Legal & Trust Center

Data Protection Policy

This policy is a factual description of the data FyndMe actually holds, where it lives, who processes it, how long it is kept and what happens when you delete your account.

Version 2.0 — effective 17 August 2026

Adults only — 18+

FyndMe is an adults-only social and relationship discovery service. You must be 18 or older (or the legal age of majority where you live, if higher) to create an account or use any part of the platform. Accounts suspected of belonging to a minor are removed immediately.

FyndMe supports discreet discovery, companionship and mutually understood relationships between consenting adults. It is not an escort, prostitution or paid-companionship service, and pornographic content, sexual services for payment, trafficking and any sexualisation of minors are prohibited without exception. See the Member Rules and Child Safety Standards.

Plain-language summary. This document is maintained alongside product changes by Neuro Blend INC and is written to be readable. It should be reviewed periodically by qualified legal counsel.

Principles

  • Collect only what the service genuinely needs.
  • Keep public profile information separate from private account information.
  • Restrict access at the database level so members can only reach their own private data.
  • Describe only what the software actually does — no aspirational claims.

What we hold, and why

DataWhy we hold itWho can see it
Account identity — email and sign-in identifier from Google or AppleAuthentication and account recoveryYou and authorised staff only. Never shown to members.
Date of birthEnforcing the 18+ requirementYou and authorised staff only. Members see a derived age.
Profile — alias, age, gender, area, bio, interests, preferences, connection modesRunning discovery, matching and profilesMembers, subject to your visibility settings.
Public album photosYour profileMembers who can see your profile, through short-lived signed links.
Private album photosContent you deliberately keep behind approvalOnly members whose access request you approved, plus authorised staff during a report review.
Interactions — likes, favourites, connection requests, profile views, blocksOperating the features themselvesOnly as the feature shows it. Favourites are private to you.
Messages, attachments and reactionsOne-to-one conversations between connected membersYou and the other member. Not scanned in the background; reviewed only when reported.
Verification submissionsConfirming a member is a real personAuthorised staff reviewers only.
Reports, moderation actions, appealsTrust and safety enforcementAuthorised staff only. Reporter identity is not shown to the reported member.
Payment requests, UPI payment proof images, transactions, membership stateActivating and accounting for PremiumYou and authorised payment reviewers.
Push device registrationsDelivering notifications you enabledSystem only.
Security and abuse eventsRate limiting, fraud and abuse preventionSystem and authorised staff.
Product analytics eventsUnderstanding which features are usedAggregate only. Stored without your identity once the account is deleted.
Administrative audit recordsAccountability for staff actionsAuthorised staff only.

FyndMe does not collect GPS or precise device location. Location is limited to the city or area you type into your profile.

Where the data is processed

ProviderWhat it handlesRegion
Supabase (managed through Lovable Cloud)Database, authentication, file storage, scheduled jobsAWS ap-northeast-1 (Tokyo)
Lovable (application hosting and delivery)Serving the web application and server functionsEdge network — specific point of presence varies by visitor
Cloudflare TurnstileBot and abuse checks on sensitive actionsCloudflare global network
Lovable AI GatewayOptional AI features (profile tips, icebreakers, recommendations) and content moderation checksProvider network — region not independently verified
Google Analytics 4Aggregate product measurement — only after you allow analytics storageGoogle network
Web push services (Apple, Google, Mozilla) via your browserDelivering push notifications you enabledDetermined by your browser vendor

Contractual terms with these providers are governed by their standard agreements. FyndMe does not claim any additional bespoke safeguard that has not been signed, and international transfer positions are subject to review by qualified counsel.

The Velyra boutique is a separate Shopify storefront. FyndMe reads its public product catalogue on the server side and sends no member identity, email, profile or browsing data to Shopify. If you buy something on Velyra, that purchase is handled entirely under Velyra's own terms and privacy notice.

How long we keep it

DataRetentionHow it ends
Account, profile, photos, preferencesWhile your account existsDeleted when you delete your account
Messages and attachmentsWhile the conversation existsDeleted when either participant deletes their account
Likes, favourites, connections, profile viewsWhile your account existsDeleted with the account
AI personalisation signals45 daysAutomatic nightly purge job
AI operational usage logs7 daysAutomatic nightly purge job; detached from you on deletion
Security and abuse events30 daysAutomatic nightly purge job
Verification submissionsUntil the account is deletedDeleted with the account, including the uploaded photo
UPI payment proof imagesUntil the account is deletedDeleted with the account
Payment transaction recordsRetained for accounting purposes after deletionKept without your profile link — no name, alias, email or photo
Staff audit records and safety reportsRetained for accountabilityReporter and reported profile links are cleared on deletion
Product analytics eventsRetention period not yet fixedIdentity link removed on deletion; a fixed period is a pending business decision

Deleting your account

Settings → Delete account permanently runs a single server-side routine. In one transaction it removes your profile, all profile and private album photos and their stored files, your conversations with their messages, attachments and media, likes, favourites, connections, profile views, blocks, private album permissions, notifications and preferences, push devices, privacy settings, verification records and photos, AI data, payment requests and uploaded payment proofs, and your membership.

Two things are deliberately not destroyed: payment transaction records, which are kept for accounting but detached from you, and staff audit and safety records, which keep the fact that an action happened without keeping your profile link. Copies may persist briefly in encrypted infrastructure backups until those backups roll over.

Deactivation is different: it hides you from discovery and keeps your data so you can return. Use deletion if you want the data gone.

Security measures

  • Encrypted transport (HTTPS) for all traffic.
  • Row-level access rules on every table holding member data.
  • All five storage buckets are private; files are served only through short-lived signed links.
  • Private albums are released only after the owner approves an access request, and can be revoked.
  • Staff functions require an explicit staff role and write to an audit log.
  • Bot and abuse checks on sensitive actions, plus per-account interaction limits.

Your requests

  • Access a copy of your data — email support@nblendinc.com from your account email. A self-service export is not built yet; requests are handled manually.
  • Correct your information — edit your profile, preferences and photos directly in the app. For account email or date of birth, contact support.
  • Delete your data — Settings → Delete account permanently.
  • Withdraw optional consent — Privacy Center → Cookies & consent, and the AI assistance toggles.
  • Raise a grievance — see Contact.

We verify that a request comes from the account holder before acting on it, and we will not disclose personal data to an unverified requester.

If something goes wrong

Our incident process is: detect, contain, investigate, assess what data was involved, remediate, and then notify affected members and any authority we are legally required to notify. We do not publish a guaranteed notification deadline, because the applicable timelines depend on the incident and on provisions whose commencement is still being confirmed with counsel.

Status of this document

This policy describes implemented behaviour that has been checked against the running application and database. It is not a legal opinion and it is not a claim of compliance with any particular statute. It remains subject to review by qualified Indian legal and privacy counsel.