Your answers have a purpose and an end.
This notice explains what Naseeb collects for the launch waitlist, accounts, saved intakes, matchmaking and subscriptions; how a human matchmaker and the compatibility software use it; who can receive it; how long it is kept; and how you can stop that processing or erase your data.
What is collected
If you join the launch waitlist, Naseeb records only the email address you enter, whether you confirmed or unsubscribed, the page source, relevant timestamps, and the version and digest of this notice. Confirmation and unsubscribe links are represented in the database only by one-way hashes; the link credentials themselves are sent by email and are not retained in readable form. Joining the waitlist does not create a matchmaking account or questionnaire profile.
The individual intake can include your name, email, date of birth, location, photographs, education and work, religion, denomination, community, ethnicity, health or disability information, family relationships and estrangement, finances, politics, sexual life, orientation and intimacy, relationship history, preferences, and free-text narratives.
The family intake can include a respondent’s email address and answers about religion, community, family expectations, work, living arrangements, marriage costs, politics, and related household views. If one person selects “Both parents, together,” that is recorded as one invited respondent’s description of a household view. It is not proof that a second adult separately consented.
Naseeb also creates operational data: a verified account and selected role, a candidate-authorized link to an invited parent, saved-draft answers and resume position, adult-eligibility state, matchmaker notes, compatibility categories, hard-filter outcomes, compliance review flags, introduction decisions, delivery state, security audit events, and keyed deletion receipts. A private Airtable base receives a limited operational mirror of new waitlist signups and currently consented accounts: opaque Naseeb identifiers, email, role, lifecycle and access state, parent-candidate link state, provider-neutral subscription state, timestamps, and counts. Airtable does not receive questionnaire or draft answers, photographs or photograph links, date of birth, location, private match or family notes, credentials, security logs, or Stripe identifiers. SQLite remains the source of truth. At the waitlist, public account, and family-access boundaries, Cloudflare Turnstile processes ordinary network, browser, and device signals and returns a short-lived security result used to distinguish people from automated abuse. Naseeb does not store the Turnstile response token or a Cloudflare device identifier.
For subscriptions, Naseeb records which verified account pays for which candidate, opaque Stripe customer, checkout and subscription references, subscription state, paid-through and cancellation dates, and bounded webhook-processing evidence. Payment card details are collected by Stripe’s hosted pages and are not stored in Naseeb’s database.
How it is used
- A waitlist email address is used only to confirm the request and send launch or availability updates. It is not used for matchmaking, a questionnaire, or targeted advertising.
- A human matchmaker reviews the private register and decides whether to make an introduction.
- Software compares structured answers, applies hard filters, calculates compatibility, and raises review flags. It does not make or send an introduction by itself.
- Email control and date of birth are checked before a new profile can become active.
- After email verification, an eligible candidate or invited family respondent can save and resume an incomplete form from their own account.
- A candidate or a verified, candidate-linked parent can fund the candidate’s single subscription. Payment never grants access to answers and does not stand in for matchmaking or family-processing consent.
- Security logs, delivery records, and a keyed external privacy-control ledger protect the service and prevent an old backup from silently restoring a deleted profile or withdrawn processing state.
Naseeb does not sell personal data and does not use it for targeted advertising.
How long it is kept
| Data | Current retention |
|---|---|
| Launch waitlist | An unconfirmed entry is removed after seven days. A confirmed entry is kept until the launch or availability notice is sent, the person unsubscribes or asks for deletion, or the service closes. After unsubscribe, Naseeb keeps only the minimum email and opt-out evidence needed to honor the choice, resolve a delivery complaint, or close the service. |
| Private Airtable operational mirror | The corresponding mirrored record follows the source record's lifecycle. An unconfirmed waitlist mirror is deleted with the seven-day source expiry; an erased account, profile, link, subscription subject, or waitlist entry is deleted from the mirror. An unsubscribed waitlist mirror is reduced to the minimum opt-out identity and time. Questionnaire answers, photographs, credentials, private notes, security logs, and Stripe identifiers are never placed in this mirror. If Airtable is unavailable, a remote update or deletion can remain pending without delaying the local signup, unsubscribe, withdrawal, or deletion. |
| Candidate profile, photos, active family data, introductions and feedback | No automatic inactivity expiry. Active while consent is current; after withdrawal, the profile is held out of matchmaking until the candidate reconsents or deletes it. Otherwise kept until deletion or service closure. |
| Verified account and parent-candidate link | Kept until account deletion, link revocation, or service closure. A candidate profile deletion does not silently erase a separate parent role or the minimum payment records needed to end and reconcile a subscription. |
| Incomplete candidate or family draft | Removed after 30 days without a save. A family draft is removed sooner when its candidate-issued invitation expires or is revoked. New photograph files are not part of saved drafts and must be selected again before final submission. |
| Family invitation and protected form session | The invitation normally expires after 14 days. The protected browser session expires after 2 hours. |
| Sign-in, intake-verification and browser-session credentials | Login links/codes and intake verification codes become unusable after 15 minutes. Candidate sessions become unusable after 30 days; console sessions after 12 hours. Used or expired credential/session rows are removed during the next retention-maintenance run, and a new intake challenge replaces the earlier challenge for that address. |
| Rejected, replaced, cancelled or quarantined family response bodies | Erased from the live register after 90 days. A direct withdrawal removes the live submitted version immediately; older snapshots may retain its bytes until rotation, while the external privacy control prevents it becoming live after a restore. |
| Declined, revoked or expired invitation records | Removed after 90 days. A consumed invitation remains with its family-form version until that version is withdrawn, deleted, or reaches its applicable retention event. |
| Email delivery log / security audit log | 180 days / 365 days. Delivery logs can contain the recipient, subject and non-credential message content; credential-bearing bodies are redacted. Security audits can contain the actor address or request IP, action and bounded detail. |
| Turnstile security challenge | The single-use response token is checked with Cloudflare and is not written to Naseeb's database or logs. Cloudflare's handling of the network, browser, and device signals it processes is governed by its own service and privacy terms. |
| Subscription and payment-operation records | Opaque customer, checkout, subscription, invoice and event references, lifecycle state, payer-beneficiary linkage, and cancellation/reconciliation evidence are kept while needed to administer the subscription, resolve disputes, satisfy legal obligations, and reconcile with Stripe. Naseeb does not store card numbers or full Stripe webhook bodies. |
| Daily-delivery quota receipt | Eight days. |
| Nightly database snapshots | The newest 7 successful snapshots are kept. This is a count, not a guaranteed seven-day window. |
| Pre-deployment database snapshots | Files older than 14 days are removed during a successful deployment. A profile deletion replaces restorable snapshots sooner so deleted data cannot be restored from them. |
| Encrypted backup bundles | Each day an encrypted backup bundle is sealed to a second disk on this machine and copied to off-machine storage. Bundles hold the same data as the live record, including photographs, and can be read only with a passphrase that is kept off this machine. Bundles are deleted 30 days after they are made, on the second disk and in the off-machine storage alike, so a deleted profile’s data leaves every backup within 30 days of the deletion. The live record and the on-machine snapshots are rewritten at the moment of deletion. The storage provider may keep its own recoverable copy of a deleted bundle for a further period; those copies remain encrypted. |
| Page-visit records | GoatCounter’s records are deleted a year after the visit. Cloudflare keeps its Web Analytics records under its own terms. |
| Deletion, withdrawal and reconsent protection receipt | A keyed pseudonymous control is kept outside the restorable data volume without a scheduled expiry so an old backup cannot resurrect deleted data or reverse the latest withdrawal/reconsent order. It records random privacy identifiers, the control event and time, the notice version/hash when applicable, and signed migration-only record/form numbers, form version and original creation times needed to recognize a pre-privacy backup. A keyed one-way email digest is also retained for deletion replay; the ledger does not contain the plain email, name, answers, photographs, IP address, user agent, or response text. |
Your choices
Waitlist permission, the individual intake, the family respondent intake, and a candidate’s authorization of a family round are separate choices. Each is recorded separately against this notice. The optional private-compatibility switch is separate again and starts off. Paying for a subscription is a separate transaction; it never supplies or widens any of those permissions.
A waitlist request must be confirmed through the email sent by Naseeb. Every waitlist message includes an unsubscribe link. You can also ask [email protected] to remove the entry. Unsubscribing from the waitlist does not delete an independently created Naseeb account, and deleting an account does not silently subscribe or unsubscribe a separate waitlist entry.
A candidate can withdraw future matchmaking processing or permanently delete the profile from the Privacy tab. Deletion is refused while a subscription for the profile is live in any state — starting, active, ending, past due, suspended, paused or on hold — or while a checkout for it is unresolved. If your own account pays for a subscription, deletion also waits until that billing is settled. Cancel or settle first, then delete. A deletion requested while a private email for the profile is being delivered is refused for a moment and can be retried. Withdrawal stops new matching, compatibility disclosure, family processing, and unsent introductions. A message already accepted by or in flight with the email provider may still arrive, and a photograph already delivered cannot be recalled. The held profile remains available to its owner for review, reconsent, or deletion.
A family respondent can use the original emailed code on the family page to withdraw a completed response. One respondent’s withdrawal invalidates and erases the whole derived family version rather than silently treating it as a different household.
Security and files
The public service must use HTTPS, owner-only application files, restricted administration, expiring credentials, verified backups, and an external anti-rollback erasure ledger. The repository does not provide application-level encryption of SQLite, photographs, or JSON downloads. Device and backup encryption are deployment responsibilities. A downloaded intake backup is a plain JSON file; store or delete it accordingly.
To ask a privacy question or make a request you cannot complete in the site, write to [email protected].
This product notice is written for Naseeb’s stated Florida, United States operating jurisdiction. Other laws can apply based on where a person lives or where the service is offered.