Privacy Policy
DRAFT — must be reviewed by a qualified EU/Netherlands privacy lawyer before publication. This covers the specific, unusual processing Eayni does (religious data, reviewer grading, guardian access, AI photo-blurring) so the lawyer has a complete, accurate starting point rather than a generic template.
1. Who we are
Eayni is a verification-first matrimonial app for Muslims seeking marriage, operated by Eayni, Ru Parelaan 199, 3527 LJ Utrecht, Netherlands, registered with the Dutch Chamber of Commerce under number 42136139. We are the data controller for the personal data described below.
How your account is created — anonymous sign-in
Your account is created through an anonymous sign-in: on first launch the app is issued its own authenticated identity by our authentication provider, without a password and without any other recoverable credential. Everything else described in this policy is attached to that identity. Because there is no password to recover, signing out or deleting your account permanently ends that identity — it cannot be restored afterwards, by you or by us. Your phone number is verified separately and does not on its own restore access to an ended account.
2. What we collect and why
| Data | Purpose | Legal basis (GDPR) |
|---|---|---|
| Phone number | Account sign-in, one bot/duplicate account per person | Contract (Art. 6(1)(b)) |
| Name, birthday, gender | Your profile; age eligibility (18+) | Contract |
| City / location | Matching by location preference | Contract |
| Photos + AI-blurred copies | Your profile; the blurred set is what other members see | Contract; explicit consent for the biometric-adjacent processing of your image |
| Religious data — sect, practice level, prayer frequency, lifestyle | The core of compatibility matching | Explicit consent (Art. 9(2)(a)) — see §4 |
| Education, work, languages, lifestyle answers | Compatibility matching | Contract |
| Reviewer grades (appearance, and objective factors) | Quality review; balanced ("parity") match suggestions | Legitimate interest (Art. 6(1)(f)) + explicit consent where derived from special-category inputs — see §5 |
| Swipes, matches, messages | Providing the matchmaking + chat service | Contract |
| Device / usage / crash data | Security, reliability, product analytics | Crash reporting: legitimate interest (Art. 6(1)(f)). Usage analytics: consent (Art. 6(1)(a)) — off by default, opt in via Settings → Privacy → "Share usage data" |
We do not sell personal data, and we do not use it for advertising.
3. Marriage intent & orientation
Eayni is a service for people seeking marriage. Using the app implies an interest that could indicate sexual orientation, which is special-category data. We process it only as inherent to providing the service you actively signed up for, under your explicit consent (§4), and never infer or share it beyond that.
4. Religious & sensitive data — explicit consent
Sect, level of practice, prayer habits and similar are special category data under GDPR Art. 9. We ask for these only to find compatible matches, we request your explicit, separate, opt-in consent at the point you provide them, and you can decline any field. You may withdraw consent at any time (Settings → account), which removes the data from matching. Withdrawing does not affect processing done before withdrawal.
5. Reviewer grading — how it works and your rights
Before a profile enters matching, trained reviewers verify photos and record grades. Objective factors (age, height, income band, education) are computed from your own answers. Any appearance grade is a human quality-review signal. Grades are used only to suggest balanced introductions (pairing profiles of comparable standing) — never shown to you or other members, never sold. Because a grade is a form of profiling, you have the right to (a) access your grades, (b) contest them, and (c) request human re-review. Open point for the reviewing lawyer: confirm whether this constitutes automated decision-making with legal or similarly significant effect under Art. 22 GDPR. The current design keeps a human in the loop and grades only rank suggestions — they exclude nobody — but that reasoning needs to be documented and confirmed.
6. Guardian (mahram) access
You may generate a family code that lets a guardian see milestones and activity only (e.g. "matched", "45-minute call", verification status) — never the contents of your private messages. You choose to share it and can revoke it at any time in your profile. The guardian is a separate account; we process their name and the fact of the link.
7. Photos & AI blurring
For female members, an automated service creates a copy of each photo with the person softly blurred; that blurred set is what other members see, while the original is retained for reviewer verification. Photos are stored in access- controlled storage; only you, matched members (blurred set), and reviewers can access them per strict rules.
8. Who we share data with (processors)
- Supabase (database, storage, authentication) — hosted in the European Union; DPA in place. No transfer outside the EEA takes place for this processor.
- SMS verification codes — Open point: not yet confirmed whether verification messages are sent through Twilio or through Supabase phone authentication. Which of the two it is determines who appears in this processor list and which transfer safeguards apply.
- Analytics and crash reporting Open point: the specific provider is not yet fixed. — usage analytics collection is off by default and starts only if you opt in via Settings → Privacy → "Share usage data" (which you can switch off again at any time). Crash reporting runs under legitimate interest. There is no first-launch consent pop-up.
- Reviewers — contracted, bound by confidentiality; access via role-based rules.
All processors are bound by data-processing agreements. Our database, storage and authentication run inside the EU. Any transfer outside the EEA would rely on adequacy decisions or standard contractual clauses to be confirmed for the SMS provider once that route is settled.
9. Retention
- Active account: for as long as your account exists.
- After deletion: deleting your account from Settings runs a single server-side operation that can only ever act on your own account. It removes your photos from storage — both the originals and the AI-blurred copies — and any voice memos from your conversations, and then deletes the account itself, which cascades through your profile, your swipes, your matches, the messages inside those matches, your daily introductions and your reviewer grade. Nothing of yours is left behind by design. Residual copies in encrypted backups age out within 30 days — to be confirmed against the actual backup retention. We keep only what we must for legal or safety reasons, such as abuse reports.
- Verification codes and transient logs: short-lived.
10. Your rights (GDPR)
Access, rectification, erasure ("right to be forgotten"), restriction, portability, objection, and withdrawal of consent — exercise any via privacy@eayniapp.com or in-app account settings; we respond within one month. You can also complain to the Dutch DPA (Autoriteit Persoonsgegevens).
11. Children
Eayni is strictly 18+. We do not knowingly process data of anyone under 18 and remove such accounts on discovery.
12. Security
Encrypted transport (HTTPS only), row-level access controls so members can only reach their own data, verified-only photo pool, and PII kept out of logs. No system is perfectly secure; we notify you and the DPA of qualifying breaches as required.
13. Changes
We will notify you in-app of material changes to this policy.
14. The waitlist on this website
Everything above describes the Eayni app. This section describes the separate processing that happens on eayniapp.com itself, before the app exists for you.
What the waitlist form collects
If you fill in the form at eayniapp.com/join, we store: your first name, email address, phone number (optional), gender, year of birth, city and country, a free-text note, and the answers you gave about education, work, languages, lifestyle and partner age preference. This is stored in a waitlist table separate from any app account.
Legal basis: your consent (Art. 6(1)(a) GDPR), given by ticking the box on the form. You can withdraw it at any time by writing to privacy@eayniapp.com, and we will delete the entry.
Purpose: to tell you when Eayni opens in your city, and to have your profile partly prepared so you do not start from an empty screen. We do not use it for anything else, we do not sell it, and it is not a newsletter list.
Faith answers on the waitlist
The form asks about sect and prayer habits. These are special category data (Art. 9 GDPR), so they sit behind their own separate tick box. If you leave that box unticked, those answers are discarded in your browser and never sent to us — the rest of the form still works. Where you do tick it, the legal basis is your explicit consent (Art. 9(2)(a)), and §4 applies to those answers in the same way.
Your wali’s name
The form optionally asks for the first name of your wali and his relationship to you. That is personal data about someone other than you, and they have rights over it even though they did not fill in the form. We therefore keep it to a first name and a relationship, use it only to prepare your profile, never contact that person on the basis of it, and delete it together with the rest of your entry. Open point for the reviewing lawyer: whether Art. 14 GDPR requires us to inform the wali directly, or whether the Art. 14(5)(b) disproportionate-effort exemption applies given that we hold only a first name. Please tell the person you name that you have done so.
Retention
Waitlist entries are kept until Eayni opens in your city and you have either created an account or told us you are no longer interested, and in any case no longer than 18 months from submission — to be confirmed. If Eayni does not launch, we delete the whole table and tell everyone on it that we have done so.
Cookies and tracking on this website
This website sets no cookies, contains no analytics, advertising or social-media trackers, and does not profile visitors. Nothing is loaded from a third-party domain except when you submit the waitlist form, at which point your entry is sent directly to our database provider. Because of that, there is no cookie banner and no consent to manage — the only data we hold about a visitor is what that visitor chose to type into the form. The separate, opt-in analytics described in §8 concern the app, not this site.
15. Open points to settle before publication
These are deliberately left open rather than guessed at. Each one changes what this policy must say.
FOR THE REVIEWING LAWYER AND FOR US
- Supabase region. Where the project actually runs. If it is outside the EEA, §8 must name the transfer and its safeguard under Art. 44–49 GDPR.
- SMS route. Whether verification codes go through Twilio or through Supabase phone authentication. This determines the processor list in §8.
- Data Protection Officer. Whether Art. 37 GDPR requires one, given the scale of special-category processing described in §4 and §5. See the DPIA.
- Analytics and crash vendor. The specific provider has not been fixed; §8 names the category only.
- Retention window. The 30-day figure in §9 must be checked against what the deletion routine and the backup rotation actually do.
- Art. 14 GDPR and the wali. Whether naming a third party on the waitlist form (§14) triggers a duty to inform that person directly.
- Waitlist retention. The 18-month ceiling in §14 needs a decision and a job that enforces it.
- Art. 22 GDPR. Whether reviewer grading (§5) amounts to automated decision-making with legal or similarly significant effect. The current design keeps a human in the loop and grades only rank suggestions — they exclude nobody — but this needs to be documented and confirmed.