Lifolo Privacy Policy
Effective Date: July 25, 2026
Last Updated: July 25, 2026
1. Introduction
Lifolo is a mobile application operated by Selin Şeker. Throughout this Privacy Policy, "Lifolo," "we," "us," and "our" refer to the Lifolo application operated by Selin Şeker.
This Privacy Policy explains how we collect, use, store, share, retain, and delete information in connection with the Lifolo mobile application (the "Service"). It is designed to describe our actual practices as implemented, not a generic or aspirational statement of policy.
This Privacy Policy should be read together with our Terms of Service, which governs your use of the Service more broadly.
2. Who We Are
For any question about this Privacy Policy or about your personal data, contact us at support@lifolo.app.
3. Scope
This Privacy Policy applies to the Lifolo mobile application and the backend services that support it. It applies to registered users of the Service. It does not apply to third-party websites, applications, or services that Lifolo may link to or integrate with, which are governed by their own privacy policies.
4. Information We Collect
We collect information in three ways:
-
Information you provide directly — when you register, build your profile, create or join an event, send a message, or submit a report.
-
Information generated through your use of the Service — records created as a result of your activity, such as your event participation history, your blocks, and your saved events.
-
Limited technical information — collected automatically to operate the Service reliably and securely, such as a push notification token and basic device identifiers used for that purpose.
We do not collect information from you through any source other than the Service itself. We do not purchase or acquire personal information about you from third-party data brokers.
5. Account and Profile Information
When you register and set up your profile, we collect:
-
Email address — used for account creation, sign-in, email verification, and password reset. Your email address is managed by our authentication provider and is not displayed to other users.
-
Password — stored only in encrypted/hashed form by our authentication provider; Lifolo does not store or have access to your plaintext password.
-
Full name — displayed to other users as described in Section 12 of our Terms of Service.
-
Age — a self-declared whole number (we do not collect your date of birth). Age is used to confirm you meet our 18+ eligibility requirement and to enforce any age range an event organizer has set for their event.
-
Gender — one of a limited set of options. Gender is used to enforce optional gender-based eligibility criteria that an event organizer may set for their event (see Section 12); it is not displayed in your public profile.
-
City — the city you select as your primary location, used for event discovery and display.
-
Biography (optional) — free text you may add to your profile.
-
Interests — a set of interest categories you select, used to personalize event discovery.
-
Profile photo (optional but required to complete onboarding) — an image you upload, stored in our file storage as described in Section 11.
We also maintain two counters on your profile — the number of events you have created and the number you have joined — which are derived automatically from your activity and are not separately provided by you.
6. Event Information
When you create an event, we collect and store the information you provide: title, category, city, a location name and, where you select one, geographic coordinates, date and time, maximum number of participants, optional age and gender eligibility criteria, and an optional description.
Because Lifolo is an event discovery service, event details — including the event's location — are visible to other authenticated users of the Service so that they can discover and evaluate the event, not only to users who have joined it. This is a core part of how the Service functions and is described further in our Terms of Service.
When you join or leave an event, we record that action (which event, which user, and when) to operate participation, capacity, and eligibility features, and to display the participant list as described in Section 8.
7. Participant Lists
An event's full participant list (the names and photos of everyone who has joined) is visible to that event's organizer and to its other current participants. If you are not a participant of a given event and not its organizer, you can see the number of participants, but not their identities. If you leave an event, you lose access to its participant list going forward.
8. Chat Messages
Each event has an associated group chat, available to its organizer and current participants.
-
Who can access messages. Only the organizer and current participants of an event can read or send messages in its chat. If you leave the event, you lose access to that chat.
-
When the chat closes. The chat stops accepting new messages 24 hours after the event's scheduled start time.
-
How long messages exist. After the chat closes, we retain the messages sent in it for a limited additional period for safety, abuse-investigation, and service-integrity purposes, after which they are automatically and permanently deleted from our systems through a scheduled cleanup process. As of this Policy, our standard retention period following chat closure is 30 days, but we may adjust this period from time to time as our safety and moderation practices evolve, and this Policy does not guarantee that a specific message will remain available, or be deleted, on any particular date.
-
Effect of an open report. If a message, or the event or user it relates to, is the subject of an open report (a report that has not yet been reviewed or resolved), we retain the related messages beyond the standard period until that report is resolved, so that the content remains available for our review.
-
In-app "delete" and "clear" features. Features that let you clear a chat from your own view, or remove or mark your own message as deleted, change what is displayed to you or to other users. They do not necessarily remove the underlying message from our systems before the retention period above has elapsed, including for the safety and moderation purposes described above.
9. Reports
If you submit a report about another user, profile, or event, we collect the reason you select, any optional description you provide, and a reference to the reported user, event, and your own account as the reporter.
-
What is included. A report record includes the reason, your optional description, the identity of the reporter, and the identity of the reported user or event. It does not include a phone number or any information beyond what is described here and what our systems can derive from the report itself (for example, the reported event's own details).
-
Who reviews reports. Reports are reviewed by our team; the Service does not currently include an automated moderation decision system or a public-facing moderator dashboard. A notification containing the report's details is sent to our internal review address for manual review.
-
How report information is used. We use report information solely to evaluate and act on the report — for example, to review the reported content, decide on any moderation action, and, where relevant, retain associated chat messages under Section 8.
-
After account deletion. If you delete your account, reports you filed are deleted along with your account. If another user filed a report against you and later you delete your account, that report record is retained for our records, but the reference to your specific account is removed once your account no longer exists.
10. Blocking
When you block another user, we store a record of that block (which account blocked which). We use this record to enforce the effects of blocking described in our Terms of Service — restricting event visibility, event joining, and chat messaging between the two accounts. Blocking records are deleted if either account involved is deleted, or if you unblock the other user.
11. Uploaded Photos
Your profile photo is stored in our cloud file storage. When you replace your photo, we make a best effort to remove the previous file from storage, though this cleanup step is not guaranteed to succeed in every case (for example, due to a transient technical failure), and any file that fails to be removed at that time may persist until it is cleaned up, including upon account deletion as described in Section 19.
We do not run automated image analysis, facial recognition, or content-scanning technology on uploaded photos. Uploaded profile photos are, by the nature of the feature, accessible via their storage address to anyone who has that address, without requiring sign-in — we do not currently restrict profile photo access to authenticated users only.
12. Notifications
To send you push notifications, we store a push notification token issued by Apple's or Google's push notification service (delivered to us through Expo's push notification relay), together with your account, the platform (iOS or Android), and a device name value reported by your device's operating system. This device name is a human-readable label (for example, the name you have given your device), not a persistent hardware identifier, and we do not use it to track you across apps or after you uninstall Lifolo.
We use your push token to send notifications relevant to your activity — for example, new chat messages, someone joining your event, or updates to an event you have joined. You control whether the Service can send you notifications through your device's operating-system permission and, where available, in-app notification settings. Push tokens are removed when you sign out or delete your account, and a token is also disabled if the push provider reports that it is no longer valid (for example, after you uninstall the app).
13. Device Information
We collect the minimum device information necessary to deliver push notifications reliably, as described in Section 12 (platform and a device name value). We do not separately collect a persistent advertising identifier, and we do not use your device information for advertising or cross-app tracking.
Our infrastructure providers (described in Section 17) may automatically log limited technical information inherent to operating a networked service — such as IP address and request timestamps — as part of their own standard infrastructure logging and security practices, in the same way any backend service, database, or content-delivery system does. We do not separately collect, compile, or use this information for profiling or advertising purposes.
14. Location Information
Lifolo's use of location is limited and entirely device-side:
-
Foreground only. We request your device's location permission only while the app is in use ("when in use" / foreground permission). Lifolo does not request or use background location access.
-
Approximate, not precision-grade. When granted, we request a "balanced" accuracy reading from your device's operating system — sufficient to estimate distance to nearby events, not a high-precision GPS fix.
-
Used on your device only. Your device's coordinates are used locally on your device to calculate and display the approximate distance to events, and are cached briefly in your device's memory for that purpose. We do not transmit your personal device location to our servers or store it in our database.
-
Event location is separate. The location associated with an event is information the organizer chooses to enter when creating the event (a place name and, where selected, coordinates) — this is event content, described in Section 6, not your personal location.
-
City field. The "city" on your profile is a value you select yourself; it is not derived from device location.
If you deny or later revoke location permission, distance-to-event information will not be available to you, but you can continue to use the rest of the Service, including manually searching and browsing events by city.
15. Cookies and Similar Technologies
Lifolo is a native mobile application and does not use browser cookies. It does not currently use any web-based tracking pixel or similar browser technology. Certain third-party SDKs integrated into the app (described in Section 17) may use their own mobile-equivalent local identifiers or storage mechanisms as part of their standard operation (for example, to associate analytics or crash events with an install); we do not separately configure these for advertising purposes.
16. How We Use Information
We use the information described above to:
-
create and maintain your account, and authenticate you;
-
operate core features — event discovery, creation, participation, and eligibility rules; participant lists; group chat; saved events; blocking; and reporting;
-
send you push notifications you have not disabled;
-
investigate and act on reports, and take moderation action, including account suspension or termination, where warranted;
-
maintain the security and integrity of the Service, including detecting and preventing abuse;
-
diagnose and fix technical problems, through crash and error reporting as described in Section 17;
-
understand aggregate usage of app screens and key actions, through product analytics as described in Section 17;
-
comply with legal obligations and respond to lawful requests, as described in Section 21.
We do not use your information to serve third-party advertising, and we do not sell your personal information.
17. Sharing Information — Third-Party Service Providers
We share information with the following categories of service providers (processors) to the extent necessary for them to provide their service to us. We do not permit these providers to use your information for their own independent purposes, such as advertising.
| Provider | Purpose | Data involved |
|---|---|---|
| Supabase | Database, authentication, file storage, real-time messaging infrastructure, and serverless backend functions | Effectively all account, profile, event, chat, report, block, and notification-token data described in this Policy — Supabase is our core infrastructure provider |
| Firebase (Google) — Analytics and Crashlytics only | Product analytics and crash/error reporting | App usage events (screen names by route pattern, and a fixed set of event names — such as an event being created, joined, or a chat message being sent — identified only by opaque IDs, never message content); crash reports and a limited, fixed set of debugging context (screen, action, feature, error code); your Supabase account ID, to associate events/crashes with a user without using your email or other profile data. We do not use Firebase Authentication or Firebase's database (Firestore) — only Analytics and Crashlytics |
| Resend | Delivery of the email we send to our own internal review address when you submit a report | The content of the moderation notification email, which includes the report's reason, your optional description, and the identity of the reporter and reported user or event, as described in Section 9 |
| Google (Maps / Places) | Address search when creating an event, and displaying an event's location on a map | The search text you type while selecting a location, and the resulting place data (address, coordinates) |
| Expo (push notification relay) | Delivering push notifications to Apple's and Google's push services on our behalf | Your push token and the notification content described in Section 12 |
Supabase
Purpose
Database, authentication, file storage, real-time messaging infrastructure, and serverless backend functions
Data involved
Effectively all account, profile, event, chat, report, block, and notification-token data described in this Policy — Supabase is our core infrastructure provider
Firebase (Google) — Analytics and Crashlytics only
Purpose
Product analytics and crash/error reporting
Data involved
App usage events (screen names by route pattern, and a fixed set of event names — such as an event being created, joined, or a chat message being sent — identified only by opaque IDs, never message content); crash reports and a limited, fixed set of debugging context (screen, action, feature, error code); your Supabase account ID, to associate events/crashes with a user without using your email or other profile data. We do not use Firebase Authentication or Firebase's database (Firestore) — only Analytics and Crashlytics
Resend
Purpose
Delivery of the email we send to our own internal review address when you submit a report
Data involved
The content of the moderation notification email, which includes the report's reason, your optional description, and the identity of the reporter and reported user or event, as described in Section 9
Google (Maps / Places)
Purpose
Address search when creating an event, and displaying an event's location on a map
Data involved
The search text you type while selecting a location, and the resulting place data (address, coordinates)
Expo (push notification relay)
Purpose
Delivering push notifications to Apple's and Google's push services on our behalf
Data involved
Your push token and the notification content described in Section 12
We do not share your information with data brokers, and we do not sell your personal information to any third party.
We may also disclose information where required to comply with a legal obligation, to respond to a lawful request from a public authority, to enforce our Terms of Service, or to protect the rights, safety, or property of Lifolo, our users, or the public — for example, in response to a valid legal process, or where we reasonably believe disclosure is necessary to prevent harm.
18. International Data Transfers
Our service providers listed in Section 17 may process and store information on servers located outside Türkiye, including in the European Union, the United States, or other countries where those providers or their sub-processors operate infrastructure. Where we transfer personal data internationally, we rely on the safeguards made available by our providers (such as standard contractual clauses or equivalent mechanisms) to the extent required by applicable law, including KVKK's rules on transferring personal data abroad.
19. Data Retention
We retain information for as long as necessary for the purposes described in this Policy, and no longer, except where a longer period is required by law or is necessary to resolve disputes or enforce our agreements.
-
Account and profile data is retained for as long as your account exists, and is deleted upon account deletion as described below.
-
Event data you create is retained for as long as your account and the event exist, and is deleted if you cancel the event or delete your account.
-
Chat messages are retained until 24 hours after the related event's start time (when the chat closes), plus our standard additional retention period described in Section 8 (currently 30 days), unless an open report extends that period as described there.
-
Reports are retained for our internal records; a report you filed is deleted if you delete your account, while a report filed against you is retained (with your account reference removed) if you delete your account, as described in Section 9.
-
Push tokens are retained while your account is active and the token remains valid, and are removed on sign-out, on account deletion, or automatically when the push provider reports the token is no longer valid.
-
Account deletion. When you request deletion of your account, we begin processing that request immediately, and in the ordinary course, deletion completes shortly afterward. Deleting your account removes your profile, the events you created (including their participant lists and chat history, for all participants), your own event participations, the messages you sent across event chats, your saved events, your blocks, and your notification tokens. As described in our Terms of Service, some data may remain briefly where technically necessary to complete deletion across our systems, or longer where required by law or relevant to an open report or investigation involving your account.
20. Security
We use technical and organizational measures intended to protect your information, including encryption of data in transit, access controls limiting which systems and roles can read sensitive data, and a defined, limited set of fields permitted in our crash-reporting and analytics context data to reduce the risk of accidentally logging sensitive information.
No method of transmission or storage is completely secure, and we cannot guarantee absolute security of your information. You also play a role in protecting your account by keeping your password confidential and not sharing your login credentials with others.
21. Your Rights
Depending on your location, you may have rights under KVKK, the GDPR, or other applicable data protection law, which may include the right to:
-
be informed about how your personal data is processed (this Policy is intended to provide that information);
-
request access to the personal data we hold about you;
-
request correction of inaccurate or incomplete data (you can update most profile fields directly in the app);
-
request deletion of your personal data (you can delete your account directly in the app at any time, as described in Section 19);
-
object to or request restriction of certain processing, where applicable law provides for this;
-
request a copy of certain data in a portable format, where applicable law provides for this;
-
lodge a complaint with your local data protection authority — in Türkiye, the Personal Data Protection Authority (Kişisel Verilerin Korunması Kurumu).
You can exercise most of these rights directly within the app. For any request you cannot complete in-app, or to ask a question about your data, contact us at support@lifolo.app. We may need to verify your identity before acting on a request.
22. Children's Privacy
Lifolo is intended for users who are 18 years of age or older, and is not directed at, marketed to, or knowingly used by children. We do not knowingly collect personal information from anyone under 18. If we become aware that an account belongs to someone under 18, we will take steps to suspend or delete that account, as described in our Terms of Service.
23. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes to the Service or our data practices. If we make material changes, we will provide notice through the Service or by other reasonable means before the changes take effect. The "Last Updated" date at the top of this Policy indicates when it was last revised.
24. Contact
If you have questions about this Privacy Policy or how we handle your information, contact us at:
