Privacy Policy

Effective date: 26 July 2026

Last updated: 26 July 2026

Version: 2.0

Applies to: the Emploi mobile application (Android package com.emploi.swipejobs) and emploi-swipejobs.com

About this Policy

This Privacy Policy explains how NilesoftAI, having its registered office at [REGISTERED_ADDRESS], India ("Emploi", "we", "us", "our"), collects, uses, shares, retains, and protects personal data when you use the Emploi mobile application, our website at emploi-swipejobs.com, and related services (collectively, the "Platform"). Emploi is a product of NilesoftAI (nilesoftai.com).

This Policy is issued pursuant to:

For the purposes of the DPDP Act, NilesoftAI is a Data Fiduciary in respect of the personal data it processes through the Platform, and you are a Data Principal.

If you do not agree with this Policy, do not use the Platform.

The short version. We collect what the app needs to match you with work near you: your name, email, phone, photos, skills, location, and what you do in the app. If you choose to verify your identity, we also handle a selfie and — optionally — the last four digits of your Aadhaar number, with all face and document analysis performed on your own device. We do not sell your data, do not run ads, and do not train AI models on your content. Message content is stored on our servers and is not end-to-end encrypted.

1. Scope and Applicability

1.1 This Policy applies to all users of the Platform, including Seekers (job seekers) and Givers (employers).

1.2 This Policy does not apply to third-party websites or services accessed via external links, or to anything that happens off-Platform between users; those are governed by their own policies and by the parties involved.

2. Personal Data We Collect

2.1 Data you provide directly

Category Specific fields Purpose
Identity Full name, email address, mobile phone number (India format, stored as +91XXXXXXXXXX) Account creation; OTP-based login; post-match contact between Seeker and Giver
Profile Avatar photo, headline, short bio, external bio link, selected skills, portfolio ("work") photos Discovery, matching, hiring decisions
Precise location Device GPS coordinates stored as a geographic point; named work areas (Seekers); job locations (Givers) Showing jobs/candidates within a chosen radius; server-side distance calculation
Identity verification Liveness selfie image; liveness challenge results; face-comparison scores; and, if you complete the optional Aadhaar step, the last four digits of your Aadhaar number, the name-match score, the advisory photo-match score, and the document reference timestamp. See Section 3. Confirming a real person operates the account; optionally binding the account to a government identity document; fraud prevention
Job content (Givers) Title, description, category, payment amount and type (one-time or regular), location, job image Presenting the job to relevant Seekers
Activity Swipe history (right/left, archived flag), applications, saved jobs, job invitations, acceptance/rejection of invitations, hiring outcomes Powering the discovery feed; preventing repeat cards; notifying you of outcomes
Messages Text content you send via in-app chat, timestamps, read status Communication between matched parties
Ratings and reviews Star rating, textual review you write or receive Reputation and trust system
Consent records Terms & Conditions and Privacy Policy version accepted, a cryptographic hash of the exact document text shown to you, and the timestamp of acceptance Legal evidence of consent; regulatory compliance
Support correspondence Anything you send us by email, including deletion or rights requests Handling your request; grievance redressal records

2.2 Data collected automatically

Category Specific fields Purpose
Device Push notification token, OS platform (Android / iOS), app version Delivering push notifications; compatibility diagnostics
Technical IP address (transient, processed at the network edge for rate limiting and abuse prevention), request timestamps, API errors Security, fraud prevention, debugging
Language Chosen interface language (English, Hindi, Telugu, Tamil, Kannada, Malayalam, Marathi, Bengali) Localisation
Product analytics (where enabled in a build) Pseudonymised user identifier, screen views, in-app interaction events, session replay of in-app UI Understanding usability problems and improving the app
Diagnostics Error logs, stack traces, user identifier (when available), feature context Resolving bugs and incidents

2.3 Sensitive personal data

Some of the data above is sensitive and receives additional care.

(a) Precise location. We collect location only after you grant location permission at the operating-system level, and only while the App is in use. There is no background location tracking. Coordinates are cached on your device for up to five (5) minutes to reduce battery use. If you decline permission, the App falls back to a default city-level location so it remains usable. Other users are shown an approximate distance, never your coordinates.

(b) Facial images and face-derived data. If you use identity verification, we process a photograph of your face and mathematical representations derived from it (face embeddings). All face detection, liveness analysis, and face comparison run on your device; the embeddings themselves are transient and are not transmitted to us or stored. The selfie image is uploaded to a private storage area that other users cannot read, and the numeric comparison scores are stored as an audit record. See Section 3.

(c) Aadhaar-related data. If you complete the optional Aadhaar Secure QR step, we store only the last four digits of the Aadhaar number, together with the name-match and advisory photo-match scores and the document reference timestamp. The full 12-digit Aadhaar number is not present in a Secure QR payload at all, is never transmitted to us, and is never stored. We do not store the Aadhaar address, date of birth, gender field, QR payload, or document portrait. See Section 3.

We do not collect, process, or store:

Do not share any of the above through messages, profile fields, or job descriptions.

2.4 Device permissions we request

PermissionWhyOptional?
Location (while in use)Find jobs and candidates near you; compute distanceYes — declining falls back to a default city location
CameraFront-camera liveness selfie; scanning the Aadhaar Secure QRYes — only requested if you start verification
Photos / mediaChoosing an avatar, work photos, or a job imageYes — only requested when you upload
NotificationsAlerts for messages, applications, invitations, hiring outcomesYes

Microphone access is never requested; it is blocked at the build level.

2.5 Children

The Platform is not intended for persons under 18 years of age. We do not knowingly collect personal data from children, and we do not knowingly undertake tracking or targeted advertising directed at children. If you believe a minor has created an account, contact privacy@emploi-swipejobs.com for prompt removal.

3. Identity Verification — How It Works and What We Keep

Identity verification is optional and free. This section explains it in full because it involves the most sensitive data on the Platform.

3.1 Processing happens on your device

Liveness detection, face detection, face comparison, QR decoding, and Aadhaar signature validation are all performed locally on your phone using on-device models and bundled public certificates. We do not send your face or your document to any external verification service, and we do not connect to UIDAI. Emploi is not an Authentication User Agency, KYC User Agency, or requesting entity under the Aadhaar Act, and performs no Aadhaar authentication or e-KYC with UIDAI.

3.2 What leaves your device

ItemLeaves your device?Where it goes
Liveness selfie imageYesPrivate storage bucket, readable only by you and authorised personnel; never shown to other users
Face embeddings (numeric face representation)NoComputed and discarded in memory on-device
Liveness challenge results (which challenges, pass/fail, timestamps)YesVerification audit record
Aadhaar Secure QR payloadNoParsed and validated on-device, then discarded
Aadhaar document portraitNoCompared on-device, then discarded
Full 12-digit Aadhaar numberNot applicableNot present in a Secure QR payload at all
Last 4 digits of Aadhaar numberYesVerification audit record
Name-match score; advisory photo-match scoreYesVerification audit record

3.3 If verification is rejected

Where a verification attempt is conclusively rejected — an invalid document signature, or a clearly different name — no record of the attempt is written at all. Nothing is uploaded and nothing is stored.

3.4 Your selfie may become your profile photo

If you have no profile photo, or your existing profile photo contains no detectable face, the App may adopt your liveness selfie as your profile photo so that verification can complete. From that point the adopted photo is publicly visible to other users like any other profile photo, and you can change it at any time from the edit-profile screen.

3.5 Why we keep verification records

Verification records are retained as evidence that a badge was legitimately earned, to detect repeat abuse of the verification system, and to respond to disputes and lawful requests. They are never used for advertising, profiling, model training, or any purpose unrelated to trust and safety.

3.6 Automated decision-making

The verification outcome is decided automatically on your device; there is no human reviewer. This decision affects only whether a trust badge is displayed on your profile — it does not decide whether you are hired, and it does not restrict your ability to use the Platform. You may re-attempt verification, correct your profile name and re-scan, or contact us at privacy@emploi-swipejobs.com if you believe an outcome is wrong.

4. How We Use Your Personal Data

We process personal data for the following purposes:

(a) Service delivery — account creation; authentication via OTP; matching Seekers and Givers; in-app messaging; delivering push and email notifications; ratings and reviews.

(b) Trust and safety — identity verification; detecting and preventing fraud, impersonation, spam, and abuse; moderating user-generated Content; enforcing our Terms & Conditions; applying account suspensions where warranted.

(c) Communication — sending transactional emails (login OTP, welcome email, account and security notifications) and push notifications (new applications, messages, invitations, hiring outcomes). We do not send promotional or marketing emails without a separate, specific opt-in.

(d) Personalisation — showing you jobs or candidates near your location; surfacing matches based on declared skills; translating job content into your chosen language on your device.

(e) Platform improvement — analysing usage and error data to improve usability and reliability.

(f) Legal compliance — responding to lawful requests, court orders, and regulatory obligations; preserving records where required by law.

We do not:

5. Legal Basis for Processing

Under the DPDP Act, we rely on:

5.1 Consent — for: collecting precise location; registering a push-notification token; sending OTP and welcome emails; displaying your profile and Content to other users; storing your profile photos and work photos; and identity verification, including the liveness selfie and the optional Aadhaar step. Consent is recorded electronically with the document version, the document hash, and the acceptance timestamp. Verification is initiated only by your own explicit action in the App.

5.2 Certain legitimate uses under Section 7 of the DPDP Act — for: fraud prevention; information security; complying with Indian law; responding to medical or safety emergencies where applicable.

You may withdraw consent at any time (see Section 9). Withdrawal of consent necessary for service delivery may require account closure.

6. Who We Share Personal Data With

6.1 Other users of the Platform

(a) Publicly visible profile fields — full name, avatar, headline, bio, bio link, selected skills, work photos, verification badge (and its tier), aggregate rating, number of completed jobs, and approximate distance — are visible to users of the opposite role during discovery and after a match.

(b) Phone number — a Seeker's phone number is released to a Giver only via a server-side function that enforces a role check at the database layer. Seekers do not receive Giver phone numbers through this mechanism.

(c) Messages — visible only to the two matched parties in the specific application thread.

(d) Reviews — visible to all users of the Platform as part of reputational data.

(e) Never shared with other users — your email address, your exact coordinates, your liveness selfie, your Aadhaar last-4 digits, your verification scores, and your device tokens. Other users see only that a badge exists, never the underlying evidence.

6.2 Service providers (Data Processors)

Provider Role Data processed Hosting region
Supabase Inc. (USA; infrastructure on AWS) Primary backend — database, authentication, storage, realtime messaging, edge functions All profile data, job data, application data, messages, swipes, work photos, job images, liveness selfies, verification records, push tokens, session tokens AWS ap-south-1 (Mumbai)
Resend Inc. (USA) Transactional email delivery Recipient email, name, email content (OTP codes, welcome messages, auth notifications) USA
Expo (EAS) (USA) Push notification relay; app build and update delivery Push notification tokens; notification title and body (no sensitive payload) USA
Google LLC (Firebase Cloud Messaging) Push delivery on Android Android device FCM token; notification content Globally distributed
Apple Inc. (APNs) Push delivery on iOS iOS device APNs token; notification content Globally distributed
Google LLC (Maps SDK / Maps APIs) Map display and place lookup in the App Map viewport and query coordinates; device and network identifiers collected by Google's SDK Globally distributed
Google LLC (ML Kit — on-device) On-device translation, face detection, and barcode scanning None transmitted — these run locally on your device. Translation models are downloaded once, then used offline On-device
Microsoft Corporation (Clarity) — Android, only where enabled in a build Product analytics and session replay for improving usability Pseudonymised user ID; screen views; in-app interaction events. Verification screens and message content are not intended targets of replay capture USA / Azure
Vercel Inc. (USA) Hosting of emploi-swipejobs.com, including these legal pages Standard web request logs (IP, user agent, timestamp) Globally distributed edge
Google LLC (Play Store) / Apple Inc. (App Store) App distribution Install and crash telemetry governed by the store operator's own policy Globally distributed

All processors are engaged under contractual terms requiring confidentiality, security, and processing only in accordance with our instructions.

6.3 Legal, regulatory, and safety disclosures

We may disclose personal data when we believe in good faith that disclosure is necessary to:

(a) comply with any applicable law, regulation, subpoena, court order, or lawful government request from an Indian authority or other authority with proper jurisdiction;

(b) enforce our Terms & Conditions or investigate suspected breaches;

(c) detect, prevent, or address fraud, security, or technical issues;

(d) protect the rights, property, or safety of Emploi, NilesoftAI, our users, or the public, including in emergencies.

6.4 Business transfers

If NilesoftAI is involved in a merger, acquisition, reorganisation, financing, or sale of assets, personal data may be transferred to the successor or acquiring entity, subject to this Privacy Policy (or a successor policy of comparable protection). You will be notified of any such transfer affecting the processing of your data.

7. International Data Transfers

Your primary account data is stored in India (AWS Mumbai, ap-south-1). Some of our service providers process limited data outside India (see Section 6.2). Cross-border transfers are conducted subject to:

8. Data Retention

We retain personal data only for as long as necessary for the purposes described in this Policy.

Data Retention period
Active account data (profile, jobs, applications, skills, work photos) Until you delete your account
Deleted accounts Deactivated and hidden from other users on receipt of a valid request; hard deletion completed within 90 days, except where longer retention is required by law
Liveness selfie image For the life of the account; deleted within 90 days of account deletion
Verification audit records (challenge results, match scores, Aadhaar last-4) For the life of the account, plus up to 180 days after deletion, as evidence of a legitimately issued badge and to prevent repeat abuse of the verification system
Rejected verification attempts Not retained at all — no record is written
Messages For the life of the account, plus 180 days after account deletion, for dispute resolution, abuse investigation, and legal compliance
Ratings and reviews Retained indefinitely in anonymised form to preserve the reputational integrity of the counterparty
Legal consent records (Terms & Privacy acceptance, version, hash, timestamp) Retained indefinitely as statutory evidence of consent
Push notification tokens Deleted on sign-out; automatically pruned when the push provider reports them invalid
OTP codes Stored only transiently during verification; expire within 5 minutes and are never retained once used or expired
Error logs, diagnostics, and analytics events 90 days
Grievance and support correspondence 3 years from closure of the matter
Records required for tax or regulatory compliance As required under the Income-tax Act, 1961, GST legislation, and other applicable law (typically up to 8 years)

On account deletion, certain data may persist in secure encrypted backups for up to an additional 90 days before being overwritten in the ordinary backup rotation.

9. Your Rights as a Data Principal (DPDP Act)

Subject to applicable law, you have the following rights in respect of your personal data:

9.1 Right to access — request a summary of the personal data we process about you and the identities of the Data Fiduciaries and Data Processors with whom it has been shared.

9.2 Right to correction and erasure — edit your profile fields directly in the App. For data you cannot edit yourself, or to request erasure, contact us. See emploi-swipejobs.com/deletion for the account-deletion process.

9.3 Right to grievance redressal — escalate concerns to our Grievance Officer (Section 14).

9.4 Right to nominate — nominate another person to exercise your rights under the DPDP Act in the event of your death or incapacity. Send nominations to privacy@emploi-swipejobs.com.

9.5 Right to withdraw consent — withdraw consent previously given, at any time, for any purpose not covered by a separate legal basis. Withdrawal does not affect the lawfulness of processing carried out prior to withdrawal. You can:

9.6 How to exercise rights. Send requests to privacy@emploi-swipejobs.com from your registered email address (this is how we verify it is really you). We will respond within 30 days of receipt. Where a request is manifestly unfounded or excessive, we may charge a reasonable fee or refuse the request, with reasons.

9.7 Duty of accuracy. Under Section 15 of the DPDP Act you must not impersonate another person when providing personal data, must not suppress material information, and must not raise a false or frivolous grievance.

10. Security

We implement the following "reasonable security practices and procedures" as contemplated by Section 43A of the Information Technology Act, 2000 and the SPDI Rules:

(a) Transport encryption — all communication between the App and our servers is encrypted using HTTPS / TLS.

(b) Row-Level Security — the database enforces per-row access policies so that each user can only reach their own data unless a policy explicitly permits otherwise.

(c) Private storage for verification media — liveness selfies are held in a private bucket that is not publicly readable; access requires a short-lived signed URL. Profile photos, work photos, and job images are, by design, publicly readable.

(d) Server-side role gating — privileged operations (for example phone-number disclosure to Givers, and recording a verification) are implemented as server-side database functions with explicit role and eligibility checks, rather than exposed as client-callable writes. Verification records cannot be forged by a client.

(e) Server-authoritative badges — verification status is written only by the server; a client cannot set its own badge.

(f) Atomic privileged operations — functions such as consent recording and skill updates are atomic, preventing partial updates.

(g) Webhook signature verification — our email-sending hook verifies an HMAC signature before processing any payload.

(h) DNS-over-HTTPS on Android — mitigates ISP-level DNS tampering on Indian mobile networks.

(i) OTP-based authentication — no user-chosen passwords; OTPs expire within 5 minutes and are consumed on first use.

(j) Device-level session storage — session tokens are stored in platform-provided storage on your device.

(k) Access controls — internal access to production data is limited to personnel with a legitimate need, under confidentiality obligations.

(l) Backups — taken regularly and stored with the same security posture as production.

Notwithstanding these measures, no method of transmission over the internet or electronic storage is 100% secure. Because login is by email OTP, anyone who controls your email inbox can access your account — keep it secure and sign out on shared or lost devices. Report suspected incidents to security@emploi-swipejobs.com.

11. Breach Notification

In the event of a personal data breach, we will:

(a) notify the Data Protection Board of India within the time-frame required under the DPDP Act and its rules;

(b) notify affected users by email or in-app notice, describing the nature of the breach, likely consequences, and the mitigation steps taken or proposed;

(c) report to the Indian Computer Emergency Response Team (CERT-In) within 6 hours of noticing a reportable cyber incident, as required by the CERT-In Directions of 28 April 2022, and maintain the logs those Directions require.

12. Cookies, Trackers, and On-Device Storage

12.1 The Emploi mobile application does not use web cookies.

12.2 The App stores the following locally on your device:

12.3 The App does not embed third-party advertising SDKs and does not perform cross-app or cross-site tracking.

12.4 The website at emploi-swipejobs.com serves static legal pages and sets no cookies of its own. Standard web request logs (IP, user agent, timestamp) are generated by our host for security and abuse prevention. If analytics or non-essential cookies are ever introduced on the website, a consent banner will be shown first.

13. Changes to this Policy

13.1 We may update this Policy from time to time. Material changes increment the version number recorded in our system, together with a cryptographic hash of the exact document text. On your next sign-in after a material change, you will be required to review and accept the updated Policy before continuing to use the Platform.

13.2 Non-material revisions (typographical, formatting) may be made without re-prompting. The "Last updated" date at the top reflects the latest revision.

13.3 Summary of changes in version 2.0: disclosure of the optional identity verification feature (liveness selfie and Aadhaar Secure QR offline verification), including what is processed on-device versus stored; addition of Google Maps, Microsoft Clarity, and website hosting to the processor list; correction of the account-deletion process to reflect that deletion is requested by email rather than performed in-app; change of operating entity name, domain, and contact addresses; expanded retention and permissions detail.

14. Grievance Officer & Data Protection Contact

In accordance with Rule 5(9) of the SPDI Rules, Rule 3(2)(b) of the Intermediary Guidelines, and the DPDP Act:

Complaint handling:

If you remain dissatisfied with the response, you may escalate the matter to the Data Protection Board of India once constituted and operational under the DPDP Act.

15. Governing Law and Jurisdiction

This Policy is governed by the laws of India. Any dispute arising from or relating to this Policy shall be subject to the exclusive jurisdiction of the courts at Hyderabad, Telangana, India, without prejudice to your rights under applicable data-protection law.

16. Contact

Purpose Email
Privacy and data rights privacy@emploi-swipejobs.com
Grievance redressal grievance@emploi-swipejobs.com
Security incidents security@emploi-swipejobs.com
Legal notices legal@emploi-swipejobs.com
General support support@emploi-swipejobs.com
Alternate / backup contact swipejobsindia@gmail.com

NilesoftAI
[REGISTERED_ADDRESS]
Hyderabad, Telangana, India
nilesoftai.com