Privacy Policy
LyLo is a dating app for iPhone. This page says what data we collect, why we need it, who else sees it, and what you can do about it. No legal fog: if anything here is still unclear, write to support@lylo.dating — a person answers.
The short version: we collect what the app needs to work, we never sell your data, other people see your city and never a point on a map, and deleting your account really deletes it. Two things are easy to miss, so we say them out loud: we keep the previous version of a message you edit, and we attach up to 30 messages from a conversation to a report about it.
1. Who we are
LyLo is made by a small team. The same team decides what happens to your data and reviews every report — here “we” means specific people, not a department. For anything about your data, write to support@lylo.dating.
Where your data lives. Our servers and file storage are Supabase, this website runs on Vercel, sign-in codes are delivered by Twilio, and Sign in with Apple, push notifications and payments go through Apple. These are US companies, so your data is processed outside the country you live in. For transfers out of the EU and the UK we rely on standard contractual clauses.
2. What we collect
Every item comes with a reason. We don’t collect things “for later”.
- Your account. Your phone number (sign-in by SMS code) or your Apple ID (Sign in with Apple). Used to sign you in and to keep the account yours.
- Your profile. Name, date of birth, gender, orientation, who you want to meet, city, height, photos, interests, answers to prompts, what you’re looking for, and — if you fill them in — kids, smoking, drinking, education and work. Other people see your age, never your date of birth. Orientation is a special category of data, so we ask for separate, explicit consent on the very first screen.
- Your voice answer. If you record a voice answer for your profile, it lives in private storage and is heard by the people we show your profile to.
- Verification selfie. Required for everyone: a selfie in a requested pose, checked by a human moderator. This is biometric data, so we ask for separate explicit consent, keep it in private storage that only moderation can reach, and never show it to other users.
- Location. Coordinates are blurred on your phone to roughly 1 km before they ever reach us — we never hold your exact point. To turn them into a city name our server sends the blurred point to OpenStreetMap (Nominatim). Other people see your city and an approximate distance. That distance is measured between two points snapped onto one coarse grid, not between your real position and theirs: measuring the same person again from a different place changes nothing, so the number can’t be used to work out where anybody lives.
- What you do in the app. Likes and passes, matches, search settings, profile pause. Without this we can’t match anyone or stop showing you the same profile twice.
- Conversations. Texts, voice messages, photos, reactions and replies. They’re stored on our servers — otherwise a conversation wouldn’t survive a restart. Photos and voice messages live in private storage: there are no permanent links to them, only signed ones that stop working after an hour. The server strips a photo’s metadata, including where it was taken, before saving it — a photo that can’t be cleaned isn’t accepted at all.
- Edited and deleted messages. You can edit a sent message for 15 minutes; we keep the previous text. The other person never sees it — only a moderator can open an earlier version, and only while reviewing a report about your conversation. A deleted message disappears for both of you but leaves a “message deleted” marker, and the text or file itself stays with us for another 30 days. This isn’t curiosity: without it, “say something vile → edit it to «hi»” would leave the other person with nothing to show.
- Forwarded messages. Along with the copy we store who wrote the original text — otherwise a report saying “someone forwarded me a private conversation” can’t be looked into. The person receiving it never sees that name: they only see a “forwarded” marker. If the author deletes their account, the text inside the forwarded copy is wiped.
- Activity status and “typing…”. Your matches see “online” or “here recently” — rounded, never an exact time; the exact time never leaves our server. This is on by default. You turn it off in Profile → Visibility, and it goes both ways: hide your status and you stop seeing everyone else’s. The same switch turns off “typing…”, and nothing about typing is ever stored.
- Safety data. Who you blocked, and reports — yours and about you. When someone reports a conversation, the server itself attaches the last 30 messages of that pair — yours and theirs (the report form says so). While reviewing, a moderator can open photos sent in that conversation, listen to voice messages, see previous versions of edited messages, and see where a forwarded message came from. Nobody else sees any of it.
- Purchases. Subscriptions are handled by Apple. We receive your subscription status and purchase identifiers. We never see your card details.
- Device and notifications. If you allow notifications, we store your device’s push token linked to your account, plus your language and app version — otherwise there’s nowhere to deliver a notification. When you sign out, we ask the server to delete that token; if the device is offline at that moment, the token is deleted the next time anyone signs in on this device.
- Analytics. We keep a log of what happens in the app: which screens opened, whether sign-up was finished, whether a like was sent. We’ll be blunt, because this is usually hidden: this is not “anonymous aggregated statistics” — every entry is tied to your account (and, before you sign in, to an install identifier that lives inside the app and disappears with it). The log does hold whom you liked, passed, or whose profile you opened — as the other account’s internal identifier, never their name or photo. That link between two people is the most sensitive thing in it, so we name it here instead of filing it under “usage data”. What this log never contains: message text, names, photos, or precise coordinates — every field is limited to a fixed list of values, and free text simply isn’t allowed in it.
- Diagnostics. Crash and freeze reports are collected by Apple’s own mechanism (MetricKit) and stay on your phone; they don’t come to us. We see a crash summary in App Store Connect — but only if you let Apple share that kind of statistics with developers.
- IP address. We don’t store it in our database — it’s used at the moment of a request to fend off automated traffic, and nothing about it is written down next to your account. Our hosting providers keep technical request logs for a short time, the way any hosting does.
3. What we don’t do
- We don’t sell or rent your data. In any form.
- We don’t show ads in the app and don’t use third-party advertising or tracking SDKs.
- We don’t use Apple’s advertising identifier (IDFA) and don’t follow you across other companies’ apps and websites.
- We don’t send marketing notifications unless you switch on “News and offers” yourself. It’s off by default, and today we don’t send those messages at all.
4. Why we use it, and on what legal basis
- To run the service — show profiles, deliver likes, matches and messages, keep your account in sync. Basis: performing our agreement with you.
- To keep the community real and safe — human review of every profile, handling reports, blocks, defending against bots and scammers. Basis: our legitimate interest and the protection of other people.
- To see where the product breaks — the analytics log. Basis: legitimate interest. It never contains what you write to people.
- Orientation and your verification selfie — only with your explicit consent, asked for separately (Article 9 GDPR).
- Location and notifications — only with the permission you grant in iOS, which you can take back in iOS Settings at any time.
- Marketing messages — only with the consent you give by switching on “News and offers”. We record the moment you gave it, so it can be proven. Switch it off and the basis is gone.
5. Who else sees your data
Companies that process it on our behalf, under contracts that limit what they may do with it:
- Supabase — database, file storage, backend.
- Twilio — delivery of SMS sign-in codes (sees your phone number, for that only).
- Apple — Sign in with Apple, push notifications, payments. Apple Maps also powers city suggestions when you type a city by hand — that search text goes to Apple.
- Vercel — hosting of this website and of our internal moderation console: the tool our own team signs into to review profiles and reports, which is where profile photos, verification selfies and the messages attached to a report are opened.
An outside service we call ourselves — no contract of that kind exists with it, which is exactly why nothing that identifies you is sent to it:
- OpenStreetMap (Nominatim) — a free public service that turns a point into a city name. Our server sends the already-blurred point and nothing else: no account, no name, no device — the request can’t be tied back to you on their side.
We will also disclose data if the law requires it, or to protect someone’s life and safety.
6. How long we keep it
| Data | How long |
|---|---|
| Profile, photos, conversations | While your account exists |
| Account after you ask us to delete it | 30 days, then erased completely |
| Conversation of a pair where someone blocked someone | 90 days from the block; up to 180 if a report about that pair is still open |
| Text or file of a deleted message | 30 days (the “deleted” marker stays) |
| Previous version of an edited message | As long as the message itself exists |
| Messages attached to a report | 30 days after the report is resolved, and no longer than 90 days from the day it was filed |
| The report itself and the decision on it | Longer, as a safety record; links to deleted accounts are removed from it |
| Voice answer on the profile of a closed account (banned, or a profile we rejected) | 90 days; up to 180 if a report is still open |
| Profile photos and the verification selfie of a closed account | No automatic deadline yet — they are the evidence the decision, and your appeal against it, rest on. Ask us and we erase them along with the rest of the account. We will name a fixed deadline for them before the public launch. |
| Log of moderators’ decisions | 12 months |
| Log of admin sign-ins | 180 days |
| Analytics log | 180 days; events from before sign-up that never got linked to an account — 90 days |
| Technical rate-limit marks | 25 hours |
We delete analytics in monthly batches, so the earliest events in a batch live a few weeks longer than the number above.
7. Deleting your account
Profile → Delete account. Your profile disappears immediately: you’re gone from the feed, from the people you matched with, and from chats. Everything is erased within 30 days — profile, photos, selfie, messages, voice messages, matches, push tokens and analytics records — and your sessions are closed.
You can still change your mind during those 30 days, because the data is still with us. There is no “restore account” button in the app yet, so write to support@lylo.dating — and then we have to make sure it’s really you, because “please bring this account back” reads exactly the same whoever sends it. The address you write from proves nothing, so we check the thing you actually sign in with: for an account on a phone number, we text a one-time code to that number and you quote it back to us in your reply. If you use Sign in with Apple, we deliberately never receive your email address from Apple — there is nothing for us to match a letter against, and we won’t act on a request we can’t verify. Until the restore button exists in the app, that is an honest gap rather than a promise: an account created with Sign in with Apple can’t be brought back by email alone.
Photos and messages you sent go away too — including from the other person’s side of the conversation.
What outlives the erasure, and why. Reports (yours and about you) and records of moderation decisions stay. What is removed from them is everything written and everything pointing at you: the link to your account, the text the person wrote when reporting, the moderator’s notes, and the copy of the messages attached to the report. What is left is a de-identified trace: “there was a report of this kind, this was decided”. That’s how someone banned for harassment can’t erase their history by deleting the account and starting a new one. The GDPR allows exactly this exception (Article 17(3)(e)). Messages attached to a report follow the deadlines in the table above and are deleted even if the account is already gone.
8. Your rights
Right in the app:
- see and change your profile — Profile → Edit profile;
- turn off your activity status — Profile → Visibility;
- set up notifications, including “News and offers” — Profile → Notifications;
- pause your profile instead of deleting it — Profile → Visibility;
- delete your account — Profile → Delete account.
By writing to support@lylo.dating:
- A copy of your data. We don’t have a one-tap export yet, so we collect it by hand and send it within 30 days. If we’re going to be late, we’ll say so honestly and give you a new date.
- Fixing what you can’t fix yourself. Date of birth, gender, orientation and who you’re looking for are locked after your profile is approved, so a checked profile can’t be swapped for a different one. Ask us and we’ll change them.
- Restricting or objecting to processing, and withdrawing consent.
Before we hand anything over or change anything by email, we make sure the request is yours: a copy of your data sent to the wrong person would be the very thing this page promises to prevent. The address you write from isn’t proof, so we check the credential you sign in with — for a phone account, a one-time code we text to that number and you quote back. The full procedure, including what we can’t verify, is on the support page.
One thing we won’t pretend about: the verification selfie is required for everyone — it’s how we can promise that everyone here is real. So you can’t withdraw consent for it and keep using LyLo; the selfie is erased together with your account.
If you’re in the EU, the UK or Switzerland, you can also complain to your data protection authority. If you’re in California: we do not sell or “share” personal information as those words are defined by the CCPA/CPRA.
9. Age
LyLo is for adults 18 and over — the server refuses a younger date of birth. We don’t knowingly keep data of anyone under 18; such accounts are removed.
10. How we protect it
All traffic is encrypted (TLS). Every table is closed by default, and anything personal is handed out by our own server functions, only to the person it belongs to — the app never reads people’s data out of the database itself. There is exactly one exception, and it holds nothing about anybody: the list of interests and the list of profile questions are identical for everyone, so the app reads those two reference tables straight from the database. Sensitive files — verification selfies, voice messages, photos from conversations, profile voice answers — live in private storage and are only ever served through short-lived signed links (an hour for chat media, minutes for a moderator). Team access is limited to what moderation and support actually require, and every admin sign-in is logged.
11. Changes
If we change this policy in a way that matters, we’ll tell you in the app before it takes effect. The current version always lives at lylo.dating/privacy.