Lobby
How it works Who it is for Pricing
Join waitlist

Legal

Privacy Policy

Last updated: 8 July 2026

This Privacy Policy explains how Kerényi Gergő egyéni vállalkozó (Kerényi Gergő e.v.), a Hungarian sole entrepreneur with tax number 42985244-1-23 ("Lobby", "we", "us" or "our"), handles personal data when you use the Lobby mobile application.

In short: Lobby is an adult-only social discovery app. We collect the data needed to create accounts, show profiles, run events and chats, send notifications, keep the platform safe, process reports, verify photos, diagnose crashes and comply with law. We do not sell personal data, do not show targeted ads and do not use advertising identifiers.

1. Controller and Contact

The data controller is Kerényi Gergő egyéni vállalkozó (Kerényi Gergő e.v.), tax number 42985244-1-23, registered seat: 6430 Bácsalmás, Mausz Rezső utca 6., Hungary. Privacy, legal and general requests: info@lobbyapp.eu. If we appoint a Data Protection Officer or become legally required to do so, we will add the DPO's contact details here.

2. Personal Data We Collect

Some data is required to provide Lobby. If you do not provide required account, profile, photo or safety information, you may not be able to use the relevant feature. Optional profile fields and free-text content are your choice.

Category

Examples

Why we use it

Account and authentication

User ID, sign-in method, email if provided by Apple or another sign-in provider, account timestamps.

Create and secure your account, authenticate you and provide support.

Profile data

First name or display name, age/date of birth, city, approximate location, languages, interests, prompts (predefined-choice and free-text), bio, education, workplace, drinking and smoking habits, favourite places, verified status and endorsement count.

Create your profile, show you to other users and help people discover relevant events and connections.

Photos and face verification

Profile photos, upload metadata, moderation result, live selfie for verification, similarity score, verification status and timestamps.

Moderate photos, reduce impersonation and verify that your selfie matches your main profile photo. Face verification is required to create a profile; we ask for your explicit consent before any biometric processing begins.

Events, chat, friends and endorsements

Event details, host and participant IDs, join requests, invitations, event chat messages, friend requests, friend connections and positive endorsements.

Run group events, enable event coordination, social connections and trust features.

Location, device and notifications

Selected city (including city-centre coordinates used for geohash calculation — not your device's GPS position), derived geohash, search radius, app language, notification tokens, notification preference settings (push on/off, message and event notifications), device/platform information needed by Firebase, and whether location permission is enabled.

Show nearby events, send service notifications, secure and operate the App. We do not store precise device GPS coordinates on our servers; the coordinates stored are the city-centre point from our city database.

Reports, moderation and safety

Reports about users, rooms, events or content that you submit or that concern you, report category, description, moderation notes, decisions, restrictions and safety signals.

Enforce the Terms, protect users, prevent fraud, handle appeals and comply with law.

Support and legal correspondence

Your email address, message content, attachments such as screenshots and our replies.

Respond to requests, exercise rights, investigate issues and keep records where needed.

Crash diagnostics

Crash logs, stack trace, app version, operating system version, device model, memory state and a pseudonymous Firebase installation ID.

Find and fix technical problems. We do not intentionally include your messages, photos, name or account ID in crash reports.

Purchases and subscriptions

App-store purchase token, product ID, subscription plan and billing period, entitlement status, renewal and cancellation status, whether you are on a free trial and when it ends, a unique purchase reference we register before your purchase so we can reliably match store notifications to your account, and limited transaction metadata. We do not receive your card details.

Provide paid features, manage subscriptions, verify entitlements, restore previous purchases, handle support and meet accounting, tax and legal obligations.

If you voluntarily include sensitive information in your profile, prompts, event details, messages or reports, you choose to make that information available to the relevant audience in the App. Please do not share sensitive information unless you are comfortable with that use. Biometric face verification is handled separately and only with explicit consent.

Inside the App we do not collect advertising identifiers, do not sell personal data and do not use third-party behavioural analytics SDKs. Our public websites (lobbyapp.eu and lobbyapp.hu) use the Meta Pixel to measure how visitors find Lobby and to support our advertising, but only if you accept it in the cookie banner; until then nothing is loaded and no cookie is set. See Section 10.

3. How We Use Data and Our Lawful Bases

Processing

Lawful basis

Account creation, profile setup, events, chat, friends, endorsements and service notifications.

Contract: processing is necessary to provide Lobby under the Terms.

Photo moderation, reports, safety investigations, fraud prevention, abuse prevention and platform security.

Legitimate interests: keeping Lobby safe, trustworthy and lawful. You may object where GDPR allows.

Face verification using a live selfie and face comparison.

Explicit consent for biometric processing under Article 9(2)(a) GDPR, plus consent or contract/legitimate interests for related account operation where applicable.

Crash diagnostics and reliability improvements.

Legitimate interests: maintaining and improving the App.

Responding to privacy/legal requests, handling purchases and subscriptions, accounting and regulatory obligations.

Legal obligation and, where needed, contract performance or legitimate interests for legal claims and platform operation.

Optional marketing or product news if introduced later.

Consent. We do not send marketing emails today.

4. What Other Users Can See

Other users may see your public profile information, photos, age, city, prompts, interests, verified status and endorsement count. Event participants may see event details, your participation and messages you send in that event chat. Friends may see friend-related activity. Reports are not shown publicly, but we may share limited information where needed to explain a moderation decision, protect users or comply with law.

5. Who We Share Data With

We share personal data only where needed to operate Lobby, comply with law, protect users or receive professional support. We do not sell personal data and do not share it with third parties for their own advertising.

Recipient

Role

Typical location

Google / Firebase

Authentication, Firestore database, Cloud Functions, Cloud Messaging, Crashlytics and related infrastructure.

Configured for European regions where available; limited global support may occur.

Amazon Web Services (AWS)

Profile photo storage, photo moderation and face verification using AWS services such as Rekognition.

EU region, currently Frankfurt (eu-central-1), according to the current implementation.

Apple

Sign in with Apple, App Store distribution, in-app purchases/subscriptions, operating-system notification services, and receiving the unique purchase reference we register before each purchase so Apple can match payment events to your account.

EU/worldwide under Apple's terms.

Google Play / Android services

Android app distribution, in-app purchases/subscriptions and operating-system services.

EU/worldwide under Google's terms.

Authorities, courts, advisers or successors

Legal compliance, safety, claims, audits, insurance, corporate transactions or insolvency.

As needed for the relevant lawful purpose.

Our processors must process personal data only on our instructions and under appropriate data processing terms where required by Article 28 GDPR.

6. International Transfers

We aim to keep Lobby data in the European Economic Area where practical. Some providers are part of global groups or may provide support from outside the EEA. Where personal data is transferred outside the EEA or the United Kingdom, we use appropriate safeguards such as adequacy decisions, the EU-US Data Privacy Framework where applicable, Standard Contractual Clauses, transfer impact assessments and supplementary measures where required.

7. Retention

We keep personal data only as long as needed for the purposes above, then delete or anonymise it. These periods may be shorter where possible or longer where law, safety, disputes or legal claims require it.

Data

Retention

Account and profile data

For as long as your account is active, then deleted or anonymised after account deletion unless a limited exception applies.

Profile photos

Approved photos are kept while active on your account. Rejected or pending photos may be kept for up to 30 days for moderation and abuse prevention.

Face verification

The live selfie is processed transiently for verification and is not stored as an image by us. Verification metadata is kept while needed for account integrity, abuse prevention and legal claims.

Event chat messages

Automatically deleted about 35 days after the scheduled event date, unless limited retention is needed for safety, legal or technical reasons.

Events, friends and endorsements

Kept while needed for the account and feature. Endorsements may be anonymised so aggregate counts remain accurate after deletion.

Reports and moderation records

Usually up to 24 months after resolution, or longer where needed for safety, repeat-abuse prevention, legal duties or claims.

Banned account markers

Kept as long as reasonably needed to prevent re-registration and protect users.

Support correspondence

Usually up to 24 months after the case closes.

Security logs and crash diagnostics

Usually up to 90 days, unless needed for an investigation. Crashlytics retention follows Firebase's standard limits.

Subscription and payment records

Subscription entitlement status (whether you have an active plan, its type and expiry) is kept while needed to provide paid features, resolve disputes, comply with law or prevent fraud. Payments and purchases are processed by the Apple App Store and Google Play, which act as the seller and issue your receipt; we do not store card or payment data. Business sales and accounting records derived from the app stores are retained for the period required by Hungarian tax and accounting law.

8. Your Rights

Subject to GDPR conditions, you may request access, rectification, erasure, restriction, portability and objection. Where processing is based on consent, you may withdraw consent at any time without affecting earlier lawful processing. You also have rights relating to automated decision-making where Article 22 GDPR applies.

To exercise your rights, contact info@lobbyapp.eu. We normally respond within one month. If a request is complex, we may extend the response period by up to two further months and will tell you within the first month. We may ask for information needed to verify your identity.

You can complain to the Hungarian National Authority for Data Protection and Freedom of Information (NAIH), 1055 Budapest, Falk Miksa utca 9-11, ugyfelszolgalat@naih.hu, https://www.naih.hu, or to the supervisory authority in the EU/EEA country where you live or work.

9. Choices and Permissions

You can edit most profile information in the App, disable push notifications in your device settings, withdraw location permission in your device settings, and delete your account in the App. You may withdraw consent for face verification by deleting your account; as face verification is required to use Lobby, withdrawing biometric consent means your profile will be removed. If you withdraw other permissions, the related feature may stop working or become limited.

10. Cookies and Device Storage

Our public websites (lobbyapp.eu and lobbyapp.hu) use the Meta Pixel, a tool provided by Meta Platforms Ireland Ltd. When you accept it in the cookie banner, the Pixel sets cookies (such as _fbp) and sends Meta information about your visit — for example the page viewed, a page-view event and, if you newly join the waitlist after accepting, a lead/waitlist signup event that does not include your email address in our event code — so we can measure how people find Lobby and how our advertising performs. This happens only with your consent (Article 6(1)(a) GDPR and the applicable ePrivacy rules). Until you accept, the Pixel does not load and sets no cookie; if you decline, or later change your mind via "Cookie settings" in the website footer, we do not load it and remove its cookies. No other analytics or advertising cookies are used on the websites, and accepting the Pixel is optional — it is not required to use the site or join the waitlist. Meta may process this data in countries outside the EEA and for its own purposes; details are set out in Meta's own policies.

Separately, the App and its SDKs store necessary information on your device, such as authentication tokens, local cache, city data, notification tokens and operating-system app data. This storage is used to make the App work, not for cross-app advertising tracking.

11. Security

We use technical and organisational measures designed to protect personal data, including TLS in transit, cloud-provider encryption at rest, access controls, Firebase security rules, AWS IAM permissions, signed upload URLs, rate limits and internal access restrictions. No system is perfectly secure. If a personal data breach requires notification under GDPR, we will notify the competent authority and affected users where required.

12. Automated Processing

Lobby uses automated systems for profile photo moderation, face comparison, abuse prevention, rate limits and event discovery/ranking. These systems help operate and protect the App. We do not intend them to make decisions that produce legal or similarly significant effects within the meaning of Article 22 GDPR. You can ask for human review of moderation or verification outcomes by contacting info@lobbyapp.eu.

13. Children

Lobby is for adults aged 18 and over. We do not knowingly collect data from children or allow under-18 users. If we learn that an under-18 user created an account, we will close the account and delete related data, except limited information needed for safety or legal reasons. Parents or guardians can contact info@lobbyapp.eu.

14. Account Deletion

You can delete your account in the App or by contacting info@lobbyapp.eu from the email linked to your account. We will delete or anonymise your profile, remove active photos, revoke authentication, remove you from future events where practical, delete notification tokens and handle endorsements and chat messages according to the retention rules above. Some content already shared with other users, system messages, safety records or legally required records may remain for a limited period.

15. Changes and Contact

We may update this Policy to reflect changes in the App, law, vendors or our processing. Material changes will be notified in the App or by another appropriate method. If new processing requires consent, we will ask before it begins.

Privacy enquiries, user-rights requests and legal/general contact: info@lobbyapp.eu Tax number: 42985244-1-23. Our name and registered seat are set out in the "Controller and Contact" section above.

-- End of Privacy Policy --

Lobby

A quietly designed space where like-minded people meet for one real evening.

How it works Who it is for Pricing Waitlist
Privacy Policy Terms and Conditions
© 2026 The Lobby App