Privacy
Luau privacy policy.
Last updated: October 2, 2026
Luau Digital, Ltd. ("Luau," "we," "our," or "us") respects your privacy. This policy explains what data we collect, why we collect it, how we share it, and the choices you have.
If you have any questions about this policy or our practices, email us at privacy@luau.co.
1. Who we are
Luau Digital, Ltd.
1975 Hickory Road
Vestavia Hills, AL 35216
United States
privacy@luau.co
We operate the Luau iOS app and the Luau website at luau.co. This policy covers both unless we say otherwise.
2. Information we collect
We collect only what we need to run Luau and the features you use.
Account & contact
- Phone number — required. We use SMS one-time codes to sign you in, and for opt-in event reminders.
- Name — required. Shown to people you host or invite.
- Email address — optional. Used for account recovery and important service emails (e.g., changes to this policy).
- Profile photo — optional. You upload it; we host it on Cloudinary (see "Service providers" below).
Event content (User Content)
- Event titles, descriptions, dates, times, locations, cover images, RSVPs, and any details you add to events you host or attend.
- AI conversations with Kai (our event-planning assistant). Your messages are sent to OpenAI to generate responses and event drafts (see "Third-party AI" below).
Device & technical
- Device type, OS version, and app version (for troubleshooting and crash reports).
- Network metadata (IP address, request timestamps) used to deliver the service and detect abuse.
- Universally unique account identifier (your Luau user ID). We do not use Apple's Identifier for Advertisers (IDFA).
PartyPass (NFC chips)
PartyPass is an NFC tag a host places at a venue or hands out. Tapping one opens the event to RSVP or, once the event is starting, to check in. When you tap:
- Tap verification — we receive the chip's unique identifier (UID), a cryptographic message authentication code (CMAC), and an optional tap counter. We use these solely to verify that the tap is authentic and to refuse replayed or copied links. Each tap is logged against the chip with the time, the event it was assigned to, and the IP address and browser identifier (user agent) of the phone that tapped.
- Access grants and the device key — each tap creates an access grant for that event that only works from the phone that tapped, so a tap link can't be forwarded. To enforce this we compute a device key: a one-way hash (SHA-256) of your phone's browser identifier and IP address. The key is stored on the access grant, scoped to that one event, and compared again when you RSVP or check in through the grant. It is not a hardware identifier, we do not use it to recognize you across events or apps, and we do not use it for advertising or analytics.
- RSVP time limit — if the host set an RSVP time limit, the grant records the deadline and when you submitted your RSVP so the countdown can be enforced.
- Check-in — when a host turns on check-in, a tap during the check-in window records a check-in: your account, the event, the time, the check-in method (PartyPass tap, location, or added by the host), whether you confirmed it, and, on multi-day events, the day. If your phone shares a location fix at that moment, the check-in also stores the location proof described under "Location" below. Hosts and co-hosts can see who checked in, when, and how, and can add or remove a check-in for a guest.
Location (optional)
Luau does not collect your location unless you turn it on. There are two separate, permission-gated uses, and both require you to grant location access to Luau in your phone or browser first.
Location check-in (per event). A host can turn on Location Check-in for an event with a mappable address. Only for those events, only if you RSVP'd, and only during the event's check-in window (from up to four hours before the start until the event ends), Luau collects:
- Check-in position — the latitude, longitude, and accuracy of the fix your device shares when you check in, plus the computed distance from the event address. Luau uses this to confirm you are at the event (within roughly 150 meters).
- Presence samples — in the Luau iOS app, once you've allowed location for Luau, the app checks about every five minutes while it is open during the window. If you also allowed location Always and turned on location personalization (below), it can additionally watch a roughly 200-meter area around the venue so arriving with the app closed still counts. Each sample sent to Luau records your position, its accuracy, the distance from the venue, and the time. The first sample at the venue records you as nearby and sends a "Looks like you're here" nudge; confirming it upgrades your check-in. Luau refuses samples outside the window, for events without location check-in, or from guests who haven't RSVP'd, so nothing is stored in those cases. This is not a movement log.
- In a browser, location check-in is manual: the check-in page asks for your location once, when you tap check in.
Location personalization (account-wide, iOS only). The iOS app can learn the areas where you spend time so suggestions fit your life. This is off until you accept Luau's own location screen (which records your opt-in) and grant the iOS location permission; either alone is not enough. When on, the app sends a handful of low-frequency snapshots per day (three on weekdays, five on weekends, enforced on our servers), each with your position, its accuracy, and the local date. When you compose a hangout, the app may take one extra fix per hour to answer "who's close by right now." Luau uses these samples to rank who appears nearby and free when a friend who has you in their crew composes a hangout, and it uses your friends' samples the same way when you compose one. The person composing sees only a coarse bucket (roughly within 2 miles or within 10 miles), never coordinates or the time of a sample.
Your controls. You can turn location off for Luau at any time in iOS Settings → Privacy & Security → Location Services → Luau, or in your browser's site permissions; Luau stops collecting immediately. To withdraw the location personalization opt-in or have stored samples removed, email privacy@luau.co. Location data is never sold, never shared with advertisers, and never sent to OpenAI.
Google Calendar (optional integration)
- If you choose to connect Google Calendar, we receive read access to your calendar's free/busy times and the ability to create, update, and delete events you make through Luau. We never read the content of calendar events you didn't create through Luau.
- Use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not use Google Calendar data to train AI, build user profiles, or sell to third parties.
Things we don't collect
- We do not collect location unless you turn it on, and only as described under "Location" above. We never collect it in the background for events you didn't RSVP to or outside an event's check-in window.
- We do not access your contacts.
- We do not access your microphone.
- We do not use third-party advertising networks. There are no ad SDKs in the Luau iOS app.
- We do not use cross-site or cross-app tracking. Apple's App Tracking Transparency prompt is not shown because we do not track.
3. How we use your information
| Purpose | What we use |
|---|---|
| Operate the app and your account | Phone, name, email, account ID |
| Deliver event reminders and updates | Phone (SMS), event content |
| Power AI-assisted event planning ("Kai") | Your prompts and event drafts |
| Verify PartyPass access | Chip UID + CMAC, tap log, per-event device key |
| Record and verify event check-ins | Check-in records, check-in position, presence samples (only when location check-in is on) |
| Suggest hangouts near you (if you opted in) | Ambient location samples |
| Sync with your Google Calendar (if connected) | Calendar free/busy + Luau events you create |
| Detect abuse, fraud, and policy violations | Network metadata, content reports |
| Comply with legal obligations | Whatever the law requires |
| Improve the product | Product usage events linked to your account; aggregated, de-identified usage |
We do not sell your personal data. We do not share your data for cross-app or cross-site behavioral advertising.
4. Service providers (third parties who process data on our behalf)
We share the minimum necessary data with the following service providers. Each is contractually required to keep your data confidential and use it only to perform the service we hired them for.
| Provider | What they do | Data shared |
|---|---|---|
| Clerk | Authentication (phone OTP) | Phone, name, email |
| Cloudinary | Image hosting (profile photos, event covers, AI-generated images) | Image files + image metadata |
| OpenAI | Powers Kai's event drafting and image generation | Your Kai messages, event drafts, image prompts. Per OpenAI's API terms, OpenAI does not use Luau API data to train its models. |
| AWS End User Messaging (formerly Amazon Pinpoint SMS) | Sends SMS event reminders | Phone, message body |
| Resend | Sends email (invitations, reminders, event updates) | Email address, message content |
| AWS Rekognition | Automated content moderation on uploaded and AI-generated images | Image files |
| Google Calendar API | Calendar sync (only if you opt in) | Calendar free/busy + Luau events you create |
| Inngest | Schedules background jobs (invites, reminders, notifications) | Account and event IDs; for messaging jobs, the recipient's phone or email and the message content |
| PostHog | Product analytics | Account ID, name, email, usage events, device and network metadata |
| Slack | Internal team notifications (new signups, new events and RSVPs, abuse reports, errors) | Name, email or phone, event titles |
| Stripe | Processes Luau Plus preorder payments on Stripe's hosted checkout page | Payment details you enter at checkout |
| Vercel | Hosting infrastructure | All app traffic |
| Supabase (PostgreSQL) | Database hosting | All persisted application data |
5. Third-party AI (Kai)
Luau uses OpenAI as its AI provider. Several features in the app send data to OpenAI on your behalf:
- Event drafting and editing: when you ask Kai to create or revise an event, your typed prompt and the event's title, description, date, and location are sent to OpenAI.
- Cover-art generation: when you tap Generate Image — on a new event, or when changing the image on an existing one — your prompt and any reference image are sent to OpenAI's image API.
- Potluck suggestions: when you ask Kai what to bring to a potluck, the event's details and the names of guests who have already claimed items are sent to OpenAI.
Consent. The first time you reach any of the surfaces above, Luau shows you a consent sheet that lists exactly what is sent and to whom. Nothing leaves Luau until you tap Use Kai. If you decline, the manual flows (manual event form, manual potluck list, upload your own image) remain available. You can change your choice any time under Profile → AI Assistant in the iOS app, or under Profile → AI Assistant on app.luau.co.
Retention and training. OpenAI's API terms prohibit OpenAI from using Luau-submitted data to train its models. OpenAI may retain prompts and outputs for up to 30 days for abuse monitoring, after which they are deleted. See OpenAI's API data usage policies for details.
What we do not send to OpenAI: your phone number, email address, password or sign-in credentials, calendar contents, location samples or check-in positions, full guest lists for events you didn't ask Kai about, or your aggregated social-graph data.
6. SMS messages
When you opt in (typically by RSVPing or accepting an event invite), Luau sends event-related SMS messages such as confirmations, guest updates, and reminders.
- Frequency: up to 10 messages per event.
- Cost: standard message and data rates may apply.
- Opt out: text STOP to any Luau SMS at any time. You'll receive one final confirmation message.
- Help: text HELP or email support@luau.co.
- Eligibility: U.S. mobile numbers only. You must be 18 or older (or have parental consent) to receive SMS.
- Carriers: messages are sent via AWS End User Messaging. Supported carriers include AT&T, Verizon, T-Mobile, and others. Carriers are not liable for delayed or undelivered messages.
We do not share or sell your phone number or SMS opt-in status to any third party for marketing.
7. How long we keep your data
| Data | Retention |
|---|---|
| Account profile (name, phone, email, photo) | While your account is active, plus a 90-day grace window after deletion (see §9) |
| Event content (titles, descriptions, RSVPs) | While the host's account is active; deleted with the host's account |
| Kai conversation history | Until you delete the conversation in-app, or up to 18 months, whichever comes first |
| AI-generated images | While linked to an event you control, plus a 90-day grace window after event deletion |
| SMS delivery logs | 12 months for compliance and troubleshooting |
| Server logs (IP, request timestamps) | 90 days |
| PartyPass tap log (chip UID, time, IP, user agent) | Kept with the chip's history; deleted when the chip record is deleted |
| PartyPass access grants (incl. device key) | Kept with the event; deleted when the event is deleted |
| Check-in records, including check-in position | Kept with the event; deleted when the host deletes the event or removes the check-in |
| Presence samples (location check-in) | Kept with the event; deleted when the event is deleted. We do not currently run a separate scheduled purge for these samples. |
| Ambient location samples (location personalization) | While your account is active; removed on request (email privacy@luau.co) |
| Aggregated, de-identified analytics | Indefinitely |
8. Sharing and disclosure
We disclose personal information only:
- To service providers described in §4 to deliver the service.
- To other Luau users when you choose to share — for example, your name and profile photo are visible to people you host or invite, and your RSVPs are visible to event hosts and other invitees. If you check in to an event, the host and co-hosts see that you checked in, when, and how (tap, location, or added by host). If you opted in to location personalization, a friend composing a hangout may see that you appear nearby as a coarse bucket, never your coordinates.
- To authorities when required by law (subpoena, court order, valid legal process), to protect the safety of our users, or to enforce our Terms of Service.
- In a corporate transaction (merger, acquisition, asset sale). If this happens, we'll post a notice on luau.co before any change.
We never sell your personal data, and we never share it for cross-context behavioral advertising.
9. Account deletion
You can delete your account inside the Luau iOS app: Profile → More → Delete Account. You can also request deletion by emailing privacy@luau.co.
When you delete your account:
- Within minutes, your name, profile photo, and email are anonymized. You're signed out of every device and your account is no longer visible to other users.
- Your phone number is retained as a hashed identifier for 90 days so you can sign back in with the same number to restore the account if you change your mind. During this window your data is restorable but otherwise inaccessible.
- After 90 days, deletion is permanent. We purge your account profile, Kai history, AI images linked only to your account, and all data not required for legal retention.
Some data is retained beyond 90 days where required:
- Aggregate, de-identified analytics that can no longer be tied back to you.
- Event content you created that other users still depend on (e.g., shared event descriptions). The host attribution is anonymized.
- Records required for tax, legal, or fraud-prevention purposes (typically 7 years).
If you'd prefer to skip the 90-day grace window and delete immediately, email privacy@luau.co with the subject line "Immediate deletion."
10. Your privacy rights
Depending on where you live, you have one or more of the following rights:
- Access — request a copy of the personal data we hold about you.
- Correction — fix inaccurate or incomplete data.
- Deletion — delete your account and associated data (see §9).
- Portability — receive your data in a portable format.
- Opt-out of sale or sharing — we don't sell or share your data for cross-context behavioral advertising in the first place; this right is built into how we operate.
- Non-discrimination — we won't penalize you for exercising any of these rights.
To exercise any right, email privacy@luau.co. We respond within 30 days (or 45 if extended; we'll tell you).
California residents (CCPA/CPRA)
You have the rights listed above plus the right to know what categories of personal information we've collected, the categories of sources, business purposes, and categories of third parties we share with — all detailed in §2 and §4.
We do not sell or "share" personal information as those terms are defined under the CCPA/CPRA.
European Economic Area, United Kingdom, and Switzerland (GDPR / UK GDPR)
The legal bases on which we process your personal data are:
- Performance of a contract — to provide the service you signed up for.
- Legitimate interests — to keep the service secure, prevent abuse, and improve the product.
- Consent — where required (e.g., the optional Google Calendar integration, AI assistant, location check-in and location personalization).
- Legal obligation — where required by law.
You also have the right to lodge a complaint with your local data protection authority. We do not require you to use our service to provide unnecessary data.
11. International data transfers
Luau operates from the United States. If you use Luau from outside the United States, your data is transferred to and processed in the United States, where data protection laws may differ from your jurisdiction.
For users in the European Economic Area, United Kingdom, and Switzerland, transfers are made under the European Commission's Standard Contractual Clauses (SCCs) and applicable adequacy decisions.
12. Children's privacy
Luau is not directed to children under 13, and we do not knowingly collect personal information from children under 13. If you believe a child under 13 has provided personal information to us, email privacy@luau.co and we'll delete it.
If you are between 13 and 18, you must have a parent or guardian's permission to use Luau.
13. Security
We use TLS 1.2+ in transit, encryption at rest, scoped access controls, and routine audits to safeguard your data. No system is 100% secure; if you suspect unauthorized activity on your account, email security@luau.co immediately.
14. Changes to this policy
We may update this policy from time to time. If we make material changes, we'll notify you by SMS or in-app message, and update the "Last updated" date at the top. Continued use of Luau after a change means you accept the updated policy.
15. Contact
Privacy questions, data requests, or anything else:
Luau Digital, Ltd.
1975 Hickory Road
Vestavia Hills, AL 35216
United States
privacy@luau.co