Privacy
You are trusting us with your faith, your family and your face. This is exactly what we do with all of it, written to be read rather than to be survived.
Last updated 10 September 2026
Aaroos holds some of the most personal information a person can give a service: their faith, their family, their face, and what they are looking for in a marriage. This page says exactly what we hold, why, and what you can ask us to do about it.
We are a matrimonial platform, not a social network and not a dating app. That difference runs through everything here. People join to find a spouse, often with family involved, and the information they share is given on the understanding that it is handled with care.
- We never sell it
- Your data is not sold, rented, or handed to advertisers or data brokers. There is no commercial arrangement anywhere in Aaroos that depends on passing your information to a third party for their own purposes.
- We do not track you
- There is no analytics script, no advertising pixel, and no cross-site tracker anywhere on Aaroos. The only cookie we set is the one that keeps you signed in.
- Faith data is consented
- Your religion, religious practice and ethnicity are special category data under UK law. We ask for your explicit consent before using them, and we use them for one thing: finding you compatible matches.
- Your answers stay private
- The Marriage Mind Insight questionnaire covers money, family and upbringing. Those answers are never shown on your profile and never shown to another member. They feed matching, and they are yours.
- You are in control
- You can see your data, correct it, export it, or ask us to delete it. How to do that is set out below.
This policy covers the Aaroos website and member dashboard. It is written to be read, so if any part of it is unclear, that is a fault worth telling us about at admin@aaroos.com.
Who is responsible for your data
The data controller is [Registered company name], registered in England and Wales, company number [company number], at [registered office address]. Where this policy says we, us or Aaroos, that is who it means.
For anything to do with your data, write to admin@aaroos.com and put the word Privacy in the subject line so it reaches the right person.
Almost all of it comes from you, because almost all of it is something you typed or chose. A small amount is produced by the act of using the service, and that part is listed here too rather than left implied.
What you give us
- Your account
- Your name, email address, and a password that is stored only as a one-way hash, so nobody at Aaroos can read it. If you sign in with Google instead, we receive your name, email address and Google account identifier from Google, and never your Google password.
- Who you are
- Your date of birth, gender, username, city, country and nationality, and a profile photo if you add one.
- Your profile
- The sections you fill in about yourself: your background, education and work, your faith and practice, your family, your lifestyle, your interests, and a short piece in your own words.
- What you are looking for
- Your partner preferences, including the age range, marital status and other qualities you would like in a spouse. These are used to rank candidates and are not displayed to other members as a list of demands.
- Your MMI answers
- The Marriage Mind Insight questionnaire asks about money, conflict, family expectations and how you were raised. Where you choose to write your own answer rather than pick an option, we keep both your words and the reading taken from them.
- Photos
- Any photos you upload. These are held in private storage and served through links that expire, so a photo URL cannot be passed around or indexed by a search engine.
- Verification
- A short face scan, or three photos of you if the scan cannot run on your device, together with the identity document you submit. See the next chapter, because this is the most sensitive thing we handle.
- Messages
- The conversations you have with members you have matched with, including text, images and voice notes.
- Support and reports
- Anything you write to our support team, and any report you make about another member, including what you tell us and what we decide.
- Payments
- Your membership tier and billing history. Card details are entered directly into Stripe and never reach our servers; we hold only the card brand, the last four digits and the expiry, so you can recognise which card is on file.
What using Aaroos produces
This is the part most policies leave vague, so here it is plainly.
- Your IP address
- Recorded when you sign up, when you sign in, and as you use the dashboard. We keep a list of the addresses an account has connected from, with the approximate country and city, the network operator, and the browser used.
- Sign-in history
- A record of each signup, sign-in, failed sign-in, password reset and sign-out, with the address it came from. Failed attempts are recorded too, because a run of them is how an attempt to break into an account looks.
- Network checks
- Whether an address belongs to a VPN, a public proxy, the Tor network or a datacentre, and which country it is in. This is what lets us keep banned members from quietly returning under a new email, and keep registrations to the countries we have launched in. See who we share this with.
- Consent records
- Which version of this policy and of our terms you agreed to, when, and from which address. We keep this because a consent we cannot evidence is not a consent.
- Activity
- When you were last active, whose profiles you visited, who you liked, shortlisted or passed on, and how much of your monthly allowance you have used. Profile visits are shown to the member you visited unless you are browsing privately on a tier that allows it.
What we deliberately do not collect
We do not ask for your precise location and the app never requests it from your device. We do not read your contacts, your calendar or your photo library. We do not build an advertising profile of you, because we do not run advertising.
UK law treats some information as needing more protection than the rest: beliefs, ethnicity, health, and biometric data used to identify a person. Aaroos handles three of those, and it would be wrong to bury that in a list.
Your faith and practice
How you describe your religion, how you practise it, your sect, your prayer habits, your views on family life: this is the heart of what Aaroos matches on, and it is special category data. We use it because you explicitly consented to us using it when you joined, and we use it for one purpose, which is finding you a compatible spouse.
Your ethnicity and background
Your ethnicity, nationality, languages and cultural background are held for the same reason and on the same basis. Many members are looking for someone who shares a background, and many are explicitly not. Either way the information is there to serve what you are looking for.
Your face, and your identity document
Verification is what makes Aaroos safe, and it is the most invasive thing we ask of you. Here is exactly what happens.
- You complete a short liveness check in the browser, which confirms a real person is present rather than a photograph held up to a camera. Where that cannot run on your device, you upload three photos instead and a person reviews them by hand.
- The images are compared against the identity document you submit, using Amazon Rekognition. The comparison produces a similarity score and a liveness result. Those are what our reviewers see alongside the images.
- A member of our team makes the final decision. An automated score never approves or declines an account on its own, so there is always a person accountable for the outcome.
- Verification images and documents are held in private storage, visible only to reviewers, and are never shown on your profile or to another member.
You can withdraw consent
Consent you gave can be taken back. Write to admin@aaroos.com and we will stop using your special category data and delete it.
Being straight with you about the consequence: faith and background are what matching runs on, and verification is what lets you message anybody. Withdrawing consent for them means your account can no longer do the thing it exists to do, so in practice it means closing it. We would rather say that now than have you find out after.
Under UK GDPR we need a lawful basis for every use of your data, and different uses rest on different ones. This is the full list rather than a summary.
- To run your account
- Creating it, signing you in, showing your profile, keeping your settings. Basis: performance of our contract with you.
- To find you matches
- Comparing your profile, preferences and MMI answers against other members and ranking the result. Basis: our contract, and your explicit consent for the faith and ethnicity parts.
- To let you talk
- Carrying messages between members who have matched, and notifying you about them. Basis: our contract.
- To verify who you are
- The face check and document review. Basis: your explicit consent, and our legitimate interest in every member being a real, single person who they say they are.
- To keep members safe
- Reviewing reports, moderating conduct, suspending and banning accounts, checking whether a new account belongs to somebody already removed. Basis: our legitimate interest in protecting members, which in a marriage context we weigh heavily.
- To prevent fraud and evasion
- Recording the addresses an account connects from, checking them against known VPN, proxy and Tor networks, and noticing when several accounts share an address. Basis: our legitimate interest in preventing fraud and ban evasion.
- To limit registration by country
- Checking the country an account is being created from while we are open in some countries and not others. Basis: our legitimate interest in offering the service only where we are able to support it properly.
- To take payment
- Processing your membership through Stripe and keeping a record of what you paid. Basis: our contract, and our legal obligation to keep financial records.
- To email you about your account
- Confirmation codes, password resets, verification outcomes, and notices about your membership. Basis: our contract. These are not marketing and you cannot opt out of them while your account is open.
- To email you news
- Occasional updates, guidance and member news. Basis: your consent, given separately at signup. You can withdraw it at any time in your settings or from any such email, and doing so changes nothing about your matches.
- To improve Aaroos
- Understanding which parts of the service work and which do not, using aggregate counts rather than reading your profile or your messages. Basis: our legitimate interest in improving what we offer.
- To meet our obligations
- Responding to lawful requests, keeping records we are required to keep, and defending legal claims. Basis: legal obligation, and our legitimate interest in establishing or defending a claim.
Automated decisions
Matching is automated. It decides the order in which candidates are shown to you, which is a suggestion and nothing more: you are never matched with anybody without both of you choosing it, and nothing about your legal position turns on a score.
The decisions that actually affect your account, approving or declining verification, suspending or banning you, are made by a person. You can ask why, and you can ask us to look again.
Some of the companies above process data outside the United Kingdom and the European Economic Area. You agreed to this when you joined, and it is worth knowing what it means in practice.
Where data goes outside the UK, we rely on one of the safeguards UK law provides: an adequacy decision covering the destination country, or the International Data Transfer Agreement, or the UK Addendum to the European Commission’s standard contractual clauses. In each case the receiving company is contractually bound to protect your data to a UK standard.
Hosting, storage, payment processing, email and the face comparison each run in a specific region chosen for the purpose, and some of those regions are outside the UK. You can ask us which regions are in use at any time and we will tell you.
Your right to know more
You are entitled to a copy of the safeguards we rely on. Write to admin@aaroos.com and we will send them.
Holding data longer than it is useful is not caution, it is risk. These are the periods we work to.
- While you are a member
- Your account, profile, photos, preferences and MMI answers are kept for as long as your account is open. You can edit or remove most of it yourself at any time.
- If you deactivate
- Deactivating pauses your account and hides you from matching. Nothing is deleted, because signing back in is meant to restore it. If you never come back, ask us to delete it and we will.
- If you delete
- Your profile, photos and MMI answers are removed. A small record that the account existed and why it closed is kept where we need it to stop a banned member simply signing up again, and to meet our own legal obligations.
- IP and sign-in history
- Twelve months from when an address was last seen, then deleted. This is the period we need for fraud prevention and for a ban appeal that arrives months later.
- Verification images
- Kept while your verification is being reviewed and for a period afterwards, so a decision can be revisited if you challenge it. Not kept indefinitely.
- Messages
- Kept for as long as the conversation exists. Where a conversation is reported, the relevant messages are kept as long as needed to deal with the report and any appeal.
- Payment records
- Six years, which is what UK tax and accounting law requires of us.
- Consent records
- Kept for as long as we need to evidence that you consented, which in practice means as long as we hold the data the consent covers.
- Support conversations
- Kept while your account is open and for a reasonable period afterwards, so a later question about an earlier answer can be understood.
These are rights you have under UK GDPR. They are free to exercise, and asking is not an inconvenience to us.
- See it
- Ask for a copy of the personal data we hold about you, and for an explanation of what we do with it.
- Correct it
- Have anything inaccurate fixed. Most of it you can edit yourself; for the rest, ask.
- Delete it
- Ask us to erase your data. We will, except where we are required to keep something, in which case we will tell you what and why.
- Take it with you
- Ask for your data in a portable, machine-readable format, or ask us to send it to another service.
- Restrict it
- Ask us to stop using your data while a dispute about its accuracy or our basis for holding it is resolved.
- Object
- Object to any use we base on our legitimate interests. We will stop unless we can show a compelling reason not to.
- Withdraw consent
- Take back any consent you gave, including for faith and ethnicity data and for marketing. See the note on what that means in practice.
- Complain
- Complain to the Information Commissioner’s Office at ico.org.uk. We would rather you came to us first so we can put it right, but it is your right either way and you do not need our permission.
How to ask
Email admin@aaroos.com from the address on your account. We will reply within one month. If your request is complicated we may need up to two months more, and we will tell you inside the first month if that is the case.
We may need to confirm it is really you before acting on a request, because handing someone’s profile to whoever asks for it would be the opposite of protecting it.
No service can promise perfect security and you should not trust one that does. These are the specific measures in place.
- Passwords are stored only as a one-way hash. Nobody at Aaroos can read your password, and a password reset retires every session that was open under the old one.
- Your session lives in a cookie the browser will not let JavaScript read, which is what stops a script on a page from stealing it.
- All traffic between your browser and Aaroos is encrypted in transit.
- Photos, verification images and message media are held in private storage and served through links that expire, so a URL cannot be shared on or picked up by a search engine.
- Two-factor authentication is available on your account, and we recommend turning it on.
- Staff access to the admin console is separate from member accounts, restricted by role, and every consequential action records who took it.
- We watch for the patterns that precede an account takeover: runs of failed sign-ins, and sign-ins from somewhere an account has never been used.
If something goes wrong
If there is a breach that is likely to risk your rights, we will tell the Information Commissioner’s Office within 72 hours, and we will tell you without undue delay. We will say what happened and what to do about it, rather than issuing a statement that avoids saying either.
Your part in it
Use a password you use nowhere else, turn on two-factor authentication, and be careful what you share in a conversation with somebody you have not met. Be especially wary of anyone who asks to move off Aaroos quickly, or who asks you for money. You can report a member from their profile, and we read every report.
A privacy policy that can be rewritten quietly is not a commitment. Here is how we handle changes to it.
If we change something that affects what we do with your data, we will tell you in the app and ask you to agree again before continuing. We keep a record of which version you agreed to, so what you consented to and what we are relying on can never drift apart.
Corrections that change no meaning, a clearer sentence or a fixed typo, we make without asking you again.
Children
Aaroos is for adults of eighteen and over. We do not knowingly hold data about anybody younger. If you believe a minor has created an account, tell us at admin@aaroos.com and we will remove it immediately.
Getting in touch
For anything in this policy, email admin@aaroos.com. For how Aaroos works and what the words mean, the field guide is the friendlier read. For the rules of membership, see the Terms of Use.
Questions about any of this are welcome.
A policy nobody can ask about is not transparency. Write to us and a person will answer.
This version took effect on 10 September 2026.
On this page