Effective 2026-09-01. Version 2026-09-01. This version is scheduled for attorney review; any changes will be posted at /privacy-changes.
Pyaar Milan Limited Liability Company ("PyaarMilan", "we", "us") operates a private, application-based matchmaking service for South Asian singles in the United States. This policy explains what we collect, why, who can see it, how long we keep it, and how to exercise your rights. It is written to be read, not skimmed: the tables below are generated directly from our data map, so what you read here is what the code actually does.
Pyaar Milan Limited Liability Company, a Wyoming limited liability company.
Postal address: 30 N Gould St, Sheridan, WY 82801.
Privacy contact: team@pyaarmilan.com (reaches our Founder, who owns privacy decisions).
Safety contact: team@pyaarmilan.com. Security reports: team@pyaarmilan.com (see /.well-known/security.txt).
We currently offer PyaarMilan to people in the United States. If you are outside the US, please do not apply; you can leave your email on the decline page and we will tell you if we open where you live. We do not target the service to the EU or UK.
Everything we collect is listed below. "Matchmaker" means the person on our team reviewing applications and making introductions. A match sees only the introduction fields, and your contact details are shared only after you both say yes, exactly as described in section 7.
| Field | Purpose | Who can see it | How long we keep it | Where it lives |
|---|---|---|---|---|
| name | Address you; a match sees your first name in the introduction | matchmaker, match (before yes) | While your application or membership is active; purged within 30 days of deletion | Supabase |
| Account contact, verification, receipts | matchmaker | While your application or membership is active; purged within 30 days of deletion | Supabase | |
| phone | Verification, introductions by text; released to a match only after mutual yes | matchmaker, match (after mutual yes) | While your application or membership is active; purged within 30 days of deletion | Supabase |
| dob | Age eligibility (18+) and age shown to matches; DOB itself visible only to the owner role | matchmaker | While your application or membership is active; purged within 30 days of deletion | Supabase |
| age | Computed from DOB; a match sees it in the introduction | matchmaker, match (before yes) | While your application or membership is active; purged within 30 days of deletion | Supabase |
| gender | Matching | matchmaker | While your application or membership is active; purged within 30 days of deletion | Supabase |
| seeking | Who you want introductions to | matchmaker | While your application or membership is active; purged within 30 days of deletion | Supabase |
| pronouns (optional) | Respectful address | matchmaker | While your application or membership is active; purged within 30 days of deletion | Supabase |
| height (optional) | Matching preference some members care about | matchmaker | While your application or membership is active; purged within 30 days of deletion | Supabase |
| location | Metro matching | matchmaker | While your application or membership is active; purged within 30 days of deletion | Supabase |
| city | Derived from location | matchmaker | While your application or membership is active; purged within 30 days of deletion | Supabase |
| community | Cultural-background matching; "prefer not to say" offered; a match sees it in the introduction | matchmaker, match (before yes) | While your application or membership is active; purged within 30 days of deletion | Supabase |
| religion | Faith matching; "prefer not to say" offered | matchmaker | While your application or membership is active; purged within 30 days of deletion | Supabase |
| hindu_subsect (optional) | Faith detail when religion is Hindu | matchmaker | While your application or membership is active; purged within 30 days of deletion | Supabase |
| religiosity | Practice-level matching | matchmaker | While your application or membership is active; purged within 30 days of deletion | Supabase |
| raised_in (optional) | Cultural context | matchmaker | While your application or membership is active; purged within 30 days of deletion | Supabase |
| education (optional) | Matching | matchmaker | While your application or membership is active; purged within 30 days of deletion | Supabase |
| profession (optional) | Matching | matchmaker | While your application or membership is active; purged within 30 days of deletion | Supabase |
| diet (optional) | Lifestyle matching | matchmaker | While your application or membership is active; purged within 30 days of deletion | Supabase |
| intention | Relationship intent matching | matchmaker | While your application or membership is active; purged within 30 days of deletion | Supabase |
| timeline | Relationship timeline matching | matchmaker | While your application or membership is active; purged within 30 days of deletion | Supabase |
| instagram (optional) | Helps our team confirm you are who you say you are; shown to a match only if you reply CHANGE INSTAGRAM after a mutual yes | matchmaker, match (after mutual yes) | While your application or membership is active; purged within 30 days of deletion | Supabase |
| linkedin (optional) | Same identity-confidence purpose as Instagram | matchmaker | While your application or membership is active; purged within 30 days of deletion | Supabase |
| language (optional) | Language compatibility | matchmaker | While your application or membership is active; purged within 30 days of deletion | Supabase |
| value_q1 (familyRelationship) | Narrative used by the matchmaker | matchmaker | While your application or membership is active; purged within 30 days of deletion | Supabase |
| value_q2 (goodWeek) | Narrative used by the matchmaker | matchmaker | While your application or membership is active; purged within 30 days of deletion | Supabase |
| value_q3 (hobbies) | Narrative used by the matchmaker | matchmaker | While your application or membership is active; purged within 30 days of deletion | Supabase |
| heart_desire (heartDesire) (optional) | Narrative used by the matchmaker | matchmaker | While your application or membership is active; purged within 30 days of deletion | Supabase |
| alcohol / smoking (optional) | Lifestyle compatibility | matchmaker | While your application or membership is active; purged within 30 days of deletion | Supabase |
| educationField / industry (optional) | Matching detail | matchmaker | While your application or membership is active; purged within 30 days of deletion | Supabase |
| livingSituation / longDistance (optional) | Practical compatibility | matchmaker | While your application or membership is active; purged within 30 days of deletion | Supabase |
| hinduTradition (alias of hindu_subsect) (optional) | Faith detail when religion is Hindu | matchmaker | While your application or membership is active; purged within 30 days of deletion | Supabase |
| bio | Essence answer used by the matchmaker; not part of today's introduction | matchmaker | While your application or membership is active; purged within 30 days of deletion | Supabase |
| photo_urls (photos) | Reviewed by our team; stored privately, re-encoded, metadata stripped; not part of today's introduction, and the format expands only with notice | matchmaker | Abandoned web uploads deleted within 24 hours; otherwise while active; originals never stored | Supabase (private bucket) |
| membership_tier | Everyone joining now is a founding member (server-set) | matchmaker | While your application or membership is active; purged within 30 days of deletion | Supabase |
| community_vertical | Internal product line marker | matchmaker | While your application or membership is active; purged within 30 days of deletion | Supabase |
| birth_city (legacy, optional) | No longer collected; the original purpose was dropped and the legacy column is retained only for older records | matchmaker | While your application or membership is active; purged within 30 days of deletion | Supabase |
| birth_time (legacy, optional) | No longer collected; legacy column retained for older records | matchmaker | While your application or membership is active; purged within 30 days of deletion | Supabase |
| birth_time_accuracy (legacy, optional) | No longer collected; legacy column retained for older records | matchmaker | While your application or membership is active; purged within 30 days of deletion | Supabase |
| birth-chart details (historical) (legacy, optional) | Computed by an old version of the service and never computed now; existing values are scheduled for deletion in the next data cleanup | matchmaker | While your application or membership is active; purged within 30 days of deletion | Supabase |
| firstName/lastName/fiveYearLocation/wantsChildren/ageMin/ageMax/openToBackground/partnerReligion/partnerEducation/partnerChildren (legacy, optional) | Accepted for older client compatibility; not rendered in the current form | matchmaker | While your application or membership is active; purged within 30 days of deletion | Supabase |
| confirm_18 / consent_terms / consent_sensitive (+ exact label texts, version, timestamps) | Proof of what you agreed to and when | matchmaker | Life of the account, plus billing records for 7 years as tax law requires | Supabase |
| sms_consent (+ text, timestamp, source) (optional) | Proof of text-messaging consent (A2P/TCPA) | matchmaker | While your application or membership is active; purged within 30 days of deletion | Supabase |
| analytics_consent_at / pm_consent (optional) | Your separate analytics choice | matchmaker | 180 days | Supabase |
| verification_codes (hashed identifier, hashed code, attempts, ip) | Prove you own your email; codes hashed, 10-minute expiry | matchmaker | Codes expire in 10 minutes; rows cleared within 30 days | Supabase |
| phone verification (Twilio Verify) | Prove you own your phone number | matchmaker | While your application or membership is active; purged within 30 days of deletion | Twilio |
| ip | Fraud prevention and abuse limits | matchmaker | 180 days | Supabase |
| geo_city/geo_region/geo_country/geo_isp | Approximate location from IP (ipapi.co) for fraud prevention | matchmaker | 180 days | ipapi.co |
| ua_device/ua_os/ua_browser | Device family for debugging and abuse patterns | matchmaker | 180 days | Supabase |
| referrer/utm_source/utm_medium/utm_campaign | Which marketing brought you here | matchmaker | 180 days | Supabase |
| pm_vid/pm_sid, screen, viewport, timezone, language, path, scroll, clicks, field names (never values) | First-party pseudonymous product analytics, only after the separate analytics opt-in | matchmaker | 180 days | Supabase |
| text_requests (phone, digits) | The homepage "text me an application" capture, so we can follow up with an application link | matchmaker | 180 days | Supabase |
| notify_interest (email, region) | The keep-me-posted capture and the outside-US expansion list | matchmaker | 180 days | Supabase |
| visits table (visitor_id, session_id, device family, screen, viewport, timezone, language, geo from IP, referrer, utm, path, timestamps) | The rows behind pseudonymous analytics, only after the separate opt-in | matchmaker | 180 days | Supabase |
| visits.identified_email / identified_phone / identified_name (legacy, optional) | Historical only: an old identify call linked visits to people; the call is removed and the columns are cleared by purge and retention | matchmaker | While your application or membership is active; purged within 30 days of deletion | Supabase |
| outbound_messages / inbound_messages (phone, message text) | Delivering introductions and reading your replies | matchmaker | While your application or membership is active; purged within 30 days of deletion | Apple iMessage (via a company-controlled Mac) / Twilio |
| reports (category, description, evidence) | Investigating a safety report; evidence kept as submitted under the safety exception | matchmaker | 365 days | Supabase |
| blocks | Making sure two people are never introduced again | matchmaker | Survives account deletion in pseudonymized form (documented exception) | Supabase |
| rights_requests (type, hashed identifier, receipts) | Tracking your access/correction/deletion/pause requests to completion | matchmaker | Life of the account, plus billing records for 7 years as tax law requires | Supabase |
| contact_releases (fields, notice text, consents) | Your per-match consent to release contact details | matchmaker | While your application or membership is active; purged within 30 days of deletion | Supabase |
| admin_audit_events / admin_logins | Immutable record of staff access and actions | matchmaker | 2 years | Supabase |
Fields marked legacy are no longer collected from new applicants; older records may still hold them until their retention runs out.
Religion, community, cultural background, and your narrative answers are sensitive. We process them only with the explicit consent you give at the start of the application (the checkbox that names them). You can withdraw that consent at any time by texting WITHDRAW CONSENT to our number or emailing team@pyaarmilan.com. If you withdraw, we can no longer make introductions for you; you choose whether to keep your application on hold or delete it.
We never ask for, and ask you not to include, caste, skin tone, income, immigration status, or health details. Please also keep other people out of your free-text answers: no family members' names, employers, addresses, or anything about third parties.
| Provider | What it does with your data | Region | Status |
|---|---|---|---|
| Supabase | Database and private photo storage | US | active |
| Render | Application hosting and logs | US | active |
| Cloudflare | Traffic proxy in front of our host that sees requests and IP addresses | US | active |
| Google (Gmail API) | Transactional email delivery until Resend is live | US | active |
| Resend | Transactional email delivery | US | not currently used |
| Twilio | Text messages, photo messages you send us, and phone verification codes | US | not currently used |
| Apple iMessage (via a company-controlled Mac) | Text delivery until Twilio replaces it | US | active |
| Anthropic | Drafting acknowledgements, intro cards, and match notes from your answers (no decisions are automated) | US | not currently used |
| Stripe | Billing (card data never touches us) | US | not currently used |
| Sentry | Error monitoring | US | not currently used |
| ipapi.co | Approximate location from IP address for fraud prevention and analytics | US | active |
| Google Fonts | Web fonts on public pages | US | active |
| Company-controlled backup device | Nightly backups of the database and photos, retained up to 7 months | US | active |
Rows marked "not currently used" describe providers we have contracts or plans for but are not sending data to today; this table is regenerated whenever that changes. All processing happens in the United States.
One consequence of a text-based service, stated plainly: introductions are delivered by text message. Profile details and photos we share with a match travel by text to their phone and cannot be recalled from their device.
We set no cookies before you act. The cookies and stored values we use:
We use no third-party analytics, advertising pixels, or cross-site tracking. Google Fonts loads on public pages, which means Google receives the font request (IP address and user agent).
Before a mutual yes, a match sees your first name, your age, and your community. That is the entire introduction today, exactly as the text message states it. The format will expand only with notice: any change is posted at /privacy-changes and told to members before anything new is shown.
After you both say yes: we release your first name and phone number (or the contact method you chose with CHANGE). The YES prompt tells you exactly which fields will be released and when, a reminder goes out before release with a WITHDRAW option, and you can switch the shared contact method with CHANGE. Nothing is released if either of you withdraws or blocks.
Every member and applicant in the US can access, correct, export, delete, pause, or cancel, and can opt out of texts and non-essential emails. Your rights never depend on an app or a login. The three request paths:
Identity verification is a code to the phone or email on file, nothing more. We acknowledge every request within 5 business days and complete it within 30 days (California residents: 45 days with notice where the law allows). Every completed request gets a written receipt listing anything we retained and why. If we refuse a request, we say why in writing, and you can appeal by replying within 14 days; a person who was not involved in the first decision reviews the appeal.
| What | How long |
|---|---|
| Abandoned web photo uploads | 24 hours |
| Abandoned text applications (and their photos) | 30 days |
| Declined applications | up to 12 months, so a later batch can be considered; deleted sooner on request |
| Withdrawn applications | up to 12 months; deleted sooner on request |
| Deleted accounts, purge from primary systems | within 30 days |
| Deleted data, gone from every backup copy | within 7 months (backups roll off by design) |
| Analytics visits and events | 180 days |
| Safety reports and their evidence | 365 days |
| Staff audit records | 2 years (your identity pseudonymized after deletion) |
| Billing records | 7 years, as tax law requires |
A declined or withdrawn application is kept for up to 12 months so a later batch can be considered, and is deleted sooner the moment you ask (text DELETE, use /account, or email us).
Photo lifecycle, in full: the original bytes you upload are never stored; only the re-encoded, metadata-stripped copy is kept in a private bucket. Previews use signed links that expire in minutes. Copies sent to a match by text live on their phone. Our nightly backup mirrors the bucket and the database to a company-controlled device; every backup copy expires within 7 months by design, which is why deleted data is fully gone from backups within that window. Deletion produces a written receipt. Report evidence is the one exception: it is kept as submitted for 365 days under the safety exception.
When you delete your account we remove your application, photos, messages, and analytics rows, and propagate the deletion to our processors. Pseudonymized records survive only where we have a documented reason: billing records (tax law, 7 years), safety reports and blocks (with your identifier replaced by a hash, so a blocked pairing stays blocked), fraud-prevention hashes, and staff audit entries with your identity pseudonymized. Your deletion receipt lists exactly what was retained.
The categories we collect are listed in section 3: identifiers, personal characteristics including sensitive personal information (religious and cultural details you consent to share), photos, approximate geolocation from IP, and internet activity if you opt into analytics. We do not sell personal information and we do not share it for cross-context behavioral advertising; if that characterization ever changes we will change this policy first and tell you. We use sensitive personal information only to provide the service you asked for. You can use an authorized agent for any request; we verify the agent and your identity the same way. We never discriminate for exercising a right.
In transit, everything is encrypted (TLS 1.3, HSTS). Photos live in a private bucket behind short-lived signed links. Staff access is logged. We run least-privilege database rules, an immutable staff audit trail, nightly backups, and secret scanning on every commit. No one can promise breach-proof systems, so here is our commitment instead: if a breach creates a risk to you, we will notify you and the authorities your state requires, promptly and plainly.
PyaarMilan is for adults 18 and older. We do not knowingly collect information from anyone under 18; if we learn we have, we delete it.
Material changes get 30 days' notice by email, and by text if you receive texts from us, before they take effect. Every version is listed at /privacy-changes with its effective date.
Pyaar Milan Limited Liability Company
30 N Gould St, Sheridan, WY 82801