Last updated 2026-06-24 · v1.5
Privacy Policy
1. Who We Are
Lueurly is a brand name used by TZU-YU CHIU, an individual developer based in Taiwan (not a registered trademark or company). TZU-YU CHIU (operating as Lueurly) is the operator/the party you contract with.
Contact: [email protected]
Lueurly's backend (API, media, notification, authentication, and related server endpoints) is operated in server environments managed for Lueurly and provided through Lueurly-related service infrastructure, including the lueurly.com domain. Related systems may be deployed in third-party data centers, cloud service providers, or network infrastructure environments.
Lueurly is not directed to, offered to, marketed to, or intended for residents of the European Union, European Economic Area, United Kingdom, Switzerland, or South Korea. We intend to limit availability in excluded regions through App Store Connect geo-restrictions and operational controls where configured and reasonably available. The Service is therefore not intended for residents of those excluded regions; if any mandatory provision of the GDPR, UK GDPR, Digital Services Act, or Korean Location Information Act nonetheless applies, Lueurly will honor the non-waivable rights it grants. Nothing in this Policy excludes any rights that cannot be excluded under applicable law.
2. Data We Collect
The categories of data we collect and process are described below. We do not intend to collect materially different categories of personal data without updating this Policy where required by applicable law or App Store requirements.
| Category | Data | When collected | Purpose |
|---|---|---|---|
| Account identifiers | Email address, display name, avatar, locale, timezone | Registration, login, profile use | Account creation, login, localization, account display |
| Authentication data | Password stored only as an Argon2id hash, Google identifier, Apple `sub` identifier | Registration, login, SSO | Authentication and account security |
| Age data | `birth_year` | Registration or first SSO use | 18+ eligibility check |
| Device and technical data | Device fingerprint made from IDFV and bundle identifier using SHA-256, IP address, user agent, app version | Authentication, token refresh, security events | Account security, new-device detection, audit records, abuse prevention |
| Push tokens | Firebase Cloud Messaging token, Apple APNs token | App launch or token refresh | Push notifications |
| Location for Keepsake (pact) signing audit | `gps_lat`, `gps_lng` | Only when you sign a Keepsake (pact) and the Premium audit-location option is enabled | Keepsake (pact) signing audit metadata |
| IP and user agent for Keepsake (pact) signing audit | Public IP and user agent captured from request headers | Keepsake (pact) signing and related security or audit events | Keepsake (pact) signing audit metadata, abuse prevention, security, and legal compliance |
| User-generated content | Text, voice files, photos, wax seal choices, replies, chat threads, pact content, electronic signatures, and other content created, uploaded, transmitted, or stored by users | When you create, upload, send, receive, reply to, store, or sign content | Core messaging and pact features |
| Message feature flags | Fading Light (burn-after-read) duration, Trusted device binding (device-bound) status, Light Up Together (Sync Open) status, Scheduled send (scheduled delivery) time, Anonymous message status | Message composition | Delivering selected message features |
| Read receipts | Recipient email, display name, `read_at` | When a recipient opens a message | Showing sender read status |
| Contacts matching data | SHA-256 hashes of normalized email addresses only; we do not store plaintext contact email, phone number, or name for contact sync | Only after your express consent | Finding registered friends, suggesting friends, detecting mutual matches, operating automatic-add rules, preventing abuse, and maintaining contact-matching integrity |
| Friends and blocks | Friend email or alias, block list entries | When you add, invite, or block users | Social graph, invitations, abuse prevention |
| Subscription data | Product ID, original transaction ID, purchase token, Apple receipt/JWS | Purchase and renewal | Subscription validation and Premium entitlement |
| Security records | Login attempts, audit logs | Automatically during security-relevant activity | Abuse prevention, account protection, operational audit |
| Content moderation data | Reports, report reasons, report notes, screenshot-detection events | User reports or client-side events | UGC safety, objectionable-content review, screenshot notice |
| Preferences | Push and email settings, quiet hours, anonymous-message preference, biometric-lock setting, marketing opt-in | Settings changes | Personalization and consent management |
You are responsible for ensuring that your User-Submitted Content is lawful, that you have all rights and permissions necessary to submit it, and that it does not infringe, misappropriate, or otherwise violate any third-party rights. Lueurly does not proactively review all User-Submitted Content and does not assume responsibility for the legality, truthfulness, completeness, or accuracy of User-Submitted Content except to the extent applicable law does not allow such responsibility to be disclaimed.
3. Device Permissions
Lueurly may request optional device permissions for app features:
| Permission | Use |
|---|---|
| Microphone | Recording voice messages |
| Speech recognition | Voice-to-text, preferably on device where available |
| Photo library | Attaching photos |
| Location while in use | Optional pact-signing audit location (Premium) |
| Face ID | Optional app unlock |
| Contacts | Friend discovery through hashed email matching |
If you deny a permission, the related feature may not work, but other app features remain available where technically possible.
4. Why We Process Data
We process data to provide the service, authenticate accounts, deliver messages, operate Premium features, process subscriptions through Apple, secure accounts, prevent abuse, respond to reports, comply with legal obligations, and honor your settings. Where a feature depends on your action or consent, such as contacts matching or optional pact-signing audit location, you may choose not to use that feature or withdraw the relevant permission.
This section describes our operational reasons for processing. It is not intended as a GDPR legal-basis notice; the Service is not directed to, offered to, or marketed to users in the EU, EEA, UK, or Switzerland, but where any mandatory provision of applicable law nonetheless applies, Lueurly will honor the non-waivable rights it grants.
5. How We Use Data
We use account, authentication, and device data to create accounts, log you in, detect new devices, and protect accounts.
We access, process, and use relevant data only to the extent reasonably necessary to provide the Service, maintain system security, prevent abuse, respond to reports, comply with legal obligations, or carry out your requests and selected feature settings.
We use message content and feature flags to deliver messages, schedule delivery, manage Sync Open, apply device-bound restrictions, and support burn-after-read. Except as required by law, authorized by you, or otherwise described in this Policy, we do not proactively read the contents of private user messages.
We use GPS coordinates in only one context: the optional Premium pact-signing audit, and only when you have enabled that option and grant permission at signing time. We do not use GPS or location for Light Up Together (Sync Open). Light Up Together relies only on a shared time window and a count of participants who choose to "light up"; it does not collect, transmit, share, or evaluate any location data. We do not continuously track location.
We use pact audit IP, user agent, GPS where enabled and available, device, and timestamp metadata only as system records, audit metadata, security records, and legal-compliance records. Pact audit settings may control selected enhanced audit fields or client-side GPS capture, but they do not prevent Lueurly from creating ordinary technical, security, anti-abuse, legal-compliance, or transaction records. Lueurly does not represent or warrant that such records have any particular legal effect, evidentiary admissibility, or enforceability; actual legal effect depends on applicable law and the determination of the competent authority or court.
We use contact hashes only for contact matching and related integrity purposes. Contact matching is optional and requires your action or consent. If enabled, the app reads email addresses from your device contacts, normalizes them locally, creates SHA-256 hashes locally, and uploads only those hashes to the server for matching. We do not upload or store plaintext contact names, phone numbers, postal addresses, notes, or plaintext contact email addresses for contact sync. Email hashes reduce exposure but may still be personal data because they can correspond to identifiable email addresses.
Lueurly may use contact hashes to find registered users, suggest friends, detect mutual matches, automatically add friends only where mutual-match rules or service configuration allow it, prevent abuse, measure eligibility, operate the feature, and maintain the integrity of friend-discovery systems. Lueurly may determine or change matching criteria, ranking, suggestion logic, automatic-add logic, frequency, eligibility, retention, and availability of contact matching, subject to applicable law. If you withdraw consent or delete synced contact hashes, future matching may stop, but existing friend relationships, invitations, blocks, abuse records, safety records, or other records separately maintained under the Service may remain until removed under the applicable feature or retention rule.
Firebase is used only for push delivery through FCM. Firebase Analytics is disabled, advertising is disabled, and Lueurly does not include third-party tracking SDKs such as Crashlytics, Sentry, or Mixpanel.
We do not sell personal data. We do not share personal data for cross-app tracking. We do not use your data for third-party advertising.
6. Processors and Third Parties
We share data with service providers only as needed to operate Lueurly.
| Provider | Data involved | Purpose | Region |
|---|---|---|---|
| Apple | App Store transactions, APNs token, Sign in with Apple identifier | Payments, push notifications, login | Global |
| FCM token, Google Sign-In identifier | Push notifications, login | Global | |
| Hetzner Online GmbH | Backend service data | Hosting and infrastructure services | Outside the United States |
| Resend, through an internal relay | Recipient email address and email contents | Transactional and notification email delivery | United States |
| Cloudflare | DNS, TLS, routing, email-routing, and related technical metadata | DNS, TLS, security, routing, and email-routing infrastructure | Global |
These service providers may apply their own terms and privacy practices. We are not responsible for third-party services outside our control, but we select and use service providers as reasonably necessary to operate, secure, and support the Service.
Hetzner Online GmbH provides hosting and infrastructure services. Hetzner acts only as a service provider and data processor for infrastructure purposes; using such an infrastructure provider does not make Lueurly an entity established in the European Union or, by itself, automatically subject Lueurly to the GDPR.
Lueurly's backend (API, media, notification, authentication, and related server endpoints) is managed and operated by us and provided through the lueurly.com domain. Related systems may be deployed in third-party data centers, cloud service providers, or network infrastructure environments operated by reputable providers.
Apple processes App Store payments. Lueurly does not receive or store your payment card number.
6A. Legal Requests and Law-Enforcement Disclosures
We may disclose relevant data when reasonably necessary to:
- comply with law, court orders, subpoenas, warrants, government requests, or other valid legal process;
- protect the rights, safety, and property of Lueurly, users, or third parties;
- investigate fraud, abuse, harassment, threats, intellectual-property violations, child-safety incidents, or other unlawful conduct;
- enforce the Terms of Service, Community Guidelines, or other applicable policies; or
- respond to disputes, claims, or security incidents.
To the extent permitted by law, we seek to disclose only the information reasonably necessary for the applicable purpose.
Where we become aware of apparent child sexual abuse material or sexual exploitation of minors, we may preserve relevant information and report it to the National Center for Missing & Exploited Children (NCMEC) and to law enforcement as required or permitted by law.
6B. Business Transfers
If Lueurly's operation, assets, or service responsibilities are transferred to a successor, purchaser, assignee, newly formed legal entity, or other operator that assumes or continues the Service, we may transfer relevant data as reasonably necessary for that transition, provided that the recipient is required to handle the data under this Policy or privacy safeguards that are materially comparable.
7. Storage Location and International Transfers
We use reputable third-party infrastructure providers to host and process information on our behalf. Your information may be stored and processed on servers located outside the United States and outside your country of residence. Lueurly is operated from Taiwan.
By using the Service, you understand that your information may be transferred to and processed in countries other than your own, including the United States for email delivery through Resend and global network-routing services through Cloudflare. Where information is transferred across borders, we take steps designed to protect it in a manner consistent with this Policy and applicable law.
This disclosure is provided for transparency. Using third-party hosting or infrastructure providers does not by itself establish Lueurly in the EU or subject the Service to the GDPR; where any mandatory provision of applicable law nonetheless applies, Lueurly will honor the non-waivable rights it grants.
8. Retention
We retain data according to the verified retention schedule below:
| Data | Retention |
|---|---|
| Fading Light (burn-after-read) content, including text, photos, and voice files | Cleared from active server storage no later than 1 hour after the applicable read and expiry condition is satisfied; for multi-recipient messages, content may remain until all relevant recipients satisfy the system's purge condition |
| Contact hashes | Deleted after 90 days without update |
| Keepsake (pact) signing audit location (`gps_lat`, `gps_lng`), only when the Premium audit-location option is enabled | Cleared after 90 days |
| Login attempts | 30 days |
| Audit logs, including IP, user agent, and device fingerprint | 180 days |
| Web access logs, including IP | 14 days |
| Application logs | 30 days |
| Database backups | 30-day rolling backups |
| Account data and remaining content | Kept while the account exists; deleted or anonymized within a reasonable period after account deletion, subject to the limited exceptions described in this Policy |
Burn-after-read is best-effort. Lueurly cannot prevent recipients from taking screenshots, screen recordings, photos of the screen, external recordings, notification previews, device backups, or other external copies before deletion. Cleared burn-after-read content is not retained long-term, and backups roll over within 30 days. Limited metadata, logs, legal holds, safety records, abuse reports, payment records, dispute records, or legally required records may be retained for the periods described in this Policy and the Data Retention Policy.
After account deletion, we will delete or anonymize relevant data within a reasonable period. To comply with legal obligations, prevent abuse, resolve disputes, enforce the Terms of Service, protect rights, process payments or refunds, or maintain system security, we may retain limited data for as long as reasonably necessary to complete the applicable purpose.
9. Your Choices and Rights
You may access, correct, or update account information in the app where available.
You may delete your account through the account-deletion feature provided in the app. Account deletion starts the process for deleting account data and related content, subject to the retention periods and limited exceptions described in this Policy.
Account deletion may be irreversible. Certain records generated through interactions with other users, transaction records, audit logs, report records, safety records, or data that must be retained by law or for legitimate security, anti-abuse, dispute-resolution, or policy-enforcement purposes may continue to be retained in accordance with this Policy.
Account deletion may cancel, disable, delete, or anonymize pending scheduled sends, drafts, Premium-dependent settings, contact-sync data, friend data, device sessions, push tokens, and other account-tied service records. Deleting your Lueurly account does not necessarily cancel an active Apple subscription; Apple subscription management remains handled by Apple.
You may request deletion by email if you cannot access the app: [email protected].
Where available, you may use export features provided in the app to download relevant message, pact, and related account data. Lueurly does not currently provide a single complete machine-readable account export feature.
You may delete contact-sync data through the app's contact-sync controls, withdraw optional device permissions in iOS Settings, block users, report content, log out devices, and change notification, email, anonymous-message, biometric-lock, and marketing preferences.
10. US State Privacy Notice
Lueurly does not sell personal information and does not share personal information for cross-context behavioral advertising. Lueurly does not use personal data for cross-app tracking.
Some US state privacy laws apply only to businesses that meet revenue, user-volume, or data-sale thresholds. Lueurly may not meet those thresholds. Even where a law does not apply, you may contact us at [email protected] to request access, correction, deletion, or information about our data practices.
If Lueurly's operations grow in a way that makes specific state privacy laws applicable, we will update this Policy and the related user-rights disclosures as required by applicable law.
11. Security
Lueurly uses reasonable administrative, technical, and organizational safeguards, including HTTPS/WSS encryption in transit, Argon2id password hashing, Keychain session storage, and device/security audit controls.
Although we use reasonable security measures, no electronic storage, network transmission, or information system can be guaranteed to be completely secure. You are responsible for keeping your account credentials and trusted devices secure.
To the maximum extent permitted by law, Lueurly is not responsible for damages caused by third-party attacks, user negligence, compromised user devices, force majeure events, infrastructure failures outside our reasonable control, or other circumstances beyond Lueurly's reasonable control.
12. Children and Adults Only
Lueurly is for adults only. You must be at least 18 years old to use the service. Lueurly is not directed to children or minors. We use `birth_year` to help enforce the 18+ requirement. Lueurly does not knowingly collect personal information from children under 13. If we learn that an underage account exists, we may suspend, disable, terminate, delete, or anonymize the account and related data as appropriate and as permitted or required by law.
13. Changes to This Policy
We may update this Privacy Policy as the service, law, or operational practices change. For material changes, we will provide reasonable notice through the app, website, email, or another appropriate method before the change takes effect where practical.
14. Contact
For privacy requests, account deletion help, security questions, or complaints, contact:
The official version and controlling language of these documents are governed by Section 27 of the Lueurly Common Terms of Use.