Lapiny

Privacy Policy

This is the complete policy draft, not an approved collection agreement. Real collection remains closed. The maintainer has identified the operator as Lapiny LLC, based in New York; legal review and the remaining policy and operational requirements are still outstanding.

The initial 90-day completed-application limit, seven-day backup limit, private manual photo review, and waitlist/escalation-only opening have received scoped approval. That does not approve this draft’s other provisions or establish that collection is live.

The maintainer supplied the operator identity and primary reviewer in P-071. Remaining review blockers include appropriate intake-policy legal review, public notice-address requirements, actual processor configuration, retention enforcement, screening coverage and the lost-session request-verification procedure. This text proposes the intended collection-only policy. It must not be relabeled approved merely because a site can display it.

Who operates this service

Lapiny's application service is operated by Lapiny LLC, based in New York. Contact the operator about applications or privacy at lapiny.app@gmail.com. This notice covers application collection and private review, not a member account, dating profile, payment, discovery, chat or the future iPhone experience.

What the application collects

When collection opens under this notice, the application asks for first name, date of birth and adult confirmation, an unverified contact email, NYC neighborhood area, gender identity, the genders and adult age range you want to date, preferred distance, relationship intention/style, self-declared activities, two recent photos, and an answer of up to 300 characters. Instagram and an invitation code are optional. We also record the agreement versions, submission time and application receipt.

The service processes request times, safe request/error identifiers and a trusted network address where needed to protect the flow against abuse. The proposed application controls use the address transiently and retain only short-lived keyed quota representations, not a location history or raw addresses in ordinary logs. The actual hosting providers' connection/security metadata and retention must be confirmed before publication; this notice does not assume their defaults match ours.

The neighborhood list uses approximate NYC neighborhood areas, not your street address or precise location. This application does not collect raw Apple Health data, workout routes, GPS coordinates, phone/selfie verification or payment details. Self-declared activities are not an activity-verification result or athletic score.

Your application, photos, dating preferences, answer and optional Instagram are private admissions information. They are not public profiles and are not published to other applicants or members. Do not upload photos of identifiable minors or information you do not have permission to submit.

Why the information is used

We use it to assess adult eligibility, NYC market fit, authentic adult dating intent, application completeness and safety, and to operate a fair private review queue. An authorized founder may record a scoring-free checklist, reason, minimal factual note and review history. We do not rank attractiveness, bodies, wealth, follower counts or athletic performance. A valid invitation affects priority, not suitability.

We also use limited information to prevent abuse, protect access, handle verified privacy requests, demonstrate authorized actions and satisfy specifically applicable preservation requirements. Application and health information are not used for advertising; we do not sell application information or reuse photos to train models.

Session access and the receipt

The service uses an essential browser session cookie and request protections. The website holds its upstream access credential privately on the server; it is not placed in page links or ordinary browser storage. Unsent form entries remain in page memory and are lost when you leave or reload.

The proposed original application session lasts 30 minutes and cannot be renewed. Successful submission receives an on-screen receipt; no confirmation or automated outcome email is promised. Your contact email is unverified information, not an account or proof that you control a mailbox. Entering or later verifying the same email cannot recover, merge or take over an application.

While the original session remains valid, you can download your own application data or request deletion. These controls remain available if new collection is paused. Ending or losing the session ends access; it does not delete a submitted application. A receipt ID is a reference, not a password or access credential.

Private review and service providers

Only individually authenticated and authorized reviewers may access the application and its private images. Access and actions are logged without copying application content into ordinary logs. The approved initial review model is manual; actual reviewer coverage and system readiness still need verification. Images are not sent to an automated image-analysis provider or used for automated biometric matching.

The selected hosting providers are Render for API processing and required background tasks, Supabase for private database storage and founder identity, and Vercel for the application website and server-side gateway. Google/Gmail handles messages you choose to send to the support address. The operator must confirm the actual provider contracts, configured processing locations and provider metadata retention before this notice is approved. These names are not evidence that private production services or founder access are already configured. Application photos remain private database contents in this initial design; selecting Supabase does not make them publicly accessible or authorize an additional image-analysis service.

Providers may process only what is needed for their assigned service under the operator's reviewed arrangements. We do not send application photos, dating preferences or private answers to ordinary support email, analytics or advertising tools. Requests from public authorities and emergency disclosures require the reviewed, applicable legal process; this notice grants no general disclosure right.

Proposed retention periods

P-069 approves the 90-day completed-application limit and seven-day backup limit; P-074 adds the narrow journal-only provider snapshot exception below. Other periods, including live deletion-marker retention, remain proposals. None is a claim of verified hosted enforcement until release evidence exists:

A preservation exception is limited to the necessary information, authorized purpose and reviewed period. It is not indefinite retention of every application. We must verify the actual backup-expiry behavior before publishing a physical deletion promise that the hosting services cannot meet.

Privacy requests after session expiry

Contact lapiny.app@gmail.com. An initial request should not include passwords, authentication tokens, identity documents or private photos. We can acknowledge the request without confirming whether the address has an application.

We must verify the request proportionately before disclosing or erasing a selected application. Email control, a receipt ID, a matching birth date or other application answers alone do not establish ownership. Where needed, the approved procedure uses a separate secure channel, not ordinary email, and requests the least additional evidence appropriate to the request. If ownership is uncertain, we provide neutral guidance and escalate rather than exposing another person's data.

Before publication, the operator must approve and implement the exact verification method and legally appropriate response process. A verified privacy case may fulfill a specific export/deletion request; it does not restore the expired application session, create an account or enable email recovery. Applicable privacy rights are not waived by this draft or by the session's time limit.

Adults, safety and changes

Lapiny applications are for adults aged 18 and older in New York City. Report an underage or serious safety concern to the contact above without sending sensitive evidence in the initial message. The service is not an emergency-response service.

Before materially changing collection or use, the operator must review and publish an accurate updated notice and obtain any required new acknowledgement. Agreement records identify the version presented; they are not permission for undisclosed new uses. See the draft terms and draft member rules.