DRAFT — pending privacy-counsel review; not yet legally effective (RishtaAI is in pre-launch testing on synthetic data).
RishtaAI Privacy Policy
Version: 2026-07-draft · Last updated: 2 July 2026
This policy explains what personal information RishtaAI collects, why we collect it, who we share it with, and the choices and rights you have. We have written it in plain language. If anything is unclear, please contact us at info@naamlab.com.
1. Who we are
RishtaAI is a marriage-intelligence app operated by NAAM Lab. It is currently an Android app, launching first in Pakistan for resident and overseas Pakistani citizens.
- Operator / data controller: NAAM Lab (parent brand of RishtaAI)
- Website: https://www.naamlab.com
- Contact: info@naamlab.com
2. What we collect
We collect only what we need to run the service. Here is the full inventory.
| Data | Why we collect it | Where it is stored | Note |
|---|---|---|---|
| Phone number | To sign you in with a one-time passcode (Firebase phone OTP) | Cloud SQL | Stored as-is (raw). |
| Google email | To let you sign in with Google | Cloud SQL | Only taken from a Google sign-in token that is already marked as verified (email_verified). |
| National ID (CNIC / Smart CNIC / NICOP / passport) | To verify your identity for trust badges (KYC), through our verification vendor | See note | Your ID is submitted to our verification vendor. We store only a one-way salted hash (so one person can only hold one account) and the structured result — your name, date of birth, pass/fail and liveness outcome. We never store the raw ID number or the ID image. |
| Profile details (your B1–B5 profile) | To build your profile and find compatible matches | Firestore (the full profile) + a matchable projection in Cloud SQL | Includes gender, date of birth, city/country, religion & sect, marital status, children, relocation, languages, education, any free text you add, and your display name. Anti-discrimination stance: caste/biradari, health, disability and appearance are never used as hard match filters — they are preference-only. |
| Profile photo | So matches can see you, if you choose | Private, encrypted storage | Location/EXIF metadata is stripped. Your photo is shown to others only with your opt-in, and every access to it is logged. |
| Messages | To deliver your 1:1 chats and keep the community safe | Firestore | Your chats with your matches are stored so we can deliver them and review them for safety. |
| Device / notification token | To send you push notifications | Cloud SQL | Collected only if you enable notifications. |
| Pseudonymous analytics id | To understand and improve the product | Analytics vendor | A one-way hash of your account id — never your real identity. |
| Subscription / billing references | To give you the subscription you bought | Cloud SQL | Opaque Google Play references plus your tier, status and renewal date. No card or payment-card data — Google is the merchant of record. |
| Voice onboarding data | To let you build your profile by speaking, if you choose | See note | If you use the voice assistant, your speech is transcribed to fill in your profile draft. No raw audio is stored at any step — only the transcript/draft (to build your profile) and non-content usage statistics. |
3. How we use it
- Matching — to show you candidates who meet your filters. Matching is hard-filter only; we never rank matches by who pays. Paying for a plan never buys you "better matches".
- Identity verification & trust badges — to confirm identities and award trust badges.
- Messaging and safety — to deliver your messages and to moderate for abuse, fraud and harmful content.
- Notifications — to alert you to matches, interests and messages, if you enable them.
- Analytics and product improvement — using a pseudonymous id, never your real identity.
- Billing and entitlements — to unlock the plan you bought.
- Voice-assisted profile building — to help you fill your profile by speaking.
4. Consent
The processing purposes gated by the consent categories below each require your recorded, timestamped consent. (Operating the account you create and providing any paid subscription you buy rest on a different legal basis — see Section 5.)
- Consent defaults to OFF — nothing is assumed or implied.
- You can withdraw any consent in Settings, and we stop that consent-based processing within 24 hours.
- No sensitive-category data is required to create a basic account.
The consent categories are: identity verification, storing your verification result, profile visibility, matching use, message moderation, analytics/telemetry, notifications, and voice intake.
5. Legal basis
- Consent — for the processing purposes gated by the consent categories in Section 4 (identity verification, verification-result storage, profile visibility, matching, message moderation, analytics/telemetry, notifications, voice intake). You can withdraw it at any time.
- Contract — for operating the account you create and for providing any paid subscription you buy. We process the details needed to deliver those, which does not depend on consent.
6. Who we share with (sub-processors)
We do not sell your data. We use the following trusted providers to run the service.
| Provider | What they handle | Where |
|---|---|---|
| Google Cloud & Firebase | Authentication, database, storage, hosting, push notifications, crash reporting, and the Cloud Vision photo-safety check | Primary region Singapore (asia-southeast1); the photo-safety check runs on Google's EU endpoint |
| Google Play | Billing (merchant of record) | |
| Didit | Identity verification | EU |
| Mixpanel | Analytics | EU |
| Deepgram | Speech-to-text (voice onboarding) | EU |
| ElevenLabs | Text-to-speech (voice onboarding) | Vendor infrastructure |
| LiveKit | Real-time audio transport (voice onboarding) | Vendor infrastructure |
| Anthropic / Google Vertex | The conversational AI (voice onboarding) | Vendor infrastructure |
For voice onboarding, the voice vendors are configured for no-retention (they do not keep your audio or transcript after the session), and the conversational AI never learns your identity.
7. International transfer
Your data is processed in Singapore (the nearest region to Pakistan) and, for some vendors, in the EU. These transfers are covered by data-processing agreements with each provider.
8. Retention
- Your profile, photos and messages are kept while your account is active.
- Any ID images held by the verification vendor, and your personal data, are deleted within about 30 days after you close your account.
- Some records — such as audit, safety and consent logs — are kept longer where the law or user safety requires it.
- Withdrawing a consent takes effect within 24 hours.
9. Security
- Encryption in transit and at rest.
- Access-logging on sensitive reads (for example, profile photos).
- Pseudonymised identifiers for analytics.
- An append-only audit trail.
- Admin access controls limiting who can see what.
10. Your rights
- Withdraw consent — at any time in Settings (takes effect within 24 hours).
- View your consent history — in Settings.
- Pause or hide your profile — in Settings.
- Request deletion — currently handled by our team via a request (see the Data Deletion page).
- Export your data — contact us at info@naamlab.com.
11. Children
RishtaAI is for adults aged 18 and over only. It is not intended for anyone under 18.
12. How to delete your data
You can ask us to delete your data. See the Data Deletion page for how, or email info@naamlab.com.
13. Changes
We may update this policy. When we make a material change, we will update the version line above and, where appropriate, notify you in the app.
14. Contact
Questions about your privacy or this policy? Email info@naamlab.com or visit https://www.naamlab.com.