Privacy Policy
The short version
Wudd introduces Muslims to each other for marriage. To do that we hold your profile, your photos, what you told us about your faith and your life, and the conversations you have here. We show your profile only to the few people you are introduced to, never to the open internet. We do not sell anything about you, we show no advertising, and we do not track you across other apps or websites. Everything below is the detail.
If you only read one more paragraph, read this one: your faith answers are special category data under European law, we ask for them only to find you someone compatible, we ask separately and clearly for your permission, and you can take that permission back at any time.
1. Who we are
Wudd is a verification-first matrimonial app for Muslims seeking marriage, operated by Wudd, Ru Parelaan 199, 3527 LJ Utrecht, Netherlands, registered with the Dutch Chamber of Commerce under number 42136139. We are the data controller for everything described here.
We are a small team. There is no separate data protection officer; questions, requests and complaints all reach a person at info@eayniapp.com, and we answer within one month.
2. How your account is created
You register in one of three ways, and the three are equal: a phone number verified with a one-time code, Sign in with Apple, or Sign in with Google. Whichever you choose is the key to the account and is how you sign in again on a new phone. Apple and Google hand us an email address, which is stored against your account and used for nothing but signing you in; Apple's private-relay addresses are treated the same way. A phone number is not required for an Apple or a Google registration, and you can add one later in Settings.
Behind all three the app first takes an anonymous identity from our authentication provider, so that registration can begin before you have given us anything at all. Everything described in this policy hangs on that identity. There is no password anywhere in Wudd.
Signing out leaves your account exactly as it is. Your profile, your photos, your matches and your messages stay where they are, and you sign back in the same way you registered. Deleting is the final act, and section 16 says exactly what it removes and what it cannot.
3. What we collect, why, and on what basis
| What | Why | Legal basis |
|---|---|---|
| Phone number, if you register with one | Signing in; one account per person; blocking (see §11) | Contract (Art. 6(1)(b)) |
| Email address, if you sign in with Apple or Google | Signing in | Contract |
| First name, date of birth, gender | Your profile; proving you are 18 or over | Contract |
| Your town, and where your phone is when you open the app, if you allow it. We round the position to about a kilometre before we store it, keep only the latest one, and never read it in the background. If you do not allow it, we use the centre of the town you typed | Showing your town, the distance filter, and measuring distance between you and the people you might meet and to a meeting place. Others see your town and a rounded distance, never your position | Contract |
| The two-letter country your phone is in | The country filter, so you are found where you actually are | Contract |
| Your time zone | So a notification at night is night where you are | Contract |
| Photos, and the blurred copies made from them | Your profile. For women, the blurred set is what men see until you match | Contract; explicit consent for processing your image (Art. 9(2)(a)) |
| The selfie taken during registration | Proving the photos are of you. Never shown to another member | Explicit consent (Art. 9(2)(a)) |
| An identity document, if you choose to show one | The second check mark. Voluntary, and the picture is deleted the moment a reviewer decides (§6) | Explicit consent (Art. 9(2)(a)) |
| Faith answers: tradition, how you practise, prayer, and related lifestyle answers | The heart of the matching | Explicit consent (Art. 9(2)(a)) |
| Ethnicity, if you give it | Matching and filters | Explicit consent (Art. 9(2)(a)) |
| Education, work, languages, height, build, family plans, and the rest of your answers | Matching and filters | Contract |
| What you write about yourself, your reflections and icebreaker answers | Your profile and your conversations | Contract |
| Who you were introduced to, who you said yes or no to, and when | Running the introductions, and not showing you the same person twice | Contract |
| Your conversations: messages, voice notes, photos sent in chat | Providing the conversation | Contract |
| Calls: that a call happened, when, and how long. Never the sound or picture | The milestones in a conversation, and your wali's view if you gave him one | Contract |
| Meeting arrangements: the place proposed, the time, and whether it happened | Running the meeting phase | Contract |
| Fingerprints (hashes) of numbers from your address book, if you use contact blocking | Keeping people you know out of your introductions (§11) | Consent (Art. 6(1)(a)) |
| Reports you make and reports about you, and blocks | Safety, and acting on abuse | Legitimate interest (Art. 6(1)(f)) and legal obligation |
| Reviewer notes and grades | Checking profiles are genuine and suggesting balanced introductions (§7) | Legitimate interest, and explicit consent where derived from the answers above |
| Your notification token and your notification settings | Sending the notifications you asked for | Contract |
| A device identifier used by the notification and crash-reporting libraries | Delivering a notification to the right phone; grouping crash reports | Contract, and legitimate interest for crashes |
| When you last opened the app | Ordering introductions, and setting aside accounts that have gone quiet | Contract |
| Your wali's first name, the fact of the link, the milestones he was shown, and a token for his device if he allows notifications | Giving your guardian the view you chose to give him (§8) | Contract, on your instruction |
| That you bought a membership, which one, and until when | Giving you what you paid for | Contract |
| Crash reports | Keeping the app working | Legitimate interest (Art. 6(1)(f)) |
| Usage analytics | Understanding which parts of the app are used | Consent (Art. 6(1)(a)). Off unless you switch it on in Settings |
We do not sell personal data. We show no advertising. We do not track you across other companies' apps or websites, and we do not work with data brokers or ad networks.
4. Faith, ethnicity, and the fact that you are looking to marry
Your tradition, how you practise, your prayer habits and your ethnicity are special category data under Article 9 GDPR. So, arguably, is the simple fact that you use a matrimonial app, because it says something about who you are looking for.
We handle all of it the same way:
- We ask for it only to introduce you to people you are likely to be compatible with. That is the whole purpose of the app.
- We ask separately and explicitly, at the moment you give it, and you can leave any of it blank. Leaving it blank makes the matching less precise; it does not shut you out of the app.
- You can withdraw your permission at any time in Settings, which takes that information out of the matching. Withdrawing does not undo processing that already happened.
- We never infer anything beyond what you told us, and we never share any of it outside what this policy describes.
5. Photos, the selfie, and the blurring
Your photos. You upload up to three. They are held in our file storage at Supabase. The database decides, file by file, who may open one: you, a reviewer, somebody you have matched with, or somebody who has you in their introductions today, and for a woman's photographs everyone in that last group sees only the blurred copies. The app fetches them through links that expire within the hour. A reviewer looks at them before your profile can be introduced to anyone.
The blurring. For women's profiles, an automated service makes a copy of each photo with the person softly blurred, and that blurred set is what men see until the two of you have matched. The sharp originals stay for you and for reviewers. The service runs on Google Cloud in the European Union and does one thing: it separates the person from the background and blurs the person. It does not recognise faces, does not build a face template, and keeps nothing after it has written the blurred copy back.
The trigger that calls it sends five things and nothing else: which account the photographs belong to, whether the profile is a woman's, the photo list, the blurred list, and the review status. Your answers never go near it.
The selfie. During registration you take one selfie, straight after your photos. It exists for a single reason: so that a reviewer can see that the person in the photos is the person holding the phone. It is never shown to another member, it lives in a private area that only you and reviewers can open, and it is kept while your account exists because it is checked again each time you change a photo. A reviewer compares it by eye. No facial recognition, no biometric template, no automated matching of faces is used anywhere in Wudd.
6. The identity check, if you want it
Any member may show a passport, identity card or driving licence once, from Settings. It is entirely voluntary and nothing in the app is closed to you if you skip it.
If you do it: you photograph the side with your picture. A reviewer looks at exactly three things and compares them with your profile: the face, the first and last name, and the date of birth. Nothing is copied from the document, ever. The picture is deleted the moment the reviewer decides. A picture nobody has looked at within three days is deleted automatically and you are asked to send it again. What stays afterwards is the verdict, the date, and which kind of document it was.
A confirmed identity shows as a second mark on your profile and moves your interest higher in the other person's list.
7. Reviewers, and how grading works
Every profile is read by a trained reviewer before it can be introduced to anyone: the photos against the selfie, and the written answers. Reviewers are under contract and bound to confidentiality, and their access is limited by the database itself, not by a promise.
Reviewers also record internal grades: how well the photographs are made, how the profile reads, the stage of your working life, and an appearance grade. Together they make one number. Its purpose is to suggest balanced introductions, pairing profiles of comparable standing. Grades are never shown to you, never shown to other members, and never sold.
Be aware of what that number does. It does not only order your introductions: the people you are shown are drawn from a band around your own grade, so it shapes who you meet here. It never closes the app to you, and it never leaves our own reviewers.
Because that is profiling, you may ask us what your grade is, tell us why you think it is wrong, and ask for a fresh review by a different person. We do not make decisions about you by automated means alone: a person sets every grade, and a person looks again when you ask.
Edits to your open answers after your profile is live go through the same queue and can be rolled back by a reviewer if they break the rules.
8. Your wali
You may create a code and give it to a guardian. He does not need an account: the code is how he signs in, and he sees a page of milestones only: that you matched, and the first name of the person; that a call has been agreed; that a meeting was agreed; and whether your photographs have been verified. He is not told how long a call lasted. He chooses which of these reach him as notifications.
He never sees the contents of your conversations. Not the messages, not the voice notes, not the photos. This is a deliberate difference from other apps in this category, some of which send a guardian transcripts.
You can revoke the code at any time, and doing so ends his access immediately. We hold his first name, the fact of the link, the milestones he was shown, and, if he allows notifications, a token for his device.
9. Conversations, calls and meeting
Messages, voice notes and photos in chat are stored so the conversation works, in storage only the two of you and, where necessary, a reviewer acting on a report can reach. A photo you send as view-once is removed once it has been seen. Deleting a message removes it for both of you.
Calls run through LiveKit, a third party that carries the audio and video between the two phones. The conversation itself is not recorded and never reaches us: what we keep is that a call took place, when it started and ended, and how long it lasted, because that is what carries the conversation into its next stage. Your wali is told that a call has been agreed and nothing more (§8).
Meeting in person. When you agree a place and a time, we store which place and when, and afterwards whether the meeting happened. The places themselves are a list we maintain; suggesting one near you uses the same rounded position or town described above, and nothing more. If you add the meeting to your phone's calendar, that happens on your phone and we are not involved.
10. Notifications
If you allow them, your phone is issued a notification token that we store against your account so a message can reach the right device. Notifications are sent through Firebase Cloud Messaging (Google). You choose which kinds you want in Settings, and quiet hours are honoured in your own time zone.
11. Blocking people you know
You can hide from anyone in your address book, so that a cousin or a colleague is never introduced to you. This is switched off unless you turn it on.
If you turn it on, the app reads your contacts on your phone, converts each number into a fingerprint (a one-way hash) and sends only those fingerprints. The numbers themselves never leave your phone. Your own number is fingerprinted the same way so the matching works in both directions.
Each fingerprint is hashed a second time on our server, with a value that exists only inside the database and that nothing we run will hand back. So a stolen database gives up no address books at all: turning a fingerprint into a phone number needs that value too, and unpacking the app does not yield it.
We do not read names, email addresses or anything else from your address book, and we never contact anyone in it.
12. Analytics, crash reports, and what we do not do
Crash reports (Firebase Crashlytics) are on. A crash report carries what went wrong and an install identifier, and we deliberately do not attach your account to it.
Usage analytics (Firebase Analytics) are off until you turn them on. Collection is disabled when the app is built, and it stays off until you say otherwise.
We ask you once. Not at registration, where nobody yet knows what the app is, but after you have answered your first three introductions: a sheet asking whether we may see which screens get used and where people give up. Yes or not now, once, and it never comes back either way. The switch is then yours in Settings, under Your data, and it works in both directions at any time.
In either state we are never sent what you wrote, who you spoke to, or your name. There is no pop-up on first launch asking you to accept tracking, because there is no tracking to accept.
We do not use advertising identifiers and we do not ask for App Tracking Transparency permission, because nothing here follows you across other companies' apps or websites. Google's measurement library on iPhone brings an advertising conversion component along with it; we never call it, there is no advertising account behind it, and Wudd carries no advertising of any kind.
13. Paying for a membership
Wudd Premium is bought through the Apple App Store or Google Play. Your card details go to the store, never to us. What reaches us is the confirmation that a purchase happened, which plan it was, and when it runs out, so we can switch the extra features on. The stores also tell us when a subscription renews, lapses or is refunded.
14. Who else touches your data
| Who | What for | Where |
|---|---|---|
| Supabase | Database, file storage, authentication | European Union |
| Twilio | Sending the one-time code by SMS. Receives your number and the six digits, nothing else | United States; standard contractual clauses |
| Google Cloud | The photo-blurring service | European Union (Belgium) |
| Google Firebase | Notifications, crash reports, and analytics if you turned it on | United States; standard contractual clauses |
| LiveKit | Carrying call audio and video. Not recorded | United States; standard contractual clauses |
| Apple, Google (stores) | Selling and renewing memberships | Their own terms; they are the seller, not us |
| Reviewers | Checking profiles, handling reports | Contracted, confidentiality bound, access limited by role |
Everything at the centre of the app, your profile, your photos and your conversations, is stored in the European Union. The transfers marked above leave the EEA and rely on standard contractual clauses approved by the European Commission, together with the protections those providers publish. We have a data-processing agreement with each processor.
We will hand data to the police or another authority only where the law requires it, and we will tell you unless we are forbidden to.
15. How long we keep things
| What | How long |
|---|---|
| Your account and everything attached to it | While the account exists |
| The selfie | While the account exists, because it is rechecked on every photo change |
| An identity document picture | Until the reviewer decides, and in any case no more than three days |
| The verdict of an identity check | While the account exists |
| An interest you sent that nobody answered | Seven days, then it lapses quietly |
| A conversation | While it is open, and as part of your account afterwards |
| Contact fingerprints | Until you turn contact blocking off, or delete your account |
| Reports about you | Kept after deletion, with your profile detached, where we need them to keep other people safe |
| A fingerprint of your number, where somebody blocked you | Kept after deletion, so that deleting and registering again is not a way around a block |
| Verification codes and transient server logs | Short-lived, days at most |
| Encrypted backups | Residual copies age out within 30 days |
16. Deleting your account
Settings → Account → Delete. One server-side operation runs, and it can only ever act on your own account. It removes your photos, both the sharp originals and the blurred copies, the voice notes and the photographs sent inside your conversations, the record that a call connected, and then the account itself, which cascades through your profile, your answers, your introductions, your interests, your matches and the messages inside them, your reviewer grades and your notification tokens.
Two things survive on purpose. A report somebody made about you is kept with your profile detached, because it concerns another person's safety rather than yours. And where somebody blocked you, a fingerprint of your phone number stays on their list, so that deleting your account and registering again is not a way around their block. That fingerprint is not a number and cannot be turned back into one; it names you to nobody, and it sits under the account of the person who blocked you rather than under yours.
One technical trace can outlive the account: a list of files the deletion routine could not manage to remove at the time, which names your old account folder until a reviewer clears it. It holds nothing you wrote and no picture of you, and it goes when the file does.
Deletion is final. There is no password and nothing that could prove a deleted account was yours, so neither you nor we can bring it back; registering again, by any of the three doors, starts a new and empty account. Copies in encrypted backups age out within 30 days.
17. Your rights
You can ask us to show you your data, correct it, delete it, restrict what we do with it, hand it to you in a portable form, or object to processing we base on legitimate interest. Where we rely on your consent you can withdraw it at any time, in the app or by writing to us.
Write to info@eayniapp.com, or use the account screens in Settings. We answer within one month. If you are not satisfied you can complain to the Dutch data protection authority, the Autoriteit Persoonsgegevens (autoriteitpersoonsgegevens.nl), or to the authority where you live.
18. Reporting something that should not be here
Every profile and every conversation has a report button, and you can block anyone. Reports reach a reviewer, who can warn, suspend or remove an account.
If you believe something here is illegal rather than merely unpleasant, there is a form at wudd.be/report, and Settings has a row that opens it. Anybody can use it, with or without an account. It asks what the content is, where to find it, why you believe it is unlawful, and how to reach you, because those are the things the law requires us to collect. We confirm that we have it and we tell you what we decided.
19. Children
Wudd is strictly for people aged 18 and over. We ask for a date of birth, we check the age it produces, and every profile is read by a person before it is introduced to anyone. If we find an account belonging to someone under 18 we remove it and delete what it holds.
20. Security
Everything travels over HTTPS. The database enforces, row by row, that you can only reach your own data and the data of people you are actually connected to. Selfies, identity documents, voice notes and photographs sent inside a conversation sit in private storage with no public link at all. Profile photos are served through links that expire within the hour, and the database decides for every single file whether the person asking is allowed to open it. Personal data is kept out of our logs. Reviewer access is limited by role and is itself recorded.
No system is perfectly secure. If something happens that puts your data at risk, we will tell the Dutch data protection authority within 72 hours as the law requires, and we will tell you where the law requires that too.
21. Changes to this policy
We will tell you in the app when something material changes here, and the version and date at the top will move. The current version is 2.0, of 20 September 2026.
22. This website, and the waitlist
Everything above describes the Wudd app. This section describes wudd.be itself.
The site sets no cookies, contains no analytics, no advertising and no social-media trackers, and does not profile visitors. Nothing loads from a third-party domain. That is why there is no cookie banner: there is nothing to consent to.
The waitlist form at wudd.be/join stores what you type: first name, email address, optional phone number, gender, year of birth, town and country, a free-text note, and your answers about education, work, languages, lifestyle and partner age. The basis is your consent, given by ticking the box, and you can withdraw it by writing to info@eayniapp.com, which deletes the entry. It is not a newsletter list and it is not sold.
Faith answers on the waitlist sit behind their own separate tick box. If you answered them and do not tick the box, the form will not send: it asks you either to tick it or to clear those answers, and nothing reaches us until you choose. Leave them blank and the rest of the form works as normal. Where you tick it, the basis is your explicit consent and §4 applies.
Your wali's name is optional on the form, and it is personal data about somebody else. We keep only a first name and a relationship, we hold no contact details for him, we never contact him on the basis of it, and we delete it with the rest of your entry. Because we have no way to reach him, telling him directly would be impossible within the meaning of Art. 14(5)(b), so we ask you to tell him you gave us his first name. If he contacts us, we will tell him what we hold and delete it on request.
Waitlist entries are kept until Wudd opens in your town and you have either created an account or told us you are no longer interested, and in any case no longer than 18 months. If Wudd never launches, we delete the whole list and tell everyone on it that we have.
23. Contact
info@eayniapp.com · Wudd, Ru Parelaan 199, 3527 LJ Utrecht, Netherlands · KvK 42136139