Privacy Policy
Effective Date: August 8, 2026 · Last Updated: September 21, 2026 ·
Applies to the Mutemate mobile application and web platform.
MUTEMATE ("Operator", "we", "us", or "our"), having its office at
Unit No KCO45, B 128 First Floor, Sector 2, Noida, Gautam Buddha
Nagar, Uttar Pradesh, 201301, operates the Mutemate
mobile application and web platform (collectively, the "Service" or
"App"). We are committed to protecting the privacy, confidentiality,
and security of our users ("Members" or "you").
This Privacy Policy explains how we collect, use, store, share, and
protect your personal data when you use Mutemate, as well as your
rights regarding your information under applicable privacy laws,
including the Information Technology Act, 2000 and the rules made
under it, and India's Digital Personal Data Protection Act, 2023
(DPDP Act) as it comes into force. MuteMate is intended for use in
India only.
By creating an account or accessing the App, you acknowledge that you
have read and understood this Privacy Policy and consent to the
collection, processing, and transfer of your personal data as
described herein.
1. Information We Collect
To provide matchmaking and social discovery services, we collect
several categories of information:
(a) Information You Provide Directly
-
Registration & Profile Details: You sign in
with your Google account, so we receive your email address and
Google account ID — we never see or store your Google password.
When you set up your profile, you provide your display
name/pseudonym, date of birth, gender, sexual orientation, dating
preferences, city, state, occupation, marital status, bio
description, and physical attributes.
-
Sensitive Personal Data: Certain information you
voluntarily share (such as sexual orientation, dating preferences,
the interests you pick for your profile, and profile photos) is considered sensitive under data protection
laws. By voluntarily adding this information to your profile, you
explicitly consent to our processing of this data for matchmaking
purposes.
-
Photos & Media: Profile pictures and photos
uploaded to your profile or shared in private chats.
-
Voice Recordings: If you choose to record a voice
"thirst", the app uses your microphone (only while you record) and
we store the recording. It can be played on your profile when you
make it public.
-
Communications & Support: Messages exchanged
with other users within the App, feedback submitted to us, and
customer support inquiries.
(b) Information Collected Automatically
-
Geolocation Data: With your explicit device
permission, we collect your precise GPS location to suggest nearby
matches and calculate distance. To show your city name, your
device's coordinates are sent to a reverse-geocoding service
(BigDataCloud), and the text you type into city search is sent to
LocationIQ (see Section 4).
-
Device & Usage Data: IP address, device model,
operating system, device identifiers (such as an app-instance ID; we do not use your advertising ID), app
crashes, and feature interaction logs.
-
Analytics: We use Google Firebase Analytics to see
which screens and features are used. It receives your MuteMate user
ID (a random ID, not your name or email), your gender, whether you
have a paid plan, and whether you are face-verified, together with
the screens you open and actions such as sending a like or a
message.
-
Crash Reports: We use Sentry to receive crash
reports containing technical details about an error and your
device. We configure Sentry not to collect personal identifiers.
-
Push Notifications: If you allow notifications, a
push token for your device is stored and used, through Google
Firebase Cloud Messaging, to deliver alerts.
-
Login Sessions: We use session tokens to keep you
signed in.
-
Website Visits: When you visit mutemate.in, we
record the choices you make in the sign-up picker, campaign tags in
the link you arrived by (such as a referral code) and
page-interaction events. We do not ask for your name or email on
the website, and your IP address is kept only as a one-way hash.
(c) Payment Information
We do not store or process payment card details on our servers. All
in-app purchases, credit packs, and subscriptions are processed
securely through Google Play Billing.
(d) Biometric Information
If you complete our optional face verification check, we process
biometric data in the form of live facial images. Because this is a
sensitive category, it is described separately and in full in
Section 2 (Biometric Information).
2. Biometric Information (Face Verification)
Mutemate offers a face verification check to confirm that an account
belongs to a real person and to reduce impersonation and fake
profiles. Because this involves biometric data, we describe it
separately and in full below. Biometric data is treated as sensitive
personal data under the DPDP Act, 2023 and equivalent laws.
(a) What Is Collected
During verification, your device camera captures a short sequence of
live images while you follow on-screen prompts (blink, turn left, turn
right). These images are used to confirm that a live person is present
and to compare against the profile photo already on your account.
(b) Consent
We request your explicit consent on screen before the camera is
opened, and the notice shown there describes this same processing. You
may decline. If you decline, the scan does not take place, though
certain features that depend on a verified account may remain
unavailable to you. You may withdraw consent at any time by contacting
our Grievance Officer.
(c) Who Processes It
Face verification is performed by
Amazon Rekognition, a service of Amazon Web Services,
acting as our data processor. Your images are transmitted to
Rekognition as inline image data for immediate analysis and are
not enrolled into any Rekognition face collection. No
reusable biometric template or faceprint of you is created or retained
by our verification provider. We do not sell, license, or disclose
biometric data to any other third party, and it is never used for
advertising, profiling, or shown to other users.
(d) Retention and Deletion
Scan images are retained only for as long as the verification decision
requires:
-
If verification succeeds: your scan images are not
retained.
-
If the result is unclear and is referred for human review:
the images are retained solely so a trained reviewer can reach a
decision, and are permanently destroyed at the moment that decision
is recorded.
-
Record of the decision: after the images are
destroyed we retain the outcome of the check (pass or fail, the
reason, and the date). This record contains no biometric data and
exists so that you can query or appeal a decision and so that we can
demonstrate the check was carried out fairly.
Any scan images still held are also destroyed when your account is
deleted, as described in Section 5.
(e) Your Rights
You may request confirmation of whether biometric data relating to you
is held, request its erasure, or withdraw your consent, by writing to
support@mutemate.in. We will
respond within the timelines stated in Section 10.
3. How We Use Your Information
We process your personal data for the following purposes, based on
your consent or as otherwise permitted by law:
-
Core Service Delivery: To create your profile,
enable search algorithms, process matches, and facilitate real-time
chat.
-
Safety & Security: To detect, prevent, and
address fraud, spam, harassment, fake profiles, and unauthorized
access.
-
App Improvement & Analytics: To diagnose
server errors, optimize user experience, and refine matchmaking
mechanics.
-
Customer Support & Notices: To send account
verification alerts, security updates, and administrative
notifications.
-
Legal Compliance: To enforce our Terms of Service
and comply with statutory legal obligations.
4. How We Store and Share Your Data
We do not sell, rent, or monetize your personal information to
third parties for direct marketing purposes. We share data only with
the service providers below, and only what each one needs to do its
job:
-
Hosting & Storage: Your photos, media files,
and chat records are stored on our own servers, which we host on
Amazon Web Services (AWS) infrastructure in India (Mumbai region).
Access is limited to authorised staff, and data is encrypted in
transit.
-
Authentication & Backend Endpoint: Data is
transmitted securely over HTTPS/SSL to our primary application
servers hosted at mutemate.in.
-
Google: Google Sign-In (your email address and
Google account ID), Firebase Cloud Messaging (your push token),
Firebase Analytics (the data described in Section 1) and Google
Play Billing (your purchases — we receive order details, never your
card details).
-
Sentry: receives crash reports (see Section 1).
-
City Search & City Name: LocationIQ receives
the text you type into city search. BigDataCloud receives your
device's coordinates (and, as with any web request, your IP
address) to turn them into a city name.
-
Email: emails you send to support@mutemate.in are
received by Zoho Mail (India). Any system email we send you is
delivered through Resend.
-
Legal & Regulatory Disclosures: We may
disclose your data if required to do so by law, court order, or
governmental demand, or when necessary to protect the safety of our
users or the public.
Transfers Outside India
Some of these providers — Google, Sentry, LocationIQ and Resend, and
possibly BigDataCloud — process data outside India, including in the
United States and Japan. We send them only what each needs for its
purpose. Face-verification images are processed in AWS's India
(Mumbai) region.
5. Data Retention and Account Deletion
(a) Retention
We retain your personal information only for as long as your account
remains active or as required to fulfill the operational purposes
outlined in this policy.
(b) Right to Erasure / Account Deletion (Google Play & Apple Compliant)
You have the right to delete your account and remove your personal
data at any time:
-
In-App Deletion: You can delete your account at any
time by navigating to
Settings > Account > Account Info > Delete
account.
-
Web Request: You can request deletion without
installing the app at
mutemate.in/legal/account-deletion.
-
Email Request: You may also request complete
account and data deletion by emailing
support@mutemate.in with
the subject line "Data Deletion Request".
Deletion happens in two stages, and we describe both because they
differ:
-
Immediately: your account stops being visible to
other users, and your personal content — profile details, photos,
voice recordings, matches, likes and chat messages — is erased from
the Service.
-
For 180 days afterwards: a limited set of
registration records is retained, as required by Rule 3(1)(g) of the
Information Technology (Intermediary Guidelines and Digital Media
Ethics Code) Rules, 2021. This is retained for legal and
fraud-prevention purposes only and is not used to contact you or to
reconstruct your profile.
-
After 180 days: those remaining registration
records are permanently deleted (except the scrambled safety
records described below).
Exception — accounts under investigation. Where an
account has been banned, or is the subject of an unresolved report by
another user, the related content is preserved as evidence for
moderation, safety and law-enforcement purposes rather than erased
immediately. Records of payments, safety reports and moderation
actions are likewise retained where we are legally required to keep
them.
Records kept to stop repeat abuse. To stop banned
people from coming back, we permanently keep scrambled (one-way
hashed) records: a hash of the email address of any banned account,
and, when an account is deleted, a hash of its email address (and
phone number, if one was on file) together with a note of whether it
had been banned. A hash cannot be turned back into your email
address and cannot be used to restore your profile or contact you.
(c) Other Retention Periods
-
Photos sent in chat are view-once: they disappear
for both people shortly after the recipient opens them. The sender
may keep a private copy in their own Saved Media until they delete
it or delete their account.
-
Messages deleted for everyone disappear from the
chat at once and are erased from our servers after up to 30 days.
They are kept longer only while a report involving them is open.
-
Reported photos: when a photo is reported, a copy
is kept in a private evidence store for up to 180 days and then
erased.
-
Server logs (which include IP addresses and the
requests made) are kept for 180 days, as required by the CERT-In
directions, and then deleted.
-
Website page-interaction records are deleted after
90 days.
6. Security Measures
We implement robust administrative, technical, and physical
safeguards to protect your personal data against unauthorized access,
alteration, disclosure, or destruction:
-
Encryption: All data in transit between the App
and our servers is encrypted using Secure Sockets Layer (SSL) / TLS
technology. Access to stored data is restricted to authorised
staff.
-
Anonymity: Search engines are blocked from
indexing user profiles or photos on Mutemate.
-
Breach Notification: In the event of a security
breach affecting your personal data, we will notify you and
relevant authorities in accordance with applicable statutory laws.
7. Age Restriction (Children's Privacy)
Mutemate is strictly intended for individuals who are at least 18
years of age. We do not knowingly collect or solicit personal
information from anyone under the age of 18. If we discover that a
user under 18 has created an account, we will immediately delete
their profile and associated data from our servers.
8. Regional Privacy Rights
(a) Indian Residents (DPDP Act, 2023 & IT Act)
As a Data Principal under India's Digital Personal Data Protection
Act, 2023 (as its provisions come into force) and under the IT Act
and its rules, you have the right to:
-
access a summary of the personal data we hold about you and how we
process it;
-
correct, complete and update your data — you can edit most of it in
Edit Profile, or write to us;
-
ask us to erase your personal data — delete your account in the app
or write to us (see Section 5);
-
withdraw your consent at any time by writing to
support@mutemate.in or by
deleting your account. Withdrawing consent may mean some features
stop working, and it does not affect processing already done;
-
have your grievances answered by our Grievance Officer (see
Section 10); and
-
nominate another person to exercise these rights for you if you die
or become unable to do so.
If you are not satisfied with our reply to a grievance, you may
complain to the Data Protection Board of India, as the law provides.
(b) Outside India
MuteMate is offered for use in India only. We do not offer the
Service to people in the European Economic Area, the United Kingdom,
or California, and this policy is written for Indian law. If you use
the Service from another country, you are responsible for following
your local law.
9. Changes to This Privacy Policy
We reserve the right to update or modify this Privacy Policy at any
time. If we make material changes, we will notify you by updating the
"Effective Date" at the top of this page, issuing an in-app notice, or
sending an email notification prior to the changes taking effect.
Continued use of Mutemate following such notification constitutes
acceptance of the updated policy.
10. Grievance Redressal & Contact Information
In accordance with the Information Technology Act, 2000, the IT
Intermediary Guidelines Rules, 2021, and the DPDP Act, 2023, if you
have any questions, privacy concerns, or grievances regarding the
processing of your data, you may contact our designated Grievance
Officer:
- Platform: Mutemate (operated by MUTEMATE)
- Grievance Officer: Grievance & Compliance Officer
-
Office Address: MUTEMATE, Unit No KCO45, B 128
First Floor, Sector 2, Noida, Gautam Buddha Nagar, Uttar Pradesh,
201301
-
Contact Email:
support@mutemate.in
-
Response Timeline: Acknowledgment within 24
hours; resolution within 15 days of receipt.