Legal
Effective date: 18 July 2026 · Last updated: 18 July 2026
ILYAL LLC ("ILYAL", "we", "us", "our") operates the ILYAL mobile application and the websites at ily.al and ilyal.app (the "Service").
This policy explains what personal data we collect, why, who we share it with, how long we keep it, and what rights you have.
ILYAL LLC is the data controller for personal data processed through the Service.
ILYAL is a game for couples. Two people link their accounts and share a small amount of content with each other every day.
The most important things to understand:
The Service is for adults. You must be 18 or older to use ILYAL. We do not knowingly collect personal data from anyone under 18. If we discover that a user is under 18, we will delete their account and associated data.
If you believe a minor is using the Service, contact legal@ilyal.app.
| Data | Purpose |
|---|---|
| Name or display name | Identifying you to your partner |
| Email address | Account creation, security notices, support |
| Profile photo (optional) | Displaying you in the app |
| Authentication identifier from LINE, Apple, or Google | Signing you in |
| Daily messages (text) | Delivering them to your partner |
| Daily photos | Delivering them to your partner and preserving shared history |
| Relationship details you choose to provide, such as start date, love language, or answers about your partner | Powering gameplay features including trivia and tasks |
| Support correspondence | Responding to you |
| Data | Purpose |
|---|---|
| Tap times, win/loss records, response speed | Operating the game |
| Streak length and history | Operating the game |
| Point balances, vouchers, mystery box activity | Operating the game economy |
| Couple link and unlink events, with timestamps | Operating the Couple Account; understanding retention |
| Purchase and subscription status | Providing paid features |
| App open times and feature usage | Understanding how the Service is used and improving it |
| Data | Purpose |
|---|---|
| Device model, operating system version, app version | Compatibility, support, and debugging |
| Device language and region | Localisation and pricing |
| Approximate location derived from IP address | Security, fraud prevention, regional settings |
| Push notification token | Delivering notifications |
| Crash reports and diagnostic logs | Finding and fixing faults |
| Analytics events | Understanding aggregate usage patterns |
Where the GDPR, UK GDPR, or Thailand's Personal Data Protection Act applies to you, we rely on the following bases:
| Purpose | Legal basis |
|---|---|
| Creating and operating your account | Performance of a contract |
| Delivering messages and photos to your partner | Performance of a contract |
| Operating gameplay, streaks, points, and vouchers | Performance of a contract |
| Processing purchases and subscriptions | Performance of a contract |
| Sending gameplay push notifications | Performance of a contract |
| Retaining content after unlink for possible reconciliation | Your consent, given at the point of unlink (see Section 8) |
| Analytics and product improvement | Legitimate interests, or consent where required by local law |
| Crash reporting and security | Legitimate interests in operating a functioning, secure service |
| Preventing cheating, fraud, and abuse | Legitimate interests in protecting users and the Service |
| Responding to legal requests | Legal obligation |
Where we rely on legitimate interests, we have considered the effect on you and believe the processing is proportionate. You may object, see Section 10.
Where we rely on consent, you may withdraw it at any time. Withdrawal does not affect processing carried out before withdrawal.
This is the part of the Service with the most significant privacy implications, so we set it out plainly.
When you link with a partner, they can see:
They cannot see:
Content you send to your partner is stored on our systems and remains available to them while you are linked. You cannot retract a message or photo from your partner's view retroactively in all cases, though you may delete content you sent, see Section 8.
Think before you send. Photos and messages sent in a relationship may outlast the relationship.
We do not sell personal data. We do not share it for advertising. We do not disclose it to data brokers.
We share data with service providers who process it on our behalf under contract:
| Provider | Role | Location |
|---|---|---|
| Supabase (AWS infrastructure) | Database, authentication, file storage | Singapore (ap-southeast-1) |
| LINE Corporation | Sign-in, if you choose LINE | Japan / Thailand |
| Apple | Sign-in, app distribution, payment processing | United States |
| Sign-in, app distribution, payment processing, push delivery | United States | |
| Google (Firebase Cloud Messaging) | Delivering push notifications | United States |
| PostHog | Aggregate usage analysis | EU or US region |
| Sentry | Crash reporting and diagnostics | EU or US region |
| RevenueCat | Managing subscription entitlements | United States |
Each provider is bound by contract to process data only on our instructions and to maintain appropriate security. We will update this policy if we add or change providers.
Apple and Google process all payments. We never see or store your card details.
We may also disclose data where required by law, to enforce our Terms, to protect the rights or safety of any person, or in connection with a merger, acquisition, or sale of assets, in which case we will notify you and this policy will continue to apply until replaced.
The Service stores data primarily in Singapore (AWS ap-southeast-1). Our company is established in the United States. Some providers process data in the United States, Japan, or elsewhere.
If you are in the EEA or UK, your data may be transferred outside those areas. Where it is, we rely on:
If you are in Thailand, transfers outside Thailand are made in accordance with the PDPA, on the basis of appropriate safeguards or your consent.
You may request a copy of the safeguards we rely on by contacting legal@ilyal.app.
| Data | Retention period |
|---|---|
| Account data | While your account is active |
| Photos and messages you sent | While your account is active |
| Gameplay records (taps, streaks, points) | While your account is active |
| Purchase records | 7 years, for tax and accounting purposes |
| Crash logs and diagnostics | Up to 90 days |
| Analytics data | Up to 24 months, in aggregated or pseudonymised form where possible |
| Support correspondence | Up to 24 months after the matter is closed |
When you delete your account, your personal data is deleted within 30 days, subject to the reconciliation window in Section 8.3 and to any records we must keep by law.
Backups are overwritten on a rolling cycle and residual copies may persist for up to a further 30 days before being permanently removed.
You may delete photos and messages you sent at any time, whether or not you are still linked to your partner. Deletion is permanent.
Deleting content you sent does not delete content your partner sent to you.
When a couple unlinks:
If you choose to retain, we hold that content on the basis of your consent. You may withdraw that consent at any time and we will delete the content.
If you choose to delete, we delete it. Your partner will no longer be able to see it.
If you delete your account:
If you want immediate and irreversible deletion with no reconciliation window, tell us at legal@ilyal.app and we will action it.
Because ILYAL is a two-person system, your partner may send photos in which you appear. You did not send that content, but you are a person whose personal data it contains.
You may request removal of content in which you appear, even where your partner sent it.
Email legal@ilyal.app from the address associated with your account, or use the data-request process on our Support page, describing the content, a date or approximate date is usually enough.
If content depicts both of you and one objects to its retention, we will generally remove it. We will normally give the other partner advance notice, so they may keep a personal copy on their own device before removal. We assess each case individually, balancing the rights of both people involved.
We aim to respond to all requests within 30 days.
Depending on where you live, you may have some or all of the following rights:
To exercise any of these, contact legal@ilyal.app. We will respond within 30 days. There is no charge, though we may decline manifestly unfounded or excessive requests.
We may need to verify your identity before acting.
You may complain to your national data protection authority. In the UK this is the Information Commissioner's Office (ico.org.uk).
You may complain to the Office of the Personal Data Protection Committee (PDPC). Under the PDPA you have rights of access, rectification, erasure, restriction, objection, and portability broadly equivalent to those listed above.
We do not sell or share personal information as those terms are defined under the CCPA/CPRA. You have rights to know, delete, correct, and to non-discrimination for exercising them.
We do not make decisions producing legal or similarly significant effects about you by automated means.
We protect your data using:
No system is completely secure. We cannot guarantee absolute security. If we become aware of a breach affecting your personal data, we will notify you and the relevant authorities where required by law, and within the timeframes those laws specify.
You are responsible for the security of the account you use to sign in, your LINE, Apple, or Google account.
Gameplay depends on push notifications. We collect a device token in order to deliver them.
You can disable notifications in your device settings at any time. Doing so will not delete your account but will make the game substantially harder to play.
We send:
We do not send marketing push notifications without your consent.
The websites at ily.al and ilyal.app are informational. We use only strictly necessary cookies and basic analytics.
If we introduce non-essential cookies, we will ask for your consent first where required.
We may update this policy. If a change is material, for example, a new category of data, a new purpose, or a new provider, we will notify you in the app or by email at least 14 days before it takes effect.
The "last updated" date at the top always reflects the current version.
We do not currently have a designated Data Protection Officer, as we are not required to appoint one. Privacy enquiries go to the address above and are handled by the company's founder.
Because someone has to say it first.