Laila - Privacy Policy
This policy explains what personal data Laila collects, why, who sees it, how long we keep it, and what you can do about it. It is also the notice required by section 11 of the Protection of Privacy Law, 5741-1981, so it starts with the facts that section requires.
Notice under section 11 of the Protection of Privacy Law
- The controller of the database is the operator of Laila, an independently owned service based in Israel. Contact: support@laila-nightlife.com; a postal address is provided on request to that address.
- You are not legally required to provide us any information. Providing it is your choice. Without a sign-in identity and your location you cannot use the features that depend on them (an account, check-in, chat); the optional profile fields can be left empty.
- Purposes: operating the Laila service - showing venues near you, verifying check-ins, producing anonymous crowd counts, running chat and messaging, keeping the service safe, billing paid plans, and complying with the law.
- Recipients: the service providers listed in section 8, other users to the extent described in section 7, and authorities where the law requires it. Data is stored in the European Union (section 9).
- You have the right to access the data held about you and to ask for it to be corrected or deleted (section 12).
1. Who is responsible
The operator of Laila is the controller of your data. Where a privacy protection officer has been appointed, their contact details are published at https://laila-nightlife.com/legal/privacy. For anything in this policy, write to support@laila-nightlife.com.
2. What we collect
2.1 Account and sign-in
- Phone number, when you sign in with SMS.
- Name and email address, when you sign in with Google or Apple. Apple lets you hide your address; if you do, we receive a relay address only.
- A user ID we create, and the record of which version of the terms you accepted and when.
2.2 Profile - what you choose to enter
- Display name and profile photos.
- Gender and birth year (shown to others only as an age range).
- Optional: who you are interested in meeting, relationship status, links to your social profiles and your preferred language.
2.3 Location
- Your position while you use the app, to sort venues by distance and to verify a check-in against the venue's radius.
- If you turn on automatic check-in, the operating system tells Laila when you enter or leave a venue's area, also while the app is closed. We record the resulting check-in or check-out. We do not keep a history of your movements, and a boundary crossing that does not become a check-in sends us nothing.
- Filling an advertising slot never uses your position; it uses the city the screen is already showing.
2.4 What you do in Laila
- Check-ins and a history of past check-ins (venue and time).
- Venue chat messages, posts, likes, direct messages, and the photos you send.
- Friendships and, if you enable it, sharing your presence with friends.
- Reports you file and blocks you set; offers you redeem.
- Requests to the AI features (message translation, the night concierge).
2.5 Device and technical
- Push notification token, device model, operating system, app version and language.
- Server logs with IP address, timestamps and error diagnostics.
- On Android, an encrypted restore credential inside your device backup so that a new phone signs in automatically; it contains no personal details.
2.6 Purchases
- Your Laila+ or night pass status, the plan, and the store's transaction identifier, received from Apple or Google through RevenueCat. We never see your card or payment details.
2.7 Support
- What you send us through Contact, and our replies.
3. Why we use it and on what basis
We process your data with your consent, given when you create an account and, separately, when you grant location, background location, camera and notification permissions - each of which you can withdraw in your device settings or in the app. We also process data to perform our agreement with you (delivering the service and paid plans), to comply with legal obligations, and for our legitimate interest in keeping the service safe and honest (moderation, abuse prevention, fraud prevention). For users in the European Economic Area, these are the lawful bases under Articles 6(1)(a), (b), (c) and (f) of the GDPR.
4. Especially sensitive information
Two things we hold are treated as "information of special sensitivity" under Israeli law: your location, and the optional "interested in meeting" field, which can indicate sexual orientation. Location is essential to the service and is processed only as described in section 2.3. The "interested in meeting" field is optional, is shown to other users only if you fill it in, and can be cleared at any time in your profile. We never use either for advertising.
5. What we use it for
- Showing venues near you and letting you check in where you are.
- Producing live crowd counts. These are aggregates: your check-in adds one to the count, and below a minimum crowd size the gender and age breakdown is hidden so small groups cannot be identified. You can exclude yourself from the counts entirely in Settings.
- Running venue chat, the Tonight feed, direct messages and friend features.
- Sending notifications you have enabled (messages, arrival prompts, offers).
- Keeping the service safe: moderation, enforcing the one-message rule, detecting spoofed locations and duplicate accounts.
- Providing and billing paid plans.
- Support, and legal compliance.
- Aggregate, non-identifying statistics about how the service is used.
6. Automated processing
Every profile photo, and every photo sent in a chat or post, is scored by a machine vision model for content that breaks our rules; reported messages are scored the same way. Content flagged with high confidence is hidden until a person reviews it. Suspensions are decided by people. Message translation and the concierge send the text you submit to our AI provider (section 8) to produce an answer; we do not use your content to train models.
7. Who can see what
- Other users at the same venue see your display name, photos, age range and the optional profile details you filled in. Nobody sees your phone number, email, exact age or exact location.
- Crowd counts shown to everyone are aggregated and suppressed for small groups as described in section 5.
- Friends see your presence at a venue only if you have turned that on.
- Venue owners see their venue's counts and offer statistics. They never see who is behind a number.
- Advertisers receive aggregate results (views, taps) with no user identity.
- Our moderation staff see reported content and the accounts involved.
8. Who we share data with
We do not sell personal data. We share it with providers who process it for us under contract, and only for the purposes above:
- Google (Firebase and Google Cloud): hosting, database, authentication, file storage, push notifications, and the Maps SDK that draws the map. Data is stored in Google's EU region (europe-west1).
- RevenueCat: subscription status, on our behalf.
- Apple and Google: sign-in with your Apple or Google account, and payments.
- Anthropic: the AI provider that scores photos and reported messages and answers translation and concierge requests. We disclose data to authorities when the law requires it, and to address a serious risk to someone's safety. If Laila is sold or merged, your data may be transferred to the new operator under this policy, and we will tell you.
9. Where data is kept and international transfers
Your data is stored in the European Union. Transfers from Israel to the EU are made under the Protection of Privacy (Transfer of Data to Databases Abroad) Regulations, 5761-2001, to a territory whose data protection law the regulations recognise. Requests to our AI provider may be processed in the United States under contractual data-protection commitments. For EEA users, Israel benefits from a European Commission adequacy decision.
10. How long we keep it
- A check-in expires within hours of your last activity and is removed from the live counts. The record that you were at a venue at a given time is kept while your account exists.
- Venue chat is emptied every day at 05:00 Israel time; photos sent in chat go with it. Posts to the Tonight feed expire after 24 hours.
- Direct messages and their photos stay until you or the other person deletes them, or until an account is deleted.
- Reports, and the content they refer to, are kept while the matter is open and for a further period needed to handle repeat abuse, then deleted.
- The Android restore credential is valid for 400 days and is rotated on use.
- Server logs are kept for up to 90 days.
- When you delete your account, your profile, photos, posts, messages, conversations, friendships, check-ins and check-in history are erased immediately; copies in backups disappear within 30 days. We keep: reports filed about the account (stripped of everything but the user ID, as a safety record), records of payments the law requires us to keep, and anything we must retain to comply with a legal obligation or an ongoing dispute.
11. Security
We operate the database under the Protection of Privacy (Data Security) Regulations, 5777-2017: data is encrypted in transit, access is limited to staff who need it and is logged, live crowd counts are computed on the server and never from the client, and location is verified by the server before a check-in counts. If a security incident affects your data we will notify the Privacy Protection Authority and, where required, you.
12. Your rights
Under the Protection of Privacy Law you have the right to inspect the information held about you (section 13) and to ask for information that is inaccurate, incomplete or out of date to be corrected or deleted (section 14). You can also: withdraw consent (by turning off a permission or deleting your account), delete your account yourself from the app, object to direct marketing, and complain to the Privacy Protection Authority (www.gov.il/en/departments/the_privacy_protection_authority). Users in the EEA additionally have the GDPR rights of access, rectification, erasure, restriction, portability and objection, and may complain to their supervisory authority. To exercise any right write to support@laila-nightlife.com; we reply within 30 days and may ask you to verify that the account is yours.
13. Notifications and marketing
Push notifications are sent only for the categories you enable, and each can be turned off in the app or in your device settings. We do not send marketing messages by SMS, email or automated call without your prior express consent, as section 30A of the Communications Law (Telecommunications and Broadcasting), 5742-1982 requires, and every such message would carry a way to opt out.
14. Children
Laila is for adults. We do not knowingly collect data from anyone under 18, and we delete such accounts when we learn of them. If you believe a minor is using Laila, tell us at support@laila-nightlife.com.
15. Changes to this policy
We will announce material changes in the app before they take effect and update the version and date above. The current version is always at https://laila-nightlife.com/legal/privacy.
16. Contact
support@laila-nightlife.com, or Contact in the app. A postal address is provided on request to that address.