Privacy Policy
Thammil is a dating app for Malayali singles in Kerala, across India and abroad. This policy explains what we collect, why, who we share it with, and the rights you have under India's Digital Personal Data Protection Act, 2023 (DPDP Act).
If you do not agree with this policy, please do not use Thammil.
1. Who we are
Thammil is operated by Sathish Nagaraj, an independent developer. For the purposes of the DPDP Act we act as the data fiduciary for the data described below.
Questions, complaints, and data principal requests: smewritingagency@gmail.com.
2. What we collect
2.1 Information you give us
| Data | When | Why |
|---|---|---|
| Mobile number (+91) | Sign-up | Account identity, OTP verification, duplicate-account prevention |
| Email address and Google account name | Google Sign-In | Authentication |
| First name / display name | Onboarding | Shown on your profile |
| Date of birth | Onboarding | Age verification (18+) and age-based matching |
| Gender and who you want to meet | Onboarding | Matching |
| State and district | Onboarding | Location-based matching |
| Profile photos | Onboarding, profile edit | Shown to other users |
| Verification selfie | Verification | Confirms your photos are of you |
| Bio, occupation, languages, height | Optional | Profile completeness and matching |
| Religion / community | Optional | Matching preferences |
| Reports you file | When you report someone | Safety investigation |
2.2 Sensitive personal information
Some of the above is sensitive — in particular your religious or community affiliation, your age, and information that reveals your sexual life (who you are looking to date). We treat it with the extra care the DPDP Act expects for personal data of this kind.
We process these only with your consent, given when you complete onboarding, and only to operate matching. You may leave the religion and community fields blank; matching still works without them. We do not sell, rent, or disclose sensitive personal information for advertising.
2.3 Biometric data (verification selfie)
Photo verification compares your selfie against your profile photos using
Amazon Rekognition (CompareFaces and DetectFaces). This is a
face-comparison operation that produces a similarity score.
- The comparison is used only to decide whether to mark your profile verified.
- We do not use your face to identify you across other services, build a face database, or share face data with advertisers.
- Your selfie is stored in our Firebase Storage bucket and is deleted when you delete your account.
- Verification is optional, but unverified profiles are shown less often.
2.4 Information collected automatically
| Data | Source | Why |
|---|---|---|
| Approximate GPS location (latitude / longitude) | Device, with your permission | Auto-fills your district and state during onboarding |
| Device and app diagnostics, crash reports | Firebase Crashlytics | Fixing crashes and bugs |
| App integrity signals | Firebase App Check | Blocking bots and fake clients |
| In-app activity — likes, passes, matches, message timestamps, credits spent | Your use of the app | Operating the feed, matching, and the credit system |
| Purchase and subscription status | Google Play Billing | Unlocking premium features |
About location: we ask for location permission once, during onboarding, to fill in your district and state. You can decline and type them manually. We store the derived district/state and the coordinates captured at that moment. We do not track your location in the background or while the app is closed.
2.5 What we do NOT collect
- We do not read your contacts, SMS, or call logs.
- We do not track you across other apps or websites.
- We do not sell your personal data to anyone.
- We do not store your Google password — sign-in is handled by Google.
3. How your phone number is protected
Your mobile number is verified by a one-time code sent over WhatsApp. To stop one person from creating many accounts, we also store a one-way cryptographic hash of your number. A hash cannot be reversed back into your number. The readable number itself stays on your private account record and is never shown to other users.
4. What other users can see
| Visible to other users | Never visible to other users |
|---|---|
| Display name, age, district and state | Your exact mobile number |
| Profile photos | Your email address |
| Bio, occupation, languages, height | Your GPS coordinates |
| Religion / community (if you filled it in) | Your verification selfie |
| Verified badge | Your credit balance, trust score, purchase history |
| Languages and occupation | Reports you have filed |
Your profile is only visible to signed-in Thammil users. Profiles are partitioned per app: Thammil profiles are never shown inside Anril, Liyag or any other app we operate, and vice versa.
5. Who we share data with
We share only what is necessary, and only with these processors:
| Processor | What it receives | Purpose | Location |
|---|---|---|---|
| Google Firebase (Auth, Firestore, Storage, Realtime Database, Crashlytics, App Check) | Account data, profile data, photos, chats, diagnostics | Core app infrastructure | Realtime Database in Singapore (asia-southeast1); other services in Google Cloud |
| Amazon Web Services — Rekognition | Your verification selfie and profile photo | Face comparison for verification | ap-south-1 (Mumbai) |
| OpenAI | Profile text and reported message text | Automated moderation for abusive or explicit content | United States |
| MSG91 | Your mobile number | Sending the WhatsApp OTP | India |
| Google Play Billing | Purchase tokens, subscription status | Processing in-app purchases | Google Cloud |
| Google AdMob | Ad interaction signals | Optional rewarded ads | Google Cloud |
We also disclose data where required by law, court order, or a lawful request from Indian or other competent authorities, and where necessary to investigate fraud, abuse, or a threat to someone's safety.
5.1 Cross-border transfer
Your data is processed in India (Firestore, Storage and face verification in Mumbai), Singapore (Realtime Database) and the United States (text moderation), as listed above. The DPDP Act permits transfers to countries the Central Government has not restricted, and we remain accountable for your data wherever it is processed. By using Thammil you consent to this transfer.
6. How long we keep data
| Data | Retention |
|---|---|
| Account and profile data | Until you delete your account |
| Photos and verification selfie | Until you delete your account |
| Chat messages | Until you or the other person deletes the match, or you delete your account |
| Phone-number hash | Retained after deletion to prevent ban evasion and duplicate accounts |
| Reports and moderation records | Retained after deletion, as needed for safety and legal defence |
| Purchase records | Retained as required by tax and accounting rules |
| Crash logs | Up to 90 days |
7. Your rights under the DPDP Act
As a data principal you have the right to:
- Be informed — this policy, and notice before any new processing purpose.
- Access — get a copy of the personal data we hold about you.
- Rectify — correct anything inaccurate. Most fields are editable in-app under Profile → Edit.
- Erasure — delete your account and data. Use Profile → Delete Account in the app, or email us.
- Withdraw consent — stop optional processing, such as location or photo verification, at any time.
- Grievance redressal — have a complaint about our handling of your data answered.
- Nominate — name a person to exercise these rights for you if you are unable to.
To exercise any of these, email smewritingagency@gmail.com. We respond within 15 working days. We may ask you to verify your identity first.
If you are not satisfied with our response, you may escalate to the Data Protection Board of India, the authority established under the DPDP Act.
8. Security
- All traffic between the app and our servers uses TLS encryption.
- Access to your account record is enforced by Firebase Security Rules — only you and our administrators can read it.
- Sensitive system fields (credits, subscription, verification status, trust score) cannot be modified by any client, only by our servers.
- Server-side API keys and credentials are stored in a server-only collection that no app client can read.
- Firebase App Check blocks requests from tampered or unofficial clients.
No system is perfectly secure. If a breach affects your personal data and poses a real risk of serious harm, we will notify you and the Data Protection Board of India as the DPDP Act requires.
9. Children
Thammil is strictly for adults 18 years and older. We collect date of birth at sign-up and reject anyone under 18. If we learn that a minor has created an account, we delete it immediately.
10. Advertising
Thammil shows optional rewarded video ads through Google AdMob — you watch one only if you choose to, in exchange for credits. We do not pass your profile data, photos, or messages to advertisers. AdMob may use device-level advertising identifiers, which you can reset or limit in your Android settings under Settings → Google → Ads.
11. Changes to this policy
We will update this page when our practices change and revise the "Last updated" date at the top. For significant changes we will notify you in-app before they take effect.
12. Contact
Email: smewritingagency@gmail.com
Response time: within 15 working days