Privacy Policy

Effective date: 16 August 2026 · Last updated: 23 August 2026

This is the current Privacy Policy, in effect as of the effective date above.

This Privacy Policy explains how Nymix ("Nymix", "we", "us", or "our") collects, uses, shares, and protects your personal data when you use the Nymix mobile application and related services (the "Service"). Nymix is a dating and social-discovery application and, by its nature, processes sensitive personal data such as your photographs, facial biometric information, and approximate location. This Policy is written for users in India and is designed to comply with the Digital Personal Data Protection Act, 2023 (DPDP Act), the Information Technology Act, 2000 and its rules. If you do not agree with it, please do not use the Service.

1Who We Are (Data Fiduciary)

Nymix is owned and operated by Dharavath Durgaprasad, a sole proprietor trading as "Nymix". For the purposes of the DPDP Act, this is the Data Fiduciary that determines the purpose and means of processing your personal data.

The Service is currently offered in India only.

2Eligibility and Minimum Age

You must be at least 18 years old to create an account or use Nymix. The Service is strictly for adults. During onboarding we collect your date of birth and block registration where the calculated age is under 18. If we learn that a person under 18 has created an account, we will suspend and delete it. If you believe a minor is using the Service, contact support@getnymix.com or child-safety@getnymix.com. We do not knowingly process children's personal data; if we discover such data, we will delete it.

3Personal Data We Collect

3.1 Registration and onboarding

3.2 Photographs and facial biometric information (sensitive data)

To confirm you are a real, live person, we offer an optional face-liveness check: you record a short live selfie, compared against your profile photo using AWS Rekognition, producing facial-template data (a face vector/identifier and match score). AWS processes these images under its own service terms.

Face verification is presented during onboarding, but successfully completing it is not required for access. If verification is unsuccessful, unavailable, cancelled, permission-denied, or incomplete, onboarding continues with an unverified status; verified, pending, and unverified users have the same access. A "verified" badge means only that a live person matching the profile photo completed the check; it is not verification of legal identity or age. Your facial template and scores are stored server-side only and are never shown to other users. This is sensitive personal data, and by completing verification you give your explicit consent, which you can withdraw at any time.

3.3 Location information

3.4 Messages, media, and activity

3.5 Device, technical, and usage data

3.6 Safety, moderation, and verification data

4How We Use Your Personal Data

We do not currently offer paid features, so we do not currently process payment or purchase data. If paid features launch, we will update this Policy and describe that processing before it begins.

5Legal Basis for Processing

Under the DPDP Act we process your personal data on the basis of your consent (given when you create an account, grant permissions, complete face verification, and accept this Policy — with explicit consent for sensitive data such as facial biometrics and location) and certain legitimate uses / legal obligations permitted by law (fraud and abuse prevention, safety, child-safety obligations, and lawful requests). You may withdraw consent at any time; withdrawing consent for optional processing such as face verification or location simply turns off that feature and does not remove access to the rest of the Service.

6Permissions We Request

7Third Parties and Data Sharing

We do not sell your personal data. We share data only with service providers ("Data Processors") who help us operate the Service. The live processors are:

Service providerPurposeData sharedRegion
ConvexBackend, database, media storageAccount, profile, messages, media, activityCloud (may be outside India)
AWS — Rekognition & Face LivenessFace verification and explicit-image detectionSelfies, photos, facial templates / moderation labelsIndia (Mumbai, ap-south-1)
Cloudflare R2User video object storage (Truth or Dare, Circle, chat)Video files you upload or sendGlobal (Cloudflare edge)
AgoraReal-time audio and video callingLive call audio/video streams and call session identifiersGlobal
MSG91Phone OTP verificationYour phone number (OTP held by MSG91, not stored by us)India
SentryCrash and error diagnosticsDiagnostics with sensitive fields scrubbedUnited States / global
PostHogProduct analytics (when enabled)Sanitised usage events, pseudonymous identifierUnited States
Resend / SendGridTransactional emailRecipient email, subject, message bodyUnited States
Expo / APNs / FCMPush-notification deliveryPush tokens and notification contentUnited States / global
Google Sign-InOptional social loginGoogle identifier, email, nameGlobal
Apple Sign-InOptional social loginApple identifier, email, nameGlobal
OpenStreetMap / NominatimReverse-geocode coordinates to a cityYour device coordinatesGlobal
Google PlacesPlace/location autocomplete (when used)Text you type and a session tokenGlobal
Talsec (freeRASP)App-integrity and tamper detection (root/jailbreak, hooking, repackaging)Device-level security signals only — threat type, integrity state, OS/build attributes. No account, message, photo or location dataGlobal (EU)

Payments (not currently enabled). Nymix does not currently sell anything or process payments, and does not operate any wallet, coin, or stored-value system. If paid features launch, billing would be handled by the Apple App Store / Google Play, and infrastructure such as RevenueCat (and, if used, Razorpay) may be engaged. These payment processors are not currently enabled; we will update this Policy before any paid feature goes live.

We may also disclose personal data to comply with law or a valid legal request, to enforce our Terms, to protect users and the public — including preserving evidence and reporting child-safety matters to the relevant Indian authorities as required by law — and in connection with a business transfer, subject to this Policy.

8Where Your Data Is Processed (Cross-Border Transfers)

Your data is processed both in India and in the United States, and may be processed elsewhere by the providers above:

Where data is transferred outside India, we take reasonable steps consistent with the DPDP Act and applicable law, and we do not transfer personal data to any country restricted by the Government of India.

9Data Retention and Deletion

For full details on deletion, see our Delete Account page.

10Your Rights

Subject to the DPDP Act, you have the right to: access a machine-readable copy of your account data via Settings → Account → Request My Data (your profile, content you created, and related account history — not other people’s identities, biometric templates, authentication secrets, CSAM/NCII case files, or signed media URLs); correct, complete, or update it; erase it (by deleting your account); withdraw consent at any time, as easily as you gave it — including for face verification and location; grievance redressal (Section 13); and nominate another individual to exercise your rights in the event of death or incapacity.

To exercise any right, email support@getnymix.com or use the in-app controls. We may need to confirm who you are before acting on a request, and we respond within the timelines required by law. You may also lodge a complaint with the Data Protection Board of India.

11Security

Important: Messages and most content are stored on our backend (Convex) and are not end-to-end encrypted — we can access content where necessary to run moderation and safety systems and to comply with law. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

12Data-Breach Notification

If a personal-data breach occurs, we will notify affected users and the Data Protection Board of India in accordance with the DPDP Act and its rules, including a description of the breach, the data affected, and steps you can take to protect yourself.

13Grievance Officer / Grievance Redressal

In accordance with the Information Technology Act, 2000, the Intermediary Guidelines and Digital Media Ethics Code Rules, 2021, and the DPDP Act, you may direct any grievance about the processing of your personal data to our Grievance Officer:

Grievance Officer: Dharavath Durgaprasad (Proprietor)

Email: grievance@getnymix.com

Address: Mahabubabad, Telangana, India

Online: getnymix.com/grievance.html

We will acknowledge your grievance within 24 hours of receipt and endeavour to resolve it within 7 days, or within the timelines otherwise prescribed by law.

14Changes to This Policy

We may update this Privacy Policy from time to time. When we make material changes we will update the "Last updated" date above and, where appropriate, notify you within the app and ask you to re-accept. Your continued use of the Service after changes take effect constitutes acceptance of the updated Policy.

15Contact Us

Nymix (Dharavath Durgaprasad, sole proprietor)

Mahabubabad, Telangana, India

Privacy / support: support@getnymix.com · Grievance: grievance@getnymix.com · Child safety: child-safety@getnymix.com

Website: getnymix.com