Privacy Policy

Last updated: 21 September 2026 · OZVAK (private dating, adults only)

What this policy promises, and what it does not

OZVAK is built so that other members learn nothing about you until you choose, and so that we hold as little as the service can run on. That is a real design position and the rest of this page shows exactly where it holds.

It is not a claim that we know nothing about you. We do hold things. Your sign-in address sits in our authentication system. The words you write into your profile and your notes sit on our servers in readable form. We can see who messages whom and when, even though we cannot read what was said. We would rather write that down than let you discover it later.

The service is operated by [COMPANY LEGAL ENTITY] of [REGISTERED ADDRESS], which is the data fiduciary under India's Digital Personal Data Protection Act, 2023 and the data controller for the purposes of the EU GDPR where it applies.

What we collect in the app

What we collect on this website

If you join the waitlist here, we store the email address you type and, only if you fill them in, your city, the language you would use, and how you describe your gender. We also store which version of the headline you saw. This is separate from an app account.

The message checker on our home page runs entirely in your browser. Text you paste into it is never sent to us. If you then join the waitlist, the numeric score it produced is submitted with your entry, because it tells us how worried people arrive. The text itself is not.

How we use it

We use your data for these purposes and no others. We do not repurpose it and we do not profile you for advertising.

Messages are end-to-end encrypted

Message bodies are encrypted on the sending device and decrypted on the receiving device. The conversation key is derived by X25519 Diffie-Hellman between the two members' long-term identity keys, passed through HKDF-SHA256, and used with XChaCha20-Poly1305 and a fresh 24-byte random nonce for every message. Each message is cryptographically bound to its conversation and its sender, so a message cannot be replayed into a different conversation or re-attributed to someone else. All the cryptographic primitives come from audited open-source libraries. Your private key is generated on your device, held in the platform secure store so that it is excluded from cloud keychain backup, and is never transmitted. Our servers hold only the encrypted text and cannot read your messages.

Three limits belong in the same breath, every time, because a claim like the one above is only honest with them attached:

And what the encryption does not cover, stated plainly: everything that is not a message body. Your alias, your intent, your availability, your notes, your city, your tags, your report text and your photos are not end-to-end encrypted. Photos are protected by an access rule on our server, which is access control, not encryption.

Photos

Photos live in a private bucket and are only ever served through links that expire. Two versions of each photo exist, and the difference is the whole mechanism:

Being exact about screening, because this is where products in this category overclaim: no automated photo screening is operating today. The seams are built on both sides, on the device and on the server, and neither is switched on. The on-device classifier has no model wired yet, and the server-side requirement is turned off for the closed test, so uploads are approved without an automated check. Neither seam ever declares an image safe on its own. What protects members right now is the rule that explicit media is not allowed, the fact that no full-resolution photo moves without mutual consent, and report and block. When automated screening is switched on, this page will say so.

Who else receives data

We do not sell your data and we share it with no one for their own purposes. These providers process it on our behalf so the service can run:

Your personal data is processed in ap-south-1 (Mumbai, India), and our error monitoring data is processed in the United States.

What we never do

How long we keep data

We keep data while your account exists and for as long as the service needs it. An introduction and an intent expire on their own and stop being visible. When you delete your account we erase your data as described below. Where the law requires us to retain a limited record, for example to answer a lawful order or to keep a ban working, we keep only that and only for as long as it is required.

Deleting your account

The complete description, including the two-line list of what is kept, is on our Delete your account page, which also covers what to do if you can no longer open the app. In summary:

In the app, open Settings and choose to delete your account. It runs for real: your profile, your intents, your introductions, your conversations and your stored photos are removed, your login is deleted, and the keys on your device are destroyed so any encrypted text that still exists anywhere can never be read. There is no waiting period, no retention offer and no maze.

One thing survives deletion, and we will not hide it: a ban. If your account has been banned, the ban is tied to the one-way value derived from your sign-in credential, not to the account, so deleting the account does not lift it. This is on purpose. Someone removed for harming another member must not be able to return by deleting themselves. If you have not been banned, that value is released when you delete, and you are free to rejoin later.

Your rights

India (DPDP Act 2023)

We process your personal data on the basis of your consent, for the purposes set out above and for nothing else, and we collect only what those purposes need. You may withdraw consent at any time, including by deleting your account. You have the right to access, correct and erase your data, the right to nominate someone to exercise your rights if you cannot, and the right to grievance redressal. Your data is processed in ap-south-1 (Mumbai, India).

Two things this Act makes us state honestly rather than favourably. First, no product table holds a name, an email address or a date of birth, which is a real minimisation, but it does not discharge our duties: our authentication system holds your sign-in address, we store a one-way value derived from it, our error monitoring provider receives diagnostic data, and you can type anything you like into a free-text note. Our obligations attach to all of that. Second, nothing in OZVAK verifies your age. The app requires you to confirm you are 18 or over, and a sign-in code proves control of an address and nothing more. We act on reports and remove anyone we learn is under 18. Stronger age assurance is planned and is not shipped.

If a personal data breach occurs we will notify the Data Protection Board of India and every affected user, as the Act requires. Our data protection contact is [GRIEVANCE OFFICER NAME], reachable at privacy@[LEGAL DOMAIN].

Europe (GDPR)

If you are in the EU or EEA you have the rights of access, rectification, erasure, restriction, portability and objection, and the right to complain to your local supervisory authority. Our lawful bases are the performance of our contract with you, for running the service, and your consent, for optional features. Where data is processed outside the EEA, it is transferred under the safeguards our providers offer for that purpose. Contact us to exercise any of these rights.

Google Play Data Safety

This policy is written to match our Google Play Data Safety declaration. In short: we collect an email address for sign-in, an account id, the profile and intent you write, your launch city, photos you add, encrypted message contents with readable metadata, reports and blocks, a notification token, and crash and diagnostic data. Crash and diagnostic data goes to our error monitoring provider. We collect no location and no contacts. We do not sell your data and do not use it for advertising. You can delete everything from Settings in the app, or by writing to the address below.

Changes

If we change what we collect or what we do with it, we update this page and change the date at the top. Where a change is significant we will say so in the app.

Contact

Privacy questions and data requests: privacy@[LEGAL DOMAIN]. For formal grievances, see our Grievance Redressal page.