Privacy Policy

Effective: 20 September 2026 · Last updated: 20 September 2026 · Version: 2.0 (replaces the version of 11 August 2026)
Controller: Wudd, Ru Parelaan 199, 3527 LJ Utrecht, Netherlands · Chamber of Commerce (KvK): 42136139
Contact: info@eayniapp.com

The short version

Wudd introduces Muslims to each other for marriage. To do that we hold your profile, your photos, what you told us about your faith and your life, and the conversations you have here. We show your profile only to the few people you are introduced to, never to the open internet. We do not sell anything about you, we show no advertising, and we do not track you across other apps or websites. Everything below is the detail.

If you only read one more paragraph, read this one: your faith answers are special category data under European law, we ask for them only to find you someone compatible, we ask separately and clearly for your permission, and you can take that permission back at any time.

1. Who we are

Wudd is a verification-first matrimonial app for Muslims seeking marriage, operated by Wudd, Ru Parelaan 199, 3527 LJ Utrecht, Netherlands, registered with the Dutch Chamber of Commerce under number 42136139. We are the data controller for everything described here.

We are a small team. There is no separate data protection officer; questions, requests and complaints all reach a person at info@eayniapp.com, and we answer within one month.

2. How your account is created

You register in one of three ways, and the three are equal: a phone number verified with a one-time code, Sign in with Apple, or Sign in with Google. Whichever you choose is the key to the account and is how you sign in again on a new phone. Apple and Google hand us an email address, which is stored against your account and used for nothing but signing you in; Apple's private-relay addresses are treated the same way. A phone number is not required for an Apple or a Google registration, and you can add one later in Settings.

Behind all three the app first takes an anonymous identity from our authentication provider, so that registration can begin before you have given us anything at all. Everything described in this policy hangs on that identity. There is no password anywhere in Wudd.

Signing out leaves your account exactly as it is. Your profile, your photos, your matches and your messages stay where they are, and you sign back in the same way you registered. Deleting is the final act, and section 16 says exactly what it removes and what it cannot.

3. What we collect, why, and on what basis

WhatWhyLegal basis
Phone number, if you register with oneSigning in; one account per person; blocking (see §11)Contract (Art. 6(1)(b))
Email address, if you sign in with Apple or GoogleSigning inContract
First name, date of birth, genderYour profile; proving you are 18 or overContract
Your town, and where your phone is when you open the app, if you allow it. We round the position to about a kilometre before we store it, keep only the latest one, and never read it in the background. If you do not allow it, we use the centre of the town you typedShowing your town, the distance filter, and measuring distance between you and the people you might meet and to a meeting place. Others see your town and a rounded distance, never your positionContract
The two-letter country your phone is inThe country filter, so you are found where you actually areContract
Your time zoneSo a notification at night is night where you areContract
Photos, and the blurred copies made from themYour profile. For women, the blurred set is what men see until you matchContract; explicit consent for processing your image (Art. 9(2)(a))
The selfie taken during registrationProving the photos are of you. Never shown to another memberExplicit consent (Art. 9(2)(a))
An identity document, if you choose to show oneThe second check mark. Voluntary, and the picture is deleted the moment a reviewer decides (§6)Explicit consent (Art. 9(2)(a))
Faith answers: tradition, how you practise, prayer, and related lifestyle answersThe heart of the matchingExplicit consent (Art. 9(2)(a))
Ethnicity, if you give itMatching and filtersExplicit consent (Art. 9(2)(a))
Education, work, languages, height, build, family plans, and the rest of your answersMatching and filtersContract
What you write about yourself, your reflections and icebreaker answersYour profile and your conversationsContract
Who you were introduced to, who you said yes or no to, and whenRunning the introductions, and not showing you the same person twiceContract
Your conversations: messages, voice notes, photos sent in chatProviding the conversationContract
Calls: that a call happened, when, and how long. Never the sound or pictureThe milestones in a conversation, and your wali's view if you gave him oneContract
Meeting arrangements: the place proposed, the time, and whether it happenedRunning the meeting phaseContract
Fingerprints (hashes) of numbers from your address book, if you use contact blockingKeeping people you know out of your introductions (§11)Consent (Art. 6(1)(a))
Reports you make and reports about you, and blocksSafety, and acting on abuseLegitimate interest (Art. 6(1)(f)) and legal obligation
Reviewer notes and gradesChecking profiles are genuine and suggesting balanced introductions (§7)Legitimate interest, and explicit consent where derived from the answers above
Your notification token and your notification settingsSending the notifications you asked forContract
A device identifier used by the notification and crash-reporting librariesDelivering a notification to the right phone; grouping crash reportsContract, and legitimate interest for crashes
When you last opened the appOrdering introductions, and setting aside accounts that have gone quietContract
Your wali's first name, the fact of the link, the milestones he was shown, and a token for his device if he allows notificationsGiving your guardian the view you chose to give him (§8)Contract, on your instruction
That you bought a membership, which one, and until whenGiving you what you paid forContract
Crash reportsKeeping the app workingLegitimate interest (Art. 6(1)(f))
Usage analyticsUnderstanding which parts of the app are usedConsent (Art. 6(1)(a)). Off unless you switch it on in Settings

We do not sell personal data. We show no advertising. We do not track you across other companies' apps or websites, and we do not work with data brokers or ad networks.

4. Faith, ethnicity, and the fact that you are looking to marry

Your tradition, how you practise, your prayer habits and your ethnicity are special category data under Article 9 GDPR. So, arguably, is the simple fact that you use a matrimonial app, because it says something about who you are looking for.

We handle all of it the same way:

5. Photos, the selfie, and the blurring

Your photos. You upload up to three. They are held in our file storage at Supabase. The database decides, file by file, who may open one: you, a reviewer, somebody you have matched with, or somebody who has you in their introductions today, and for a woman's photographs everyone in that last group sees only the blurred copies. The app fetches them through links that expire within the hour. A reviewer looks at them before your profile can be introduced to anyone.

The blurring. For women's profiles, an automated service makes a copy of each photo with the person softly blurred, and that blurred set is what men see until the two of you have matched. The sharp originals stay for you and for reviewers. The service runs on Google Cloud in the European Union and does one thing: it separates the person from the background and blurs the person. It does not recognise faces, does not build a face template, and keeps nothing after it has written the blurred copy back.

The trigger that calls it sends five things and nothing else: which account the photographs belong to, whether the profile is a woman's, the photo list, the blurred list, and the review status. Your answers never go near it.

The selfie. During registration you take one selfie, straight after your photos. It exists for a single reason: so that a reviewer can see that the person in the photos is the person holding the phone. It is never shown to another member, it lives in a private area that only you and reviewers can open, and it is kept while your account exists because it is checked again each time you change a photo. A reviewer compares it by eye. No facial recognition, no biometric template, no automated matching of faces is used anywhere in Wudd.

6. The identity check, if you want it

Any member may show a passport, identity card or driving licence once, from Settings. It is entirely voluntary and nothing in the app is closed to you if you skip it.

If you do it: you photograph the side with your picture. A reviewer looks at exactly three things and compares them with your profile: the face, the first and last name, and the date of birth. Nothing is copied from the document, ever. The picture is deleted the moment the reviewer decides. A picture nobody has looked at within three days is deleted automatically and you are asked to send it again. What stays afterwards is the verdict, the date, and which kind of document it was.

A confirmed identity shows as a second mark on your profile and moves your interest higher in the other person's list.

7. Reviewers, and how grading works

Every profile is read by a trained reviewer before it can be introduced to anyone: the photos against the selfie, and the written answers. Reviewers are under contract and bound to confidentiality, and their access is limited by the database itself, not by a promise.

Reviewers also record internal grades: how well the photographs are made, how the profile reads, the stage of your working life, and an appearance grade. Together they make one number. Its purpose is to suggest balanced introductions, pairing profiles of comparable standing. Grades are never shown to you, never shown to other members, and never sold.

Be aware of what that number does. It does not only order your introductions: the people you are shown are drawn from a band around your own grade, so it shapes who you meet here. It never closes the app to you, and it never leaves our own reviewers.

Because that is profiling, you may ask us what your grade is, tell us why you think it is wrong, and ask for a fresh review by a different person. We do not make decisions about you by automated means alone: a person sets every grade, and a person looks again when you ask.

Edits to your open answers after your profile is live go through the same queue and can be rolled back by a reviewer if they break the rules.

8. Your wali

You may create a code and give it to a guardian. He does not need an account: the code is how he signs in, and he sees a page of milestones only: that you matched, and the first name of the person; that a call has been agreed; that a meeting was agreed; and whether your photographs have been verified. He is not told how long a call lasted. He chooses which of these reach him as notifications.

He never sees the contents of your conversations. Not the messages, not the voice notes, not the photos. This is a deliberate difference from other apps in this category, some of which send a guardian transcripts.

You can revoke the code at any time, and doing so ends his access immediately. We hold his first name, the fact of the link, the milestones he was shown, and, if he allows notifications, a token for his device.

9. Conversations, calls and meeting

Messages, voice notes and photos in chat are stored so the conversation works, in storage only the two of you and, where necessary, a reviewer acting on a report can reach. A photo you send as view-once is removed once it has been seen. Deleting a message removes it for both of you.

Calls run through LiveKit, a third party that carries the audio and video between the two phones. The conversation itself is not recorded and never reaches us: what we keep is that a call took place, when it started and ended, and how long it lasted, because that is what carries the conversation into its next stage. Your wali is told that a call has been agreed and nothing more (§8).

Meeting in person. When you agree a place and a time, we store which place and when, and afterwards whether the meeting happened. The places themselves are a list we maintain; suggesting one near you uses the same rounded position or town described above, and nothing more. If you add the meeting to your phone's calendar, that happens on your phone and we are not involved.

10. Notifications

If you allow them, your phone is issued a notification token that we store against your account so a message can reach the right device. Notifications are sent through Firebase Cloud Messaging (Google). You choose which kinds you want in Settings, and quiet hours are honoured in your own time zone.

11. Blocking people you know

You can hide from anyone in your address book, so that a cousin or a colleague is never introduced to you. This is switched off unless you turn it on.

If you turn it on, the app reads your contacts on your phone, converts each number into a fingerprint (a one-way hash) and sends only those fingerprints. The numbers themselves never leave your phone. Your own number is fingerprinted the same way so the matching works in both directions.

Each fingerprint is hashed a second time on our server, with a value that exists only inside the database and that nothing we run will hand back. So a stolen database gives up no address books at all: turning a fingerprint into a phone number needs that value too, and unpacking the app does not yield it.

We do not read names, email addresses or anything else from your address book, and we never contact anyone in it.

12. Analytics, crash reports, and what we do not do

Crash reports (Firebase Crashlytics) are on. A crash report carries what went wrong and an install identifier, and we deliberately do not attach your account to it.

Usage analytics (Firebase Analytics) are off until you turn them on. Collection is disabled when the app is built, and it stays off until you say otherwise.

We ask you once. Not at registration, where nobody yet knows what the app is, but after you have answered your first three introductions: a sheet asking whether we may see which screens get used and where people give up. Yes or not now, once, and it never comes back either way. The switch is then yours in Settings, under Your data, and it works in both directions at any time.

In either state we are never sent what you wrote, who you spoke to, or your name. There is no pop-up on first launch asking you to accept tracking, because there is no tracking to accept.

We do not use advertising identifiers and we do not ask for App Tracking Transparency permission, because nothing here follows you across other companies' apps or websites. Google's measurement library on iPhone brings an advertising conversion component along with it; we never call it, there is no advertising account behind it, and Wudd carries no advertising of any kind.

13. Paying for a membership

Wudd Premium is bought through the Apple App Store or Google Play. Your card details go to the store, never to us. What reaches us is the confirmation that a purchase happened, which plan it was, and when it runs out, so we can switch the extra features on. The stores also tell us when a subscription renews, lapses or is refunded.

14. Who else touches your data

WhoWhat forWhere
SupabaseDatabase, file storage, authenticationEuropean Union
TwilioSending the one-time code by SMS. Receives your number and the six digits, nothing elseUnited States; standard contractual clauses
Google CloudThe photo-blurring serviceEuropean Union (Belgium)
Google FirebaseNotifications, crash reports, and analytics if you turned it onUnited States; standard contractual clauses
LiveKitCarrying call audio and video. Not recordedUnited States; standard contractual clauses
Apple, Google (stores)Selling and renewing membershipsTheir own terms; they are the seller, not us
ReviewersChecking profiles, handling reportsContracted, confidentiality bound, access limited by role

Everything at the centre of the app, your profile, your photos and your conversations, is stored in the European Union. The transfers marked above leave the EEA and rely on standard contractual clauses approved by the European Commission, together with the protections those providers publish. We have a data-processing agreement with each processor.

We will hand data to the police or another authority only where the law requires it, and we will tell you unless we are forbidden to.

15. How long we keep things

WhatHow long
Your account and everything attached to itWhile the account exists
The selfieWhile the account exists, because it is rechecked on every photo change
An identity document pictureUntil the reviewer decides, and in any case no more than three days
The verdict of an identity checkWhile the account exists
An interest you sent that nobody answeredSeven days, then it lapses quietly
A conversationWhile it is open, and as part of your account afterwards
Contact fingerprintsUntil you turn contact blocking off, or delete your account
Reports about youKept after deletion, with your profile detached, where we need them to keep other people safe
A fingerprint of your number, where somebody blocked youKept after deletion, so that deleting and registering again is not a way around a block
Verification codes and transient server logsShort-lived, days at most
Encrypted backupsResidual copies age out within 30 days

16. Deleting your account

Settings → Account → Delete. One server-side operation runs, and it can only ever act on your own account. It removes your photos, both the sharp originals and the blurred copies, the voice notes and the photographs sent inside your conversations, the record that a call connected, and then the account itself, which cascades through your profile, your answers, your introductions, your interests, your matches and the messages inside them, your reviewer grades and your notification tokens.

Two things survive on purpose. A report somebody made about you is kept with your profile detached, because it concerns another person's safety rather than yours. And where somebody blocked you, a fingerprint of your phone number stays on their list, so that deleting your account and registering again is not a way around their block. That fingerprint is not a number and cannot be turned back into one; it names you to nobody, and it sits under the account of the person who blocked you rather than under yours.

One technical trace can outlive the account: a list of files the deletion routine could not manage to remove at the time, which names your old account folder until a reviewer clears it. It holds nothing you wrote and no picture of you, and it goes when the file does.

Deletion is final. There is no password and nothing that could prove a deleted account was yours, so neither you nor we can bring it back; registering again, by any of the three doors, starts a new and empty account. Copies in encrypted backups age out within 30 days.

17. Your rights

You can ask us to show you your data, correct it, delete it, restrict what we do with it, hand it to you in a portable form, or object to processing we base on legitimate interest. Where we rely on your consent you can withdraw it at any time, in the app or by writing to us.

Write to info@eayniapp.com, or use the account screens in Settings. We answer within one month. If you are not satisfied you can complain to the Dutch data protection authority, the Autoriteit Persoonsgegevens (autoriteitpersoonsgegevens.nl), or to the authority where you live.

18. Reporting something that should not be here

Every profile and every conversation has a report button, and you can block anyone. Reports reach a reviewer, who can warn, suspend or remove an account.

If you believe something here is illegal rather than merely unpleasant, there is a form at wudd.be/report, and Settings has a row that opens it. Anybody can use it, with or without an account. It asks what the content is, where to find it, why you believe it is unlawful, and how to reach you, because those are the things the law requires us to collect. We confirm that we have it and we tell you what we decided.

19. Children

Wudd is strictly for people aged 18 and over. We ask for a date of birth, we check the age it produces, and every profile is read by a person before it is introduced to anyone. If we find an account belonging to someone under 18 we remove it and delete what it holds.

20. Security

Everything travels over HTTPS. The database enforces, row by row, that you can only reach your own data and the data of people you are actually connected to. Selfies, identity documents, voice notes and photographs sent inside a conversation sit in private storage with no public link at all. Profile photos are served through links that expire within the hour, and the database decides for every single file whether the person asking is allowed to open it. Personal data is kept out of our logs. Reviewer access is limited by role and is itself recorded.

No system is perfectly secure. If something happens that puts your data at risk, we will tell the Dutch data protection authority within 72 hours as the law requires, and we will tell you where the law requires that too.

21. Changes to this policy

We will tell you in the app when something material changes here, and the version and date at the top will move. The current version is 2.0, of 20 September 2026.

22. This website, and the waitlist

Everything above describes the Wudd app. This section describes wudd.be itself.

The site sets no cookies, contains no analytics, no advertising and no social-media trackers, and does not profile visitors. Nothing loads from a third-party domain. That is why there is no cookie banner: there is nothing to consent to.

The waitlist form at wudd.be/join stores what you type: first name, email address, optional phone number, gender, year of birth, town and country, a free-text note, and your answers about education, work, languages, lifestyle and partner age. The basis is your consent, given by ticking the box, and you can withdraw it by writing to info@eayniapp.com, which deletes the entry. It is not a newsletter list and it is not sold.

Faith answers on the waitlist sit behind their own separate tick box. If you answered them and do not tick the box, the form will not send: it asks you either to tick it or to clear those answers, and nothing reaches us until you choose. Leave them blank and the rest of the form works as normal. Where you tick it, the basis is your explicit consent and §4 applies.

Your wali's name is optional on the form, and it is personal data about somebody else. We keep only a first name and a relationship, we hold no contact details for him, we never contact him on the basis of it, and we delete it with the rest of your entry. Because we have no way to reach him, telling him directly would be impossible within the meaning of Art. 14(5)(b), so we ask you to tell him you gave us his first name. If he contacts us, we will tell him what we hold and delete it on request.

Waitlist entries are kept until Wudd opens in your town and you have either created an account or told us you are no longer interested, and in any case no longer than 18 months. If Wudd never launches, we delete the whole list and tell everyone on it that we have.

23. Contact

info@eayniapp.com · Wudd, Ru Parelaan 199, 3527 LJ Utrecht, Netherlands · KvK 42136139