Privacy Policy
Last updated: 2026-06-28 · India · DPDPA 2023
1. Who we are
Rightswype (“we”, “us”) is a dating service operated from India. We are the Data Fiduciary under the Digital Personal Data Protection Act, 2023 (DPDPA) for the personal data you provide while using the app.
Contact: privacy@rightswype.com for privacy questions; see /contact for our Grievance Officer.
2. What we collect
Account data — email address, hashed password (we never see your password in clear text), and a login session token.
Profile data — first and last name, date of birth (used to compute and display age, and to enforce 18+), gender, city, intent (long-term / casual / friendship), bio, photos, optional fields (occupation, education, religion, height), and your discover filter preferences.
Verification selfie — if you choose to verify your profile, we keep a single selfie for face-matching against future photo uploads. Stored privately; never displayed to other users.
Usage data — your swipes (like / pass / super-like), matches, conversations, blocks, reports. Activity timestamps so we can show people who are recently active in their deck.
Payment data — if you subscribe, Razorpay (our payments processor) handles your card / UPI details. We never see them. We store the subscription status, plan tier, and renewal date.
Device data — if you use the mobile app, an Expo push token that lets us send you match / message alerts. Generic device platform (iOS / Android). IP address on each request (server logs; rotated after 30 days).
Cookies and similar storage — we use a first-party session cookie (auth) and local storage in the browser (UI preferences). We do not use third-party advertising cookies. PostHog (analytics) sets a first-party cookie to de-duplicate sessions.
3. Lawful basis — why we may process this
Under DPDPA, every category of personal data we process relies on one of the following:
- Your consent (Section 6) — given when you sign up, accept these terms, and add data to your profile. You may withdraw consent any time by deleting your account.
- Performance of the service — the data necessary to operate matching, messaging, and payments.
- Legal compliance — payment audit trails required by Indian tax law; lawful requests from authorities.
- Legitimate use (Section 7) — fraud prevention, account security, abuse detection, moderation.
4. How we use it
- Show you people you can match with, ranked by a transparent score (recency + completeness + city + intent + premium)
- Show your profile to other users who match the filters you've set
- Deliver messages between matched users in real time
- Send push notifications for new matches and new messages
- Moderate uploaded photos, bios, and messages for harmful content using automated systems (see Section 5)
- Enforce safety: block-on-report cooldowns, account-deletion cascade, premium-feature gating, rate limits
- Comply with legal obligations and respond to lawful requests
5. Automated decision-making & AI moderation
We use automated systems to keep the service safe. Specifically:
- Photo moderation — every uploaded photo is checked by an automated NSFW / safety classifier before becoming visible. Borderline cases are reviewed by a human moderator.
- Bio & message moderation — text is screened for hate, harassment, sexual content involving minors, and self-harm. Some categories are blocked outright; others trigger a confirmation prompt before sending.
- Verification — your verification selfie is matched against your profile photos using a face-match service. A high-similarity match triggers the verified badge; mismatches require manual review.
- Discover ranking — the order of profiles in your deck is determined by a deterministic, non-personal score (recency, profile completeness, city match, intent match, premium boost). No black-box AI.
If an automated decision blocks something you posted, you can appeal via safety@rightswype.com and a human will re-review within 48 hours.
6. Third parties (Data Processors)
We use the following services to run Rightswype. Each receives only the data it needs and is bound by contractual confidentiality.
- Supabase (database, authentication, storage, realtime) — hosts your data in the ap-south-1 region (Mumbai, India). No data leaves India for primary processing.
- OpenAI(content moderation, photo coaching, verification face-match) — receives photo URLs and short text snippets (bios, individual messages). OpenAI's API terms confirm they do not train on API traffic by default.
- Razorpay (payments) — receives your card / UPI details directly during checkout. We never see them. PCI-DSS compliant.
- Expo (push notification delivery on mobile) — receives the push token + notification preview.
- PostHog (product analytics) — receives de-identified event data hosted in the EU. We do not send your email or phone to PostHog.
- Resend (transactional email) — receives your email address and the email contents we send you (verification links, password resets).
- Vercel (web hosting) and Google Play / Apple App Store (mobile distribution) — receive standard CDN / app-distribution data.
7. International data transfers
Your primary personal data is stored in Mumbai, India. Some of our processors (OpenAI, PostHog, Expo) operate outside India. We rely on standard contractual clauses and processor obligations under DPDPA for those transfers, and we limit what we send to the minimum needed for each operation.
8. Your rights
Under DPDPA, you have the right to:
- Access the data we hold about you — your profile page shows the bulk of it; for the rest, email the Grievance Officer
- Correct inaccurate data — most fields are editable directly via /onboarding
- Deleteyour account and all associated data via the “Delete account” button on /account. The deletion is permanent, immediate, and includes your profile, photos, verification selfie, matches, conversations, push tokens, and subscriptions
- Withdraw consent — same flow as deletion
- Nominate another person to exercise these rights in the event of your death or incapacity — email the Grievance Officer to register a nominee
- File a grievance — see /contact for the Grievance Officer. We acknowledge within 24 hours (per IT Rules 2021 Rule 3(2)(a)) and resolve content/safety grievances within 15 days. Data-only grievances under DPDPA may take up to 30 days where complex
- Appeal to the Grievance Appellate Committee (GAC, at https://gac.gov.in) if you're unhappy with the Grievance Officer's decision — per IT Rules 2021 Rule 4A
9. Data retention
We retain your profile data and conversations for as long as your account exists. When you delete your account, everything tied to you is removed from the product within seconds (cascade delete across profile, photos, matches, conversations, swipes, blocks, push tokens, and subscriptions). You and other users see the account as gone immediately.
Limited records retained for 180 days post-deletion — IT Rules 2021 Rule 3(1)(h) requires intermediaries to preserve a minimal set of information for 180 days after user removal to support lawful investigations. We retain only: account email, last-known IP address, login timestamps, and the metadata of any content under active investigation. We do not retain profile text, photos, messages, or any usage detail beyond what this rule requires. After 180 days these records are purged.
Other limited records may be retained for legal compliance — payment audit trails for the period required by Indian tax law, abuse-investigation case files for up to 90 days after account closure. These are minimal and never include unrelated profile content.
10. Security & breach notification
We use industry-standard practices: TLS in transit, at-rest encryption on database and storage, row-level access control, restricted column-level reads on sensitive fields, HSTS, content security policy, and per-user rate limits on abuse-prone endpoints.
No system is unbreakable. If a personal data breach occurs that is likely to result in a risk to your rights, we will notify the Data Protection Board of India and affected users without undue delay, as required by DPDPA Section 8(6).
11. Children
Rightswype is 18+ only. We collect date of birth and verification photos to enforce this. If we learn we have data on a person under 18, we will delete it and terminate the account.
12. Changes to this policy
We may update this policy as the product evolves. When we do, we'll update the “Last updated” date above and (for material changes) notify you via email or an in-app banner at least 7 days before the change takes effect.
13. Governing law
This policy is governed by the laws of India. Disputes are subject to the exclusive jurisdiction of the courts of Bengaluru, Karnataka, after the dispute-resolution process in our Terms of Service has been exhausted.