletes your number and consent record.
Call records
Records include when a call was scheduled and placed, whether a person or voicemail answered, how long it lasted, and whether it confirmed the all clear. They are linked to your device ID.
Currently, call records are kept until you ask us to delete them.
Apple notification tokens
We receive a push notification token and a Live Activity token. They let the server send “all clear” and “escalate” notifications and show a check-in card while the app is in the background.
The name on a lock-screen card
When you walk away with the app in the background, it asks our server to put the check-in card on your lock screen. That request includes the name shown on the card, such as “Did you get Ana Sophia?” The server passes it to Apple’s push service and does not store it.
Short-lived abuse-prevention data
The server keeps counters keyed by device ID, phone number and IP address. They expire automatically within two days. Verification codes are stored only as hashes and expire after 10 minutes.
The services that help Lookback work
- Twilio sends the verification text and places the call. It receives your phone number and call details.
- Apple provides push notifications, Live Activities, the location service for place names, and App Store purchases.
- Supabase and Upstash host our server and its data.
- PostHog, in the United States, receives the anonymous usage analytics described below.
Anonymous usage analytics
We use PostHog to understand whether Lookback is working, how quickly check-ins get answered, and where setup is confusing.
What we measure
- Which setup steps you saw and your permission choices, such as whether location is set to “Always”.
- Whether you added a call number.
- Each walk-away, how it was cleared through a notification, lock-screen card, alarm or phone call, and how long that took.
- When a permission Lookback needs is turned off or back on.
We also measure app opens, whether a call number was skipped or removed, paywall and purchase outcomes when subscriptions are enabled, and when an all-clear happens in the app. Event details use general labels rather than names, phone numbers, places or coordinates.
What accompanies an event
App version, iPhone model, iOS version, screen size, and a random analytics ID created when the app is installed. This ID is not connected to your phone number or to the device ID our server uses.
What is never included
Names, phone numbers, places and coordinates are never included in analytics events. The app disables PostHog’s IP-based location enrichment. PostHog may still receive and store network metadata, including an IP address, when it processes an event.
The website itself uses no cookies or analytics. Fonts and images are hosted with the site, so the website does not load third-party resources.
Your choices and deleting data
- Stop calls: choose “Stop calling me” in the app to turn off calls and delete your number and consent record.
- Delete local data: deleting the app removes everything it stores on your phone.
- Delete server data: email jean@spenser.app with the phone number you verified to ask us to delete your device ID and call records. If you never verified a number, email us from the device you use with Lookback. Because that server record is pseudonymous and is not linked to an email address, we may need additional information to identify it, and in some cases may not be able to connect it to you.
- Change permissions: you can change permissions at any time in iOS Settings. Lookback tells you what stops working.
Children
Lookback is for adults, including parents and caregivers. It is not directed to children and does not collect information from them. A parent can enter an optional first name. That name stays on the phone except for the lock-screen request described above.
Security and where data is processed
All connections use HTTPS. Device secrets and verification codes are stored only as hashes. Administrative access is restricted through provider credentials. Our service providers may access data when needed to operate, secure or support their services.
Our providers process data in the United States and in other locations where they operate. Their own privacy terms govern their processing and international safeguards.
US state privacy rights
The categories we collect are identifiers, such as a phone number and device ID, and app activity, as described above. We do not sell or share personal data for cross-context behavioral advertising.
Depending on the law that applies to you, you may have rights to know about, delete or correct your personal data. You can exercise these rights by emailing jean@spenser.app. We will not discriminate against you for exercising a privacy right that applies to you. We may need to verify your request before acting on it.
If you are in the EU or UK
We rely on your consent for verification texts and automated calls. You can withdraw that consent at any time using “Stop calling me”. We rely on legitimate interests for anonymous usage analytics and abuse prevention.
Where applicable, you can ask to access, correct, erase or receive a portable copy of your personal data, request restrictions on processing, and object to processing based on legitimate interests. You may also complain to your local data protection authority. Contact jean@spenser.app to exercise your rights.
Where EU or UK data-protection law applies, our providers may process information outside your country under the safeguards described in their terms. You may withdraw consent for calls and texts at any time. An objection to processing based on legitimate interests will be reviewed against the reasons for that processing.
Changes to this policy
We update the effective date at the top when this policy changes. We will tell you in the app about significant changes.
Questions? Contact jean@spenser.app or visit Support.