LEGAL

Privacy Policy

What we collect, why we collect it, who it goes to, and what you can ask us to do about it. We have tried to write this so it can actually be read.

14
Sections
41
Policy points
18+
Adults only
1Who we are

Phizley Technologies Private Limited ("phizley", "we", "us") operates the phizley mobile application and this website. Our registered office is at TODO — Registered office address line 1, TODO — Address line 2, TODO — City, TODO — State TODO — PIN, India.

We are the Data Fiduciary for the personal data described in this policy, as that term is used in India's Digital Personal Data Protection Act, 2023. If you are in the EEA or the UK, we are the Controller for the purposes of the GDPR.

phizley is an 18+ service. We do not knowingly permit anyone under 18 to create an account or use the app.

2What we collect

We collect the following, and nothing beyond it. Where a category is optional, the app works without it, though some features will not.

Account data — your mobile number, and a one-time code sent to it to prove you control it. Phone number is how you sign in; there is no password.
Profile data — display name, date of birth, gender, country, avatar selection, and a short bio if you write one. Date of birth is used to enforce the 18+ requirement.
Identity verification (optional) — if you choose to get verified, or apply to become a host, a selfie is processed by our verification provider to confirm you are a real, adult person. We receive the pass or fail result and a verification reference.
Call metadata — who called whom, when, for how long, the call type, and how it ended. This is what billing and dispute resolution are based on.
Call content — audio and video are transmitted between participants over WebRTC. We may monitor, review or record calls where it is necessary for safety, quality or legal compliance. Calls are not recorded routinely, and where a recording is made it is kept for up to 90 days and then deleted.
Messages and content you post — chat messages, captions, comments, and anything else you write or upload. These are stored so they can be delivered and displayed.
Wallet and transaction data — coin balance, ledger entries, purchases made through the App Store or Google Play, and host earnings and payouts.
Device and technical data — device model, operating system version, app version, IP address, and a push notification token.
Safety and moderation records — reports you file or that are filed about you, blocks, and records created by our automated content filter.
3What we do not collect

Stating this plainly, because it is what people most often assume:

We do not access your contacts, photo library, precise location, calendar, or messages outside the app.
We never receive your card, bank, or UPI details. All purchases are handled by Apple or Google; we are told only that a purchase succeeded and which product it was for.
We do not use third-party advertising SDKs, and we do not track you across other companies' apps or websites.
We do not sell or share personal data for cross-context behavioural advertising, as those terms are defined under the CCPA/CPRA.
4Why we use it, and our lawful basis
To operate the service — signing you in, connecting calls, delivering messages, and maintaining your wallet. Basis: performance of our contract with you; consent under the DPDP Act.
To take payment and pay hosts — processing coin purchases and calculating and settling host earnings. Basis: contract, and compliance with tax and accounting obligations.
To keep the service safe — verifying age and identity, filtering objectionable content, acting on reports, monitoring or recording calls where necessary to investigate one, and detecting fraud and abuse. Basis: legitimate interests, and our obligations under the IT Rules 2021.
To notify you — incoming call alerts and service notices. Basis: contract. Marketing messages, if any, are sent only with your consent and can be withdrawn at any time.
To meet legal obligations — responding to lawful requests, retaining records we are required to retain, and cooperating with child-safety authorities. Basis: legal obligation.
5Automated content filtering

Text you send or publish — messages, captions, comments, display names and bios — is checked automatically against a list of prohibited patterns before it is saved. Content that matches is refused, and a moderation record is created describing what was blocked.

This is a pattern check, not a decision about you as a person, and it does not by itself suspend or restrict your account. Where a match is serious, a human moderator reviews the record before any action is taken. You can contest any decision by writing to our Grievance Officer using the details below.

6Who we share it with

We share personal data only with the processors below, only for the purposes listed, and only to the extent needed. We do not sell personal data.

MSG91 — sends the one-time code to your mobile number. Receives your phone number.
HyperVerge — performs identity and liveness verification when you request it. Receives your selfie and returns a result.
Apple and Google — process in-app purchases and deliver push notifications. We receive purchase confirmations and use a push token.
Razorpay — processes host payouts. Receives the payout details a host provides.
Our cloud hosting and database providers — store the data described above on our behalf, under contract.
Law enforcement and regulators — only where we are legally required to disclose, or where disclosure is necessary to prevent imminent harm. Child sexual abuse material is reported to the appropriate authorities without exception.
7Where your data is stored, and transfers

Personal data is stored on servers located in India. Some of our processors operate infrastructure outside India; where personal data is transferred internationally, we rely on contractual safeguards with those processors and transfer only what the processor needs to perform its function.

For transfers of EEA or UK personal data, we rely on the European Commission's Standard Contractual Clauses and the UK Addendum where applicable.

8How long we keep it
Account and profile data — for as long as your account exists, and deleted when you delete it, subject to the exceptions below.
Call metadata and wallet ledger entries — retained for eight years after the transaction, as required for tax and financial record-keeping. These records are retained in a form tied to your account identifier rather than your profile.
Messages and posted content — until you or the recipient deletes them, or your account is deleted.
Identity verification results — the pass or fail outcome and its reference are retained while your account exists. The selfie itself is not retained by us after verification completes.
Moderation and safety records — retained for three years after the account is closed, so that a banned user cannot simply re-register, and so that we can respond to law enforcement about past reports.
Call recordings, where made — up to 90 days, then deleted. Access is restricted to the staff investigating the matter that prompted the recording, and every access is written to an audit log.
Device and log data — 90 days.
9Your rights

Under the DPDP Act you have the right to access a summary of your personal data and how it is processed, to have inaccurate data corrected, to have data erased where we no longer need it, to nominate someone to exercise your rights if you die or become incapacitated, and to a readily available grievance mechanism.

If the GDPR applies to you, you additionally have rights of access, rectification, erasure, restriction, portability, and objection, and the right to lodge a complaint with your supervisory authority. If the CCPA/CPRA applies to you, you have rights to know, delete, correct, and to opt out of sale or sharing — noting that we do neither.

To exercise any of these, write to privacy@phizley.com. We respond within 30 days. We may ask you to confirm control of your registered mobile number before we act, because acting on an unverified request is itself a privacy risk.

10Deleting your account

You can delete your account from inside the app, under Settings, or by requesting deletion from this website — no reinstall required. Deletion removes your profile, your posted content, your messages, and your device tokens.

Two things survive deletion, and we would rather say so than surprise you. Financial ledger entries are retained for the statutory period described above, because we are required to keep them. Safety and moderation records are retained as described above, because deleting them would let a banned account return immediately. Neither is used to contact you or to rebuild a profile.

Any unspent coin balance is forfeited on deletion. Coins are not refundable and have no cash value.

11Children

phizley is strictly for adults aged 18 and over. We collect date of birth at sign-up and refuse accounts that do not meet the age requirement.

If we learn that a minor has created an account, we terminate it and delete the associated data. If you believe a minor is using phizley, tell us immediately at support@phizley.com. Reports involving a minor are treated as the highest priority and are actioned ahead of everything else.

12Security
All traffic between the app and our servers uses TLS.
Call media is encrypted in transit using DTLS-SRTP, which is part of WebRTC.
Sign-in uses one-time codes to your mobile number; we store no passwords for member accounts.
Access to production data is restricted to staff who need it, and administrative actions are recorded in an audit log.
No system is perfectly secure. If a breach affects your personal data, we will notify you and the Data Protection Board of India as the DPDP Act requires.
13Changes to this policy

We will update this page when our practices change and revise the effective date at the top. Where a change materially affects how we use your personal data, we will tell you in the app before it takes effect. This policy is effective from 1 August 2026.

14Grievance Officer

In accordance with the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021 and the DPDP Act, 2023, the contact details of our Grievance Officer are:

Name: TODO — Full name
Designation: Grievance Officer
Email: grievance@phizley.com
Address: TODO — Registered office address line 1, TODO — Address line 2, TODO — City, TODO — State TODO — PIN, India
We acknowledge every complaint within 24 hours and resolve it within 15 days.
Need clarification?

If any section is unclear, contact us and include the section name for a faster response.