This Privacy Policy explains how AskMyCrush ("AskMyCrush", "we", "us", or "our") collects, uses, shares, and protects your information when you use the AskMyCrush mobile application and related services (the "App").
By creating an account or using the App, you agree to the practices described in this Policy. If you do not agree, please do not use the App.
AskMyCrush is intended for users in India and is governed by Indian law, including the Digital Personal Data Protection Act, 2023 (the "DPDP Act").
1 Who we are
AskMyCrush is an anonymous crush-matching service. The core idea: you can let someone know they're your crush without revealing your identity unless the feeling is mutual. Identities are only disclosed when a match occurs.
- Service provider: AskMyCrush
- Privacy contact: ashish.nath.business@gmail.com
2 Age requirement
The App is only for users aged 13 and over. We do not knowingly collect personal data from anyone under 13. If we learn that we have collected data from a person under 13, we will delete it. Users under the age of 18 should use the App only with the involvement and consent of a parent or guardian. If you believe a child under 13 is using the App, contact us at ashish.nath.business@gmail.com.
3 Information we collect
3.1 Information you provide
| Data | Why we collect it | Required? |
|---|---|---|
| Mobile phone number | Account creation and login via one-time password (OTP); the unique identity used to send and receive crush pings. | Required |
| Display name | Shown as one of the options a recipient sees, and revealed to the other person after a match. | Required |
| Institution (college / workplace / group) | Provides context for pings and is appended to poll options to preserve anonymity (see Section 6). | Required |
| Your crush selection (the phone number you set as your current crush) | To enable pinging and to detect a mutual-crush match. | Required to use the core feature |
| Decoy ("fake") names and their institutions | When you send a ping, you supply decoy options so the recipient cannot tell which option is really you. | Required to send a ping |
| Poll responses | The option a recipient selects when responding to a ping, used to determine a match. | Provided when you respond |
3.2 Payment information
When you purchase ping credits, payments are processed by the relevant app store or payment provider (Google Play Billing, Apple In-App Purchase, and/or our payment partner). We do not collect or store your full card, UPI, or bank details. We receive only a confirmation of the transaction and a provider-generated transaction/order reference needed to grant your purchase and keep records.
3.3 What we do not collect
We do not collect your contacts list, precise GPS location, photos, chat messages (the App has no chat), or social-media profiles. Setting someone as your crush does not require or grant us access to that person's account or contact details.
4 SMS / OTP
We send a one-time password (OTP) by SMS to verify your phone number at sign-in.
5 How we use your information
We use your information to:
- Create and manage your account and authenticate you (OTP and tokens).
- Provide the core features: setting a crush, sending pings, generating anonymous poll options, recording responses, and detecting matches.
- Reveal contact details only after a match (see Section 6).
- Enforce limits (free monthly ping, lifetime ping caps, removal locks) and process credit purchases.
- Maintain security, prevent fraud and abuse, and debug problems.
- Comply with legal obligations and enforce our Terms.
We rely on the following legal bases under the DPDP Act: your consent (given when you sign up and use features) and the necessity to provide the service you requested, as well as legitimate uses permitted by law.
6 Anonymity and what gets revealed in a match
Anonymity is central to AskMyCrush. Please read this carefully:
- Setting someone as your crush is silent and anonymous. The other person is not notified and cannot see that you have set them as your crush.
- When you send a ping, the recipient sees a set of options (your real display name mixed with the decoy names you provided, plus a "None of the above" option). To protect your identity, the same institution label is applied to all options so it never singles you out.
- A match reveals identities. A match happens in one of two ways:
- Poll match — the recipient selects the option that is actually you; or
- Mutual-crush match — you and another user have each set the other as your current crush.
- When a match occurs, both matched users are shown each other's display name, institution, and phone number. This disclosure is the intended reward of a match. By using the App you consent to this disclosure upon a match. We do not reveal your phone number or identity in any other situation.
7 How we share information
We do not sell your personal data. We share information only as follows:
| Recipient | What & why |
|---|---|
| Other users | Your display name and institution appear as poll options; after a match, your name, institution, and phone number are revealed to the matched user (see Section 6). |
| Service providers (processors) | Cloud hosting, SMS/OTP delivery, payment processing, and analytics/crash reporting — only as needed to run the App, under contractual confidentiality obligations. |
| App stores / payment providers | Google Play Billing, Apple In-App Purchase, and/or our payment partner process purchases. |
| Legal & safety | When required by law, court order, or to protect rights, safety, and prevent fraud or abuse. |
| Business transfers | In a merger, acquisition, or asset sale, with notice to you as required. |
8 Data security
We apply technical and organizational safeguards, including:
- Encryption of your phone number at rest in our database.
- Stateless, signed authentication tokens (JWT) with refresh-token rotation.
- Rate limiting to deter abuse.
- Transport encryption (HTTPS/TLS) for data in transit.
- Access controls and the principle of least privilege for our systems.
No method of transmission or storage is 100% secure, but we work to protect your data and continuously improve our safeguards.
9 Data retention
We keep your personal data for as long as your account is active and as needed to provide the service. We retain certain records (e.g., transaction records) for as long as required by law. When you delete your account, we delete or anonymize your personal data within a reasonable period, except data we must retain for legal, accounting, fraud-prevention, or dispute-resolution purposes.
10 Your rights
Subject to applicable law (including the DPDP Act), you have the right to:
- Access the personal data we hold about you.
- Correct or update inaccurate or incomplete data.
- Delete your data / account ("right to erasure").
- Withdraw consent (this may limit or end your ability to use the App).
- Grievance redressal — raise a complaint with us.
- Nominate another individual to exercise your rights in case of death or incapacity (as provided under the DPDP Act).
To exercise any right, contact us at ashish.nath.business@gmail.com. We will respond within the timeframe required by law.
11 Account deletion
You can request deletion of your account and associated personal data at any time by emailing us at ashish.nath.business@gmail.com from the account you wish to delete. Some information may be retained as described in Section 9.
12 Children
The App is not directed to and may not be used by anyone under 13. See Section 2.
13 Links to other sites
Our Service may contain links to third-party websites. We are not responsible for the content or privacy practices of those sites and encourage you to review their privacy policies independently.
14 Changes to this Policy
We may update this Policy from time to time. We will update the "Last updated" date and, for material changes, provide additional notice (e.g., in the App). Your continued use of the App after changes take effect constitutes acceptance.
15 Contact us
For any questions, requests, or complaints about this Policy or your data: