Privacy Policy
Effective date: 16 August 2026 · Last updated: 23 August 2026
This Privacy Policy explains how Nymix ("Nymix", "we", "us", or "our") collects, uses, shares, and protects your personal data when you use the Nymix mobile application and related services (the "Service"). Nymix is a dating and social-discovery application and, by its nature, processes sensitive personal data such as your photographs, facial biometric information, and approximate location. This Policy is written for users in India and is designed to comply with the Digital Personal Data Protection Act, 2023 (DPDP Act), the Information Technology Act, 2000 and its rules. If you do not agree with it, please do not use the Service.
1Who We Are (Data Fiduciary)
Nymix is owned and operated by Dharavath Durgaprasad, a sole proprietor trading as "Nymix". For the purposes of the DPDP Act, this is the Data Fiduciary that determines the purpose and means of processing your personal data.
- Operator: Dharavath Durgaprasad (sole proprietor), trading as Nymix
- Registered place of business: Mahabubabad, Telangana, India
- Privacy / support: support@getnymix.com
- Grievance Officer: Dharavath Durgaprasad — grievance@getnymix.com (Section 13)
- Child safety: child-safety@getnymix.com
- Website: getnymix.com
The Service is currently offered in India only.
2Eligibility and Minimum Age
You must be at least 18 years old to create an account or use Nymix. The Service is strictly for adults. During onboarding we collect your date of birth and block registration where the calculated age is under 18. If we learn that a person under 18 has created an account, we will suspend and delete it. If you believe a minor is using the Service, contact support@getnymix.com or child-safety@getnymix.com. We do not knowingly process children's personal data; if we discover such data, we will delete it.
3Personal Data We Collect
3.1 Registration and onboarding
- Account / contact: your phone number (verified via one-time password, or "OTP") and, if you use Google or Apple, the email and name on that account. We do not use account passwords — you sign in with a phone OTP, Google, or Apple.
- Profile details: display name, date of birth (to verify age), gender, sexual orientation and, if you provide them, LGBTQ+ identity, religion, and similar attributes.
- Profile content: photos, a short bio, lifestyle/education details, daily-routine information, and answers to prompts.
3.2 Photographs and facial biometric information (sensitive data)
To confirm you are a real, live person, we offer an optional face-liveness check: you record a short live selfie, compared against your profile photo using AWS Rekognition, producing facial-template data (a face vector/identifier and match score). AWS processes these images under its own service terms.
Face verification is presented during onboarding, but successfully completing it is not required for access. If verification is unsuccessful, unavailable, cancelled, permission-denied, or incomplete, onboarding continues with an unverified status; verified, pending, and unverified users have the same access. A "verified" badge means only that a live person matching the profile photo completed the check; it is not verification of legal identity or age. Your facial template and scores are stored server-side only and are never shown to other users. This is sensitive personal data, and by completing verification you give your explicit consent, which you can withdraw at any time.
3.3 Location information
- Approximate location. With your permission, to power Nearby and Crossed Paths.
- Precision and storage. For discovery we store your location snapped to a coarse grid of roughly 300 metres plus your city — never your exact coordinates, and never shown to other users. To label your city we send your coordinates to a geocoding provider (Section 7); we do not store the raw coordinates for discovery.
- Background location (optional). "Background Crossed Paths" runs in the background only after you explicitly enable it and can be turned off anytime in Nearby Settings. When enabled on iOS or Android, it uses battery-aware, power-efficient background mechanisms snapped to a coarse grid of roughly 300 metres to detect approximate crossings without tracking continuous movement. You can turn this off anytime. Foreground location and background location both require your explicit, versioned consent, which can be withdrawn at any time.
- Short retention. Raw samples are deleted within hours; Crossed Paths events and history within about 7–30 days.
- Privacy zones. Zones you define store precise centre coordinates visible only to you, used solely to hide your location when you are inside them. You can edit or delete them anytime.
3.4 Messages, media, and activity
- Messages and chat content (text, images, audio, video) across chats, chat rooms, Circles, and Truth or Dare.
- Interactions such as likes, matches, prompts, comments, reports, and blocks.
- Ephemeral media ("view-once" or timed) is deleted from our servers when its timer expires.
- Screenshot events on protected media may be logged and shown to the other participant.
3.5 Device, technical, and usage data
- Device identifiers and fingerprints (fraud, ban-evasion, and duplicate-account detection).
- IP address, session and login metadata (session tokens stored hashed; sign-up IP kept for security investigation only, never used to block you).
- Push notification tokens (delivery via APNs and Firebase Cloud Messaging).
- Diagnostics and crash data (via Sentry, sensitive fields scrubbed).
- Product-analytics events (via PostHog when enabled) — sanitised, pseudonymous, with content and URLs stripped.
3.6 Safety, moderation, and verification data
- Verification session data (including liveness selfies).
- Reports, strikes, behaviour flags, moderation decisions, ban records, and any appeals you submit.
4How We Use Your Personal Data
- Operate your account — registration and authentication (phone OTP, Google, Apple; optional device biometrics for local login).
- Provide core features — discovery, Nearby, Crossed Paths, matching, chats, chat rooms, Circles, and Truth or Dare.
- Verify a live person and prevent fraud — optional face-liveness verification and duplicate/ban-evasion detection.
- Keep the community safe — automated and human moderation, explicit-image and text moderation, reporting, blocking, strikes, restrictions, and bans.
- Communicate with you — transactional notifications, service messages, and support.
- Maintain, secure, and improve the Service — diagnostics, crash reporting, analytics, and abuse prevention.
- Comply with law — lawful requests, child-safety obligations, and enforcing our Terms.
We do not currently offer paid features, so we do not currently process payment or purchase data. If paid features launch, we will update this Policy and describe that processing before it begins.
5Legal Basis for Processing
Under the DPDP Act we process your personal data on the basis of your consent (given when you create an account, grant permissions, complete face verification, and accept this Policy — with explicit consent for sensitive data such as facial biometrics and location) and certain legitimate uses / legal obligations permitted by law (fraud and abuse prevention, safety, child-safety obligations, and lawful requests). You may withdraw consent at any time; withdrawing consent for optional processing such as face verification or location simply turns off that feature and does not remove access to the rest of the Service.
6Permissions We Request
- Camera — profile photos, video, and face verification.
- Photo library — to upload photos and send media.
- Microphone — voice and video messages.
- Location (while in use) — Nearby and approximate Crossed Paths.
- Location (background) — only for Background Crossed Paths, only after you explicitly enable it.
- Notifications — push delivery. Previews may appear on your lock screen; you can hide previews in device settings.
7Third Parties and Data Sharing
We do not sell your personal data. We share data only with service providers ("Data Processors") who help us operate the Service. The live processors are:
| Service provider | Purpose | Data shared | Region |
|---|---|---|---|
| Convex | Backend, database, media storage | Account, profile, messages, media, activity | Cloud (may be outside India) |
| AWS — Rekognition & Face Liveness | Face verification and explicit-image detection | Selfies, photos, facial templates / moderation labels | India (Mumbai, ap-south-1) |
| Cloudflare R2 | User video object storage (Truth or Dare, Circle, chat) | Video files you upload or send | Global (Cloudflare edge) |
| Agora | Real-time audio and video calling | Live call audio/video streams and call session identifiers | Global |
| MSG91 | Phone OTP verification | Your phone number (OTP held by MSG91, not stored by us) | India |
| Sentry | Crash and error diagnostics | Diagnostics with sensitive fields scrubbed | United States / global |
| PostHog | Product analytics (when enabled) | Sanitised usage events, pseudonymous identifier | United States |
| Resend / SendGrid | Transactional email | Recipient email, subject, message body | United States |
| Expo / APNs / FCM | Push-notification delivery | Push tokens and notification content | United States / global |
| Google Sign-In | Optional social login | Google identifier, email, name | Global |
| Apple Sign-In | Optional social login | Apple identifier, email, name | Global |
| OpenStreetMap / Nominatim | Reverse-geocode coordinates to a city | Your device coordinates | Global |
| Google Places | Place/location autocomplete (when used) | Text you type and a session token | Global |
| Talsec (freeRASP) | App-integrity and tamper detection (root/jailbreak, hooking, repackaging) | Device-level security signals only — threat type, integrity state, OS/build attributes. No account, message, photo or location data | Global (EU) |
Payments (not currently enabled). Nymix does not currently sell anything or process payments, and does not operate any wallet, coin, or stored-value system. If paid features launch, billing would be handled by the Apple App Store / Google Play, and infrastructure such as RevenueCat (and, if used, Razorpay) may be engaged. These payment processors are not currently enabled; we will update this Policy before any paid feature goes live.
We may also disclose personal data to comply with law or a valid legal request, to enforce our Terms, to protect users and the public — including preserving evidence and reporting child-safety matters to the relevant Indian authorities as required by law — and in connection with a business transfer, subject to this Policy.
8Where Your Data Is Processed (Cross-Border Transfers)
Your data is processed both in India and in the United States, and may be processed elsewhere by the providers above:
- In India: AWS Rekognition face processing (Mumbai / ap-south-1) and MSG91 OTP delivery.
- In the United States: PostHog analytics and Resend/SendGrid transactional email; Sentry and push-delivery providers may also process data in the US or globally.
- Other / global: our backend/storage (including Cloudflare R2 for videos), Agora for live calls, and the sign-in and mapping providers may process data on servers outside India.
Where data is transferred outside India, we take reasonable steps consistent with the DPDP Act and applicable law, and we do not transfer personal data to any country restricted by the Government of India.
9Data Retention and Deletion
- Active accounts. We retain your profile and content while your account is active.
- Account deletion (30-day recovery). On deletion your account is soft-deleted and hidden; sign in within 30 days to restore it, after which an automated process permanently deletes your data. (Deactivation simply hides your account and is reversible.)
- Messages. Deleted messages may be retained in masked form for conversation integrity and safety investigations; tombstoned media is purged on a rolling basis (around 90 days).
- Ephemeral media is deleted when its timer expires; location data is short-lived (Section 3.3).
- Biometric data.
- Liveness / verification images are generally removed after approximately 90 days.
- Facial template. The AWS Rekognition facial template used for verification and duplicate/ban-evasion detection is retained while your account exists. For a banned account it is deleted 365 days after the ban becomes final (a permanent ban becomes final after the 30-day appeal window closes; while any appeal is pending it is retained), or immediately if the ban is overturned on appeal.
- Deletion. When you delete your account or withdraw biometric consent, the facial template is queued for deletion from AWS through a durable system that retries until AWS confirms removal.
- Safety, moderation, and ban records. To prevent abuse and ban evasion, certain records — ban history, confirmed moderation decisions, founding-member records, and certain reports — are retained after account deletion for as long as necessary for safety and legal compliance (for example resolved reports up to about 18 months and safety/audit records up to about 24 months), or longer where the law requires.
For full details on deletion, see our Delete Account page.
10Your Rights
Subject to the DPDP Act, you have the right to: access a machine-readable copy of your account data via Settings → Account → Request My Data (your profile, content you created, and related account history — not other people’s identities, biometric templates, authentication secrets, CSAM/NCII case files, or signed media URLs); correct, complete, or update it; erase it (by deleting your account); withdraw consent at any time, as easily as you gave it — including for face verification and location; grievance redressal (Section 13); and nominate another individual to exercise your rights in the event of death or incapacity.
To exercise any right, email support@getnymix.com or use the in-app controls. We may need to confirm who you are before acting on a request, and we respond within the timelines required by law. You may also lodge a complaint with the Data Protection Board of India.
11Security
- Authentication via phone OTP, Google, or Apple (we do not use account passwords). Session tokens are stored hashed, and sensitive media is served only through signed, expiring links.
- Server-side-only storage of facial biometric data, never exposed to other users.
- Scrubbing of sensitive fields from diagnostic, crash, and analytics data.
- Access controls, fraud detection, and automated abuse prevention.
Important: Messages and most content are stored on our backend (Convex) and are not end-to-end encrypted — we can access content where necessary to run moderation and safety systems and to comply with law. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
12Data-Breach Notification
If a personal-data breach occurs, we will notify affected users and the Data Protection Board of India in accordance with the DPDP Act and its rules, including a description of the breach, the data affected, and steps you can take to protect yourself.
13Grievance Officer / Grievance Redressal
In accordance with the Information Technology Act, 2000, the Intermediary Guidelines and Digital Media Ethics Code Rules, 2021, and the DPDP Act, you may direct any grievance about the processing of your personal data to our Grievance Officer:
Grievance Officer: Dharavath Durgaprasad (Proprietor)
Email: grievance@getnymix.com
Address: Mahabubabad, Telangana, India
Online: getnymix.com/grievance.html
We will acknowledge your grievance within 24 hours of receipt and endeavour to resolve it within 7 days, or within the timelines otherwise prescribed by law.
14Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes we will update the "Last updated" date above and, where appropriate, notify you within the app and ask you to re-accept. Your continued use of the Service after changes take effect constitutes acceptance of the updated Policy.
15Contact Us
Nymix (Dharavath Durgaprasad, sole proprietor)
Mahabubabad, Telangana, India
Privacy / support: support@getnymix.com · Grievance: grievance@getnymix.com · Child safety: child-safety@getnymix.com
Website: getnymix.com