Last updated: July 26, 2026
1. U.S. Launch Scope
Rishtio currently operates nationwide in the United States. Privacy rights differ by state and may depend on whether a law applies to Rishtio, the information, and the request. This page describes the request paths the product currently supports; it does not expand or limit rights provided by applicable law.
2. United States Privacy Rights
Depending on applicable state law, you may have the right to:
• Confirm whether we process your personal information and access it.
• Correct inaccurate personal information.
• Delete personal information, subject to legal exceptions.
• Receive a portable copy of information you provided.
• Opt out of sale, sharing for cross-context behavioral advertising, targeted advertising, or qualifying profiling.
• Limit certain uses of sensitive personal information.
• Appeal a denied privacy request.
Rishtio does not sell personal information or share it for cross-context behavioral advertising. We do not discriminate against users for exercising an applicable privacy right and respond within the timeframe required by the law that applies to the request.
3. California Privacy Rights
Eligible California residents may request access to categories and specific pieces of personal information, correction, deletion, and information about sources, purposes, and service-provider disclosures. They may also opt out of sale or sharing and limit qualifying uses of sensitive personal information. Rishtio does not sell personal information or share it for cross-context behavioral advertising. We verify requests and respond within the period required by California law.
4. Biometric Information
Photo liveness, face matching, and duplicate-face detection are disabled in the current U.S. production launch, and production does not provision an Azure Face resource. Before any future activation, Rishtio must publish the applicable state biometric notice and retention/destruction schedule and obtain any required consent or written release. Contact privacy@rishtio.com with questions about a future biometric feature or a prior test-environment verification record.
5. How to Submit a Request
Anyone in the United States may submit a request or appeal by emailing privacy@rishtio.com. If you sign in to your own Rishtio account, you can also create a support ticket from Settings → Privacy & Support; helper accounts do not have that screen. Statutory rights depend on applicable law, but you do not need to identify a statute to use this nationwide intake path.
Tell us the right you want to exercise and provide enough account information for us to locate the request. Do not email identity documents, passwords, social-provider tokens, or other unnecessary sensitive material. We use proportionate account or identity checks to protect against unauthorized access, correction, or disclosure.
6. Account Deletion
You can delete your account from Settings → Account actions → Delete Account. After a valid ordinary deletion request is confirmed, access and bearer sessions are revoked immediately and the profile is removed from use. Durable asynchronous cleanup then deletes account-owned profile data, preferences, photos and files, verification uploads, Share Kit and support files, chat attachments and resources, match records, device registrations, provider credentials, Azure Communication Services resources, provider-side Face resources if any exist, and AI-derived embeddings, summaries, suggestions, scores, match reasons, and outreach output. Cleanup waits for still-valid upload credentials to expire and retries required external deletion instead of reporting success early. We do not promise a fixed cleanup time that is not enforced by the workflow.
Production database backups expire under the configured backup policy, currently up to 35 days. Deleted active data is not restored except for disaster recovery and is removed again through normal cleanup.
7. Limited Retention
Limited records may remain after deletion:
• Reviewed platform-ban provider/document aliases are purpose-separated HMAC values, contain no raw provider subject or document number, and may remain for up to 1,825 days. Renewal requires staff review and resets the reviewed term.
• Directional pair-block HMAC aliases belong to the blocker and remain until that person unblocks or deletes their account. They do not prevent registration.
• Reports are stripped of free text and direct profile links and grouped only by a random token. Unresolved reports remain until resolution and any appeal are final. Ordinary resolved report evidence is then retained for 365 days. Evidence supporting an active platform ban follows that ban's reviewed retention cap; after the ban is lifted or expires, the configured 30-day grace applies without extending beyond the reviewed cap. A staff-reviewed ban renewal extends that cap.
• An active CyberTip, 18 U.S.C. Section 2703(f), or litigation hold overrides the report deadline until the hold is explicitly released. The already-computed deadline applies at the next cleanup after release.
• Closed support-ticket projections follow the implemented 14-day-after-view or 60-day-after-closure schedule.
• Azure Monitor operational records follow the enforced 30-day retention; Expo diagnostics follow the configured provider retention.
Ordinary deletion permits recreation of a new account, subject to an effective platform ban or restored pair block.
8. Privacy Requests and Appeals
Submit privacy questions, requests, or appeals to privacy@rishtio.com, or, if you sign in to your own Rishtio account, by creating a support ticket from Settings → Privacy & Support. If we deny a request, we explain the reason and provide the available appeal path. You may also contact your state attorney general or other authorized regulator where applicable.