Privacy Policy
Last updated: 28 September 2026
1. Who we are
LongTable is a verified community app for institute alumni in India, developed and operated by Lilywilliam Craftedcode (OPC) Pvt. Ltd. (CIN U46411CT2025OPC017478), with its registered office at 7th Floor, C/o Zenith Workspace Solution, Currency Tower, Telibandha Road, Raipur, Chhattisgarh 492001, India. LongTable offers alumni-only housing listings, flatmate search, events, discussion forums, a services directory, a marketplace, and private messaging. This policy explains what information LongTable collects, how it is used, and the controls you have.
2. Information we collect
- Account information — your name, email address, and sign-in credentials (managed by Firebase Authentication; we never see your password). If you sign in with Google, we receive your basic Google account profile. If you sign in with Apple, we receive the name and email address Apple shares with us — if you choose Apple's Hide My Email, that is a private relay address rather than your real one.
- Verification information — your LinkedIn profile details and education history you submit, and any documents you upload to verify your alumni status (for example a degree or ID document). Verification documents are used only for review and are deleted within 30 days of approval or closure.
- Profile information — details you add to your profile such as company, role, city, and contact details. Each field carries a visibility setting you control.
- Contact details you publish — a phone number you attach to a listing or profile so other members can reach you, where you choose to provide one. Contact details are hidden unless you opt in to sharing them.
- Content you create — housing, flatmate, marketplace, and directory listings, events, forum posts and comments, reviews, and messages you send.
- Saved searches — search filters you choose to save, so the app can show you matching listings and, if you turn alerts on, notify you. You can delete a saved search at any time.
- Location information — locations you attach to listings and events. Public viewers see only an approximate area; your exact location is shared only as described in the app (for example with the listing owner, admins, or event attendees where you choose to reveal it). If you grant device location access for the Explore map, it is used to center the map and is not shared with other members.
- Safety choices — items you hide, members you block, and anonymous authors you block. For an anonymous-author block we keep, on our servers only, a link to the account that wrote the post, so we can hide that author's later posts from you. You never see that link, and neither does anyone else except authorised moderators.
- Terms acceptance — the version of the Terms you accepted, when, and your confirmation that you are 18 or older.
- Moderation records — reports you file or that concern you; how often your reports were acted on or dismissed (used only to order the moderators' queue, never to hide content); and, if your account is suspended, when, by whom and why.
- Device and diagnostics — push-notification tokens and app-integrity signals (Firebase App Check). We also use Firebase Crashlytics for crash reporting and Firebase Performance Monitoring for app performance. These collect crash reports and stack traces, app start and screen rendering timings, network request timings (URLs, response codes and sizes — not request or response bodies), and device and app details such as model, operating system version, app version and a Firebase installation identifier. They are used to diagnose crashes and slowness. We do not use analytics or advertising SDKs, and this data is not used to track you across other companies' apps or websites.
- Server logs — when the app talks to our servers, the servers record technical logs such as the service called, the time, the account ID and the IP address of the request. See section 5 for how long they are kept.
3. How we use information
- To verify alumni status and operate the trust-tier system that gates community features.
- To provide the app's features: listings, events, forum, directory, marketplace, and messaging.
- To keep the community safe: moderation, report handling, anti-abuse limits, and enforcement of community rules.
- To send notifications you have enabled. You can change notification preferences in the app at any time.
4. How information is shared
- With other members — only according to the visibility rules shown in the app. Profile fields respect your per-field visibility choices (all members, verified members only, or only you). Contact details are hidden unless you opt in. Anonymous forum posts and comments do not display your name or profile to other members. Authorised LongTable moderators can identify the account behind anonymous content when investigating abuse. Your profile photo is visible to signed-in LongTable members.
- With service providers — LongTable runs on Google Firebase (authentication, database, storage, cloud functions, push notifications, crash reporting and performance monitoring). Your data is processed and stored on Google Cloud infrastructure.
- With Google, if you choose Google sign-in — signing in with Google shares your basic Google account profile (name, email address and profile picture) with LongTable, and tells Google that you signed in to LongTable. Using Google sign-in is optional; you can create an account with an email address and password instead.
- With Apple, if you choose Sign in with Apple — signing in with Apple shares the name and email address you approve on Apple's sheet with LongTable, and tells Apple that you signed in to LongTable. Using Sign in with Apple is optional; you can create an account with an email address and password instead.
- With LinkedIn, if you choose LinkedIn verification — verifying with LinkedIn shares your LinkedIn profile details with LongTable so we can confirm your alumni status. LinkedIn verification is used for verification only, never to sign you in.
- We do not sell your personal information and we do not share it with advertisers.
- Legal requirements — we may disclose information if required by applicable law.
5. Data retention and deletion
You can permanently delete your account at any time from Profile → ⋯ → Settings → Delete account in the app. Deletion is thorough: it removes your account and sign-in, your profile and profile photo, your housing, flatmate, marketplace and directory listings, your events, your saved and recent searches, your notifications and push tokens, and the files you uploaded. A sealed copy of your registration details is kept for 180 days, because Indian law requires it — see the first item below.
A small number of things are deliberately not removed. We would rather state each of them plainly, and say why, than summarise them.
- Your registration details, for 180 days — India's Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021 (rule 3(1)(h)) require us to keep the information you gave us to register for 180 days after your account is deleted. So when an account is deleted we keep, in a separate sealed record: your name and email address; how you signed in, including the identifier, name and email address Apple or Google gave us if you used them; when your account was created; the institute, programme, graduation year and roll number on your account, and a second institute if you added one; and your LinkedIn profile address, profession and industry if you gave them. It does not include your photo, your content, your messages or your verification documents. No member can see it and it is not shown anywhere in the app; we use it only to answer a lawful request from an authority, or in an emergency. It is deleted automatically once 180 days have passed.
- Server logs — our servers keep technical logs of requests to LongTable's backend for 180 days, then delete them automatically. They record, for example, which service was called and when, the account ID and the IP address the request came from. We keep them to investigate security incidents and because India's CERT-In directions require logs to be kept for 180 days. Logs already written are not removed early when an account is deleted.
- Verification documents — used only for verification, and deleted within 30 days of approval or closure.
- Manual-review attachments — images, PDFs and videos submitted through manual review may be retained for up to 90 days after the review request is closed, and are then deleted automatically.
- Community content you posted publicly — your forum posts and comments and your directory reviews, including the images attached to them, are kept when you delete your account. Your name, photo, headline, city, institute and trust score are removed from them and the author is shown as “[deleted user]”. This applies to all such content — not only posts you made anonymously, and not only content that was reported or moderated. We keep it because removing one member's side of a public discussion would break conversations that other members are still reading. Your identity is removed; the content and its images remain. Content you posted inside an Alloy stays restricted to that Alloy's members — deleting an account never widens who can see a post. This holds even when the person deleting their account is the Alloy's creator: the Alloy is retired rather than erased, so its existing members keep exactly the access they had, and nobody gains any. Events hosted in that Alloy by other members are kept too, with the same audience and the same host controls; only the departing member's own events are removed.
- Private messages you have sent — when you delete your account, the people you messaged keep their copy of the conversation, including the full text of the messages you sent them. Your identity is removed from that copy and the conversation becomes permanently read-only, so nothing further can be added to it — but the message text is retained exactly as written, and there is no expiry date. A conversation belongs to both people in it, and we do not allow one person to erase the other's record of it. If this matters to you, delete those messages before you delete your account. Choosing Delete for everyone on a message you sent removes its text for both you and the other person, and a message cleared that way carries no text into the retained copy.
- Moderation and safety records — if you reported someone, or you were reported, the report and the evidence captured with it are pseudonymised rather than deleted, so that deleting an account cannot be used as a way to destroy evidence. Pseudonymised means identifying details are replaced — it does not mean the record becomes anonymous, and copies of the reported content, including images and videos, form part of that evidence and are retained. Evidence is deleted only once all of the following have passed: one year from when the evidence was captured, 180 days from when the content was removed, and 90 days from when the report was resolved. Evidence belonging to a report that is still open is never deleted while it remains open, and evidence subject to a legal hold is retained for as long as that hold lasts. Deletion is automatic: a job runs every day and removes the reports, the audit records and the stored evidence files once their retention has run out — we do not rely on anyone remembering to do it. Within these records, each of the following applies (the retention rule above applies to each unless the item says otherwise):
- Evidence about a profile. What was captured when a profile was reported, and a removed profile photo, is kept for at most one year from when it was captured, even while a report is still open.
- Reported anonymous content. When an anonymous post or comment is reported, the evidence captured with the report includes a private link to the account that wrote it, so moderators can act on the report even if the post is later deleted. The link is visible only to authorised moderators, never to other members, and it is kept and deleted with the rest of that evidence. If that account is deleted, the link is removed like every other direct identifier in the evidence.
- Content hidden by the filter. If something is hidden automatically because it contains listed words, the original is kept, visible only to moderators, so it can be checked and restored if the filter was wrong. It is deleted on the same schedule as other evidence.
- When an account is deleted. Direct identifiers of the account — its account ID and name — are removed from these records, including from the names they are stored under and the names of their evidence files, and replaced with a random reference. Reports and their evidence still point at each other, so moderators can finish reviewing them. This does not make the records anonymous: the evidence we keep, such as reported text, profile text or a photo, can itself identify a person.
- Removed profile photos. If a moderator removes your profile photo for breaking the Community rules, it is removed from your profile and from your earlier posts, comments and poll votes. If LongTable stores the photo, it is deleted and a copy is kept, visible only to moderators, as evidence for up to one year — also after you delete your account, as with other evidence. A photo LongTable does not store, such as one shown from LinkedIn, stops appearing in LongTable, but we cannot delete it from where it is hosted, and we do not keep a copy.
- Safety choices are deleted with your account. If you delete your account, other members' blocks that point at your account are deleted too.
- Terms acceptance and suspension records are deleted with your account, except where they form part of the moderation and safety records described above.
- Vouch history — verification on LongTable relies on existing members vouching for new ones. Vouch requests you made are deleted with your account, along with the vouches other members gave you. Vouches you gave to other people are kept, with your identity removed: your name and identifier are replaced with “[deleted user]”, and the record is re-keyed so that it no longer carries your account identifier. We keep it because that endorsement still counts towards the other member's verification, and withdrawing it afterwards would undo a verification they already hold. This de-identified history is then deleted automatically one year after the request it belongs to is settled — approved, rejected, cancelled or expired. A job runs every day and removes it once that year has passed.
- Account-deletion audit record — a record that an account was deleted, retained for 365 days to meet record-keeping obligations and to allow us to investigate misuse of the deletion process. It does not contain your profile or your content, or the random reference used in moderation records.
- Complimentary-membership fingerprint — if a complimentary paid-membership period has ever been granted on your account, we retain a pseudonymous fingerprint derived from your institute email address and your LinkedIn ID, so that the same person cannot delete and recreate an account in order to receive that benefit repeatedly. It is a keyed cryptographic digest — not a readable email address or LinkedIn ID — and it is stored on its own, with no other information about you. It deliberately survives account deletion, and is retained until three years after the end of the complimentary period, after which it is deleted automatically.
6. Your controls
- Per-field profile visibility settings.
- Contact-detail opt-in on listings.
- Approximate-location protection on listings and events.
- Hide any post, comment, listing, event or directory entry; block members and anonymous authors; manage blocks and hidden items in Settings → Blocked accounts; report content, members, Alloys and conversations.
- Notification preferences.
- In-app account deletion.
7. Children
LongTable is only for adults. You must be 18 or older to use it, and you confirm this when you accept the Terms in the app. It is not directed at children under 18.
8. Changes to this policy
We may update this policy from time to time. Material changes will be reflected on this page with an updated date above.
9. Contact
For privacy questions or requests, email support@lilywilliam.com, or contact the LongTable team via Profile → ⋯ → Help & support in the app. Complaints can also go to our Grievance Officer, Ashish Kerketta (ashish@lilywilliam.com, +91 97526 88667); see the Contact page for how complaints are handled.