Last updated: July 26, 2026

1. Introduction

Rishtio ("we," "us," or "our") currently offers its matrimony platform and related services nationwide. The current production launch is intended for adults in the United States. This Privacy Policy explains how we collect, use, disclose, retain, and safeguard personal information, including essential AI-powered processing, automated safety checks on ordinary profile photos, and required identity-document verification. Account creation requires agreement to the current Terms and acknowledgement of this Privacy Notice, which together cover the required identity-document processing described below. Processing begins only when the profile subject chooses to upload a document. Face and liveness verification remain unavailable. Rights and obligations vary by state and apply where the relevant law covers Rishtio, the information, and the request. Where applicable law grants eligible residents additional rights, we honor them as described below.

2. Information We Collect

We collect the following categories of personal information: • Personal Identifiers: Name, date of birth, gender, email address, phone number, and social sign-in account identifiers. • Location Data: Hometown, city, state, and country; street address and geographic coordinates only when you provide them. • Physical Characteristics: Height and photographs. • Optional Profile Details: Religion, community/caste, gotra and related astrology fields, nationality, and precise location. These may be left blank or deleted. • Lifestyle Information: Drinking habits, smoking habits, hobbies, interests, personality traits, languages known, marital status, diet, and relocation preferences. • Financial, Work & Education Information: Annual income and currency, job title, company, work status, profession, educational qualifications, field of study, and institution name. • Profile Narratives: About Me, What Matters to Me, and Family Background. • Search Data: Natural-language search text, structured filters, saved preferences, and search history. • Communication Data: Messages exchanged through our chat feature powered by Azure Communication Services. • AI-Processed Data: Profile and preference embeddings, generated profile summaries, generated search suggestions, writing-review decisions, AI-extracted filters and search names, and semantic scores. • Identity Verification Data: When the profile subject chooses to upload a document under the account agreement, government identity document images or PDFs, extracted identity details, document metadata, verification status, and purpose-separated document-identity aliases used to detect duplicate reuse and enforce safety actions. • Device & Usage Data: Browser and app version information, crash, performance, operational and security diagnostics, screen views, feature-use events, and native app lifecycle events. Photo liveness, face matching, and duplicate-face detection remain disabled, so production does not collect verification face data.

3. How We Use Your Information

We use personal information to provide the AI-powered profile, search, matching, writing-review, recommendation, relationship-manager, connection, and chat features described in this notice; to authenticate accounts and prevent fraud or abuse; to automatically moderate each new ordinary profile photo before publication; to process the required identity-document check when the profile subject chooses to upload a document under the account agreement; to use optional profile fields when supplied; to understand feature use through first-party product analytics; to provide security and reliability; and to comply with applicable law. A helper-created managed profile remains a private, inert, photo-free draft until the authenticated subject reviews and accepts the current legal documents and managed-profile authority disclosure, explicitly scopes helper access, and chooses publication. The subject must add the first profile photo. After that, a helper with Full Access may manage ordinary profile photos, and every new photo receives the same safety check. Helpers cannot initiate or complete identity, Face, or liveness verification. Before acceptance we use the expected sign-in email only to verify the claim against the social provider's verified email and do not expose the draft through ordinary member features. Claim credentials are random, single-use, time-limited, stored only as salted hashes, and invalidated after use, expiry, revocation, or a replacement invitation.

4. Artificial Intelligence Processing

Microsoft Azure OpenAI in East US may process the profile, narrative, search, saved-preference, and profile-context categories listed above for embeddings and semantic ranking, multilingual profile summaries, profile search suggestions, exact-text narrative review, natural-language search extraction and naming, and Rishtio Select scoring. This processing is essential to the current Rishtio service and is covered by the account agreement; Rishtio does not offer a separate non-AI mode. Rishtio stores derived embeddings, summaries, suggestions, extracted saved-search fields and names, and semantic scores as described in the AI Usage Disclosure. You can control what optional information you supply, edit or delete profile fields, and delete your account. Assistants cannot accept the account agreement for managed subjects, and unclaimed profiles are not processed by these AI features.

5. Service Providers

We disclose limited data to service providers that process it on our behalf: • Microsoft Azure OpenAI: Processes the disclosed profile, search, preference, and narrative data in East US. Microsoft states customer prompts, completions, and embeddings are not available to OpenAI or other customers and are not used to train models without explicit permission or instruction. Content flagged for potential abuse may be reviewed under Microsoft terms. • Microsoft Azure AI Content Safety (East US): Receives each new whole ordinary profile photo before publication and returns Hate, Sexual, Violence, and Self-Harm severity values for our configured thresholds. Microsoft states content is not stored for filtering or used to train the filtering system without customer consent. Assistant photos, identity documents, Share Kit files, and support uploads are never sent to this service. This pipeline does not perform facial recognition, create biometric templates, test liveness, verify identity, or conduct background screening. • Microsoft Azure AI Document Intelligence (East US): When the profile subject submits a government identity document under the account agreement, processes it to extract the fields needed for the configured identity check. Rishtio uses those results to compare the document with profile details and detect duplicate document-number reuse. • Microsoft Azure Face API: Not provisioned or enabled for the current production launch. Photo liveness, face matching, and duplicate-face detection are unavailable. • Microsoft Azure Communication Services: Facilitates chat messaging. • Microsoft Azure Blob Storage: Stores profile images and other user files in our United States production environment. • Google Maps API: Provides location search and geocoding. • Microsoft Azure Monitor: Collects necessary operational and security telemetry and first-party product analytics. • Expo Application Services: Processes anonymous installation-level startup performance and EAS Update delivery and failed-launch health under Expo's service and subprocessor terms. We do not sell personal information or share it for cross-context behavioral advertising.

6. U.S. Processing Locations

Rishtio's primary production application data is stored and processed in Microsoft Azure's Central US region. Azure OpenAI, Azure AI Content Safety, and Azure AI Document Intelligence process their disclosed inputs in East US. Azure Face API is not provisioned for the production launch. Expo Application Services and other vendors may use subprocessors in locations identified in their published service terms.

7. Data Retention

We retain active-service data while needed to provide the account and for the purposes described here. A photo blocked by Content Safety is deleted, and abandoned prepared uploads are removed by cleanup. When ordinary account deletion is confirmed, access and bearer sessions are revoked immediately and the profile is removed from use while asynchronous cleanup deletes account-owned database records, files, provider credentials, chat resources, and AI-derived output. Cleanup retries required external deletion rather than reporting success early, and we do not promise a fixed cleanup time that is not enforced by the workflow. Limited exceptions apply: • For a reviewed platform ban, purpose-separated HMAC aliases of the provider subject and verified document identity may be retained for up to 1,825 days under our business policy. Renewal requires explicit staff review and resets the reviewed term. We do not retain raw provider subjects or document numbers in those aliases. • A directional pair-block HMAC alias is owned by the blocker and remains until that person unblocks or deletes their account. It restores the block if the blocked person recreates an account; it does not prevent registration. • Reports about a deleted profile are stripped of free text and direct profile links and grouped only by a random token. Unresolved reports remain until resolution and any appeal are final. Ordinary resolved evidence is then retained for 365 days. Evidence supporting an active platform ban follows that ban's reviewed retention cap; after lift or expiry, the configured 30-day grace applies without extending beyond the reviewed cap. A staff-reviewed ban renewal extends that cap. • An active CyberTip, 18 U.S.C. Section 2703(f), or litigation hold overrides the report deadline until the hold is explicitly released. The already-computed deadline applies at the next cleanup after release. • Closed support-ticket projections are scheduled for deletion 14 days after you view the closure, or 60 days after closure if you do not view it. • Production database backups expire under the configured backup policy, currently up to 35 days. Deleted active data is not restored except as necessary for disaster recovery and is removed again through normal cleanup. • Azure Monitor data follows the enforced 30-day workspace retention. Expo diagnostics follow the limited retention configured with the provider. After ordinary deletion, a person may create a new account. A still-effective platform ban or blocker-owned pair block may be reapplied through the restricted aliases above.

8. U.S. State Privacy Rights

Depending on your state and whether its law applies, you may have rights to know or access personal information, correct inaccurate information, request deletion, obtain a portable copy, appeal a denied request, or opt out of certain sale, targeted-advertising, profiling, or sensitive-data uses. Rishtio does not sell personal information or use it for cross-context behavioral advertising. We verify requests to protect the account and respond within the timeframe required by the law that applies.

9. California Residents

Where the California Consumer Privacy Act applies, California residents may request access to categories and specific pieces of personal information, correction, deletion, and information about sources, purposes, and recipients. California law also provides rights concerning sale, sharing, and some uses of sensitive personal information. Rishtio does not sell or share personal information for cross-context behavioral advertising. We will not discriminate against you for exercising an applicable privacy right.

10. Biometric Feature Status

Photo liveness, face matching, and 1:N duplicate-face detection are not enabled in the current U.S. production launch. Before any future production activation, Rishtio must publish an updated biometric notice and retention/destruction schedule, describe the specific purpose and term of collection and Microsoft processor use, identify duplicate-face detection as a distinct purpose, and obtain the consent or written release required for the applicable state. This notice does not represent that those activation requirements have already been completed.

11. Telemetry and Analytics

Rishtio collects necessary operational telemetry covering security events, sanitized reliability issues, release health, startup performance, and aggregate failed EAS Update launch signals. Rishtio also collects first-party product-flow events, screen views, and native lifecycle events to understand feature use and improve the Service. These collections are part of the Service, are purpose-limited, and are not used for advertising, targeted advertising, cross-app tracking, or sale of personal information.

12. Local Storage & Cookies

Rishtio does not use tracking cookies. On the web, the access token stays in memory and the refresh token is kept in a secure HttpOnly cookie. Browser storage is used for interface preferences, active-profile state, and push notification identifiers. We collect operational, security, performance, and first-party product analytics through Microsoft Azure Application Insights and Expo Application Services for secure sign-in, fraud and abuse prevention, release safety, app reliability, and understanding feature use. Telemetry does not include advertising identifiers, chat or profile content, verification document content, document blob paths, authentication tokens, screenshots, session replays, or provider response bodies. No advertising cookies, cross-site tracking cookies, or cross-app tracking are used.

13. Data Security

We use safeguards including encryption in transit (TLS/HTTPS) and at rest, short-lived access tokens and secure refresh cookies, role-based authorization, private blob containers with time-limited access, managed identity for Content Safety, and operational monitoring through Azure Monitor. No transmission or storage method is completely secure.

14. Children's Privacy

Rishtio is a matrimony service intended exclusively for users age 18 and older. We do not knowingly collect personal information from children under 18. If we learn that a child provided personal information, contact us so we can investigate and delete it where required.

15. Privacy Contact

Anyone in the United States may submit a privacy request or appeal by contacting: Email: privacy@rishtio.com If you sign in to your own Rishtio account, you can also create a support ticket from Settings → Privacy & Support. Helper accounts do not have that screen and should use the email address above. Statutory rights depend on applicable law, but we provide this nationwide intake path without requiring you to identify a particular statute. We verify and respond within the period required by applicable law.

16. Changes to This Policy

We may update this Privacy Policy as the service, launch scope, or legal requirements change. We will provide notice where required and will request fresh affirmative consent before a newly enabled activity when the applicable law requires it.