Thammil

Where it's mutual.

Privacy Policy

Last updated: 2 September 2026  ·  Applies to: Thammil (com.thammil.app) on Google Play

Data controller: Sathish Nagaraj (developer)  ·  Contact: smewritingagency@gmail.com

Thammil is a dating app for Malayali singles in Kerala, across India and abroad. This policy explains what we collect, why, who we share it with, and the rights you have under India's Digital Personal Data Protection Act, 2023 (DPDP Act).

If you do not agree with this policy, please do not use Thammil.

1. Who we are

Thammil is operated by Sathish Nagaraj, an independent developer. For the purposes of the DPDP Act we act as the data fiduciary for the data described below.

Questions, complaints, and data principal requests: smewritingagency@gmail.com.

2. What we collect

2.1 Information you give us

DataWhenWhy
Mobile number (+91)Sign-upAccount identity, OTP verification, duplicate-account prevention
Email address and Google account nameGoogle Sign-InAuthentication
First name / display nameOnboardingShown on your profile
Date of birthOnboardingAge verification (18+) and age-based matching
Gender and who you want to meetOnboardingMatching
State and districtOnboardingLocation-based matching
Profile photosOnboarding, profile editShown to other users
Verification selfieVerificationConfirms your photos are of you
Bio, occupation, languages, heightOptionalProfile completeness and matching
Religion / communityOptionalMatching preferences
Reports you fileWhen you report someoneSafety investigation

2.2 Sensitive personal information

Some of the above is sensitive — in particular your religious or community affiliation, your age, and information that reveals your sexual life (who you are looking to date). We treat it with the extra care the DPDP Act expects for personal data of this kind.

We process these only with your consent, given when you complete onboarding, and only to operate matching. You may leave the religion and community fields blank; matching still works without them. We do not sell, rent, or disclose sensitive personal information for advertising.

2.3 Biometric data (verification selfie)

Photo verification compares your selfie against your profile photos using Amazon Rekognition (CompareFaces and DetectFaces). This is a face-comparison operation that produces a similarity score.

2.4 Information collected automatically

DataSourceWhy
Approximate GPS location (latitude / longitude)Device, with your permissionAuto-fills your district and state during onboarding
Device and app diagnostics, crash reportsFirebase CrashlyticsFixing crashes and bugs
App integrity signalsFirebase App CheckBlocking bots and fake clients
In-app activity — likes, passes, matches, message timestamps, credits spentYour use of the appOperating the feed, matching, and the credit system
Purchase and subscription statusGoogle Play BillingUnlocking premium features

About location: we ask for location permission once, during onboarding, to fill in your district and state. You can decline and type them manually. We store the derived district/state and the coordinates captured at that moment. We do not track your location in the background or while the app is closed.

2.5 What we do NOT collect

3. How your phone number is protected

Your mobile number is verified by a one-time code sent over WhatsApp. To stop one person from creating many accounts, we also store a one-way cryptographic hash of your number. A hash cannot be reversed back into your number. The readable number itself stays on your private account record and is never shown to other users.

4. What other users can see

Visible to other usersNever visible to other users
Display name, age, district and stateYour exact mobile number
Profile photosYour email address
Bio, occupation, languages, heightYour GPS coordinates
Religion / community (if you filled it in)Your verification selfie
Verified badgeYour credit balance, trust score, purchase history
Languages and occupationReports you have filed

Your profile is only visible to signed-in Thammil users. Profiles are partitioned per app: Thammil profiles are never shown inside Anril, Liyag or any other app we operate, and vice versa.

5. Who we share data with

We share only what is necessary, and only with these processors:

ProcessorWhat it receivesPurposeLocation
Google Firebase (Auth, Firestore, Storage, Realtime Database, Crashlytics, App Check)Account data, profile data, photos, chats, diagnosticsCore app infrastructureRealtime Database in Singapore (asia-southeast1); other services in Google Cloud
Amazon Web Services — RekognitionYour verification selfie and profile photoFace comparison for verificationap-south-1 (Mumbai)
OpenAIProfile text and reported message textAutomated moderation for abusive or explicit contentUnited States
MSG91Your mobile numberSending the WhatsApp OTPIndia
Google Play BillingPurchase tokens, subscription statusProcessing in-app purchasesGoogle Cloud
Google AdMobAd interaction signalsOptional rewarded adsGoogle Cloud

We also disclose data where required by law, court order, or a lawful request from Indian or other competent authorities, and where necessary to investigate fraud, abuse, or a threat to someone's safety.

5.1 Cross-border transfer

Your data is processed in India (Firestore, Storage and face verification in Mumbai), Singapore (Realtime Database) and the United States (text moderation), as listed above. The DPDP Act permits transfers to countries the Central Government has not restricted, and we remain accountable for your data wherever it is processed. By using Thammil you consent to this transfer.

6. How long we keep data

DataRetention
Account and profile dataUntil you delete your account
Photos and verification selfieUntil you delete your account
Chat messagesUntil you or the other person deletes the match, or you delete your account
Phone-number hashRetained after deletion to prevent ban evasion and duplicate accounts
Reports and moderation recordsRetained after deletion, as needed for safety and legal defence
Purchase recordsRetained as required by tax and accounting rules
Crash logsUp to 90 days

7. Your rights under the DPDP Act

As a data principal you have the right to:

To exercise any of these, email smewritingagency@gmail.com. We respond within 15 working days. We may ask you to verify your identity first.

If you are not satisfied with our response, you may escalate to the Data Protection Board of India, the authority established under the DPDP Act.

8. Security

No system is perfectly secure. If a breach affects your personal data and poses a real risk of serious harm, we will notify you and the Data Protection Board of India as the DPDP Act requires.

9. Children

Thammil is strictly for adults 18 years and older. We collect date of birth at sign-up and reject anyone under 18. If we learn that a minor has created an account, we delete it immediately.

We have zero tolerance for child sexual abuse and exploitation. See our Child Safety Standards.

10. Advertising

Thammil shows optional rewarded video ads through Google AdMob — you watch one only if you choose to, in exchange for credits. We do not pass your profile data, photos, or messages to advertisers. AdMob may use device-level advertising identifiers, which you can reset or limit in your Android settings under Settings → Google → Ads.

11. Changes to this policy

We will update this page when our practices change and revise the "Last updated" date at the top. For significant changes we will notify you in-app before they take effect.

12. Contact

Email: smewritingagency@gmail.com
Response time: within 15 working days