LuveDay

Privacy Policy

Last Updated: August 21, 2026

Young Dai Zi Innovation ("we," "our," or "us") is the Data Controller committed to protecting your privacy. This Privacy Policy explains how we collect, use, store, and safeguard your information when you use the LuveDay application (the "App").

By creating an account or using LuveDay, you agree to the collection and use of information in accordance with this policy.


1. Information We Collect

We collect only the information necessary to provide our services, improve performance, and ensure security.

1.1 Account Information

To create an account and verify your identity, we collect:

1.2 End-to-End Encrypted Content (Zero-Knowledge)

To ensure absolute privacy, LuveDay utilizes End-to-End Encryption (E2EE). The following user content is encrypted on your device before being transmitted to our servers, meaning we have zero technical ability to read, view, or access it:

1.3 Encryption Metadata

While the contents of your messages, files, events, and finance entries are completely encrypted, certain non-content data (metadata) must remain visible to our servers to route communication, handle sync, and maintain audit integrity across your devices. We process:

This metadata does not contain any readable personal content or message text.

1.4 Finance Tracker Data Security

Your finance records are end-to-end encrypted on your device before transmission.

Important: We DO NOT collect or process bank account numbers, credit card numbers, or online banking login credentials. We do not connect to banking APIs or financial institutions.

1.5 Device & Security Information

We collect non-personal technical data to troubleshoot issues and improve App stability:

1.6 What We DO NOT Collect

To protect your privacy, we strictly do not collect:

1.7 App Permissions

To provide specific features, LuveDay may request access to:

You can revoke these permissions at any time in your device settings.

2. How We Use Your Information

We use the collected data for the following purposes:

Strict No-Sale Policy: We do not sell, trade, or rent your personal data to third parties for marketing purposes.

3. Data Retention

We retain your data only as long as necessary to provide our services, resolve disputes, and comply with legal or security obligations.

Data Type Active Retention Period Post-Deletion Retention Window
Encrypted Content (Messages, Media, Events, Finance) Stored while active until you manually delete entries or request account deletion. Encrypted payload and media files are scrubbed immediately from active storage; residual metadata is completely purged within 30 to 90 days.
Account Profile Info Retained while your account is active. Deactivated immediately upon account deletion request; fully purged within up to 90 days.
Security & Audit Logs Up to 90 days for fraud prevention and stability monitoring. Automatically purged on a rolling 30-to-90-day cycle.

3.1 Item-Level Deletion

When you manually delete an individual message, media file, calendar event, or finance entry within the App, the encrypted payload and associated cloud storage files are erased immediately. Non-content metadata (e.g., record IDs and deletion flags) is retained for up to 90 days to maintain multi-device sync and system logs before being automatically purged.

4. Third-Party Services

We use trusted third-party service providers to help us operate LuveDay. These providers process data on our behalf and are subject to strict confidentiality and security obligations.

4.1 Cloud Infrastructure

We use Amazon Web Services (AWS) for secure data hosting and server infrastructure. Third-party infrastructure hosts only your encrypted data payloads and metadata; they have no structural capability to read your encrypted content.

4.2 Communication Services

We use third-party email providers to send verification emails and support communications.

International Data Transfers

Your information, including personal data, is processed at our operating offices and in any other places where the parties involved in the processing are located (including AWS servers). This means that this information may be transferred to—and maintained on—computers located outside of your state, province, country, or other governmental jurisdiction where the data protection laws may differ from those from your jurisdiction.

5. Security

We take the security of your data seriously. We implement reasonable administrative, technical, and physical security measures to protect your personal information from unauthorized access, disclosure, or destruction.

However, please be aware that no method of transmission over the internet or method of electronic storage is completely secure. Therefore, while we strive to protect your data, we cannot guarantee its absolute security.

5.1 Cryptographic Security & Key Management

To preserve end-to-end security, your account's cryptographic private keys are saved on our database in an encrypted format. They are encrypted locally on your device using a key derived from your account password or recovery keys before being transmitted.

Because your recovery keys are never stored on our servers, we do not possess the key to decrypt your private key. If you lose access to your recovery keys, we cannot recover or decrypt your end-to-end encrypted messages, files, calendar events, or finance records.

5.2 Data Breach Notification

In the event of a personal data breach, we will notify the Personal Data Protection Commissioner of Malaysia within 72 hours. If the breach is likely to result in a high risk to your rights and freedoms, we will notify you without unnecessary delay. Note that because your content is end-to-end encrypted, a server breach would still protect your actual message text, files, calendar events, and finance entries from being read by unauthorized parties.

6. Your Rights

Depending on your jurisdiction, you may have specific rights regarding your personal data, including:

7. Account Deletion

You may delete your account at any time within the App settings or by following our Account Deletion Guide.

When you request account deletion, the deletion process begins immediately. Complete erasure across all production systems and offline system backups takes up to 90 days to fully process due to automated backup overwrite cycles and data safety protocols.

During the account deletion process, the following steps occur:

Please Note: Once account deletion is initiated, the process cannot be cancelled or reversed, and deleted encrypted data cannot be recovered by us.

8. Children's Privacy

LuveDay is not intended for use by children under the age of 16. We do not knowingly collect personal data from children under 16 during account creation.

Due to our End-to-End Encryption (E2EE) architecture, we have zero access to user-generated content inside the App. If a parent or guardian discovers that a child under 16 has created an account, please contact us at contact@youngdaizi.com, and we will promptly delete the account and purge all associated cryptographic keys.

9. Changes to This Privacy Policy

We may update this policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the "Last Updated" date. You will be deemed to have accepted such policy changes by continuing to use the Service, so do review it frequently.

Governing Law

This Privacy Policy shall be governed and constructed in accordance with the laws of Malaysia, without regard to its conflict of law provisions.

10. Contact Us

If you have any questions or concerns about this Privacy Policy, please do contact us: contact@youngdaizi.com