Privacy Policy
Version 2026-07-25
YakDil is built privacy-first: your matrimony profile exists for the people you choose — not for search engines, advertisers, or strangers. This policy explains, completely and honestly, what we collect, why, who can see it, how long we keep it, and the rights and controls you have. It supplements our Terms of Use and applies wherever you use YakDil.
Who is responsible for your data: Saedi Group LLC, a limited liability company organised in Wyoming, United States, operating the YakDil service (the “controller” where data-protection law uses that term). Privacy contact: support@yakdil.com.
1. What we collect
Account data: your email address and/or phone number (used only to sign you in with one-time codes and send account emails), your language preference, and — if you choose Sign in with Google or Apple — the name and email those providers share with us.
Profile data you choose to provide: display name, date of birth, gender, city and country, heritage (ethnicity, province of origin), languages, education, profession, faith and practice details, lifestyle answers, marriage intentions, biography, icebreaker answers, photos, and optional voice or video introductions.
Verification data: if you choose to verify, a live selfie — and, for higher tiers, a photo of a government ID or a short live video — used only to confirm your profile is genuine. Section 3 describes exactly how this works and how long it is kept.
Guardian (wali) data: if a member invites a guardian, we process the email address or phone number the member provides for that guardian in order to send the invitation and, if accepted, operate the access level the member chose. If you received an invitation and do not want it, ignore it and nothing further is processed about you.
“Hide people I know” data: if you choose this optional feature, phone numbers you provide are converted to one-way cryptographic hashes and the hashes alone are stored — used solely to prevent those people and you from seeing each other on YakDil. We cannot read the numbers back, and they are never used for contact, marketing, or anything else.
Activity data: your likes, passes, matches, messages, calls metadata, reports, blocks, guardian invitations, and subscription status — the minimum needed for the service to work and for moderation to protect members.
Technical data: basic logs (IP address, device/browser type, timestamps) used for security, rate-limiting, and abuse prevention.
2. Faith and other sensitive information
A matrimony service for Muslims necessarily involves information about religion — your faith, practice level, sect, and similar details you choose to share. Where laws such as the EU/UK GDPR treat this as special-category data, we process it only with your explicit consent, which you give by choosing to enter it (every faith field offers “prefer not to say”), and only to operate the matching and profile features you signed up for. You can edit or remove these details at any time, and deleting your account deletes them. We never use faith information for advertising, never sell it, and never disclose it except as this policy describes.
3. Verification selfies & biometric processing
This section is our public written policy for verification media, including the retention schedule and destruction rules that biometric privacy laws (such as the Illinois Biometric Information Privacy Act) expect.
What happens: when you choose to verify, you capture a live selfie (or, for higher tiers, an ID photo or short live video) after giving explicit consent on the capture screen. A brief, automated check runs first — face detection to confirm the image shows one clear, unobscured face, and content moderation to block inappropriate images. The verification decision itself is made by a trained member of our team, who compares your submission with your profile photos.
What does NOT happen: we do not build a face template or faceprint of you, and we do not store or retain any biometric identifier. The automated check analyses the image in the moment and keeps nothing: no template, embedding, or measurement of your face is written to our systems, and we never use your image to search for or link you to any other account. The automated face detection runs transiently and returns only pass/fail-style results (for example, “one face found”). We never sell, lease, trade, or otherwise profit from verification media or any biometric data, and we never disclose it except to the service providers that store and process it for us under contract (section 6) or where section 6’s legal-request rules require.
Retention schedule and destruction: verification media is stored privately, is never shown to other members, and is destroyed as soon as the purpose for collecting it is met. In practice that means we permanently erase the image or video within 30 days of the verification decision — we keep only the outcome (verified or not) and an audit record of who decided and when. If a decision is still pending, or an appeal or fraud investigation is open, we hold the media only until that closes. In every case, media is destroyed at the latest on the earlier of: (a) your account deletion becoming final (deletion takes effect after a 30-day recovery window, after which a nightly process erases the files and the account); or (b) 3 years passing since your last interaction with YakDil.
Withdrawing consent: you may withdraw consent at any time by deleting your account (which destroys the media as above) or by contacting support@yakdil.com to request removal of your verification media — in which case your verified badge is also removed, since we can no longer stand behind it.
4. What we deliberately do NOT do
We do not sell or rent your data — to anyone, ever. We do not show advertising and do not share your data with advertisers or data brokers. We do not run third-party tracking pixels or advertising analytics on your profile. Your profile and photos are never indexed by search engines — a web search for your name will not lead to your YakDil profile. We do not read your conversations for advertising or profiling. Authorised staff may review conversations only where necessary to investigate a report or automatically-flagged message, to address a safety or fraud concern, or to comply with a legal obligation — and every such review is limited to authorised staff and recorded in an internal access log.
5. How we use your data — and the legal bases
We use your data only to: create and display your profile as you configure it; suggest compatible members; deliver messages and calls; verify identity; keep members safe (moderation, fraud and scam prevention, enforcing our Terms); provide support; process subscriptions; send service messages (sign-in codes, account confirmations) and — only with your consent, which you may withdraw in Settings — match/interest notification emails. Where GDPR or similar laws apply, our legal bases are: performance of our contract with you (operating the service), your explicit consent (faith details, verification media, optional data, notifications), our legitimate interests (safety, security, preventing abuse), and legal obligations.
6. When we share data
We share data only with: (a) service providers that process it on our instructions to run YakDil, each limited to what its function requires. Currently these are: Vercel (hosting), Neon (database), Cloudflare (private media storage and bot protection), Amazon Web Services (the transient automated checks that screen images uploaded to YakDil — verification media, profile photos, chat images, and community post photos — described in sections 3 and 7), Resend (email delivery), Twilio (SMS delivery, where a sign-in code or a guardian invitation is sent to a phone number), LiveKit (voice/video calls), Google Firebase (push notifications, if you use the mobile app and turn them on), and Sentry (error monitoring). (b) Payment processors — Stripe, when you purchase Plus — who handle your card details directly; we never see or store full card numbers. (c) Authorities, where we believe in good faith that disclosure is required by law or necessary to prevent serious harm to someone. We review every legal request narrowly, provide the minimum data that a valid request lawfully compels, and — where the law allows — tell the affected member. We understand that for parts of our community, this discipline is not a formality; it is safety. (d) A successor operator, if YakDil is ever merged or acquired — in which case this policy continues to protect your data and you will be notified. There is no category (e): we do not share with advertisers, brokers, or “partners”.
7. Who can see your photos and profile
Every photo is stored in a private bucket and served only through requests we access-check each time — never a public link, and never indexed by search engines. Beyond that, the two kinds of photo on YakDil work differently, and the difference is important enough to spell out.
Profile photos follow the privacy level you set, and blurring is a control on women’s profiles. A woman can choose to stay blurred to everyone (the default she starts with), to unblur for members she has matched with, or to hide her photos entirely — and she can change that at any time. Men’s photos are not blurred: they are shown to signed-in members, and a man’s one photo control is to hide his photos entirely, which is available to everyone. Whatever the level, it is re-checked on every single request, so access revokes the moment a match ends or a block is placed.
Community post photos are public to the whole signed-in community — deliberately. If you attach a photo to a community post, every signed-in member who can see that post sees the photo in full. There is no blurred version of it, and your profile photo-privacy setting does not apply to it: if your profile photos are set to “blurred to everyone”, a photo you post to the community is still shown unblurred. Posting a photo is therefore a separate decision from anything you have chosen for your profile — treat it as showing your face to the entire community, because that is what it does. Three rules protect that choice: a photo can be attached only in the “Everyone” circle, never in the sisters-only or brothers-only circles; a photo can never be posted anonymously, because a face identifies you no matter what name sits above it; and every community photo is screened and must be approved before it appears — until then nobody but you can see it.
Common to both: location metadata is stripped from every photo automatically, and every member controls who can view, contact, and find them. Guardian (wali) access exists only if — and at the level — the member herself chooses. Remember that anything you reveal to a matched member, or post to the community, can be seen and kept by the people who saw it; choose what you share with care.
8. Cookies & on-device storage
YakDil uses only essential storage: a session cookie that keeps you signed in (httpOnly, secure), a language cookie, cookies for the guardian and staff areas when those are used, and on-device preferences such as your light/dark theme, sign-up draft, and which announcements you have read. All of these are first-party. The one third-party element is Cloudflare Turnstile, the bot check on the sign-in screen. We use no third-party advertising or tracking cookies, so there is no cookie consent theatre — there is simply nothing to opt out of. Because we do not track you across sites or sell data, signals like Global Privacy Control and Do Not Track are honoured by design: there is nothing they need to switch off.
9. How long we keep data (retention)
Your data is kept while your account exists. If you pause your account, everything is kept but hidden until you return. If you delete your account, it is hidden immediately and permanently erased after a 30-day recovery window (so a hijacked account can be rescued); after erasure your profile, photos, verification media, voice/video intros, messages, and chat attachments are deleted from the service and its storage; residual copies inside encrypted backups are overwritten as those backups age out on their normal cycle, and are never restored into the service or used for any other purpose. Verification media additionally has the 3-year inactivity limit in section 3. Hashed “hide people I know” entries are kept until you remove them or delete your account. We retain only what the law requires or safety demands — for example, records tied to a fraud or safety report, payment records required for tax law, and minimal audit logs. Unfinished sign-ups and expired sign-in codes are cleaned up automatically.
10. Security
Data is encrypted in transit (TLS) and at rest. Sign-in uses one-time codes stored only as hashes — there are no passwords to steal. Sessions are revocable server-side; you can see and end your other sessions in Settings. Photo access is authorised on every single request. Changing your email or phone requires a code sent to the new contact. Administrative actions are audit-logged. Screenshot deterrents and human moderation add further protection. No online service can promise perfect security — but if we ever discover a breach affecting your personal data, we will notify you and the relevant authorities as applicable law requires.
11. Your rights and controls
Directly in the app, at any time, you can: edit or remove any profile detail or photo; control who sees, contacts, and finds you; switch notification emails off; change your email or phone; pause your account; export your data; and delete your account entirely. Depending on where you live — including under the EU/UK GDPR and California’s CCPA/CPRA — you may also have legal rights to access, correct, delete, port, restrict, or object to processing of your data, to withdraw consent, to not be discriminated against for exercising rights, and to complain to your data-protection authority. The in-app tools satisfy most of these instantly; for anything else, contact support@yakdil.com or Help & Contact and we will respond within the legally required time. You may use an authorised agent where the law provides for one; we will verify the request with you directly before acting.
12. Notice to California residents
In CCPA/CPRA terms, we collect these categories: identifiers (email, phone); characteristics of protected classifications you choose to share (such as religion, gender, marital status); biometric information only in the limited, transient sense described in section 3; audio/visual information (photos, voice/video intros, verification media); coarse geolocation (the city and country you enter, and the country your connection appears to come from, which we use for regional pricing and sanctions compliance — we do not collect GPS location); internet activity limited to the security logs in section 1; and inferences limited to the match suggestions described in section 13. We collect them for the purposes in section 5, keep them for the periods in sections 3 and 9, and disclose them only as in section 6. We do NOT sell personal information, do NOT “share” it for cross-context behavioural advertising, and have no financial-incentive programs based on it. Sensitive personal information (faith details, verification media) is used only to provide the service you asked for — never to infer characteristics for other purposes — so no “Limit the Use of My Sensitive Personal Information” step is needed.
13. How matching works (automated processing)
YakDil suggests profiles using the preferences and details you provide — such as languages, location, practice level, and stated intentions. These suggestions are recommendations only: they filter and order profiles; they never make any decision with legal or similarly significant effect about you. You can change your filters at any time, and no suggestion algorithm ever overrides your privacy settings.
14. Children
YakDil is strictly for adults seeking marriage. You must be at least 18 years old. We do not knowingly collect data from anyone younger; any such account is removed and its data deleted as soon as we become aware.
15. International transfers
YakDil serves the global Muslim community, so your data may be processed on servers outside your country (currently in the United States and Europe via the providers named in section 6). Where the GDPR or similar laws apply to a transfer, we rely on the safeguards those laws provide — such as the European Commission’s Standard Contractual Clauses and our providers’ equivalent commitments — and the protections in this policy travel with your data wherever it is processed.
16. Changes to this policy
If we change this policy, the version date above changes, and material changes are announced in the app before they take effect. If a change ever reduced your privacy in a significant way — including any change to section 3 — we would ask for your consent rather than assume it.
17. Contact
Privacy questions or requests: email support@yakdil.com, or use the in-app support tools or Help & Contact. We answer privacy requests from the account owner after verifying identity, so nobody else can use your rights against you.