Lymark

Privacy Policy

Last updated: 16 September 2026 · Lymark app, version 1.4.0

This policy describes how Lymark (com.lycosteam.lymark) and this site handle personal data. It is written for the data-protection and consumer regimes of the rule-of-law jurisdictions where the service is offered — including Brazil’s LGPD, the GDPR (EEA), UK GDPR, US state laws (including California’s CCPA/CPRA), PIPEDA (Canada), the Privacy Acts (Australia and New Zealand), APPI (Japan), PDPA (Singapore), POPIA (South Africa), Mexico’s LFPDPPP, Argentina’s Ley 25.326 and equivalent Latin-American laws, plus Brazil’s consumer code and EU/UK consumer rules. Where the mandatory law of your country of residence grants stronger rights, that law prevails. This text does not claim to exhaust every national code, nor worldwide compliance.

In one sentence

Lymark does not transmit your photos or your raw location. Images, visible addresses, history and preferences stay on your device. An account is required to use the app and the subscription: the server keeps your e-mail, account id, plan, export count and, when you request a seal, the file hash — a fingerprint, not the photo.

Besides the account, what leaves the device is: (a) coordinates, via the operating system, to become an address (item 05); (b) the file hash, to issue the seal and, when available, a third-party timestamp (item 18); (c) payment data, handled by the billing processor (item 18). None of these flows send the image.

Who this policy applies to

It applies to anyone who uses the app or this site, in jurisdictions where Lymark is lawful. Brazil: LGPD and ANPD. EEA and United Kingdom: GDPR and UK GDPR. California and other US states with a consumer privacy law: the equivalent rights in item 19. In other countries with a data-protection statute, we honour equivalent rights (access, correction, deletion, objection, portability) through the same channel: contato@lymark.app. We may refuse or limit the service where offering it would be unlawful or subject to sanctions.

Who the controller is

The controller of the personal data — controlador, in the terminology of the LGPD — is 29.015.357 AMAD ALI HAMMOUD, registered under CNPJ 29.015.357/0001-25, with an address at Avenida Ana Costa, 433, Gonzaga, Santos - SP.

The person in charge of personal data processing, for the purposes of Article 41 of the LGPD, is Amad Ali Hammoud, who can be contacted at contato@lymark.app. Given the volume and the nature of the processing — which involves neither sensitive data at scale nor systematic monitoring — there is no obligation to appoint a Data Protection Officer under Article 37 of the GDPR.

What information the app handles

There are two places. On the device (below, through “Preferences”): none of that uploads. On the server (account, payment, seal hash, technical access data): only what items 18 and 14 describe.

Photographs
The image you choose from the gallery or capture with the camera, and the file exported with the watermark. A photograph may contain third parties’ personal data — see item 11.
Location
Approximate latitude and longitude, obtained once per capture, for the sole purpose of filling in the address field. The coordinates are not recorded: only the resulting address text is kept, alongside the photo.
Date, time and weekday
Read from the device clock at the moment of capture, and editable by you.
Photo code
A sequence of fourteen hexadecimal characters drawn at random. It derives neither from a device identifier nor from one of yours, and it enables no tracking across apps.
History
A record of the last two hundred exports, containing the file path on the device and the data stamped onto the image.
Preferences
Visible fields, position, size and the other watermark options.
Account
E-mail, account identifier, plan (free or Pro) and export count, at the authentication processor.
Payment
The billing processor handles card data. Lymark does not store the card number; it keeps only subscription state (how long Pro lasts) and billing identifiers needed to cancel or invoice.
Seal hash
A fingerprint of the exported file, sent to issue the seal and, if available, a timestamp. The photo itself never uploads. The hash cannot rebuild the image.
Technical access data
IP address, date, time and requested resource, in hosting and API logs, for as long as service security requires — including fraud prevention.

The app does not collect on-device, for the developer: identity documents, advertising identifiers, contacts, calendar, browsing history, usage metrics, crash reports. There is no analytics, advertising, attribution or tracking SDK. E-mail exists because there is an account; it is not read from the address book and not used for ads.

The only information that leaves the device

When you grant the location permission, the app asks the operating system to turn the GPS coordinates into a postal address. That translation — reverse geocoding — is carried out by the operating system itself, which for that purpose sends the coordinates to its map service: Google on Android devices and Apple on iOS devices.

That communication comes from the operating system, and not from Lymark. The app receives no copy of it, does not mediate it and has no access to anything beyond the address returned. The processing carried out by those providers is governed by their own privacy policies.

No photograph leaves the device through any action of the app. If you use the Share button, the image is transmitted by the destination app you choose in the system share sheet — messenger, email, cloud storage — under that app’s privacy policy.

Permissions requested, and why

Camera
To take the photo or record the video that will receive the watermark. Requested when you capture.
Photos and media
To choose an existing image and to write the exported file to the gallery. Access is restricted to photographs, and the write permission is used only for writing — the app neither browses nor reads your gallery.
Location while in use
To fill in the address field. Requested in the foreground, only while the app is in use, and never in the background.
Microphone
Only when recording video with sound. Not used for still photos or in the background.

All permissions are optional and revocable at any time in the device settings. Refusing location keeps the app fully functional: the address is then typed by you. Refusing gallery access only prevents automatic saving, and the photo can still be shared.

Legal bases and purposes

The processing of location takes place on the basis of your consent — Article 7, I of the LGPD and Article 6(1)(a) of the GDPR — expressed when you grant the system permission, and revocable at any time, without prejudice to the lawfulness of the processing carried out before revocation.

The processing of the remaining data takes place for the performance of the feature you requested — Article 7, V of the LGPD and Article 6(1)(b) of the GDPR — since without it there is no watermark for the app to produce.

The processing of account data rests on the performance of a contract (LGPD art. 7, V; GDPR art. 6(1)(b)). Processing based on legitimate interest (LGPD art. 7, IX; GDPR art. 6(1)(f)) exists only for security and fraud prevention — for example, logging the IP address of requests to the server. There is no processing for advertising, profiling, behavioural analysis or any secondary purpose, and no processing of special categories of data or sensitive data by the developer.

International transfer

Account and payment data are handled by processors in the United States (authentication and billing), and hosting may process access logs outside Brazil. The seal hash, when a timestamp is requested, may go to an independent timestamp authority. These transfers rest on standard contractual clauses and LGPD art. 33 and GDPR arts. 44–49, or an equivalent under your law. Geocoding in item 05 follows the OS providers’ own transfer tools.

This site is hosted by Vercel Inc., under items 14 and 18.

Sharing with third parties

The developer does not sell, rent or hand personal data to advertising or data brokerage. Contracted processors are listed in item 18. If you sign in with Google or Apple, those providers handle the login under their own policies; the developer receives the e-mail and identifier needed for the account. Photos and raw location pass through no processor, because they never leave the device.

Storage, retention and security

The data sits in the app’s private area, protected by the operating system’s isolation between apps and by the device’s screen lock. In the Android version, the system’s automatic backup is disabled, so that history and preferences are not sent to the user’s Google account.

Retention is entirely controlled by you: records remain until they are deleted in the app itself, and the history automatically discards the oldest ones once it passes two hundred items, removing the corresponding files as well. Uninstalling the app erases everything it stored. Photos already saved to the device gallery belong to the gallery and stay there — it is up to you to remove them if you wish.

No system is infallible. Account data — e-mail, identifier, plan and count — is held by the authentication processor, under its security measures. Photos, addresses and location exist in no central repository, and therefore cannot leak from the developer’s infrastructure. Should a security incident affect account data, the developer will notify the authority and the data subjects under LGPD art. 48 and GDPR art. 33. The relevant risk to your photos remains physical access to the unlocked device.

When you photograph other people

When you photograph identifiable people in the course of your professional activity, you become the controller of that data in relation to the data subjects portrayed, and it is up to you to provide the legal basis, the information and the response to their rights. The developer takes no part in that processing and has no access to the images.

Your rights

Article 18 of the LGPD and Articles 15 to 22 of the GDPR guarantee you the rights of confirmation and access, correction, deletion, anonymisation, blocking, portability, restriction of processing, objection, withdrawal of consent and information about sharing.

Photos, addresses, history and preferences reside only on your device, and those rights are exercised directly in the app: view and delete entries in the Gallery tab, correct any field before exporting, revoke the location permission in the system settings, and erase everything by uninstalling the app — the developer cannot access, export or delete that data for you, because it does not hold it. As for account data — e-mail, plan and count — you can view it on the account page and request correction, export or deletion at this Policy’s contact e-mail; deleting the account erases that data at the authentication processor.

Requests: contato@lymark.app. You may complain to your country’s authority — in Brazil, the ANPD; in the EEA, your Member State’s supervisory authority; in the UK, the ICO; in California, the CPPA; elsewhere, the equivalent body. Item 19 lists the rights we honour outside the LGPD/GDPR pair.

Automated decisions

There is no automated decision, profiling or processing that produces legal effects concerning you, under Article 20 of the LGPD and Article 22 of the GDPR.

About this website

This site has no analytics, shows no advertising and embeds no social-network buttons. It uses only the cookies strictly necessary for your account session, set by the authentication processor (item 09) when you sign in; no tracking or advertising cookies. Fonts are served from the site’s own domain. The only requests your browser makes to third parties are those of the sign-in and account screens, addressed to the authentication processor — and, if you choose it, to the sign-in provider (Google or Apple).

The website is hosted by Vercel Inc., which as a processor logs technical access data — IP address, date, time and the resource requested — for as long as is necessary for the security and the operation of the hosting. The legal basis is the legitimate interest in maintaining the security of the service, Article 7, IX of the LGPD and Article 6(1)(f) of the GDPR.

Changes to this policy

Changes will be published on this page, with a new update date. Changes that materially alter the processing of data will also be communicated inside the app before they take effect.

Children and adolescents

Lymark is a work tool, intended for people aged 18 or over. It is not directed at children or adolescents, and it does not intentionally collect data about that audience.

Applicable law

Brazilian law governs this policy, without prejudice to the GDPR, UK GDPR, CCPA/CPRA and any mandatory data-protection or consumer law of the data subject’s country of residence. Forum: the data subject’s domicile when consumer law so requires; otherwise Santos, Brazil.

Processors

Who handles data on the controller’s instructions only:

Clerk, Inc.
Account authentication (e-mail, identifier, plan and quota metadata). United States.
Stripe
Pro subscription billing. Lymark never receives the card number. United States, and, where applicable, a Stripe entity in the billing country.
RevenueCat, Inc.
Acts as intermediary for the Pro subscription made through the Android app: it receives from Google Play the purchase data, your Lymark account identifier and technical data from the device needed for the purchase (OS and app version), and notifies Lymark when the subscription starts, renews, is cancelled or refunded. The charge itself is made by Google Play, under its own terms. It does not receive photos, videos or location. United States.
Vercel Inc.
Hosting of the site and APIs; technical access logs (item 14).
Timestamp authority
When the seal asks for a third-party time, only the file hash is sent, not the photo. The current provider is a public RFC 3161 service; it may be replaced by a contracted authority, including ICP-Brasil, without changing this purpose.

Google and Apple appear as sign-in providers (if you choose them) and as geocoders (via the OS, item 05), under their policies — not as our processors for the photo.

Rights outside Brazil and the EEA

On request at contato@lymark.app we honour access, correction, deletion, portability, restriction and objection, to the extent the data exist on the server (account, plan, count, hash, technical logs). What lives only on the device, you delete in the app or by uninstalling.

California and US states with a consumer privacy law: we do not sell personal information and we do not “share” it for cross-context advertising (there are no ads). You may ask to know, delete, and opt out of sale/sharing — we already do not sell. We do not use data for automated decisions with legal effect (item 13).

Canada (PIPEDA), Australia and New Zealand (Privacy Act), Japan (APPI), Singapore (PDPA), South Africa (POPIA), India (DPDP), Switzerland (nFADP), Mexico, Argentina, Colombia, Chile and other countries with an equivalent statute: the same channel and the same practical rights, limited to what the server actually keeps.

Scope and limits of this policy

Lymark is offered where that is lawful. We do not operate to evade sanctions, nor in jurisdictions where offering the service would be unlawful. This document is not legal advice and does not claim that every article of every national code has been reproduced. If your mandatory law is more protective, it prevails; write to contato@lymark.app.

See also the Terms of Use.