سادہ زبان میں رازداری کی تفصیل

RingMatcher میں رازداری

دیکھیں کہ RingMatcher تجزیے کے لیے کیا بھیجتا، جان بوجھ کر کیا محفوظ کرتا اور Ringprint شیئر کرنے پر کیا شامل ہوتا ہے۔

آپ کے بھیجے ہوئے جوابات

مفت عمل آپ کے منتخب انداز اور خریداری کے جوابات اور ایک اختیاری نوٹ کو پراسیس کرتا ہے۔ یہ صرف نتیجہ مانگنے پر RingMatcher سرور کو بھیجے اور اسی نتیجے کو بنانے اور جانچنے میں استعمال ہوتے ہیں۔

اختیاری تصاویر اور AI پراسیسنگ

تصاویر اختیاری ہیں اور چہرے کی تصویر کبھی لازم نہیں۔ زیادہ سے زیادہ تین تصاویر براؤزر میں چھوٹی ہوتی اور اس درخواست کے لیے ترتیب دیے گئے AI فراہم کنندہ تک RingMatcher سرور سے گزر سکتی ہیں۔ RingMatcher اپ لوڈ شدہ فائلیں جان بوجھ کر محفوظ نہیں کرتا۔ صفر برقرار رکھنے اور جمع نہ کرنے کی ترتیبات مانگی جاتی ہیں، مگر فراہم کنندہ کا ڈھانچہ، شرائط اور قانونی ذمہ داریاں پھر بھی لاگو ہیں۔

تصویر کی ہدایات صرف بصری ڈیزائن اشاروں کی اجازت اور شناخت یا حساس خصوصیات اخذ کرنے کی ممانعت کرتی ہیں۔ تصویر کے اندر متن یا ہدایات نظرانداز ہوتے ہیں۔

شیئر کیے گئے لنکس

شیئر لنک URL فریگمنٹ میں دکھائی دینے والا نتیجہ، منتخب ہیرے کا راستہ، بجٹ درجہ اور مواد کی زبان رکھتا ہے۔ اپ لوڈ شدہ تصاویر کبھی شامل نہیں ہوتیں۔ لنک رکھنے والا ہر شخص رمز شدہ معلومات پڑھ سکتا ہے، اس لیے بھیجنے سے پہلے جائزہ لیں۔

ایک محدود فریگمنٹ دکھائی دینے والے رہنمائی کے خانے ریٹیلر فائنڈر تک منتقل کر سکتا ہے۔ یہ صفحے کی HTTP درخواست کے ساتھ نہیں بھیجا جاتا اور درآمد کے بعد ایڈریس بار سے ہٹ جاتا ہے، مگر غیر درآمد شدہ لنک رکھنے والا اسے پڑھ سکتا ہے۔

Native app data, purchases, and recovery (authoritative English disclosure)

This native-app section is the authoritative English disclosure. The surrounding translated text may not yet describe every native-app behavior.

A questions-only Ringprint in the native app is created on the device, so those answers do not leave the device for matching. If you add up to three photos, the app re-encodes them and sends the device-resized images, their context labels, the questionnaire answers, the content locale, and a random installation identifier through RingMatcher for that request. Cookies are omitted. RingMatcher then sends the answers and images to OpenRouter, the configured AI gateway, with zero-data-retention and data-collection-denial settings requested. RingMatcher does not intentionally persist the match request body or uploaded image files, and saved Ringprints never contain a photo file or image payload. OpenRouter, any routed model provider, and their infrastructure, terms, and legal obligations still apply.

The app stores saved Ringprints in AsyncStorage, including the questionnaire answers, optional note, generated result, locale, source, timestamps, and image-analysis counts. Paid-plan snapshots, generated guidance, setup inputs, and tool activity are also stored in AsyncStorage; source snapshots omit the free-form Ringprint note. These records are app-local but are not encrypted by AsyncStorage. Photo files are excluded. A random installation UUID and purchase capabilities—including draft and access tokens, obfuscated purchase-binding identifiers, and a Google Play purchase token after billing—are stored separately with device-only SecureStore settings.

On Android, RingMatcher disables app backup and excludes its app files, databases, preferences, and device-to-device transfer domains from backup rules. This is intended to keep local Ringprints, plans, and purchase capabilities off Android backup and migration services. Other operating-system, device-administration, forensic, or user-initiated copying behavior is outside RingMatcher's control.

If you choose Report this result, the app sends RingMatcher the result identifier, visible result title, summary and rationale, the selected report reason, an optional note, the content locale, and the random installation identifier in a request header. The service uses the installation identifier and network address to enforce an hourly report limit. It writes the report content, reason, optional note, locale, a generated report identifier, and the receipt time to structured deployment logs so the report can be reviewed. Those report logs do not intentionally include the raw installation identifier or network address; their retention follows the deployment logging configuration. Reporting is optional and does not affect saved Ringprints or paid access.

Starting a Google Play checkout sends RingMatcher the selected pack, random installation UUID, local Ringprint identifier, and a SHA-256 digest of the Ringprint—not the questionnaire answers, uploaded photos, or generated plan. The server persists a digest of the installation identifier, the Ringprint identifier and digest, generated draft/access identifiers, product and pack identifiers, obfuscated Google Play binding identifiers, capability hashes, and timestamps. Claiming a purchase sends the raw Google Play purchase token to RingMatcher so it can be verified with Google Play. The server persists a digest of that token, and may persist an order-ID digest and purchase-completion timestamp; it does not write the raw purchase or order token to its purchase-state file.

The protected Google Play app-review path sends the reviewer access code and random installation UUID to RingMatcher. The server compares a one-way code digest, enforces network and installation limits, and persists only the code digest, installation digest, synthetic draft/claim/access identifiers, pack and product identifiers, and timestamps—not the plaintext review code. It returns signed, expiring plan capabilities to device-only SecureStore. This review path does not open billing or create a charge.

An unclaimed purchase draft expires after 7 days. After a successful claim, its draft and replay-claim record become eligible for pruning when that same 7-day draft capability expires. Paid access expires after 30 days for Shortlist or Complete Plan and after 90 days for Together Plan. Expired eligible rows are pruned atomically during later purchase-state maintenance, such as a subsequent draft creation or purchase grant; there is no background deletion timer. Unexpired drafts and access records are not evicted to make room for newer records.

Saved Ringprints and completed paid plans remain on the device until you remove them, the bounded local history replaces older Ringprints, app storage is cleared, or the operating system removes the app data. Removing a completed paid plan also asks SecureStore to delete its associated capability. A plan with an unfinished purchase is protected from ordinary removal because the local draft may still be needed for Google Play recovery. RingMatcher has no user account or cross-device plan library: clearing local app data, removing protected credentials, changing devices, or uninstalling can make a consumed one-time purchase or its generated plan impossible to recover. Contact contact@ringmatcher.com for privacy or server-record deletion questions.

درخواست کی حدیں، داخلی پیمائش اور تکنیکی لاگز

سرور نیٹ ورک پتے سے صرف میموری میں رہنے والی عارضی درخواست-حد کلید بنا سکتا ہے۔ RingMatcher لینڈنگ صفحے، Ringprint کی تیاری، اشتراک اور ڈاؤن لوڈ، اختیاری چیک آؤٹ و ادائیگی والے پیک، اور ریٹیلر فائنڈر میں داخلی فنل مراحل ریکارڈ کرتا ہے۔ ایونٹ معاہدہ صرف ایونٹ کا نام، اجازت یافتہ گائیڈ سلگ، ماخذ، چینل، پیک، حالت، CTA منزل، CTA کی جگہ یا لوکیل کی مقررہ قدریں، بولین اور محدود گنتی یا اسکور قبول کرتا ہے۔ سوال نامے کے جواب، بجٹ، نوٹس، تیار کردہ سمت کا متن، من مانے URL یا صفحے کے راستے، آزاد متن والی منزل، ادائیگی شناختی نمبر، خرابی کے پیغامات یا اسٹیکس، ذاتی معلومات اور آزاد متن شامل نہیں ہوتے۔

ریٹیلر فائنڈر کے ایونٹس میں خریداری کی ایک مقررہ قسم اور RingMatcher کے جائزہ شدہ کیٹلاگ سے ریٹیلر ID بھی شامل ہو سکتی ہے۔

گائیڈ سے کوئز پر کلک کرنے کے بعد براؤزر کا سیشن اسٹوریج صرف یہ انتسابی قدریں—اجازت یافتہ گائیڈ سلگ، لوکیل اور CTA کی جگہ—اور تکنیکی ورژن و اختتامی مدت کا میٹا ڈیٹا رکھ سکتا ہے۔ انتساب زیادہ سے زیادہ 30 منٹ تک قبول ہوتا اور منسوب Ringprint درخواست کے لیے ایک بار استعمال ہوتا ہے۔ مدت ختم شدہ ریکارڈ نظرانداز ہو کر اگلی رسائی پر حذف ہوتا ہے؛ براؤزر ٹیب یا سیشن ختم ہونے پر سیشن اسٹوریج بھی ختم ہو جاتا ہے۔ اس میں سوال نامے کے جواب، بجٹ، تصاویر، رابطے کی تفصیلات یا اکاؤنٹ یا صارف کا شناختی نمبر شامل نہیں ہوتا۔

قبول شدہ ایونٹس صرف منظم سرور ڈپلائمنٹ لاگز میں لکھے جاتے ہیں۔ RingMatcher انہیں کسی تیسرے فریق کی اینالٹکس سروس کو نہیں بھیجتا اور نہ مخصوص اینالٹکس ڈیٹابیس میں رکھتا ہے؛ مدتِ تحفظ ڈپلائمنٹ لاگنگ کی ترتیب پر منحصر ہے۔ ایونٹس میں اکاؤنٹ یا صارف شناختی نمبر نہیں ہوتا۔ تکنیکی AI استعمال بھی سوال نامے کے جوابات یا اپ لوڈ شدہ تصاویر کے بغیر لاگ ہو سکتا ہے۔

ادائیگی والے پیک اور Stripe

اختیاری ادائیگی والے پیک کی ایک مرتبہ کی ادائیگی Stripe پراسیس کرتا ہے۔ RingMatcher رسید کا ای میل، منتخب پیک، سرور کی مقرر کردہ رقم اور کرنسی، اور بنائے گئے درخواست و PaymentIntent شناختی نمبر Stripe کو بھیجتا ہے۔ ادائیگی کی تفصیل Stripe کا Payment Element جمع کرتا ہے؛ RingMatcher مکمل کارڈ نمبر یا سیکیورٹی کوڈ وصول یا محفوظ نہیں کرتا۔

Stripe میٹا ڈیٹا میں صرف بنائے گئے شناختی نمبر، ادائیگی اور تکمیل کی حالت، اور براؤزر رسائی سے منسلک یک طرفہ ہیش ہوتا ہے—سوال نامے کے جواب، تصاویر، نجی نوٹس یا رپورٹ کا مواد نہیں۔ ہر پیک کی HttpOnly، SameSite کوکی زیادہ سے زیادہ 100 دن اور زیر التوا ادائیگی کا ریکارڈ اسی براؤزر کے مقامی اسٹوریج میں زیادہ سے زیادہ 30 دن رہ سکتا ہے۔ Stripe کی شرائط اور رازداری پالیسی لاگو ہوتی ہیں۔

پروڈکشن ویب سائٹ پر ادائیگی والی رپورٹ کے سیشن محفوظ سرور والیوم پر رکھے جاتے ہیں اور معمول کے ری اسٹارٹ اور ڈپلائمنٹ کے بعد بحال ہو جاتے ہیں۔ Shortlist اور Complete Plan کے سیشن 30 دن بعد اور Couple’s Edition کے سیشن 90 دن بعد ختم ہوتے ہیں۔ RingMatcher حذف کرنے کی درخواست مکمل ہونے پر سیشن کو اس سے پہلے مٹا سکتا ہے۔

RingMatcher کیا فروخت نہیں کرتا

RingMatcher انگوٹھیاں یا ذاتی ڈیٹا فروخت نہیں کرتا۔ اگر اکاؤنٹس، ادائیگی، تجزیات، ذخیرہ یا ماڈل فراہم کنندہ بدلیں تو بدلی ہوئی خدمت عوام کو دینے سے پہلے اس صفحے کا جائزہ ضروری ہے۔ رازداری کے سوال contact@ringmatcher.com پر بھیجیں۔