Version 1 · Effective October 11, 2026
Privacy policy
This policy explains the personal data Ulakla uses to run private conversations, manage memberships and handle safety and support.
Account and activity data
We store account identifiers, names, X identity details and profile photos, creator usernames and bios, and your settings. Email sign-in stores your address and a password hash, not a readable password. We store message text, participants, send times, read activity, first-message usage, blocks, hidden-thread state, reports and membership status. Billing records include Stripe identifiers and charge, trial, renewal and cancellation information. Security records help protect sign-in and prevent abuse. Information you email support is also used to handle your request.
Public profiles and private messages
Creator names, usernames, photos and bios are public. Only signed-in participants can read a conversation through the app. Ulakla stores messages; they are not end-to-end encrypted. Authorized operational access may be needed for support, abuse handling, disputes or legal obligations. Do not send information you are unwilling to share with the other participant. Reply emails summarize activity without including message bodies. Fans can change their notification email and reply-alert preference in Settings; essential billing and recovery emails serve their own purposes. Creators receive no emails, including when acting as fans.
Cookies and browser storage
Cookies keep you signed in and support sign-in security and language preferences. Browser storage preserves unsent drafts during navigation and checkout and helps other tabs respond to sign-out. Drafts are tied to your signed-in session. Signing out or deleting your account clears Ulakla’s private state in the browser when it receives that change. On a shared device, sign out when finished and avoid leaving a signed-in tab open.
Service providers
X processes X sign-in and supplies identity and profile data. Stripe processes payments and holds its own payment records; Ulakla does not store full card details. Our email delivery provider processes recipient addresses and recovery, reply and billing email content. Hosting and network providers process data needed to deliver and protect the service. These providers have their own applicable privacy policies and retention obligations. We may also disclose necessary information to meet legal obligations or handle safety and disputes.
Reports and hidden conversations
A conversation report stores the reporting creator, the participants, the reason, any details provided and the report date. The report receipt confirms storage; it does not promise human review, a reply or a particular outcome. Reports and related conversations may be retained with restricted access as safety or dispute evidence. Removing a conversation from a creator’s inbox hides it there, rather than erasing message history, blocks, reports or first-message usage.
Deleting your account
Request deletion in Settings → Delete account and confirm your identity. Acceptance revokes sessions and suppresses pending notifications. We cancel memberships you bought and memberships to your creator profile before deletion completes. If billing cancellation is unresolved, deletion remains pending. Completion removes your public profile, uploaded photo, sign-in credentials and unnecessary personal details; it does not automatically refund past charges. Email already accepted by a delivery provider cannot be recalled. The other participant keeps their conversation history. Once both participants delete, ordinary conversations and messages are removed; reported conversations can remain as restricted evidence.
What remains after deletion
Restricted account IDs, X identity IDs where present, a digest of the email sign-in address and consumed first-message records remain for as long as needed to enforce identity and prevent deletion or re-registration from resetting usage. Deleted identities cannot be reactivated through X or email registration. These records are pseudonymous personal data, not anonymous data. Minimal billing IDs, cancellation dates, reduced checkout records and event receipts remain for reconciliation, refunds, disputes and required accounting. Stripe customer deletion does not erase its immutable invoice or payment records.
Retention limits and backups
Completed deletion receipts are purged after 30 days; unfinished deletion records remain until billing and removal steps succeed. Short-lived security records expire through normal cleanup. Safety and accounting records have no single fixed retention period: access is restricted to operational need, and records are reviewed for removal when that need or an applicable obligation ends. Backup copies may persist until replaced or removed; account deletion records must be applied before restored data returns to service so deleted accounts, uploads, sessions and notifications do not become active again.
Data questions and requests
You can update account details and notification preferences in Settings and use account deletion as described above. Contact support to request access, correction or deletion of personal data, or to ask about retained records. We may need to verify ownership and retain records needed for safety, billing or applicable obligations. We will explain relevant limits for your request. Your rights under applicable data-protection law continue to apply.
Contact support
For account help, a billing question, a report or a privacy request, email info@ulakla.com. Include your account email or username and enough detail to identify the issue. For a charge, include its date and the creator’s username. Never send passwords, sign-in or reset links, or full card details. We may need to verify account ownership before sharing or changing private records. Contacting support does not cancel a membership, guarantee a refund or promise a response time.