Privacy Policy

Last updated: 21 August 2026 — draft, pending legal review

This document is a working draft prepared for review by qualified legal counsel. It is published for transparency while the service is in its early, invitation-based stage.

1. Overview

Ashegham is built privacy-first. We collect the minimum data needed to run a marriage-focused community, we never sell it, and we treat the safety of members living in Iran as a design requirement, not an afterthought.

2. What we collect

Account: your email address, hashed password (or, with Google sign-in, your Google account identifier), language, and account dates.

Profile: the information you choose to publish (display name, birth year, location, photos, about text, preferences).

Activity: likes, matches, and messages you exchange — required to provide those features.

Technical: a session cookie, a language-preference cookie, and minimal server logs for security and abuse prevention. We do not run third-party advertising or tracking scripts.

3. How we use data

To operate your account, show and match profiles, deliver chat, verify members, prevent abuse, and provide support. That is the complete list.

4. What we deliberately do not do

We do not sell or rent personal data, share it with advertisers, or send emails or notifications that reveal membership, matches, or message activity.

Activity notifications (a like or a new message) are on by default and can be switched off at any time in Settings; we send at most one short email per day per type, and subjects never reveal the nature of the activity. Other emails concern only account actions you requested (for example a password reset).

5. Photos and verification evidence

Uploaded photos are stripped of EXIF metadata (including location) and processed before storage. Photos are served through an authorization layer, not as public files.

Selfie/ID verification evidence is deleted permanently immediately after the review decision is recorded — regardless of the outcome.

6. Sharing

We share data only with service providers strictly necessary to operate (hosting, transactional email), under contract and limited to their function, or when compelled by valid legal process. If we are ever lawfully compelled to disclose data, we will notify affected members unless legally prohibited.

7. Retention and deletion

Your data is kept while your account is active. Deleting your account from Settings removes your profile, photos, matches, and messages from the live database and photo storage; copies inside encrypted backups expire within 30 days.

Password-reset records expire after one hour and are single-use.

8. Security

Traffic is encrypted in transit (TLS). Passwords are hashed with Argon2. Photo and verification files live outside the web root behind per-object authorization. Administrative actions are logged.

9. Your rights

You can access and correct your data from Settings, control visibility (hidden profile, hide from your own country), and delete your account at any time without contacting us. For anything else: [email protected].

10. Cookies

We set one session cookie (sign-in) and one locale cookie (language). No advertising or analytics cookies are used.

11. Contact

Privacy questions and requests: [email protected].