Privacy Policy
Last updated: 14 September 2026
1. Overview
Ashegham is built privacy-first. We collect the minimum data needed to run a marriage-focused community, we never sell it, and we treat the safety of our members as a design requirement, not an afterthought.
2. What we collect
Account: your email address, hashed password (or, with Google sign-in, your Google account identifier), language, and account dates.
Profile: the information you choose to publish — display name, location, photos, about text, and the profile answers you give, including your gender and who you are looking for, your religious observance, marital status, children, smoking and drinking habits, and immigration status — plus your private date of birth, used only to confirm age eligibility and calculate the age shown on your profile. Your date of birth is never displayed.
Activity: likes, matches, and messages you exchange — required to provide those features. When you file a safety report, we capture a limited filing-time copy of the reported profile, up to 50 messages between the two accounts, and up to 6 profile photos so deletion cannot erase an open case. If you contact support, we store the ticket, its email address, and the messages exchanged so you and support can continue the conversation.
Billing: if you buy a membership, we receive from the payment processor or app store which plan you bought, when it starts, renews or ends, and a reference for the subscription. We never see or store card numbers. Redeeming a gift code gives us only the code.
Technical: a session cookie, a language-preference cookie, a short-lived cookie used only while signing in with Google, and minimal server logs for security and abuse prevention. If you explicitly enable push notifications, we store an encrypted browser subscription or device token, a one-way identifier used to update or revoke it, your notification language, and delivery-failure timestamps. When an error occurs, the mobile app sends a privacy-minimized crash report to Sentry. It contains the exception, stack trace, app version, and operating-system and device context needed to diagnose the failure; it excludes account identity, request data, screenshots, and interaction history. Performance tracing is disabled. We do not run third-party advertising or tracking scripts.
3. How we use data
To operate your account, show and match profiles, deliver chat, verify members, prevent abuse, provide support, and send the account, optional email, and explicitly enabled push notifications described below.
Push notifications are off for a device until you turn them on there and grant the operating-system or browser permission. Push and email are separate choices. You can choose interest, message, and match alerts independently, and you can disable the device subscription in Settings. Visible lock-screen copy is deliberately generic and contains no member name, photo, message text, or reference to dating.
Like and message notifications are on by default, limited to one short email per day per type, and can be switched off in Settings. The discovery digest is off by default and is sent at most weekly after explicit opt-in, only when a newly completed profile is currently visible and relevant under saved gender and location preferences. It contains no candidate identity, photo, city, or count. Registration and the first onboarding step offer a separate unchecked choice for up to two setup reminders; Google registration does not enable it automatically. The first reminder follows 24 hours of inactivity and, only if you have not returned, one final reminder follows 72 hours later; the campaign stops after 14 days, completion, return, opt-out, suspension, or two claimed sends. We record each opt-in time, source, and copy version. Every promotional email has a topic-specific one-click unsubscribe; delivery uses the transactional email provider described under Sharing. Operational emails, such as photo or identity-verification decisions and support replies, are sent only to a verified account address and cannot be disabled because they explain an action taken on your account.
4. What we deliberately do not do
We do not sell or rent personal data, share it with advertisers, or put a member name, photo, city, match, conversation, or event type in an activity-email subject or inbox preview. Other email is limited to account operations, moderation outcomes, support replies, and actions you requested such as a password reset.
5. Photos and verification evidence
Uploaded photos are stripped of EXIF metadata (including location) and processed before storage. Before human review, automated checks may look for a clearly identifiable main face and other detected faces, unsafe content, contact details, duplicate uploads, and public-web image matches. Objective failures can be returned immediately so you can choose another photo; uncertain signals are shown only to the reviewer and never publish a photo automatically. We retain only bounded result codes and image hashes used to detect reuse, not OCR text, matching URLs, provider payloads, or a face template. You choose a separate audience for each photo: members eligible to see your profile, people you liked, matches, or verified members. Gold and Platinum never override that choice. Anyone outside the selected audience receives a generic locked placeholder; the real image bytes and identifier are not sent to their browser. Photos are served through an authorization layer, not as public files.
Selfie/ID verification evidence is deleted permanently immediately after the review decision is recorded — regardless of the outcome.
6. Sharing
We share data only with service providers strictly necessary to operate — hosting, transactional email, push delivery, image safety screening, crash reporting, and payment processing — under contract and limited to their function, or when compelled by valid legal process. When automated public-photo screening is enabled, the normalized photo is sent to Google Cloud Vision solely for face, content, text, and public-web-match analysis; its raw response is not retained by Ashegham. Android push delivery uses Firebase Cloud Messaging; installed-web-app delivery uses the browser's push service. They receive the technical delivery token and generic alert needed to reach your device, not a member name, photo, message text, or dating-specific lock-screen copy. Privacy-minimized mobile crash reports go to Sentry, our error-monitoring provider, with the limits described above. Card payments are taken by Stripe through a hosted checkout page operated for us by a payment partner; they receive your email address and plan choice so the purchase can be tied to your account, and we never see your card details. Purchases made in the app go through Google Play or the App Store and our subscription service, RevenueCat, which receive an anonymous account identifier and the purchase details. If we are ever lawfully compelled to disclose data, we will notify affected members unless legally prohibited.
7. Retention and deletion
Your data is kept while your account is active. Deleting your account from Settings removes your live profile, photos, matches, and messages from the service. Limited evidence already attached to a safety report is available only to moderators while the report is open and for up to 90 days after a decision, then its text and photo copies are purged. Support tickets are retained while needed to answer the request, maintain service records, or meet legal and safety obligations. Privacy-minimized crash reports are kept for the retention period configured in our Sentry project and are automatically deleted at the end of that period. Backups are kept for about two weeks and then deleted, so other copies disappear from them within that window. An administrative log keeps an anonymous record of moderation decisions and sensitive administrative access — the action and an internal reference — after an account is deleted.
Password-reset records expire after one hour and are single-use.
8. Security
Traffic is encrypted in transit (TLS). Passwords are hashed with Argon2. Photo and verification files live outside the web root behind per-object authorization. Administrators see conversation metadata by default; opening message content requires a written safety, moderation, or support reason, creates an immutable audit entry, and grants access for 15 minutes. Administrative actions are logged.
9. Your rights
You can access and correct your data from Settings, control visibility (hidden profile, hide from your own country, and a separate audience for each photo), manage ongoing email preferences, stop setup reminders from their one-click link, and delete your account at any time without contacting us. For anything else: [email protected].
10. Cookies
We set one session cookie (sign-in), one locale cookie (language), and one short-lived cookie that protects Google sign-in against forgery. No advertising or analytics cookies are used.
11. Contact
Privacy questions and requests: [email protected].