Last updated: 14 September 2026
Bupbokmuk Lab Ltd ("we", "us") is the data controller for the personal data described in this policy. We are a company registered in England and Wales under company number 17292473, and we are registered with the Information Commissioner's Office (ICO) under registration number ZC191440.
For privacy questions: admin@localz.chat
The rest of this page is the detail behind those points.
Email address, display name, username, and password (stored as a one-way hash — we never see your plain-text password). Profile photo or avatar settings if you add one.
Date of birth — we ask for this once, at signup, to confirm you are old enough to use Localz (13+) and so we can apply extra protections to younger users' data. We store the date but never display it to other members.
Legal basis: Performance of a contract for your account details; for date of birth, our legitimate interest in age-appropriate design and meeting our obligations to child users.
Real-time location — when you share your GPS coordinates, we use them solely to check whether you are within a Hub's radius. This record becomes stale after 24 hours.
Hub visit history — when you are confirmed physically inside a Hub's geofence, we log that visit. This is visible to you under "My Places" in your profile and can be deleted at any time. Individual visit logs are automatically deleted 90 days after the visit, so "My Places" only ever reflects your last 90 days.
Saved places — location bookmarks you manually save.
Legal basis: Performance of a contract for real-time checks and your Places history; legitimate interests (anonymised only) for aggregate analytics.
Hub messages, feed posts, comments, direct messages, and uploaded images. Hub content is visible to members according to the Hub's access rules. Direct messages are visible only to participants.
Content in a public Hub may be shown publicly. Where a Hub is public, what you post in it — with the username you use there — may be displayed outside the app, for example on a public page about that area which anyone can read and which search engines can index. Treat anything you write in a public Hub as public. This never applies to your direct messages, or to Hubs whose access rules restrict who can see them.
Legal basis: Performance of a contract.
Where a Hub owner has enabled the AI Subroom Organisation feature, messages posted in that Hub may be processed by an AI model to group them into topic-based subrooms. Before any message content is sent to the AI model, user identifiers are replaced with anonymous labels (e.g. "User 1", "User 2") — no account details, name, or email address are included.
The AI model used is Google Gemini, operated by Google LLC. Message content sent for processing is subject to Google's Gemini API Terms. We have a data processing agreement with Google covering this use.
Legal basis: Legitimate interests — organising community discussions improves the experience for all Hub members and does not change who can read the content. You have the right to object to this processing at any time (see Section 4). Hub owners can also disable AI organisation for their entire Hub at any time.
XP, levels, login streaks, message counts, inventory, and notification status — these power the gamification features that are core to the service.
Legal basis: Performance of a contract.
Push notification token, app version, and OS version (iOS app). IP address received as part of standard HTTP traffic — not stored beyond security rate-limiting.
We also record the app version, build number, platform and OS version of the client you last signed in from, stored against your account. We use it to support you, to understand which versions are still in use, and to require an update if a released version turns out to be unsafe or broken. It is not used for advertising or profiling, and it is deleted when your account is deleted.
Diagnostics — if something errors, we send a diagnostic report to our error-monitoring provider (Sentry) to help us fix it. A report can include the technical details of the error, your account ID, and your IP address. We do not use Sentry to track your activity, and Session Replay (screen recording) is switched off.
Legal basis: Legitimate interests (operating a secure, reliable service).
We use what you do on Localz — the Hubs you join, what you open and post, the places you are near, your saved places — to decide what to show you and in what order: which Hubs and events come first in Explore, what gets suggested to you, which notifications are worth sending. Where the Service shows promoted content, that content may be selected and ranked the same way.
This is profiling under UK GDPR and it is automated, but it produces no decision with legal or similarly significant effects for you — it decides the order of a list, nothing more.
Legal basis: Legitimate interests — a local app is only useful if it puts the places and people near you first. You can object at any time (Section 4), and where the profiling relates to direct marketing we will stop on request, without exception.
Hub conversations are the raw material for local knowledge: what a topic concluded, what an area recommends, what is going on nearby. We produce this as aggregated, anonymised material about places — not about people. Names, handles and account identifiers are removed, and the result describes a neighbourhood rather than any individual.
Once material is genuinely anonymised it is no longer personal data under UK GDPR. We may use, publish or share it — including with partners — to build and fund the Service. Because it cannot be traced back to you, deleting your account does not remove it.
Data that can still be linked to you is a different thing, and having your name stripped off does not make it anonymous. Profile and behavioural data remains your personal data, we do not sell or rent it, and if we ever wanted to share that kind of data with a partner for their own purposes we would ask your permission first.
Legal basis: Legitimate interests in producing anonymised material from Hub content. UK GDPR does not apply to the anonymised result.
| Data | Retention |
|---|---|
| Account data | Until account deletion, plus 30 days in backups |
| Real-time location | Overwritten each update; deleted on account deletion |
| Hub visit logs | Automatically deleted 90 days after each visit |
| Messages and posts | Until deleted by you or a moderator. On account deletion they stay in the conversation, permanently detached from you (see below) |
| Uploaded images | Deleted when the message/post is deleted or on account deletion |
| Push tokens | Deleted on account deletion or logout |
| Last app version / build / OS | Overwritten at each sign-in; deleted on account deletion |
When you delete your account, all personal data is permanently deleted within 30 days, except where we are legally required to retain it.
Messages, posts and comments you left in a Hub are not deleted with your account. They are permanently detached from you: your account is erased, and what you wrote is re-attributed to an anonymous Deleted User label shared by everyone who has left. There is no record kept that could link it back to you — not your name, not your email, not an internal identifier — and we could not restore the link if we wanted to.
We do this because a conversation with its messages cut out is worse for everyone still in it: replies end up answering nothing, and the local knowledge built on top of it stops making sense. Once detached, the content describes a conversation rather than a person, so it is no longer your personal data.
If you want something you wrote gone as well, delete those messages before deleting your account — you can remove any message you posted at any time. Direct messages are different and are always deleted with your account: they are private and two-party, so there is no community for them to belong to.
We do not sell or rent your personal data. We share it only with the providers below, who act on our instructions and may not use it for their own purposes:
| Provider | Purpose |
|---|---|
| Amazon Web Services (AWS) | App hosting, database, file storage (EU/UK region) |
| Apple Inc. | Push notification delivery (APNs) |
| Google LLC (Gemini API) | AI organisation of Hub messages — content only, user IDs anonymised before sending |
| Nominatim / OpenStreetMap | Reverse geocoding — only coordinates sent, no personal data |
| Functional Software, Inc. (Sentry) | Error and performance monitoring. Receives diagnostic reports that may include your account ID and IP address. Data may be processed in the USA under Standard Contractual Clauses / the UK Addendum. |
We add providers as the Service grows, and keep this table current — material changes are notified in the app. Aggregated, anonymised insights that cannot identify you are not personal data; how those are produced and used is covered in Section 1.
| Right | What it means |
|---|---|
| Access | Request a copy of all data we hold about you |
| Rectification | Ask us to correct inaccurate data |
| Erasure | Ask us to delete your data ("right to be forgotten") |
| Restriction | Ask us to pause processing while a dispute is resolved |
| Portability | Receive your data in a machine-readable format |
| Object | Object to processing based on legitimate interests — including AI organisation of your messages |
| Withdraw consent | Withdraw consent (e.g. push notifications) at any time |
To exercise any right, email admin@localz.chat. We respond within one calendar month. You can also delete your account at any time from Settings → Privacy in the app, which permanently removes your personal data. One exception: a community Hub you created that other members are still active in is not deleted with you — because it belongs to its whole community, it is frozen and handed to our team to either keep running or close.
You have the right to complain to the Information Commissioner's Office (ICO) at ico.org.uk or on 0303 123 1113.
Localz is available to users aged 13 and over in most of the places we operate. In Australia the minimum age is 16, to comply with Australian law on minimum ages for social media. We ask for your date of birth when you sign up to confirm this, and we block accounts that declare an age below the minimum for their country.
We apply stricter data minimisation to under-16 accounts, and we do not use data from under-18 accounts for commercial analytics or marketing. If you discover a child under the minimum age has an account, contact us at admin@localz.chat and we will delete it immediately.
Localz currently operates in the United Kingdom. Your data is stored in the United Kingdom wherever you are.
We have not launched anywhere else. If you are outside the UK you can still create an account and register your interest in a community near you, and we will keep that interest on record — but no community will open there until we launch in that country. We decide where to launch next partly by where that interest builds up, and we cannot say in advance when or whether any particular country will follow.
Wherever you are, the rights described in section 4 are available to you in practice: email admin@localz.chat to access, correct, export or delete your data, and we will act on it. If you would rather we did not hold your data at all while your country is not served, tell us at the same address and we will delete your account.
Local law where you live may give you rights in addition to these. Where it does, those rights apply and nothing in this policy limits them.
Passwords are stored as bcrypt hashes. All data in transit is encrypted via TLS. File uploads are stored in private S3 buckets. Database access is restricted to the application server.
We will update the date at the top when this policy changes and notify you in the app for material changes.
Bupbokmuk Lab Ltd
71-75 Shelton Street
Covent Garden
London
WC2H 9JQ
United Kingdom
Email: admin@localz.chat
Company number: 17292473
ICO Registration: ZC191440
© 2026 Bupbokmuk Lab Ltd. All rights reserved.