Lueurly · Legal Center

Last updated 2026-06-24 · v1.5

Privacy Policy

1. Who We Are

Lueurly is a brand name used by TZU-YU CHIU, an individual developer based in Taiwan (not a registered trademark or company). TZU-YU CHIU (operating as Lueurly) is the operator/the party you contract with.

Contact: [email protected]

Lueurly's backend (API, media, notification, authentication, and related server endpoints) is operated in server environments managed for Lueurly and provided through Lueurly-related service infrastructure, including the lueurly.com domain. Related systems may be deployed in third-party data centers, cloud service providers, or network infrastructure environments.

Lueurly is not directed to, offered to, marketed to, or intended for residents of the European Union, European Economic Area, United Kingdom, Switzerland, or South Korea. We intend to limit availability in excluded regions through App Store Connect geo-restrictions and operational controls where configured and reasonably available. The Service is therefore not intended for residents of those excluded regions; if any mandatory provision of the GDPR, UK GDPR, Digital Services Act, or Korean Location Information Act nonetheless applies, Lueurly will honor the non-waivable rights it grants. Nothing in this Policy excludes any rights that cannot be excluded under applicable law.

2. Data We Collect

The categories of data we collect and process are described below. We do not intend to collect materially different categories of personal data without updating this Policy where required by applicable law or App Store requirements.

CategoryDataWhen collectedPurpose
Account identifiersEmail address, display name, avatar, locale, timezoneRegistration, login, profile useAccount creation, login, localization, account display
Authentication dataPassword stored only as an Argon2id hash, Google identifier, Apple `sub` identifierRegistration, login, SSOAuthentication and account security
Age data`birth_year`Registration or first SSO use18+ eligibility check
Device and technical dataDevice fingerprint made from IDFV and bundle identifier using SHA-256, IP address, user agent, app versionAuthentication, token refresh, security eventsAccount security, new-device detection, audit records, abuse prevention
Push tokensFirebase Cloud Messaging token, Apple APNs tokenApp launch or token refreshPush notifications
Location for Keepsake (pact) signing audit`gps_lat`, `gps_lng`Only when you sign a Keepsake (pact) and the Premium audit-location option is enabledKeepsake (pact) signing audit metadata
IP and user agent for Keepsake (pact) signing auditPublic IP and user agent captured from request headersKeepsake (pact) signing and related security or audit eventsKeepsake (pact) signing audit metadata, abuse prevention, security, and legal compliance
User-generated contentText, voice files, photos, wax seal choices, replies, chat threads, pact content, electronic signatures, and other content created, uploaded, transmitted, or stored by usersWhen you create, upload, send, receive, reply to, store, or sign contentCore messaging and pact features
Message feature flagsFading Light (burn-after-read) duration, Trusted device binding (device-bound) status, Light Up Together (Sync Open) status, Scheduled send (scheduled delivery) time, Anonymous message statusMessage compositionDelivering selected message features
Read receiptsRecipient email, display name, `read_at`When a recipient opens a messageShowing sender read status
Contacts matching dataSHA-256 hashes of normalized email addresses only; we do not store plaintext contact email, phone number, or name for contact syncOnly after your express consentFinding registered friends, suggesting friends, detecting mutual matches, operating automatic-add rules, preventing abuse, and maintaining contact-matching integrity
Friends and blocksFriend email or alias, block list entriesWhen you add, invite, or block usersSocial graph, invitations, abuse prevention
Subscription dataProduct ID, original transaction ID, purchase token, Apple receipt/JWSPurchase and renewalSubscription validation and Premium entitlement
Security recordsLogin attempts, audit logsAutomatically during security-relevant activityAbuse prevention, account protection, operational audit
Content moderation dataReports, report reasons, report notes, screenshot-detection eventsUser reports or client-side eventsUGC safety, objectionable-content review, screenshot notice
PreferencesPush and email settings, quiet hours, anonymous-message preference, biometric-lock setting, marketing opt-inSettings changesPersonalization and consent management

You are responsible for ensuring that your User-Submitted Content is lawful, that you have all rights and permissions necessary to submit it, and that it does not infringe, misappropriate, or otherwise violate any third-party rights. Lueurly does not proactively review all User-Submitted Content and does not assume responsibility for the legality, truthfulness, completeness, or accuracy of User-Submitted Content except to the extent applicable law does not allow such responsibility to be disclaimed.

3. Device Permissions

Lueurly may request optional device permissions for app features:

PermissionUse
MicrophoneRecording voice messages
Speech recognitionVoice-to-text, preferably on device where available
Photo libraryAttaching photos
Location while in useOptional pact-signing audit location (Premium)
Face IDOptional app unlock
ContactsFriend discovery through hashed email matching

If you deny a permission, the related feature may not work, but other app features remain available where technically possible.

4. Why We Process Data

We process data to provide the service, authenticate accounts, deliver messages, operate Premium features, process subscriptions through Apple, secure accounts, prevent abuse, respond to reports, comply with legal obligations, and honor your settings. Where a feature depends on your action or consent, such as contacts matching or optional pact-signing audit location, you may choose not to use that feature or withdraw the relevant permission.

This section describes our operational reasons for processing. It is not intended as a GDPR legal-basis notice; the Service is not directed to, offered to, or marketed to users in the EU, EEA, UK, or Switzerland, but where any mandatory provision of applicable law nonetheless applies, Lueurly will honor the non-waivable rights it grants.

5. How We Use Data

We use account, authentication, and device data to create accounts, log you in, detect new devices, and protect accounts.

We access, process, and use relevant data only to the extent reasonably necessary to provide the Service, maintain system security, prevent abuse, respond to reports, comply with legal obligations, or carry out your requests and selected feature settings.

We use message content and feature flags to deliver messages, schedule delivery, manage Sync Open, apply device-bound restrictions, and support burn-after-read. Except as required by law, authorized by you, or otherwise described in this Policy, we do not proactively read the contents of private user messages.

We use GPS coordinates in only one context: the optional Premium pact-signing audit, and only when you have enabled that option and grant permission at signing time. We do not use GPS or location for Light Up Together (Sync Open). Light Up Together relies only on a shared time window and a count of participants who choose to "light up"; it does not collect, transmit, share, or evaluate any location data. We do not continuously track location.

We use pact audit IP, user agent, GPS where enabled and available, device, and timestamp metadata only as system records, audit metadata, security records, and legal-compliance records. Pact audit settings may control selected enhanced audit fields or client-side GPS capture, but they do not prevent Lueurly from creating ordinary technical, security, anti-abuse, legal-compliance, or transaction records. Lueurly does not represent or warrant that such records have any particular legal effect, evidentiary admissibility, or enforceability; actual legal effect depends on applicable law and the determination of the competent authority or court.

We use contact hashes only for contact matching and related integrity purposes. Contact matching is optional and requires your action or consent. If enabled, the app reads email addresses from your device contacts, normalizes them locally, creates SHA-256 hashes locally, and uploads only those hashes to the server for matching. We do not upload or store plaintext contact names, phone numbers, postal addresses, notes, or plaintext contact email addresses for contact sync. Email hashes reduce exposure but may still be personal data because they can correspond to identifiable email addresses.

Lueurly may use contact hashes to find registered users, suggest friends, detect mutual matches, automatically add friends only where mutual-match rules or service configuration allow it, prevent abuse, measure eligibility, operate the feature, and maintain the integrity of friend-discovery systems. Lueurly may determine or change matching criteria, ranking, suggestion logic, automatic-add logic, frequency, eligibility, retention, and availability of contact matching, subject to applicable law. If you withdraw consent or delete synced contact hashes, future matching may stop, but existing friend relationships, invitations, blocks, abuse records, safety records, or other records separately maintained under the Service may remain until removed under the applicable feature or retention rule.

Firebase is used only for push delivery through FCM. Firebase Analytics is disabled, advertising is disabled, and Lueurly does not include third-party tracking SDKs such as Crashlytics, Sentry, or Mixpanel.

We do not sell personal data. We do not share personal data for cross-app tracking. We do not use your data for third-party advertising.

6. Processors and Third Parties

We share data with service providers only as needed to operate Lueurly.

ProviderData involvedPurposeRegion
AppleApp Store transactions, APNs token, Sign in with Apple identifierPayments, push notifications, loginGlobal
GoogleFCM token, Google Sign-In identifierPush notifications, loginGlobal
Hetzner Online GmbHBackend service dataHosting and infrastructure servicesOutside the United States
Resend, through an internal relayRecipient email address and email contentsTransactional and notification email deliveryUnited States
CloudflareDNS, TLS, routing, email-routing, and related technical metadataDNS, TLS, security, routing, and email-routing infrastructureGlobal

These service providers may apply their own terms and privacy practices. We are not responsible for third-party services outside our control, but we select and use service providers as reasonably necessary to operate, secure, and support the Service.

Hetzner Online GmbH provides hosting and infrastructure services. Hetzner acts only as a service provider and data processor for infrastructure purposes; using such an infrastructure provider does not make Lueurly an entity established in the European Union or, by itself, automatically subject Lueurly to the GDPR.

Lueurly's backend (API, media, notification, authentication, and related server endpoints) is managed and operated by us and provided through the lueurly.com domain. Related systems may be deployed in third-party data centers, cloud service providers, or network infrastructure environments operated by reputable providers.

Apple processes App Store payments. Lueurly does not receive or store your payment card number.

6A. Legal Requests and Law-Enforcement Disclosures

We may disclose relevant data when reasonably necessary to:

  • comply with law, court orders, subpoenas, warrants, government requests, or other valid legal process;
  • protect the rights, safety, and property of Lueurly, users, or third parties;
  • investigate fraud, abuse, harassment, threats, intellectual-property violations, child-safety incidents, or other unlawful conduct;
  • enforce the Terms of Service, Community Guidelines, or other applicable policies; or
  • respond to disputes, claims, or security incidents.

To the extent permitted by law, we seek to disclose only the information reasonably necessary for the applicable purpose.

Where we become aware of apparent child sexual abuse material or sexual exploitation of minors, we may preserve relevant information and report it to the National Center for Missing & Exploited Children (NCMEC) and to law enforcement as required or permitted by law.

6B. Business Transfers

If Lueurly's operation, assets, or service responsibilities are transferred to a successor, purchaser, assignee, newly formed legal entity, or other operator that assumes or continues the Service, we may transfer relevant data as reasonably necessary for that transition, provided that the recipient is required to handle the data under this Policy or privacy safeguards that are materially comparable.

7. Storage Location and International Transfers

We use reputable third-party infrastructure providers to host and process information on our behalf. Your information may be stored and processed on servers located outside the United States and outside your country of residence. Lueurly is operated from Taiwan.

By using the Service, you understand that your information may be transferred to and processed in countries other than your own, including the United States for email delivery through Resend and global network-routing services through Cloudflare. Where information is transferred across borders, we take steps designed to protect it in a manner consistent with this Policy and applicable law.

This disclosure is provided for transparency. Using third-party hosting or infrastructure providers does not by itself establish Lueurly in the EU or subject the Service to the GDPR; where any mandatory provision of applicable law nonetheless applies, Lueurly will honor the non-waivable rights it grants.

8. Retention

We retain data according to the verified retention schedule below:

DataRetention
Fading Light (burn-after-read) content, including text, photos, and voice filesCleared from active server storage no later than 1 hour after the applicable read and expiry condition is satisfied; for multi-recipient messages, content may remain until all relevant recipients satisfy the system's purge condition
Contact hashesDeleted after 90 days without update
Keepsake (pact) signing audit location (`gps_lat`, `gps_lng`), only when the Premium audit-location option is enabledCleared after 90 days
Login attempts30 days
Audit logs, including IP, user agent, and device fingerprint180 days
Web access logs, including IP14 days
Application logs30 days
Database backups30-day rolling backups
Account data and remaining contentKept while the account exists; deleted or anonymized within a reasonable period after account deletion, subject to the limited exceptions described in this Policy

Burn-after-read is best-effort. Lueurly cannot prevent recipients from taking screenshots, screen recordings, photos of the screen, external recordings, notification previews, device backups, or other external copies before deletion. Cleared burn-after-read content is not retained long-term, and backups roll over within 30 days. Limited metadata, logs, legal holds, safety records, abuse reports, payment records, dispute records, or legally required records may be retained for the periods described in this Policy and the Data Retention Policy.

After account deletion, we will delete or anonymize relevant data within a reasonable period. To comply with legal obligations, prevent abuse, resolve disputes, enforce the Terms of Service, protect rights, process payments or refunds, or maintain system security, we may retain limited data for as long as reasonably necessary to complete the applicable purpose.

9. Your Choices and Rights

You may access, correct, or update account information in the app where available.

You may delete your account through the account-deletion feature provided in the app. Account deletion starts the process for deleting account data and related content, subject to the retention periods and limited exceptions described in this Policy.

Account deletion may be irreversible. Certain records generated through interactions with other users, transaction records, audit logs, report records, safety records, or data that must be retained by law or for legitimate security, anti-abuse, dispute-resolution, or policy-enforcement purposes may continue to be retained in accordance with this Policy.

Account deletion may cancel, disable, delete, or anonymize pending scheduled sends, drafts, Premium-dependent settings, contact-sync data, friend data, device sessions, push tokens, and other account-tied service records. Deleting your Lueurly account does not necessarily cancel an active Apple subscription; Apple subscription management remains handled by Apple.

You may request deletion by email if you cannot access the app: [email protected].

Where available, you may use export features provided in the app to download relevant message, pact, and related account data. Lueurly does not currently provide a single complete machine-readable account export feature.

You may delete contact-sync data through the app's contact-sync controls, withdraw optional device permissions in iOS Settings, block users, report content, log out devices, and change notification, email, anonymous-message, biometric-lock, and marketing preferences.

10. US State Privacy Notice

Lueurly does not sell personal information and does not share personal information for cross-context behavioral advertising. Lueurly does not use personal data for cross-app tracking.

Some US state privacy laws apply only to businesses that meet revenue, user-volume, or data-sale thresholds. Lueurly may not meet those thresholds. Even where a law does not apply, you may contact us at [email protected] to request access, correction, deletion, or information about our data practices.

If Lueurly's operations grow in a way that makes specific state privacy laws applicable, we will update this Policy and the related user-rights disclosures as required by applicable law.

11. Security

Lueurly uses reasonable administrative, technical, and organizational safeguards, including HTTPS/WSS encryption in transit, Argon2id password hashing, Keychain session storage, and device/security audit controls.

Although we use reasonable security measures, no electronic storage, network transmission, or information system can be guaranteed to be completely secure. You are responsible for keeping your account credentials and trusted devices secure.

To the maximum extent permitted by law, Lueurly is not responsible for damages caused by third-party attacks, user negligence, compromised user devices, force majeure events, infrastructure failures outside our reasonable control, or other circumstances beyond Lueurly's reasonable control.

12. Children and Adults Only

Lueurly is for adults only. You must be at least 18 years old to use the service. Lueurly is not directed to children or minors. We use `birth_year` to help enforce the 18+ requirement. Lueurly does not knowingly collect personal information from children under 13. If we learn that an underage account exists, we may suspend, disable, terminate, delete, or anonymize the account and related data as appropriate and as permitted or required by law.

13. Changes to This Policy

We may update this Privacy Policy as the service, law, or operational practices change. For material changes, we will provide reasonable notice through the app, website, email, or another appropriate method before the change takes effect where practical.

14. Contact

For privacy requests, account deletion help, security questions, or complaints, contact:

[email protected]

The official version and controlling language of these documents are governed by Section 27 of the Lueurly Common Terms of Use.