Marryfix Privacy Policy
Effective Date: June 9, 2026
Last Updated: August 19, 2026 (version 4)
> Translation notice: This English translation is provided for informational purposes only. The original Turkish text is the sole legally binding version; in the event of any conflict or inconsistency between this translation and the Turkish original, the Turkish text prevails.
Our Commitment to You
Your privacy is one of the highest priorities for Marryfix. It is at the core of how we design and build the services and products you know and love, so that you can fully trust them and focus on making meaningful connections.
We are grateful that you trust us with your information, and we do not take that lightly.
Our privacy commitment: We design all of our products and services with your privacy in mind. In every decision we make, we involve experts from law, security, engineering, product design, and many other fields to keep our respect for your privacy at the highest possible level.
Our transparency commitment: Because we use many of the same online services you do, we know that insufficient information and overly complex language are common problems in privacy policies. That's why we take the opposite approach and do our best to write our Privacy Policy and related documents in plain language — because we genuinely want you to read our policies and understand our privacy practices!
Our security commitment: We have teams dedicated to keeping your data safe. We continuously update our security practices and invest in our security efforts to strengthen the safety of your information.
1. Who Are We?
Welcome to the Marryfix Privacy Policy.
Marryfix is not a company — it is a service operated by an individual (natural person) developer. The data controller responsible for your information under this Privacy Policy is:
İsmail Nebi GENÇ
Küçüksu Mahallesi, Rasathane Caddesi, No: 54/2, Üsküdar / İSTANBUL, Türkiye
Phone: +90 539 910 96 35
Email: support@marryfix.com
If the individual developer begins operating in the future through a virtual office or a legal entity, this information will be revised here under the same versioning rule (effective date and version number updated).
> Global service note: Marryfix provides its service to users worldwide from a single base (Türkiye, individual developer). You can always reach the data controller directly using the §1 information above and support@marryfix.com. For additional rights specific to your region, see §12 (Regional Supplementary Provisions).
2. Where Does This Privacy Policy Apply?
This Privacy Policy applies to the websites, applications, events, and other services we operate under the Marryfix brand. For simplicity, we refer to all of these as "services" in this Privacy Policy.
Some services may require their own specific privacy policies. If a particular service has its own privacy policy, that policy applies instead of this Privacy Policy.
3. Information We Collect
Needless to say, we cannot help you develop meaningful connections without some information about you, such as basic profile information and the kind of people you'd like to meet. In addition, we collect technical/usage data generated while you use our services, and information other members share about you (registration/sign-in via a social media account is not offered as of launch — see the "Social Media" item below). More details can be found below.
Information You Give Us
When you use our services, you choose to give us certain information. This includes:
- When you create an account, you provide us with at least some basic information, such as your first and last name, phone number, email address, and gender and date of birth, which are necessary for the service to function.
- When you complete your profile, you may share additional information with us, such as details about your bio, your interests, and other details about yourself, as well as content such as photos and videos. To add certain content, such as pictures or videos, you may allow us to access your camera or photo album.
- When you subscribe to a paid service, your payment is processed through the App Store / Google Play; your credit/debit card number never reaches us — it is only processed within the payment infrastructure of the relevant store. We only receive the purchase/subscription status information the store passes to us (e.g. product ID, transaction date). If an out-of-store purchase option is offered in the future, card information will only be processed through a PCI-DSS-compliant payment service provider and will never be transmitted to us.
- When you participate in surveys, focus groups, and market research, you provide us with insights about our products and services, answer our questions, and provide customer feedback.
- When you choose to participate in our promotions, events, and contests, we collect the information you use to register or enter.
- When you contact our customer service team, we collect the information you give us during that interaction.
- If you share information about other people with us (for example, a friend's contact information for a specific feature), we process this information on your behalf to complete your request.
- Of course, we also process your chats with other members and the content you post, as necessary for the services to function.
Information We Receive From Others
In addition to the information you may give us directly, we also receive various information about you from others, including:
- Members: Members may provide information about you while using our services — for example, when interacting with you or sending a notification concerning you.
- Social Media (not currently active): Creating/signing in to a Marryfix account through social media or another account (e.g. Facebook, Google, or Apple), and importing photos from your social media accounts, is not offered as of launch; registration is only performed via email/phone. If this feature is added in the future, it will be announced in advance and this section will be updated.
- Other Partners (not currently active): Since Marryfix does not operate any advertising partner as of launch, no third-party information about advertising campaign performance is collected (see the "no advertising" note in §7). In addition, Marryfix does not obtain criminal record or "convicted person" information about users from third parties, and does not conduct any such screening — see Terms of Use §10 and Safety Tips. If either of these points changes in the future (e.g. an advertising partnership is established), advance notice and an update to this policy are required.
Information Collected When You Use Our Services
When you use our services, technical data is generated about which features you use, how you use them, and the devices you use to access our services. See below for more information:
- Usage Information: When you use the services, various data is generated about your activity on our services, including how you use them (e.g. the sessions you open, the features you use, the actions performed, the information shown to you, the address of referring web pages, and the advertisements you interact with) and your interactions with other members (e.g. the members you connect and interact with, interaction dates, and the number of messages you send and receive).
- Device Information: We collect information from and about the devices you use to access our services, including hardware and software information such as IP address, device ID and type, application settings and characteristics, app crashes, advertising identifiers (randomly generated numbers you can reset in your device's settings), cookies, or other identifiers associated with technologies that can uniquely identify a device or browser.
- Information Subject to Your Permission: If you grant permission, we collect your photos and videos (e.g. profile photo, chat media). Precise geolocation (latitude/longitude) and background location tracking (while the app is closed) are not active as of launch. If this feature is introduced in the future, it will only be activated with your separate, revocable, explicit consent and with advance notice; this Privacy Policy and the Explicit Consent Text will be updated before activation.
Identity Information (First and Last Name)
The first and last name information we collect during registration is processed according to the following principles:
- Collection: Through separate fields for first name and last name in the signup form.
- Visibility (last name field): The information you enter in the last name field is never shown to other users in the app interface; it is processed only for internal security and administrative purposes.
- Visibility (first name field): The information you enter in the first name field may be displayed to other users on your profile, given the nature of the service. You are expected to enter only your first name in this field.
- User responsibility: If you voluntarily enter your last name or full name into the first name field, that information may be visible to other members. This does not mean that the last name field is shown to other users by Marryfix; it results from content you entered into the first name field. Marryfix cannot be held responsible for the visibility of user-entered content in the first name field — independent of the last name field — unless there is an intentional last name disclosure on our system's part.
- Purposes of use:
* Account creation and completion of membership registration
* Ensuring account security, preventing abuse and fake accounts
* Investigating user complaints, reports, and disputes between users
* Conducting customer support processes
* Fulfilling legal obligations
* Establishing, exercising, or defending a legal right (e.g. our rights under the Terms of Use)
- Legal basis: Establishment and performance of the membership agreement, our legal obligations, and — provided it does not harm your fundamental rights and freedoms — our legitimate interest in maintaining account security and platform integrity (KVKK Art. 5).
- Sharing: Information in the last name field may be transferred to our hosting, customer support, and security infrastructure providers, and to legally authorized authorities, limited to the purposes above — it is not transferred to other members for profile or matching purposes. Since the first name field may be displayed on your profile, content you enter in that field may be seen by other members (see user responsibility above). For details, see the KVKK Disclosure Text.
Identity and Face Verification (Biometric Data)
To verify your profile and prevent fake accounts, we may ask you to go through a facial liveness detection and selfie-based identity verification process, either optionally or as required for access to certain features.
Important: This process involves the processing of biometric data (data relating to your face). The following principles apply:
- Purpose of processing: Verifying that your account belongs to a real person, detecting fake or impersonated profiles, and enhancing platform security.
- Data minimization: Your selfie image is not stored. The facial recognition data generated during verification is retained solely as an opaque FaceId within Amazon Web Services (AWS) Amazon Rekognition; the only record associated with your account is the opaque reference field in our database (`verifiedfaceref`).
- Place of processing: Biometric verification is performed in the AWS `eu-west-1` (Ireland — European Union data center) region.
- Legal basis: Your explicit consent (special-category personal data under KVKK Art. 6 and GDPR), together with our legitimate interest in ensuring platform security.
- Service provider: AWS acts as a data processor (sub-processor). A GDPR Data Processing Addendum (DPA) is signed under our AWS account.
- Retention period: Your FaceId reference is retained for as long as your account is active and as necessary for the verification purpose.
- Deletion: When you delete your account, your FaceId record is permanently deleted from AWS Rekognition via the `deleteEnrolledFace` operation, and the `verifiedfaceref` field in our database is also cleared. Since the selfie image is never stored, there is nothing further to delete.
You may decline to participate in the verification process; however, in that case your access to the verified profile badge or certain features requiring verification may be limited.
4. Cookies and Other Similar Data Collection Technologies
We may use, and allow others to use, cookies and similar technologies (e.g. web beacons, pixels, SDKs) to recognize you and/or your devices. For more information on why we use these and how you can better control their use, please read our Cookie Policy.
Some web browsers (such as Safari, Internet Explorer, Firefox, and Chrome) have a "Do Not Track" ("DNT") feature that tells a website that the user does not want their online activity tracked. If a website that responds to DNT signals receives one, it may prevent the browser from collecting certain information about the browser user. Not all browsers offer a DNT option, and DNT signals are not yet standardized. For this reason, many businesses, including Marryfix, do not currently respond to DNT signals.
5. How Do We Use Information?
The main reason we use your information is to provide and improve our services. In addition, we use your information to keep you safe and to show you advertisements that may be of interest to you.
A. To manage your account and provide you with services
- Creating and managing your account
- Providing you with customer support and responding to your requests
- Completing your transactions
- Communicating with you about our services
B. To help you connect with other users
- Recommending other members for you to meet
- Showing members' profiles to one another
C. To offer you new Marryfix services
- Registering you and displaying your profile in new features and apps
- Managing your account within these new features and apps
D. To conduct advertising and marketing campaigns (inactive at launch)
> Important — no advertising: As of launch, Marryfix does not run any third-party advertising network, custom/lookalike audience targeting, or advertising SDK. The items below only describe a possibility that could be activated in the future, with separate and revocable explicit consent; it is not a currently active practice. If activated, only an allowlist of advertising ID, attribution, and non-sensitive conversion data will be used. Message content, relationship/matching data, biometric data, precise location, contacts data, profile/test/compatibility data, and safety/sensitive preference data are never used for advertising, custom-audience, or lookalike-audience purposes — even if the user has given explicit consent. Hashed-email-based ad matching remains disabled without a separate assessment and separate opt-in.
- (If activated) Managing sweepstakes, contests, discounts, and other offers
- (If activated) Ensuring and measuring the effectiveness of advertising campaigns on our services and marketing campaigns promoting Marryfix outside our services — using only non-sensitive data on the allowlist
- (If activated) Contacting you about products or services we think may interest you, provided you have given separate marketing consent
E. To improve our services and develop new ones
- Managing focus groups, market research, and surveys
- Reviewing interactions with customer service teams to improve our service quality
- Understanding how members typically use our services in order to improve them
- Developing new features and services
F. To detect, prevent, and combat fraud and other illegal or unauthorized activity
- Detecting and investigating violations of our Terms of Use
- Better identifying violations of our Terms of Use and designing countermeasures
- Detecting fake or impersonated accounts through facial liveness and selfie verification processes
- Investigating and evaluating user complaints, reports, and disputes between users (identity information — including first and last name — may be used for internal record-keeping in these processes)
- Enforcing or exercising our rights, such as under our Terms of Use
G. To ensure legal compliance
- Complying with legal requirements
- Supporting law enforcement
Legal Bases
We rely on the following legal bases to process your information as described in this Privacy Policy:
- To provide you with services: We process your information for items A, B, and C above because it is necessary to perform our contract with you.
- Legitimate interests: We process your information for items D, E, and F above based on our legitimate interests. For example, we analyze user behavior to continually improve our services; we process your identity information (including first and last name) in account security, abuse prevention, and dispute review processes.
- Compliance with applicable laws and regulations: We process your information for item G above when we are required to comply with applicable laws and regulations.
- Consent: If you choose to share information with us that may be considered "special" or "sensitive" in certain regions, such as your sexual orientation, you have allowed us to process that information in accordance with this Privacy Policy.
- Biometric data consent: When you participate in the facial liveness and selfie verification process, you give your explicit consent to the processing of your biometric data (facial recognition data) as described above — without the selfie image being stored, retaining only an opaque FaceId reference, and processing it in the AWS `eu-west-1` region.
6. How Do We Share Information?
Since our goal is to help you make meaningful connections, members' information is of course primarily shared with other members.
Sharing with other members:
When you voluntarily disclose information by using our service (including your public profile), you share information with other users. Information you record in the last name field is not shown to other members; the first name field may be displayed as part of your profile. If you enter your last name or full name into the first name field, this may be reflected to other members as content you entered (see Identity Information (First and Last Name) and the KVKK Disclosure Text).
Sharing with our service providers and partners:
We rely on third parties to operate and improve our services. These third parties assist us with various tasks such as data hosting and maintenance, analytics, customer service, marketing, advertising, payment processing, and security activities.
For identity and facial verification services, we work with Amazon Web Services (AWS). Facial verification data is processed through the AWS Amazon Rekognition service, only in the `eu-west-1` (Ireland — EU data center) region. AWS acts as a data processor (sub-processor) under GDPR, and a GDPR Data Processing Addendum (DPA) is signed under our account. Your selfie image is not stored on AWS or Marryfix servers; only an opaque FaceId reference is retained.
For corporate transactions:
We may transfer your information if we become involved in a full or partial merger, acquisition, divestiture, restructuring, reorganization, dissolution, bankruptcy, or other change of management or control.
Sharing with law enforcement / as a legal requirement:
We may disclose your information when reasonably necessary to: (i) comply with legal process or requirements such as a court order, subpoena, or search warrant, or public/law enforcement investigations, (ii) assist in the prevention or detection of crime, or (iii) protect the safety of any person.
To enforce legal rights:
We may also share information when: (i) disclosure would reduce our liability in an actual or threatened lawsuit, or (ii) it is necessary to protect the legal rights of us, our members, our business partners, or other relevant parties.
7. Cross-Border Data Transfers
The sharing of information described in Section 6 involves cross-border transfers of data to the United States and other jurisdictions that may have different laws regarding data processing. When we transfer personal information outside the EEA, the United Kingdom, Switzerland, Türkiye, or other countries, we use standard contractual clauses or other appropriate transfer mechanisms.
Specifically regarding biometric verification data: facial verification is performed only in the AWS `eu-west-1` (Ireland) region, which is within the European Economic Area. Data processing safeguards apply under the GDPR DPA signed with AWS.
8. Your Rights
We want you to be in control of your information.
- Access/update tools within the service: Tools and account settings can help you directly access, correct, or delete information you have shared with us and that is associated with your account, from within the service.
- Device permissions: Mobile platforms may have permission systems for specific device data, such as contacts, photos, and location services on the phone.
- Uninstallation: You can stop all information collection by uninstalling the app using your device's standard uninstallation process.
- Account closure: You can close your account using the relevant function offered in the service.
We also want you to be aware of your privacy rights:
- Reviewing your information: The right to review personal information we hold about you.
- Updating your information: The right to request correction of inaccurate information.
In some countries, including the European Economic Area, the United Kingdom, and Türkiye, you have the right to lodge a complaint with the appropriate data protection authority if you have concerns about how we process your personal information.
9. How Long Do We Keep Your Information?
We retain your personal information only for as long as we need it for legitimate business purposes and as permitted by applicable law. The periods below reflect the actual retention/erasure mechanisms (retention worker) running in our code — for the current, detailed technical inventory, see `docs/privacy/DATARETENTIONPOLICY.md`.
- Chat messages: After a chat room ends, message content (body) is retained for a maximum of 12 months, after which the content is permanently deleted (including destruction of the encryption key — "cryptographic erasure"); only operational metadata (such as send time, message count) may remain.
- Recalled (unsent) messages: The content of a recalled message is permanently deleted within 90 days.
- Active complaint/legal dispute exception: If there is an active user complaint, security investigation, or legal dispute concerning you or your chat, the relevant messages may be retained separately — even after the normal period has elapsed — until the investigation/dispute concludes and an additional safety window (up to 180 days after the complaint is closed) has passed ("safety hold"); in exceptional cases, a legal hold approved by a super-admin, justified, and reviewed at least every 90 days may also apply. Outside these exceptions, no message is retained indefinitely.
- Chat media: 30 days (as described in §6 above), subject to the safety/legal hold exception.
- Profile photos (avatar): When you remove or change a photo, it is temporarily kept for 7 days in case you re-upload the same file; if it is not reused within that time, it is permanently deleted from our servers within 90 days. When you permanently delete your account (after the 30-day reversible waiting period), your photos are no longer needed for any purpose and are deleted the same day, without these waiting periods applying.
- Security audit logs: 12 months.
- Identity/facial verification decision metadata: 24 months (the selfie image itself is never stored — see above).
- After account deletion: For the sake of the other party's chat integrity, the message record is not deleted immediately; your identity is anonymized, and the message content is deleted at the end of the normal 12-month/90-day period described above, calculated from the room's closing date — account deletion does not reset or extend this period.
Message security (encryption): Chat message content is not stored as plaintext in the database; it is encrypted server-side with AES-256-GCM, and the encryption keys are managed through AWS KMS (Key Management Service) (envelope encryption). This is not end-to-end encryption (E2EE) — authorized personnel may view content during an authorized security/moderation review (e.g. investigating a complaint); however, direct access to the database (e.g. a breach) would expose encrypted data, not plaintext. Access is restricted on a role basis and every access is recorded in an audit log; see §8 (Your Rights) and the KVKK Disclosure Text.
Biometric verification data: Your selfie image is never stored. When account deletion is initiated, your FaceId record in AWS Rekognition is permanently deleted via the `deleteEnrolledFace` operation, and the `verifiedfaceref` field in our database is cleared. After the 30-day account deletion waiting period, this reference is fully removed along with your remaining personal data. You may withdraw your consent to biometric verification at any time; withdrawal automatically triggers deletion of your enrolled FaceId reference and revocation of your verification badge.
10. Children's Privacy
Our services are limited to individuals aged 18 and over. We do not allow persons under the age of 18 to use our platform. If you suspect that a member is under the age of 18, please use the reporting mechanism available in the service.
11. Changes to the Privacy Policy
This policy may change over time to ensure that the disclosures about our data practices remain current. We will notify you before any material change takes effect, so that you have time to review the changes.
12. Regional Supplementary Provisions
Marryfix applies a single global Privacy Policy; the provisions below are supplementary clauses that complement this policy depending on your region of residence, and in case of conflict, the more protective provision applies.
Türkiye (KVKK): For your rights and how to exercise them, see the KVKK Disclosure Text and the KVKK Application Process. Data controller contact information is provided in §1.
European Economic Area / United Kingdom (GDPR / UK GDPR): If you are a resident of the EEA/UK, you may direct your requests regarding the processing of your personal data directly to the data controller listed in §1, or lodge a complaint with the data protection authority in your own country.
Switzerland: The same provisions as the EEA/UK clause above apply.
United States — California (CCPA/CPRA): Marryfix does not sell your personal information or "share" it with third parties for advertising purposes (within the meaning of the CPRA). California residents have the right to know, delete, correct, port their data, and not be discriminated against. You can contact us at support@marryfix.com to exercise these rights. For subscription cancellation, also see the California subscribers clause at the beginning of the Terms of Use.
Other regions: If you live in a region not listed above, the general provisions of this Privacy Policy (§1-§11) apply to you.
13. How Can You Reach Us?
If you have questions about this Privacy Policy, you can reach us through the following channels:
Online: support@marryfix.com
By Mail:
İsmail Nebi GENÇ
Küçüksu Mahallesi, Rasathane Caddesi, No: 54/2, Üsküdar / İSTANBUL, Türkiye
Because Marryfix is operated by an individual developer, no separate Data Protection Officer (DPO) has been appointed; the communication channels above reach the data controller directly. For formal applications under KVKK, see the KVKK Application Process.