Privacy Policy
Last Updated: July 10, 2026 | Effective: July 10, 2026
lylai (hereinafter referred to as "the Service") is developed and operated by Cheng-I Wu (hereinafter referred to as "I"). In accordance with the Personal Data Protection Act of the Republic of China (Taiwan) and related regulations, I have established this Privacy Policy to explain how I collect, process, use, and protect your personal data.
By using the Service, you acknowledge that you have read, understood, and agreed to the terms of this Privacy Policy. If you do not agree, please do not use the Service.
1. Categories and Purposes of Personal Data Collected
Pursuant to Article 8 of the Personal Data Protection Act, I hereby inform you of the following:
| Data Category | Specific Items | Purpose of Collection |
|---|---|---|
| Identifiers (C001) | Name, email, phone number, organization, job title, account identifier | Account registration, authentication, profile, and service communications |
| Photos and User Content | Optional avatar, event logo or cover, business-card image, and digital-card content | Displaying profile and event content, optional card recognition, and card exchange |
| Social Activities (C061) | Registration, invitation response, approval, waitlist, check-in, seating, agenda, and team-permission records | Event management, admission passes, check-in, and collaboration |
| User Content and Optional Sensitive Data | Custom registration answers, dietary preferences and allergy information, survey responses, organizer or exhibitor roster notes, and lead records | Registration, catering arrangements, event operations, surveys, and in-person networking |
| Purchases and Entitlements | App Store product, purchase, and subscription-entitlement status | Paid plans, event add-ons, and Restore Purchases |
| Product Interaction | Invitation opens, registration status, pass views, check-in, and feature-operation records | Event funnel reporting, app functionality, and abuse prevention |
| Device Information | Device type and push notification token | Event reminders and organizer updates |
Collection Methods: Through information you actively provide within the App, authorization via third-party sign-in (Apple ID, Google Account), or attendee lists imported by event organizers.
2. Duration, Region, Recipients, and Methods of Personal Data Use
- Duration: Account and user data is generally retained until you delete your account, an organizer deletes the relevant event, or it is no longer needed to provide the Service. Account deletion removes your account, events you host, cards, and related user data. To preserve another organizer's aggregate attendance statistics, your participation record in their event is unlinked from your account and de-identified. Limited records may be retained where reasonably necessary for legal obligations, security, fraud prevention, dispute resolution, or backup cycles.
- Region: Data may be processed by me and the cloud providers listed below in Taiwan or in countries and regions where those providers operate data centers, subject to reasonable cross-border transfer and security safeguards.
- Recipients:
- The Service's operations team (limited to the scope necessary for providing the Service)
- Event organizers (limited to registration and check-in information for their respective events)
- Other users with whom you consent to exchange business cards (only upon mutual QR code scanning consent)
- Methods: Processed through automated means with encrypted transmission and access control measures.
3. Third-Party Services
The Service uses the following third-party services, each with its own privacy policy:
- Supabase (data storage, authentication) — Privacy Policy
- Apple (Sign in with Apple) — Privacy Policy
- Google (Google Account sign-in) — Privacy Policy
- Google Places (venue search text you enter and venue data you select) — Privacy Policy
- Expo (push notification service) — Privacy Policy
- RevenueCat (in-app purchase and subscription management) — Privacy Policy
- Anthropic (optional business-card image recognition) — Privacy Policy. Only when you choose to use recognition, the card image is sent to its API to extract contact information and return the result.
I will not sell, rent, or exchange your personal data to any third party other than those listed above.
4. Data Security Measures
In accordance with Article 12 of the Enforcement Rules of the Personal Data Protection Act, I implement the following security measures:
- All data transmission is encrypted using HTTPS/TLS
- Database access is controlled via Row Level Security (RLS)
- Passwords and sensitive data are hashed and never stored in plaintext
- Security measures are periodically reviewed for adequacy
5. Data Breach Notification
In the event of a personal data breach, I will notify affected users within 72 hours of becoming aware of the incident, via App push notification or email, and report to the competent authority in accordance with the Personal Data Protection Act. The notification will include: the facts of the breach, the categories of data affected, response measures taken, and recommendations for users to protect themselves.
6. Data Subject Rights
Pursuant to Article 3 of the Personal Data Protection Act, you have the following rights regarding your personal data:
- To inquire about or request access to your data
- To request a copy of your data
- To request supplementation or correction
- To request cessation of collection, processing, or use
- To request deletion
You can edit data, manage notifications, or permanently delete your account from the "Me" page in the App. You may also email crucify0202@gmail.com with a request. I will respond within 30 days of receiving it.
Exercising any of the above rights is free of charge.
7. Consequences of Not Providing Personal Data
You are free to choose whether to provide personal data. If you choose not to provide it, the following impacts may occur:
- Not providing Email: Unable to register an account or use the Service
- Not providing name/organization/job title: Business card exchange feature will not display complete information
- Not authorizing push notifications: Unable to receive event reminders
8. Cookies and Tracking Technologies
The App does not use cookies. The web component (event registration pages) uses only essential cookies to maintain proper functionality. No advertising tracking or behavioral analytics is performed.
9. Protection of Minors
The Service is not directed at children under the age of 13. I do not knowingly collect personal data from children under 13. If a parent or guardian discovers that their child has provided personal data without consent, please contact me and I will promptly delete it.
Minors under the age of 18 must obtain consent from a legal guardian before using the Service.
10. Amendments to This Privacy Policy
If this Policy is amended, I will publish the updated effective date on this page. Material changes will be communicated via App push notification or email. If you do not agree with the amendments, you may delete your account and discontinue use of the Service before the amendments take effect. Continued use of the Service after the amendments become effective constitutes your acceptance of the revised Policy.
11. Contact Information
Data Controller: Cheng-I Wu
Email: crucify0202@gmail.com
If you believe the Service has violated any provisions of the Personal Data Protection Act, in addition to contacting me, you may also file a complaint with the National Development Council or your local government.