PRIVACY NOTICE
Aya Lookup privacy notice
Operator: the service operator. Privacy questions may be sent to the privacy contact. This notice must be reviewed by qualified counsel and completed with the operator's jurisdiction, physical mailing address, and effective-date requirements before public launch.
Data processed
The service processes account email, password hashes, verification and recovery tokens, credit balance, accepted terms, lookup purposes, lookup history, saved results, notes and tags, purchase identifiers, subscription status, security logs, privacy requests, and inaccurate-result reports. Plaintext passwords and full payment-card credentials are not stored by Aya Lookup.
Lookup data
A phone number is sent to the configured licensed provider to return available identity or call-information data. Results may be incomplete, stale, incorrect, or associated with a prior subscriber. Normalized results can be cached for the configured retention period. Raw provider responses are disabled by default. Verified suppression requests remove the number from Aya's cache, purge matching saved contacts, lookup-history entries, and recent replay records held in Aya user accounts, and prevent new Aya results while the suppression remains active.
Payments and processors
Web payments are processed by Stripe. Native purchases are processed by Apple or Google and synchronized through RevenueCat. Aya stores transaction identifiers, product identifiers, credit grants, refund or dispute status, and subscription state for reconciliation and duplicate-credit prevention. Aya does not receive complete card numbers or App Store and Google Play payment credentials.
Retention and deletion
Lookup cache, reports, and security records use configured retention limits. Users can export account data and delete an account in the app or through the public account-deletion page. Account deletion removes account data, lookup history, saved results, and user-linked reports. Minimal transaction identifiers may be retained or anonymized when reasonably necessary for taxes, accounting, chargebacks, fraud prevention, and preventing duplicate credit grants. Payment and lookup providers maintain their own records under their policies and legal obligations.
Your choices
Use the privacy request page to request access, correction, deletion, or suppression. Suppression and correction requests require identity or number-ownership verification before data is changed. In-app reports can flag an incorrect identity, address, reassigned number, or privacy concern.
Children
The service is limited to adults age 18 or older and is not directed to children.
Security and transfers
Aya uses password hashing, verified bearer sessions, rate limits, security headers, idempotent billing, and least-data defaults. No system is perfectly secure. Hosting, email, lookup, payment, and analytics providers may process data in other jurisdictions; the production operator must identify all processors and required transfer mechanisms before launch.