Privacy Policy
Last updated: 21 July 2026
The one-line version
We never sell your data. Ever. We collect the minimum needed to run a safe marketplace, encrypt the sensitive parts, delete on a published schedule, and give you a working export and delete button — not a support ticket.
Who we are
Buddyly (“we”) operates buddyly.ai, a verified companionship marketplace for India. This policy is written for compliance with the Digital Personal Data Protection Act, 2023 (DPDP). Buddyly is strictly 18+; we do not knowingly process children's data, and an account found to belong to a minor is removed.
What we collect, and why
- Identity — your mobile number (it is your account), optional email, and your name. Your legal name, date of birth, and gender are stored encrypted (AES-256-GCM) and are never shown publicly. Companion verification stores a DigiLocker reference — never the Aadhaar number itself.
- Profile & preferences — what you choose to tell us at onboarding (interests, languages, budget, companion preferences). All of it is optional, used only to improve your browsing, and editable or removable in Settings.
- Bookings, offers, and payments — session details, price-negotiation offers (amounts only — the flow has no message field by design), and Cashfree payment references. We never see or store card numbers or UPI credentials.
- Location — your “near me” coordinates are used for the search and never stored. A companion's operating area is a locality centroid rounded to roughly 110 metres — never a street address — and other users only ever see a distance bucket. The venue on a booking is always a verified public place.
- Chat — messages exist to coordinate booked sessions. Contact details are redacted automatically before a message is stored or scanned for safety. Messages are deleted 90 days after the booking ends.
- Emergency contacts — encrypted at rest, used only in a genuine emergency, never shown to other users, and hard-deleted the moment your account is erased.
- Security records — sign-ins, device records, and an append-only audit trail of security-relevant actions (with IP address), kept to protect your account and to make our own conduct provable.
How long we keep it
- Account & profile data — until you delete your account (plus the 30-day grace below).
- Chat messages — 90 days after the booking's scheduled end, then hard-deleted.
- Signed-out sessions — 30 days, then deleted. Devices unseen for a year are deleted.
- Bookings, payments, and payouts — retained for the statutory financial record-keeping period (up to 8 years) with your identity stripped once you delete your account.
- Consent records and the security audit trail — retained as evidence of lawful processing; they are append-only and cannot be edited, including by us.
Your rights (DPDP Act, 2023)
- Access & portability — download a complete JSON export of your data instantly from Settings → Account.
- Correction — edit your profile, preferences, and account details at any time.
- Erasure — delete your account from Settings → Account. You get a 30-day grace window (signing back in cancels it); after that your personal data is erased and verification documents and photos are deleted from storage. Financial records the law requires us to keep survive with your identity removed.
- Consent & withdrawal — every consent decision is recorded in an append-only ledger you can inspect in Settings → Privacy & data. Withdrawing is a new entry, one tap, effective immediately. Marketing is opt-in, never opt-out.
- Grievance — our named Grievance Officer is on every page footer and the Grievance page, with published response timelines.
Cookies
Buddyly uses strictly-necessary cookies for sign-in and security. We currently run no analytics or advertising cookies. The cookie banner records your choice (accept or decline, both equally easy) against a specific policy version, and any future analytics will be gated on that recorded consent — if the meaning of the choice changes, we ask again.
How it's protected
Sensitive personal columns are encrypted at rest (AES-256-GCM) on top of full-disk encryption; everything travels over TLS. Verification documents live in a private bucket readable only through short-lived signed links minted per authorised review. Application logs are scrubbed of personal data. Security-relevant actions — including every time an admin looks up an account — land in an audit trail the database itself refuses to let anyone edit or delete.
Who we share data with
Only processors needed to run the product, each receiving the minimum required and bound by contract: Cashfree (payments), Google Firebase (phone verification), Google Maps (venue and area lookup), Cloudflare R2 (file storage), Vercel and Neon (hosting and database), Upstash (rate limiting), Pusher (chat delivery), Sentry (error reports, scrubbed), and OpenAI (safety moderation — which only ever receives chat text after contact details are redacted). We share data with authorities only under valid legal process, and we do not transfer personal data except to these processors.
Changes to this policy
Material changes bump this policy's version and every member is asked to consent again before continuing — your previous consent is never silently stretched to cover new text. The date at the top is the version you are reading.