Privacy is the architecture, not the policy

This is health data about your body. We built the app so that we cannot read the sensitive parts, and neither can anyone else.

Your notes are encrypted before they leave your phone

Free-text day notes are encrypted on your device with AES-256-GCM. The key never leaves it. What reaches our servers is ciphertext we cannot open.

The AI never sees your words

When Lambi generates guidance, the request carries only machine codes — a phase key, a status ID. A runtime guard refuses any request containing free text, so your writing cannot reach a model even by mistake.

Your partner never reads your raw data

There is no path from your entries to your partner's screen. A server-side function computes a filtered summary from your permissions, and security rules make your partner's copy unwritable from any client.

It works without us

Your phone holds the source of truth. The app works offline and syncs when it can — so it stays useful on a patchy connection, and it does not need to phone home to function.

Your data can leave

You can export a report to bring to a doctor. Your data is yours, and taking it elsewhere is a feature, not a support ticket.

Be told when it opens

One email when Lambi is available. Nothing else, and you can leave at any time.