1. INTRODUCTION & DATA CONTROLLER
DATA CONTROLLERWelcome to Nila. We respect your privacy and are committed to safeguarding your personal data in accordance with applicable data protection laws, including the Information Technology Act, 2000, the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, and the Digital Personal Data Protection Act, 2023 (DPDP Act).
This Privacy Policy describes how Mastroke Enterprises Pvt Ltd (“Company”, “we”, “us”, or “our”) collects, uses, stores, shares, protects, and handles your personal information when you access or use the Nila mobile application, our website (www.mynila.in), audio calling features, video calling services, messaging tools, virtual credits, and related offerings (collectively, the “Platform”).
By accessing, registering with, or using Nila or www.mynila.in, you acknowledge that you have read, understood, and consented to the data practices described in this Privacy Policy. If you do not agree with this policy, please do not use the Platform.
2. AGE RESTRICTION & CHILD SAFETY (18+ ONLY)
18+ ONLYWe enforce an absolute zero-tolerance policy against Child Sexual Abuse Material (CSAM), Child Sexual Abuse and Exploitation (CSAE), grooming, and the sexualization of minors. If we discover or reasonably suspect that an account belongs to a minor under 18, we will immediately delete that account, purge associated personal data, and report the incident to statutory law enforcement authorities (including NCMEC and cybercrime units) as required by law.
For complete details on our safety protocols, please review our dedicated Child Safety Standards.
3. CATEGORIES OF DATA WE COLLECT
DATA COLLECTIONDepending on how you interact with Nila and the features you choose to use, we may collect and process the following categories of personal data:
3.1 Account & Profile Data
- Registration Information: Mobile phone number, country code, email address.
- Profile Details: Display name, age/date of birth, gender, interests, biography, preferences, languages spoken.
- Profile Photos & Media: Photographs and avatar images uploaded by you for your public profile.
- Verification Selfie Data: Real-time selfie image captured for automated facial match verification against profile photos to eliminate impersonation and fake profiles (facial geometry data is used solely for verification and not sold).
3.2 Calling & Interaction Metadata
- Call Metadata: Timestamps of incoming/outgoing audio and video calls, call duration, connection status, participant user IDs, and network quality metrics.
- Call Content Privacy: We do not record, store, listen to, or archive raw audio or video streams during your calls. Real-time audio and video communications are transmitted securely between peers using encrypted protocols.
- In-App Messages: Text messages, emojis, and virtual gifts exchanged within the chat features.
3.3 Geolocation Data
- Approximate / Precise Location: With your explicit device permission, we collect your geographic coordinates (GPS, Wi-Fi, or cellular triangulation) to show you nearby users and calculate distance for discovery.
- City / Region: General location inferred from IP address for regional routing and language preferences.
3.4 Financial & Transaction Data
- Purchases & Credits: In-app credit package purchases, coin top-ups, transaction date/time, order IDs, and billing amounts.
- Payment Security: All financial transactions are processed securely via authorized third-party gateways (Google Play In-App Billing, Apple App Store, Razorpay, or RBI-regulated payment aggregators). We never store complete debit/credit card numbers or CVVs on our servers.
3.5 Device & Technical Information
- Device Identifiers: IP address, device model, hardware manufacture, operating system and version, unique device identifier (UUID/GAID/IDFA), language settings, and network operator.
- Usage & Performance Logs: App launch times, page views, feature interactions, crash logs, latency, and battery/network performance telemetry.
3.6 Safety, Moderation & Support Data
- User Reports & Flags: Information submitted when you report or block another user, including report reason and evidence.
- Customer Support Logs: Communications with our support or grievance team via support@nila.app or grievance@nila.app.
- Trust & Safety Records: Automated toxicity/nudity screening logs generated to enforce community guidelines.
4. HOW WE COLLECT YOUR INFORMATION
We collect personal information through three primary channels:
- Direct Collection: When you register an account, fill in your profile, upload photos, grant permissions, make in-app purchases, initiate calls, or communicate with our support desk.
- Automated Collection: When you access Nila or browse www.mynila.in, our systems automatically collect device telemetry, IP addresses, log data, and session cookies.
- Third-Party Integrations: When you authenticate via Google or Apple sign-in, or when payment status notifications are received from authorized payment aggregators.
5. DEVICE PERMISSIONS REQUESTED
DEVICE PERMISSIONSTo provide interactive audio and video calling features, Nila requests access to specific device capabilities. You can manage or revoke these permissions at any time through your device settings:
6. PURPOSES & LEGAL GROUNDS FOR DATA PROCESSING
We process your personal information for the following legitimate business, contractual, and legal purposes:
- To Provide Core Services: Setting up accounts, facilitating user discovery, connecting real-time WebRTC audio and video calls, and managing in-app messages.
- To Manage Virtual Wallet & Billing: Processing credit coin purchases, tracking wallet balances, maintaining digital ledgers, and fulfilling statutory tax obligations (such as GST).
- To Protect User Safety & Prevent Fraud: Authenticating real users via selfie verification, detecting fake profiles, filtering spam/bots, moderating offensive content, and preventing financial scams, harassment, blackmail, and impersonation.
- To Comply with Statutory Legal Obligations: Cooperating with lawful requests from law enforcement agencies, cybercrime cells, and judicial courts pursuant to the IT Act 2000, IT Rules 2021, and DPDP Act 2023.
- To Improve Platform Experience: Analyzing aggregated technical metrics, diagnosing crashes, optimizing call latency, and enhancing website performance at www.mynila.in.
- To Provide Customer Support: Resolving user grievances, responding to support tickets, and addressing refund or billing inquiries.
7. AUDIO & VIDEO CALL PRIVACY
CALL PRIVACYOur call privacy commitments:
- No Call Audio/Video Recording: Mastroke Enterprises Pvt Ltd does not record, intercept, or store the contents of your live audio or video calls on our servers.
- Strict Anti-Recording Rule for Users: Users are strictly prohibited from screenshotting, recording, capturing, publishing, or sharing other users' video calls, audio feeds, or private photos without express mutual consent. Violators will face immediate account termination and legal action under applicable cyber privacy laws.
- Metadata Retention: We only log call metadata (start time, end time, duration, user IDs, network connection quality) for diagnostic, billing, and anti-abuse verification purposes.
8. DATA SHARING & THIRD-PARTY DISCLOSURES
We do not sell, rent, trade, or monetize your personal data to third-party advertisers or data brokers.
We share personal data strictly with trusted service providers under confidentiality agreements to operate the Platform:
- Cloud Infrastructure & Hosting: Reputable cloud hosting providers (such as Amazon Web Services, Google Cloud Platform, or Cloudflare) for secure database storage, server hosting, and DDoS mitigation.
- Real-Time Communication Providers: WebRTC signaling and media infrastructure providers for establishing audio and video calling pipelines.
- Payment Gateways & App Stores: Google Play In-App Billing, Apple Store Billing, Razorpay, Cashfree, or RBI-authorized payment aggregators for processing credit purchases securely.
- SMS & OTP Verification Services: Telecom messaging gateways for delivering login verification codes.
- Law Enforcement & Statutory Authorities: We may disclose data when legally required by a binding court order, government directive, police notice under Section 91 of the Code of Criminal Procedure / Bharatiya Nagarik Suraksha Sanhita, or emergency circumstances involving imminent threat to life or child safety.
9. COOKIES & TRACKING ON WWW.MYNILA.IN
When you visit our website at www.mynila.in, we may use cookies and similar browser storage technologies to:
- Essential Cookies: Maintain secure user sessions and remember essential platform preferences.
- Analytics & Performance: Collect aggregated, non-personally identifiable traffic metrics to analyze page load speeds and visitor demographics.
- Cookie Management: You can manage or disable cookies through your browser settings. However, disabling essential cookies may impact the proper functionality of the website.
10. DATA RETENTION & DELETION
DATA RETENTIONWe retain your personal information only for as long as necessary to fulfill the purposes outlined in this Privacy Policy, provide our services, maintain security, and comply with legal obligations:
- Active Accounts: We retain your profile, photos, and settings while your account remains active.
- Financial & Transaction Records: Retained for a minimum statutory period (typically up to 7 years) in compliance with Indian taxation, GST, and corporate accounting laws.
- Safety & Banned Accounts: Identifiers (e.g. mobile hash, device ID) of accounts permanently banned for severe safety violations (such as child exploitation, severe harassment, or fraud) are retained in our safety blacklist to prevent bad actors from re-registering.
- Account Deletion: You can delete your account at any time directly through the app settings or via our web portal at Account Deletion Page. Upon deletion, your public profile and identifiers will be permanently removed or anonymized within 30 days, subject to statutory retention obligations.
11. YOUR DATA PROTECTION RIGHTS
USER RIGHTSUnder applicable Indian data protection laws (including the DPDP Act 2023), you have the following rights regarding your personal information:
To exercise any of these rights, please write to our Privacy & Data Protection team at support@nila.app or grievance@nila.app.
12. DATA SECURITY & PROTECTION MEASURES
SECURITYMastroke Enterprises Pvt Ltd implements robust technical, operational, and organizational security measures in compliance with Rule 8 of the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011:
- Encryption in Transit: All data transmitted between your device, the Nila app, www.mynila.in, and our backend servers is encrypted using modern TLS 1.3 / HTTPS protocols.
- Encryption at Rest: Databases storing sensitive user information, credentials, and verification tokens are encrypted using AES-256 standards.
- Access Controls: Strict role-based access control (RBAC), multi-factor authentication (MFA), and audit logging for all internal engineering and operational personnel.
- Vulnerability Management: Regular security audits, penetration testing, automated dependency scanning, and firewall rules to protect against unauthorized intrusion.
13. CROSS-BORDER DATA TRANSFERS
Your personal data is primarily hosted and processed on secure servers in India. Where third-party cloud infrastructure or communication relay servers require international routing, such transfers comply with Indian data protection regulations (DPDP Act) ensuring equivalent safeguards, confidentiality, and security standards.
14. CHANGES TO THIS PRIVACY POLICY
We may update this Privacy Policy from time to time to reflect changes in our platform features, operational practices, or legal requirements. When updates occur, we will revise the “Last Updated” date at the top of this page.
For material changes, we will provide prominent notice via in-app alerts, email notification, or an announcement banner on www.mynila.in. Continued use of Nila after the effective date of an updated Privacy Policy signifies your agreement to the revised terms.
15. GRIEVANCE REDRESSAL MECHANISM
IT RULES 2021In compliance with Rule 3(2) of the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021 and the Digital Personal Data Protection Act, 2023, Mastroke Enterprises Pvt Ltd has designated a Grievance Officer to address privacy, safety, and data protection concerns.
Grievance Officer Details
2nd Floor, Suite 589, 24/1701
KC Arcade, Near TV Centre
Cochin Special Economic Zone
Kakkanad, Ernakulam
Kerala – 682037
Turnaround Time: The Grievance Officer will acknowledge receipt of your grievance within 24 hours and resolve or address the matter within 15 days in accordance with statutory guidelines.
16. CORPORATE CONTACT INFORMATION
CONTACTIf you have any questions, clarifications, or feedback regarding this Privacy Policy or our privacy practices, please reach out to us:
General Support & Privacy
For account privacy, data rights, or app support:
support@nila.appWebsite: www.mynila.in
Grievance & Compliance
For legal, regulatory, or statutory complaints:
grievance@nila.appKerala – 682037, India