Kylala · Privacy policy
The fine print, in plain words
Privacy policy
Effective ⟨date of this revision⟩ · previous version 5 August 2026 · applies to the app at app.kylala.com and this website.
Kylala exists so neighbors can help each other without handing their lives to an ad machine. This page says exactly what we store, what is never kept on our servers, which services your browser talks to, and how to take everything back. It is written to be read.
The short version
- No real names: a nickname and a generated face; the profile has no real-name field; a first name is shared per conversation, or never.
- No ads, no analytics, no trackers, no cookies, no data sales, on the website or in the app.
- No feed to scroll and no archive: a map of open asks and the list under it; nothing ranked for engagement; asks fade after 14 days.
- No crime-and-fear category: a heads-up is practical news, never an alert about people.
- No phone number needed and no email shared: neighbors see a nickname and a generated face, never your email or your number. Your email is never kept on Kylala’s servers; what we keep from a Google or email sign-in is one opaque account id from the provider, and nothing else.
- No prices, ratings, pro badges or paid placement anywhere, including standing offers ("Your offers").
- No pings you did not ask for: a ring is earned by someone waiting on you, or by an interest alert you switched on, two a day at most.
- No app store: it installs from the browser.
Deleting your account is immediate, and does what it says.
Who is responsible
The service is operated by Kylala (the “we” on this page), the data controller for everything described here: an early-stage, founder-run project introduced on our team page. For anything privacy-related (questions, requests, complaints), write to [email protected].
What we store when you join
Joining asks for a sign-in (Google or an email address) and a nickname; no phone number and no real name. The server keeps a random account ID, your nickname, two numbers that generate your portrait and, from the sign-in, one opaque account id from the provider: never your email, which is read from the sign-in token on your device and shown only to you, in your Profile. A guest account (a street run without a sign-in provider) keeps a hash of the device secret that is your key instead: the secret is issued exactly once, to your device; only its hash is kept, so we could not recover or reuse it for you (that is what the recovery key is for).
Your home pin. Stored exactly as your device sends it: exact by default, or blurred about 50 m on your phone before it is sent, when you flip the blur toggle. Other neighbors never see your home pin at all: no API response carries another neighbor’s home. What they see are the pins of your asks, placed with the same precision choice, and rough distance buckets in Hands nearby, computed from a deliberately coarsened copy of your home.
Your address. Joining asks for one real address (street, number, postcode, city). It is checked against OpenStreetMap’s geocoder when you join, kept as you typed it if the map does not know it yet, and returned by exactly one API response: your own profile. No other endpoint includes any neighbor’s address, and the control center does not show it either.
Linked devices. Each device you link holds its own hashed secret; the server keeps that hash and the day it joined. Device-link codes are hashed at rest, valid ten minutes, single use, cancellable. The Devices list in Settings shows an id and a day, never an IP address, a browser, a name or a location. Removing a device signs it out at its next call.
If you sign in with Google or an email. Those identities are handled by Auth0 (Okta Inc.), our sign-in provider. Our server receives the signed sign-in token, verifies its signature, keeps the opaque subject string (like google-oauth2|…) and, at first sign-up, reads a name claim once to suggest a nickname. Nothing else in the token is parsed, logged or stored: the email inside it rides through verification and is discarded; no column for it exists. The copy you see in your Profile is read from the token on your device.


A demo street with made-up neighbors.
What we store while you use it
- Asks: category, title, text, the pin you placed (same precision rule as your home pin), optional photo, optional away-dates for home-watch (on the street, shown only to the helper you accept and to vouched-for neighbors; in a circle, to its members).
- Raised hands on asks: two ids and three clocks per raised hand (who, on which ask, when it went up, when it was accepted, when it was reported done); never a note, a reason or a score. An ended hand is deleted, not marked. Who ended a commitment is recorded only in the rows the people concerned read in Notifications.
- Conversations: messages, optional photos, and read-receipt timestamps shown only to the person you are talking to. If you choose to sign a conversation with your real name, that name lives only in that conversation, and only because you typed it. It is the single place a real name can exist in Kylala, and it is erased if your account goes.

Your first name, in this conversation only. Or never. - Standing offers: up to three short labels and one line, the one deliberately public text you write about yourself. Hands nearby is computed from grid-snapped homes, never raw coordinates, and distances leave the server as rough buckets. An offer nobody confirms goes to sleep after 90 quiet days.
- Notifications ledger: one row per event: ids, a kind, enum parameters and clocks. Never a title, a note, a name, a pin, an address, a reason or a moderator: the words are joined when you read the row, and only for the people who may see them. Rows fade after 30 days.
- Conversation origin: whether a conversation started from a standing offer, one nullable column, used only for aggregate counts.
- Photos: compressed on your device to roughly 350 KB before upload, stored with the content they belong to, and erased when you delete that content (or your account). They are served from unguessable links; new fetches stop the moment the content is removed or moderated, and caches expire within the hour.
- Check-ins: the gentle verification. Your device sends one GPS fix; the server compares it to your pin and keeps only a grid-snapped point (~55 m) plus the fix’s stated accuracy radius as evidence, at most one per day. The raw fix is discarded, and check-in points are never displayed anywhere.
- Push: if you turn notifications on, we store your browser’s push endpoint, its encryption keys, and your quiet-hours window. Message contents are encrypted to your browser; the push service in the middle cannot read them.
- Blocks, reports, appeals: who you blocked (visible only to you), what you reported and why (visible to moderation), and what you wrote if you appeal a ban.
- Kudos: a counter of thanks received.
- A coarse last-active timestamp: bumped at most once per five minutes, visible only to the person running the street (never to neighbors), and zeroed when your account goes.
Asks and announcements fade from the street after 14 days; the map keeps no archive of the street’s past for anyone to scroll. Deleting one of yours erases its text, pin and photo on the spot; what remains attached to your account until the account goes is only the blank marker other phones need in order to drop it.
What never reaches our servers
- Your email and phone number are never kept: no columns for them exist, and the sign-in token they ride in is discarded the moment its signature checks out.
- Your real name is never asked for; it can only exist where you typed it yourself: a conversation you chose to sign, or the one-time nickname suggestion above.
- Anyone else’s view of your home: no endpoint returns another user’s coordinates or address, full stop.
- Raw GPS fixes: compared, snapped to a ~55 m grid, and only the snapped point kept.
- Device fingerprints, advertising IDs, tracking pixels: none, anywhere.
IP addresses, briefly and honestly
Like every website, our infrastructure sees your IP address when your device connects. We use it in exactly one stored form: a rate-limit counter on sign-in and registration endpoints, so nobody can hammer the door with guesses. Those counters are keyed by IP, swept automatically, and live at most ~31 days. Our error log, kept so we can fix crashes, deliberately records no IP, no user ID, no URL, and no message content: just which route failed and why. Kylala runs on Cloudflare, which processes connection data (including IPs) to deliver and protect the service, as any host does.
Services your browser talks to
We keep third parties to the minimum a map app can have. This website serves its own fonts and runs no analytics. When you use Kylala, your browser talks directly to:
- OpenFreeMap: the map itself. Fetching tiles reveals your IP and the areas you look at (usually your own street) to the tile server. OpenFreeMap is a free, open project whose privacy policy states it does not store IP addresses in its regular logs; your app also caches tiles on-device to keep requests down.
- Esri (ArcGIS World Imagery): only if you switch on the satellite layer; same tile mechanics.
- Nominatim (OpenStreetMap Foundation): one-shot address checks. When you confirm your address or move your pin, the address you typed and the pin’s whereabouts are sent for validation; our server repeats the same one-shot check on its side, without your IP. Never used as you type. The OSMF’s privacy policy governs those lookups.
- Photon (a free geocoder by komoot): address autocomplete. While you type your own address during onboarding or a move, the letters typed so far and a search box a few kilometers around your pin are sent to suggest completions. Photon publishes no privacy statement of its own, so we tell you exactly what it receives instead.
- Auth0: only when you choose a sign-in method; you are on their hosted page at that moment, and Google’s own pages if you pick Google.
- Your browser’s push service (Google, Apple, or Mozilla, depending on the browser): only if you enable notifications; payloads are end-to-end encrypted to your browser.
In the self-contained demo (the app without an account), nothing leaves your device except map tiles.
Where data lives
Kylala’s own database and servers run on Cloudflare’s network. Cloudflare, Inc. is a US company processing connection data globally under its data processing addendum (EU standard contractual clauses; Cloudflare is also certified under the EU–US Data Privacy Framework). Sign-in identities live in our Auth0 tenant, which is hosted in the United States, a fact we state plainly rather than bury: if you use Google or email sign-in, that identity (and Auth0’s security logs, which include IPs) is processed in the US under Auth0’s own certification to the EU–US Data Privacy Framework. Guest accounts involve no Auth0 at all.
How long we keep things
Asks fade after 14 days; notification rows after 30 days; standing offers stay until you take them down and sleep after 90 quiet days; device-link codes live ten minutes, then are swept; sign-in rate-limit counters live at most about 31 days. Messages cannot yet be deleted one by one; deleting your account removes them.
- Your account and its content: until you delete them.
- Asks and announcements: shown for 14 days, kept until deleted by you, by moderation, or with your account.
- Reports, appeals and the moderation log: for as long as they are needed to keep the street safe.
- Crash fingerprints (no personal data): until the bug is fixed and the row is cleared.
- Photos: for as long as the content they belong to exists, and not a moment longer.
Deleting your account
Profile, Settings, Delete my account. It is immediate and deletes for real: your asks, raised hands, standing offers, conversations, photos, notification rows, devices and link codes go with it; your circles pass to the next steward or close. What other neighbors keep is only the blank marker their phones need in order to drop what was yours. If you’d rather we do it, or you want your Auth0 sign-in record removed too, write to [email protected].
When you write to us
Mail to [email protected] is forwarded by Cloudflare Email Routing to a mailbox hosted by Google (in the US, under the same Data Privacy Framework). It is read by a human, used only to handle your message, and never added to any list.
Your rights
Kylala is operated from Geneva, Switzerland, so the Swiss Federal Act on Data Protection (FADP) governs how we handle your data wherever in the world you live. If you live in the European Union, the GDPR applies as well. Under either law you can ask for access to your data, correction, deletion, restriction of processing, a portable copy, or object to processing: write to [email protected] and we will answer within a month. Almost everything is faster in the app: your profile shows what we hold, and deletion is self-service. You can also complain to a supervisory authority: in Switzerland, the Federal Data Protection and Information Commissioner (FDPIC); in the EU, the authority of your country.
The legal bases we rely on: performing the service you asked for (running your account and your street, including the address checks and map tiles that requires), our legitimate interest in keeping the service safe (rate limiting, moderation, crash logs), and your consent where you grant it (notifications, the browser’s location permission; both withdrawable at any time, in place, without affecting anything else).
Cookies
We set no cookies, on this website or in the app. If you sign in with Google or an email, the sign-in provider (Auth0) sets its own on its domain and sends its own verification and reset emails.
Children
Kylala is not directed at children and is not intended for anyone under 15.
When this page changes
We date every revision at the top of this page and keep the previous date beside it. A change that widens what we store would be announced inside the app before it takes effect.