Privacy Policy

Legal Centre Terms of Service Privacy Policy Community Guidelines Identity Verification Law Enforcement & Transparency Refunds & Cancellations Safety Guide Cookie Policy Grievance Redressal Contact Us About us

This policy explains what Rangmel collects, why, who sees it and what you can do about it. It is written to India's Digital Personal Data Protection Act, 2023.

The short version. Your gender identity, pronouns and orientation are the most sensitive things you give us, and we treat them that way: they are shown only to the people you chose to be shown to, they are never sent to advertising networks in any form, and you can hide or delete them at any time without losing your account.

1. What we collect

What you give us

What we record as you use it

2. Special category data, and the promise attached to it

Under the DPDP Act and comparable laws elsewhere, your gender identity, gender history and sexual orientation are sensitive personal data. We collect them because the app cannot function without them — a dating app that does not know who you are or who you want to meet is not a dating app — and we collect them only with your explicit, itemised consent, recorded with the exact wording you agreed to, the timestamp and the IP address.

Specifically, we commit that:

3. Photographs

You choose who sees your photographs: everyone signed in, only people you match with, or one person at a time. When they are hidden, we do not merely blur them in the browser. We generate a separate, permanently blurred file under its own random filename, and that is the only file a viewer who is not entitled to the original ever receives. The original is never sent to their device, so it cannot be recovered from the network tab or by guessing a URL.

No membership tier can see past another member's photo privacy setting.

4. Identity documents

Verification is optional. If you submit a document:

5. Who sees what

6. Advertising and analytics

We measure how people find the app, using Meta's Conversions API and Google Analytics. What we send is limited to an email address, a phone number, an account identifier and a city, all hashed where the platform supports it, plus the name of the action taken (for example "signed up").

What is never sent: your gender identity, your pronouns, your orientation, your date of birth, your photographs, your messages, who you matched with, or anything derived from them. Event names are generic on purpose: an advertising network is told that an account was created, never what kind of person created it.

You can opt out of analytics in your browser, and blocking them does not restrict any part of the app.

7. How long we keep things

8. Your rights

9. Security

Traffic is encrypted in transit. Documents are encrypted at rest. Passwords are hashed, never stored or recoverable. Sessions are regenerated on sign-in and on password change. Admin access is role-restricted and every administrative action is logged with the actor, the entity and the time.

We cannot promise a breach will never happen. If one does and it affects you, we will tell you and the Data Protection Board, as the DPDP Act requires.

10. Requests from the authorities

How we handle law enforcement requests, and what we will not do, is set out separately on the Law Enforcement & Transparency page.

11. Changes

If we change how we use your data, we ask for your consent again rather than assuming it. Material changes are shown in the app before they take effect.