Welcome to Lavo, the real-time video social and matching platform built for genuine face-to-face connection. This Privacy Policy (“Policy”) explains how Lavo (“we,” “our,” or “us”) collects, uses, stores, shares, and protects your personal information when you use our mobile application and all related services (collectively, the “Service”). By using Lavo, you agree to this Policy. If you do not agree, please do not use the Service.
When you create a Lavo account, we collect the information you provide: display name, email address, date of birth (to verify you are 18 or older), profile photo, gender (optional), country of residence, and any personal bio or interest tags you choose to add. If you register via Apple Sign-In or Google, we receive a limited profile dataset authorized by you and that provider.
We automatically collect device model, operating system version, unique device identifiers, IP address, mobile carrier, app version, crash logs, and performance diagnostics. This data is used to maintain service quality and diagnose technical issues.
When you participate in a video call, we collect session metadata: call initiation timestamp, end timestamp, call duration, connection quality metrics (packet loss, latency, resolution), device and network type, and whether a safety report was submitted during or after the session. We do not record or store the content of video calls. See Section 3 for full details.
You may optionally set matching preferences including preferred gender and age range. This data is used exclusively to operate the matching algorithm and is not shared with advertisers or third-party data brokers.
We record how you use the Service: features accessed, call acceptance and skip patterns, session frequency and duration, content interactions, and search queries. This informs product improvements and recommendation systems.
Profile photos, profile videos, or other content you upload to your public profile are collected and stored. See Section 5 for full UGC details.
If you contact support, submit a user report, or complete a survey, we retain the content and metadata of those communications for resolution and product improvement purposes.
All payments are processed by Apple App Store or Google Play. We do not store your payment card details. We receive only anonymized transaction confirmation tokens and purchase entitlement data to activate in-app features.
We use your information to authenticate your account, facilitate video calls and matching, enforce community standards, process purchases, and deliver all core Service functions.
Your profile data, stated preferences, behavioral history, and safety eligibility signals are used to connect you with compatible users in real time. See Section 4 for full matching details.
We process session metadata, behavioral patterns, and user reports to detect and prevent harassment, policy violations, and prohibited conduct. Real-time safety signals protect users during calls without accessing call content.
Aggregated, de-identified usage data is analyzed to improve matching accuracy, call quality, and platform performance. Individual behavioral data is not shared externally for research purposes.
With your consent where required by applicable law, we may send promotional communications. You may withdraw consent at any time via in-app settings or email unsubscribe.
We process personal data as necessary to comply with applicable laws, respond to legal process, enforce our Terms of Service, and protect user safety.
Live video calls on Lavo are powered by encrypted RTC (Real-Time Communication) infrastructure using SRTP (Secure Real-Time Transport Protocol) and DTLS encryption. Your video and audio streams are transmitted peer-to-peer via encrypted relay nodes. Lavo employees cannot access the content of live call streams.
Lavo does not record, store, or analyze the content of live video calls for any purpose, including advertising, AI training, or user profiling. The sole exceptions are: (a) where a safety report filed during or immediately following a call triggers a limited safety review process in which a session fragment may be retained exclusively for that review; and (b) any opt-in clip feature you explicitly activate, which will be clearly disclosed at point of use.
While call content is not stored, the following session metadata is collected and retained for up to 12 months for safety enforcement and technical diagnostics:
- Call start and end timestamps
- Call duration
- Connection quality metrics (resolution, packet loss, latency)
- Device model and network type used during the call
- Whether a user report was submitted during or after the session
Lavo requests camera and microphone access at first use of the video call feature, governed by your device operating system's permission controls. You may revoke these permissions at any time in device settings, though doing so will prevent participation in video calls. Lavo does not access your camera or microphone outside of active call sessions.
Our RTC relay infrastructure is provided by third-party operators who process encrypted signaling and relay data as technical intermediaries under data processing agreements prohibiting independent use of your data. Details available at service@lavo.run.
To deliver low-latency calls, Lavo routes your call through the RTC relay node geographically closest to your current location at the time of the call. This means call signaling data may be processed in a region that differs from your country of residence, subject to appropriate data transfer safeguards described in Section 12.
Lavo's matching algorithm connects you with other online users based on your stated preferences (gender, age range, language), your behavioral signals within the app (acceptance rates, session quality feedback, skip patterns), and safety eligibility (users with active enforcement actions have reduced or suspended matching eligibility). The algorithm is tuned to improve connection quality and minimize exposure to users flagged for safety concerns.
Matching preference data is used exclusively to operate and improve the matching system. It is not used for external advertising, shared with data brokers, or sold to third parties. You may update or clear matching preferences at any time in profile settings.
We retain a record of your match history (matched user identifiers, session outcomes, timestamps) for up to 12 months for the purposes of improving matching accuracy, preventing re-matching with blocked or reported users, and supporting safety enforcement. Match history is not visible to other users.
Lavo maintains an internal trust score for each account derived from behavioral history, reports received, content moderation outcomes, and engagement patterns. This score affects matching eligibility and the priority of safety reviews. It is not shared externally or visible to other users.
When you block or report a user, that action is recorded to prevent future matches with that individual and to inform our safety review process. Your identity as the reporting user is kept confidential from the reported party.
Profile photos, profile videos, and any other content you upload to Lavo are stored on our secure cloud servers and associated with your account. You retain ownership of all original content you create.
By submitting UGC, you grant Lavo a non-exclusive, worldwide, royalty-free, sublicensable license to host, store, reproduce, display, and distribute your content within the Service and in connection with marketing the Service, subject to your privacy settings. This license persists for a commercially reasonable period following account deletion.
Photos and videos you upload may contain embedded geolocation metadata (EXIF data). Lavo automatically strips all geolocation EXIF data from uploaded media before it is made publicly visible, protecting your physical location from disclosure through your content.
Profile images and other UGC are reviewed using automated scanning and human review for compliance with our Community Guidelines. Prohibited content including nudity, deceptive imagery, and hate material will be removed. Repeat violators may face account suspension or termination.
Deleted UGC is removed from public display within 48 hours, from production servers within 30 days, and from backup archives within 90 days. Content flagged for active safety review may be retained for the duration of that review.
Lavo may use your interaction history, stated interests, and behavioral signals to personalize in-app features such as suggested users and notification relevance. Personalization improves your in-app experience and is not used for third-party advertising targeting.
You may disable personalized features at any time in Settings > Privacy > Personalization. Core matching functionality is not affected by this setting.
We share personal information with trusted third-party service providers: cloud infrastructure, RTC relay operators, payment processors, analytics platforms, customer support tools, and content moderation systems. All providers are contractually bound to process your data only on our instructions and in compliance with applicable data protection law.
We do not sell your personal information. We do not share your data with advertisers, data brokers, or third-party marketing platforms for their independent commercial use.
In the event of a merger, acquisition, or asset sale, your personal data may transfer to the acquiring entity. We will notify you in advance before your data becomes subject to a materially different privacy policy, giving you the opportunity to request account deletion.
We may disclose your information to law enforcement or government authorities when required by applicable law, valid legal process, or where necessary to protect the life or safety of any person. Where legally permitted, we will notify affected users prior to disclosure.
Where we identify an immediate threat to the life or physical safety of a person, we may proactively share relevant information with law enforcement without awaiting formal legal process. Such disclosures are documented internally and subject to our legal review process.
Your display name and profile photo are visible to other Lavo users as part of the matching experience. You may update or remove your profile photo at any time from your account settings.
Live video functionality relies on third-party RTC providers that process encrypted signaling and relay data as technical intermediaries. They are bound by data processing agreements prohibiting independent access to your data or call content.
Mobile analytics SDKs measure app performance and feature engagement. These SDKs operate in privacy-preserving modes including anonymized event collection and suppression of advertising identifiers absent user consent.
Third-party AI-assisted content safety tools scan UGC for prohibited material. These tools process only the data necessary for safety review under strict confidentiality and data minimization obligations.
Apple Sign-In and Google authentication are governed by their own terms and privacy policies. Our use of data from these services is limited to account authentication and basic profile creation.
We retain personal information for as long as your account is active. Accounts with no login activity for 24 consecutive months will receive a dormancy notice, after which inactive data may be anonymized or deleted.
Session metadata is retained for up to 12 months for technical diagnostics and safety enforcement, after which it is anonymized or deleted.
Records of user reports, moderation actions, and enforcement decisions are retained for up to 36 months after account closure to support appeals, pattern analysis, and legal defense.
Financial transaction records are retained for a minimum of seven years to comply with applicable accounting, tax, and consumer protection obligations.
Aggregate, irreversibly anonymized data may be retained indefinitely for product research and development.
We implement TLS 1.2+ for all data in transit, SRTP/DTLS encryption for all video and audio streams, AES-256 encryption for sensitive data at rest, strict role-based access controls, and automated anomaly detection for unusual access patterns.
Data access is need-to-know, requires multi-factor authentication, and is subject to comprehensive audit logging. All personnel with data access undergo data protection training and sign confidentiality agreements.
We conduct regular security assessments and third-party penetration testing. Responsible disclosure: report security vulnerabilities to service@lavo.run.
In the event of a personal data breach posing risk to your rights and freedoms, we will notify relevant supervisory authorities within 72 hours where required by law and inform affected users without undue delay.
The Lavo app uses session tokens, local storage, and analytics SDKs (not traditional browser cookies) to maintain your authenticated session, remember preferences, and measure feature engagement.
On iOS, we request ATT consent before accessing your IDFA. On Android, we respect your opt-out via device settings. Advertising identifiers are used only to measure our own user acquisition campaigns and are not shared for third-party behavioral advertising.
Our website may use standard browser cookies for session management and analytics, manageable via browser settings.
Lavo operates infrastructure across multiple regions. Your data may be transferred to and processed in countries other than your country of residence, which may have different data protection standards.
For transfers from the EEA, UK, or Switzerland to countries lacking an adequacy decision, we rely on EU Standard Contractual Clauses (SCCs) and, where applicable, the UK International Data Transfer Addendum (IDTA). Equivalent safeguards apply to other cross-border transfers.
Due to real-time video delivery requirements, call signaling and relay data are routed through the geographically closest available relay node, which may differ from your country of residence. All such processing is governed by the transfer safeguards described above.
Request a copy of personal data we hold via in-app settings or by emailing service@lavo.run with subject “Data Access Request.”
Correct inaccurate information in account settings or by contacting us. We action corrections within 30 days.
Request account and data deletion via Settings > Account > Delete Account or by emailing us. See Section 20 for full deletion details.
Object to or request restriction of processing in certain circumstances. We pause relevant processing while assessing your objection.
Where processing is based on consent or contract and automated, request your data in a structured, machine-readable format for transfer to another service.
Withdraw consent for marketing or personalization at any time via in-app settings or by contacting us, without affecting prior lawful processing.
Email service@lavo.run with “Privacy Rights Request” in the subject, your registered email, and a description of your request. We verify your identity and respond within applicable legal timeframes.
For EEA and UK users, Lavo acts as data controller under the GDPR and UK GDPR respectively.
We process your data under: (a) contractual necessity; (b) legal obligation; (c) legitimate interests (safety, fraud prevention, service improvement), where not overridden by your rights; and (d) consent (for marketing and optional personalization).
You may lodge a complaint with your national data protection supervisory authority if you believe your data has not been handled lawfully. We encourage direct contact first.
California residents have rights under CCPA as amended by CPRA including the right to know, delete, correct, and opt out of sale or sharing. Lavo does not sell personal information and does not share it for cross-context behavioral advertising.
Exercising California privacy rights will not result in denial of services, different pricing, or reduced service quality.
California residents may designate an authorized agent by providing written proof of authorization. We verify both agent and resident identity before processing any request.
Brazilian users have rights under the Lei Geral de Protecao de Dados (LGPD) including confirmation, access, correction, anonymization, deletion, portability, and withdrawal of consent.
We process Brazilian users' data based on contract performance, legal obligation, and consent where applicable. We do not rely on legitimate interests alone to process sensitive data categories of Brazilian users.
Brazilian users may lodge complaints with the Autoridade Nacional de Protecao de Dados (ANPD) where they believe data processing violates the LGPD.
Lavo is designed exclusively for users 18 years of age or older. We implement date-of-birth verification at registration and apply supplementary detection measures to accounts suspected of being operated by minors. Accounts confirmed to belong to users under 18 are immediately and permanently terminated with all associated data deleted.
If you are a parent or guardian and believe a minor has created a Lavo account, contact us immediately at service@lavo.run. We will investigate and, where confirmed, permanently delete the account and all associated data without delay.
We deploy hash-matching systems on all UGC, AI-assisted behavioral detection on session metadata patterns, and dedicated human safety reviewers monitoring for CSAE signals. Upon confirmed detection or credible report: all associated content is immediately and permanently removed; the responsible account is permanently terminated and all associated device identifiers and IP addresses are blocked; a mandatory report is filed with the NCMEC CyberTipline or the legally required equivalent national authority; and we cooperate fully and proactively with all resulting law enforcement investigations, including preserving and producing records as legally required.
CSAE-related terminations carry no right of appeal.
To report suspected CSAE: use the in-app Report function on any profile or call screen, or email service@lavo.run immediately with subject “CSAE Report.” These reports are our highest-priority safety matter.
We conduct regular audits of child safety policies, collaborate with recognized child safety organizations, and continuously update detection capabilities in line with evolving best practices and legal requirements.
All in-app purchases are processed exclusively through Apple App Store or Google Play. Lavo does not store payment card details. We receive only anonymized transaction confirmation tokens and purchase entitlement data.
If Lavo offers virtual currency: (a) it has no cash value; (b) it is non-transferable between accounts; (c) it is non-refundable except as required by applicable law or app store policy; (d) it may expire per terms disclosed at purchase; and (e) it may be forfeited upon account termination for cause.
Transaction records are retained for a minimum of seven years to satisfy accounting, tax, and consumer protection obligations.
Lavo may send push notifications for incoming match or call requests, social interactions, feature announcements, and account security alerts.
Control notification types in Settings > Notifications or via device OS settings. Disabling all notifications may cause you to miss important security alerts.
Transactional emails (account confirmations, security alerts, purchase receipts) are essential for Service operation and cannot be unsubscribed from while your account is active. Marketing emails are optional and may be unsubscribed from at any time.
Delete your account via Settings > Account > Delete Account, or email service@lavo.run with subject “Account Deletion Request.”
Your profile and public content are removed from view within 48 hours. Personal data is deleted from production servers within 30 days. Backup archives are purged within 90 days of the next scheduled rotation.
Certain data is retained where required by law: transaction records (up to 7 years); safety and moderation records (up to 3 years); data subject to a legal hold. Retained data is isolated and used only for the specific purpose requiring retention.
Lavo operates real-time safety monitoring that analyzes session metadata and behavioral signals — not call content — to detect indicators of abusive or prohibited conduct during matching and video sessions. These systems may interrupt sessions or flag accounts exhibiting prohibited behavior patterns.
Each account carries an internal trust score based on behavioral history, reports received, and moderation outcomes. This score affects matching eligibility and safety review priority. It is not visible to other users or shared externally.
You may report another user at any time during or after a call via the in-app reporting function. Your identity as the reporting user is kept confidential from the reported party.
This Policy is governed by applicable international data protection law and the laws of the jurisdiction in which Lavo is incorporated, except where mandatory local law in your country of residence imposes higher standards that cannot be contractually excluded.
If our response to a direct complaint has not resolved your concern, you retain the right to escalate to the relevant data protection supervisory authority in your country of residence.
Material changes are communicated at least 14 days before taking effect via in-app notice, push notification, and/or email. Non-material corrections may be made without advance notice.
Continued use of Lavo after any revised Policy's effective date constitutes acceptance. If you do not accept changes, delete your account before they take effect.
Prior versions are available on request at service@lavo.run.
For questions, data rights requests, or privacy concerns:
- Email: service@lavo.run
- Subject: “Privacy Inquiry — [Your Name]”
We acknowledge inquiries within 5 business days and respond within 30 days.
Use the in-app Report function on any profile or call screen, or email service@lavo.run immediately with subject “CSAE Report.” These are our highest-priority safety matter, actioned without delay.