Privacy Policy
Last updated: 2026-05-22
Lami Matrimony is a matchmaking platform for the Nepali community. We take your privacy seriously because the data you share with us — your photos, your background, your identity documents — is among the most personal information you have. This policy explains what we collect, why, and how we protect it. We've written it in plain English so you can actually read it.
Who we are
Lami Matrimony is operated by an independent founder based in Nepal. You can reach us at any time:
- Email: lamimatrimony@gmail.com
- WhatsApp: +977 9801320324
- Website: lamimatrimony.com
What we collect
To make matchmaking work, we collect:
- Account basics — your name, email address, and (optionally) phone number. Used to sign you in, communicate with you about your account, and let other members address you by name.
- Profile information — gender, date of birth, religion, caste, mother tongue, education, profession, marital status, the city/country you entered, and the bio text you write. Used so we can suggest compatible candidates and so candidates can decide whether to express interest in you.
- Kundali (astrological) data — birth date, birth time, and birth place if you choose to use the Kundli compatibility (Ashtakoot Guna Milan) feature. Used solely to compute compatibility scores; never shared.
- Photos — profile pictures you upload, and a government-issued ID photo submitted during verification. Profile pictures are visible to other verified members. Your government ID is visible only to our internal verification team and is used only to confirm you are a real, single adult; it is not shown to other members.
- Messages — the text you send to other members through the in-app chat. We store these so the conversation history persists for both of you. We don't read or scan them except in response to a specific abuse report or a lawful legal request.
- Subscription history — which plan you purchased, when, and the transaction reference from the payment processor. We do not store your card number or bank account details — those go directly to the payment provider.
- App activity — which profiles you swiped, liked, or shortlisted; which features you used. Used to improve the matchmaking algorithm and to enforce daily quotas on the free tier.
- Device identifiers — a push notification token issued by your device's operating system, so we can deliver match alerts and message notifications to your phone. We also collect crash logs and basic diagnostics from Google Play and Apple App Store so we can fix bugs.
We do not collect: your phone's location, contacts, calendar, files, browsing history, microphone audio, or any data from other apps.
How we use it
- Matchmaking. Your profile information is shown to other verified members whose preferences are compatible with you, and theirs is shown to you.
- Verification. Our team manually reviews every government ID submission before approving a profile. This is how Lami stays a serious matrimonial platform.
- Account management. Logging you in, letting you reset your password, notifying you when your subscription is ending, etc.
- Notifications. Push notifications when someone expresses interest in you, when you match, when you receive a message, or when your verification is approved.
- Improvement. Aggregated, anonymized statistics about which features are used help us prioritize what to build next.
What we don't do
- We do not sell your data to anyone. Ever.
- We do not run advertising in the app. No ad networks, no behavioral tracking, no "sponsored" profiles.
- We do not share your government ID with anyone outside our verification team. Once verification is approved, the ID image is retained only for record-keeping and audit (in case Apple/Google or a regulator asks us to prove our verification process).
- We do not use your data to train AI models, build user profiles for marketing, or feed third-party data brokers.
Who we share data with
We share the minimum data necessary with the following processors so the app can function:
- Firebase (Google) — handles authentication. Firebase receives your email address and the password you set (Firebase stores it hashed and salted on their servers — we never see your plain-text password).
- Firebase Cloud Messaging (Google) — delivers push notifications. The notification payload contains only the alert text (e.g., "You have a new match"), not your personal data.
- Payment processors (Khalti, eSewa, Google Play Billing, Apple App Store) — handle subscription payments. They receive the amount and reference; we receive only a transaction ID.
- Hosting provider — our backend server is hosted on a virtual private server in a commercial data center. They have no access to your account contents; they only operate the underlying machine.
We may also disclose information if compelled by a valid legal process (subpoena, court order, lawful government request) or if we believe disclosure is necessary to prevent imminent harm.
How we keep it safe
- All data is transferred between your device and our servers over HTTPS (TLS 1.2+). Data in transit is encrypted.
- Passwords are never stored in plain text — Firebase Auth handles password hashing.
- Authentication tokens on your device are kept in the iOS Keychain / Android Keystore, not in plain storage.
- Access to our backend systems is restricted to the founder and the verification team, with strong-password and two-factor-authentication requirements.
No system is perfectly secure. If we ever detect a breach that may have exposed your data, we'll notify affected users by email within 72 hours of confirming the incident.
How long we keep it
We retain your data for as long as your account is active. When you delete your account (see below), we remove your profile, photos, chats, and personal information from our live systems within 30 days. Anonymized analytics data (counts and aggregates that can no longer be tied to you) may be retained indefinitely.
Some data is retained longer if we're legally required to — for example, payment records may be kept up to 7 years to comply with Nepali tax law.
Your rights
You can, at any time:
- See your data — your profile is visible to you inside the app. To request a full data export, email us.
- Correct your data — edit your profile anytime through the app's Account screen.
- Delete your data — see the account deletion page for in-app and out-of-band deletion options.
- Object to processing — if you believe we are using your data in a way you didn't agree to, contact us and we'll address it within 30 days.
Children
Lami is a matrimonial platform for adults. You must be 18 or older to create an account. If we learn we've accidentally collected data from someone under 18, we'll delete it immediately. If you believe a minor has signed up, please email us so we can investigate.
Changes to this policy
When we make material changes to this policy, we'll notify you through the app (in-app notice) and by email if we have your address. Minor edits — fixing a typo, clarifying wording — won't trigger a notification, but the "Last updated" date at the top of this page always reflects the most recent revision.
Contact us
Questions, concerns, or a data request? Reach out:
- Email: lamimatrimony@gmail.com
- WhatsApp: +977 9801320324