PRIVACY POLICY — WeFell
Last updated: 18 July 2026
────────────────────────────────────────
INTRODUCTION
────────────────────────────────────────
WeFell ("WeFell", "we", "us", or "our") operates the WeFell mobile application (Android package com.wefell.app and equivalent iOS builds), related APIs, and WeFell for Business tools (together, the "Service"). Our tagline is "Write your own love story."
This Privacy Policy explains, in clear language:
• what personal information we collect;
• why we collect it;
• how we use, store, and protect it;
• who we share it with;
• how long we keep it;
• your rights and choices; and
• how to contact us.
This Policy is written to align with common requirements under India's Digital Personal Data Protection Act, 2023 (DPDP Act), the EU/UK General Data Protection Regulation (GDPR) where applicable, the California Consumer Privacy Act as amended by the CPRA (CCPA/CPRA), and California's Online Privacy Protection Act (CalOPPA). If a section does not apply to you because of where you live, the remaining terms still apply.
This is the single WeFell Privacy Policy for both consumer users and WeFell for Business partners. You only need this one document for store listings and partner onboarding privacy disclosures.
By creating a WeFell account, registering WeFell for Business, tapping "I agree", completing signup, or otherwise using the Service, you acknowledge that you have read and understood this Privacy Policy. If you do not agree, do not use WeFell.
────────────────────────────────────────
1. BASIC APP INFORMATION
────────────────────────────────────────
App name: WeFell
Operator / developer: WeFell (operated by the WeFell team)
Website: WeFell does not currently maintain a separate public marketing website. The consumer Service is offered primarily through the mobile app and the Google Play listing for com.wefell.app (and any future App Store listing).
Support & privacy email: manassawant2499@gmail.com
Business / postal address: Not published. For privacy requests, use the email above.
────────────────────────────────────────
2. WHO THIS POLICY COVERS
────────────────────────────────────────
This Policy applies to:
• Consumer users of the WeFell app (dating discovery, matching, First Light chat, couple linking, shared diary, Journey features, gift discovery, notifications, and in-app purchases)
• WeFell for Business partners (café/venue partners, gift sellers, and advertisers) — see Section 25
• Visitors who contact us by email about the Service
• Processing on our backend systems and cloud providers that host WeFell data on our behalf
This Policy does NOT control:
• Third-party websites or apps you open through affiliate gift links, partner sites, or external checkouts
• Apple, Google Play, Google Sign-In, Firebase, Cloudinary, MongoDB Atlas, Railway, Render, Brevo, or other processors — they have their own policies
• How other users use information you choose to share with them in chat, diary, Journey, or offline
────────────────────────────────────────
3. CHILDREN'S PRIVACY (18+ ONLY / COPPA)
────────────────────────────────────────
WeFell is strictly for adults aged 18 and over.
• Minimum age: 18+
• We do not knowingly collect personal information from children under 13 (COPPA) or from anyone under 18.
• We verify age using date of birth you provide, optional Google account birthday verification where enabled, and photo-based age estimation where enabled.
• If we learn that a user is under 18, we will suspend or delete the account and delete or anonymise associated personal data as required by law.
• If you believe a minor is using WeFell, email manassawant2499@gmail.com immediately.
────────────────────────────────────────
4. PERSONAL INFORMATION WE COLLECT
────────────────────────────────────────
We collect only what we need to operate WeFell safely and as designed. Categories include:
4.1 Account information you provide
• Email address (required)
• Display name / first name (required; we do not require a separate legal last name)
• Date of birth (required) and age calculated from it
• Gender (required at signup; not editable after registration)
• City and state/region (provided by you and/or derived from location)
• Country may be inferred from location or device locale where available
• We do NOT collect consumer phone numbers, home street address, or postal code for dating accounts
• Business partners separately provide business phone and verification documents (see Business section)
4.2 Profile information
• Profile photos (face photos required for verification; additional photos optional within product limits)
• Bio
• Interests and dislikes / preferences
• Discoverability settings
• Relationship path (looking to meet someone vs already a couple) and couple-link status
• Optional profile fields that may be stored if you or the API set them (for example occupation, education, relationship goals, height, languages, lifestyle)
4.3 Authentication & security
• Email one-time passwords (OTP) for sign-in
• Google Sign-In identifiers and tokens when you choose Google (including birthday for age verification where requested)
• Device identifier (X-Device-Id) used to bind one primary dating account per device and reduce abuse
• Session/authentication tokens stored securely on your device
4.4 Device permissions & technical data
When you grant permission (or as automatically collected for security), we may process:
• GPS location (precise latitude/longitude) — see Location section
• Camera — profile photos and live face verification selfies
• Photo gallery / storage access — selecting images to upload
• Notifications — push delivery
• Device information — platform (Android/iOS), app version, and request metadata needed for security and support
• IP address and server request logs (via our hosting providers) for security, rate limiting, and abuse prevention
We do NOT request contacts, microphone, Bluetooth, or calendar access for the consumer app.
4.5 Face verification & biometric-related data
• Do users upload selfies? Yes — a live selfie is required for identity verification.
• Do we compare faces? Yes — we compare the live selfie to your profile face photo(s).
• Is facial data stored permanently? No. The selfie image file is deleted from WeFell servers after verification processing. We may retain mathematical face descriptors (non-reversible feature vectors) linked to your account while the account is active, to prevent fraud and to support re-verification when you change face photos. Descriptors are cleared when the account is deleted (subject to limited legal/safety retention below).
• Is the selfie deleted after verification? Yes — the uploaded selfie file is removed after processing.
• Do we use AI for verification? Yes.
• Libraries/services used: on-device Google ML Kit face detection (presence check on your phone); server-side face matching and optional age estimation using face-api / TensorFlow.js models operated by WeFell. We do not sell biometric data and do not use face data to train unrelated third-party advertising AI.
4.6 User-generated content we store
• Messages (First Light chat and couple communications as designed)
• Likes and passes
• Matches
• Uploaded images (profile, diary, Journey)
• Reports you submit about other users
• Shared couple diary / memory entries and milestone content
• Journey notes, café selections, level photos, Open When letters, and related progress
• In-app notification records
We do not operate a separate consumer "block list" product; safety is handled via reports, admin review, and account restrictions.
4.7 Purchases
• In-app purchase product IDs, platform transaction/receipt verification data, and credit applied to your account (for example extra likes or diary photo slots; business products for partners)
• WeFell does not receive or store your full payment card number — consumer purchases are processed by Google Play Billing and, if enabled on iOS, Apple In-App Purchase. WeFell for Business products are billed through Google Play only.
4.8 Communications with us
• Support emails and any information you include when contacting manassawant2499@gmail.com
────────────────────────────────────────
5. WHY WE USE YOUR INFORMATION
────────────────────────────────────────
We use personal information to:
• Create and manage your account and authenticate you (Email OTP and/or Google Sign-In)
• Provide discovery, matching, chat, couple mode, diary, Journey, gift discovery, and related features
• Calculate distance and show approximate proximity / city-level context
• Verify you are 18+ and that profile face photos match a live selfie
• Moderate uploads for safety and policy compliance (including automated screening tools)
• Send push notifications and transactional emails (OTP, security, service messages)
• Process and fulfil in-app purchases
• Detect fraud, spam, multi-accounting, and abuse; process reports
• Operate the WeFell Control Panel for authorised staff safety review, profile/face verification support, and business moderation (Section 14)
• Maintain, debug, and improve the Service using first-party server logs and activity events
• Comply with law and protect the rights and safety of users and WeFell
WeFell does NOT:
• Sell your personal information
• Share your email with other users
• Show your precise GPS coordinates to other users (only approximate distance and city-level information as designed)
• Use private chat, diary, or Journey notes to train unrelated third-party advertising AI
• Allow staff to use Control Panel access for marketing or unrelated personal browsing of private diaries/chats
────────────────────────────────────────
6. LOCATION USAGE
────────────────────────────────────────
We collect GPS (when permitted / required by product gates) to:
• Enable discovery ranked by distance and show approximate distance to other users
• Update displayed city/state via reverse geocoding as you travel
• Support couple Journey features (for example partner distance)
• Improve safety and integrity of location-sensitive features
Precise coordinates are processed on our servers and are not displayed as a live map pin of your home to other users. You can revoke location permission in device settings; some WeFell features may then be limited or unavailable because location is part of core matching and Journey design.
────────────────────────────────────────
7. ANALYTICS
────────────────────────────────────────
WeFell does not currently integrate third-party product analytics SDKs such as Firebase Analytics, Google Analytics, Crashlytics, Performance Monitoring, or Mixpanel in the consumer app.
We use:
• First-party server activity events and logs (for example likes, gift clicks, campaign impressions) stored in our database
• Firebase primarily for Cloud Messaging (push) and related Google project configuration for Sign-In / messaging
────────────────────────────────────────
8. NOTIFICATIONS & EMAILS
────────────────────────────────────────
Push notifications (Firebase Cloud Messaging)
• Sent when you grant notification permission
• Purposes include likes, matches, chat/partner activity, diary/Journey updates, and other service alerts
• You may disable push in system settings
• Providers: Brevo and/or SMTP (including Gmail SMTP where configured)
• Purposes: OTP login/verification codes, account security, and essential service messages
• We do not use SMS
• We do not send marketing newsletters unless you opt in where required by law
────────────────────────────────────────
9. AUTHENTICATION METHODS
────────────────────────────────────────
• Email OTP — yes
• Google Sign-In — yes (including birthday verification where required)
• Apple Sign-In — not currently offered
• Facebook login — not offered
• Phone OTP for consumer dating accounts — not offered
────────────────────────────────────────
10. ADVERTISING
────────────────────────────────────────
WeFell does not show third-party network ads via Google AdMob, Google Ads, AppLovin, Unity Ads, InMobi, or similar ad SDKs.
WeFell may show first-party partner promotions inside the app (for example café campaigns or swipe ads submitted by verified WeFell Business partners). Those are WeFell-operated placements, not a third-party advertising network. Impression/click logs may be used for partner reporting in aggregated or account-level form appropriate to the feature — not for selling your identity to advertisers.
We do not use remarketing pixels or third-party remarketing networks inside the consumer app.
────────────────────────────────────────
11. PAYMENTS
────────────────────────────────────────
Users can purchase optional digital items through:
• Google Play Billing (primary on Android)
• Apple In-App Purchase if/when enabled on iOS builds
What users may purchase (examples; catalogue may change):
• Extra likes packs
• Diary / milestone photo capacity packs
• Business partner products (venue verification, ad packs, gift-related packs) for WeFell for Business
Razorpay or other direct card gateways are not the primary consumer checkout path. WeFell does not store full card details.
────────────────────────────────────────
12. THIRD-PARTY SERVICES (PROCESSORS)
────────────────────────────────────────
We use service providers as data processors under our instructions, including:
Backend hosting: Railway and/or Render (or equivalent cloud hosts)
Database: MongoDB Atlas
Image storage/CDN: Cloudinary
Notifications: Firebase Cloud Messaging
Authentication helpers: Google Sign-In / Google OAuth APIs
Email: Brevo and/or SMTP providers
Payments: Google Play / Apple
AI / vision: Google ML Kit (on-device); face-api / TensorFlow.js (server-side WeFell verification and moderation-related tooling such as content screening libraries where enabled)
Maps: We do not embed a full Google Maps SDK for browsing; we may use platform geocoding and Google Business / Places-related APIs for partner venue verification where configured
These providers may process data in data centres outside your country.
────────────────────────────────────────
13. HOW WE SHARE INFORMATION
────────────────────────────────────────
We share personal information only as follows:
• Service providers listed above (to operate WeFell)
• Other users — your public profile fields (photos, name, age, city, bio, interests, approximate distance) as designed; chat/diary/Journey content with your match or linked partner
• Authorised WeFell staff — through the WeFell Control Panel, only as described in Section 14 (for safety, verification, moderation, and fraud prevention — not for marketing)
• Payment processors (Apple/Google) — to verify purchases
• Affiliate retailers — when you tap out to buy a gift, you deal with that retailer under their policy; WeFell may append affiliate tracking parameters to URLs
• Government / legal — when legally required or to protect rights, safety, investigate fraud, or prevent harm
• Business transfers — if WeFell is merged or acquired, data may transfer to a successor under notice where feasible
We do NOT sell personal information to data brokers.
We do NOT share personal information with advertising networks for cross-app tracking ads (we do not use those networks).
────────────────────────────────────────
14. WEFELL CONTROL PANEL (ADMIN / STAFF ACCESS)
────────────────────────────────────────
WeFell operates an internal Control Panel used only by authorised WeFell staff (allowlisted by email, such as Super Admin and Gift Admin). This is not a public feature.
Why we use the Control Panel
Staff access exists only to:
• Keep the community safe (review reports, block abusive accounts, moderate harmful content)
• Verify identities and ages where needed (face-verification status and related review signals)
• Prevent fraud and multi-account abuse (device / IP signals, blocked devices)
• Review and moderate WeFell for Business partners (venues, ads, campaigns, gift listings)
• Fulfil support and legal obligations
• Manage the Gift Store catalogue and related analytics (Gift Admin)
Staff do NOT use Control Panel access for advertising, selling your data, reading your private diary for curiosity, or training unrelated third-party advertising AI.
What authorised Super Admins may see (when needed for the purposes above)
• Dating profile information: name, email, age/date of birth fields, gender, city/state, approximate location coordinates stored for matching, bio and optional profile fields, profile photos
• Account status: onboarding, discoverability, couple / partner / ex-partner linkage as stored for the Service, face-verification status and similarity scores (not used to rebuild your face for unrelated purposes)
• Device and security signals: device identifiers, IP addresses associated with abuse prevention, admin block history
• Match metadata (who matched with whom and status/dates) — not the private text of First Light / couple chat messages
• User reports you submit or that are submitted about you (reason, details, context such as swipe / chat / diary) — report context does not load private chat or diary contents into the Control Panel
• WeFell for Business records needed for partner review: business name/email/phone, verification status, PAN and verification media where collected for business KYC, venue and ad/campaign records, business payment records (amounts, product IDs, status — not your full card number)
• Aggregated Service metrics (counts of users, reports, businesses, etc.)
What authorised Gift Admins may see
• Gift catalogue products and categories
• Gift-store analytics (clicks, top products/partners) which may include the name/email of a user who clicked a gift listing, for fraud and catalogue integrity review
What Control Panel staff cannot browse as a general feature
• Private First Light / couple chat message bodies
• Shared diary entry text and diary photos (admins do not have a diary reader in the Control Panel)
• Open When letters and private Journey notes as a browsable inbox
(If you permanently delete your account, related chat/diary/Journey data is removed as part of account deletion processing described in Section 16.)
Actions authorised staff may take
• Block or unblock a user account for safety or policy violations (with a reason)
• Permanently delete a user account when required for safety, abuse, or legal compliance (subject to safeguards — staff cannot use the panel to delete another Super Admin account)
• Mark user reports as reviewed
• Suspend or reactivate a WeFell for Business account
• Approve, reject, or block partner ads/campaigns and related business content
• Create, update, hide, or remove Gift Store products (Gift Admin)
Access controls
• Only email-allowlisted staff accounts can open admin APIs / Control Panel features
• Access is restricted on a need-to-know basis
• WeFell does not sell Control Panel data exports to third parties
If our Control Panel capabilities materially expand beyond this Section 14, we will update this Privacy Policy before relying on that broader access.
────────────────────────────────────────
15. INTERNATIONAL TRANSFERS
────────────────────────────────────────
Yes — data may be stored and processed outside your country of residence (for example in regions used by MongoDB Atlas, Cloudinary, Railway/Render, Google, or Apple). Where required, we rely on appropriate safeguards such as contracts with processors, access controls, and encryption in transit (HTTPS/TLS).
────────────────────────────────────────
16. DATA RETENTION, BREAKUP & ACCOUNT DELETION
────────────────────────────────────────
• Active accounts: we keep profile, photos, matches, messages, diary, Journey, and purchase records while your account remains open.
• Couple breakup (Delete Diary): when either partner confirms breakup in-app after reviewing memories, the shared diary is closed for both partners and both return to discovery/dating mode. The diary is soft-archived for up to 30 days so you can choose to get back together and restore it from where you left off (get-back may require both partners to confirm, as designed in the product). During that grace window the diary is not shown in the normal couple experience.
• After the 30-day grace window: if you do not restore the relationship, the archived diary and its entries are permanently deleted from active systems and cannot be restarted.
• Account deletion: you may delete your account in-app (Profile / Settings → Delete account) or by emailing manassawant2499@gmail.com from your registered email. When you delete, we permanently remove personal data from active systems promptly (including related matches, chat, diary/Journey media where applicable). Residual copies in encrypted backups may persist for a limited period (typically up to 30 days) before being overwritten, except where we must retain specific records for legal, tax, safety, fraud, or dispute purposes (for example certain report/moderation records and admin block history).
• Face verification selfies: deleted after processing; descriptors removed with account deletion (subject to the limited exceptions above).
• OTP records: short-lived.
• Business partner soft-delete windows (where offered) are described in Section 25 (WeFell for Business).
────────────────────────────────────────
17. YOUR RIGHTS (INCLUDING GDPR & CCPA/CPRA)
────────────────────────────────────────
Depending on your location, you may have rights to:
Access / know — request categories and a copy of personal data we hold about you
Correction / rectification — update editable profile fields in-app; request correction of inaccurate data by email
Deletion / erasure — delete your account in-app or request deletion by email
Portability — request a machine-readable export of data you provided, where applicable
Withdraw consent — revoke camera, location, or notification permissions in device settings (some features may stop working)
Object / restrict — object to certain processing based on legitimate interests, where the law allows
Non-discrimination (CCPA/CPRA) — we will not discriminate against you for exercising privacy rights
Do Not Sell or Share (CCPA/CPRA) — WeFell does not sell personal information and does not "share" it for cross-context behavioural advertising as those terms are commonly defined under CCPA/CPRA. If our practices change, we will update this Policy and provide required notices/opt-outs.
Limit use of sensitive personal information (CPRA) — we use sensitive categories (for example precise location, photos, face verification data) only as needed to provide WeFell and for security/compliance, not for unexpected secondary advertising
CalOPPA: users may review this Policy in-app; you may request access/changes to personal information via the contact email below; we notify of material changes as described in Updates.
To exercise rights, email manassawant2499@gmail.com from the email address linked to your WeFell account. We may verify your identity before responding. We aim to respond within timelines required by applicable law (and for India DPDP grievances, we aim to acknowledge within 72 hours and resolve within 30 days where reasonably possible).
Rights that are intentionally limited by product design:
• Date of birth is not manually editable after signup (age updates automatically)
• Gender is not editable after signup
────────────────────────────────────────
18. SECURITY
────────────────────────────────────────
We protect data using measures appropriate to the nature of a dating/relationship app, including:
• HTTPS/TLS for API communication
• Secure authentication (OTP / Google Sign-In) and server-side authorisation checks
• Device binding to reduce multi-account abuse
• Rate limiting on sensitive endpoints
• Restricted staff access on a need-to-know basis via the Control Panel (Section 14)
• Cloud provider security controls and encrypted storage/transit where offered by processors
• Automated and manual moderation tools for uploads
No method of transmission or storage is 100% secure. Keep your device locked, do not share OTP codes or couple invite codes, and report suspected account compromise to us immediately.
────────────────────────────────────────
19. AUTOMATED PROCESSING
────────────────────────────────────────
We use automated systems for face matching, optional age estimation, upload moderation scoring, discovery ranking, and temporary restrictions after repeated unique reports. These systems may affect feature access or visibility. Where law requires human review of significant decisions, contact us.
────────────────────────────────────────
20. OFFLINE MEETINGS & SAFETY
────────────────────────────────────────
WeFell helps people connect, including offline meetups. We provide product safeguards (age checks, face verification, reporting, discovery filters, partner venues that favour public spots), but we do not supervise offline meetings and cannot guarantee another person's behaviour.
Practical precautions: meet in busy public places; prefer daytime/early evening; tell a trusted person your plans; arrange your own transport; keep early plans in-app where you can Report; trust your comfort level and leave if something feels wrong.
────────────────────────────────────────
21. DATA BREACHES
────────────────────────────────────────
If we become aware of a personal data breach likely to affect your rights, we will investigate, contain, remediate, and notify you and regulators as required by applicable law without undue delay.
────────────────────────────────────────
22. LEGAL COMPLIANCE FRAMEWORKS COVERED
────────────────────────────────────────
This Policy is drafted to support compliance expectations under:
• India's DPDP Act, 2023 (including grievance contact)
• GDPR (where WeFell offers services to individuals in the EEA/UK or otherwise falls in scope)
• CCPA/CPRA (California)
• CalOPPA (California)
• COPPA — WeFell does not collect from children under 13; Service is 18+ only
Nothing in this Policy is legal advice. If you need counsel for your jurisdiction, consult a qualified lawyer.
────────────────────────────────────────
23. PRIVACY POLICY UPDATES
────────────────────────────────────────
We may update this Privacy Policy from time to time.
• The "Last updated" date at the top will change
• Material changes may be highlighted in the app and/or by email to your registered address where appropriate
• Continued use after the effective date means you accept the updated Policy unless law requires fresh consent
────────────────────────────────────────
24. CONTACT
────────────────────────────────────────
Privacy questions, access/deletion requests, and grievances (users and business partners):
Email: manassawant2499@gmail.com
App: WeFell (in-app Settings / legal screens also link to this Policy)
Business partners may also use Business → Settings → Email WeFell support.
────────────────────────────────aDATA SECTION)
────────────────────────────────────────
This Section 25 is part of the same WeFell Privacy Policy. It explains extra data WeFell processes when you use WeFell for Business. Commercial rules (refunds, listings, payments, partner obligations) are in the separate WeFell Business Terms & Conditions — not in this Privacy Policy.
Who this covers
• Venue owners verifying via Google Business Profile
• Gift product sellers listing on the WeFell Gift Store
• Businesses running swipe-screen advertisements on WeFell
• Authorised business account holders and their staff
Information we collect from business partners
Registration & identity
• Owner name, phone number, and business email
• Email verification OTP
• Reference face photo and live selfie face match (same WeFell verification technology as consumer users)
• Google account email used for Business Profile verification (venues)
Venue verification
• Café/venue name as listed on Google Maps / Business Profile
• Google Place ID when verification succeeds
• Verification attempt logs, IP addresses, and device identifiers for abuse prevention
• Google Play payment records for venue verification
Gift listings
• Product URLs (Amazon, Flipkart, Myntra, Ajio only)
• Auto-fetched product title, price, description, images
• Monthly subscription payment records (via Google Play)
Advertising
• Ad creative (images/videos), title, description
• Destination settings (Play Store package, website URL, or none)
• Impression, click, and engagement analytics
QR & visits
• QR scan events when you scan a WeFell couple's visit code
• Timestamp and venue associated with each scan
Payments
• All WeFell Business payments are processed by Google Play. We store transaction IDs, product IDs, amounts, and purchase categories. WeFell does not store your card details.
• WeFell does not currently require PAN number or PAN document upload during standard business onboarding. If a future compliance step asks for tax identity documents, we will update this Policy before collecting them.
How we use business partner data
• Verify identity and business legitimacy
• Display your venue on the WeFell Journey Map or product in the Gift Store
• Show your ads in the WeFell Discover swipe feed
• Prevent fraud, abuse, and fake listings
• Send subscription renewal reminders (gift sellers)
• Provide analytics (scans, impressions, clicks)
• Enforce verification attempt limits and block accounts after repeated failures
• Notify WeFell admin of blocked accounts requiring review
WeFell does NOT sell your business contact list, share private verification face photos with dating users, or use business data for unrelated advertising outside WeFell.
Sharing
Same processor categories as elsewhere in this Policy (Cloudinary, MongoDB, Railway/Render or equivalent, Brevo/SMTP, Google Sign-In / Business Profile / Play Billing). Authorised WeFell staff may review business/partner records in the Control Panel as described in Section 14 (including blocked-account details for fraud review). Users see venue name, discount, photos, and gift product details — not private verification media.
Business retention & deletion
• Active business accounts: retained while the account is active
• Payment records: retained for tax/disputes (typically up to 7 years where required)
• Soft-deleted accounts: 15-day restore window via business email OTP; face photo kept during that window
• After 15 days without restore: permanent closure; identity media removed or anonymised except where law requires retention
• Your WeFell Business account is separate from any personal WeFell user account — deleting one does not delete the other
For refunds, impression delivery after deletion, and partner commercial obligations, see the WeFell Business Terms & Conditions.
Thank you for trusting WeFell with your story.