Screen hidden

Click anywhere to come back.

Privacy Policy

Last updated 25 September 2026

Legal Centre Terms of Service Privacy Policy Cookie Policy Community Guidelines Prohibited Content & Acceptable Use Safety Centre Identity Verification Policy AI Companion Disclosure Anti-Trafficking & Exploitation Policy Law Enforcement Request Policy Account & Data Deletion Points, Limits & Payments Member Listing Agreement Grievance Redressal Disclaimer Contact Us About Us

This policy explains what Parda collects, why, who sees it, how long we keep it and what you can demand of us. It is written under India’s Digital Personal Data Protection Act, 2023.

The short version. We do not show your real name to anybody. We hold as little as we can get away with. Your photos are masked on our server and the clear file is never sent to a browser you have not given a key to. Deletion is real deletion. And a court order can still reach whatever we hold, which is the honest reason we hold so little — see Law Enforcement Requests.

1. Who is responsible

Parda is the Data Fiduciary for your personal data. Our Grievance Officer is named on the Grievance Redressal page and is the person to contact about anything in this policy.

2. What we collect

a. Account data

Email address, a password (stored only as a bcrypt hash, never in readable form), and a display name you choose. We do not ask for your real name for your profile.

b. Profile data

Age, gender, city and general locality, relationship status, what you are looking for, availability, interests and anything you write about yourself. You choose all of it and you can change or remove any of it.

c. Identity verification data

To list a profile you submit a government photo identity document (passport, driving licence, voter ID or PAN) and a live camera selfie. We do not use Aadhaar. A private platform cannot require it, following K.S. Puttaswamy v. Union of India (2018), which struck down Section 57 of the Aadhaar Act.

d. Photographs

For every photo you upload we generate a masked copy on our server. The image is reduced to 40 pixels wide, enlarged in interpolating steps and passed through twelve gaussian passes, so the detail that identifies a face is destroyed rather than hidden. The masked copy gets its own random filename. The clear file is never sent to a browser that has not been given a key by you. This matters: a blur applied with CSS can be removed by anybody who opens a developer console, and many platforms in this category do exactly that.

e. Messages

Message content, so conversations work. Phone numbers, email addresses and social handles are stripped out of message bodies automatically before delivery. Messages are not end-to-end encrypted — we can read them if a report or a lawful order requires it, and we would rather say so than imply otherwise.

f. Payment data

Handled by our payment gateway. We never see or store your card number. We keep the transaction reference, amount, date and status, because tax law requires it.

g. Technical data

IP address, device and browser type, and timestamps, for security, fraud prevention and abuse investigation. Kept for the minimum period in section 5.

h. Measurement

Only with your consent from the cookie banner. See the Cookie Policy.

3. Why we process it, and on what basis

PurposeBasis under the DPDP Act
Creating and running your accountYour consent, given at registration
Verifying age and identityYour consent, and our legitimate need to keep minors off an adult platform
Showing your profile to other membersYour consent, withdrawable by hiding or deleting your profile
Safety, moderation and fraud preventionLegitimate use, and our obligations as an intermediary
Payments and tax recordsLegal obligation
Measurement and advertisingYour consent, withdrawable at any time

4. Who sees what

5. How long we keep things

6. Your rights under the DPDP Act

7. Security

No system is perfectly secure. The 2015 Ashley Madison breach is the reference case for this entire category, and the lesson we took from it is architectural rather than cosmetic: the only data that cannot leak is data we never collected. That is why your real name is not in our database.

If a breach occurs that is likely to affect you, we will notify you and the Data Protection Board of India as the DPDP Act requires.

8. Children

This service is for adults only. We do not knowingly process the data of anyone under 18, and every listing is age-checked against a government photo ID by a person. If you believe a minor has an account, report it immediately and we will act the same day.

9. Where your data is

Data is stored on servers located in India. Where a processor operates outside India, transfers are made only to jurisdictions permitted under the DPDP Act and under contractual safeguards.

10. Changes

Material changes to this policy are announced here and by email at least 7 days before they take effect.

Last updated: 25 September 2026.