1. Introduction
At milni, we are committed to protecting your privacy and ensuring the security of your personal information. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use milni.app, including the marketing website and the authenticated web portal for biodata, discovery, communities, family collaboration, and consent-based introductions. A native mobile app is not required to use the current service.
2. Information We Collect
2.1 Information You Provide
- Account authentication: Display name and phone number used for one-time password (OTP) sign-in. Portal accounts do not require an email address.
- Biodata: Age, location, profession, religion, mother tongue, diet, hometown, gender, height, marital status, caste or community, gotra, education, bio, family details, partner preferences, and optional Kundali details.
- Photos: Up to five profile photos stored in private cloud storage and delivered through time-limited signed URLs.
- Visibility choices: Whether your biodata is discoverable globally, in selected communities, or private.
- Collaboration and safety content: Family invite acceptances, private shortlist notes, contact-request decisions, report details, and matchmaker verification applications when you use those features.
- Support and waitlist forms: Name and email when you contact support or join a marketing waitlist.
2.2 Information We Collect Automatically
- Technical logs: IP address, browser type, and request metadata needed to operate and secure the site.
- Product diagnostics: Allowlisted portal feature events and hashed error fingerprints. These exclude biodata, phone numbers, notes, member identifiers, invite or share codes, and raw error messages.
- Marketing analytics: Basic website traffic measurement may run on public pages only and is separate from authenticated portal diagnostics.
We do not currently collect device advertising identifiers, continuous GPS tracking, or in-app chat message histories.
3. How We Use Your Information
We use your information to:
- Authenticate you with phone OTP and maintain your account
- Create, store, and display your biodata according to your visibility settings
- Power server-filtered discovery, community feeds, shortlists, and private notes
- Enable optional family co-search without transferring contact authority away from the account owner
- Process mutual contact consent and release a WhatsApp number only after both parties accept
- Operate community invites and verified matchmaker administration
- Review safety reports and matchmaker applications through authorized staff workflows
- Deliver in-portal notifications about contact, family, community, and verification events
- Improve reliability with privacy-bounded product diagnostics
- Comply with legal obligations and protect the safety of members
4. Family Features and Privacy
Family collaboration is optional and designed so the candidate remains the decision-maker for contact.
4.1 Family Invites
- You may invite a parent or guardian with a time-limited invite link
- Both parties must accept the link before collaboration begins
- Either party can remove the family link later
4.2 Family Co-Search
- Guardians may help manage a candidate’s shortlist and private notes
- Guardians cannot send, accept, decline, or revoke contact requests on the candidate’s behalf
- WhatsApp numbers are never released through guardian co-search context
4.3 Private Biodata Share Links
- You may create an expiring private share link for a specific biodata review
- Recipients must sign in; the link does not place your profile into discovery
- Photo visibility and contact consent rules still apply; links can be revoked
5. Information Sharing and Disclosure
We do not sell, trade, or rent your personal information to third parties. We may share your information in the following circumstances:
5.1 With Other Users
- Biodata and photos are shown to other signed-in members only according to your global, community, or private visibility settings
- There is no in-app messaging product; introductions use mutual contact requests, after which WhatsApp may open outside milni
- Your phone number is read from authentication records and shared with another member only after both parties accept a contact request
- Family collaborators see only the candidate-owned shortlist context you enable
- Community invite codes are bearer secrets for joining a cohort and are not shown to ordinary members as public profile data
5.2 With Service Providers
- Cloud hosting, authentication, and storage providers that power the portal under contractual protections
- SMS delivery for phone OTP codes
- Email delivery for support and waitlist forms after server-side abuse checks
- Basic website traffic analytics may be processed by an analytics provider. Inside the authenticated portal, milni uses first-party product diagnostics that record only allowlisted feature events and error fingerprints and exclude biodata, phone numbers, notes, member identifiers, invite or share codes, and raw error messages.
5.3 Legal Requirements
- To comply with applicable laws and regulations
- To respond to legal requests and court orders
- To protect our rights, property, and safety
- To investigate and prevent fraud, abuse, or safety harm
6. Data Security
We implement comprehensive security measures to protect your information:
- Encryption: Data is encrypted in transit and at rest with industry-standard providers
- Access controls: Database row-level security and server-authorized functions limit who can read or change sensitive records
- Private photos: Photos remain in a private bucket and are served with short-lived signed URLs
- Data minimization: We collect only information needed for the features you use
- Safety controls: Reporting and blocking remove discovery and contact access on milni; WhatsApp blocking must be completed separately in WhatsApp
7. Data Retention
We retain your information for as long as necessary to provide our services:
- Active Accounts: Information is retained while your account is active
- Deactivated Accounts: Information is retained for 30 days after deactivation
- Deleted Accounts: Information is permanently deleted within 90 days after a verified deletion request
- Product Events: Allowlisted product usage events are retained for no more than 90 days and are deleted with your account
- Error Diagnostics: Sanitized error fingerprints are retained for no more than 30 days and are deleted with your account
- Legal Requirements: Some information may be retained longer for legal compliance or safety investigation
8. Your Rights and Choices
You have the following rights regarding your personal information:
8.1 Access and Control
- Access: Request a copy of your personal information
- Update: Update biodata, photos, and visibility in the portal
- Delete: Request deletion of your account and data by emailing priyanka@milni.app
- Portability: Request a copy of your data in a portable format
8.2 Privacy Settings
- Choose global, community, or private biodata visibility
- Control photo visibility until mutual contact consent where configured
- Invite, remove, or decline family collaboration
- Create or revoke private biodata share links
- Disable product analytics and error diagnostics for the current browser in portal settings; browser Do Not Track is also respected
8.3 Communication Preferences
- Opt out of marketing waitlist or support email follow-ups by contacting us
- Use in-portal notifications for contact, family, community, and verification updates
- Push notification and paid subscription preferences are not currently offered in the portal
9. International Data Transfers
milni operates globally and may transfer your information to countries other than your own. We ensure that such transfers comply with applicable data protection laws and implement appropriate safeguards.
10. Children's Privacy
milni is not intended for children under 18 years of age. We do not knowingly collect personal information from children under 18. If you believe we have collected information from a child under 18, please contact us immediately.
11. Third-Party Services
After mutual contact consent, milni may open WhatsApp or other third-party services you choose. Those services have their own privacy practices. Public pages may also link to third-party websites.
12. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will post the updated policy on milni.app with a revised date. Continued use of the service after changes constitutes acceptance of the updated policy.
13. Contact Us
If you have questions about this Privacy Policy or our privacy practices, please contact us:
- Email: priyanka@milni.app
- Address: San Francisco, CA
- Data Protection Officer: priyanka@milni.app
14. Regional Privacy Rights
Depending on your location, you may have additional privacy rights under local laws:
14.1 California Residents (CCPA)
California residents have additional rights under the California Consumer Privacy Act, including the right to know what personal information is collected and the right to opt out of the sale of personal information.
14.2 European Residents (GDPR)
European residents have additional rights under the General Data Protection Regulation, including the right to erasure, the right to data portability, and the right to object to processing.
15. Cookie Policy
Our website uses cookies and similar technologies to enhance your experience. You can control cookie settings through your browser preferences.