Privacy Policy
Last updated: 21 September 2026 · OZVAK (private dating, adults only)
What this policy promises, and what it does not
OZVAK is built so that other members learn nothing about you until you choose, and so that we hold as little as the service can run on. That is a real design position and the rest of this page shows exactly where it holds.
It is not a claim that we know nothing about you. We do hold things. Your sign-in address sits in our authentication system. The words you write into your profile and your notes sit on our servers in readable form. We can see who messages whom and when, even though we cannot read what was said. We would rather write that down than let you discover it later.
The service is operated by [COMPANY LEGAL ENTITY] of [REGISTERED ADDRESS], which is the data fiduciary under India's Digital Personal Data Protection Act, 2023 and the data controller for the purposes of the EU GDPR where it applies.
What we collect in the app
- Your email address. Used to send a one-time sign-in code, through our authentication provider. It lives in the authentication system, and it is never written to any product table: your profile, your notes, your messages and your reports are keyed to a random account id instead.
- A one-way value derived from that address. We compute a keyed hash of your sign-in address on our server so that one credential maps to one account, and so that a ban keeps working after an account is gone. It is stored instead of the address it came from. Being precise about what this is worth: it proves control of a sign-in credential and nothing else. It does not establish that you are a particular person, that you are one person, or how old you are. And because it is a keyed hash rather than a shredder, someone holding our secret key and guessing your address could confirm the guess. We treat that key accordingly.
- A random account id. What your profile and your activity actually key off, in place of any real-world identity. We store no legal name and no date of birth, in any product table.
- Your profile and your intent. The alias you pick, what you are open to, your availability, the tags you choose, and any note you write. Notes are free text, up to 140 characters on an intent and 280 on an introduction. These sit on our servers in readable form, because other members have to be able to read them. Do not put anything in them you would not want us to hold.
- Your city. Recorded as the launch market your account belongs to. It is a fixed value attached to your account, not something read off your device.
- Photos. The images you add, stored in a private bucket. Your full-resolution photo is not released to another member until a server-side check confirms that both of you have chosen to reveal. A 48-pixel-wide blurred thumbnail can be visible before that. See Photos below.
- Messages. We store the encrypted contents, which we cannot read, together with who sent a message, in which conversation, and when. See Messages are end-to-end encrypted below.
- Reports and blocks. The reason you pick, any detail you type, and both account ids. If you choose to attach evidence to a report, up to 20 of the flagged messages are sent to us in readable form. That is deliberate, it is the only way a human can act on an encrypted conversation, and it happens only when you report.
- A notification token. Issued by the push service so we can tell your device something happened. Notification text is deliberately vague and does not announce what this app is on your lock screen.
- Crash and performance data. Sent to our error monitoring provider so we can fix what breaks. On a small share of errors this includes a replay of the screen with all text and images masked.
- Whether you are a paying member. We store the fact of the entitlement. We never see or store your card, bank or UPI details.
What we collect on this website
If you join the waitlist here, we store the email address you type and, only if you fill them in, your city, the language you would use, and how you describe your gender. We also store which version of the headline you saw. This is separate from an app account.
The message checker on our home page runs entirely in your browser. Text you paste into it is never sent to us. If you then join the waitlist, the numeric score it produced is submitted with your entry, because it tells us how worried people arrive. The text itself is not.
How we use it
- To sign you in, with a one-time code to your email address.
- To keep one sign-in credential to one account, and to make a ban stick.
- To run the service: matching on intent, introductions, and delivering your messages.
- To release a photo to one specific person once you have both chosen to.
- To act on reports and blocks, and to keep the community safe.
- To fix crashes and keep the app working.
- To unlock paid features once you subscribe.
We use your data for these purposes and no others. We do not repurpose it and we do not profile you for advertising.
Messages are end-to-end encrypted
Message bodies are encrypted on the sending device and decrypted on the receiving device. The conversation key is derived by X25519 Diffie-Hellman between the two members' long-term identity keys, passed through HKDF-SHA256, and used with XChaCha20-Poly1305 and a fresh 24-byte random nonce for every message. Each message is cryptographically bound to its conversation and its sender, so a message cannot be replayed into a different conversation or re-attributed to someone else. All the cryptographic primitives come from audited open-source libraries. Your private key is generated on your device, held in the platform secure store so that it is excluded from cloud keychain backup, and is never transmitted. Our servers hold only the encrypted text and cannot read your messages.
Three limits belong in the same breath, every time, because a claim like the one above is only honest with them attached:
- We distribute the public keys. Your device remembers the first key it sees for a person and refuses to continue if it ever changes, until you accept the change yourself. That turns a silent substitution into a visible warning. It does not remove the trust you place in us to hand out the right key the first time.
- There is no forward secrecy. The conversation key comes from long-term identity keys. Anyone who obtains the secret key on a device can read every message in that thread they hold a copy of, past and future.
- Reporting moves message text to us on purpose. When you attach evidence to a report, those messages arrive readable. The act of reporting is the consent.
And what the encryption does not cover, stated plainly: everything that is not a message body. Your alias, your intent, your availability, your notes, your city, your tags, your report text and your photos are not end-to-end encrypted. Photos are protected by an access rule on our server, which is access control, not encryption.
Photos
Photos live in a private bucket and are only ever served through links that expire. Two versions of each photo exist, and the difference is the whole mechanism:
- A 48-pixel-wide blurred thumbnail, which is what another member can see while browsing. At that size it carries a shape and a colour and not a face.
- Your full-resolution photo, which is released only after a check on our server sees that you and that one specific person have each chosen to reveal. A match on its own opens nothing. Both sides choose, separately, and neither of you learns the other chose until both have.
Being exact about screening, because this is where products in this category overclaim: no automated photo screening is operating today. The seams are built on both sides, on the device and on the server, and neither is switched on. The on-device classifier has no model wired yet, and the server-side requirement is turned off for the closed test, so uploads are approved without an automated check. Neither seam ever declares an image safe on its own. What protects members right now is the rule that explicit media is not allowed, the fact that no full-resolution photo moves without mutual consent, and report and block. When automated screening is switched on, this page will say so.
Who else receives data
We do not sell your data and we share it with no one for their own purposes. These providers process it on our behalf so the service can run:
- Our database, authentication and storage provider. Holds everything listed above that reaches a server.
- Our error monitoring provider. Receives crash reports, performance traces and masked error replays. Its data is processed in the United States.
- Our app build and push provider. Receives an update check when the app starts, and delivers notifications to your device.
- Our payment provider, on the web only. If you subscribe on this website, the payment itself is handled by Razorpay. We receive confirmation that you paid. We never receive your card, bank or UPI credentials.
- Google Play, for purchases made inside the app. Handled under Google's own terms.
Your personal data is processed in ap-south-1 (Mumbai, India), and our error monitoring data is processed in the United States.
What we never do
- We do not sell your data. Ever.
- We do not share it with advertisers, ad networks or ad-tech.
- We do not collect your location. The app asks for no location permission, reads no GPS, and stores no coordinates. Your city is a value on your account, not a measurement of where you are.
- We do not read your contacts, your camera or your microphone.
- We do not ask for, or store, your legal name or your date of birth.
How long we keep data
We keep data while your account exists and for as long as the service needs it. An introduction and an intent expire on their own and stop being visible. When you delete your account we erase your data as described below. Where the law requires us to retain a limited record, for example to answer a lawful order or to keep a ban working, we keep only that and only for as long as it is required.
Deleting your account
The complete description, including the two-line list of what is kept, is on our Delete your account page, which also covers what to do if you can no longer open the app. In summary:
In the app, open Settings and choose to delete your account. It runs for real: your profile, your intents, your introductions, your conversations and your stored photos are removed, your login is deleted, and the keys on your device are destroyed so any encrypted text that still exists anywhere can never be read. There is no waiting period, no retention offer and no maze.
One thing survives deletion, and we will not hide it: a ban. If your account has been banned, the ban is tied to the one-way value derived from your sign-in credential, not to the account, so deleting the account does not lift it. This is on purpose. Someone removed for harming another member must not be able to return by deleting themselves. If you have not been banned, that value is released when you delete, and you are free to rejoin later.
Your rights
- Access. You can ask what we hold about your account.
- Correction. You can edit your profile at any time in the app.
- Erasure. You can delete everything yourself in Settings, or ask us to.
- Withdraw consent. You can stop using an optional feature, or delete your account, at any time.
- Grievances. You can raise a concern with our Grievance Officer on the Grievance Redressal page.
India (DPDP Act 2023)
We process your personal data on the basis of your consent, for the purposes set out above and for nothing else, and we collect only what those purposes need. You may withdraw consent at any time, including by deleting your account. You have the right to access, correct and erase your data, the right to nominate someone to exercise your rights if you cannot, and the right to grievance redressal. Your data is processed in ap-south-1 (Mumbai, India).
Two things this Act makes us state honestly rather than favourably. First, no product table holds a name, an email address or a date of birth, which is a real minimisation, but it does not discharge our duties: our authentication system holds your sign-in address, we store a one-way value derived from it, our error monitoring provider receives diagnostic data, and you can type anything you like into a free-text note. Our obligations attach to all of that. Second, nothing in OZVAK verifies your age. The app requires you to confirm you are 18 or over, and a sign-in code proves control of an address and nothing more. We act on reports and remove anyone we learn is under 18. Stronger age assurance is planned and is not shipped.
If a personal data breach occurs we will notify the Data Protection Board of India and every affected user, as the Act requires. Our data protection contact is [GRIEVANCE OFFICER NAME], reachable at privacy@[LEGAL DOMAIN].
Europe (GDPR)
If you are in the EU or EEA you have the rights of access, rectification, erasure, restriction, portability and objection, and the right to complain to your local supervisory authority. Our lawful bases are the performance of our contract with you, for running the service, and your consent, for optional features. Where data is processed outside the EEA, it is transferred under the safeguards our providers offer for that purpose. Contact us to exercise any of these rights.
Google Play Data Safety
This policy is written to match our Google Play Data Safety declaration. In short: we collect an email address for sign-in, an account id, the profile and intent you write, your launch city, photos you add, encrypted message contents with readable metadata, reports and blocks, a notification token, and crash and diagnostic data. Crash and diagnostic data goes to our error monitoring provider. We collect no location and no contacts. We do not sell your data and do not use it for advertising. You can delete everything from Settings in the app, or by writing to the address below.
Changes
If we change what we collect or what we do with it, we update this page and change the date at the top. Where a change is significant we will say so in the app.
Contact
Privacy questions and data requests: privacy@[LEGAL DOMAIN]. For formal grievances, see our Grievance Redressal page.