Privacy Policy
Last updated: 20 July 2026
Who we are
Lyra is operated by CheckLyra Ltd ("we", "us", "our"), a company registered in England & Wales (company no. 16351012; registered office: 71–75 Shelton Street, Covent Garden, London, WC2H 9JQ). CheckLyra Ltd is the data controller for the personal data described here, and is registered with the UK Information Commissioner's Office (ICO) under registration reference ZC124222. We are committed to protecting your privacy and handling your personal data transparently.
What data we collect
When you create a Lyra profile, we collect:
- Account data: Email address and display name. Sign-in is passwordless — we email you a secure one-time link, so there's no password to store.
- Profile data: Headline, bio, city, country, preferences, gift ideas, likes, dislikes, boundaries, school affiliations, external links, and profile photo — all provided voluntarily by you
- Usage data: Page views and basic analytics (via Vercel Analytics), collected anonymously unless you opt in
- Age confirmation: The fact that you confirmed you are 18 or over, and the date and time you confirmed it — see Age (18+) below. We do not ask for your date of birth.
Lyra is for adults — you must be 18 or over to create a profile, and it is not intended for children. We do not collect payment information, precise location data, browsing history, date of birth, identity documents, or biometric data. We do not receive any data about you from third-party data brokers or profiling services.
Why we collect it (lawful basis)
- Consent: You choose to create a profile and share your preferences. You can withdraw consent at any time by deleting your account.
- Legitimate interest: We use anonymised analytics to improve the service and security logs to protect against abuse.
Age (18+)
Lyra is an adults-only service. Before you can create a profile we ask you a single question — whether you are 18 or over — and you must confirm that you are in order to continue. We record your answer and the date and time you gave it.
What we do not collect. We do not ask for your date of birth, we do not ask you for identity documents, and we do not use facial scanning, age-estimation software, or any other biometric check. Lyra holds no special-category data under Article 9 of the UK GDPR for this or any other purpose.
What this means. This is a self-declaration: it records what you have told us, and it is not an independently verified check of your age. We rely on it together with our Terms of Service, which require you to be 18 or over to use Lyra. If we become aware that an account belongs to someone under 18, we will suspend it and delete the associated personal data.
How we use your data
- To display your public profile at checklyra.com/your-slug
- To show your profile in Lyra's search/browse page when published
- To enable AI companions (via MCP) to help people find gift ideas and understand your preferences
- To improve the Lyra service through anonymised analytics
- To send essential account emails (your sign-in link and account notices)
We will never sell your data, use it for targeted advertising, or share it with third parties for their marketing purposes.
Who we share data with
We use the following service providers, who each act as our processor under a data processing agreement:
- Supabase (database, authentication, and file storage) — stores your profile data, media, and sign-in records
- Vercel (website hosting) — serves checklyra.com
- Cloudflare (DNS, CDN, and encrypted backup storage) — routes web traffic and holds our database backups in Cloudflare R2
- Railway (application hosting) — runs the MCP integration servers that let AI companions access published profiles
- Resend (transactional email) — delivers your sign-in link, event invites, and account notices
- Google (sign-in, calendar, and town/city lookup) — provides optional Google sign-in; if you connect it, reads your calendar's free/busy availability to help plan events; and, when you use the optional town/city finder, resolves a postcode or place name you type into a town/city using the Google Places API. Only the resulting town/city is saved to your profile — the postcode or place text you type is sent to Google solely to perform that lookup and is never stored by Lyra.
Each of these providers processes data under its own GDPR-compliant data processing agreement. Some of them are based in, or host data in, the United States. Where personal data is transferred outside the UK, that transfer is protected by the UK Addendum to the EU Standard Contractual Clauses (or the UK International Data Transfer Agreement) incorporated by the provider's DPA, together with encryption in transit and at rest. Database backups are stored, encrypted, in Cloudflare R2 with 90-day retention. Our full sub-processor register is available on request at privacy@checklyra.com.
Your rights (UK GDPR / Data Protection Act 2018)
You have the right to:
- Access: Download all your data in JSON format from your account settings
- Rectification: Edit any of your profile data at any time via the dashboard
- Erasure: Permanently delete your account and all associated data from your account settings
- Restrict processing: Unpublish your profile to hide it from public view without deleting your data
- Data portability: Export your data in machine-readable JSON format
- Object: Opt out of analytics tracking via the cookie consent banner
To exercise any of these rights, use the controls in your account settings or email us at privacy@checklyra.com.
Cookies
Lyra uses only essential cookies for authentication (keeping you logged in). We use Vercel Analytics which collects anonymised page view data without cookies. You can opt out of analytics via the cookie consent banner.
Affiliate links route you to retailers via a redirect. The retailer (and, when relevant, the affiliate network operating the redirect) may set their own cookies on their own domain — those are governed by the retailer's and the network's privacy policies, not ours. Lyra does not set any tracking cookies on your browser as part of clicking an affiliate link. See the Cookie Policy for the full breakdown.
Data retention
- Active accounts: Data retained while your account is active
- Deleted accounts: All data permanently deleted within 30 days of account deletion
- Security logs: Retained for 90 days, then automatically deleted
Data security
We protect your data with: HTTPS encryption in transit, encrypted database storage, Row Level Security ensuring users can only access their own data, and regular security audits.
Changes to this policy
We may update this policy from time to time. We will notify you of significant changes via email or a notice on the website.
Data protection complaints
If you are unhappy with how we have handled your personal data, you can make a data-protection complaint to us. Email privacy@checklyra.com with the word "complaint" and a description of your concern, or use our complaints page.
We will acknowledge your complaint within 30 days of receiving it, investigate it without undue delay, keep you informed of progress, and write to you with the outcome. This reflects our statutory duty under the Data (Use and Access) Act 2025.
If you remain dissatisfied, you have the right to complain to the UK Information Commissioner's Office (ICO), our supervisory authority:
- Online: ico.org.uk/make-a-complaint
- Helpline: 0303 123 1113
- Post: Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
You can complain to the ICO at any time, but we would welcome the chance to resolve your concern first.
Contact
For privacy enquiries: privacy@checklyra.com
For complaints, you can contact the UK Information Commissioner's Office (ICO) at ico.org.uk.