Bohri Connect

Privacy Policy

Bohri Connect Version 1.0 · Effective 15 August 2026 · Last updated 19 August 2026


In short

We are a matrimonial platform for the Dawoodi Bohra community. Everything below comes down to a few commitments:


1. Who we are

Bohri Connect is operated by iByte Apps Limited, a company registered in England and Wales, company number 09504342, registered office Barton Seagrave, Northamptonshire, NN15, England.

For UK data protection law, we are the data controller for your information.

Privacy contact privacy@bohriconnect.com
General support support@bohriconnect.com
ICO registration ZB033543
India grievance officer Shabbir Khilawala, shabbir@bohriconnect.com — required by the DPDP Act
EU representative Shabbir Khilawala, shabbir@bohriconnect.com — UK GDPR Art 27

2. Who can use Bohri Connect

You must be 18 or older. If the law where you live sets a higher age of majority, that age applies to you.

We verify age against identity documents. If we believe an account belongs to someone under 18 we remove it and delete the data. We do not knowingly collect information about children.


3. What we collect

3.1 Things you give us

What Why Lawful basis (UK GDPR)
Email address It is how you sign in, and how we tell you when your profile has been reviewed Contract
Mobile number Optional. A verification badge, and a way back in if you lose access to your email Contract
First name Shown on your profile Contract
Date of birth To confirm you are 18+ and show your age Contract, legal obligation
Gender Determines who sees you and whom you see Contract
Photographs Your profile Contract
Profile details — height, education, work, languages, marital status, children, family plans, household preference, community involvement Matching and filtering Contract
Location — country and city Showing you people nearby Contract
Prompt answers, notes and messages The service itself Contract

We deliberately do not collect income, caste, political views, smoking or drinking habits, or astrological information. Nobody can filter on them because we never ask.

3.2 Identity and verification

What Why Lawful basis
Verification selfie (facial recognition) To confirm you are a real person, and to check that your photographs are of you Explicit consent — UK GDPR Art 9(2)(a)
Identity document — passport, Aadhaar, licence or national ID To confirm your name and age Legal obligation, legitimate interests (fraud prevention)
Community verification photo (topi or rida) To confirm community membership Consent

Biometric data. The verification selfie uses facial recognition. That is special category data under UK GDPR Article 9 and requires your explicit, separate consent, which we ask for on its own screen before anything is captured.

Identity documents. Encrypted, viewed by one named reviewer, and permanently deleted within 7 days. We keep only the outcome. We never store the document number.

Community verification photos are used for verification only and are never shown on your profile.

3.2a Where you live

We ask for your location once, and only once. You can decline and type your town instead — nothing in the app is closed to you if you do.

What we keep: the town or suburb, the county or district it sits in, the country, and the coordinates of that one reading.

⚠ Other members never see your street, and never see a distance. The number of miles between two people is never shown anywhere in the app — not on a profile card, not on a full profile, not after you match.

We do not use it to decide who you are shown, either. Profiles are ordered by what you have in common — shared interests, whether you both want children — and never by who happens to live nearest. Your location is used for one thing only: if a member has chosen to search within a set distance, we work out whether you fall inside it. Nothing else in the app reads it.

What other members see:

Before you match Your county or district — "Northamptonshire", "Pune"
After you both say yes Your town — "Barton Seagrave", "Kondhwa, Pune"

We check where you are when you open the app. Which country you can search in depends on where you live, and that only means anything if it stays true — so when you open BohriConnect we look at where you are and compare it with the region on your account.

What that does not mean, and these are the parts worth reading:

You can also change your location yourself in Settings.

Turning a reading into a town name means asking somebody who knows the map. We use Google for that, and it is listed with our other processors in section 6. What we send them is a pair of coordinates and nothing else — not your name, not your account, not your device, not your phone's connection. The request goes from our servers, not from your phone, so Google is never told which of our members asked or where they were connecting from.

We do not keep your exact reading. Before anything is saved we round it to roughly a kilometre — enough to know that Barton Seagrave is nearer to Kettering than to Leicester, nowhere near enough to point at a house. The precise reading exists for the few seconds it takes to name your town, and is then gone. It is never written down, so there is nothing precise about your home in our database for anybody to lose, leak or be compelled to hand over.

When you delete your account, the coordinates go with it. They are not in any of the exceptions in section 9.

3.3 Your contacts — we do not collect them

The app does not ask for access to your contacts and never reads your address book.

An earlier version of this policy described a "hide me from my contacts" feature, in which numbers were scrambled on your phone and only the scrambled values sent to us. That feature has been removed and no such data was ever collected. There is no contacts permission in the app.

We have never messaged anyone's contacts and never will. No invitations, no "your friend has joined", ever.

3.4 Things we collect automatically

What Why Lawful basis
Device type, operating system, app version Making the app work and diagnosing faults Legitimate interests
IP address and approximate location Security, fraud prevention, region-appropriate settings Legitimate interests
Sign-in times and device identifiers Detecting compromised accounts Legitimate interests
How you use the app — screens, actions, timings Improving the product. Some of this goes to Google Analytics; section 12 says exactly what does and does not Legitimate interests
Crash reports — what the app was doing when it stopped working, your phone model and app version Finding and fixing faults. This goes to Firebase Crashlytics; section 12.2a says exactly what is in one Consent — you can turn it off in the app

3.5 Things others tell us about you


4. What we do with it

4.1 Running the service

Creating your account, showing you profiles, delivering interests and messages, generating your daily set, applying your filters, taking payment.

4.2 Keeping people safe

This is the part that matters most on a platform like this one.

4.3 Moderation access to your conversations

Our moderators can read a conversation when it is attached to a report. They cannot browse conversations at will, and every time one is opened it is recorded — who opened it, when, and for how long.

4.4 Understanding how the app is working

During our launch period, a single named administrator can view a member's complete activity, including messages, in order to understand how the product is being used and to find faults.

Note to you, not to members: this clause exists because the capability exists. If you turn the flag off before launch, delete this section. If you keep it, this wording must stay — an undisclosed capability of this kind is the single largest regulatory exposure in the product.

4.5 Improving the product

Aggregate statistics — how many people complete signup, which step they leave at, how many interests become conversations. These cannot identify you.

4.6 What we never do


5. AI features

Some features use automated processing:

Feature What happens
Writing help Not switched on at the moment. Where it is offered: if you ask for it, we send only the words you typed to OpenAI, which suggests a rewrite. You always decide whether to accept
Compatibility highlights Not switched on at the moment. Where it is offered: shows what you and another member have in common. There is no compatibility score, and no ranking of people
Profile checks Text you write for your profile is checked automatically before it is published. This is the one AI feature you do not choose — see 5.1
Photo checks Your photographs are checked automatically, and compared to your own verification selfie by software. Nothing is refused by software alone, and your face is never matched against anybody else's — see 5.2
Message screening Described in 4.2

5.1 Checking profile text before it is published

Everything you write for your profile — your description of yourself, what you are looking for, your job title, your qualification, where you studied, and your prompt answers — is already read before it appears, because nothing on a profile is published unchecked. Until now that reading was done entirely by a moderator. It is now done first by OpenAI, and only then, if needed, by a person.

This applies to profile text only. Your messages and your notes are between you and one other person, and we do not send them anywhere. See 4.2 for what happens to messages, which is a different process running on our own servers.

What the check can do: if your text is clear, it is published — often within a minute of you saving it, rather than after a wait for a moderator.

What the check cannot do: it cannot reject anything, and it cannot tell you anything. If it has any doubt at all, your text goes to a moderator to be read by a person, exactly as it would have before this existed. Every rejection you will ever receive was written by a human being.

We do this because it lets us look at every profile properly. The things we are looking for are the things a moderator was looking for anyway: contact details and social handles, somebody else's phone number, advertising, demands for money, pressure to move the conversation off the app, anything suggesting the writer is under 18, slurs, sexual or abusive language, and political or sectarian campaigning. Our community guidelines describe each of these; the automatic check adds nothing to that list.

Ordinary life is not flagged. Naming your community, your sect, your language or your country is not a slur. Practising your faith is not campaigning. Your job, your salary band, a divorce, a disability or your family circumstances are not, on their own, anything at all.

If the check is unavailable, nothing is published. When OpenAI cannot be reached, or answers in a way we cannot read, your text simply waits for a moderator. It is never published on the strength of a check that did not happen.

5.2 Checking your photographs

Every photograph you upload is checked automatically by Amazon Rekognition before it appears. It looks for three things: what is in the picture, whether anything is written on it, and roughly how old the people in it appear to be.

If it finds nothing, your photograph is published. Often within a minute of you uploading it, rather than after a wait for a moderator.

If it finds anything at all, your photograph waits for a person, exactly as it would have before this existed. The automatic check can publish a photograph; it can never refuse one. Every refusal you receive was decided by a human being who looked at your picture.

A person still looks afterwards. Photographs that publish automatically go into a queue our moderators work through, and one can be removed later if something was missed. You are told if that happens, and why.

We check that your photographs are of you, and software does that comparison. Each photograph in your profile grid is compared against your verification selfie by Amazon Rekognition. If they match closely enough, your profile can go live without anybody reading it.

Anything the software is unsure about goes to a person, and is never refused by software alone. A photograph it cannot match is held back — not deleted, not marked as false — and a moderator looks at it. There are ordinary reasons a real photograph of you does not match: a childhood picture, a group shot where you are small, a heavy filter, or simply a covered head, which these systems are measurably worse at. None of those is dishonesty, and none of them is treated as dishonesty.

Photographs attached to prompts are not compared to your face at all. They can be a place, a meal, a view, or your friends. They are still checked for the things section 5.2 describes.

About faces, precisely

We want to be exact here, because "facial recognition" means several different things and only some of them are true of us.

What we send to Amazon, and what we do not

We send the image and nothing else. Not your name, your age, your location, your account identifier, or any other photograph. Amazon is asked what is in a picture; it is not told whose picture it is, and it cannot be, because we never send anything that would say.

Your photographs are not stored by Amazon. They are sent for the length of one request and are kept only by us, under section 9's retention rules. Amazon does not train on them — this is a configuration commitment on our account, in the same way as section 5's promise about OpenAI.

Your verification selfie is sent to Amazon, for one purpose only. It is sent alongside one of your own photographs so the two can be compared, for the length of that request, and Amazon does not keep it. This changed on 14 August 2026 — it used to stay on our systems entirely.

It is never compared to anybody else's face, never added to a database, and never used to search for you anywhere.

We keep it for as long as your profile exists. It used to be deleted 30 days after a moderator had looked at it. It is kept now because it is what every future photograph you add is checked against — including photographs you add months from now. It goes when your account goes, under section 9.

You can see it. It is in Settings → Your data, in the app. You can look at it whenever you like; you cannot replace it there, because a selfie that could be swapped after your photographs had been checked against it would not be a check at all. Re-verification replaces it (section 4).

If the checker is unavailable, nothing is published. Your photograph waits for a moderator. It is never published on the strength of a check that did not happen.

What we send to OpenAI, and what we do not

Writing help, compatibility highlights and the profile check in 5.1 use OpenAI's API. We are deliberately narrow about what leaves our systems.

When you ask for writing help, we send the text you typed and the question you were answering. That is all. We do not send your name, your age, your city, your country, your gender, your marital status, your photographs, your account identifier, or anything else from your profile. OpenAI is asked to improve a sentence and is told nothing about whose sentence it is.

The profile check sends the same two things — the text and the question it answers — and nothing else. Not your name, your age, your location, your photographs or any identifier. OpenAI is asked whether a sentence contains a phone number; it is not told whose sentence it is, and it cannot be told, because we never send anything that would say.

Compatibility highlights send answer codes, not sentences. Where you and another member have each answered the same structured question, we send the two sets of answers as codes — not your words, not your names, not your profiles. The result is stored and never generated again for that pair.

We never send your private messages to OpenAI. Message screening (section 4.2) runs on our own servers.

OpenAI does not train on anything we send. We use their API under settings that exclude our data from model training and, where offered, from retention. This is a contractual and configuration commitment, not a preference.

Writing help and compatibility only happen if you use them. If you never tap writing help, nothing you type is ever sent for it. The profile check in 5.1 is different, and we want to be plain about it: it runs on profile text you have submitted, whether or not you asked, because publishing unchecked profiles to strangers is not something we are willing to do. It does not run on anything private.

No decision that materially affects you is made by a machine alone. Photo rejections, text rejections, suspensions and bans are all made by a person. What software decides by itself is only ever to publish — your words, your photographs, or your profile — all of which you wrote or uploaded and asked us to publish. It can hold something back for a person to look at. It cannot refuse you. You have the right to ask for human review of any automated decision (section 10) — and for profile text, a human review is what a refusal already is.


6. Who else sees your information

We do not sell your data and we do not share it for anyone else's marketing. We do use other companies to run the service, and they only ever process data on our instructions:

Who What for Where
Fasthosts Internet Limited Servers and databases United Kingdom
OpenAI The profile-text check in section 5.1. Also writing help and compatibility highlights, where those features are switched on United States
Amazon Web Services (Rekognition) The automatic photograph check in section 5.2, and comparing your photographs to your own verification selfie Europe
Amazon Web Services (SES) Sending you email: your sign-in link, confirming your address, the outcome of your review, your deletion receipt, and the link to a data export you asked for. It handles your email address, and your name where a message uses it United States
Apple, Google Payments and app distribution Global
Google Firebase Push notifications, and confirming a phone number Global
Google Analytics Understanding how the website and the app are used, as described in section 12. Never told who you viewed, what you wrote, or your name, photographs, phone number or email Global
Google Maps Platform Turning one set of coordinates into a town name, as described in section 3.2a. Sent from our servers, never from your phone, and never with anything identifying you attached Global

Each is bound by a written data processing agreement.

Other members

Other members see your profile as described in the app: your first name, age, city, photos and prompt answers. Some details unlock only when interest is mutual. Your phone number, your email address and your date of birth are never shown to another member.

When the law requires it

We may disclose information where we are legally required to, or where it is necessary to prevent serious harm — including to law enforcement in cases involving fraud, threats of violence, or the safety of a child. Anything involving a child is reported without exception.


7. Where your information goes

We are a global community and our members are in many countries.

Your profile, your messages and your photographs are stored in the United Kingdom. Our servers and databases are hosted here, by Fasthosts Internet Limited.

Some of the companies listed in section 6 process data outside the UK. The photograph checks in section 5.2 run in Europe. The profile-text check in section 5.1 and the email we send you both run in the United States, and Apple, Google and Firebase operate globally. Where we transfer personal data out of the UK we rely on the UK International Data Transfer Addendum to the European Commission's standard contractual clauses, together with the additional safeguards described in section 5: the checks are sent the minimum they need and never your name. That mechanism is for the transfers to the United States. European processing needs none of it — UK law already treats Europe as providing an equivalent standard of protection.

One exception, stated plainly: your verification selfie is sent to Amazon, alongside one of your own photographs, for the single purpose of comparing the two. It stays in Europe — your face does not cross the Atlantic. It is sent for the length of that comparison, is not stored there, and is never compared against anybody else. Section 5.2 explains why.

For members in India, we comply with the DPDP Act 2023 in addition to UK law.


8. How we protect it

No system is perfectly secure, and we will not claim otherwise. If a breach occurs that is likely to put you at risk, we will tell you and the ICO within the required timescales.


9. How long we keep things

What How long
Your profile and photos Until you delete your account
Identity documents Deleted within 7 days of review
Verification video Never stored. The video is discarded; a single still frame from it is kept — see the row below
Verification selfie (the still frame) Until you delete your account. It is compared against each photograph you add, so it has to outlive the day you were verified. You can see it in Settings → Your data
Withdrawn conversations 90 days
Blocked conversations 12 months
Reported conversations 24 months
Family link viewer numbers 90 days after the link expires
Moderation records 3 years — needed to handle appeals and repeat conduct
Payment records 7 years — UK tax law
Scrambled email address after deletion 30 days, so a removed account cannot immediately return. And a scrambled phone number, if you verified one

When you delete your account

Your profile, photos, prompts, conversations, interests, share links and your verification selfie are deleted immediately.

Three things survive, each for a stated reason:

  1. A scrambled version of your email address, for 30 days — and of your phone number, if you verified one. So someone removed for serious misconduct cannot immediately re-register. Neither identifies anything on its own.
  2. Moderation records, if you were reported or subject to enforcement. Needed for appeals and for the safety of others.
  3. Your success story, only if you explicitly agreed to it. If you told us you were leaving to marry and ticked the box allowing us to contact you, we keep your name and number for that purpose alone. You can ask us to delete it at any time. If you did not tick it, nothing is kept.

10. Your rights

Under UK GDPR and the DPDP Act you can:

Right What it means
Access Ask for a copy of everything we hold about you
Rectification Have anything inaccurate corrected
Erasure Have your data deleted — this is the delete function in the app
Restriction Ask us to stop using your data while a dispute is resolved
Portability Receive your data in a machine-readable format
Object Object to processing based on legitimate interests, including section 4.4
Withdraw consent For anything based on consent, including biometric verification
Human review Ask a person to review any automated decision
Nominate (India) Nominate someone to exercise your rights if you die or become incapacitated

How: privacy@bohriconnect.com, or "Download my data" in Settings. We respond within 30 days.

If you are unhappy: contact us first, then the Information Commissioner's Office (ico.org.uk) in the UK, or the Data Protection Board in India.


11. Notifications and marketing


12. Cookies and analytics

We never use advertising cookies, and we never allow anyone to build an advertising profile of you from what you do here. That has not changed and will not.

12.1 On our website

Our website uses cookies that are strictly necessary to make sign-up, share links and account deletion work.

We also use Google Analytics to understand how people find and use the public parts of the site — how many arrive, which pages they read, and where they stop. This sets cookies and tells Google your IP address, your approximate location, and which pages you opened.

It is switched off on the pages where it would identify you:

We exclude those deliberately. A referral link contains the code of the agent who gave it to you, and the sign-up pages carry your name and email — none of that goes to Google.

12.2 In the app

We use Google Analytics for Firebase to see which screens are used, where people get stuck in sign-up, and which features go unused. It records an app instance identifier, your device type and approximate region.

It never records:

We do not use it to track you across other companies' apps or websites, and we do not enable Google's advertising features on it.

12.2a Crash reports

When the app stops working, we send a report to Firebase Crashlytics so we can find out why. A report contains the technical trace of what the software was doing at the moment it failed, your phone model, your operating system version, the app version, and an installation identifier that is specific to this app on this handset.

It never contains:

The one thing we attach on purpose is which plan you are on, because some faults only affect one, and a plan describes thousands of people rather than one.

12.3 Turning it off

Analytics and crash reports are two separate switches in Settings → Your data, and you can change either at any time. Nothing else about the app changes when you do.

Turning crash reports off also deletes any report still waiting on your phone to be sent. Neither switch removes what has already been sent — see section 10 for asking us to delete it.

On the website, refusing analytics cookies leaves everything working.


13. Changes

If we make a material change we will tell you in the app and by email, and ask you to accept the new version before continuing. Every version is dated and previous versions are available on request.


14. Contact

Privacy privacy@bohriconnect.com
Support support@bohriconnect.com
Post iByte Apps Limited, Barton Seagrave, Northamptonshire, NN15, England
India grievance officer Shabbir Khilawala, shabbir@bohriconnect.com
EU representative Shabbir Khilawala, shabbir@bohriconnect.com

Bohri Connect is an independent platform. It is not affiliated with, endorsed by, or operated on behalf of any religious authority or institution.