Privacy Policy
This is the complete policy draft, not an approved collection agreement. Real collection remains closed. The maintainer has identified the operator as Lapiny LLC, based in New York; legal review and the remaining policy and operational requirements are still outstanding.
The initial 90-day completed-application limit, seven-day backup limit, private manual photo review, and waitlist/escalation-only opening have received scoped approval. That does not approve this draft’s other provisions or establish that collection is live.
- Status: Draft — not approved or published for real collection
- Owners: Founders, with appropriate legal review
- Last reviewed: 2026-09-27
- Proposed version:
2026-09-27-intake-privacy-draft-3 - Proposed destination:
https://lapiny.app/privacy— availability and bytes not verified
The maintainer supplied the operator identity and primary reviewer in P-071. Remaining review blockers include appropriate intake-policy legal review, public notice-address requirements, actual processor configuration, retention enforcement, screening coverage and the lost-session request-verification procedure. This text proposes the intended collection-only policy. It must not be relabeled approved merely because a site can display it.
Who operates this service
Lapiny's application service is operated by Lapiny LLC, based in New York. Contact the operator about applications or privacy at lapiny.app@gmail.com. This notice covers application collection and private review, not a member account, dating profile, payment, discovery, chat or the future iPhone experience.
What the application collects
When collection opens under this notice, the application asks for first name, date of birth and adult confirmation, an unverified contact email, NYC neighborhood area, gender identity, the genders and adult age range you want to date, preferred distance, relationship intention/style, self-declared activities, two recent photos, and an answer of up to 300 characters. Instagram and an invitation code are optional. We also record the agreement versions, submission time and application receipt.
The service processes request times, safe request/error identifiers and a trusted network address where needed to protect the flow against abuse. The proposed application controls use the address transiently and retain only short-lived keyed quota representations, not a location history or raw addresses in ordinary logs. The actual hosting providers' connection/security metadata and retention must be confirmed before publication; this notice does not assume their defaults match ours.
The neighborhood list uses approximate NYC neighborhood areas, not your street address or precise location. This application does not collect raw Apple Health data, workout routes, GPS coordinates, phone/selfie verification or payment details. Self-declared activities are not an activity-verification result or athletic score.
Your application, photos, dating preferences, answer and optional Instagram are private admissions information. They are not public profiles and are not published to other applicants or members. Do not upload photos of identifiable minors or information you do not have permission to submit.
Why the information is used
We use it to assess adult eligibility, NYC market fit, authentic adult dating intent, application completeness and safety, and to operate a fair private review queue. An authorized founder may record a scoring-free checklist, reason, minimal factual note and review history. We do not rank attractiveness, bodies, wealth, follower counts or athletic performance. A valid invitation affects priority, not suitability.
We also use limited information to prevent abuse, protect access, handle verified privacy requests, demonstrate authorized actions and satisfy specifically applicable preservation requirements. Application and health information are not used for advertising; we do not sell application information or reuse photos to train models.
Session access and the receipt
The service uses an essential browser session cookie and request protections. The website holds its upstream access credential privately on the server; it is not placed in page links or ordinary browser storage. Unsent form entries remain in page memory and are lost when you leave or reload.
The proposed original application session lasts 30 minutes and cannot be renewed. Successful submission receives an on-screen receipt; no confirmation or automated outcome email is promised. Your contact email is unverified information, not an account or proof that you control a mailbox. Entering or later verifying the same email cannot recover, merge or take over an application.
While the original session remains valid, you can download your own application data or request deletion. These controls remain available if new collection is paused. Ending or losing the session ends access; it does not delete a submitted application. A receipt ID is a reference, not a password or access credential.
Private review and service providers
Only individually authenticated and authorized reviewers may access the application and its private images. Access and actions are logged without copying application content into ordinary logs. The approved initial review model is manual; actual reviewer coverage and system readiness still need verification. Images are not sent to an automated image-analysis provider or used for automated biometric matching.
The selected hosting providers are Render for API processing and required background tasks, Supabase for private database storage and founder identity, and Vercel for the application website and server-side gateway. Google/Gmail handles messages you choose to send to the support address. The operator must confirm the actual provider contracts, configured processing locations and provider metadata retention before this notice is approved. These names are not evidence that private production services or founder access are already configured. Application photos remain private database contents in this initial design; selecting Supabase does not make them publicly accessible or authorize an additional image-analysis service.
Providers may process only what is needed for their assigned service under the operator's reviewed arrangements. We do not send application photos, dating preferences or private answers to ordinary support email, analytics or advertising tools. Requests from public authorities and emergency disclosures require the reviewed, applicable legal process; this notice grants no general disclosure right.
Proposed retention periods
P-069 approves the 90-day completed-application limit and seven-day backup limit; P-074 adds the narrow journal-only provider snapshot exception below. Other periods, including live deletion-marker retention, remain proposals. None is a claim of verified hosted enforcement until release evidence exists:
- Unsubmitted contact data and uploaded photos: erase within 24 hours after the original session expires. Expiry is not a promise of instant physical removal.
- Submitted application, attached photos and detailed review data: retain for no more than 90 days from submission, unless you request authorized deletion sooner or a specifically documented legal/safety preservation requirement applies. Later review does not silently restart that period.
- Authorized deletion: end application access immediately when accepted and target active-data erasure within 24 hours. A deletion acknowledgement does not mean every backup has already been physically erased.
- Encrypted application/database backups, including photos and email addresses: retain for no more than seven days. Deleted records stay inaccessible and must be removed before a restored copy can serve the application.
- A separate deletion journal protects against accidentally restoring deleted applications. It contains only internal applicant/event IDs, timestamps and integrity/order information, not application fields, photos, email addresses or credentials. These IDs can be linked to internal records and are restricted, not anonymous. Render's encrypted snapshots of this journal may remain longer than seven days; Render does not publish a maximum. This exception does not extend application backups or approve indefinite retention of the live journal.
- Minimal action/deletion evidence: 180 days; sensitive-access records: 30 days; deletion markers used to protect restores: 90 days after deletion. These records exclude photos, application fields, full checklists and free-text review notes.
- Keyed abuse records and expired session secrets: cleanup within 24 hours under their limited purpose; ordinary payload-free service logs: seven days.
- Privacy-case correspondence: 30 days after closure. Prefer non-recorded verification; any specifically approved temporary proof is erased within 24 hours after assessment.
A preservation exception is limited to the necessary information, authorized purpose and reviewed period. It is not indefinite retention of every application. We must verify the actual backup-expiry behavior before publishing a physical deletion promise that the hosting services cannot meet.
Privacy requests after session expiry
Contact lapiny.app@gmail.com. An initial request should not include passwords, authentication tokens, identity documents or private photos. We can acknowledge the request without confirming whether the address has an application.
We must verify the request proportionately before disclosing or erasing a selected application. Email control, a receipt ID, a matching birth date or other application answers alone do not establish ownership. Where needed, the approved procedure uses a separate secure channel, not ordinary email, and requests the least additional evidence appropriate to the request. If ownership is uncertain, we provide neutral guidance and escalate rather than exposing another person's data.
Before publication, the operator must approve and implement the exact verification method and legally appropriate response process. A verified privacy case may fulfill a specific export/deletion request; it does not restore the expired application session, create an account or enable email recovery. Applicable privacy rights are not waived by this draft or by the session's time limit.
Adults, safety and changes
Lapiny applications are for adults aged 18 and older in New York City. Report an underage or serious safety concern to the contact above without sending sensitive evidence in the initial message. The service is not an emergency-response service.
Before materially changing collection or use, the operator must review and publish an accurate updated notice and obtain any required new acknowledgement. Agreement records identify the version presented; they are not permission for undisclosed new uses. See the draft terms and draft member rules.