Privacy Policy
About this Policy
This Privacy Policy explains how NilesoftAI, having its registered office at [REGISTERED_ADDRESS], India ("Emploi", "we", "us", "our"), collects, uses, shares, retains, and protects personal data when you use the Emploi mobile application, our website at emploi-swipejobs.com, and related services (collectively, the "Platform"). Emploi is a product of NilesoftAI (nilesoftai.com).
This Policy is issued pursuant to:
- the Digital Personal Data Protection Act, 2023 ("DPDP Act");
- Rule 3 of the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 ("SPDI Rules");
- the Information Technology Act, 2000 and subsidiary legislation;
- the Aadhaar (Targeted Delivery of Financial and Other Subsidies, Benefits and Services) Act, 2016, to the extent relevant to the offline verification described in Section 3;
- other applicable Indian data-protection and privacy laws.
For the purposes of the DPDP Act, NilesoftAI is a Data Fiduciary in respect of the personal data it processes through the Platform, and you are a Data Principal.
If you do not agree with this Policy, do not use the Platform.
The short version. We collect what the app needs to match you with work near you: your name, email, phone, photos, skills, location, and what you do in the app. If you choose to verify your identity, we also handle a selfie and — optionally — the last four digits of your Aadhaar number, with all face and document analysis performed on your own device. We do not sell your data, do not run ads, and do not train AI models on your content. Message content is stored on our servers and is not end-to-end encrypted.
1. Scope and Applicability
1.1 This Policy applies to all users of the Platform, including Seekers (job seekers) and Givers (employers).
1.2 This Policy does not apply to third-party websites or services accessed via external links, or to anything that happens off-Platform between users; those are governed by their own policies and by the parties involved.
2. Personal Data We Collect
2.1 Data you provide directly
| Category | Specific fields | Purpose |
|---|---|---|
| Identity | Full name, email address, mobile phone number (India format, stored as +91XXXXXXXXXX) |
Account creation; OTP-based login; post-match contact between Seeker and Giver |
| Profile | Avatar photo, headline, short bio, external bio link, selected skills, portfolio ("work") photos | Discovery, matching, hiring decisions |
| Precise location | Device GPS coordinates stored as a geographic point; named work areas (Seekers); job locations (Givers) | Showing jobs/candidates within a chosen radius; server-side distance calculation |
| Identity verification | Liveness selfie image; liveness challenge results; face-comparison scores; and, if you complete the optional Aadhaar step, the last four digits of your Aadhaar number, the name-match score, the advisory photo-match score, and the document reference timestamp. See Section 3. | Confirming a real person operates the account; optionally binding the account to a government identity document; fraud prevention |
| Job content (Givers) | Title, description, category, payment amount and type (one-time or regular), location, job image | Presenting the job to relevant Seekers |
| Activity | Swipe history (right/left, archived flag), applications, saved jobs, job invitations, acceptance/rejection of invitations, hiring outcomes | Powering the discovery feed; preventing repeat cards; notifying you of outcomes |
| Messages | Text content you send via in-app chat, timestamps, read status | Communication between matched parties |
| Ratings and reviews | Star rating, textual review you write or receive | Reputation and trust system |
| Consent records | Terms & Conditions and Privacy Policy version accepted, a cryptographic hash of the exact document text shown to you, and the timestamp of acceptance | Legal evidence of consent; regulatory compliance |
| Support correspondence | Anything you send us by email, including deletion or rights requests | Handling your request; grievance redressal records |
2.2 Data collected automatically
| Category | Specific fields | Purpose |
|---|---|---|
| Device | Push notification token, OS platform (Android / iOS), app version | Delivering push notifications; compatibility diagnostics |
| Technical | IP address (transient, processed at the network edge for rate limiting and abuse prevention), request timestamps, API errors | Security, fraud prevention, debugging |
| Language | Chosen interface language (English, Hindi, Telugu, Tamil, Kannada, Malayalam, Marathi, Bengali) | Localisation |
| Product analytics (where enabled in a build) | Pseudonymised user identifier, screen views, in-app interaction events, session replay of in-app UI | Understanding usability problems and improving the app |
| Diagnostics | Error logs, stack traces, user identifier (when available), feature context | Resolving bugs and incidents |
2.3 Sensitive personal data
Some of the data above is sensitive and receives additional care.
(a) Precise location. We collect location only after you grant location permission at the operating-system level, and only while the App is in use. There is no background location tracking. Coordinates are cached on your device for up to five (5) minutes to reduce battery use. If you decline permission, the App falls back to a default city-level location so it remains usable. Other users are shown an approximate distance, never your coordinates.
(b) Facial images and face-derived data. If you use identity verification, we process a photograph of your face and mathematical representations derived from it (face embeddings). All face detection, liveness analysis, and face comparison run on your device; the embeddings themselves are transient and are not transmitted to us or stored. The selfie image is uploaded to a private storage area that other users cannot read, and the numeric comparison scores are stored as an audit record. See Section 3.
(c) Aadhaar-related data. If you complete the optional Aadhaar Secure QR step, we store only the last four digits of the Aadhaar number, together with the name-match and advisory photo-match scores and the document reference timestamp. The full 12-digit Aadhaar number is not present in a Secure QR payload at all, is never transmitted to us, and is never stored. We do not store the Aadhaar address, date of birth, gender field, QR payload, or document portrait. See Section 3.
We do not collect, process, or store:
- your full Aadhaar number, or an image or scan of your Aadhaar card;
- PAN, passport, voter ID, driving licence, or any other government identifier;
- financial information (bank account numbers, card numbers, UPI IDs, payment credentials) — the Platform handles no payments;
- fingerprints, iris scans, or any biometric captured by a biometric device;
- health information;
- data relating to caste, religion, sexual orientation, political beliefs, or trade-union membership;
- passwords — authentication is OTP-based and no user-chosen passwords exist;
- contacts, call logs, SMS, or the contents of your device storage beyond the specific images you choose to upload;
- audio — microphone access is explicitly blocked in the Android build.
Do not share any of the above through messages, profile fields, or job descriptions.
2.4 Device permissions we request
| Permission | Why | Optional? |
|---|---|---|
| Location (while in use) | Find jobs and candidates near you; compute distance | Yes — declining falls back to a default city location |
| Camera | Front-camera liveness selfie; scanning the Aadhaar Secure QR | Yes — only requested if you start verification |
| Photos / media | Choosing an avatar, work photos, or a job image | Yes — only requested when you upload |
| Notifications | Alerts for messages, applications, invitations, hiring outcomes | Yes |
Microphone access is never requested; it is blocked at the build level.
2.5 Children
The Platform is not intended for persons under 18 years of age. We do not knowingly collect personal data from children, and we do not knowingly undertake tracking or targeted advertising directed at children. If you believe a minor has created an account, contact privacy@emploi-swipejobs.com for prompt removal.
3. Identity Verification — How It Works and What We Keep
Identity verification is optional and free. This section explains it in full because it involves the most sensitive data on the Platform.
3.1 Processing happens on your device
Liveness detection, face detection, face comparison, QR decoding, and Aadhaar signature validation are all performed locally on your phone using on-device models and bundled public certificates. We do not send your face or your document to any external verification service, and we do not connect to UIDAI. Emploi is not an Authentication User Agency, KYC User Agency, or requesting entity under the Aadhaar Act, and performs no Aadhaar authentication or e-KYC with UIDAI.
3.2 What leaves your device
| Item | Leaves your device? | Where it goes |
|---|---|---|
| Liveness selfie image | Yes | Private storage bucket, readable only by you and authorised personnel; never shown to other users |
| Face embeddings (numeric face representation) | No | Computed and discarded in memory on-device |
| Liveness challenge results (which challenges, pass/fail, timestamps) | Yes | Verification audit record |
| Aadhaar Secure QR payload | No | Parsed and validated on-device, then discarded |
| Aadhaar document portrait | No | Compared on-device, then discarded |
| Full 12-digit Aadhaar number | Not applicable | Not present in a Secure QR payload at all |
| Last 4 digits of Aadhaar number | Yes | Verification audit record |
| Name-match score; advisory photo-match score | Yes | Verification audit record |
3.3 If verification is rejected
Where a verification attempt is conclusively rejected — an invalid document signature, or a clearly different name — no record of the attempt is written at all. Nothing is uploaded and nothing is stored.
3.4 Your selfie may become your profile photo
If you have no profile photo, or your existing profile photo contains no detectable face, the App may adopt your liveness selfie as your profile photo so that verification can complete. From that point the adopted photo is publicly visible to other users like any other profile photo, and you can change it at any time from the edit-profile screen.
3.5 Why we keep verification records
Verification records are retained as evidence that a badge was legitimately earned, to detect repeat abuse of the verification system, and to respond to disputes and lawful requests. They are never used for advertising, profiling, model training, or any purpose unrelated to trust and safety.
3.6 Automated decision-making
The verification outcome is decided automatically on your device; there is no human reviewer. This decision affects only whether a trust badge is displayed on your profile — it does not decide whether you are hired, and it does not restrict your ability to use the Platform. You may re-attempt verification, correct your profile name and re-scan, or contact us at privacy@emploi-swipejobs.com if you believe an outcome is wrong.
4. How We Use Your Personal Data
We process personal data for the following purposes:
(a) Service delivery — account creation; authentication via OTP; matching Seekers and Givers; in-app messaging; delivering push and email notifications; ratings and reviews.
(b) Trust and safety — identity verification; detecting and preventing fraud, impersonation, spam, and abuse; moderating user-generated Content; enforcing our Terms & Conditions; applying account suspensions where warranted.
(c) Communication — sending transactional emails (login OTP, welcome email, account and security notifications) and push notifications (new applications, messages, invitations, hiring outcomes). We do not send promotional or marketing emails without a separate, specific opt-in.
(d) Personalisation — showing you jobs or candidates near your location; surfacing matches based on declared skills; translating job content into your chosen language on your device.
(e) Platform improvement — analysing usage and error data to improve usability and reliability.
(f) Legal compliance — responding to lawful requests, court orders, and regulatory obligations; preserving records where required by law.
We do not:
- sell or rent personal data to any third party;
- use your personal data for targeted advertising, or serve ads in the App;
- use your Content, photos, selfies, or messages to train general-purpose artificial-intelligence or machine-learning models;
- share your verification data or selfie with other users, employers, or data brokers;
- make automated decisions that produce significant legal or similarly significant effects on you without meaningful human oversight.
5. Legal Basis for Processing
Under the DPDP Act, we rely on:
5.1 Consent — for: collecting precise location; registering a push-notification token; sending OTP and welcome emails; displaying your profile and Content to other users; storing your profile photos and work photos; and identity verification, including the liveness selfie and the optional Aadhaar step. Consent is recorded electronically with the document version, the document hash, and the acceptance timestamp. Verification is initiated only by your own explicit action in the App.
5.2 Certain legitimate uses under Section 7 of the DPDP Act — for: fraud prevention; information security; complying with Indian law; responding to medical or safety emergencies where applicable.
You may withdraw consent at any time (see Section 9). Withdrawal of consent necessary for service delivery may require account closure.
6. Who We Share Personal Data With
6.1 Other users of the Platform
(a) Publicly visible profile fields — full name, avatar, headline, bio, bio link, selected skills, work photos, verification badge (and its tier), aggregate rating, number of completed jobs, and approximate distance — are visible to users of the opposite role during discovery and after a match.
(b) Phone number — a Seeker's phone number is released to a Giver only via a server-side function that enforces a role check at the database layer. Seekers do not receive Giver phone numbers through this mechanism.
(c) Messages — visible only to the two matched parties in the specific application thread.
(d) Reviews — visible to all users of the Platform as part of reputational data.
(e) Never shared with other users — your email address, your exact coordinates, your liveness selfie, your Aadhaar last-4 digits, your verification scores, and your device tokens. Other users see only that a badge exists, never the underlying evidence.
6.2 Service providers (Data Processors)
| Provider | Role | Data processed | Hosting region |
|---|---|---|---|
| Supabase Inc. (USA; infrastructure on AWS) | Primary backend — database, authentication, storage, realtime messaging, edge functions | All profile data, job data, application data, messages, swipes, work photos, job images, liveness selfies, verification records, push tokens, session tokens | AWS ap-south-1 (Mumbai) |
| Resend Inc. (USA) | Transactional email delivery | Recipient email, name, email content (OTP codes, welcome messages, auth notifications) | USA |
| Expo (EAS) (USA) | Push notification relay; app build and update delivery | Push notification tokens; notification title and body (no sensitive payload) | USA |
| Google LLC (Firebase Cloud Messaging) | Push delivery on Android | Android device FCM token; notification content | Globally distributed |
| Apple Inc. (APNs) | Push delivery on iOS | iOS device APNs token; notification content | Globally distributed |
| Google LLC (Maps SDK / Maps APIs) | Map display and place lookup in the App | Map viewport and query coordinates; device and network identifiers collected by Google's SDK | Globally distributed |
| Google LLC (ML Kit — on-device) | On-device translation, face detection, and barcode scanning | None transmitted — these run locally on your device. Translation models are downloaded once, then used offline | On-device |
| Microsoft Corporation (Clarity) — Android, only where enabled in a build | Product analytics and session replay for improving usability | Pseudonymised user ID; screen views; in-app interaction events. Verification screens and message content are not intended targets of replay capture | USA / Azure |
| Vercel Inc. (USA) | Hosting of emploi-swipejobs.com, including these legal pages | Standard web request logs (IP, user agent, timestamp) | Globally distributed edge |
| Google LLC (Play Store) / Apple Inc. (App Store) | App distribution | Install and crash telemetry governed by the store operator's own policy | Globally distributed |
All processors are engaged under contractual terms requiring confidentiality, security, and processing only in accordance with our instructions.
6.3 Legal, regulatory, and safety disclosures
We may disclose personal data when we believe in good faith that disclosure is necessary to:
(a) comply with any applicable law, regulation, subpoena, court order, or lawful government request from an Indian authority or other authority with proper jurisdiction;
(b) enforce our Terms & Conditions or investigate suspected breaches;
(c) detect, prevent, or address fraud, security, or technical issues;
(d) protect the rights, property, or safety of Emploi, NilesoftAI, our users, or the public, including in emergencies.
6.4 Business transfers
If NilesoftAI is involved in a merger, acquisition, reorganisation, financing, or sale of assets, personal data may be transferred to the successor or acquiring entity, subject to this Privacy Policy (or a successor policy of comparable protection). You will be notified of any such transfer affecting the processing of your data.
7. International Data Transfers
Your primary account data is stored in India (AWS Mumbai, ap-south-1). Some of our service providers process limited data outside India (see Section 6.2). Cross-border transfers are conducted subject to:
- contractual safeguards with each processor;
- compliance with the DPDP Act's provisions on cross-border transfer and any restrictions notified by the Central Government;
- compliance with the SPDI Rules' requirement that the receiving entity ensures at least the same level of data protection as those Rules.
8. Data Retention
We retain personal data only for as long as necessary for the purposes described in this Policy.
| Data | Retention period |
|---|---|
| Active account data (profile, jobs, applications, skills, work photos) | Until you delete your account |
| Deleted accounts | Deactivated and hidden from other users on receipt of a valid request; hard deletion completed within 90 days, except where longer retention is required by law |
| Liveness selfie image | For the life of the account; deleted within 90 days of account deletion |
| Verification audit records (challenge results, match scores, Aadhaar last-4) | For the life of the account, plus up to 180 days after deletion, as evidence of a legitimately issued badge and to prevent repeat abuse of the verification system |
| Rejected verification attempts | Not retained at all — no record is written |
| Messages | For the life of the account, plus 180 days after account deletion, for dispute resolution, abuse investigation, and legal compliance |
| Ratings and reviews | Retained indefinitely in anonymised form to preserve the reputational integrity of the counterparty |
| Legal consent records (Terms & Privacy acceptance, version, hash, timestamp) | Retained indefinitely as statutory evidence of consent |
| Push notification tokens | Deleted on sign-out; automatically pruned when the push provider reports them invalid |
| OTP codes | Stored only transiently during verification; expire within 5 minutes and are never retained once used or expired |
| Error logs, diagnostics, and analytics events | 90 days |
| Grievance and support correspondence | 3 years from closure of the matter |
| Records required for tax or regulatory compliance | As required under the Income-tax Act, 1961, GST legislation, and other applicable law (typically up to 8 years) |
On account deletion, certain data may persist in secure encrypted backups for up to an additional 90 days before being overwritten in the ordinary backup rotation.
9. Your Rights as a Data Principal (DPDP Act)
Subject to applicable law, you have the following rights in respect of your personal data:
9.1 Right to access — request a summary of the personal data we process about you and the identities of the Data Fiduciaries and Data Processors with whom it has been shared.
9.2 Right to correction and erasure — edit your profile fields directly in the App. For data you cannot edit yourself, or to request erasure, contact us. See emploi-swipejobs.com/deletion for the account-deletion process.
9.3 Right to grievance redressal — escalate concerns to our Grievance Officer (Section 14).
9.4 Right to nominate — nominate another person to exercise your rights under the DPDP Act in the event of your death or incapacity. Send nominations to privacy@emploi-swipejobs.com.
9.5 Right to withdraw consent — withdraw consent previously given, at any time, for any purpose not covered by a separate legal basis. Withdrawal does not affect the lawfulness of processing carried out prior to withdrawal. You can:
- disable location permission at the operating-system level to stop location collection;
- disable camera permission to prevent any further verification capture;
- disable push notifications at the operating-system level;
- delete photos or profile fields from within the App;
- request erasure of your verification records (your badges will be removed);
- delete your account for a full withdrawal of consent.
9.6 How to exercise rights. Send requests to privacy@emploi-swipejobs.com from your registered email address (this is how we verify it is really you). We will respond within 30 days of receipt. Where a request is manifestly unfounded or excessive, we may charge a reasonable fee or refuse the request, with reasons.
9.7 Duty of accuracy. Under Section 15 of the DPDP Act you must not impersonate another person when providing personal data, must not suppress material information, and must not raise a false or frivolous grievance.
10. Security
We implement the following "reasonable security practices and procedures" as contemplated by Section 43A of the Information Technology Act, 2000 and the SPDI Rules:
(a) Transport encryption — all communication between the App and our servers is encrypted using HTTPS / TLS.
(b) Row-Level Security — the database enforces per-row access policies so that each user can only reach their own data unless a policy explicitly permits otherwise.
(c) Private storage for verification media — liveness selfies are held in a private bucket that is not publicly readable; access requires a short-lived signed URL. Profile photos, work photos, and job images are, by design, publicly readable.
(d) Server-side role gating — privileged operations (for example phone-number disclosure to Givers, and recording a verification) are implemented as server-side database functions with explicit role and eligibility checks, rather than exposed as client-callable writes. Verification records cannot be forged by a client.
(e) Server-authoritative badges — verification status is written only by the server; a client cannot set its own badge.
(f) Atomic privileged operations — functions such as consent recording and skill updates are atomic, preventing partial updates.
(g) Webhook signature verification — our email-sending hook verifies an HMAC signature before processing any payload.
(h) DNS-over-HTTPS on Android — mitigates ISP-level DNS tampering on Indian mobile networks.
(i) OTP-based authentication — no user-chosen passwords; OTPs expire within 5 minutes and are consumed on first use.
(j) Device-level session storage — session tokens are stored in platform-provided storage on your device.
(k) Access controls — internal access to production data is limited to personnel with a legitimate need, under confidentiality obligations.
(l) Backups — taken regularly and stored with the same security posture as production.
Notwithstanding these measures, no method of transmission over the internet or electronic storage is 100% secure. Because login is by email OTP, anyone who controls your email inbox can access your account — keep it secure and sign out on shared or lost devices. Report suspected incidents to security@emploi-swipejobs.com.
11. Breach Notification
In the event of a personal data breach, we will:
(a) notify the Data Protection Board of India within the time-frame required under the DPDP Act and its rules;
(b) notify affected users by email or in-app notice, describing the nature of the breach, likely consequences, and the mitigation steps taken or proposed;
(c) report to the Indian Computer Emergency Response Team (CERT-In) within 6 hours of noticing a reportable cyber incident, as required by the CERT-In Directions of 28 April 2022, and maintain the logs those Directions require.
12. Cookies, Trackers, and On-Device Storage
12.1 The Emploi mobile application does not use web cookies.
12.2 The App stores the following locally on your device:
- your authentication session token;
- your currently active role (Seeker or Giver);
- your chosen language;
- downloaded offline translation models;
- a short-lived location cache (up to 5 minutes);
- app-level preferences (for example toggles and last-used filters).
12.3 The App does not embed third-party advertising SDKs and does not perform cross-app or cross-site tracking.
12.4 The website at emploi-swipejobs.com serves static legal pages and sets no cookies of its own. Standard web request logs (IP, user agent, timestamp) are generated by our host for security and abuse prevention. If analytics or non-essential cookies are ever introduced on the website, a consent banner will be shown first.
13. Changes to this Policy
13.1 We may update this Policy from time to time. Material changes increment the version number recorded in our system, together with a cryptographic hash of the exact document text. On your next sign-in after a material change, you will be required to review and accept the updated Policy before continuing to use the Platform.
13.2 Non-material revisions (typographical, formatting) may be made without re-prompting. The "Last updated" date at the top reflects the latest revision.
13.3 Summary of changes in version 2.0: disclosure of the optional identity verification feature (liveness selfie and Aadhaar Secure QR offline verification), including what is processed on-device versus stored; addition of Google Maps, Microsoft Clarity, and website hosting to the processor list; correction of the account-deletion process to reflect that deletion is requested by email rather than performed in-app; change of operating entity name, domain, and contact addresses; expanded retention and permissions detail.
14. Grievance Officer & Data Protection Contact
In accordance with Rule 5(9) of the SPDI Rules, Rule 3(2)(b) of the Intermediary Guidelines, and the DPDP Act:
- Name: [GRIEVANCE_OFFICER_NAME]
- Designation: Grievance Officer and Data Protection Contact
- Company: NilesoftAI
- Email: grievance@emploi-swipejobs.com / privacy@emploi-swipejobs.com
- Alternate email: swipejobsindia@gmail.com
- Postal address: [REGISTERED_ADDRESS], India
- Working hours: Monday to Friday, 10:00–18:00 IST (excluding public holidays)
Complaint handling:
- Complaints are acknowledged within 24 hours of receipt.
- Complaints are ordinarily resolved within 15 days of acknowledgement, subject to statutory timeframes.
- A valid complaint should include: your full name, registered email, a clear description of the issue, the data or content concerned, and any supporting evidence.
If you remain dissatisfied with the response, you may escalate the matter to the Data Protection Board of India once constituted and operational under the DPDP Act.
15. Governing Law and Jurisdiction
This Policy is governed by the laws of India. Any dispute arising from or relating to this Policy shall be subject to the exclusive jurisdiction of the courts at Hyderabad, Telangana, India, without prejudice to your rights under applicable data-protection law.
16. Contact
| Purpose | |
|---|---|
| Privacy and data rights | privacy@emploi-swipejobs.com |
| Grievance redressal | grievance@emploi-swipejobs.com |
| Security incidents | security@emploi-swipejobs.com |
| Legal notices | legal@emploi-swipejobs.com |
| General support | support@emploi-swipejobs.com |
| Alternate / backup contact | swipejobsindia@gmail.com |
NilesoftAI
[REGISTERED_ADDRESS]
Hyderabad, Telangana, India
nilesoftai.com