privacy policy
updated September 2026
what we collect
When you create an account we collect your email address, first name, date of birth, gender, city and the interests you choose. Anything you add to your scrapbook (photos, notes, stickers, a song) is stored so other people can see your profile. If you report someone, we store the reason, any details you add and your user ID so our team can review it. If you choose to get verified, we collect a selfie and a photo of your ID (see "verification" below).
how we use it
We use your information to run mithuru: showing your profile to people nearby, matching you with people based on your preferences, delivering messages and hangout reminders, and keeping the community safe. We do not sell your personal data and we do not use it for advertising.
who can see what
Other signed-in members can see your public profile: first name, age, city, gender, star sign, interests, languages, song, scrapbook (including its photos), the circles you joined, your passport stamps and whether you are verified. Hangouts, spontaneous plans and dansals you post are visible to all members, along with who is going. Your email address and exact date of birth are never shown to anyone. When you say hi, only that person sees it. Messages are only visible to the people in that chat. Pausing your account hides you from discover.
optional details
In Settings you can choose to add more about you: height, religion, ethnicity, education, politics and drinking, smoking or drug habits. These are always optional and you can leave any of them blank. We only use them to match people who filter by them in their preferences. They are never shown on your profile, and you can clear them at any time.
where your data is kept
Your account (email address and name) is managed by Google Firebase Authentication. Your profile (including your date of birth and any optional details you add), your public profile, hellos, messages, group chats, hangouts, plans, dansals, blocks and reports are stored in Google Firebase (Cloud Firestore), and your profile and hangout photos in Google Firebase Cloud Storage, on Google servers in Mumbai, India. Photos are resized before upload. Your preferences, settings and passport are kept on your phone.
verification
Getting verified is optional. If you do it, you take two selfies (one doing a quick challenge, like turning your head) and a photo of your national identity card, driving licence or passport. Our servers check them automatically, with no person looking at them: Google Cloud Vision checks each selfie shows one clear face and that the challenge was done; Google’s Gemini AI (on Vertex AI, which does not use your photos to train its models) checks the selfies were taken live and the ID is a genuine, unaltered card, and reads the name and dates on it; and a face-matching model running on our own servers checks your selfies and your ID photo show the same person. We also check that the date of birth on your ID (including the date built into an NIC number) matches your profile and shows you are over 18. The answer comes back within seconds. We keep only the pass or fail results, not the text read from your ID. The photos are never shown on your profile or to other members, and they are deleted automatically as soon as you are approved or declined. If you delete your account first, they are deleted with it.
apartment connect
If you join your building in Apartment Connect, you send a photo of a recent utility bill. Our servers check it automatically with Google’s Gemini AI, which reads the bill’s date and service address, and look the address up on OpenStreetMap to confirm it is your building. Only the pass or fail result is kept; the bill photo is deleted as soon as it has been checked. Other verified residents of your building can see your first name, your flat number if you add one, and the messages you send in its group chats, which are stored in Google Firebase (Cloud Firestore). You can delete your own messages, report or hide anyone, and leave the building at any time. When you add a new building, its name and address are looked up on OpenStreetMap and shown to other members.
notifications
If you allow notifications, we store a notification token for your phone with your account, along with which kinds you want (hellos, matches, messages, hangouts). Notifications are delivered through Expo’s push service and Apple Push Notification service (or Google’s on Android). They contain the sender’s first name and a preview of the message. You can turn each kind off in Settings.
sign in with apple and google
If you sign in with Apple or Google, we receive your name and email address from that provider, and that provider knows you use mithuru. If you choose "Hide My Email" with Apple, we only receive a relay address.
other services we use
When you search for a profile song, the text you type is sent to Apple’s iTunes Search service, and song previews play from Apple’s servers. Some place photos load from Unsplash, which can see your IP address, like any website. When you browse or search stickers in the scrapbook editor, your search and a random ID for your phone (not your account) are sent to KLIPY, which provides the sticker library, and the stickers load from their servers. When you add a building, it is looked up on OpenStreetMap. Nearby events come from Tickets Ministry’s public listings, and event posters load from their servers; tapping an event opens their website. The service status screen contacts Google and Apple only to check they can be reached. We don’t use any analytics, advertising or tracking tools.
your rights
You can edit your profile at any time, download a copy of your data by emailing us, and delete your account from Settings. Deleting your account permanently removes your profile, scrapbook, photos, hellos, messages, hangouts, plans and dansals from our servers within a few minutes. We comply with the Sri Lanka Personal Data Protection Act No. 9 of 2022 and, where it applies, UK GDPR.
contact
Questions about privacy? Email support@mithuru.lk.