← All legal pages

Privacy Policy

Effective 5 Sep 2026 Last updated 5 Sep 2026 Version 1.0

We collect your phone number, the content you create, who you send it to, and what you buy. We store it in the UAE. We do not sell it, we do not run ads, and we do not use third-party analytics. Your chats are end-to-end encrypted, which means we cannot read them. The parts worth reading carefully are Section 5 (what happens when you let us see your contacts), Section 6 (data about people who aren't our users) and Section 11 (your rights and how to use them).

1. Who is responsible for your data

LET'S HORARO F-Z-C, registered in Ajman Free Zone, United Arab Emirates under licence 50974, of C1 Building, Ajman Free Zone, Ajman, United Arab Emirates, is the data controller for personal data processed through LetsHoraro.com and the Let's Horaro apps.

Data Protection Officer: dpo@letshoraro.com

Privacy enquiries: privacy@letshoraro.com

Which law applies

We are established in Ajman Free Zone, United Arab Emirates. Ajman Free Zone is not a financial free zone with its own data protection regime, so we process personal data under Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (PDPL) and its executive regulations, together with Cabinet Resolution No. 4 of 2022 where applicable.

Our supervisory authority is the UAE Data Office.

If you are in the EEA or UK: where we offer services to you or monitor your behaviour, the GDPR (and UK GDPR) also applies. See Section 14 for the additional rights and information that gives you.

2. Our privacy commitments

These are the promises this policy is built around. If we ever change one, it will be a material change under our Terms of Service and you will get 30 days' notice.

We doWe don't
✅ Store your data in the UAE❌ Sell your personal data
✅ Encrypt chats end-to-end❌ Show you advertising
✅ Collect the minimum we need❌ Use third-party advertising or behavioural analytics
✅ Let you export everything❌ Read the content of your encrypted chats
✅ Delete your account on request❌ Use your content to train AI without your specific action
We do
✅ Store your data in the UAE
We don't
❌ Sell your personal data
We do
✅ Encrypt chats end-to-end
We don't
❌ Show you advertising
We do
✅ Collect the minimum we need
We don't
❌ Use third-party advertising or behavioural analytics
We do
✅ Let you export everything
We don't
❌ Read the content of your encrypted chats
We do
✅ Delete your account on request
We don't
❌ Use your content to train AI without your specific action

3. What we collect

3.1 Information you give us

CategoryExamplesWhy
AccountMobile number, date of birth, display name, profile photo, "about" statusTo create and secure your account, verify age
Optional account additionsEmail address, Google/Apple ID, PIN, 2FA setupRecovery and stronger security
Tribute contentMessage text, photos, videos, voice notes, engraving text, subject, occasionTo store and deliver your Tribute
Tribute metadataUnlock date and time, recipient list, relationship type, anonymity setting, location name and GPS coordinates if you add themTo deliver correctly and show countdowns
Recipient detailsRecipient name, mobile number, avatar, delivery address, relationshipTo notify and deliver to them — see Section 6
Order and deliveryGift selection, engraving, chain options, shipping address, trackingTo manufacture and deliver goods
PaymentCardholder name, billing address, transaction records, invoicesTo take payment and meet tax/accounting law
Chat and socialMessages, media, reactions, poll votes, group and Channel membership, contact cards, shared locationsTo run messaging features
ContactsYour device address book, if you grant permissionContact discovery — see Section 5
Identity documentsPassport or Emirates ID copy, only if we need to verify your age or run a required identity checkAge verification; legal compliance on precious metals transactions
SupportComplaints, feedback, attachments, support chat historyTo help you and improve
Category
Account
Examples
Mobile number, date of birth, display name, profile photo, "about" status
Why
To create and secure your account, verify age
Category
Optional account additions
Examples
Email address, Google/Apple ID, PIN, 2FA setup
Why
Recovery and stronger security
Category
Tribute content
Examples
Message text, photos, videos, voice notes, engraving text, subject, occasion
Why
To store and deliver your Tribute
Category
Tribute metadata
Examples
Unlock date and time, recipient list, relationship type, anonymity setting, location name and GPS coordinates if you add them
Why
To deliver correctly and show countdowns
Category
Recipient details
Examples
Recipient name, mobile number, avatar, delivery address, relationship
Why
To notify and deliver to them — see Section 6
Category
Order and delivery
Examples
Gift selection, engraving, chain options, shipping address, tracking
Why
To manufacture and deliver goods
Category
Payment
Examples
Cardholder name, billing address, transaction records, invoices
Why
To take payment and meet tax/accounting law
Category
Chat and social
Examples
Messages, media, reactions, poll votes, group and Channel membership, contact cards, shared locations
Why
To run messaging features
Category
Contacts
Examples
Your device address book, if you grant permission
Why
Contact discovery — see Section 5
Category
Identity documents
Examples
Passport or Emirates ID copy, only if we need to verify your age or run a required identity check
Why
Age verification; legal compliance on precious metals transactions
Category
Support
Examples
Complaints, feedback, attachments, support chat history
Why
To help you and improve

3.2 Information we collect automatically

CategoryExamples
DeviceDevice model, OS version, app version, language, time zone
TechnicalIP address, connection timestamps, push notification token
Usage metadataWhen you open the app, which features you used, Credits consumed, storage used
DiagnosticsCrash reports, performance traces, error logs
Category
Device
Examples
Device model, OS version, app version, language, time zone
Category
Technical
Examples
IP address, connection timestamps, push notification token
Category
Usage metadata
Examples
When you open the app, which features you used, Credits consumed, storage used
Category
Diagnostics
Examples
Crash reports, performance traces, error logs

We do not use third-party advertising SDKs, behavioural analytics or cross-site tracking. Our diagnostics are limited to crash and performance data.

3.3 What we deliberately do not collect

  • The content of your end-to-end encrypted chats. Encryption keys live on your device, in the iOS Keychain or Android Keystore. We hold ciphertext we cannot decrypt.
  • Precise location tracking. We use GPS coordinates only if you attach a location to a Tribute or use GPS to fill in an address. We do not track your movements.
  • Biometric identifiers. We do not run facial recognition on your photos or videos.

4. Why we use your data, and our legal basis

What we doLegal basis (PDPL)Legal basis (GDPR, if applicable)
Create and run your accountPerformance of contractArt. 6(1)(b) contract
Store and deliver TributesPerformance of contractArt. 6(1)(b) contract
Manufacture, engrave and ship giftsPerformance of contractArt. 6(1)(b) contract
Process payments and issue invoicesContract; legal obligationArt. 6(1)(b); Art. 6(1)(c)
Notify Tribute recipients by SMS/WhatsApp/emailLegitimate interests of sender and us in delivering a requested messageArt. 6(1)(f) legitimate interests
Contact discovery from your address bookYour consentArt. 6(1)(a) consent
Age verification and identity checksLegal obligation; legitimate interests in child safetyArt. 6(1)(c); Art. 6(1)(f)
AML/CDD checks on precious metals ordersLegal obligationArt. 6(1)(c)
Security, fraud prevention, abuse investigationLegitimate interestsArt. 6(1)(f)
Crash and performance diagnosticsLegitimate interests in a working productArt. 6(1)(f)
Aggregated business analyticsLegitimate interestsArt. 6(1)(f)
Marketing emails and promotionsYour consentArt. 6(1)(a) consent
Responding to lawful authority requestsLegal obligationArt. 6(1)(c)
What we do
Create and run your account
Legal basis (PDPL)
Performance of contract
Legal basis (GDPR, if applicable)
Art. 6(1)(b) contract
What we do
Store and deliver Tributes
Legal basis (PDPL)
Performance of contract
Legal basis (GDPR, if applicable)
Art. 6(1)(b) contract
What we do
Manufacture, engrave and ship gifts
Legal basis (PDPL)
Performance of contract
Legal basis (GDPR, if applicable)
Art. 6(1)(b) contract
What we do
Process payments and issue invoices
Legal basis (PDPL)
Contract; legal obligation
Legal basis (GDPR, if applicable)
Art. 6(1)(b); Art. 6(1)(c)
What we do
Notify Tribute recipients by SMS/WhatsApp/email
Legal basis (PDPL)
Legitimate interests of sender and us in delivering a requested message
Legal basis (GDPR, if applicable)
Art. 6(1)(f) legitimate interests
What we do
Contact discovery from your address book
Legal basis (PDPL)
Your consent
Legal basis (GDPR, if applicable)
Art. 6(1)(a) consent
What we do
Age verification and identity checks
Legal basis (PDPL)
Legal obligation; legitimate interests in child safety
Legal basis (GDPR, if applicable)
Art. 6(1)(c); Art. 6(1)(f)
What we do
AML/CDD checks on precious metals orders
Legal basis (PDPL)
Legal obligation
Legal basis (GDPR, if applicable)
Art. 6(1)(c)
What we do
Security, fraud prevention, abuse investigation
Legal basis (PDPL)
Legitimate interests
Legal basis (GDPR, if applicable)
Art. 6(1)(f)
What we do
Crash and performance diagnostics
Legal basis (PDPL)
Legitimate interests in a working product
Legal basis (GDPR, if applicable)
Art. 6(1)(f)
What we do
Aggregated business analytics
Legal basis (PDPL)
Legitimate interests
Legal basis (GDPR, if applicable)
Art. 6(1)(f)
What we do
Marketing emails and promotions
Legal basis (PDPL)
Your consent
Legal basis (GDPR, if applicable)
Art. 6(1)(a) consent
What we do
Responding to lawful authority requests
Legal basis (PDPL)
Legal obligation
Legal basis (GDPR, if applicable)
Art. 6(1)(c)

Where we rely on consent, you can withdraw it at any time in Settings, without affecting anything we did before you withdrew it.

Where we rely on legitimate interests, we have weighed our interest against your rights. You can object — see Section 11.

4.1 A note on our business analytics

We produce internal dashboards on revenue, Tribute volumes, occasions, sender-recipient relationship types, delivery regions and seasonal patterns.

These are built from aggregated, non-identifying metadata only. We do not analyse the content of your messages to do this, and we do not build individual profiles for targeting. Where our dashboards use demographic fields such as age band or nationality, they are aggregated to group level and not used to make decisions about individual users.

5. Contact discovery — please read this one

If you allow it, we access your device address book to show you which of your contacts already use Let's Horaro.

This is optional. The app works without it — you can enter a recipient's number manually. We ask separately, not bundled into signing up, and you can turn it off at any time in your device settings.

How we handle it:

  • We match contacts against our user base using irreversible hashes of phone numbers where technically possible, rather than uploading readable numbers.
  • Contacts who are not Let's Horaro users are not retained. We discard non-matching entries after the match runs.
  • We do not use your address book for marketing, and we do not message your contacts because they are in your address book.
  • We do not build a "shadow profile" of non-users from address book data.

Your responsibility: your address book contains other people's personal data. By enabling contact discovery you confirm you may share it with us for this purpose. If a contact objects, ask us at privacy@letshoraro.com and we will remove any trace and add them to a suppression list.

6. Data about people who aren't our users

Let's Horaro is unusual: to work at all, it needs data about people who have not signed up.

6.1 Tribute recipients

When you create a Tribute you give us a recipient's name, mobile number and possibly their address and photo. We use it to send a notification and, where relevant, to deliver a gift.

When we first contact a recipient we tell them: that someone has sent them something on Let's Horaro; where their details came from; how to see this policy; and how to stop further contact.

A recipient who does not want contact can opt out. If they do, we add their number to a suppression list, we stop sending them notifications, and we tell the sender that delivery could not be completed. A suppression request cannot be overridden by a sender.

6.2 People mentioned in Tribute content

A Tribute may include photographs, recordings or descriptions of others, often people who have died. We do not analyse this content — much of it is encrypted and inaccessible to us in any event. If you believe content about you or a family member is being shared inappropriately, contact privacy@letshoraro.com and we will handle it under our Acceptable Use & Community Guidelines.

6.3 Deceased persons and posthumous data

Let's Horaro is expressly designed for messages that may be delivered after a sender has died. Our full position on scheduled delivery after death, and on what a personal representative may and may not request, is set out in Section 9 of the Tribute, Vault & Scheduled Delivery Terms.

In summary: scheduled and paid Tributes are still delivered; a personal representative may request suspension on documented proof; and undelivered Tribute content is not disclosed to the estate.

6.4 Deceased persons appearing in content

Data protection law generally applies to living people. We nevertheless treat material about deceased individuals with care, and we will act on well-founded requests from close family members or a personal representative.

7. Who we share data with

We do not sell personal data. We do not share it for advertising. We share it only with the following categories of recipient, and only what each needs.

RecipientWhat they getWhy
Payment processors (our certified PCI-DSS payment providers)Payment and billing details. We do not store your full card number.To take payment
Couriers (our designated high-security logistics partners)Recipient name, address, phone, parcel detailsTo deliver
Gift manufacturers and QA partnersEngraving text and design assets, order referenceTo make your gift
SMS / WhatsApp / email gatewaysRecipient phone number or email, message templateTo send notifications
Cloud hosting (our UAE-based cloud infrastructure provider)Encrypted data at restTo run the service
AI providersOnly the specific prompt or media you submit to an AI feature — see AI Features TermsTo run Auto-Prompt and Memorial Video
Professional advisersAs neededLegal, audit, accounting
AuthoritiesAs required — see Section 8Legal obligation
An acquirerIf our business is sold or mergedBusiness transfer, with notice to you
Recipient
Payment processors (our certified PCI-DSS payment providers)
What they get
Payment and billing details. We do not store your full card number.
Why
To take payment
Recipient
Couriers (our designated high-security logistics partners)
What they get
Recipient name, address, phone, parcel details
Why
To deliver
Recipient
Gift manufacturers and QA partners
What they get
Engraving text and design assets, order reference
Why
To make your gift
Recipient
SMS / WhatsApp / email gateways
What they get
Recipient phone number or email, message template
Why
To send notifications
Recipient
Cloud hosting (our UAE-based cloud infrastructure provider)
What they get
Encrypted data at rest
Why
To run the service
Recipient
AI providers
What they get
Only the specific prompt or media you submit to an AI feature — see AI Features Terms
Why
To run Auto-Prompt and Memorial Video
Recipient
Professional advisers
What they get
As needed
Why
Legal, audit, accounting
Recipient
Authorities
What they get
As required — see Section 8
Why
Legal obligation
Recipient
An acquirer
What they get
If our business is sold or merged
Why
Business transfer, with notice to you

Every processor is bound by a written data processing agreement requiring confidentiality, security, and processing only on our instructions.

A current list of our sub-processors is published at letshoraro.com/legal/sub-processors. We will notify you of material additions.

8. Law enforcement and legal requests

We may disclose data where legally required by a UAE court, regulator or law enforcement authority, or to protect life, prevent serious harm, or defend legal claims.

Our approach: we require requests to be properly authorised and specific; we disclose only what the request actually covers; and we notify affected users unless the law prohibits it or notification would create a risk to someone's safety.

What we can and cannot hand over: we can provide account details, metadata, order and payment records, and Channel content. We cannot provide the content of end-to-end encrypted chats, because we do not have the keys. We will say so rather than imply otherwise.

9. Where your data is stored

Your data is stored in the United Arab Emirates, on our UAE-based cloud infrastructure provider infrastructure in AWS me-central-1. This includes messages, media, metadata and backups.

9.1 Transfers outside the UAE

Some transfers are unavoidable:

  • A recipient in another country. If you send a Tribute or gift abroad, the content and address go there. That is what you asked us to do.
  • Couriers and payment processors operating internationally.
  • AI providers, where you use an AI feature and the provider processes outside the UAE. We tell you in the AI Features Terms.

Where we transfer personal data outside the UAE we rely on: a determination of adequate protection in the destination country; contractual safeguards imposing equivalent protection; or your explicit consent for a specific transfer.

9.2 Federation

Our messaging infrastructure is based on the Matrix protocol, but federation is disabled. Your messages are not exchanged with servers operated by other organisations. All message data remains on our servers in the UAE.

If we ever enable federation, we will treat that as a material change to this policy and give you 30 days' notice before it takes effect.

10. How long we keep things

DataRetention
Draft Tributes (never sent)Deleted after 10 days
Sent TributesDeleted 10 days, unless the sender selects a longer option after unlock, unless you chose "keep forever"
Tributes marked "keep forever"Retained for as long as the account is active and the service operates — see below
Chat messagesDeleted after 12 months, and 24 hours after every member has read them
Account dataWhile your account is open, then deleted within 30 days of closure
Order and delivery records7 years — tax and commercial law
Payment and invoice records7 years — tax law
AML/CDD records, where applicable5 years from the transaction, as required by law
Identity documents for age checksDeleted immediately after verification, or within 30 days at the latest
Support tickets2 years after closure
Crash and diagnostic logs90 days
Security and access logs12 months
Suppression list (opt-outs)Indefinitely — we must keep it to honour the opt-out
BackupsOverwritten within 90 days
Data
Draft Tributes (never sent)
Retention
Deleted after 10 days
Data
Sent Tributes
Retention
Deleted 10 days, unless the sender selects a longer option after unlock, unless you chose "keep forever"
Data
Tributes marked "keep forever"
Retention
Retained for as long as the account is active and the service operates — see below
Data
Chat messages
Retention
Deleted after 12 months, and 24 hours after every member has read them
Data
Account data
Retention
While your account is open, then deleted within 30 days of closure
Data
Order and delivery records
Retention
7 years — tax and commercial law
Data
Payment and invoice records
Retention
7 years — tax law
Data
AML/CDD records, where applicable
Retention
5 years from the transaction, as required by law
Data
Identity documents for age checks
Retention
Deleted immediately after verification, or within 30 days at the latest
Data
Support tickets
Retention
2 years after closure
Data
Crash and diagnostic logs
Retention
90 days
Data
Security and access logs
Retention
12 months
Data
Suppression list (opt-outs)
Retention
Indefinitely — we must keep it to honour the opt-out
Data
Backups
Retention
Overwritten within 90 days

On "keep forever": we will maintain the Tribute for as long as we reasonably can. We cannot promise a period longer than the life of the company. If we ever wind down, Section 20 of the Terms of Service applies: 90 days' notice, and a way to export or receive your content.

Deletion is not instant. Removing data from live systems is immediate; removing it from rolling backups takes up to 90 days.

11. Your rights

You have the right to:

RightWhat it meansHow
AccessGet a copy of your dataSettings → PDPL Rights → Request My Data. We deliver an encrypted archive within 48 hours.
CorrectionFix data that's wrongEdit in Settings, or ask us
DeletionHave your data erasedSettings → Delete Account, or ask us
RestrictionHave us pause processing while a dispute is resolvedprivacy@letshoraro.com
ObjectObject to processing based on legitimate interestsprivacy@letshoraro.com
PortabilityGet your data in a machine-readable formatIncluded in Request My Data
Withdraw consentFor contact discovery, marketing, AI featuresSettings
ComplainTo the supervisory authoritySee Section 15
Right
Access
What it means
Get a copy of your data
How
Settings → PDPL Rights → Request My Data. We deliver an encrypted archive within 48 hours.
Right
Correction
What it means
Fix data that's wrong
How
Edit in Settings, or ask us
Right
Deletion
What it means
Have your data erased
How
Settings → Delete Account, or ask us
Right
Restriction
What it means
Have us pause processing while a dispute is resolved
How
privacy@letshoraro.com
Right
Object
What it means
Object to processing based on legitimate interests
How
privacy@letshoraro.com
Right
Portability
What it means
Get your data in a machine-readable format
How
Included in Request My Data
Right
Withdraw consent
What it means
For contact discovery, marketing, AI features
How
Settings
Right
Complain
What it means
To the supervisory authority
How
See Section 15

Response times: we respond to data requests within 30 days, and to Request My Data exports within 48 hours. We will not charge you, unless a request is manifestly excessive or repetitive.

Limits on deletion. Some things survive an erasure request:

  • Tributes already delivered. Once unlocked, the recipient's copy is theirs. Deleting your account does not delete their copy.
  • Financial records we must keep for tax and accounting law.
  • Suppression list entries, which exist precisely to protect people who asked not to be contacted.
  • Records needed to defend legal claims.

We will always tell you what we retained and why.

12. Security

  • End-to-end encryption for chats, using the Matrix protocol's Megolm and Olm implementations, with forward secrecy.
  • Encryption keys stored on your device only — iOS Keychain or Android Keystore, never on our servers.
  • AES-256 encryption for data at rest.
  • TLS/HTTPS for all data in transit.
  • Access controls limiting staff access to what their role requires, with logging.
  • Automated backups with restore testing.

No system is perfectly secure. If a breach affects your personal data and creates a risk to you, we will notify you and the relevant supervisory authority within 72 hours of becoming aware, as required.

What you should do: enable a PIN or two-factor authentication, set up encryption key backup, keep your device updated, and never share a one-time code with anyone. We will never ask you for your OTP.

13. Children

The Platform is not for anyone under 16. We do not knowingly collect data from children under 16. If you believe a child under 16 has an account, tell us at privacy@letshoraro.com and we will investigate and delete it.

Note that children may appear in Tribute content — a parent recording a message for a child, or photographs of a family. That content is under the sender's control and their responsibility under our Terms.

14. If you are in the EEA or UK

Where the GDPR or UK GDPR applies to our processing:

  • Additional rights: you may lodge a complaint with your local supervisory authority. In Germany this is your state's Datenschutzbehörde; in the UK, the ICO.
  • Automated decision-making: we do not make decisions producing legal or similarly significant effects about you by automated means alone. Automated fraud and abuse screening is always subject to human review before an account is terminated.
  • Transfers: transfers from the EEA to the UAE are made under appropriate safeguards, including Standard Contractual Clauses where required. Contact dpo@letshoraro.com for a copy.
  • Digital consent age: where a member state sets the age of digital consent above 16 for any processing based on consent, we apply that higher age.

15. Complaints

Talk to us first: privacy@letshoraro.com or dpo@letshoraro.com. We aim to resolve privacy complaints within 30 days.

If you're not satisfied:

  • UAE mainland: the UAE Data Office
  • DIFC: the DIFC Commissioner of Data Protection
  • ADGM: the ADGM Office of Data Protection
  • EEA: your national supervisory authority
  • UK: the Information Commissioner's Office

You do not need to complain to us first, but we would like the chance to fix it.

16. Changes to this policy

We will notify you of material changes by email and in-app at least 30 days before they take effect. We keep previous versions available at letshoraro.com/legal/archive so you can see what changed.

Questions? privacy@letshoraro.com · Data Protection Officer: dpo@letshoraro.com · LET'S HORARO F-Z-C, C1 Building, Ajman Free Zone, Ajman, United Arab Emirates