Your profile.
Your data.
LYA stores only the information needed to operate accounts, public profiles and product measurement.
What we store
Account identifiers and credentials are stored securely as password hashes. Recovery codes are stored only as one-way hashes and become invalid after use. Profile content is stored so it can be published at your LYA address. If a profile owner enables native email capture, LYA stores the visitor email, the profile and block that collected it, consent version, broad device class, source attribution when available, and capture timestamps so the owner can view, export or delete the lead. Native lead records are automatically removed after 365 days unless deleted sooner. Product events can record profile visits and primary-action selections without treating a click as a confirmed conversion.
Measurement
LYA can store source domain, broad device class and UTM campaign parameters when they are present for product analytics. When someone reaches signup from another published LYA profile, LYA can also record that source profile address to measure referral intent. LYA can use a short-lived first-party signup journey identifier to connect a signup-page visit with account creation and can record one authenticated account-activity event per UTC day to measure retention. These measurement identifiers are not used for advertising, and we do not need the visitor's name to record these events. Attribution and interaction events are automatically removed after 90 days.
Payments and sharing
Public profile content is visible to visitors. LYA may rely on infrastructure providers needed to deliver the service. LYA Pro payments are processed through Stripe Hosted Checkout; LYA does not store full payment-card details. LYA stores only the billing evidence needed to verify and maintain the account entitlement. We do not sell personal data to advertisers. Questions about account data or billing can be sent to hello@lya.bio.
Your choices
You can keep a profile as a draft, publish it, update it, or stop using the service. Account data can be exported from Account settings. Self-service deletion is implemented but temporarily disabled while its production canary is being verified. Until that closes, you can request account deletion from the address on your account by emailing hello@lya.bio. Account export remains available from Account settings. When deletion is enabled, the public profile, profile analytics, entitlements and account credentials are removed while billing evidence, if present, keeps only the disabled internal account identifier needed for referential integrity.