Last updated: August 20, 2026
Rishtio is operated by Stone Roses Circle Co.
1. Who We Are and Scope
Stone Roses Circle Co ("Company," "we," "us," or "our") operates Rishtio. This Privacy Policy describes how we handle personal information for Rishtio's nationwide United States service. The current launch is for adults age 18 and older. Creating an account requires agreement to the current Terms and acknowledgement of this Policy, which together cover the required identity-document processing described below. Processing begins only when the profile subject chooses to upload a document. Privacy rights vary by state and apply when the relevant law covers the Company, the information, and the request.
2. Information We Collect
We collect these categories when they are needed for the Service:
• Account and identity data, such as name, date of birth, gender, email, phone number, and Apple or Google sign-in identifiers.
• Profile data, including photos, location, height, education, work, income, lifestyle, languages, narratives, and optional religion, community/caste, astrology, nationality, and precise-location details.
• Search and activity data, including search text, filters, saved preferences, profile views, connections, reports, and feature use.
• Communications and support data, including chat messages, support requests, attachments, app-review feedback, and safety reports.
• Identity-verification data when the profile subject uploads a government document, including the file, extracted fields, document metadata, verification result, and restricted identifiers used to detect duplicate reuse or enforce a safety action.
• Device, security, and analytics data, such as app and browser version, screen views, product-flow events, performance, release health, and fraud or reliability signals.
• AI-derived data, including embeddings, summaries, suggestions, review results, extracted search fields, and ranking scores.
Photo liveness, face matching, and duplicate-face detection are disabled for the current production launch, so Rishtio does not collect verification face data.
3. Where Information Comes From
We receive information from you; from a family member or helper acting with your knowledge; from Apple or Google when you use social sign-in; from your activity in Rishtio; and from service providers that perform requested functions, security checks, or support work for us. A helper-created draft stays private and outside member features until the adult profile subject signs in, accepts the required documents, chooses helper access, and decides whether to publish.
4. How We Use Information
We use personal information to operate profiles, search, recommendations, writing review, matching, connections, chat, support, and invited-helper features; authenticate accounts; prevent fraud and abuse; moderate profile photos; complete identity-document verification after the subject chooses to upload a document; provide first-party analytics, security, and reliability; enforce our policies; and comply with law. We do not use personal information for third-party advertising.
5. AI and Automated Processing
Microsoft Azure OpenAI in East US processes relevant profile, narrative, search, preference, and context data for embeddings, ranking, summaries, suggestions, writing review, and search interpretation. These features are essential to Rishtio; there is no separate non-AI mode. We store the resulting outputs until they are replaced, no longer needed, or deleted with the account.
Azure AI Content Safety checks each new ordinary profile photo before publication. Azure AI Document Intelligence reads the fields needed from an identity document after the profile subject chooses to submit it. Identity documents, chat messages, and contact details are not sent to Azure OpenAI for profile or preference embeddings. Face verification remains unavailable. Automated output can be wrong or biased, and users and families remain responsible for relationship decisions.
6. When We Disclose Information
We disclose only the information needed for these purposes:
• Microsoft Azure provides hosting, storage, chat, monitoring, security, Azure OpenAI, Content Safety, and Document Intelligence services.
• Apple and Google provide social sign-in and mobile push delivery. Browser push services deliver web notifications, our configured email provider delivers account and safety email, and Google Maps provides location search and geocoding.
• GitHub hosts restricted support-ticket and app-review work items. Support and app-review text, attachment names and references, and a pseudonymous account identifier with platform and app version may be copied there for case handling; attachment files remain in our Azure storage.
• Expo Application Services provides app delivery and limited installation-level startup and update-health diagnostics.
• Professional advisers, authorities, or other recipients may receive information when reasonably necessary to protect rights or safety, complete a transaction you request, or comply with law.
We do not sell personal information or share it for cross-context behavioral advertising.
7. Processing Locations
Primary production application data is stored and processed in Microsoft Azure's Central US region. Azure OpenAI, Azure AI Content Safety, and Azure AI Document Intelligence process the disclosed inputs in East US. GitHub, Expo, Apple, Google, browser push services, email delivery providers, and their subprocessors may process information in locations described in their terms.
8. Retention and Deletion
We keep active-account information while needed to provide the Service and for the purposes above. Photos rejected by the safety check and abandoned uploads are removed through cleanup. Closed support tickets and their attachments are scheduled for deletion 120 days after closure.
Deleting an account revokes access and removes the profile from use while background cleanup removes account-owned data and files. We do not promise a fixed completion time, because provider deletion and credential-expiry checks may require retries.
Limited records may remain: reviewed ban identifiers, which are one-way codes that contain neither your sign-in ID nor your document number, may be kept for up to five years; a member-controlled block record remains until the blocker unblocks or deletes their account; unresolved reports remain through final review and appeal; ordinary resolved report evidence remains for one year; and evidence supporting a ban follows the ban period plus a capped 30-day post-ban grace. A CyberTip, preservation request, litigation hold, or other legal obligation can delay deletion until the hold is explicitly released.
Production backups expire within up to 35 days. Azure Monitor records follow a 30-day retention period. Other providers retain information under their terms and our deletion instructions.
9. U.S. State Privacy Rights
Depending on your state and whether its law applies, you may have rights to know or access personal information, correct it, delete it, obtain a portable copy, appeal a denied request, or opt out of qualifying sale, targeted advertising, profiling, or sensitive-data uses. We verify requests to protect the account and do not discriminate against anyone for exercising an applicable privacy right.
10. California Residents
Where the California Consumer Privacy Act applies, California residents may request categories and specific pieces of personal information, sources, purposes, recipients, correction, deletion, and portability. California law also provides rights concerning sale, sharing, and qualifying uses of sensitive personal information. We do not sell or share personal information for cross-context behavioral advertising.
11. Biometric Feature Status
Photo liveness, face matching, and duplicate-face detection are disabled in the current U.S. production launch. Before any future activation, we must publish the required biometric notice and retention schedule, explain each purpose and provider, and obtain any consent or written release required by applicable law. This Policy does not mean those future requirements have been completed. Contact support@rishtio.com with questions about a future biometric feature or a prior test-environment verification record.
12. Analytics, Local Storage, and Cookies
We collect operational, security, performance, and first-party product-flow events to protect accounts, maintain reliability, and understand feature use. This information is not used for advertising, targeted advertising, cross-site tracking, cross-app tracking, or sale.
Rishtio does not use advertising or tracking cookies. On the web, a secure HttpOnly cookie supports session refresh, and browser storage keeps interface preferences, active-profile state, and push identifiers. Telemetry excludes advertising identifiers, chat and profile content, identity-document content or paths, authentication tokens, screenshots, session replays, and provider response bodies.
13. Data Security
We use administrative, technical, and organizational safeguards, including encryption in transit and at rest, access controls, short-lived credentials, private file storage, monitoring, and restricted staff access. No method of transmission or storage is completely secure.
14. Children's Privacy
Rishtio is only for adults age 18 and older. We do not knowingly allow an account or profile for a child. Contact us if you believe a child has provided personal information so we can investigate and take appropriate action.
15. Changes to This Policy
We may update this Policy as the Service, providers, or legal requirements change. We will post the updated text and date, provide additional notice where required, and obtain fresh consent before a newly enabled activity when applicable law requires it.
16. Contact and Requests
Operator: Stone Roses Circle Co
Submit a privacy question, request, or appeal at support@rishtio.com. If you sign in to your own account, you may also use Settings → Privacy & Support. Do not send passwords, social-provider tokens, identity documents, or other unnecessary sensitive information. We verify requests and respond within the period required by applicable law.