Privacy Policy
The short version
LyPinn is a tiny 3 km neighbourhood notice-board. You drop a card, your neighbours pick it up, you chat once, then it's gone. We collect the bare minimum to make that work: an email address, a one-line name, a self-declaration that you are 18+, your location *only while the app is open* (unless you opt in to background mode), and the text of cards you choose to publish. Sponsored content: LyPinn shows a small number of clearly-labelled sponsored cards and location-based sponsor branding in the Discover feed. Sponsors never see your profile — matching happens on our servers. You can turn off sponsored content and personalised matching at any time in Settings → Ads & sponsored content.
1. Who runs LyPinn
LyPinn is operated by Bhavik Patel as a sole proprietor, from a registered virtual office at Ahmedabad, Gujarat 380058, India. Bhavik Patel is your Data Fiduciary under India's Digital Personal Data Protection Act, 2023, and — where applicable — the Data Controller under EU / UK GDPR and the Business under the California Consumer Privacy Act (CCPA / CPRA).
Contact us
- Grievance Officer (DPDPA §8): `grievance@lypinn.com`
- Data Protection Officer / data-subject requests: `dpo@lypinn.com`
- General legal notice: `contact@lypinn.com`
Trademarks & copyright. "LyPinn" and the LyPinn logo are trademarks of Bhavik Patel. The LyPinn platform, mobile app and website content are © Bhavik Patel, 2026 — all rights reserved.
Company being incorporated. A private limited company, LYPINN TECHNOLOGIES PRIVATE LIMITED, is being incorporated to take over the LyPinn platform. When the transfer completes we will publish an updated Privacy Policy naming the Company as Data Fiduciary and require you to accept it before continuing to use LyPinn. If you decline the updated policy at that time you may close your account without penalty. Until then, Bhavik Patel remains the sole Data Fiduciary.
LyPinn is a free-to-use service for individual users — there is no paid tier, no in-app purchase and no subscription. Advertisers and sponsors may pay fees for placement (covered in the separate Business Terms document); no user data is sold or exchanged for that revenue.
2. What we collect
You give us, when you sign up
- Email address (used as your login + for service emails).
- Display name (one line, shown only on cards you choose to attribute; anonymous mode is the default).
- A self-declaration that you are 18 years or older (we no longer store a date of birth).
- A hashed password (we store the hash, never the plain text).
- Account type — `individual` or `business`. Business profiles get a small `Business` tag on their cards; nothing else.
You may add, optionally
- A profile picture or avatar slug, a one-line bio.
- A LyPinn ID — a short public handle (e.g. `@meera_99`) that you choose once and that becomes permanent. It is the *only* identifier shown to people you share GNotes with via LyPinn Connect; your email is never revealed to them.
- Your preferred interface language (12 supported; persists across devices on login).
- Apple, Google or Facebook identity tokens (we keep the stable identifier each provider returns; never your provider password).
- A device-only 4-digit PIN for the My Cards screen (stored hashed in your browser/device storage only — never on our servers).
The platform produces, when you use the app
- Card content (≤140 characters), its category and the coordinates it was pinned to. Cards live 24 hours then auto-expire.
- Connect + reply history (one connect → one reply, then locked).
- LyPinn Connect entries — the trusted-contact graph you explicitly opt into by sending or accepting a Connect request. We store both sides of the trust relation by `id`, the optional short note attached to the request, and the date/time of the decision. You can pause incoming requests at any time from *Profile → Allow connect requests*.
- NLocal ideas + votes — when you post or upvote a community feature suggestion. We keep the idea text, the neighbourhood it was filed under, your `user_id` (so you can edit / remove your own post), and the vote tally. Idea text is publicly visible inside the same 3 km neighbourhood. NLocal moderators (sub- admins with the `nlocal.moderate` permission) can take down ideas that breach the Terms.
- GNote attachments you choose to attach — a recorded voice clip ≤15 s (stored as audio inside your account), a Spotify track id + cached title/artist/artwork, a YouTube video id + cached title/channel/thumbnail, a sticker code, a one-line lyric quoted next to its track id, or a Strava route id. We never store the original Strava URL — only the numeric id the recipient's browser uses to render the official Strava embed. Each attachment is held alongside the GNote and deleted with it.
- Physical-gift QR unlocks — when a sender prints a GNote QR and the recipient scans it on a phone *without* the LyPinn app, we collect a compliance trail to prove the unlock was legitimate: the recipient's email, the 6-digit one-time code attempts (only the hash is kept), the IP and user-agent of the browser, and the *single* GPS reading sampled at the moment the recipient taps Share my location. We use that reading only to compute the distance to the pin (in or out of the unlock radius) — it is never combined with other readings, shared with the sender, or used for any other purpose. We keep this audit row for two years for fraud-defence and DPDP Act compliance and then auto-purge it.
- In-app notifications — a private feed of events meant for you (incoming Connect request, GNote delivered, GNote daily-limit decision, NLocal idea status change, etc.). Notifications are tied to your account, never shared, and purged when you delete the account.
- Notify Me preferences — when you opt into the *Notify Me* feature (Profile → Notify Me), we store the single pinned coordinate you chose (current location or a custom pin), an optional human-readable label (e.g. `Home`, `Office`), your optional category filter, the up-to-5 short keywords you typed, and for each keyword a derived bundle: a 12-language translation set, 8-12 short synonym / transliteration terms generated by our LLM provider (see § 5 vendors), and a 384- dimensional semantic embedding vector computed locally on our own server by an open-source multilingual model. The derived bundle exists solely so a card you might like — written in any of the 12 supported languages, or in a domain synonym you didn't think to type — can still trigger your notification. Notify Me is OFF by default for every new account; enabling it is an explicit opt-in toggle. When matches fire we also store an audit log row (`notify_me_matches`) with the matched keyword and the card id, kept for 60 days for abuse-defence and analytics, then purged.
- Push-notification device tokens (Apple APNs / Google FCM / web push), used purely to deliver pings.
- Network metadata captured at signup and at each login: IP address, user agent, approximate country (looked up against a public IP geo database). We use this only for fraud and abuse scoring.
- A risk score and risk-flag list computed by our automated abuse-detection rules.
We never collect
- Phone numbers. We don't have an SMS provider and never send SMS.
- Government IDs, payment cards, or any banking details.
- Biometric templates — biometric sign-in uses your device's built-in unlock (Touch ID / Face ID / fingerprint) which never leaves your phone.
- Continuous background location (unless you explicitly opt in to the Reminder background mode in Settings — see §3).
3. How location works
Foreground only by default. When the app is open we ask the OS for your current coordinates so we can (a) show you what's within 3 km and (b) pin any card you drop. We do not store a trail of where you've been — only the single coordinate of each card you publish.
Discovery is opt-in. As of our 2026-05 release, *using your live location for Discovery* is a per-user opt-in (Settings → Features → Discovery — current location). When you turn it off you can pin a single custom location for the Discover feed instead. We lock the custom pin for 24 hours after you set it so it stays a deliberate choice — switching the live-location toggle back on at any time is free, but changing the custom pin is rate-limited. When the 24-hour lock expires we send a single, polite push notification reminding you that you can change the pin if you'd like — we don't spam.
Background opt-in (Reminders only). If you turn on *Background location* under Settings → Notifications, we enable a low-power geofence watcher for Reminders: when you cross within ~200 m of a place you've set a reminder for, your phone fires a local notification — even when LyPinn is closed.
GNotes are foreground-only. As of v1.0.97 (June 2026), GNotes no longer use background location. They unlock the moment you open LyPinn (or scan the QR / open the share link) while you're within ~500 m of the pinned spot. Recipients without the LyPinn app can also unlock GNotes directly in their phone's browser at lypinn.com/g/<token> — the page asks for your browser's location *only at that single moment of unlock* and never stores your coordinates beyond a one-line compliance log.
Notify Me pin (opt-in). When you enable Notify Me you can ask the OS for a fresh GPS reading to seed your pinned 3 km centre. We use that single coordinate only as the geofence for matching cards against your keywords — it never appears on any feed and is never shared with another user. You can change or delete the pin from Profile → Notify Me at any time. Notify Me itself is OFF by default and stays off until you save your first keyword + pin.
You can revoke any location permission at any time from your OS settings or by toggling the in-app switch off. Disabling it stops the corresponding watcher immediately.
Reliability disclosure. Reminders are designed as a fun, convenient nudge — not a guaranteed alarm. Because we do not maintain a continuously-running foreground location service (which would drain battery and trigger an always-visible system notification), the OS decides when to wake LyPinn and check your location. On devices with aggressive battery savers (MIUI, ColorOS, Funtouch OS, OxygenOS, EMUI, One UI) or when the OS has force-closed the app, notifications may be delayed by several minutes or skipped entirely. Treat them as helpful nudges rather than a primary tool — set a separate phone alarm for any time-critical task.
4. How we use your data
- Run the service. Deliver the cards-and-connects loop, authenticate logins, send transactional emails (verify email, reset password, OTP for unlock), route push notifications, and — for users who have opted into Notify Me — match newly- dropped cards against their saved keywords (substring + synonym + local semantic embedding) so we can ping them when something they care about lands inside their pinned 3 km. The embedding model runs on our own server; card text is never sent to a third-party LLM for matching.
- Keep the community safe. Apply the abuse heuristics, run the per-language profanity filter at card-create time, honour Reports and Block lists, take down content that violates the Terms, and store a minimum of evidence to defend a takedown if challenged.
- Improve the product. Aggregate, anonymous usage trends — how many cards drop in a city, how many connects close, which categories are popular, which NLocal ideas reach the upvote threshold. We do not profile individuals.
- Comply with the law. Respond to lawful requests from Indian or other competent authorities, and to honour your privacy-rights requests under the DPDP Act and analogous laws.
We do not: profile you for advertising, sell or rent data to third parties, share your location with other users (only the approximate distance bucket appears on a card), or train any third-party AI model on your private content.
5. Service providers we rely on
- MongoDB Atlas — database hosting.
- SendGrid — transactional email delivery.
- Firebase Cloud Messaging + Apple Push Notification service — delivery of push notifications.
- Cloudflare Turnstile — bot-protection CAPTCHA at signup.
- OpenStreetMap / Nominatim — optional reverse-geocoding when you choose to pin a card to a specific address.
- ip-api.com — IP → country lookup for the abuse-detection engine.
- Spotify Web API + Apple iTunes Search — looking up the title, artist and artwork for a song the *sender* chose to attach to a GNote. We send Spotify only the search query and the track id; no listener-identifying information leaves our servers.
- YouTube Data API v3 — fetching the title, channel and thumbnail for a video the *sender* chose to attach. The recipient's eventual playback happens inside YouTube's embedded player.
- Strava — when the *sender* attaches a Strava route, the recipient's browser loads Strava's official embed at `https://www.strava.com/routes/{id}/embed` inside a sandboxed iframe. We never call Strava ourselves and never share any LyPinn user data with Strava. Strava may set its own cookies inside that iframe under Strava's own privacy policy.
- MyMemory Translated.net — an admin-only "translate to English" tool used by moderators to review non-English cards. We send MyMemory only the card text and the source/target language codes — never your account email, IP, or any other identifying detail. MyMemory's free tier is rate-limited and we throttle it on our side to stay within the cap.
- Emergent LLM proxy (Google Gemini 2.5 Flash) — when you add a keyword to *Notify Me*, the short keyword string you typed is sent to our LLM provider so it can return: (a) the 12 LyPinn-supported language translations, and (b) 8-12 domain synonyms / common transliterations a fellow neighbour might use for the same thing. The keyword is sent *without* your name, email, IP, location or any other identifier — only a session-id randomly generated per request. We do not send any card text, profile field, message thread, or notification content to this provider, ever. The translated bundle is then cached on our servers under a hash of the normalised keyword and reused for every future LyPinn user who types the same word — so most keyword saves never reach the LLM at all. Calls to the LLM are batched in 30-second windows across all users, deduplicated by hash, and rate-limited globally — a single neighbour can add at most 5 keywords and 10 new keywords per rolling hour, and candidate keywords that look like keyboard-mashing (e.g. `asd`, `qwerty`, all-digits) are rejected locally before any network call is made.
- Local semantic embedding model — the open-source `sentence-transformers/paraphrase-multilingual-MiniLM-L12-v2` model runs on our own server, never leaves it, and is used to convert each dropped card's text and each Notify Me keyword into a 384-dimensional vector so the matcher can recognise meaning-equivalent phrases across languages (e.g. `gym partner` ↔ `fitness buddy`). No card text or keyword text reaches any external service through this path.
Each vendor processes only the slice of data they need to perform the listed function, under their own privacy commitments.
6. How long we keep things
- Cards — exactly 24 hours from publish, then automatically expired. Reminder cards (private to the dropper) follow your configured lifetime, up to 30 days.
- Connect threads — kept for the lifetime of the cards they reference (i.e. typically ≤24 hours), then archived for 30 days for moderation appeals, then permanently deleted.
- GNotes — 24 hours from publish (delivered or not), then automatically expired. Attachments are deleted with the GNote. Physical-gift QR unlock audit rows are kept for two years for DPDP / fraud-defence compliance.
- LyPinn ID — permanent while your account exists. When you delete your account we move your handle into a reserved list so it can never be claimed by another person impersonating you. The reserved entry holds only the lowercased handle and the original claim date — no other personal data.
- LyPinn Connect graph — kept while both sides keep their accounts open. Either party can sever a trusted connection at any time; the row is deleted within 24 hours of removal.
- NLocal ideas — kept while you keep your account. Closed ideas (shipped or rejected) move into a read-only archive for one year and are then purged.
- In-app notifications — 60 days, then aggregated or purged.
- Notify Me preferences — kept while your account exists and you keep the feature on. Turning Notify Me off in-app preserves your keywords + pin so you can re-enable later; full deletion happens when you delete the account or remove the keyword in- app. The Notify Me match audit log (`notify_me_matches`) is retained for 60 days then purged. The global keyword-translation cache is content-only (no user IDs) and survives indefinitely as a shared resource.
- Account record — kept while your account is open. Delete your account from Settings → Account → Delete and we remove the record within 30 days. Some backups may take up to 60 additional days to roll over.
- Login/IP logs — 90 days, then aggregated or purged.
7. Your rights
Under the DPDP Act, 2023 and analogous laws you can, at any time:
- Access and export your data (email `contact@lypinn.com`).
- Correct anything in your profile from the app.
- Delete your account end-to-end (Settings → Account → Delete).
- Withdraw consent for optional features (background location, push notifications, marketing emails — although we currently send no marketing emails).
- Nominate another individual to exercise these rights on your behalf if you become incapacitated (DPDP §14).
- Lodge a complaint with the Data Protection Board of India or your local supervisory authority.
7a. Selective deletion (keep account, delete specific items)
Sometimes you'll want to clean up *part* of your LyPinn footprint without nuking the whole account. We support these targeted deletions on request — most are handled within 7 working days:
- One or more cards you've published (we'll soft-delete and purge within 14 days).
- One or more GNotes you've sent (we'll mark them `revoked` so the recipient can no longer claim them; already-delivered attachments are removed from our object store).
- Reminders you've set (instantly removable in-app under Reminders → tap → Delete; the email path is only for batch removals of >50 items).
- Connect-history entries with a specific neighbour (we'll soft-delete the thread on both sides if both parties consent, otherwise just on yours).
- Login / IP history entries older than a given date.
- Profile photo, display name, bio (or set them back to defaults). The in-app Profile editor handles these instantly; email us only if the editor refuses (rare).
- Custom Discover pin (we'll wipe the pin and clear the 24- hour lock so you're free to set a new one immediately).
- Notify Me preferences — your saved keywords, pin and match history (instantly removable in-app under Profile → Notify Me; email us only if you need a bulk wipe across all your keywords and the audit log in one shot).
- Device-linked FCM tokens for a lost or sold phone (we'll unregister the device).
How to ask:
- Email `contact@lypinn.com` from the address tied to your LyPinn account (we use this for identity verification — replies from other addresses get a polite prompt to verify ownership).
- Mention "Selective deletion request" in the subject.
- Briefly list what you want removed (card IDs / GNote IDs / date ranges — paste from the app's Activity tab if it's easier). The more specific, the faster.
- We confirm receipt within 2 working days and complete most deletions within 7 working days. Court-mandated holds or live abuse investigations may extend this; we'll always tell you honestly if that's the case.
If you'd rather delete *everything*, the in-app Settings → Account → Delete flow is faster and doesn't require an email round-trip.
8. Security
Passwords are hashed with bcrypt. Sessions are JWT-signed and expire after 24 hours (refresh tokens after 14 days). The mobile app stores its session token inside the device's secure preferences store — biometric unlock is your device's native feature and never sees the network. We use HTTPS exclusively. Despite our best efforts, no internet service is invulnerable — if we detect a breach affecting your data we'll notify you and the Data Protection Board of India within the timelines required by §8(6) of the DPDP Act, 2023.
9. Minors
LyPinn is strictly 18+. Age verification is a binding self-declaration users accept at registration (see Terms §1). If we discover an under-18 account we'll terminate it immediately. Parents who believe their child holds an account can email `contact@lypinn.com` and we'll delete it within 24 hours of verification.
10. Feature flags + regional availability
Some features can be turned on or off per device family (LyPinn mobile app, mobile browser, desktop browser) or per content type (card category, GNote attachment kind). We use this for staged rollouts, store-review compliance, and incident response. When a feature is off on your device you'll see a clear "Not available on this device" badge — never a silent failure. Admins can grant per-user overrides to enable a feature for specific users (VIP testers, incident escalations); when an override is set on your account it is visible to LyPinn moderators and auditable.
10a. Per-feature opt-in (Reminders + GNotes + Discovery location + Notify Me)
Four of LyPinn's location-aware features are opt-in: Reminders, GNotes, Discovery — current location, and Notify Me. All four default to OFF for every new sign-up; the *Discovery — current location* toggle was grandfathered to ON for users who were already on LyPinn before 2026-05, since you were actively using location-based discovery; the other three (including Notify Me) default to OFF for every account regardless of when you joined. You can turn any of the four on or off any time from Settings → Features (Reminders / GNotes / Discovery) or from Profile → Notify Me.
- When a feature is OFF, the related UI is hidden across LyPinn: no Reminder category in Drop, no GNote button in Discover, no incoming GNote notifications, the Discover screen prompts you for a custom pin instead of using live GPS, etc.
- Past data is preserved when you toggle off. Your historical Reminders, GNote inbox and last-known Discover pin remain available read-only. You just can't add new ones or accept new incoming GNotes until you turn the feature back on.
- If you have GNotes OFF and someone tries to send you one, the sender is told politely that you haven't enabled GNotes — they can't burn a daily-quota slot on a delivery that won't trigger.
- If you switch GNotes OFF while an in-flight GNote is waiting for you, it is paused (not deleted). Turning GNotes back on restores it to your inbox.
- If you opt out of *Discovery — current location*, the Discover feed switches to a custom map pin you choose. We lock the pin for 24 hours so it stays a deliberate choice; when the lock expires we send a single polite push notification ("Your Discover pin is unlocked — change it if you'd like") and that's the only nudge we'll send.
- When Notify Me is OFF, we never run keyword matching for your account and no Notify Me push can fire. Your saved keywords + pin are preserved so a future re-enable picks up exactly where you left off; full deletion happens in-app from the same Profile → Notify Me screen or with account deletion.
- The choices themselves (opted-in vs opted-out) are stored on your user record. They are never shared with other users, partners or advertisers — only your sender sees a generic "recipient hasn't enabled GNotes" message when they try to drop you one.
11. Changes to this policy
When we update this policy materially we'll show an in-app banner and require a fresh acceptance before you continue. Smaller edits (typos, clarifications) are versioned silently at the footer of this page.
11a. Sponsored content and location-based promotions
LyPinn shows sponsored cards and location-based promotional overlays in the Discover feed. These are always visibly labelled with a Sponsored tag or a Presented by banner.
What we log:
- An aggregate impression when a sponsored placement is shown to you (no personally-identifying data).
- A per-device 24-hour dedupe token so you don't see the same sponsored card repeatedly.
- If you tap a sponsored card, an anonymous click event.
- If you tap Message the sponsor, we forward your LyPinn ID and message to the sponsor.
How sponsors target you:
Sponsored cards may be shown based on your general area (the same lat/lng LyPinn uses for the organic Discover feed), any Notify Me keywords you've added, and topics you've publicly posted about in the last 90 days. Matching happens on LyPinn's servers. Sponsors never see your profile, your Notify Me list, or your posts.
Your controls:
Open Settings → Ads & sponsored content to:
- Turn off sponsored cards entirely.
- Turn off location-based sponsor branding on cards.
- Turn off any of the personalisation signals independently (location / keywords / posted-cards history).
How to report an ad: Every sponsored card has a Report link. Reports are reviewed within 24 hours; content that violates our Advertiser Policy is taken down.
Ad repository: For transparency, LyPinn maintains a repository of every sponsored placement served in the last 12 months at `https://lypinn.com/ads/repository`. The page is not indexed by search engines and is only referenced from this policy.
12. Contact
Email contact@lypinn.com with any privacy question, rights request, data-access request, or grievance under the IT Act 2000 / DPDP Act 2023. The Grievance Officer (Bhavik Patel) responds within seven days, and within the 30-day statutory window for formal grievances.
v1.1.19 — Trending Keywords surface & B2B partner sharing
Trending Keywords surface. The LyPinn homepage and a new internal Trending dashboard publish an aggregate cloud of the most-saved Notify Me keywords across the platform — at three scopes: global, per-country (ISO-3166 alpha-2), and within ad-hoc 3 km neighbourhoods. Each keyword is subject to a strict k-anonymity floor of 3 distinct users before it can appear on any surface; no personal name or single user's private keyword can ever surface as 'trending'. The score is a simple weighted popularity count — `unique_users + 0.3 × card_matches` — over a rolling 7-day window. The list never carries user IDs, card IDs, or coordinates.
IP-based city label on lypinn.com. The public-website trending cloud derives a coarse city name from the visitor's IP address via the same `ip-api.com` provider already disclosed for abuse detection. The IP itself is never written to our database; only the city/country label is used, and only to caption the cloud (e.g. 'Trending in Ahmedabad'). No geolocation prompt is shown to website visitors.
B2B Integrations API. A new `/api/v1/trending` endpoint exposes the same aggregate trending list to vetted partner businesses under a per-key rate limit. API keys are issued manually after a partner emails `developer@lypinn.com` — there is no self-serve issuance and no SDK. Partners only see the same aggregate, k-anonymised feed every other surface uses; the API never exposes user identifiers, card identifiers, exact coordinates, or any field that could re-identify a person. Partners are bound by the LyPinn Business Terms § 9 (Partner API access) which restricts onward sharing.
Your rights under the EU / UK GDPR (users in the EEA and United Kingdom)
If you access LyPinn from the European Economic Area, the United Kingdom, or Switzerland, Bhavik Patel acts as the Data Controller and processes your personal data under the following Article 6 GDPR lawful bases:
| Purpose | Lawful basis | |---|---| | Delivering the core service (accounts, cards, connect, NotifyMe, GNote, NLocal) | Art. 6(1)(b) — performance of a contract with you | | Anti-abuse (reCAPTCHA, Turnstile, rate limits, moderation) | Art. 6(1)(f) — our legitimate interests in a safe platform | | Sponsored-content matching within 3 km, and impression / click analytics | Art. 6(1)(a) — your consent, revocable in Settings → Ads & sponsored content | | Compliance with legal obligations (IT Rules 2021 record-keeping, law-enforcement responses) | Art. 6(1)(c) |
As a Data Subject you have the right to (a) access the personal data we hold about you, (b) rectify inaccuracies, (c) erase your data ("right to be forgotten"), (d) restrict processing pending a dispute, (e) portability of your personal data in a structured, machine-readable format, (f) object to processing based on our legitimate interests, (g) withdraw consent at any time, and (h) not be subject to automated decision-making with legal effect. Exercise any right by emailing `grievance@lypinn.com`; we will respond within one month of a valid request (extendable by two further months for complex cases per Art. 12(3) GDPR).
Cross-border transfers. LyPinn's servers and staff are located in India. Where your personal data leaves the EEA / UK to reach Bhavik Patel in India, the transfer relies on the European Commission's Standard Contractual Clauses (2021/914, Module Two: Controller-to-Processor) or the UK Addendum issued by the ICO, and additional organisational safeguards including TLS 1.3 in transit and access controls at rest.
The following sub-processors handle limited categories of your personal data on LyPinn's behalf. Each has executed the EU Standard Contractual Clauses with LyPinn, either through their publicly available Data Processing Addendum (DPA) or a signed side-letter. You can inspect the full text of the clauses at each provider's DPA URL below, or request a consolidated PDF pack from the Grievance Officer:
- MongoDB Atlas (primary database at rest) — DPA + SCCs: `https://www.mongodb.com/legal/dpa`
- Google Firebase (push notifications, crash telemetry) — DPA + SCCs: `https://cloud.google.com/terms/data-processing-addendum`
- Twilio SendGrid (transactional email delivery) — DPA + SCCs: `https://www.twilio.com/legal/data-protection-addendum`
- Stripe Payments Europe, Ltd. (payment processing, only if you make a purchase) — DPA + SCCs: `https://stripe.com/legal/dpa`
- Apple Inc. (App Store distribution, sign-in with Apple) — DPA baked into the Apple Developer Program Licence Agreement.
- Google LLC (Google Play distribution, Sign-in with Google) — DPA baked into the Play Developer Distribution Agreement.
- Emergent Labs (application hosting on Kubernetes) — DPA + SCCs available via `support@emergentagent.com`.
- Emergent Universal LLM Key (routing to OpenAI, Anthropic, Google Gemini for AI-generated text and images, only when you trigger a generation) — sub-processors listed at `https://emergent.sh/legal/subprocessors`; SCCs flow through the Emergent Labs DPA above.
We keep the executed copies of every DPA / SCC on file. To request the countersigned versions (commercial terms redacted), write to `grievance@lypinn.com` with the subject *"SCC request — [your registered email]"*. We respond within one month of a valid request per Art. 12(3) GDPR.
Supervisory authority. You have the right to lodge a complaint with your local supervisory authority — for example the Data Protection Commission (Ireland) if you use LyPinn from Ireland, the ICO if from the United Kingdom, CNIL if from France, the BfDI if from Germany, or the equivalent authority in your Member State.
EU representative. As required by Art. 27 GDPR for controllers established outside the EU, Bhavik Patel will appoint a written-mandated representative in the Union before commencing regular, monitored processing of EU-resident personal data at scale. Until then, EU residents should raise all data-protection queries to `grievance@lypinn.com`.
Your rights under the California CCPA / CPRA (residents of California)
If you are a California resident, Bhavik Patel is a Business for CCPA / CPRA purposes and you enjoy the following rights over the personal information (PI) we collect about you:
1. Right to know — categories and specific pieces of PI collected, sources, purposes, and categories of recipients. 2. Right to delete — deletion of PI subject to statutory exemptions (fraud prevention, ongoing legal obligations). 3. Right to correct — inaccuracies in PI we hold. 4. Right to opt out of 'sale' or 'sharing' — LyPinn does not sell your personal information for money and does not share it for cross-context behavioural advertising with any third party. Our sponsored content is matched entirely in-app on aggregate signals (coarse location, category preferences, on-device NotifyMe keywords). There is therefore no "Do Not Sell / Share My Personal Information" mechanism to enable — because it is already the default state. 5. Right to limit use of Sensitive Personal Information — we do not use SPI for any purpose beyond what is necessary to deliver the service. 6. Right to non-discrimination — we will never deny service, charge a different price, or provide a different level of quality because you exercised a CCPA right.
Global Privacy Control (GPC). LyPinn's web application honours the Global Privacy Control browser signal as a valid opt-out request; if your browser sends GPC, our servers treat that session as "do-not-sell / do-not-share" for the duration of the session.
How to exercise your California rights. Email `grievance@lypinn.com` with the phrase "California request" in the subject and the specific right you wish to exercise. We will verify your identity by matching two data points already on file and respond within 45 days (extendable once by another 45 days for complex cases).
Twelve-month look-back. Upon a verified "right to know" request, we will provide the categories of PI collected, sold (none), shared (none), and disclosed for a business purpose during the twelve months preceding the request.
Data retention
We retain personal data only for as long as necessary to deliver the service, defend legal claims, or comply with law. Concretely:
| Data | Retention | |---|---| | Account credentials (email, password hash) | Until you delete your account, then removed within 30 days | | Cards you post | 24 hours from posting (auto-expiring TTL index on MongoDB) | | GNotes (including voice notes) | 24 hours from send | | Connect messages | 90 days from last activity in the thread | | NotifyMe keywords | Until you remove them or delete your account | | Sponsor-content impression logs (anonymised device_id + country + platform only) | 12 months (auto-TTL) | | Consent ledger rows | Retained for the life of the account + 3 years (limitation-period defence) | | Audit / access logs | 12 months | | Legal-hold data (subpoena, active dispute) | As required by the court order, then purged |
Third-party sub-processors
The following sub-processors handle personal data on LyPinn LLP's behalf. Each is bound by a written data-processing agreement that mirrors Art. 28 GDPR / DPDPA § 8(5) obligations:
| Sub-processor | Purpose | Region | |---|---|---| | MongoDB Atlas | Primary database (accounts, cards, GNotes, consent ledger) | Asia-Pacific | | Google Firebase Cloud Messaging | Push-notification delivery to Android + iOS | Global (Google) | | Apple Push Notification service | Push-notification delivery to iOS | Global (Apple) | | SendGrid (Twilio) | Transactional email (verification, grievance replies, licence-expiry reminders) | United States with EU sub-processing available | | Cloudflare (Turnstile) | Bot / abuse detection at auth endpoints | Global edge network | | Google reCAPTCHA v2 | Bot detection on auth + card-drop endpoints | Global (Google) | | Google Sign-In · Apple Sign In · Facebook Login | OAuth identity for optional social sign-in | Global | | Stripe (activation planned) | Payments for sponsored-ad purchases (advertisers only, not users) | Global |
We do not use any third-party advertising SDK. No IDFA or GAID is collected. Sponsored content is matched entirely in-app by LyPinn's own servers.
How to request your ad viewing history
LyPinn keeps a per-user log of every sponsored card you were shown, together with any taps or messages you sent to the sponsor. This log is used only to (a) cap how often the same ad is repeated to you (frequency cap), (b) prevent abusive sponsors from spamming a device, and (c) power the analytics the sponsor sees, which never contains your identity — only anonymised device / platform counts.
Your right to see this log. You can request a full copy of your own ad viewing history (up to the last 12 months) at any time. It will be delivered as a CSV containing one row per impression, click, or connect-message, with the ad title, sponsor name, timestamp, and device family (phone / tablet / web). We do not share this log with the sponsor.
How to request it. Email `grievance@lypinn.com` from your registered address with the subject *"Ad viewing history request"*. We verify your identity by matching two data points already on file and reply within 30 days with the CSV attached (encrypted zip if the file exceeds 5 MB). This request is free of charge and can be repeated once every 90 days. If you would like the log deleted after export, mention *"and please delete after export"* in the same email and we will drop the corresponding `ad_impressions` / `ad_clicks` / `ads_connect_requests` rows for your account.
Automatic retention. Impression rows are auto-deleted after 24 hours (TTL index) unless you have specifically requested a longer retention for evidence in a dispute. Click and connect-message rows are retained for 90 days.
Age assurance (18+ only)
LyPinn is strictly for users aged 18 and older. We enforce this in two layers:
Layer 1 — Signup declaration. You must actively tick "I confirm I am 18 or older" on the sign-up form before an account is created. This declaration is time-stamped in our consent ledger. We do not collect your date of birth at sign-up — since v12.7.3 (Jan 2026) accepting our Terms & Conditions constitutes the binding 18+ declaration (Terms §2).
Layer 2 — Explicit Age Attestation. After signup you will be shown a dedicated Age Attestation notice — a separate legal document that appears in the same in-app modal as our Terms and Privacy Policy updates. To continue using LyPinn you must explicitly accept the attestation, which states that you are 18 or older, that the account is yours (not a child's), and that misrepresentation may be recorded for regulator or law-enforcement disclosure. When you accept, we store:
- A row in your consent ledger with slug `age_attestation`, the document version, the UTC acceptance timestamp, the platform (web/iOS/Android), and the acceptance IP.
- `age_gate_status = 'adult'` on your user record.
- `age_attested_at` (UTC timestamp) + `age_attestation_version` (the numeric version of the attestation doc you accepted).
This attestation is a legally stronger act than a checkbox — it is a separate, timestamped, version-stamped declaration in an immutable audit trail. We rely on it as our authoritative record that you are an adult. We do not ask for or store your exact date of birth at any point in this flow.
Grandfathering. Admins, sub-admins (Ads/Sponsor manager accounts), and the Apple App Review account are exempt from the attestation modal — those accounts operate LyPinn on our behalf under separate contractual terms and never appear on consumer surfaces where the 18+ gate applies.
If you decline or misrepresent your age: 1. Declining the attestation signs you out of the app. You may re-open the app and re-attempt later; without acceptance the account remains signed out. 2. If we later discover the account is used by a minor (community report, moderation review, or you self-declare during account deletion), we (a) block the account immediately, (b) revoke all sessions, (c) soft-hide every card / GNote / NLocal / connect the account has ever created, and (d) add the email address to a 6-month block list — re-signup with the same email during that window is refused with a pointer to `grievance@lypinn.com`.
How to appeal. If the block is a mistake, email `grievance@lypinn.com` from the same address you registered with. Include a scan or photo of a valid government-issued ID showing you are 18+ (Aadhaar, passport, driving licence — you may black out the ID number and photo; only DOB and name are checked). We reply within 30 days. If we clear the block, we delete the ID scan from our mailbox within 7 days of clearing and record only "appeal cleared on YYYY-MM-DD by <admin>" in your audit trail. See the next section for how we handle documents you email us in general.
How we handle documents you (or a business) email us
You may need to email us documents in a few situations:
- Age-appeal (see previous section)
- Business verification for an Ads/Sponsor agency account (GSTIN, PAN, Certificate of Incorporation, etc.)
- DPA / SCC counter-signature requests
- DSAR (data-subject access request) proof of identity
Storage location. Our shared grievance / support mailboxes (`grievance@lypinn.com`, `support@lypinn.com`, `dpo@lypinn.com`) live on Google Workspace, which is physically stored in Google's regional data centres. Google Workspace is a sub-processor covered by our DPA (see *Sub-processor list* above).
Cross-border transfer. If you're in the EU/EEA, UK, or another restricted-transfer region and you email us an attachment, that attachment may transit to and be stored on Google infrastructure outside your region. This transfer is covered by:
- Google Workspace's EU Standard Contractual Clauses (SCCs) in Google's DPA;
- LyPinn's own DPA countersignature (available on request via `dpo@lypinn.com`).
Precautions we take: 1. Redaction first. Please redact any field you do not need us to see. For age proof, redact the ID number and photo — only the DOB and name are needed. For GSTIN verification, we only need the GSTIN certificate PDF. 2. Purpose-locked review. Documents are read by exactly one reviewer, logged in the admin audit trail as "opened YYYY-MM-DD by <admin>", and never forwarded outside the `@lypinn.com` domain. 3. 7-day deletion post-verdict. Once we act on your document (approve / reject / clear a block), the mailbox attachment is deleted within 7 days. Only the verdict + timestamp + reviewer email is kept in the audit log. 4. Never used for marketing. Documents you send us for verification are never merged into our marketing / CRM database. 5. Encrypted at rest. Google Workspace encrypts mailbox contents at rest and in transit. Attachments larger than 5 MB should be sent as an encrypted zip; email `dpo@lypinn.com` for the passphrase over a separate channel.
If you would prefer an in-region alternative (e.g. an EU-hosted upload URL for EU residents), email `dpo@lypinn.com` — we can generate a one-time upload link to our EU cell (see *Cross-border transfers* above) on request. This is a manual process today; automated in-region upload is on our roadmap for a future release.
Cookies & similar tracking (web only)
Our web application uses a minimal set of first-party cookies strictly necessary to deliver the service:
- Session / authentication cookies (log you in, remember your session)
- CSRF anti-forgery tokens
- A single consent cookie that remembers you accepted this cookie policy (avoids re-prompting)
- Cloudflare Turnstile and Google reCAPTCHA cookies (issued by those vendors on their own domains solely to distinguish humans from bots — not used for tracking or advertising)
We do not set any advertising cookies, analytics cookies, or tracking pixels. There is no cross-site profiling. Because our cookies are strictly-necessary or consent-recording, no Article 5(3) ePrivacy Directive opt-in banner is legally required for them — however we display an informational banner on your first visit that explains this and points you to this section. If you disable cookies entirely in your browser, the service will not work (you will be unable to stay signed in).
The LyPinn iOS and Android apps do not use cookies; they authenticate via OS-level secure storage (Capacitor Preferences → Keychain on iOS, EncryptedSharedPreferences on Android).
Your rights under India's Digital Personal Data Protection Act, 2023 (DPDPA)
LyPinn processes personal data of users in India in accordance with the Digital Personal Data Protection Act, 2023 (India), the DPDP Rules, 2026 (as notified from time to time), and the Information Technology Act, 2000. For the purposes of the DPDPA, LyPinn Technologies (operator of the LyPinn app and website) is a Data Fiduciary, and you — the person whose personal data is being processed — are a Data Principal.
§ 4 · Notice. Before we collect any personal data from you, we tell you (a) the categories of personal data collected (email, name, coarse location, device identifiers, cards you post, keywords you save to Notify Me, and — if you choose to post them — voice notes and images), (b) the purposes for which each category is used (delivering the service, matching cards to Notify Me keywords within 3 km, moderation, security, sponsored-content targeting only where permitted, and aggregate analytics), (c) how you can withdraw consent and erase your data at any time (Settings → Account → Delete account), and (d) how to raise a grievance (see § 8 below). This entire Privacy Policy constitutes the DPDPA § 4 notice.
§ 6 · Consent. By ticking the box on our sign-up screen — or by tapping through the equivalent consent screen when you sign in via Google, Apple, or Facebook for the first time — you provide free, specific, informed, unconditional, and unambiguous consent by clear affirmative action for LyPinn to process your personal data for the purposes listed in this Privacy Policy. Every acceptance is recorded in our internal consent-ledger (versioned + timestamped) — you can view your full acceptance history at Settings → Privacy → My consent history. You may withdraw consent at any time; withdrawal does not affect the lawfulness of processing carried out before withdrawal (DPDPA § 6(4)).
§ 7 · Duties of the Data Fiduciary. LyPinn implements reasonable security safeguards including TLS 1.3 in transit, at-rest encryption on the MongoDB Atlas cluster, per-user password hashing with bcrypt, one-time-signed refresh tokens, rate limits on all authentication endpoints, and periodic penetration testing. In the event of a personal-data breach we will notify both the Data Protection Board of India and affected Data Principals within the timelines specified by the Rules (currently 72 hours). Our servers primarily reside in the Asia-Pacific region; onward transfers, if any, are only to jurisdictions permitted under DPDPA § 16.
§ 8 · Grievance Officer, Nodal Officer & how to reach us. In accordance with DPDPA § 8(9) and Rules 3(2) & 4(2) of the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, Bhavik Patel has designated the following officers for India:
> Grievance Officer > Bhavik Patel > Bhavik Patel, Ahmedabad, Gujarat 380058, India > Email: `grievance@lypinn.com`
> Nodal Officer (24×7 law-enforcement contact) > Bhavik Patel > Bhavik Patel, Ahmedabad, Gujarat 380058, India > Email: `nodal@lypinn.com`
We acknowledge every grievance within 7 (seven) days of receipt and resolve valid grievances within 30 (thirty) days — both timelines are DPDPA + IT Rules compliant. If you are not satisfied with our response, you may escalate to the Data Protection Board of India per DPDPA Chapter V.
§ 11 · Your rights as a Data Principal. You have the right to:
1. Access — receive a summary of the personal data we hold about you and the purposes for which we process it. Ask at Settings → Account → Export my data, or email the Grievance Officer. 2. Correction & erasure — correct inaccuracies and delete your account (which erases all personal data linked to you except records we are legally required to retain — e.g. invoices under tax law, or logs subpoenaed by a court). Use Settings → Account → Delete account. 3. Grievance redressal — escalate any concern to the Grievance Officer above. 4. Nomination — nominate any individual, in the event of your death or incapacity, to exercise these rights on your behalf. Contact the Grievance Officer to lodge a nomination. 5. Withdraw consent — at any time, without affecting the lawfulness of prior processing.
§ 14 · Your duties as a Data Principal. You agree to (a) provide accurate information (no impersonation, no fictitious identities), (b) not submit false or frivolous grievances, (c) not attempt to re-identify anonymised data or otherwise compromise other users' privacy, and (d) comply with all applicable Indian laws when using LyPinn. Breach of these duties is treated as a violation of the Terms & Conditions and may attract penalties under DPDPA § 15.
Data of minors. LyPinn does not knowingly collect personal data of anyone under the age of 18. Every user must confirm they are 18+ before sign-up, and we reserve the right to terminate any account where we have reasonable grounds to believe the user is a minor (DPDPA § 9). If you believe a minor has registered, please email the Grievance Officer.
_Last updated: 12 July 2026 — v26 (added EU/UK GDPR, California CCPA/CPRA, data retention, sub-processors, cookies, and named Nodal Officer)._
Grievance Officer (India IT Rules 2021)
In compliance with the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, LyPinn has designated a Grievance Officer to address user complaints regarding content, privacy, and account actions.
To file a formal grievance: open the LyPinn app → Settings → Help & Support → Contact Support → select category "File a formal grievance (IT Rules 2021)" and submit your complaint. You will receive an acknowledgement within 72 hours and a resolution within 15 days.
*Grievance Officer contact details are maintained internally and provided in the acknowledgement email you will receive on filing.*
Last updated: 7/16/2026