Privacy Policy
This Privacy Policy ("Policy") explains how Qwikhive Technologies Private Limited ("Company", "we", "us", or "our"), a company incorporated under the Companies Act, 2013, collects, uses, shares, stores, and deletes your personal data when you use the "Duet" mobile application ("Platform") and related services ("Services").
This Policy is published under the Information Technology Act, 2000, the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 ("SPDI Rules"), the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021 ("IT Rules"), and the Digital Personal Data Protection Act, 2023 and the rules made under it ("DPDPA"), to the extent each is in force.
Some of the information you give us is sensitive — for example your sexual orientation, gender identity, religion, and intimate preferences. We ask for your explicit consent to process it when you sign up. Please read this Policy carefully; if you do not agree with it, do not use the Platform.
1. Who We Are
The Company is the Data Fiduciary for your personal data. For any privacy question, request, or grievance, contact our Grievance Officer:
- Name: Grievance Officer name, Qwikhive Technologies Private Limited
- Address: D-9, Ground Floor, Sector 3, Noida, Gautam Buddha Nagar, Uttar Pradesh 201301, India
- Email: contact@qwikhive.com
- We acknowledge grievances within 24 hours and resolve them within 15 (fifteen) days of receipt.
2. Data We Collect
2.1 Data You Give Us
- Sign-in data: if you use Google Sign-In, your name, email address, and Google account ID; if you use Sign in with Apple, your Apple user ID, and the name and email address (or Apple's private relay email) you choose to share. We use this only to sign you in and contact you about your account. We do not access your contacts, emails, or any other data in those accounts.
- Identity: display name, date of birth, gender, sexual orientation, relationship status, and who you are looking to meet.
- Profile details: photographs, bio, vibe prompt answer, spark tags, personality archetype, intentions, languages, religion, diet, smoking and drinking habits, children and family plans, profession, industry, alma mater, income range, height, body type, hair and eye colour, and (optionally) intimate preferences.
- Location: see Section 2.3.
- Discovery preferences: age range, distance, and filters you set.
- Messages and media: the text messages, voice notes, photos, and gifts you send and receive.
- Verification: if you choose to get verified, a selfie of you holding a handwritten code.
- Safety and support: reports you make or that are made about you, blocks, and your support tickets and our replies.
- Purchases: the credit packs you buy (product, time, and store transaction ID) and how you spend Credits. We never receive your card or bank details.
- App Lock PIN: if you set one, only a salted hash of it is stored, and only on your device. It is never sent to us.
2.2 Data Collected Automatically
- Activity on the Platform: likes, passes, matches, profile views, and when you were last active.
- Device and technical data: device model, operating system and app version, IP address, access logs, and a push-notification token.
- Usage analytics: app-usage events such as screens viewed and sessions, collected through Firebase Analytics. We do not collect your device's advertising identifier.
- Crash and error reports: technical diagnostics when the app crashes or encounters an error, collected through Firebase Crashlytics and Sentry. We do not include your gender, orientation, relationship status, or messages in these reports.
2.3 Location
If you tap "use my location" and grant permission, the app reads your device's current GPS position once. The coordinates are sent to OpenStreetMap's Nominatim service to find your city and state, and are stored on our servers so we can show you people nearby first. If you type or select a place instead, we look up approximate coordinates for that place. We do not track your location in the background. Other members see only your city/state — never your coordinates or your distance from them. You can change your location at any time in Edit Profile.
2.4 Sensitive Personal Data
The following are sensitive personal data under the SPDI Rules, or are data we treat with the same care. We process them only with your explicit consent and only to run the Platform:
- Sexual orientation, gender identity, and intimate preferences (information about your sex life).
- Religion.
- Financial information (the income range you choose to add to your profile).
- Your verification selfie. It is reviewed manually by our team and is not processed with facial-recognition or biometric-matching technology. We would ask for fresh consent before any such use.
2.5 Automated Content Moderation
Profile photographs and profile text are screened by OpenAI's moderation service before they are published, to detect nudity, sexual content, violence, self-harm, and other prohibited material. Content that fails screening is not published, and a rejected photograph is never stored. Chat messages are not automatically screened. A person reviews content only if it is reported, if you appeal a decision, or if needed for a safety or legal reason.
3. What Other Members Can See
Other members can see the profile you build, including:
- Your display name, age, sun sign, gender, city/state, and whether you are verified.
- Your photographs — or, if you turn on "Mutual approval for photos", only a blurred version until you have both matched.
- Your bio, prompt answer, spark tags, intentions, and any optional details you add: relationship status, children, religion, languages, diet, smoking and drinking habits, profession, industry, alma mater, income range, height, body type, hair and eye colour, and intimate preferences.
- Whether you are online now, and when you were recently active.
Members who unlock premium filters can filter Discover by religion, sun sign, income range, and intimate preferences, so these details affect who sees your profile. Leave an optional field blank if you do not want it shown or used this way.
Other members never see your exact date of birth, sexual orientation (it is used only to decide who you are shown to), email address, location coordinates, verification selfie, Credit balance, or purchases.
If you turn on Incognito Mode, your profile is hidden from Discover feeds; people you have liked, sent a Spark to, or matched with may still see it.
3.1 Chemistry Score
Any member who can see your profile can ask for a Chemistry Score with you. It is a percentage, with a percentage for each of ten areas (such as faith and culture, lifestyle, interests, attraction, stars, life stage, career and sexual chemistry) and a few shared "green flags". It is calculated automatically on our servers from both members' profile answers — including religion, income range, height, body type, relationship status, children and intimate preferences — the preferences each of you set in Discover Filters (which we store for this purpose), and, for the attraction area only, whether each of you is looking to meet the other's gender, which is derived from sexual orientation.
A Chemistry Score never shows your sexual orientation, and never names your intimate preferences (only how many you share). Income, height and body type only ever appear as positive statements, such as "you fit each other's type". You are not told when someone checks a score with you; you see it only if they choose to share it with you in chat. The result for a pair is stored so either member can see it again, and is deleted if either account is deleted. It is for fun and is not advice or a prediction.
4. Why We Use Your Data
- To create and run your account and sign you in.
- To show you profiles and rank Discover by location, age, preferences, and activity, and to show your profile to others according to your settings.
- To calculate Chemistry Scores when you or another member asks for one (see Section 3.1).
- To deliver messages, voice notes, photos, and gifts.
- To process Credit purchases and spends, and to decide which features are free for you (this depends on your gender, as set out in the Terms of Use).
- To send you notifications about activity on your account and, if you have not opted out, promotional offers.
- To verify profiles, moderate content, handle reports, and prevent fraud, abuse, and harm.
- To respond to support requests and grievances.
- To fix crashes and improve the app.
- To comply with the law and with lawful requests from authorities.
We do not sell your personal data, and we do not use it for third-party advertising.
5. Consent and Legal Basis
We process your personal data on the basis of the consent you give at sign-up, and, where applicable, for legitimate uses permitted by the DPDPA, such as complying with law, responding to a medical emergency or threat to safety, or a court order.
You can withdraw consent at any time: remove optional details or photos in Edit Profile, revoke location or notification permission in your device settings, turn off promotional notifications in Settings, or delete your account to withdraw consent entirely. Withdrawal does not affect processing already carried out. Some features cannot work without certain data — for example, the Platform cannot match you without your age and gender.
6. Who We Share Your Data With
We share personal data only as described below.
- Other members: your profile, as described in Section 3, and the messages and media you send them.
- Supabase — hosts our database, sign-in, file storage, and server functions in the Mumbai, India region.
- Google (Firebase) — delivers push notifications, and provides usage analytics and crash reporting. Google also provides Google Sign-In and, on Android, Google Play billing.
- Apple — provides Sign in with Apple and, on iOS, App Store billing and push delivery.
- RevenueCat — manages in-app purchase records so that Credits can be delivered. It receives your internal account ID (a random identifier, not your name or email) and purchase details, not your profile.
- OpenAI — screens profile photographs and profile text for prohibited content (see Section 2.5).
- Sentry — receives crash and error diagnostics.
- OpenStreetMap Foundation (Nominatim) — converts GPS coordinates into a city and state name, and place names into approximate coordinates.
- Law enforcement and authorities: when required by law, including in response to a lawful order or request from an authorised government agency under the IT Act and IT Rules, or where we believe in good faith that disclosure is necessary to prevent imminent harm to someone.
- Business transfers: if the Company is involved in a merger, acquisition, or sale of assets, personal data may be transferred to the successor, which must protect it as described in this Policy.
Our service providers process data only on our instructions and for the purposes above, under contractual confidentiality and security obligations.
7. Transfers Outside India
Your profile, photographs, messages, and account data are stored in India (Mumbai region). Some service providers — Google (Firebase), Apple, RevenueCat, OpenAI, Sentry, and the OpenStreetMap Foundation — may process limited data outside India, for example in the United States or the European Union. We transfer data only to countries not restricted by the Government of India under the DPDPA, and only as needed for the purposes above.
8. How Long We Keep Data
- While your account is active, we keep your data for as long as it is needed to provide the Services.
- "View once" and timed photos are deleted from our servers once viewed or once the timer ends.
- When you delete your account, your profile, photographs, verification selfie, matches, conversations (including messages and media you exchanged, which also disappear for the other person), Credit balance, and transaction history are erased from our live systems immediately. Copies in our hosting provider's encrypted backups are overwritten on its regular backup cycle.
- Where the law requires us to keep certain data after deletion — for example, registration information that the IT Rules require an intermediary to retain for 180 days after an account is closed, information relevant to a pending report, investigation, or legal claim, or records required under tax law — we keep only that data, only for the required period, and only for that purpose.
- Purchase records are also kept by Apple, Google, and RevenueCat under their own policies.
- Analytics and crash data are kept for limited periods set in Firebase and Sentry, and are not linked to your profile details.
9. How We Protect Your Data
- All data in transit — including messages, photos, and voice notes — is encrypted with TLS.
- Messages are not end-to-end encrypted. They are access-controlled so that only the two people in a conversation can retrieve them in the app. Our staff do not read them except as necessary to investigate a report, a safety issue, or a lawful request.
- Database access is restricted by server-side Row Level Security policies, including for Incognito Mode.
- Profile photographs, chat photos, voice notes, and verification selfies are kept in private storage and served only through links that expire automatically.
- Location and device metadata (EXIF, including GPS coordinates) is removed from profile photographs before they are stored or screened.
- Your sign-in session is stored in your device's secure Keychain (iOS) or Keystore (Android), not in plain app storage.
No system is completely secure. If a personal-data breach occurs, we will notify affected users and the relevant authorities (including the Data Protection Board of India and CERT-In) as required by law.
10. Your Rights
Subject to the DPDPA and other applicable law, you have the right to:
- Access a summary of the personal data we process about you and how we process it, and the identities of those we have shared it with.
- Correct, complete, or update your data — most of it directly in Edit Profile.
- Erase your data by deleting your account (Section 11), or ask us to erase specific data.
- Withdraw consent (Section 5).
- Nominate another person to exercise these rights on your behalf in the event of your death or incapacity.
- Raise a grievance with our Grievance Officer, and, if you are not satisfied, complain to the Data Protection Board of India.
To exercise these rights, email contact@qwikhive.com from the email address linked to your account. We may need to verify your identity before acting on a request.
11. Deleting Your Account
You can delete your account at any time from Settings → Legal & Data → Delete Account. Deletion takes effect immediately and cannot be undone. Unused Credits are forfeited. What we keep, and for how long, is described in Section 8.
12. Notifications
With your permission, we send push notifications through Firebase Cloud Messaging. The push message itself contains only a notification type and ID; the app then fetches the text to display from our servers. The displayed notification may include another member's display name (for example, "Asha sent you a message") and can appear on your lock screen — you can hide notification previews in your device settings. Message content is never included.
We may send promotional offers, which may be targeted using your gender (because pricing depends on it). You can turn them off in Settings → Notifications → New Offers, and turn off all notifications in your device settings.
13. Age Restriction and Children
The Platform is only for people aged 30 and above. We do not knowingly collect personal data from anyone under 30, and never from children (under 18). If we learn that such a person has created an account, we will delete it. Please report any such account to contact@qwikhive.com.
14. Cookies and Tracking
The app does not use browser cookies. We do not collect your device's advertising identifier, and we do not track you across other companies' apps or websites.
15. Changes to This Policy
We may update this Policy from time to time. We will tell you about material changes in the app at least 15 (fifteen) days before they take effect, and ask for fresh consent where the law requires it. We will also remind you of this Policy at least once a year.
16. Governing Law
This Policy is governed by the laws of India. Disputes are resolved as set out in the "Governing Law and Dispute Resolution" section of our Terms of Use. This does not limit your right to complain to the Data Protection Board of India.
Contact us
Qwikhive Technologies Private LimitedD-9, Ground Floor, Sector 3, Noida, Gautam Buddha Nagar, Uttar Pradesh 201301, India
Email: contact@qwikhive.com