Privacy Policy
This policy explains what personal data Crushly collects, why, who can see it, how long it is kept and the choices you have. It describes what the service does today. If that changes, we publish a new version here and ask members to read and accept it in the app.
Who we are
Crushly is a dating service for adults in India, available as a mobile app and at https://crushly.in.
- Operator (the entity responsible for your data): NioDelta Web Studio
- Address: Nasik, Maharashtra, India
- Privacy and support contact: hello@crushly.in
- Grievance officer: see Grievance officer
Adults only
Crushly is for people aged 18 and over. We do not knowingly collect data from anyone younger. You give your date of birth when you sign up, and an account found to belong to someone under 18 is suspended and removed. See Child Safety Standards.
What we collect
Account
- Your phone number, which is how you sign in
- An email address, only if you choose to add one for account recovery
- Your date of birth, to confirm you are 18 or over and to show your age on your profile
Profile — what you choose to tell other members
- Name, gender, a short bio, city and state
- Occupation, education, height, what you are looking for, languages, interests and answers to prompts
- Your discovery preferences, such as who you would like to see
- Up to 6 photos. Photos are re-encoded when they arrive, which removes embedded metadata such as the camera model and GPS position
- An approximate location, only if you allow it. Coordinates are rounded to about 1 km before they are stored; the precise position is not kept
Verification
- A selfie that a member of our team compares with your profile photos. It is deleted as soon as you are approved. If it is not approved it is kept for 30 days so that you can ask us to look again, and then deleted
Activity
- Who you liked or passed, any note you attached to a like, and your matches
- Messages you send and receive in conversations
- Date plans you create or accept: time, venue and any address you add
- Trusted contacts you add (their name and phone number), which date plans you chose to share with them, your check-in answers, and private feedback you leave after a date
- Reports and blocks you make, appeals, and conversations with our support team
- Your notification settings
Device and technical data
- Device name, platform (Android or iOS) and app version for each device you sign in on
- A push-notification token if you allow notifications. Push delivery through a third-party provider is not switched on today; we will update this policy before it is
- Your IP address, recorded when you accept a policy and with security-relevant actions on your account, and held in routine web-server logs
- A minimal error log: which part of the service failed and the status code, without the content of your request
We do not read your contacts, your photo library beyond the pictures you pick, or your SMS messages.
How we use it
- To create your account and sign you in with a one-time code
- To show your profile to other members and theirs to you, and to run matching, conversations and date plans
- To review photos, profile text and verification selfies, and to act on reports — this is how we enforce the Community Guidelines
- To send check-in reminders for dates you confirmed and notices about your account
- To answer support requests and handle appeals, privacy requests and deletion
- To keep a record of enforcement decisions so that banned accounts cannot simply return
- To meet legal obligations and respond to lawful requests from authorities
We do not use your data for advertising, we do not build advertising profiles, and we do not sell personal data. Discovery shows you a small daily set of profiles that fit the preferences you set; there is no hidden compatibility score.
Who can see your information
Other members see your profile: name, age, photos that have passed review, bio, city, and the profile details you filled in. They never see your phone number, email address, date of birth or exact location. Only people you have matched with can hold a conversation with you; someone who likes you can attach a short note to that like. Members you block cannot find or contact you, and you cannot be found by them.
Our team. Access is limited by role, and sensitive actions are logged. Staff do not browse conversations. Messages can be read by an authorised safety reviewer only when they are part of a report under review, and the reviewer must record a reason; every such access is logged. Verification selfies are visible only to verification reviewers, and each view is logged. Contact details are masked in staff screens by default.
A trusted contact you choose. If you share a date plan, we send that person a text message with your first name, the time, and the venue name and area — not the full address. This happens only when you ask for it.
Who we share data with
- MSG91, our SMS provider. Your phone number is sent to MSG91 so that it can deliver and verify your one-time sign-in code. If you share a date plan with a trusted contact, their number and the message are sent through our SMS provider for delivery.
- Our hosting provider, which runs the servers where the service and its database are stored.
- Authorities, where the law requires it or where we report suspected child sexual abuse material or a credible threat to someone's safety.
That is the complete list today. The app contains no advertising SDKs and no third-party analytics SDKs.
How we protect it
- Connections to the service use HTTPS
- Message text, messages to support, trusted-contact names and numbers, date-plan addresses and private post-date notes are encrypted in the database with a key held by the application
- Photos sit in private storage and are shown through links that expire after 10 minutes
- Staff accounts have role-based permissions; the most privileged roles must use two-step sign-in, and staff actions are written to an audit log
No system is perfectly secure. If you think your account has been accessed by someone else, contact hello@crushly.in.
How long we keep it
| Data | Kept for |
|---|---|
| Your account, profile, photos, likes, matches and messages | Until you delete your account |
| Messages with someone you unmatched | 90 days after the unmatch, unless they are evidence in a report |
| Verification selfie | Deleted on approval; 30 days if not approved |
| One-time code records | 1 day |
| Notification delivery logs | 90 days |
| Error log | 30 days |
| Staff audit log | 730 days |
| Backups | Expire within 30 days |
When you delete your account, your profile is hidden straight away and your data is permanently deleted 14 days later. The full list of what is removed and the limited records we keep is on the account deletion page. In short, we keep:
- Messages or photos that are evidence in an open safety report, until the case is closed and 180 days have passed
- The record of moderation decisions, reports and cases about an account
- For accounts that were banned, or suspended when they were deleted, a one-way keyed hash of the phone number and email so the same person cannot re-register to escape the decision. The number itself is not kept
- A deletion record: a reference, the dates and a count of what was removed
- An empty placeholder for the account, with no phone number, email, date of birth or profile
Your choices
- See and correct your profile, photos and preferences in the app at any time
- Pause your profile so that you are not shown in discovery
- Control notifications in settings
- Block or report any member
- Remove trusted contacts and sign out other devices
- Ask for a copy of your data or raise another privacy request in the app under Settings, or by email. A member of our team handles these requests by hand, so they are not instant
- Delete your account in the app, or on the web without the app
- Withdraw consent. Because the service cannot run without the data described here, withdrawing consent means deleting your account
Depending on where you live, data-protection law — in India, the Digital Personal Data Protection Act, 2023 — may give you further rights, including the right to complain to a regulator. You can raise a complaint with our grievance officer first.
This website
https://crushly.in sets only the cookies needed for it to work: a session cookie and a security token that protects forms such as account deletion. It carries no advertising trackers and no third-party analytics. The account-deletion page may load the phone-verification widget of our SMS provider, MSG91, when you ask to verify your number there.
Changes to this policy
When we change this policy we publish a new numbered version on this page. Members are asked to read and accept the new version in the app before they continue.
Contact
Questions about this policy or your data: hello@crushly.in. Complaints: Grievance officer.
Questions about this page? See Contact and support.