Privacy Policy
Last updated: 14 June 2026
In short: LightsOn collects, stores and transmits no personal data to us or to any third party. The app has no accounts, no ads, no tracking and no analytics tools, and it sends no data to any server whatsoever. All data — including your health data — stays solely on your device.
This policy explains how the iOS app LightsOn handles your data. It also applies to this website.
1. Controller
Controller within the meaning of the EU General Data Protection Regulation (GDPR):
Jirko CernikUrsrainer Ring 89/1
72076 Tübingen
Germany
E-mail: cernik@freewar.de
2. Principle: no data collection
LightsOn is built to work without collecting data. The app:
- requires no registration and no user account,
- has no networking — it sends no data to us or to third parties and does not contact any external server,
- contains no analytics, tracking or advertising components (no third-party SDKs),
- uses no cookies or comparable identification technologies.
Because no processing of personal data takes place on our side, there is, in practice, no data held by us to which data-subject requests (see section 7) could apply.
3. Health data (Apple Health / HealthKit)
The gameplay of LightsOn uses your activity: active calories burned charge your city’s “battery”. To do this, the app reads the following data from Apple Health — only with your explicit permission:
- Active energy (active calories burned),
- Workout entries (used to award bonus credits).
Regarding this health data:
- It is processed solely locally on your device to compute your game state.
- It is never transmitted to us or to any third party and does not leave your device through the app.
- The app has read access only; it writes nothing back to Apple Health.
- HealthKit data is never used for advertising or shared with third parties (in accordance with Apple’s requirements).
- You can revoke permission at any time: iOS Settings → Privacy & Security → Health → LightsOn, or in the Health app. Without access, the battery will not charge from your activity, but the app remains usable.
4. Data stored locally on your device
To preserve your progress, the app stores your game state (e.g. battery level, screws, credits, upgrades) and a derived calorie ledger locally within your app’s storage on the device. These files reside in the protected app container and are not sent to us.
If you have enabled Apple’s iCloud Backup or iCloud device backup, this game state may be included in your device backup at Apple. This happens under your control within your Apple/iCloud settings and is subject to Apple’s Privacy Policy.
5. Notifications
If you allow notifications, the app reminds you, for example, about an impending “blackout”. These notifications are scheduled and triggered locally on the device. No push servers are used and no data is transmitted to us for this purpose. You can disable notifications at any time in iOS Settings.
6. Distribution via the App Store
The app is downloaded and installed via the Apple App Store. In doing so, Apple, acting as an independent controller, processes data (e.g. your Apple ID, download history, and possibly aggregated crash/usage statistics if you have enabled sharing with developers in iOS Settings). We have no influence over this; Apple’s Privacy Policy applies.
7. Your rights
Under the GDPR you generally have rights to access, rectification, erasure, restriction of processing, data portability and objection. As described above, we do not collect or store any personal data about you, so we hold no data that we could process subject to access, rectification or erasure obligations.
- You can delete all locally stored data by removing the app from your device.
- You can revoke access to health data in your Health settings (see section 3).
You also have the right to lodge a complaint with a data protection supervisory authority (for us, e.g. the State Commissioner for Data Protection of Baden-Württemberg, Germany).
8. Provision of this website
When you visit these web pages, the hosting provider may, for technical and security reasons, process standard server access data (e.g. IP address, date and time of access, the file requested, the amount of data transferred) in server log files. The legal basis is our legitimate interest in the secure operation of the website (Art. 6 (1)(f) GDPR). This log data is not combined with other data sources and is deleted after a short period. This website sets no cookies and embeds no external content.
9. Changes to this Privacy Policy
We will update this Privacy Policy when app features or the legal situation change. The current version is always available on this page.
This is a translation of the German privacy policy. In case of any discrepancy, the German version shall prevail.