Privacy

Privacy Policy

This policy explains what personal data Chikooya collects, why we collect it, whom we share it with, how long we keep it, and the rights you can exercise under the Digital Personal Data Protection Act, 2023. It also explains exactly how facial verification and automated video call safety screening work.

Version
1.0
Effective from
Last updated

1.Who we are and what this policy covers

This policy applies to the Chikooya dating application and the website at chikooya.com. For the purposes of the Digital Personal Data Protection Act, 2023 we are the Data Fiduciary in respect of the personal data described in this policy, and you are the Data Principal.

This policy explains what personal data we collect, why we collect it, the legal basis on which we process it, whom we share it with, how long we keep it, how we protect it, and the rights you can exercise. It applies to the Chikooya app, the Chikooya website and all related services.

This policy is published in accordance with the Information Technology Act, 2000, the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021 and the Digital Personal Data Protection Act, 2023.

Dating profiles reveal intimate details about a person. We have tried to write this policy in plain language, and to collect as little as we can while still keeping the platform safe.

2.Personal data we collect

Data you give us during sign up

  • Email address, or mobile number, or the identifier issued by Google, Apple or Facebook if you use social sign in.
  • Password, which is stored only as a one way salted hash and is never readable by us.
  • One time passwords used to verify your email address or mobile number.
  • Referral code, if you were invited by an existing Member.

Profile and onboarding data

  • Full name and any nicknames you choose to display.
  • Date of birth, which we use to confirm you are 18 or over and to show your age.
  • Gender, and the gender you are interested in.
  • Profile photograph and album photographs.
  • Bio, profession and interests.
  • Height, marital status, religion and community details, where you choose to provide them.
  • City, state, country and postal code from the address you provide, and your place of birth.
  • Time of birth and place of birth, only if you choose to use astrology and compatibility features.
  • What you are looking for, such as marriage, a long term relationship or friendship, and your preferred age range.

Some of these fields, in particular religion, community, sexual orientation implied by your stated preference, and biometric facial data, are sensitive personal data under Indian law. We collect them only where you choose to provide them or where they are necessary to run a dating service, we ask for your explicit consent, and we apply stricter access controls to them.

Facial verification data

During onboarding we ask you to take a live selfie. That image is analysed by an automated facial analysis service to confirm that exactly one clear, unobstructed, forward facing human face is present, that the eyes are open, and that the capture is of adequate quality. The check produces a pass or fail result together with quality signals. This is biometric data and is treated as sensitive personal data. It is used only for verification and anti impersonation purposes and is never used for advertising, for identifying you across other services, or for sale.

Activity data generated by your use

  • Profiles you view, like, super like, skip, rate, block or report.
  • Matches, conversations, message content, message status and reactions.
  • Audio and video call metadata, such as who called whom, the time and the duration.
  • Reports you file and reports filed against you, along with the evidence attached to them.

Device, technical and log data

  • Device identifier, device model, operating system and app version.
  • IP address, approximate location derived from IP address, and time zone.
  • Session records, login and logout times, and refresh token identifiers stored in hashed form.
  • Push notification tokens.
  • Crash logs, diagnostic logs and error traces.

Transaction data

  • Plan purchased, order identifier, amount, currency, tax, status, date and time of payment.
  • A payment reference, a masked payment instrument identifier and the payment method type returned by the payment gateway.
  • Invoices, refunds and any chargeback correspondence.

We never receive or store your full card number, CVV, card expiry, UPI PIN, net banking password or any other authentication factor. Those are captured directly by the payment gateway on a PCI DSS certified environment.

Data from third parties

  • Basic profile fields such as name, email address and profile picture from Google, Apple or Facebook where you sign in with them, subject to the permissions you grant.
  • Payment status confirmations from our payment gateway.
  • Signals from anti fraud and anti abuse providers where we need to detect duplicate or automated accounts.

3.Video calls, chats and automated safety screening

Chikooya offers audio and video calling between matched Members, and every call and every chat is subject to automated safety screening designed to detect unwanted activity such as nudity, sexual content, child sexual abuse material, violence, weapons, self harm, coercion, sextortion, abusive language, scams and spam.

What this means in practice:

  • Calls are not recorded for general purposes. We do not create a stored recording of your calls, we do not make calls available for playback, and no employee listens to or watches a live call.
  • Screening is transient. Sampled video frames and short audio segments are analysed in memory by automated classifiers and are discarded immediately afterwards where no violation signal is produced.
  • Only violation evidence is retained. Where a classifier produces a high confidence violation signal, or where a Member presses the report button during or immediately after a call, the relevant frame or short segment together with the associated metadata is retained as evidence for the periods listed in the retention table below, so that it can be reviewed, so that an appeal can be decided, and so that it can be preserved for law enforcement where the law requires it.
  • Chat messages are stored so that conversations work, and are scanned by automated classifiers for the same categories of harm.
  • Human review is limited. A trained reviewer sees content only when it has been flagged by a Member report or by an automated signal, and reviewer access is logged.

Screening is a condition of using the Services and cannot be switched off, because it exists to protect other Members as much as it protects you. Depending on severity, the system may blur the offending video, warn both participants, disable the camera, or end the call and lock calling on the offending account pending review.

These systems are not perfect. A swimming costume can be read as nudity and a joke can be read as a threat. We therefore never impose a permanent ban on an automated signal alone, except for confirmed child sexual abuse material. Where an automated decision materially affects your account, you have the right to human review: use the appeal link in the notification, or write to hello@chikooya.com. We acknowledge within 24 hours and give a reasoned decision within 15 days, and a reviewer who is not the system that made the original decision decides the appeal.

These systems are never used to build advertising profiles, to score your appearance, to infer your personality or emotions for commercial purposes, or to identify you on any other service. We do not sell or share biometric data.

4.Why we process your data and on what legal basis

PurposeData usedBasis
Create and secure your accountEmail, mobile number, password hash, device and session dataPerformance of the contract with you and your consent
Confirm you are 18 or overDate of birthLegal obligation and legitimate use
Verify that a real, single person is behind a profileSelfie and facial analysis resultExplicit consent for biometric data, and platform safety
Show your profile to compatible Members and rank discoveryProfile, preferences, activity, subscription tierPerformance of the contract with you
Enable chat, calling and matchesMessages, call metadata, match recordsPerformance of the contract with you
Detect and act on unwanted activity in photos, chats and callsMedia samples, message content, reports, device signalsLegitimate use for prevention of fraud and harm, and legal obligation as an intermediary
Process payments, issue invoices and handle refundsOrder, transaction and subscription dataPerformance of the contract and legal obligation under tax law
Provide customer support and handle grievancesCorrespondence, account and transaction dataPerformance of the contract and legal obligation
Send transactional notifications such as one time passwords and payment receiptsEmail, mobile number, push tokenPerformance of the contract
Send offers, product updates and marketingEmail, mobile number, push tokenYour consent, withdrawable at any time
Improve the product and measure feature performanceAggregated and de identified usage dataLegitimate use
Comply with court orders, government directions and tax and accounting lawWhatever is specified in the lawful requestLegal obligation

We do not sell your personal data. We do not share your profile, photographs, messages or facial data with advertisers or data brokers.

5.What other Members can see

  • Your display name, age, gender, photographs, bio, profession, interests, what you are looking for, and the city and state you have set, are visible to other Members who can see your profile in discovery.
  • Your album photographs may be restricted to certain Members depending on your settings and on the subscription tier of the person viewing.
  • Your exact address, postal code, email address, mobile number, date of birth, payment data and verification imagery are never shown to other Members.
  • Depending on plan features, Members may be able to see that you viewed or liked their profile. You can control visibility settings from within the app.
  • When you block a Member, you disappear from their discovery and they disappear from yours. The block itself is not disclosed to them as an event.

Anything you choose to share inside a chat or a video call is shared with that Member directly. We cannot prevent another person from remembering, transcribing or photographing what you show them. Never share intimate content, identity documents or financial information with someone you have met online, however well the conversation is going.

6.Who we share your data with

We share personal data only where it is necessary, and only with categories of recipients listed here. Every processor is bound by a written agreement that limits them to processing on our instructions and requires appropriate security safeguards.

Recipient categoryExamplesWhat they receive
Cloud hosting and storageAmazon Web Services, managed database hostingAll application data, encrypted in transit and at rest
Facial analysisAmazon RekognitionThe selfie submitted for verification, for automated analysis
Media storage and deliveryAmazon S3 with time limited signed URLsProfile and album images
PaymentsRazorpay Software Private Limited, banks and card networksOrder identifier, amount, currency, contact identifiers required for the transaction
CommunicationsSMS one time password provider, transactional email providerMobile number or email address and the message content
App stores and sign in providersGoogle, Apple, FacebookAuthentication tokens and identifiers you have authorised
Analytics, crash reporting and push deliveryMobile analytics and crash reporting toolsDevice and event data, pseudonymised where possible
Professional advisersAuditors, lawyers, accountantsOnly what is necessary for the engagement
Law enforcement and courtsPolice, courts, regulatorsOnly what is specified in valid legal process
Corporate transactionsAn acquirer in a merger or sale of assetsSubject to this policy continuing to apply, with notice to you

Requests from law enforcement are honoured only against valid legal process, such as a written request under section 91 of the Bharatiya Nagarik Suraksha Sanhita, 2023, a court order, or a direction under section 69 of the Information Technology Act, 2000. We disclose only what the request specifies, we reject requests that are overbroad or that lack authority, and we notify the affected Member unless we are legally barred from doing so or notification would risk life or an investigation.

7.How long we keep your data

We keep personal data only for as long as it is needed for the purpose for which it was collected, or for as long as the law requires.

CategoryRetention period
Active account profile dataFor as long as your account is active
Selfie submitted for verificationDeleted after the verification result is produced and the account is activated. The pass or fail result and a non reversible reference are retained while the account is active
Temporary uploads that are never confirmedAutomatically purged from temporary storage
Chat messagesUntil deleted by a participant or until the account is deleted
Video and audio call streamsNot stored
Call safety samples with no violation signalDiscarded immediately after analysis
Evidence retained after a violation signal or a Member reportUp to 180 days, or longer where a legal proceeding or a preservation request requires it
Session and login recordsSession records expire automatically after the refresh token lifetime
Server and security logsUp to 180 days, in line with the requirement to retain such logs under Indian law
Transaction, invoice and tax recordsEight financial years, as required under Indian tax and company law
Grievance and support correspondenceThree years from closure of the complaint
Records of banned accountsA minimal record, including a hashed identifier, retained indefinitely to prevent a banned Member from re registering and to protect other Members
Deleted account dataErased or irreversibly anonymised within 30 days of deletion, except for the categories above that must be retained

The deletion process and its effects are described in full in Deleting your account and your data.

8.Deleting your account and your data

You can delete your Chikooya account at any time. Deletion is permanent and cannot be undone.

In the app

  1. Open Chikooya and go to Profile, then Settings.
  2. Select Account, then Delete account.
  3. Confirm your identity with your password or a one time password.
  4. Choose a reason if you wish, and confirm.

By email

Write to hello@chikooya.com from the email address registered on your account, with the subject line Delete My Account, and include your registered mobile number or Chikooya ID. We verify the request and complete it within 30 days.

Before you delete

  • Deleting the app from your phone does not delete your account. Your profile stays visible until you delete the account itself.
  • Deleting your account does not automatically cancel a subscription bought through the App Store or Google Play. Cancel that in the store first.
  • No refund is payable for the unused part of a paid term on deletion. See Cancellation and refunds.

What is deleted

  • Your profile, photographs, album, bio, preferences and birth details.
  • Your likes, super likes, views, ratings and matches.
  • Your messages, subject to the note below on copies held by the other participant.
  • Your device records, sessions and push tokens.
  • Your facial verification result.

What is retained, and why

  • Transaction, invoice and tax records, for eight financial years, as required under Indian tax and company law.
  • Moderation evidence and records relating to a report, a ban or an ongoing investigation, for as long as required to protect other Members or to comply with law.
  • A minimal, hashed record of a banned account, retained to stop a banned Member from re registering.
  • Server and security logs, for up to 180 days.
  • A copy of a message already delivered to another Member, which remains in that Member copy of the conversation.
  • Aggregated and de identified statistics, which can no longer identify you.

Everything else is erased or irreversibly anonymised within 30 days of the deletion request, from production systems and from encrypted backups on their normal rotation cycle.

9.Your rights as a Data Principal

Under the Digital Personal Data Protection Act, 2023 you have the right to:

  • Access a summary of the personal data we process about you, the processing activities undertaken, and the identities of the Data Fiduciaries and processors with whom it has been shared.
  • Correction, completion and updating of inaccurate or incomplete data. Most profile fields can be corrected directly in the app.
  • Erasure of personal data that is no longer necessary for the purpose for which it was collected, unless retention is required by law.
  • Withdraw consent at any time. Withdrawal takes effect prospectively, and where consent was necessary to provide the Services, withdrawal may mean that we can no longer keep your account open.
  • Grievance redressal through the process described in section 12, before approaching the Data Protection Board of India.
  • Nominate another individual to exercise your rights in the event of your death or incapacity.

To exercise any of these rights, write to hello@chikooya.com from the email address registered on your account, or use the in app privacy controls. We respond within 30 days. We may need to verify your identity before acting, and we may decline a request that is manifestly unfounded, repetitive, or that would prejudice the rights of another Member, giving you reasons.

You are also under a duty not to impersonate another person, not to suppress material information when providing data, and not to file a false or frivolous complaint.

10.How we protect your data

  • All traffic between your device and our servers is encrypted using TLS.
  • Passwords are stored as salted one way bcrypt hashes and are never recoverable.
  • Sensitive stored values are encrypted using AES 256 in Galois Counter Mode, and refresh tokens are stored only as SHA 256 digests.
  • Access tokens are short lived and are bound to a specific device, and sessions expire automatically.
  • Media is stored in private object storage and is served only through short lived, signed URLs.
  • Access to production systems and to any moderation evidence is restricted on a least privilege basis, requires multi factor authentication, and is logged.
  • We follow reasonable security practices and procedures within the meaning of Rule 8 of the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011.

No system is perfectly secure. If a personal data breach occurs, we will notify the Data Protection Board of India and every affected Data Principal in the manner and within the timelines prescribed under the Digital Personal Data Protection Act, 2023, and will report the incident to the Indian Computer Emergency Response Team where the applicable directions require it.

11.Children

Chikooya is an adults only service. We do not knowingly collect personal data from any person below 18 years of age, and we do not permit any person below 18 to hold an account, to be depicted in any profile photograph or album, or to take part in any chat or call.

We verify age at sign up using date of birth, we run automated checks that look for indicators of under age accounts, and we act on Member reports. If we learn that a Member is below 18, we terminate the account immediately and delete the associated personal data, other than the minimum record needed to prevent re registration and any material we are legally required to preserve.

If you believe a person below 18 is using Chikooya, report the profile in the app or write immediately to hello@chikooya.com. Confirmed child sexual abuse material is preserved and reported to the competent authority under the Protection of Children from Sexual Offences Act, 2012 and the Information Technology Act, 2000.

12.Storage location and cross border transfers

Our primary databases and media storage are hosted on cloud infrastructure. Some of our processors, including cloud, analytics and communications providers, may process data on servers located outside India.

Where personal data is transferred outside India, we do so in accordance with section 16 of the Digital Personal Data Protection Act, 2023 and any restrictions notified by the Central Government, and we put contractual safeguards in place with the recipient requiring a standard of protection equivalent to this policy. Payment data continues to be stored in India in accordance with the Reserve Bank of India directive on storage of payment system data.

13.Cookies, SDKs and marketing preferences

Our website uses a small number of cookies, and our app uses software development kits that store identifiers on your device. We do not use third party advertising cookies and we do not sell data to ad networks.

CategoryWhat it doesCan you refuse it
Strictly necessaryKeeps you signed in, remembers your session and device, protects against fraud and abuse, and balances loadNo, the service cannot work without it
PreferenceRemembers your language, theme and display choicesYes, clear them in your browser or device settings
AnalyticsCounts visits and measures which features are used, in aggregate and pseudonymised formYes, opt out in app settings or in your browser
Crash and diagnosticsRecords errors so we can fix themYes, opt out in app settings

You can clear or block cookies in your browser settings, and reset or limit the advertising identifier on your phone in the device privacy settings. Blocking strictly necessary cookies will stop you from signing in.

You can opt out of promotional email at any time using the unsubscribe link in the message, opt out of promotional SMS by replying with the stop keyword, and turn push notifications off in your device settings or in the app. Transactional messages such as one time passwords, payment receipts, security alerts and policy change notices cannot be switched off while your account is open.

14.Contact, Data Protection Officer and grievances

Write to hello@chikooya.com from the email address registered on your account. Mark the subject Privacy so that it reaches the right team, and mark it Grievance if you are filing a formal complaint. You may also call +91 74285 24629 during working hours, or write to us at H. No. 142, F-1 Block, Street No. 5, Near Old Shiv Temple, Sunder Nagri, North East Delhi, Delhi 110093, India.

  • Privacy requests, including access, correction, erasure and withdrawal of consent, are resolved within 30 days.
  • Formal grievances are acknowledged within 24 hours and resolved within 15 days by our Grievance Officer, Rohit Kohli, appointed under Rule 3(2) of the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021.

Data Protection Board of India

If you are not satisfied with the outcome, you may make a complaint to the Data Protection Board of India in the manner prescribed under the Digital Personal Data Protection Act, 2023.

15.Changes to this policy

We may update this policy as the Services, our processors or the law change. The current version and its effective date always appear at the top of this page. Where a change materially affects how we use your personal data, we will notify you by email or by an in app notice before it takes effect, and where the law requires it we will ask for fresh consent.