Privacy Policy
Last updated: 25 September 2026
This policy explains what Ammye collects, why, who else sees it, how long we keep it, and how you get it out or delete it. It describes what the app actually does — where something is not built yet, we say so.
Who we are
Ammye is a dating app operated from Malaysia by Izzul Aizad ("we", "us"), who is the data controller for the personal data described here.
Contact for anything in this policy, including data requests: support@ammye.com.
Who may use Ammye
Adults only (18+). We ask for your date of birth during setup and derive your age from it on our servers; an account without an adult date of birth cannot reach matching. We do not knowingly collect data from anyone under 18 — if you believe a member is under 18, tell us and we will act on it.
What we collect
| What | Why we have it |
|---|---|
| Account and profile — email address, name, date of birth and derived age, gender, who you are looking for, location, height, smoking and drinking answers, your filters, your match margin, content preferences, verification state | To create your account, show you to people who fit your filters, and show you people who fit yours |
| Profile photo — the image you upload | So members can recognise you. We store a re-encoded copy (max 1440 px, JPEG) with no EXIF or GPS metadata; your original file is never stored, and the bucket is private |
| Answers to questions, including edits, and questions you submit | They build how well you match with others — that is the product, not a side effect |
| Activity — clicks sent and received, mutual matches, profile views, conversations and messages | To run matching and chat, and to keep the counts you see in the app correct |
| Safety records — people you block, reports you file, reports about you, moderation actions | To protect members and to act on reports. Report rows are kept as evidence after they are resolved |
| Purchases — which plan you hold, when it renews or ends, and the store's transaction reference | To give you what you paid for and to keep the plan correct. Card details never reach us — the app stores handle payment |
| Device push token and your per-device notification choices | To deliver notifications you asked for; the token is deleted when you log out, delete the account, or when the store tells us the app is gone from that device |
| Technical logs — one line per request: method, path, status, duration, a request id, and your user id when you are signed in | To run and secure the service. Request and response bodies are never logged, and credentials and personal fields (tokens, passwords, e-mail, date of birth) are redacted before writing |
| Feedback and bug reports you send us | To fix what is broken |
No analytics SDK and no crash-reporting vendor is installed in the app today. If that changes, this policy changes with it before the release that contains it.
What we do not do
- We do not sell your personal data.
- We do not show your photo, name or profile to anyone you have not clicked with, beyond the matching surfaces the app itself provides.
- We do not use your messages to target advertising.
- We do not log the contents of requests or responses.
Who else processes it
We use a small number of service providers, each of which sees only what its job requires:
| Provider | What it does for us |
|---|---|
| Supabase | Database, authentication and private photo storage (the processor hosting your data) |
| Render | Runs our API and background workers, and holds the request logs above |
| Resend | Delivers account emails (verification codes, password resets) |
| Expo | Delivers push notifications to your device |
| Apple App Store / Google Play | Handle payment and subscription management when you buy a plan |
Our own moderation operators see reports, the content they relate to, and the minimum profile information needed to act. Operator actions are recorded in an audit trail.
How long we keep it
- Until you delete your account: your profile, photo, answers, submitted questions, clicks, matches, conversations and messages, profile views, blocks, reports, feedback and purchase records.
- Skipped questions: 7 days, then purged automatically.
- Signed photo links: valid 1 hour, cached for 50 minutes. They stop working after that, which is why a shared link to a photo does not last.
- Derived caches (your question deck, match list, rate-limit counters) expire on their own: minutes to 7 days, and none of them is a system of record — they are rebuilt from the database.
- Request logs: kept for a short period by our hosting provider.
- Deletion is immediate and final. We do not keep a backup copy from which your data could reappear; we also cannot recover an account once it is deleted.
Your choices and rights
- Get a copy: Settings → Download my data produces an archive of everything we hold about you. It deliberately excludes other people's data — messages you received, who clicked you, and reports about you are not in it.
- Delete it: Settings → Delete account, with a confirmation step. Read what it removes below before you do it.
- Correct it: edit your profile and filters at any time.
- Control notifications: per device, in Settings, and in your phone's own settings.
- Block anyone: from their profile or a chat. Unblocking does not restore a deleted conversation.
To make a request you cannot make in the app, email support@ammye.com and we will respond within 30 days.
What deletion actually removes
Deleting your account removes your profile and photo, your answers and answer history, the questions you submitted and every answer and skip other members left on those questions, your clicks and matches, the conversations you were part of (including the other member's messages in them), profile views, blocks and reports in both directions, feedback, and your purchase records. Your photo is removed from storage and your email is removed from our authentication provider. Your current session is revoked.
Two consequences members notice: blocking somebody deletes the conversation permanently, and deleting your account removes other people's answers to your questions.
Security
Connections are encrypted in transit. Photos live in a private store and are served only as short-lived signed links. Access tokens are verified on every request against the project's published signing keys. Passwords are never stored by us — Supabase Auth holds them — and we refuse a new password that matches your current one or your last five.
Changes to this policy
When we change this policy we update the date at the top, and for anything significant we tell you in the app before the change takes effect.
Contact
support@ammye.com — see also Support.