Privacy policy
Effective date: Oct-01-2026 Version: 2026-10-01
This policy explains what Lovyza collects about you, why, how long it is kept, who it is shared with, and what you can do about it. It is written to be read, not skimmed past.
Lovyza is a dating and events app for adults in Kenya. You must be 18 or over to use it.
---
1. Who is responsible for your data
The data controller is:
Lovyza Technologies Ltd Nairobi, Kenya
Email: privacy@lovyza.co.ke Data protection contact: Lovyza
Our obligations come from the Data Protection Act, 2019 and the regulations made under it. If you are outside Kenya, your data is processed in Kenya and in the countries named in section 6.
---
2. What we collect
You give us
| What | When |
|---|---|
| Phone number | Sign-up. It is how you sign in and it is how we keep one account per person |
| Date of birth | Sign-up. We store the date and use it to confirm you are 18 or over and to show your age |
| Your name or the name you go by | Sign-up |
| Gender, and who you want to see | Sign-up |
| Photos | Profile creation and any time you edit your profile |
| What you are looking for — your intent, whether you want something serious, casual or to make friends | Profile creation |
| Profile detail you choose to add — bio, prompt answers, interests, height, education, occupation, languages, and lifestyle answers such as whether you smoke or drink | Any time. All of this is optional |
| Messages, and any photos or voice notes you send in them | When you use chat |
| A verification selfie | Only if you choose to get a verified badge. See section 4 |
| Reports you make about another person, and anything you write in them | When you report someone |
| Event details if you organise an event, and RSVPs and tickets if you attend one | When you use events |
| The phone number you pay from | When you buy a subscription, a boost or a ticket |
| Marketing preference | Sign-up, and you can change it whenever you like |
Your device gives us
| What | Detail |
|---|---|
| Approximate location | Only while the app is open and only if you allow it. See section 3 — it is deliberately imprecise |
| Camera and photo library access | Only when you are choosing or taking a photo. We do not browse your library |
| Microphone and camera during a call | Only during a call you have accepted |
| A push notification token | So we can tell you about a match, a message or an event |
We record automatically
- Your IP address and device information at the moment you accept our terms and this policy, together with the exact time and the version you accepted. This is evidence that consent was given, and it is the only thing we use it for.
- Sign-in activity — the devices with a live session, and when each was last used, so you can see them and sign them out.
- Who you liked and passed on, so you are not shown the same person twice.
- When you were last active, so the app can show people who are actually using it.
- Call records — who called whom, when, and for how long. See section 4.
- Server logs for security and fault-finding, kept briefly.
We do not collect
- We do not buy data about you from anyone.
- We do not read your contacts, your other apps, your SMS messages, or your call history.
- We do not track you across other apps or websites.
- We do not collect your precise location, ever — see the next section.
- We do not collect biometric data. We do not run face recognition or face matching on your photos.
- We never see or store your M-Pesa PIN, your card number, or your card's security code.
---
3. Location, and why it is imprecise on purpose
Location is the part of a dating app that can genuinely hurt you if it is done carelessly, so we made it imprecise before it reaches our database rather than after.
- We round your position to a grid of roughly 550 metres before we store it. Everyone inside the same cell is recorded at the same point. This is done as your location arrives, not when it is displayed, so a precise position is never written to our database or into any backup of it.
- Other users see a distance band, never a direction. "3 km away", with no bearing.
- We only read location while the app is open. Nothing is read in the background.
- You control it. You can leave it live, pin a neighbourhood instead of using your real one, or pause location entirely.
Rounding to a fixed grid rather than adding random noise matters: random noise averages out if someone measures you enough times, and a grid does not. This puts a floor under how precisely anyone can place you, however many measurements they collect.
If you join Circle
Circle is opt-in, and none of this applies unless you join it.
- Who sees you. While you are in Circle, other members who have also joined, and who are within about 25 km of you, can see your profile card — the same card the deck shows, with your distance as a band rather than a place. People you have blocked, or who have blocked you, never see you, and your gender preferences apply both ways.
- What we record. When you joined, and the requests you send and receive, including whether each was accepted or declined. A declined request is kept so that it cannot be sent to you again.
- How to stop. Leave Circle at any time in the app. You stop appearing immediately, and any requests you sent that are still waiting are withdrawn.
---
4. Photos, verification, calls and messages
Photos
Every photo is checked before anyone else can see it: we compare a fingerprint of the image against fingerprints of images already on Lovyza, to catch profiles built from someone else's pictures. A photo that matches is held for a person on our team to review. We do not currently scan photos automatically for nudity or other content our guidelines do not allow — those reach us through reports, and a person reviews every report.
The fingerprint is a short mathematical summary. It cannot be turned back into your photograph. We keep fingerprints after an account is deleted, because catfishing works by reusing the same stolen pictures and a fingerprint store that is cleared out alongside the account it belonged to catches nobody.
Verification, and what we deliberately do not do
If you want a verified badge, we ask you for a live selfie in a pose we choose at the moment you ask, and a person on our team compares it with your profile photos.
- We do not use face recognition or face matching, and we do not send your selfie to any biometric service. Under the Data Protection Act, biometric data is sensitive personal data with its own obligations, and we chose not to collect it.
- The selfie is shown to nobody but the reviewer, through a link that expires within minutes.
- It is deleted as soon as the decision is made, whether you are approved or not.
A verified badge means a person looked. That is all it claims.
Calls
Video and voice calls are only possible inside a match, once you have both messaged and both accepted. The audio and video travel between the two of you and no call media is recorded or stored by us — not the video, not the audio, not a still frame.
What we do keep is the record that a call happened: who called whom, when, and how long it lasted. We keep it because a reported call is part of a safety record and because we need it to bill and to diagnose faults.
Messages
We store your messages so that we can deliver them and so that you and the person you are talking to can read them again. Messages are screened automatically for abuse and for common scam patterns.
We do not read your conversations for advertising or profiling. A person on our team only reads a specific conversation when it is reported to us, or when we are legally required to.
---
5. Why we are allowed to use your data
Under section 30 of the Data Protection Act we must have a lawful basis for everything we do with your data. Ours are:
| What we do | Our lawful basis |
|---|---|
| Run your account, show you people, deliver your messages, take your payments | Performance of our contract with you — this is the service you signed up for |
| Store and use your profile, your photos and your approximate location | Your consent, given at sign-up and withdrawable at any time |
| Send you marketing messages | Your consent, which is separate, optional, never a condition of using Lovyza, and withdrawable at any time |
| Screen photos and messages, act on reports, keep bans from being evaded, detect fraud | Our legitimate interest in keeping users safe, and the legitimate interest of the people we are protecting |
| Keep payment and ticket records | Legal obligation — tax and financial record-keeping law |
| Confirm you are 18 or over | Legal obligation, and our legitimate interest in keeping minors off an adults-only service |
Where we rely on your consent you can withdraw it at any time, and withdrawing it does not make our earlier use of your data unlawful. Withdrawing consent to the core processing in this policy means we can no longer run your account, so it is treated as a request to delete it.
---
6. Who we share it with
We do not sell your personal data. We do not share it with anyone for their own marketing.
We use the following service providers, who process data on our instructions and are contractually bound to protect it:
| Provider | What they do | What they receive |
|---|---|---|
| Kamatera | Hosts our server | Everything the service holds, at rest and in transit through the server |
| MongoDB Atlas | Hosts our database | Everything stored in the database |
| Cloudflare | DNS, content delivery, photo and media storage, and the relay that carries call traffic | Photos and message media. Call traffic passes through the relay and is not stored |
| TextSMS | Sends your sign-in code | Your phone number and the code |
| Google (Firebase Cloud Messaging) | Delivers push notifications | Your device's notification token and the notification text |
| Google (Sign-In) | An optional way to sign in | Your Google account identifier, only if you choose this |
| IntaSend | Takes payments by M-Pesa, Airtel Money and card | The payment amount, the phone number or card you pay with, and a reference. IntaSend is a separate controller of the payment data it holds — its own privacy policy applies to that |
Some of these providers store or process data outside Kenya. Where they do, we rely on the transfer conditions in Part VI of the Data Protection Act, including the provider's contractual commitments to appropriate safeguards.
We will also disclose your data where we are legally required to — a court order, a lawful request from the police or a regulator — and where it is necessary to protect someone's life or safety, or to establish or defend a legal claim. We do not hand over user data on an informal request.
If our business is sold or transferred, your data may transfer with it. You will be told before that happens and this policy will continue to apply until you are given a new one.
---
7. How long we keep it
While you have an account, we keep your data for as long as the account exists.
When you delete your account, we do not simply drop every row that mentions you, because some of those rows belong to other people or to a legal obligation. Here is exactly what happens:
Deleted straight away
- Your profile — your name, bio, prompt answers, interests, and your approximate location. Your photos are deleted from storage, not merely unlinked.
- Every live session, on every device.
- Your notification token, so nothing is ever sent to a handset you may since have sold.
- Your likes and passes. A record of who you liked is deeply personal and is useful to nobody once you are gone.
- Any unspent boosts or remaining premium days.
- Your event RSVPs.
- Your verification selfie, if any was still held.
Kept, with your content removed
- Your matches are unmatched rather than deleted, so the other person's conversation list keeps its shape instead of a row silently vanishing.
- Your messages lose their content and keep their place, exactly as a message you deleted yourself would. Removing them outright would punch holes in someone else's conversation; keeping the words would not be erasure.
Kept in full, and why
- Payment and ticket records. We have to be able to answer what we were paid, by whom and when, for longer than an account lasts. Tax and financial law requires this and the Data Protection Act does not override it.
- Your consent record. The ledger is append-only and is the only evidence of what you agreed to and when — including that your deletion was properly authorised.
- Reports made about you. These belong to the people who made them and to our safety record. Deleting an account must never be a way to clear a moderation history.
- Blocks placed on you. Someone blocked you for a reason, and deleting must not be a route back into their deck.
- Photo fingerprints, as explained in section 4.
- Tickets you sold and events you organised, because other people bought tickets to them. An event you organised is cancelled — which refunds and notifies attendees — rather than silently deleted.
- Call records — who called whom and for how long. No media was ever stored.
Your phone number
Your number is normally freed for reuse when you delete your account. "One account per phone number" does not mean one account per phone number for ever, and you are entitled to come back later or to sell the SIM.
The exception: if your account was suspended or banned when it was deleted, we keep a hash of your number for 12 months, so that deleting is not a way to wash a ban off and re-register. A hash is not a copy of your number and cannot be turned back into it.
Backups
Your account disappears from the app immediately. Our backups roll off within 30 days, after which the data is gone from our systems entirely.
---
8. Advertising
Free accounts see advertising. Paid tiers do not.
Advertising is served by Google AdMob. Google may use an advertising identifier held on your device to decide which advert to show you, and Google's own privacy policy governs what it does with that. We do not give advertisers your phone number, your profile, your location, your messages or your photos, and we do not let anyone target adverts at you using them.
You can reset or delete your advertising identifier, and turn off personalised advertising, in your Android settings under Settings → Google → Ads. The simplest way to see no advertising at all is to upgrade.
---
9. Your rights
Under the Data Protection Act you have the right to:
- Be told how your data is used — this document.
- Get a copy of the personal data we hold about you.
- Correct anything inaccurate or incomplete. Most of it you can edit yourself in the app.
- Delete your account and your data, subject to what section 7 explains we must keep.
- Object to processing based on our legitimate interests, and to withdraw any consent you have given.
- Ask us to restrict how we use your data while a dispute about it is being resolved.
- Receive your data in a portable form, where that applies.
- Not be subject to a decision made purely automatically that significantly affects you. Suspensions and bans are decided by a person, not by a filter alone, and you can ask for one to be reviewed.
How to use them
Most of it is in the app: You → Settings. Editing your profile, pausing or deleting your account, signing out a device, and changing your marketing preference are all there and take effect immediately.
For anything else, email support@lovyza.co.ke from the address on your account, or with the phone number you registered with, and we will verify you another way. We will respond within 30 days. There is no charge unless a request is excessive or repetitive, in which case we will tell you the cost before doing anything.
If you are not satisfied
Please raise it with us first — most issues are a misunderstanding we can fix quickly. If we cannot resolve it, you can complain to the Office of the Data Protection Commissioner:
Office of the Data Protection Commissioner Britam Tower, 33rd Floor, Hospital Road, Upper Hill, Nairobi Email: info@odpc.go.ke Website: www.odpc.go.ke
---
10. Keeping it safe
- All traffic between the app and our servers is encrypted in transit.
- Photos and message media are never publicly accessible. Every view goes through a link that is generated for you and expires within the hour; uploads use a link that expires in 15 minutes.
- Sign-in codes are stored hashed, never in readable form, and expire in minutes.
- Sign-in tokens rotate on every use. If a token is ever presented twice, we treat it as theft and end that session everywhere.
- Access is scoped by role. A moderator clearing reports cannot see payment data. Support can look up an account and cannot change it.
- Every staff action is written to an append-only log that nobody, including the account owner, can edit or delete.
- Staff access requires two-factor authentication, and can be revoked in a single action that also ends every live session.
No system is perfectly secure. If a breach occurs that is likely to cause you harm, we will notify the Office of the Data Protection Commissioner within 72 hours as the Act requires, and we will tell you.
---
11. Children
Lovyza is for adults only. You must be 18 or over.
Your age is worked out from the date of birth you give us, on our servers, not in the app — so it cannot be bypassed by modifying the app or by calling our systems directly. We do not create an account for anyone under 18.
If we find or are told that an account belongs to someone under 18, we remove it immediately and permanently, and we do not wait for a report to act. If you believe a minor is using Lovyza, please report the profile in the app or email safety@lovyza.co.ke. How we prevent and respond to child sexual abuse and exploitation is set out in our Child safety standards.
---
12. Changes to this policy
When we change this policy we publish a new version with a new date. If the change affects what you agreed to, we will ask you to accept the new version the next time you open the app, and you will not be able to continue until you do. That is why our consent record stores a version rather than a yes or no: agreeing to an earlier version is not agreement to this one.
We will tell you about a significant change before it takes effect, not after.
---
13. Contact us
Lovyza Technologies Ltd Nairobi, Kenya
- Privacy and your rights: privacy@lovyza.co.ke
- Safety concerns: safety@lovyza.co.ke
- Everything else: support@lovyza.co.ke
We aim to reply within 7 working days.