Effective 28 August 2026 · Version 2.4.0

Privacy Policy

This policy explains how Silarah processes personal data to provide and protect the app, website and related support, safety and verification services.

1. Data fiduciary and contact

Silarah is operated in India and is the data fiduciary responsible for deciding why and how personal data is processed. Privacy questions and rights requests: privacy@silarah.com. The Silarah Grievance Desk receives formal grievances at grievance@silarah.com.

2. Data you provide

Shortlist details are visible only to the account that writes them. Do not put passwords, OTPs, payment details, government identifiers or another person’s confidential contact information in notes.

3. Data generated through use

We process consent and authentication records, device and app version, language, settings, push tokens, feature activity, matches, message delivery and typing state, moderation and fraud signals, subscription and transaction events, crash diagnostics, security information, timestamps and audit logs. Precise location is requested only for radius discovery and can be denied.

4. Sensitive and verification data

Religious beliefs, temporary verification captures and some matrimonial information may be sensitive. Religious data is used for compatibility with explicit consent where required. The optional photo check creates three temporary guided captures for human comparison with the current profile photo. We do not create facial embeddings or templates, perform government-ID matching or estimate age from a face. Sensitive data is not used for third-party advertising.

5. Purposes and legal bases

We use data to secure accounts; provide discovery, explainable compatibility, interests, chat, private shortlists and reminders, Incognito, photo privacy, guardian and subscription features; personalize results; moderate and verify; deliver service and safety messages; prevent fraud; support members; diagnose failures; keep records; and comply with law. Compatibility uses stated profile and preference fields and returns criterion-level explanations rather than another member’s raw preference values. Depending on location, the bases are contract, consent (including explicit consent), legitimate safety and operational interests, and legal obligations.

6. Member and guardian visibility

Chosen profile fields are visible to eligible registered members under discovery and privacy settings. Incognito removes a profile from general discovery and name/city search while it is effective, but existing interests, matches, permitted photo-access relationships and connected guardian relationships remain accessible as needed. It cannot make prior interactions anonymous. Photos follow public, mutual-interest or request-to-view controls. Private shortlist categories, notes and reminders are visible only to their author and are not shown to the saved member or their guardian. Conversation messages are visible to participants and may be visible to a properly linked guardian where chat mirroring is enabled. Reports expose necessary information only to authorized safety staff and those required for a fair process.

7. Processors and disclosures

We use Supabase for verified-email authentication, database, private storage, realtime and server functions; Google Firebase for push delivery and crash reporting; RevenueCat and app stores for subscriptions; Brevo for transactional email; Cloudflare for web delivery, DNS and security; Google ML Kit for on-device capture guidance and photo-safety signals; Photon/Wikidata for location and language lookup; and MyMemory for message text only when a member requests translation. They process data needed for their role under their own obligations. We may also disclose data at your direction, during a corporate transaction, for safety, or when lawfully required. We do not sell personal data or run third-party behavioural advertising.

8. International processing

Providers may process data outside your country. Where required, we use contractual safeguards and assess provider security and transfer mechanisms. Contact us for information relevant to your region.

9. Retention

Active-account profile, preference, photo, match and message data remains while needed to provide Silarah. Private shortlist metadata is removed with its bookmark or account; a one-shot reminder is marked sent rather than repeatedly queued. Incognito preference metadata remains with the active account so the setting is enforced across devices. Deletion requests enter a 30-day recovery period. Temporary photo-verification captures are deleted from active verification storage after review and no later than 48 hours after submission; the decision and deletion audit may remain without the captures. Information and removed content that applicable intermediary rules require us to preserve may be retained for 180 days, or longer under a lawful order. Reports, blocks, transaction, consent, security and backup records otherwise remain only for applicable payment, tax, abuse-prevention, limitation and legal periods, then are deleted or de-identified. Backups expire through normal rotation.

10. Security

Controls include encrypted transport, private temporary-capture storage, row-level permissions, short-lived signed media access, restricted staff roles, audit logs, rate limits, backups and managed secrets. No system is risk-free. Protect OTP codes and report suspected compromise promptly. We investigate suspected personal-data breaches, take proportionate containment and remediation steps, and notify affected people and the competent authority within the time and manner required by applicable law.

11. Your rights and choices

Depending on law, you may access, correct, export or delete data; withdraw consent; object or restrict processing; request portability; nominate another person where applicable; and complain to a regulator. In-app controls support profile editing, photo visibility, pausing, notification settings, blocking, immediate download of a machine-readable ZIP archive and deletion. We may proportionately verify identity before acting. See the Privacy Rights & Grievance Policy or email privacy@silarah.com.

12. Adults only

Silarah is for adults aged 18 and over. If you believe a minor supplied data, contact safety@silarah.com.

13. Changes

Material changes will be notified in-app or by email and renewed consent requested where required. This page’s version and effective date identify the applicable notice.