Ammye

Privacy Policy

Last updated: 25 September 2026

This policy explains what Ammye collects, why, who else sees it, how long we keep it, and how you get it out or delete it. It describes what the app actually does — where something is not built yet, we say so.

Who we are

Ammye is a dating app operated from Malaysia by Izzul Aizad ("we", "us"), who is the data controller for the personal data described here.

Contact for anything in this policy, including data requests: support@ammye.com.

Who may use Ammye

Adults only (18+). We ask for your date of birth during setup and derive your age from it on our servers; an account without an adult date of birth cannot reach matching. We do not knowingly collect data from anyone under 18 — if you believe a member is under 18, tell us and we will act on it.

What we collect

WhatWhy we have it
Account and profile — email address, name, date of birth and derived age, gender, who you are looking for, location, height, smoking and drinking answers, your filters, your match margin, content preferences, verification state To create your account, show you to people who fit your filters, and show you people who fit yours
Profile photo — the image you upload So members can recognise you. We store a re-encoded copy (max 1440 px, JPEG) with no EXIF or GPS metadata; your original file is never stored, and the bucket is private
Answers to questions, including edits, and questions you submit They build how well you match with others — that is the product, not a side effect
Activity — clicks sent and received, mutual matches, profile views, conversations and messages To run matching and chat, and to keep the counts you see in the app correct
Safety records — people you block, reports you file, reports about you, moderation actions To protect members and to act on reports. Report rows are kept as evidence after they are resolved
Purchases — which plan you hold, when it renews or ends, and the store's transaction reference To give you what you paid for and to keep the plan correct. Card details never reach us — the app stores handle payment
Device push token and your per-device notification choices To deliver notifications you asked for; the token is deleted when you log out, delete the account, or when the store tells us the app is gone from that device
Technical logs — one line per request: method, path, status, duration, a request id, and your user id when you are signed in To run and secure the service. Request and response bodies are never logged, and credentials and personal fields (tokens, passwords, e-mail, date of birth) are redacted before writing
Feedback and bug reports you send usTo fix what is broken

No analytics SDK and no crash-reporting vendor is installed in the app today. If that changes, this policy changes with it before the release that contains it.

What we do not do

Who else processes it

We use a small number of service providers, each of which sees only what its job requires:

ProviderWhat it does for us
SupabaseDatabase, authentication and private photo storage (the processor hosting your data)
RenderRuns our API and background workers, and holds the request logs above
ResendDelivers account emails (verification codes, password resets)
ExpoDelivers push notifications to your device
Apple App Store / Google PlayHandle payment and subscription management when you buy a plan

Our own moderation operators see reports, the content they relate to, and the minimum profile information needed to act. Operator actions are recorded in an audit trail.

How long we keep it

Your choices and rights

To make a request you cannot make in the app, email support@ammye.com and we will respond within 30 days.

What deletion actually removes

Deleting your account removes your profile and photo, your answers and answer history, the questions you submitted and every answer and skip other members left on those questions, your clicks and matches, the conversations you were part of (including the other member's messages in them), profile views, blocks and reports in both directions, feedback, and your purchase records. Your photo is removed from storage and your email is removed from our authentication provider. Your current session is revoked.

Two consequences members notice: blocking somebody deletes the conversation permanently, and deleting your account removes other people's answers to your questions.

Security

Connections are encrypted in transit. Photos live in a private store and are served only as short-lived signed links. Access tokens are verified on every request against the project's published signing keys. Passwords are never stored by us — Supabase Auth holds them — and we refuse a new password that matches your current one or your last five.

Changes to this policy

When we change this policy we update the date at the top, and for anything significant we tell you in the app before the change takes effect.

Contact

support@ammye.com — see also Support.