Naseeb
Privacy and retention · Florida, USA

Your answers have a purpose and an end.

This notice explains what Naseeb collects for the launch waitlist, accounts, saved intakes, matchmaking and subscriptions; how a human matchmaker and the compatibility software use it; who can receive it; how long it is kept; and how you can stop that processing or erase your data.

Controller: Naseeb · [email protected]
Primary jurisdiction: Florida, United States
Notice 2026-09-25-v12, effective 2026-09-25 · SHA-256 92d70ddfa180079245c72044676738a397cf8572fcc92224ba6489c9e1adde27

What is collected

If you join the launch waitlist, Naseeb records only the email address you enter, whether you confirmed or unsubscribed, the page source, relevant timestamps, and the version and digest of this notice. Confirmation and unsubscribe links are represented in the database only by one-way hashes; the link credentials themselves are sent by email and are not retained in readable form. Joining the waitlist does not create a matchmaking account or questionnaire profile.

The individual intake can include your name, email, date of birth, location, photographs, education and work, religion, denomination, community, ethnicity, health or disability information, family relationships and estrangement, finances, politics, sexual life, orientation and intimacy, relationship history, preferences, and free-text narratives.

The family intake can include a respondent’s email address and answers about religion, community, family expectations, work, living arrangements, marriage costs, politics, and related household views. If one person selects “Both parents, together,” that is recorded as one invited respondent’s description of a household view. It is not proof that a second adult separately consented.

Naseeb also creates operational data: a verified account and selected role, a candidate-authorized link to an invited parent, saved-draft answers and resume position, adult-eligibility state, matchmaker notes, compatibility categories, hard-filter outcomes, compliance review flags, introduction decisions, delivery state, security audit events, and keyed deletion receipts. A private Airtable base receives a limited operational mirror of new waitlist signups and currently consented accounts: opaque Naseeb identifiers, email, role, lifecycle and access state, parent-candidate link state, provider-neutral subscription state, timestamps, and counts. Airtable does not receive questionnaire or draft answers, photographs or photograph links, date of birth, location, private match or family notes, credentials, security logs, or Stripe identifiers. SQLite remains the source of truth. At the waitlist, public account, and family-access boundaries, Cloudflare Turnstile processes ordinary network, browser, and device signals and returns a short-lived security result used to distinguish people from automated abuse. Naseeb does not store the Turnstile response token or a Cloudflare device identifier.

For subscriptions, Naseeb records which verified account pays for which candidate, opaque Stripe customer, checkout and subscription references, subscription state, paid-through and cancellation dates, and bounded webhook-processing evidence. Payment card details are collected by Stripe’s hosted pages and are not stored in Naseeb’s database.

How it is used

Naseeb does not sell personal data and does not use it for targeted advertising.

Who receives what

Authorized matchmakers can read active, currently consented candidate and family answers. A candidate can see their own individual answers, never a family respondent’s answers. A family respondent can submit only through their own invitation and cannot see the candidate’s answers or another respondent’s answers.

An introduced person receives the introduction note and a compatibility reflection, not the other person’s raw questionnaire or grade. Photographs accompany the introduction itself, so the person deciding can see who they are deciding about; the other person's full name is withheld until both accept. If both people separately opt in, the private-question result is shown only as a broad compatibility line, never as the underlying answers. When both people accept, the matchmaker sends one introduction email addressed to both of you, and that message shows each of you the other's email address so the conversation can continue directly. Nothing else about either person is disclosed, and no address is shared before both have accepted.

Infrastructure providers may process limited data to operate the service: the hosting and network provider handles requests; Cloudflare processes Turnstile security-challenge signals to prevent automated abuse; the email provider receives waitlist and account destination addresses and message content; Airtable receives the limited private operational signup and account mirror described above; Stripe receives payer and payment information on its hosted payment and account-management pages; and Google Fonts can receive ordinary connection metadata when typography loads. Operators with filesystem access can access the application files as needed to run, secure, back up, and restore the service.

Naseeb measures how its pages are used with two tools. GoatCounter runs on Naseeb’s own server and records each page visit: which page, where the visitor came from, the browser, operating system, screen size and language, and the country, linked by a random visit code. Its records are deleted after a year. Cloudflare, the network provider, runs its Web Analytics service through a small script on every page, including this one, which reports page visits and how quickly pages load and respond; Cloudflare keeps those records under its own terms. Neither tool sets cookies, and neither is used for advertising or to follow you across other sites.

A parent-candidate account link proves only that a candidate invited that mailbox and the parent verified it. It does not reveal the candidate’s answers, another respondent’s answers, or authorize a future family instrument. Each family instrument still requires its own candidate-issued invitation.

How long it is kept

DataCurrent retention
Launch waitlistAn unconfirmed entry is removed after seven days. A confirmed entry is kept until the launch or availability notice is sent, the person unsubscribes or asks for deletion, or the service closes. After unsubscribe, Naseeb keeps only the minimum email and opt-out evidence needed to honor the choice, resolve a delivery complaint, or close the service.
Private Airtable operational mirrorThe corresponding mirrored record follows the source record's lifecycle. An unconfirmed waitlist mirror is deleted with the seven-day source expiry; an erased account, profile, link, subscription subject, or waitlist entry is deleted from the mirror. An unsubscribed waitlist mirror is reduced to the minimum opt-out identity and time. Questionnaire answers, photographs, credentials, private notes, security logs, and Stripe identifiers are never placed in this mirror. If Airtable is unavailable, a remote update or deletion can remain pending without delaying the local signup, unsubscribe, withdrawal, or deletion.
Candidate profile, photos, active family data, introductions and feedbackNo automatic inactivity expiry. Active while consent is current; after withdrawal, the profile is held out of matchmaking until the candidate reconsents or deletes it. Otherwise kept until deletion or service closure.
Verified account and parent-candidate linkKept until account deletion, link revocation, or service closure. A candidate profile deletion does not silently erase a separate parent role or the minimum payment records needed to end and reconcile a subscription.
Incomplete candidate or family draftRemoved after 30 days without a save. A family draft is removed sooner when its candidate-issued invitation expires or is revoked. New photograph files are not part of saved drafts and must be selected again before final submission.
Family invitation and protected form sessionThe invitation normally expires after 14 days. The protected browser session expires after 2 hours.
Sign-in, intake-verification and browser-session credentialsLogin links/codes and intake verification codes become unusable after 15 minutes. Candidate sessions become unusable after 30 days; console sessions after 12 hours. Used or expired credential/session rows are removed during the next retention-maintenance run, and a new intake challenge replaces the earlier challenge for that address.
Rejected, replaced, cancelled or quarantined family response bodiesErased from the live register after 90 days. A direct withdrawal removes the live submitted version immediately; older snapshots may retain its bytes until rotation, while the external privacy control prevents it becoming live after a restore.
Declined, revoked or expired invitation recordsRemoved after 90 days. A consumed invitation remains with its family-form version until that version is withdrawn, deleted, or reaches its applicable retention event.
Email delivery log / security audit log180 days / 365 days. Delivery logs can contain the recipient, subject and non-credential message content; credential-bearing bodies are redacted. Security audits can contain the actor address or request IP, action and bounded detail.
Turnstile security challengeThe single-use response token is checked with Cloudflare and is not written to Naseeb's database or logs. Cloudflare's handling of the network, browser, and device signals it processes is governed by its own service and privacy terms.
Subscription and payment-operation recordsOpaque customer, checkout, subscription, invoice and event references, lifecycle state, payer-beneficiary linkage, and cancellation/reconciliation evidence are kept while needed to administer the subscription, resolve disputes, satisfy legal obligations, and reconcile with Stripe. Naseeb does not store card numbers or full Stripe webhook bodies.
Daily-delivery quota receiptEight days.
Nightly database snapshotsThe newest 7 successful snapshots are kept. This is a count, not a guaranteed seven-day window.
Pre-deployment database snapshotsFiles older than 14 days are removed during a successful deployment. A profile deletion replaces restorable snapshots sooner so deleted data cannot be restored from them.
Encrypted backup bundlesEach day an encrypted backup bundle is sealed to a second disk on this machine and copied to off-machine storage. Bundles hold the same data as the live record, including photographs, and can be read only with a passphrase that is kept off this machine. Bundles are deleted 30 days after they are made, on the second disk and in the off-machine storage alike, so a deleted profile’s data leaves every backup within 30 days of the deletion. The live record and the on-machine snapshots are rewritten at the moment of deletion. The storage provider may keep its own recoverable copy of a deleted bundle for a further period; those copies remain encrypted.
Page-visit recordsGoatCounter’s records are deleted a year after the visit. Cloudflare keeps its Web Analytics records under its own terms.
Deletion, withdrawal and reconsent protection receiptA keyed pseudonymous control is kept outside the restorable data volume without a scheduled expiry so an old backup cannot resurrect deleted data or reverse the latest withdrawal/reconsent order. It records random privacy identifiers, the control event and time, the notice version/hash when applicable, and signed migration-only record/form numbers, form version and original creation times needed to recognize a pre-privacy backup. A keyed one-way email digest is also retained for deletion replay; the ledger does not contain the plain email, name, answers, photographs, IP address, user agent, or response text.

Your choices

Waitlist permission, the individual intake, the family respondent intake, and a candidate’s authorization of a family round are separate choices. Each is recorded separately against this notice. The optional private-compatibility switch is separate again and starts off. Paying for a subscription is a separate transaction; it never supplies or widens any of those permissions.

A waitlist request must be confirmed through the email sent by Naseeb. Every waitlist message includes an unsubscribe link. You can also ask [email protected] to remove the entry. Unsubscribing from the waitlist does not delete an independently created Naseeb account, and deleting an account does not silently subscribe or unsubscribe a separate waitlist entry.

A candidate can withdraw future matchmaking processing or permanently delete the profile from the Privacy tab. Deletion is refused while a subscription for the profile is live in any state — starting, active, ending, past due, suspended, paused or on hold — or while a checkout for it is unresolved. If your own account pays for a subscription, deletion also waits until that billing is settled. Cancel or settle first, then delete. A deletion requested while a private email for the profile is being delivered is refused for a moment and can be retried. Withdrawal stops new matching, compatibility disclosure, family processing, and unsent introductions. A message already accepted by or in flight with the email provider may still arrive, and a photograph already delivered cannot be recalled. The held profile remains available to its owner for review, reconsent, or deletion.

A family respondent can use the original emailed code on the family page to withdraw a completed response. One respondent’s withdrawal invalidates and erases the whole derived family version rather than silently treating it as a different household.

Security and files

The public service must use HTTPS, owner-only application files, restricted administration, expiring credentials, verified backups, and an external anti-rollback erasure ledger. The repository does not provide application-level encryption of SQLite, photographs, or JSON downloads. Device and backup encryption are deployment responsibilities. A downloaded intake backup is a plain JSON file; store or delete it accordingly.

To ask a privacy question or make a request you cannot complete in the site, write to [email protected].

This product notice is written for Naseeb’s stated Florida, United States operating jurisdiction. Other laws can apply based on where a person lives or where the service is offered.