Kylala · Privacy policy

The fine print, in plain words

Privacy policy

Effective ⟨date of this revision⟩ · previous version 5 August 2026 · applies to the app at app.kylala.com and this website.

Kylala exists so neighbors can help each other without handing their lives to an ad machine. This page says exactly what we store, what is never kept on our servers, which services your browser talks to, and how to take everything back. It is written to be read.

The short version

Deleting your account is immediate, and does what it says.

Who is responsible

The service is operated by Kylala (the “we” on this page), the data controller for everything described here: an early-stage, founder-run project introduced on our team page. For anything privacy-related (questions, requests, complaints), write to [email protected].

What we store when you join

Joining asks for a sign-in (Google or an email address) and a nickname; no phone number and no real name. The server keeps a random account ID, your nickname, two numbers that generate your portrait and, from the sign-in, one opaque account id from the provider: never your email, which is read from the sign-in token on your device and shown only to you, in your Profile. A guest account (a street run without a sign-in provider) keeps a hash of the device secret that is your key instead: the secret is issued exactly once, to your device; only its hash is kept, so we could not recover or reuse it for you (that is what the recovery key is for).

Your home pin. Stored exactly as your device sends it: exact by default, or blurred about 50 m on your phone before it is sent, when you flip the blur toggle. Other neighbors never see your home pin at all: no API response carries another neighbor’s home. What they see are the pins of your asks, placed with the same precision choice, and rough distance buckets in Hands nearby, computed from a deliberately coarsened copy of your home.

Your address. Joining asks for one real address (street, number, postcode, city). It is checked against OpenStreetMap’s geocoder when you join, kept as you typed it if the map does not know it yet, and returned by exactly one API response: your own profile. No other endpoint includes any neighbor’s address, and the control center does not show it either.

Linked devices. Each device you link holds its own hashed secret; the server keeps that hash and the day it joined. Device-link codes are hashed at rest, valid ten minutes, single use, cancellable. The Devices list in Settings shows an id and a day, never an IP address, a browser, a name or a location. Removing a device signs it out at its next call.

If you sign in with Google or an email. Those identities are handled by Auth0 (Okta Inc.), our sign-in provider. Our server receives the signed sign-in token, verifies its signature, keeps the opaque subject string (like google-oauth2|…) and, at first sign-up, reads a name claim once to suggest a nickname. Nothing else in the token is parsed, logged or stored: the email inside it rides through verification and is discarded; no column for it exists. The copy you see in your Profile is read from the token on your device.

Onboarding, the locate step: Where is home? The map with the home pin, the toggle Blur my spot (~50 m) and the button The pin is on my door.
Where is home? Exact, or a gentle ~50 m blur. Your call.
Onboarding, the address step, filled in: Your address, Lindengracht 46, 1015 KN Amsterdam, the line Never shown to other neighbors, only you ever see it, and the button That’s my address.
Your address: never shown to other neighbors, only you ever see it.

A demo street with made-up neighbors.

What we store while you use it

Asks and announcements fade from the street after 14 days; the map keeps no archive of the street’s past for anyone to scroll. Deleting one of yours erases its text, pin and photo on the spot; what remains attached to your account until the account goes is only the blank marker other phones need in order to drop it.

What never reaches our servers

IP addresses, briefly and honestly

Like every website, our infrastructure sees your IP address when your device connects. We use it in exactly one stored form: a rate-limit counter on sign-in and registration endpoints, so nobody can hammer the door with guesses. Those counters are keyed by IP, swept automatically, and live at most ~31 days. Our error log, kept so we can fix crashes, deliberately records no IP, no user ID, no URL, and no message content: just which route failed and why. Kylala runs on Cloudflare, which processes connection data (including IPs) to deliver and protect the service, as any host does.

Services your browser talks to

We keep third parties to the minimum a map app can have. This website serves its own fonts and runs no analytics. When you use Kylala, your browser talks directly to:

In the self-contained demo (the app without an account), nothing leaves your device except map tiles.

Where data lives

Kylala’s own database and servers run on Cloudflare’s network. Cloudflare, Inc. is a US company processing connection data globally under its data processing addendum (EU standard contractual clauses; Cloudflare is also certified under the EU–US Data Privacy Framework). Sign-in identities live in our Auth0 tenant, which is hosted in the United States, a fact we state plainly rather than bury: if you use Google or email sign-in, that identity (and Auth0’s security logs, which include IPs) is processed in the US under Auth0’s own certification to the EU–US Data Privacy Framework. Guest accounts involve no Auth0 at all.

How long we keep things

Asks fade after 14 days; notification rows after 30 days; standing offers stay until you take them down and sleep after 90 quiet days; device-link codes live ten minutes, then are swept; sign-in rate-limit counters live at most about 31 days. Messages cannot yet be deleted one by one; deleting your account removes them.

Deleting your account

Profile, Settings, Delete my account. It is immediate and deletes for real: your asks, raised hands, standing offers, conversations, photos, notification rows, devices and link codes go with it; your circles pass to the next steward or close. What other neighbors keep is only the blank marker their phones need in order to drop what was yours. If you’d rather we do it, or you want your Auth0 sign-in record removed too, write to [email protected].

When you write to us

Mail to [email protected] is forwarded by Cloudflare Email Routing to a mailbox hosted by Google (in the US, under the same Data Privacy Framework). It is read by a human, used only to handle your message, and never added to any list.

Your rights

Kylala is operated from Geneva, Switzerland, so the Swiss Federal Act on Data Protection (FADP) governs how we handle your data wherever in the world you live. If you live in the European Union, the GDPR applies as well. Under either law you can ask for access to your data, correction, deletion, restriction of processing, a portable copy, or object to processing: write to [email protected] and we will answer within a month. Almost everything is faster in the app: your profile shows what we hold, and deletion is self-service. You can also complain to a supervisory authority: in Switzerland, the Federal Data Protection and Information Commissioner (FDPIC); in the EU, the authority of your country.

The legal bases we rely on: performing the service you asked for (running your account and your street, including the address checks and map tiles that requires), our legitimate interest in keeping the service safe (rate limiting, moderation, crash logs), and your consent where you grant it (notifications, the browser’s location permission; both withdrawable at any time, in place, without affecting anything else).

Cookies

We set no cookies, on this website or in the app. If you sign in with Google or an email, the sign-in provider (Auth0) sets its own on its domain and sends its own verification and reset emails.

Children

Kylala is not directed at children and is not intended for anyone under 15.

When this page changes

We date every revision at the top of this page and keep the previous date beside it. A change that widens what we store would be announced inside the app before it takes effect.