Overview
Ekmilan ("we", "us", or "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our match finder application and related services. By using Ekmilan, you agree to the practices described in this policy.
Ekmilan is intended for users aged 18 and above. We do not knowingly collect data from anyone under 18.
Information We Collect
Account & Profile Information
- Name, date of birth, and gender
- Profile photos you provide
- About Me / Bio text you write — subject to automated text content moderation before being stored
- Mobile phone number — collected for account verification and security purposes
- Security audit data — IP address and browser/device User-Agent string, recorded during authentication events (login, registration, account deletion) for security and fraud detection. Limited audit records may be retained for a short period for safety and legal purposes.
Location Data
- Precise GPS coordinates (when location permission is granted)
- City-level location (selected manually if GPS is denied)
- Location is used solely for profile discovery within your configured radius
Usage & Interaction Data
- Swipe interactions (likes, dislikes, blocks)
- Chat messages and message delivery status — stored encrypted at rest
- App activity timestamps and session data
- Device token for push notifications (Firebase FCM)
- Phone numbers you voluntarily enter for contact privacy blocking — when you use the "Block a Contact" feature, the phone number you enter is immediately and irreversibly converted to a one-way cryptographic hash (HMAC-SHA256). The plain phone number is never stored in our databases. Only the hash and a partially-masked display string (e.g. +91****10) are retained.
Phone Number — Collection & Usage
We collect your mobile phone number for the following purposes only:
- Identity verification — A one-time passcode (OTP) is sent via SMS to confirm your identity during registration or when updating your phone number
- Account security — Your phone number serves as an additional layer of account protection
- Account recovery — Used to help you regain access to your account if needed
- Contact privacy blocking — When you voluntarily enter another person's phone number to apply a contact-level privacy block, that number is immediately converted to a one-way HMAC-SHA256 hash. Only the hash is stored — the plaintext number is never retained by our systems. See the "Contact Privacy Blocking" section below for full details.
Phone number OTP verification is powered by MSG91, a TRAI-compliant SMS service. A one-time passcode is generated on our servers and delivered via SMS. OTPs expire after 10 minutes and are single-use only.
We do not share your phone number with other users, use it for marketing calls or SMS, or sell it to any third party.
Contact Privacy Blocking
Ekmilan provides a voluntary "Block a Contact" feature that lets you silently prevent a specific phone number from being matched with or discovering you on the platform — without revealing to either party whether the other has an account.
What data is collected: When you use this feature, you enter a 10-digit mobile phone number belonging to someone you want to block (e.g. a family member, colleague, or ex-partner). This is a phone number belonging to a person who is not you.
How it is stored: The phone number you enter is immediately converted to a one-way cryptographic hash (HMAC-SHA256) on our servers. The original plain phone number is never written to our database. We also store a partially-masked display string (e.g. +91****10) solely so you can identify entries in your own "Blocked Contacts" list. This masked string reveals only a few trailing digits and carries no meaningful personal information on its own.
How it is used: The stored hash is silently checked during platform activity. If any account registered with a matching phone number is active on EkMilan, neither that account nor yours will appear in each other's discovery feed. This happens automatically and silently — it is a mutual privacy filter.
No notification, no confirmation: The person whose number you enter is never notified that you have blocked their number. We do not confirm whether a phone number belongs to a registered EkMilan account, either to you or to anyone else. This feature is designed so that neither party can determine through it whether the other is registered on the platform.
Sharing: The contact hash and masked string are not shared with any third party, not shared with other users, and not used for advertising, profiling, or any purpose beyond the silent discovery exclusion described above.
Retention and user control: The hash and masked display string are retained for as long as the block is active. You can view and remove any contact block at any time from Settings → Blocked Contacts within the app. Removing a block immediately deletes the associated hash and masked record. After account deletion, these records may be retained as part of safety infrastructure (see "Data retained after deletion" below), but they contain only a cryptographic hash — no recoverable personal information.
Your responsibility: By using this feature, you confirm that you are entering a phone number for legitimate personal safety or privacy purposes, and not to harass, stalk, or harm another person.
How We Use Your Information
- To create, maintain, and display your profile to potential matches
- To power location-based profile discovery and matching
- To deliver real-time chat messages and push notifications
- To detect and remove inappropriate or unsafe content using AI moderation — this applies to both profile photos (AWS Rekognition DetectLabels) and text content such as your About Me / Bio and name (OpenAI GPT-4o-mini)
- To prevent fraud, abuse, and policy violations
- To improve app performance and user experience
Camera & Profile Photo Moderation
Ekmilan requests access to your device camera solely for taking profile photos and live selfie verification. Camera access is used only when you actively initiate a photo capture — we do not access your camera in the background.
Profile photos are analyzed using AWS Rekognition DetectLabels to ensure:
- No adult, violent, drug-related, weapon-related, or otherwise unsafe content
- No spoofed/non-authentic uploads (for example screenshots, memes, or cartoon images)
Photos are stored securely on AWS S3. We do not share your photos with third parties beyond what is necessary for moderation and display.
Biometric Data — Live Selfie Fraud Detection
As part of live selfie verification, we process your selfie capture to generate a mathematical face representation (a face embedding — a set of numerical values derived from your facial geometry). This is classified as biometric data under India's Digital Personal Data Protection (DPDP) Act 2023 and similar regulations.
What face data we collect and process: (1) a liveness selfie capture used to verify a real, live person, and (2) a face embedding generated from that capture for duplicate-account and fraud prevention.
How we use face data: Face data is used only for identity/liveness verification, duplicate-account checks, fraud prevention, and verified badge determination. It is not used for advertising, marketing, or personalized ad profiling.
Sharing and storage: Face data is processed only by trusted infrastructure providers on our behalf — AWS Rekognition (liveness and face indexing) and AWS S3 (secure storage of your private verification reference image). We do not sell face data.
Retention: Your face embedding and private verification reference image are retained only while your account exists (including during a temporary account suspension for safety review). If an account remains suspended and is not restored, we retain this data for up to 3 years from the suspension action for fraud prevention, abuse investigation, and legal compliance, after which it is deleted or irreversibly anonymized unless a legal hold requires longer retention. When you delete your account, this data is permanently removed immediately as part of the deletion process.
Your rights: You may request erasure of your biometric face data at any time by deleting your account from within the app, or by contacting us at support@ekmilan.com.
Verified profile badge: If you pass the live selfie liveness check, your profile may show a verified badge in the app. The badge indicates successful liveness verification at the time of check; it is not a background check, criminal check, or guarantee of user behavior.
Service Providers & Processing
We do not sell your personal data. We use trusted service providers that process data on our behalf:
- Amazon Web Services (AWS Rekognition DetectLabels) — Profile photo content moderation and safety screening
- OpenAI — GPT-4o-mini for automated text content moderation. When you submit your About Me / Bio, the text is sent to OpenAI's API solely to check for inappropriate or harmful content.
- Amazon Web Services (AWS S3) — Secure photo storage
- Amazon Web Services (AWS Rekognition) — Live selfie liveness verification and fraud prevention. Your live selfie capture is processed to generate a face embedding (a mathematical representation of your facial geometry) which is indexed in an encrypted AWS Rekognition face collection for duplicate-account detection.
- Firebase (Google) — Push notification delivery (FCM) for real-time alerts (matches, messages, account updates)
- MSG91 — TRAI-compliant SMS delivery for phone number OTP verification.
- Meta (Facebook) — App install and event attribution for advertising measurement. We use the Meta SDK to report anonymised app events (such as app installs and account registrations) to measure the effectiveness of our ad campaigns. On iOS 14 and later, this requires your permission via Apple's App Tracking Transparency (ATT) prompt. If you decline, only aggregated, privacy-preserving attribution via Apple's SKAdNetwork framework is used — no identifier is shared with Meta. You can change your choice at any time in your iOS device settings under Privacy & Security → Tracking.
All providers are bound by data processing agreements and applicable privacy laws.
Data Retention & Deletion
You may delete your account at any time from within the app. Upon deletion, we permanently remove:
- Your profile, photos, and verified details
- All your interactions and matches
- Your location data and cached profile information
- Your authentication tokens and account credentials (including your stored phone number)
- Your biometric face embedding — permanently deleted from the AWS Rekognition face collection as part of the deletion process
- Your private liveness verification reference image — permanently deleted from secure storage as part of the deletion process
Deletion is irreversible and is processed immediately upon request. For step-by-step instructions, see our Account Deletion Guide.
Suspended accounts: If an account is suspended for safety or abuse review, related account and safety data may be retained for up to 3 years from the suspension event to handle appeals, prevent repeat abuse/fraud, and meet legal obligations. After that period, data is deleted or irreversibly anonymized unless retention is legally required.
Data retained after deletion: A small number of records are kept after deletion for legitimate safety and legal reasons:
- Safety block records — If another user has blocked you, we retain a one-way cryptographic identifier (an HMAC hash — not your phone number) within that block record. This cannot be reversed to obtain your phone number, and ensures that if you re-register, safety blocks placed by other users continue to apply.
- Contact privacy block hashes — If you used the "Block a Contact" feature, a one-way cryptographic hash (HMAC-SHA256) of the phone number you entered and a partially-masked display string may be retained after account deletion. These records contain no plaintext phone number and no recoverable personal information. They cannot be used to identify or contact any individual.
- Terms acceptance log — We retain a record that your account accepted our Terms of Service, for legal compliance. This record contains only an internal account reference and the date of acceptance — no personal contact information.
- Moderation reports — If a safety report was filed against your account prior to deletion, that report is retained for moderation audit purposes. It contains no contact information.
- Security audit logs — Authentication events (login, registration, account deletion) may be retained for a limited period for safety and legal reasons. Logs contain only a masked identifier, IP address, and timestamp.
- Conversation history for other users — Messages in chats involving other users may remain visible in their inbox as part of their own account history. Your deleted account no longer appears as an active profile.
Your Rights
In accordance with India's Digital Personal Data Protection (DPDP) Act 2023, you have the following rights:
- Access — Request a summary of the personal data we hold about you
- Correction — Update inaccurate information via your profile settings
- Deletion — Delete your account and associated profile data at any time. This removes your profile, photos, interactions, location data, and authentication credentials permanently and irreversibly
- Data Portability — Request a copy of the personal data you have provided to us
- Withdrawal of Consent — Revoke location access or notification permissions via device settings at any time
- Grievance Redressal — Raise a complaint regarding the processing of your personal data
To exercise any of these rights, contact us at support@ekmilan.com. We will respond within 72 hours.
Security & Encryption
We implement multiple layers of security to protect your personal data:
- Encryption at rest — credentials: Your phone number is stored in our authentication database encrypted using AES-256-GCM. Lookups use a keyed HMAC-SHA256 index so the plaintext value is never written to disk
- Encryption at rest — profile data: Sensitive profile fields (name and other PII) are encrypted using a unique per-user key. Each user's key is itself wrapped by a master key using AES-256-GCM envelope encryption, ensuring GDPR-style erasure — deleting your account cryptographically destroys all your PII
- Encryption at rest — chat messages: All chat messages are encrypted with a per-conversation AES-256-GCM key derived from a master secret, so messages are unreadable outside of the application context
- Encryption in transit: All communication between the app and our servers uses HTTPS/TLS. Internal service-to-service communication within our infrastructure is also encrypted
- Authentication: Sessions use short-lived signed JWT tokens. Token subjects contain only an internal user ID — your phone number is never embedded in a token
No method of transmission over the Internet is 100% secure. We encourage you to keep your login credentials confidential and to report any suspected unauthorised access immediately.
Children's Privacy & Child Safety Standards
Ekmilan is strictly an 18+ platform. We do not knowingly collect or process personal data from anyone under 18 years of age. Age is validated at registration — our system checks your date of birth and will not permit account creation if you are under 18, both in the app and on our servers.
If we become aware, or if it is reported to us, that an account belongs to a person under 18, we will immediately terminate that account and delete all associated data. To report a suspected minor, contact us at support@ekmilan.com.
Ekmilan has a zero-tolerance policy for Child Sexual Abuse and Exploitation (CSAE) in any form. For our full child safety standards — including prohibited content, our in-app reporting mechanism, CSAM handling procedures, and our child safety point of contact — please see our Child Safety Standards page.
Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of significant changes via the app. Continued use of Ekmilan after changes constitutes acceptance of the updated policy.
Contact Us
If you have any questions or concerns about this Privacy Policy, please reach out to us:
support@ekmilan.com