Privacy Policy
Last updated: July 6, 2026
1. Who we are
ai-match.org is a community-centric, AI-assisted matchmaking platform operated as a privacy-first service. We are designed for values-driven seekers, with Sikh-first branding and open community tags.
2. What we collect
- Account data: email, phone number (E.164), password hash
- Profile data: display name, birth date, location, bio, values statement, community tags, photos
- Verification data: email and phone OTP verification timestamps
- Usage data: login timestamps, profile completeness, match interactions (when features are enabled)
3. How we use your data
- To create and maintain your account and profile
- To verify your identity via email and phone OTP before your profile becomes visible
- To suggest compatible matches using on-premise AI (Ollama embeddings) — no third-party LLM APIs
- To operate trust & safety features (reports, blocks) when enabled
4. Search engine indexing
We enforce noindex on all member areas (/app/*, /profile/*, API routes).
Your matrimonial profile will not appear in Google or other search results.
Only public marketing and community landing pages are intended for indexing.
5. Photo storage
Profile photos are stored on self-hosted MinIO infrastructure (homelab). Photos are not shared with third-party CDNs at launch. You may upload up to 8 photos; you can delete them at any time.
6. Data sharing
We do not sell your personal data. We do not use Google AdSense. Limited sponsored placements may appear on public pages only (max 1 per page); member areas remain ad-free for the first 12 months.
Your profile is visible only to mutual matches (or yourself) — not to the general public.
7. Your rights (including India DPDP)
- Access: Request a copy of your data via account settings or support
- Correction: Update your profile at any time
- Deletion: Request full account and data deletion — we will remove profile, photos, and verification records
- Withdraw consent: Deactivate visibility or delete your account
8. Security
Passwords are hashed with bcrypt. Sessions use short-lived JWT access tokens. Logout invalidates tokens via server-side denylist. Auth endpoints are rate-limited.
9. Retention
Active account data is retained while your account exists. Deleted accounts are purged within 30 days, except where law requires retention of minimal audit logs.
10. Contact
Privacy requests: [email protected]