
Loka · Privacy
How Loka collects, uses, shares, and protects your personal data.
Loka is a location-based travel discovery service for Malaysia. It helps you explore nearby attractions and points of interest, view interactive maps, build and save itineraries and bucket lists, browse tours, and chat with an AI travel assistant.
This Policy applies to the Loka mobile app and to loka.my. The data practices described below reflect the Loka app in particular; where a practice applies only to a specific website feature, we note it. Undefined terms used here have the same meaning as in our Terms and Conditions.
We have prepared this Policy to be compliant in substance with Malaysia’s Personal Data Protection Act 2010, as amended (including by the Personal Data Protection (Amendment) Act 2024) (the “PDPA”) and to align with the data-disclosure expectations of the Apple App Store and Google Play.
You can browse much of Loka as a guest. Some features - the AI travel assistant and syncing your saved content to your account - require you to sign in. Where a feature is available only to signed-in users, the data described below for that feature is processed only when you choose to use it.
We collect only the categories of data described below, which reflect what Loka actually handles. We are explicit about whether each category stays on your device only or is transmitted off your device to our backend or a service provider.
When you create an account or sign in, we process:
This data is transmitted off your device to Firebase and to the Loka backend.
To power nearby discovery and map features, the app can access your device location. At the system level the app requests approximate (“coarse”) location on Android (ACCESS_COARSE_LOCATION); on iOS, location is requested for use while you are using the app (“when in use”). When you grant permission, your coordinates and accuracy are used to find attractions and tours near you and to render maps. Your location is sent to our backend with the relevant request (for example, when searching nearby places or asking the AI assistant a location-aware question) and to our maps provider to display and search the map. If you do not grant location permission, location-dependent features will be limited, but you can still use the rest of Loka.
When you use the AI travel assistant or itinerary planner, the content you submit - your prompts, messages, travel preferences and questions, together with relevant location context - is transmitted to our backend AI/LLM endpoint to generate responses. Your conversation history may be stored on our backend so you can return to past conversations.
Content you choose to save - your bucket list, saved tours, and saved itineraries - is stored to let you return to it. Saved itineraries and bucket-list items associated with your account are synced to our backend. Saved tours (bookmarks) are stored locally on your device so they survive app restarts; they are deliberately device-local and are not synced to, or deleted from, a backend when you sign out.
To operate and troubleshoot the Services, we process basic device and technical data, such as device/OS type and version, the Firebase authentication token attached to your requests, and in-app/diagnostic logs generated during use. In-app debug logs are generated for development purposes and are device-side; technical metadata necessarily accompanies requests that reach our backend so they can be authenticated and served.
At a glance: what stays on your device vs. what is transmitted
| Data category | Examples | Where it lives |
|---|---|---|
| Account & identity | Email, display name, profile photo, Firebase UID, Google account info | Transmitted (Firebase / backend) |
| Location | Coordinates, accuracy | Transmitted on request |
| AI chat & itineraries (input) | Prompts, messages, preferences | Transmitted (backend AI) |
| Saved itineraries & bucket list | Saved places, planned itineraries | On deviceBackend |
| Saved tours (bookmarks) | Bookmarked tours | On device only |
| Device & technical | Device/OS info, auth token, app logs | On deviceMetadata with requests |
What we do NOT collect
We use the data above to:
We do not use your data for third-party advertising, and we do not sell your personal data (see Section 6).
Under the PDPA (as amended), we process your personal data on the basis of your consent and where processing is necessary for the performance of, or in connection with, the services you request (a recognised basis under the PDPA). By using Loka, creating an account, and granting the permissions the app asks for (such as location), you consent to the collection and use of your personal data as described in this Policy.
Some data is necessary to deliver core functionality - without it, we may not be able to provide all the features you request (for example, the AI assistant cannot answer without receiving your message, and nearby discovery cannot work without location access). You may withdraw your consent or limit processing as described in Section 12, recognising that doing so may limit certain features.
As required by the PDPA’s Notice and Choice Principle, this Policy describes the personal data we collect, the purposes for which it is processed, the parties to whom it may be disclosed, and how you can request access to and correction of your data. We do not process sensitive personal data (as defined by the PDPA) through the Loka app.
We share personal data only with the service providers (data processors) needed to operate Loka, and only to the extent necessary for the purposes described above:
We may also disclose personal data where required by law, regulation, legal process, or enforceable governmental request, or to protect the rights, safety, or property of Loka, our users, or the public.
We do not sell your data
Loka integrates the following third-party services. Each is governed by its own privacy policy; we encourage you to review them:
| Service | Purpose | Data involved | Their policy |
|---|---|---|---|
| Firebase (Google) | Authentication & account identity | Email, password (handled by Firebase), Firebase UID | firebase.google.com/support/privacy |
| Google Sign-In (Google OAuth) | Sign-in option | Basic Google account info you authorise | policies.google.com/privacy |
| Mapbox | Maps & geocoding | Location and map/search queries, access token | mapbox.com/legal/privacy |
| expo-location | Device location access | Coordinates & accuracy (when permitted) | expo.dev/privacy |
| Loka backend (AI/LLM) | AI assistant & itinerary generation | Chat & itinerary inputs, location context | This Policy |
Loka does not currently include third-party analytics, advertising, attribution, or crash-reporting SDKs in the app (see Section 15).
The Loka app asks for the following device permission:
You can change or revoke the location permission at any time in your device’s settings (iOS: Settings → Privacy & Security → Location Services; Android: Settings → Apps → Loka → Permissions). If you revoke location access, nearby discovery, map-centred features, and location-aware AI responses will be limited or unavailable, but you can continue to use the rest of the app.
The app does not currently request push-notification access or other sensitive device permissions. If we add new permissions in future, we will update this Policy and request your consent through the system permission prompt.
We retain personal data only for as long as necessary for the purposes described in this Policy, or as required by law:
When data is no longer needed, we delete it or de-identify it. Note that third-party providers (Section 7) retain data according to their own retention policies.
We take reasonable steps to protect your personal data:
Personal data breach notification. In line with the PDPA (as amended), if a personal data breach affecting your personal data occurs, we will notify the Personal Data Protection Commissioner as soon as practicable after becoming aware of it and, where the breach is likely to cause you significant harm, we will notify you without unnecessary delay.
No method is perfectly secure
Loka is based in Malaysia, but some of the service providers we rely on - including Google/Firebase, Mapbox, and our cloud/hosting and AI infrastructure - operate globally. As a result, your personal data may be processed, stored, or transferred to servers located outside Malaysia. Where data is transferred internationally, we take reasonable steps so that it remains protected consistent with this Policy and applicable law, including the PDPA’s requirements for cross-border transfers. By using Loka, you consent to such transfers where necessary to provide the service.
Subject to the PDPA (as amended), you have the right to:
You can update much of your profile and saved content directly in the app. To exercise any of these rights, contact our Data Protection Officer at faizal@loka.my (see Section 18). We may need to verify your identity before acting on your request, and we will respond within the timeframe required by applicable law. Withdrawing consent or limiting processing may mean certain features no longer work. If you are not satisfied with our response, you may lodge a complaint with the Personal Data Protection Commissioner of Malaysia.
How to delete your account
If you prefer, you can also request deletion by emailing our Data Protection Officer at faizal@loka.my from the email address linked to your Loka account (or otherwise allow us to verify your identity), with the subject line “Account Deletion Request.” We handle deletion in line with the Apple App Store and Google Play account-deletion requirements and the PDPA.
Please note that saved tours stored locally on your device are device-local and are not held on our backend; you can remove them in-app or by uninstalling the app. Data held by third-party providers is subject to their own deletion processes.
Signing out of the app clears your locally cached session and user-scoped data on the device, but does not by itself delete your account or backend-stored data - use the deletion request route above for that.
Loka is not directed at children. Consistent with our Terms and Conditions, you must be at least 18 years of age, or possess the legal capacity to enter into a binding contract in your jurisdiction, to create an account. We do not knowingly collect personal data from children below the applicable age. If you believe a child has provided us with personal data, please contact us at faizal@loka.my and we will take reasonable steps to delete it.
The Loka app does not currently use any third-party analytics, advertising, attribution, or crash-reporting SDKs. We do not build advertising profiles, and we do not track you across other companies’ apps or websites. If we introduce analytics or crash-reporting in future, we will update this Policy, update our App Store / Google Play data disclosures, and where required obtain your consent.
Cookies and similar technologies. The Loka mobile app does not use advertising or analytics cookies. When you use the loka.my website, we may use strictly necessary cookies that are required for the site to function (for example, to keep you signed in or to remember your preferences). If we introduce non-essential, analytics, or advertising cookies on the website, we will provide notice and, where required by law, obtain your consent before doing so.
Because the Loka app is distributed through the Apple App Store and Google Play, the following applies:
We may update this Privacy Policy from time to time to reflect changes to the Services, our practices, or legal requirements. When we make material changes, we will update the “Last updated” date above and, where appropriate, provide a more prominent notice in the app. Your continued use of Loka after an update takes effect constitutes acceptance of the revised Policy. We encourage you to review this Policy periodically.
If you have questions about this Policy, wish to exercise your PDPA rights, or want to request account deletion, please contact us:
This Policy and your use of the Services are governed by the laws of Malaysia, and any related legal matters will be resolved in the Malaysian courts.
For quick reference, and to align with Apple App Store and Google Play disclosures, here is a plain-language summary of the Loka app’s data practices. The detailed sections above govern in case of any difference.
| Data type | Collected? | Linked to you? | Purpose |
|---|---|---|---|
| Contact info (email) | Yes | Yes | Account & authentication |
| Name / profile photo | Yes (if provided) | Yes | Account & profile |
| User ID (Firebase UID) | Yes | Yes | Account identity |
| Approximate location | Yes (with permission) | Yes (signed-in) | Discovery, maps, AI context |
| User content (AI chat, itineraries, saved items) | Yes | Yes | App functionality |
| Device & technical metadata | Yes | Yes | Security, operation |
| Government ID / payment / financial data | No | N/A | N/A |
| Analytics / advertising / tracking data | No | N/A | N/A |
Data sold? No. Used for tracking across other apps/sites? No. Used for third-party advertising? No.
This Privacy Policy governs your use of the Loka Services, including the Loka mobile app for iOS and Android. See also our Terms and Conditions.
© 2026 · Loka · Privacy Policy · Last updated 13 June 2026