Privacy Policy
Effective Date: 2026-09-23 Last Updated: 2026-09-23 Publisher / Data Controller: BKPA (PT. BERSAMAKITA PERKASA ABADI), operator of LiLO Contact: privacy@lilo.club
This Privacy Policy explains what data the LiLO mobile application ("LiLO", "we", "us") collects, how we use it, who we share it with, how long we keep it, and what choices you have. It applies to LiLO on iOS and Android, and to the LiLO web surfaces we operate (the liveness check and these legal pages).
LiLO is a live social platform. You can broadcast live video or audio, join voice rooms and parties, take part in PK battles and in-room games, post short videos and photos ("Moments"), chat one-to-one and in groups, and send or receive virtual gifts. Some features involve money: you can buy Coins, and creators can convert the Diamonds they earn into a payout.
Because of those features, LiLO collects more data than an ordinary photo-sharing app — including, where you choose to use the relevant feature, face data and identity documents. This policy says so plainly. We do not sell personal data and we do not run third-party advertising or cross-app tracking.
1. Data We Collect
1.1 Information you give us directly
| Data | Required for | Stored where |
|---|---|---|
| Email address | Account creation, login, password reset | users.email |
| Password | Login | users.password_hash |
| Phone number (if you sign in by phone) | Phone sign-in and one-time codes | users.phone_number, phone_otps |
| Apple account identifier and email | Sign in with Apple | oauth_links |
| Display name, profile photo, cover photo, extra photos | Your public profile | profiles, profile_photos, media in object storage |
| Bio | Your public profile | profiles.bio |
| Date of birth | The 17+ age check. We do not show your birth date, but the age calculated from it is visible to other users on your profile, in room audience lists and in rankings | profiles.date_of_birth |
| Gender and country | Profile identity, recommendations, "nearby" ordering | profiles.gender, profiles.country |
| Moments you post (video, photo, caption, hashtags) | The Moments feed | posts + object storage |
| Comments, likes, favourites, follows | Social interaction | comments, likes, favorites, follows |
| Chat messages, including images and voice notes | One-to-one and group messaging | messages, conversations + object storage |
| Messages you send inside live rooms, PK arenas and paid marquees | Showing them to the room | pk_chat_messages, pk_team_chat, marquee_messages |
| Reports you file and the details you write | Content moderation (Apple Guideline 1.2) | reports |
| Block list | Hiding blocked users | blocks |
| Privacy preferences | Honouring your choices | privacy |
| Security PIN (for withdrawals) | Protecting money leaving your account | users.security_pin_hash (bcrypt) |
If you apply to become a recharge agent, agency owner or coin reseller, we also collect your legal name, phone number and, for resellers, your WhatsApp number and the payment details you choose to publish (agent_applications, resellers).
1.2 Information collected automatically
| Data | Purpose |
|---|---|
| Authentication token (JWT) | Keeping you signed in; stored on your device in the iOS Keychain / Android EncryptedSharedPreferences |
| IP address and device User-Agent at each login, and at EULA acceptance | Security, session management, abuse investigation, proof of consent (sessions, eula_acceptances) |
| Push notification token and platform | Delivering notifications (device_tokens) |
| App version and platform | Diagnostics and forced-update checks |
| Watch history — which live rooms you entered and when | The "Watch History" feature (room_views) |
| Which Moments you watched | View counts and creator statistics (post_views) |
| Profile visits — whose profile you opened | The "Visitors" feature, which you can switch off in Settings → Privacy (profile_visits) |
| Room membership, seat and microphone events, broadcast durations | Running rooms, moderation, and billing reconciliation with our streaming provider (room_members, rtc_usage_channel) |
| Gift, coin and diamond movements | Operating the economy (gift_events, coin_transactions, wallet_transactions) |
| Face-absence counters while you broadcast | Enforcing the rule that a host must be present on camera — see §1.3 |
1.3 Face data and identity documents (special categories)
These are collected only if you use the feature that needs them. You can use LiLO's core features — Moments, Messages, watching live rooms — without any of it.
Face verification. To get a verified badge, and before some host features, you may complete a face check. You take a selfie in the app, and you may be asked to complete a short "liveness" challenge in a web page inside the app. In the liveness challenge, your camera video is streamed directly from your device to Amazon Web Services using short-lived credentials; it does not pass through LiLO's servers. We store: the selfie image, the liveness result and confidence score, and a mathematical face template ("faceprint") held in an AWS Rekognition collection. We compare your faceprint against those of other LiLO accounts to detect one person holding several verified accounts; if there is a match we record the similarity score and the other account's identifier so a reviewer can act on it. A human reviewer may look at your selfie. Rejected attempts are kept so that repeat attempts with a different face can be detected.
Presence check while broadcasting. While you are live, the app periodically checks whether a face is visible on camera and whether it is moving (to detect a photo held in front of the lens). This check runs entirely on your own device; the image is analysed locally and deleted. Only a number — how many seconds a face has not been seen, and the reason — is sent to us. If a face stays absent past the configured limit, the room is closed automatically.
Identity documents. If you request a payout of Diamonds, we ask you to complete identity verification: your legal name, the type and number of a government ID, a photograph of the front and back of that ID, and a selfie. We also store the bank account name and number, or the crypto wallet address, you want to be paid to.
1.4 What we do NOT collect
- We do not collect GPS or precise location. The "nearby" feature sorts rooms by the country on your profile, which you set yourself. There is no latitude or longitude anywhere in LiLO.
- We do not access your contacts, calendar, SMS or call logs.
- We do not run third-party advertising SDKs and we show no third-party ads.
- We do not run third-party analytics SDKs, and we do not track you across other companies' apps or websites. LiLO does not ask for the iOS tracking permission.
- We never receive your card number, CVV or billing address. Coin purchases are processed by Apple; we receive only the transaction identifier we need to credit your Coins.
2. How We Use Your Data
We use the data above to:
- Provide the service — sign you in, render your profile, deliver your posts, comments, chats and gifts, run live rooms and voice rooms, keep your balances.
- Keep the community safe — act on reports, enforce the EULA, suspend or remove accounts that break the rules, hide content from users you blocked, detect duplicate or impersonating accounts, and enforce the host-presence rule.
- Operate the economy and pay creators — credit verified purchases, run the Coin and Diamond ledgers, verify identity where money leaves the platform, and meet tax and accounting obligations.
- Operate and improve the service — diagnose faults, prevent abuse and spam, and reconcile what our streaming provider bills us against our own records.
- Comply with legal obligations and respond to lawful requests.
We do not use your data for targeted advertising, and we do not sell or rent it.
3. How You Sign In
LiLO offers email and password, phone number with a one-time SMS code, and Sign in with Apple.
With Sign in with Apple we receive only the email address Apple gives us (which may be Apple's private relay address) and the name you choose to share. We store that in oauth_links and treat it like any other account identifier. We receive nothing else from your Apple account.
Phone sign-in stores your phone number and a short-lived one-time code. The SMS itself is sent by Twilio.
3A. In-App Purchases, Virtual Currency and Payouts
LiLO has an optional virtual economy. You are never required to spend money.
Coins are bought with real money through Apple's In-App Purchase system. Apple — not LiLO — processes your payment; we never see your card details. We store the transaction identifier, the product bought and the resulting balance so we can credit your Coins and show your purchase history.
Coins may also be bought through an authorised recharge agent or reseller where that is offered. In that case the agent records the transfer, and payment to the agent happens outside LiLO under the agent's own terms. We store the record of the coin transfer, and the agent's own crypto deposit addresses and transaction hashes where the agent funds their float that way.
Diamonds are earned by creators from gifts. Diamonds can be exchanged for Coins or, subject to identity verification, paid out. Coins and Diamonds have no cash value in your hands, cannot be transferred off the platform except through the payout process, and are not refundable except where Apple's rules or applicable law require.
Subscriptions. VIP is sold as an auto-renewing subscription through Apple. We store the original transaction identifier and receipt so we can keep your entitlement in sync.
4. Who We Share Data With
We share personal data only with the processors below, only for the purposes listed, and only the minimum needed. We do not share data with advertisers, data brokers or social networks.
| Party | Purpose | Data shared |
|---|---|---|
| Cloud hosting provider | Run the LiLO API and MySQL database | All stored data, at rest |
| Alibaba Cloud OSS (Singapore) | Store the media you upload: avatars, Moments, chat images and voice notes, selfies, ID photos | The files themselves, in a private bucket served through expiring signed links |
| Agora | Carry live video and audio, and in-room realtime chat and gift events | Your audio/video stream while you are in a room, plus a short-lived token and a numeric room user id. Media goes device-to-Agora and never through our servers |
| Tencent Cloud / streaming CDN | Deliver the live stream to viewers efficiently | The published stream and its metadata |
| Amazon Web Services (Rekognition, Singapore and Tokyo) | Face liveness challenge and duplicate-face detection | Your liveness video (streamed directly from your device), your selfie, and your faceprint |
| Twilio | Send the SMS one-time code | Your phone number and the code |
| Brevo | Send account emails such as password reset | Your email address and the message |
| Firebase Cloud Messaging (Google) and Apple Push Notification service | Deliver push notifications | Your push token and the notification content |
| Apple | Process purchases, verify receipts, and Sign in with Apple | Handled under Apple's privacy policy; we receive only transaction identifiers and the sign-in claims described in §3 |
| Google Translate | Translate a chat message when you tap "translate" | The text of that message. Translation is only performed when you ask for it, and only that message is sent |
| Payout and banking partners | Pay creators | Your name, bank account or wallet address, and the amount |
If we are required by law to disclose data, we will narrow the disclosure to what is compelled and, where we are legally permitted, tell the affected user.
Third-party software included in the app
Beyond the services above, these are the third-party components built into the LiLO app itself. Everything else in the app is our own code.
| Component | What it is for | What it can reach |
|---|---|---|
| Agora RTC and Agora Signaling | Carrying live video and audio, and in-room chat and gift events | Your camera and microphone while you are in a room, and the messages you send in that room |
| Google ML Kit face detection | The on-device presence check described in §1.3 | Camera frames, analysed on your device and deleted immediately. No image is uploaded |
| Firebase Cloud Messaging (Google) | Receiving push notifications | A push token identifying your installation of the app |
| Apple StoreKit and Sign in with Apple | Purchases and signing in | Handled by Apple; see §3 and §3A |
| Amazon Web Services liveness component | The liveness challenge in §1.3. It is loaded as a web page inside the app, not built into it | Your camera during the challenge, streamed directly to AWS |
| Video playback and QR scanning components | Playing video and reading a friend's QR code | Run on your device. QR decoding does not leave your device |
The app contains no advertising SDK, no analytics SDK, no crash-reporting or attribution SDK, and no advertising identifier. We have deliberately kept it that way, and §1.4 above is a commitment, not just a description.
5. Data Retention
We keep personal data for as long as your account exists, and afterwards only where a record must survive the account for legal, financial or safety reasons.
| Data | Retention |
|---|---|
| Account, profile, privacy settings | Until you delete your account (§7) |
| Your Moments, comments, likes, follows and blocks | Deleted when you delete your account |
| Chat messages | Kept for as long as the conversation exists. Deleting your account does not remove your messages from the other person's copy |
| Reports filed by or about you | Kept after your account closes, so that a safety decision can be reviewed |
| Face verification — selfie, liveness result, faceprint | Kept while the verification stands. Rejected attempts are kept too, so that repeat attempts with a different face can be detected. Deleted on request (§7) |
| Identity documents and payout details | Kept as long as tax, accounting and anti-fraud law require us to be able to evidence a payout |
| Coin, Diamond, gift and purchase records | Kept as financial records, including after your account closes |
| Login sessions (IP and User-Agent), push tokens | Kept until you revoke the session or log out, and as a security record afterwards |
| Watch history, profile visits, Moment views | Kept while your account exists |
| Uploaded media files | The stored file survives automatic account deletion; ask us to erase it (§7) |
If you want anything in the lower rows erased sooner, write to privacy@lilo.club and we will delete whatever we are not legally required to keep.
6. Children's Privacy
LiLO is for users 17 and older. The app asks for your date of birth when you complete your profile and refuses to continue if it shows you are under 17. That check is based on the date you enter, so it depends on you answering honestly; we do not otherwise verify age. (Face verification, where used, checks that one person is not running several accounts — it is not an age check.)
We do not knowingly collect data from children. If you believe an underage person has registered, email safety@lilo.club and we will remove the account. Child sexual abuse material is prohibited absolutely; see our Child Safety Standards Policy.
7. Your Rights — including Account Deletion
From inside the app you can, at any time:
- Edit your profile (Me → Edit Profile).
- Change your privacy settings, including whether profile visitors are recorded (Me → Settings → Privacy).
- See and revoke your logged-in sessions and devices (Me → Settings → Security).
- Block or unblock users, and report content or a user.
- Delete your account (Me → Settings → Account & Security → Delete Account).
Deleting your account removes your user record, profile, privacy settings, Moments and their comments and likes, your own comments and likes, your follows and blocks in both directions, and the reports you filed. Deleting your account forfeits any remaining Coins and Diamonds.
Some records are not removed by that automatic deletion, because they belong to another person's account, to a financial or safety record we must keep, or to a duplicate-account control: messages in other people's conversations, transaction and payout records, identity verification records, face verification records and faceprints, login history, and stored media objects. To have those erased as well — and in particular to have your faceprint and identity documents deleted — email privacy@lilo.club from your registered address. We will erase everything we are not legally required to keep, within 30 days.
You may also email privacy@lilo.club to ask for a copy of the data we hold about you, or to correct it.
8. Security
- Your login is verified against a bcrypt hash of your password, and your password only ever travels over an encrypted connection. Your withdrawal PIN is hashed separately, so knowing your password is not enough to move money out of your account.
- All traffic between the app and our servers uses HTTPS/TLS.
- Tokens are stored on your device in the iOS Keychain or Android EncryptedSharedPreferences.
- Uploaded media sits in a private bucket and is served through links that expire.
- Live audio and video travel between your device and our streaming provider, not through our own servers.
- Administrative access to user records is limited to named operator accounts with role-based permissions, and administrative actions are written to an audit log.
- We export no user data to any advertising or analytics network.
No system is perfectly secure. If you find a vulnerability, email security@lilo.club.
9. International Transfers
Our servers run in a single region. Media is stored in Singapore. Face verification uses AWS in Singapore and Tokyo. SMS, email, push and translation providers operate internationally. If you use LiLO from elsewhere, your data crosses borders to reach these services, protected by HTTPS in transit and by contractual terms with each provider.
10. Changes to This Policy
If we change this policy we will update the "Last Updated" date above and, for material changes, show an in-app notice the next time you open LiLO. Continued use after that notice means you accept the change.
11. Contact
- Privacy and data requests: privacy@lilo.club
- General support: support@lilo.club
- Trust and safety: safety@lilo.club
- Security: security@lilo.club
- Legal and copyright: legal@lilo.club
These addresses are reviewed every business day; trust-and-safety reports are actioned within 24 hours.