Meowdy

Privacy Policy

Effective date: July 15, 2026

This Privacy Policy describes how Futureaiit Consulting Private Limited collects, uses, discloses, and protects information in connection with the Meowdy website and mobile applications. Please read it carefully, in particular Section 2 on age eligibility and Section 5 on the real, feature-by-feature scope of our encryption.

1. Who we are and what this policy covers

Meowdy (the "Service," "we," "us," or "our") is owned and operated by Futureaiit Consulting Private Limited ("Futureaiit," "the Company," "Parent Company"), a company incorporated in India with its registered office at UNIT 405-411 BIZNESS SQR, HN.1-98/3/5/23 TO 27, Madhapur, Shaikpet, Hyderabad – 500081, Telangana, India. "Meowdy" is a brand and product of Futureaiit Consulting Private Limited - it is not a separate legal entity, subsidiary, or joint venture. Any reference to "Meowdy" in this Policy means Futureaiit Consulting Private Limited acting under that brand.

This Privacy Policy explains what personal data we collect through our website and mobile applications (together, the "Service"), why we collect it, how long we keep it, who we share it with, and the choices and rights available to you. It applies to everyone who uses the Service, whether as an anonymous guest or a registered account holder.

This Policy should be read together with our Terms of Service, Community Guidelines, and Cookie Policy. If you do not agree with this Policy, you must not use the Service.

2. Eligibility and age restriction - the Service is strictly 18+

The Service is not directed at, and must not be used by, anyone under the age of 18. We do not knowingly collect personal data from minors, and we do not permit minors to create accounts, use anonymous chat sessions, or otherwise access any part of the Service.

By using the Service you represent and warrant that you are at least 18 years old. If we become aware, or have reason to believe, that a user is under 18, we will terminate that user's access and delete the account and associated data we hold, to the extent permitted or required by applicable law, without prior notice. Parents or guardians who believe a minor has accessed the Service and provided us with personal data should contact us using the details in Section 15 so we can investigate and take appropriate action, including deletion.

We do not operate any part of the Service, and this Policy does not apply, in a manner directed at children as defined under the U.S. Children's Online Privacy Protection Act ("COPPA") or equivalent laws in other jurisdictions. If you are a parent or guardian and believe your child has provided us with personal information without your consent, contact us immediately so we can take corrective action.

3. Information you provide to us

Anonymous chat sessions. You can use the core random-chat feature without creating an account. We assign you a temporary session identifier and ask you to choose a display username, a gender you wish to present as, and (optionally) an avatar image and a matching "intent." No email, password, or other identifying credential is required or collected for anonymous sessions.

Registered accounts. If you choose to create an account - for example, to save chat history, add friends, or subscribe to Premium - we collect: your email address, a password (which we never store in plain text; it is hashed using bcrypt before storage), a username, your stated gender, and optionally a profile avatar image. We do not currently ask for or store your date of birth, phone number, or government-issued identification.

Two-factor authentication. If you enable optional two-factor authentication (2FA), we store your TOTP secret and backup recovery codes in encrypted/hashed form.

Content you send. Messages, photos, and other content you send through the Service are processed as described in Section 5 ("Encryption and how we handle your messages") below - the level of protection differs materially depending on which feature you are using.

Payment information. If you purchase a Premium subscription, your payment is processed entirely by our third-party payment processors - Stripe or Razorpay. We do not receive, process, or store your card number, CVV, or other full payment credentials on our servers. We retain only the transaction outcome (success/failure), amount, currency, a provider-issued reference ID, and your subscription status and renewal date.

Communications with us. If you contact support, respond to a report, or otherwise communicate with us directly, we retain that correspondence to respond to you and maintain a record of the interaction.

4. Information we collect automatically

Location data (Nearby Matching). If you are a Premium subscriber and choose to use the optional "Nearby Matching" filter, we request your device's precise geolocation coordinates (via your browser's or mobile OS's location services) at the moment you search for a match. These coordinates are used solely, in memory, to calculate the distance between you and other waiting users so we can apply your chosen radius filter (5, 10, 50, or 100 miles). Your coordinates are never written to a database, are never shown to your matched partner, and are never retained after your search session ends - they exist only transiently in server memory for the duration of active matching. If our reverse-geocoding feature displays your approximate location as a place name (e.g., a city), that lookup is performed by your own device directly against a third-party mapping service (OpenStreetMap Nominatim) - see Section 8.

Usage and device information. Like most online services, our servers automatically log technical information necessary to operate the Service, including IP address, browser or device type, operating system, timestamps, and general request metadata (for example, in server access/error logs and for abuse-prevention purposes). We do not currently use dedicated third-party analytics, advertising, or crash-reporting SDKs.

Cookies and local storage. We use a limited set of cookies and browser local storage to keep you signed in, remember your preferences, and enforce the age-verification gate described in Section 2. See our Cookie Policy for full detail.

5. Encryption and how we handle your messages

We believe you should know exactly what is and is not protected. The level of protection differs by feature:

Random chat (anonymous, ephemeral 1:1 rooms). Text messages, photos, and voice/video call signaling exchanged in a random chat room are end-to-end encrypted using a key exchanged directly between you and your matched partner (ECDH key exchange, AES-256-GCM message encryption). When end-to-end encryption is active for a given message, our servers relay only encrypted, unreadable ciphertext and cannot read the content. Random chat conversations are not stored in a database by default; they exist only in server memory for the duration of the chat and are discarded once the chat ends or the server restarts. Exception: if you use the optional "save message" feature to add a specific message to your personal chat history, that message is stored in our database in readable (unencrypted) form, tied to your account, until you delete it or your account is deleted.

Friend / direct messaging (persistent conversations with connections you've added). Messages you exchange with friends through the persistent conversation feature are not end-to-end encrypted. They are encrypted at rest on our servers using AES-256-GCM with a key we control, which protects your messages if our database were ever compromised, but it means our systems are technically capable of decrypting this content to deliver it back to you and your friend, and to respond to valid legal process. Friend messages are retained indefinitely unless you or your friend deletes them (see Section 6).

Voice and video calls. Call audio/video itself always flows directly between participants' devices (peer-to-peer WebRTC, protected by industry-standard DTLS-SRTP) - our servers never receive or store call media. For random chat calls, the connection setup information (signaling) is additionally end-to-end encrypted using your chat's shared key. For friend/direct calls, signaling is relayed through our servers without that additional encryption layer, though it never contains call audio/video itself, only connection-negotiation data.

Self-destructing photos. Photos sent with a view-once timer are held temporarily on our servers so we can deliver and then delete them. Random chat photos are capped at 10 minutes if unopened and deleted shortly after viewing per your chosen timer. Friend chat photos are encrypted at rest, capped at 24 hours if unopened, and the encrypted image data (not the message record) is permanently wiped once the viewing window closes.

In short: treat random chat as more private by default, and friend/direct chat as a persistent record that our systems can technically access, similar to most conventional messaging services. Do not send anything in either context that you would not want potentially reviewed in response to a report, abuse investigation, or legal request.

6. How long we keep your information

Anonymous session data (username, gender, avatar, intent) persists only for the life of your session and is not linked to any other identifying information.

Account data (email, username, gender, avatar, settings) is retained for as long as your account exists.

Random chat content is ephemeral and not stored, except messages you explicitly save, which persist until you delete them or your account is deleted.

Friend/direct chat content persists indefinitely once sent. If you "clear" or "delete" a conversation in the app, this hides it from your own view only - it does not delete the underlying messages for the other participant, and does not delete the messages from our servers. Deleting your account (see Section 9) does permanently delete the underlying conversation data, including your friend's copy, because conversations are stored as a single shared record between two participants rather than separate copies.

Reports you file, or that are filed against you, are retained indefinitely as part of our permanent trust-and-safety record, even after an account involved in the report is deleted, so we can identify repeat abuse patterns and comply with legal obligations.

Blocks you place on other users persist until your account is deleted.

Payment and subscription records are retained for as long as required for accounting, tax, and legal compliance purposes, generally for several years after the transaction, even if you later delete your account.

7. Who we share your information with

We do not sell your personal data. We share information only in the following circumstances:

Your matched chat partner or friend sees the profile information you choose to share (username, avatar, gender, verification badge) and the content of messages you send them.

Payment processors (Stripe and Razorpay) receive the information necessary to process your Premium subscription payment, governed by their own privacy policies.

Email delivery providers process the content of transactional emails we send you (account verification, password reset, notifications) on our behalf.

Service providers acting on our behalf, such as hosting and infrastructure providers, who process data only as necessary to operate the Service and under confidentiality obligations.

Law enforcement and legal process. We may disclose information if required by law, subpoena, court order, or other legal process, or if we believe in good faith that disclosure is necessary to protect the rights, property, or safety of Futureaiit, our users, or the public, including in response to reports of suspected illegal activity, harassment, or harm to minors.

Business transfers. If Futureaiit is involved in a merger, acquisition, financing, reorganization, or sale of assets, your information may be transferred as part of that transaction, subject to standard confidentiality protections.

We do not currently use third-party advertising networks, and we do not share your data with advertisers.

8. Third-party services

The Service integrates with a limited number of third parties, each of which processes data under its own privacy policy:

Stripe and Razorpay - payment processing for Premium subscriptions.

OpenStreetMap Nominatim - if you use Nearby Matching, your device queries this third-party service directly (not routed through our servers) to convert coordinates into a readable place name for display to you. This request is made by your own browser or app and is subject to OpenStreetMap's own privacy practices.

Google STUN servers - used only for WebRTC network address discovery (NAT traversal) when establishing a peer-to-peer voice/video call. Google receives only network connectivity metadata (your public IP address and port), never call content.

SMTP email delivery - used to send account verification, password reset, and notification emails.

We do not use third-party analytics, advertising, or crash-reporting SDKs at this time. If this changes, we will update this Policy.

9. Your rights and choices

Access and correction. You can review and update most of your account information (username, avatar, gender, notification preferences) directly within the app's settings.

Account deletion. To request deletion of your account and associated data, contact us using the details in Section 15. Deleting your account permanently removes your profile, friend connections, and shared conversation history (including your friends' copies of shared conversations, since conversations are stored as a single shared record), subject to information we are required to retain for legal, tax, security, or fraud-prevention purposes (such as payment records and trust-and-safety reports).

Blocking and reporting. You can block another user at any time to prevent future matching and contact, and report content or behavior that violates our Community Guidelines.

Location. Nearby Matching is entirely optional. You can decline location permission requests and continue using the Service without this feature; declining simply disables distance-based filtering.

Marketing and notifications. You can manage notification preferences, including push notifications, in the app's settings.

Depending on your jurisdiction, you may have additional rights under applicable data protection law (for example, the right to data portability, restriction of processing, or objection to certain processing activities, under India's Digital Personal Data Protection Act, the EU/UK GDPR, or U.S. state privacy laws). To exercise any such right, contact us using the details in Section 15 and we will respond in accordance with applicable law.

10. Data security

We use reasonable technical and organizational measures designed to protect your information, including password hashing (bcrypt), encryption at rest for sensitive data (payment provider credentials, two-factor secrets, friend message content), and end-to-end encryption for random chat content as described in Section 5. However, no method of transmission or storage is 100% secure, and we cannot guarantee absolute security. You are responsible for keeping your account password confidential and for any activity that occurs under your account.

11. International data transfers

Futureaiit Consulting Private Limited is based in India, and our servers and service providers may be located in India or other countries. If you access the Service from outside India, your information may be transferred to, stored, and processed in India or other jurisdictions whose data protection laws may differ from those of your home country. By using the Service, you consent to this transfer, storage, and processing.

12. Content moderation and safety monitoring

To protect users and comply with legal obligations, plaintext (non-encrypted) messages sent through random chat are automatically scanned by an automated filter designed to detect attempts to share contact information (phone numbers, email addresses, and social media handles), in order to reduce off-platform harassment and grooming risks. We also operate a report-and-block system and an administrative review process; our authorized personnel may review reported content, message metadata, and account activity as necessary to investigate violations of our Community Guidelines or applicable law, including suspected exploitation of minors, which we treat as a zero-tolerance matter and will report to law enforcement and relevant authorities (such as the National Center for Missing & Exploited Children, where applicable) as required by law.

13. Changes to this Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. If we make material changes, we will update the "Effective date" at the top of this page and, where appropriate, provide additional notice (such as an in-app notification). Your continued use of the Service after a change becomes effective constitutes acceptance of the revised Policy.

14. Contact us

If you have questions, requests, or concerns about this Privacy Policy or our data practices, or if you are a parent/guardian reporting a suspected minor user, please contact us at:

Futureaiit Consulting Private Limited
UNIT 405-411 BIZNESS SQR, HN.1-98/3/5/23 TO 27, Madhapur, Shaikpet, Hyderabad – 500081, Telangana, India

Futureaiit Consulting Private Limited

UNIT 405-411 BIZNESS SQR, HN.1-98/3/5/23 TO 27, Madhapur, Shaikpet, Hyderabad – 500081, Telangana, India