Fazool
← Back to home

Privacy Policy

How Fazool collects, uses, and protects your personal information.

Updated June 9, 2026·Effective June 9, 2026

On this page

  1. 1.Information we collect
  2. 2.Wali (chaperone) feature
  3. 3.How we use your information
  4. 4.How we share your information
  5. 5.Identity verification and your ID
  6. 6.Location data
  7. 7.Data retention and account deletion
  8. 8.Special category data
  9. 9.Automated decision-making and profiling
  10. 10.Your rights and choices
  11. 11.Cookies and tracking technologies
  12. 12.Security
  13. 13.Voice and video calls
  14. 14.Children's privacy
  15. 15.International data transfers
  16. 16.Changes to this policy
  17. 17.Contact us

Fazool LLC ("Fazool," "we," "us," or "our") is committed to protecting your privacy. This policy explains how we collect, use, share, and protect your personal information when you use the Fazool mobile application and website (the "Service"). By using the Service you agree to the practices described below.

1

Information we collect

Information you provide directly

  • Account information: email address, phone number, password (stored as a cryptographic hash), and date of birth. If you sign up with a phone number, a one-time SMS verification code is sent via Google Firebase. Your phone number cannot be changed once verified. You may add an email address and password later in your profile settings.
  • Profile information: first name, display name, biography, gender, sexual orientation, religion, education, employment, relationship goals, height, and lifestyle preferences (smoking, drinking, pets, etc.).
  • Photos and voice notes: images and audio clips you upload to your profile.
  • Identity verification (government-issued ID): when you verify your account, you submit a photo of a government-issued ID (e.g., driver's license). We use this to confirm your real name, date of birth, and that you are at least 18 years old. The ID image is reviewed by our moderation team. Once verification is complete, the ID image is deleted. A one-way cryptographic hash of your ID number is retained to prevent duplicate accounts and re-registration after a ban. We do not sell or share your ID data with third parties except as required by law.
  • Selfie and biometric data: as part of identity verification you submit a selfie photo. This selfie is compared against your government-issued ID photo using our self-hosted face recognition software to confirm that you are the person on the ID. During this process we generate a mathematical representation of your facial geometry (a "face embedding"). This is a 512-dimensional numerical vector that cannot be reversed to reconstruct your face or the original photo. See the "Identity verification" section below for full details on what we collect, how we use it, and when we delete it.
  • Communications: messages you send to other users and feedback or support requests you submit to us.
  • Payment information: if you subscribe to a paid tier, payment details are processed by Apple or Google. Fazool does not store full payment card numbers.

Information collected automatically

  • Location data: with your permission, we collect your precise GPS location to show you people nearby and improve recommendations. You can disable location access in your device settings, but this will limit core app functionality.
  • Usage data: pages viewed, features used, swipe activity, session duration, and crash reports.
  • Device information: device type, operating system, device identifiers, IP address, and browser type.
  • Onboarding IP address: when you complete your profile at the end of the onboarding process, we record the IP address of that request. This is used exclusively by our Trust & Safety team to assist with identity verification and fraud prevention. It is not shared with other users.
  • Cookies and similar technologies: we use cookies, local storage, and similar technologies on our website. See the Cookies section below for details.
  • Age signals from app stores: on Android and iOS, we may receive age range information provided by Google Play or the Apple App Store. This includes an age bracket (not your exact birthday), verification method, and whether your account is supervised by a parent or guardian. We receive this information only during account creation to verify you meet our minimum age requirement.
2

Wali (chaperone) feature

Fazool offers an optional Wali (chaperone) feature that allows users to invite a trusted family member or guardian to oversee their activity on the platform in accordance with Islamic principles of mahram supervision.

What a Wali can see
  • Your profile information (name, photos, bio, and other profile fields you have set).
  • Your approved photos.
  • Your match inbox: a list of users you are currently matched with.
  • The full message history of each conversation in your inbox.

Wali accounts have read-only access and cannot send messages, swipe, or take any action on your behalf.

How invites work

You send an invite to the Wali's email address from within the app. The Wali receives an email with a unique, time-limited invite link (links expire after 1 hour). The Wali must create their own separate Fazool account to accept the invite. They do not use your account credentials. You may invite up to 3 Wali accounts at any time.

Your control

  • You can disable, re-enable, or permanently remove any Wali at any time from Settings → Wali.
  • Removing a Wali immediately revokes their access and deletes their Fazool account.
  • Wali accounts are automatically deleted when you delete your own account.

Data sharing with a Wali

By inviting a Wali, you consent to sharing your profile, photos, match list, and message history with that person. Fazool is not responsible for how a Wali uses or shares information they observe through their access. Choose your Wali carefully.

Notice to all users. Your messages may be visible to a Wali

When you send messages to another user on Fazool, that user may have an active Wali account. A Wali can read the full message history of their ward's conversations, which includes messages you send to their ward. By using the messaging features of this Service, you acknowledge and accept that your messages may be visible to a Wali designated by the person you are communicating with. Wali accounts are bound by these Terms of Service and are prohibited from sharing, distributing, or misusing any information they access through their ward's account.

3

How we use your information

We use your information to:

  • Create and manage your account and verify your identity.
  • Verify that your selfie matches your government-issued ID using automated face comparison, to prevent impersonation and protect the safety of all users.
  • Power the discovery feed, matching you with compatible people based on your preferences, location, and profile.
  • Enable messaging between matched users.
  • Process subscription payments and manage billing.
  • Send you notifications about matches, messages, and account activity.
  • Send service-related emails (e.g., email verification, password reset, account security alerts).
  • Enforce our Terms of Service, investigate violations, and protect the safety of our users. This includes using automated AI systems to screen user content (photos, text, and audio) for potential policy violations before or during human review.
  • Improve the Service through analytics, A/B testing, and machine learning.
  • Comply with legal obligations.

We may also use anonymized, aggregated, or de-identified data derived from your use of the Service for any purpose, including analytics, research, product development, and marketing, without restriction. Such data does not identify you personally.

No ad targeting, no sale of data

We do not use your profile or behavioral data to serve third-party advertising. We do not sell your personal information.

4

How we share your information

With other users

Your profile information (name, photos, bio, age, and other profile fields) is visible to other users in the discovery feed and in matches. Social media handles you add to your profile (Instagram, TikTok, X/Twitter, LinkedIn, Reddit) are only visible to users you have matched with. They are not shown in the public discovery feed. Messages you send are visible to the recipient. Your exact location is never shown to other users; we only display a rounded distance (e.g., "2 miles away"). Photos and messages that another user can see may be captured or saved by that user. No website or app can fully prevent this on every device, so share only what you are comfortable being seen. Redistributing another user's photos or messages outside the Service is prohibited and may result in account termination.

With service providers

We share information with trusted third-party vendors who help us operate the Service:

  • Cloud infrastructure providers (hosting, databases, object storage, content delivery, and network security that operate the Service and deliver media)
  • Google Firebase (phone authentication and push notifications)
  • Google (OAuth sign-in)
  • Apple (sign-in and in-app purchases)
  • Resend (transactional email)
  • Sentry (error monitoring: receives your pseudonymous Fazool user ID and the technical details of any error you encounter, so we can diagnose and fix bugs. No email, phone number, or profile content is sent to Sentry.)
  • Axiom (server log aggregation: receives request metadata such as the URL path, HTTP status, request duration, and your pseudonymous user ID. Authorization tokens, cookies, and other sensitive headers are redacted before any log leaves our servers.)
  • Together AI (automated content moderation and ID verification: profile photos, text, voice notes, profile prompts, and identity documents may be processed by Together AI, a SOC 2 Type II certified inference provider, to detect content that violates our community guidelines and to verify the authenticity of identity documents. Voice notes are first transcribed to text using a speech recognition model (Whisper) and then classified for policy violations; the transcription is stored alongside the original audio for moderator review. When processing ID documents, text fields such as name and date of birth may be extracted to assist our moderation team with faster verification. Before any text content is sent, personally identifiable information such as email addresses, phone numbers, and URLs is removed. Together AI operates under Zero Data Retention, meaning your content is not stored after processing and is never used to train AI models. The provider receives only the content itself with no user identifiers, names, or account information. You can disable automated AI safety checks at any time in your account settings; your content will then be reviewed manually by our moderation team.)

These providers are contractually required to protect your information and may only use it to provide services to us.

For legal reasons

We may disclose your information if required by law, court order, or governmental authority, or if we believe disclosure is necessary to protect the rights, property, or safety of Fazool, our users, or the public.

Business transfers

If Fazool is acquired, merges with another company, or sells substantially all of its assets, your information may be transferred as part of that transaction. We may provide notice of such a transfer through the Service or by other reasonable means.

5

Identity verification and your ID

To access the full Fazool experience, you must verify your identity by uploading a photo of a government-issued ID (such as a driver's license or passport) and a selfie photo. Here is exactly what happens during verification:

Step 1: Government-issued ID

  • Upload: your ID image is transmitted over an encrypted connection (TLS) and stored in our secure cloud storage temporarily during the review process.
  • AI quality check: your ID photo is sent to Together AI to check that it is a real, legible document (not a screenshot or photocopy). The AI also extracts text fields (name, date of birth, document type, and state) to assist our moderation team with faster verification. Together AI does not store your ID image or the extracted data.
  • Review: a trained human moderator reviews your ID to verify your name, date of birth, and ID number.
  • Deletion: once your identity is verified (or permanently denied), the original ID image is deleted from our servers. We do not retain a copy of your ID photo after verification is complete.
  • What we retain: we store a one-way cryptographic hash (SHA-256) of your ID number solely to detect duplicate accounts and prevent banned users from re-registering. This hash cannot be reversed to reconstruct your ID number.

Step 2: Selfie and face verification

After uploading your ID, you submit a selfie photo. We use this selfie for three purposes:

  • Face comparison: our self-hosted face recognition software compares your selfie to the photo on your government-issued ID to confirm that you are the same person. The software produces a numerical similarity score. This comparison runs on servers operated exclusively by Fazool. Your selfie is never sent to a third-party service for face matching.
  • Liveness check: the software analyzes your selfie to detect whether it was taken of a live person rather than a printed photo, screen, or mask. This prevents impersonation. The liveness check produces a numerical score and a pass/fail result.
  • Duplicate detection: a mathematical representation of your facial geometry (a "face embedding") is computed from your selfie. This is a 512-dimensional numerical vector derived from your facial features. We compare this vector against those of other verified users to detect whether the same person has created multiple accounts. The comparison uses a mathematical distance calculation. Only potential matches are flagged for human review; no automated action is taken.
What is a face embedding?

A face embedding is a list of 512 numbers that represents the geometry of your face. It is generated by passing your selfie through a face recognition model (ArcFace). The embedding cannot be reversed to reconstruct your face, your photo, or any identifiable image. It can only be compared mathematically against other embeddings to determine whether two photos likely depict the same person.

What we retain after verification

  • Face embedding: your face embedding is retained after verification to support ongoing duplicate detection. When new users verify their accounts, their embeddings are compared against existing ones. This allows us to detect banned users attempting to re-register with a new account. The embedding cannot be used to reconstruct your face or identify you by name outside of our system. We do not keep it indefinitely: see the Biometric Data Policy below for our retention and destruction schedule.
  • Numerical scores: the face similarity score, liveness score, and estimated age produced during verification are retained as part of your identification record.
  • ID number hash: as described above.
  • App store age signal records: the platform (Android or iOS), age bracket, verification status, and outcome of any age signal received from your device's app store during account creation.

What we delete after verification

  • Your original ID photo and selfie photo are both deleted from our servers once verification is complete. We do not retain copies of either image.

Human review

The automated face comparison and liveness check produce advisory results only. A trained human moderator reviews every identification submission before making a final decision to approve or deny your account. The automated scores assist the moderator but do not replace their judgment. If the automated system produces a result you believe is incorrect, you may contact us to request a manual review.

No sale of biometric data

We never sell, lease, trade, or otherwise profit from your face embedding, selfie, or any biometric data. We do not share biometric data with third parties except as required by applicable law or court order.

Biometric Data Policy

This section is our written policy governing the facial-recognition template (your face embedding) described above. We obtain your explicit consent before creating it, and we retain and destroy it on a fixed schedule rather than keeping it indefinitely.

  • What it is: a numerical facial-recognition template derived from your selfie, used only to verify you are a real adult and to detect duplicate or banned accounts.
  • Consent: we ask for and record your explicit consent before your selfie is captured and the template is created. You may decline, but identity verification, and therefore use of the app, requires it.
  • Retention and destruction schedule: we destroy your facial-recognition template within three years of your last activity on Fazool, and when you delete your account. After deletion, a minimal irreversible fingerprint may be retained for up to three years solely to stop banned users from rejoining, after which it is permanently destroyed. Your selfie image is retained only as long as needed to complete the verification check and any manual review, then deleted.
  • Where we do not collect it: if you are located in a US state with a dedicated biometric-privacy statute (currently Illinois, Texas, and Washington), we do not create or store a facial-recognition template for you at all. Identity verification still runs, using only a transient comparison that retains no template.
6

Location data

Fazool uses your location to show you nearby people and power distance-based matching. Specifically:

  • We request access to your device's precise location (GPS) when you use the app.
  • Your precise coordinates are stored in our database and used for proximity queries.
  • Other users are never shown your exact location, only an approximate distance.
  • You can revoke location permission at any time in your device settings. If you do, you will need to enter your city manually to use discovery.
  • Your last known location is retained while your account is active and deleted when your account is permanently closed.
7

Data retention and account deletion

We retain your personal information for as long as your account is active and for a reasonable period thereafter as needed to:

  • Provide the Service.
  • Comply with our legal obligations.
  • Resolve disputes and enforce agreements.
  • Prevent fraud, abuse, and repeat violations.
  • Protect the safety and security of our users and the Service.

We may retain anonymized, aggregated, or de-identified data indefinitely for analytics, product improvement, and business purposes.

When you delete your account

Deleting your account triggers the following, immediately:

  • All your matches are dissolved immediately. Every match you had becomes inactive and disappears from both your inbox and the other user's inbox. Conversation history on the other side is no longer visible. If you restore your account within the 30-day grace period, your previous matches are NOT restored. They stay dead forever.
  • Your subscription is cancelled immediately. If you had an active paid subscription, it is cancelled with no prorated refund.
  • Your profile enters a 30-day grace period. During this window your profile is hidden from discovery and other users cannot see you, but your data is kept in our systems so you can change your mind. You can restore your account at any time during the grace period by logging in with your email and password, or by clicking the restore link in the deletion confirmation email we send.

What happens after 30 days

If you do not restore your account within 30 days, the deletion becomes permanent and irreversible. Your profile, photos, voice notes, identification records, messages, matches, swipe history, preferences, and all other personal information are permanently deleted from our systems. The only information retained after permanent deletion is:

  • The cryptographic hash of your ID number (retained to prevent re-registration after a ban).
  • A minimal irreversible face fingerprint, retained for up to three years after deletion to prevent banned users from re-registering with a new selfie, then permanently destroyed. It cannot be used to reconstruct your face or photo, and is not created at all for users in states where we do not collect biometric data. See the Biometric Data Policy above.
  • Information we are required to retain by law.
  • Anonymized, aggregated analytics data that cannot identify you.
8

Special category data

Fazool is a marriage app designed for the Muslim community. By creating an account and completing your profile, you may provide information that constitutes special category data under data protection law (such as the EU General Data Protection Regulation), including your religion, ethnicity, and sexual orientation.

We process this data on the basis of your explicit consent, which you provide when you voluntarily enter this information during profile creation. You can update or remove this information at any time in your profile settings. Where you choose to display this information on your public profile, it may also be processed on the basis that you have manifestly made it public (GDPR Article 9(2)(e)).

Biometric data

During identity verification, we collect biometric data in the form of a face embedding derived from your selfie. Under the EU General Data Protection Regulation (GDPR), biometric data processed for the purpose of uniquely identifying a natural person is classified as special category data under Article 9. We process your face embedding on the basis of your explicit consent, which you provide when you voluntarily submit your selfie during the identity verification step. You may withdraw consent at any time by contacting privacy@fazool.org and requesting deletion of your biometric data.

Under the Illinois Biometric Information Privacy Act (BIPA), the Texas Capture or Use of Biometric Identifier Act (Texas CUBI), and similar state laws, your face embedding may be classified as a biometric identifier. By submitting your selfie during identity verification, you consent to our collection, use, and storage of this biometric data as described in this Privacy Policy. You may request deletion of your biometric data at any time by contacting us at privacy@fazool.org.

9

Automated decision-making and profiling

Fazool uses automated systems to power certain features of the Service. These include:

  • Discovery feed ranking: our matching algorithm scores and ranks profiles shown to you based on various factors such as geographic proximity, shared interests, and account activity. No single factor is determinative, and the algorithm does not make decisions that produce legal effects or similarly significant effects on you.
  • Photo moderation: uploaded photos are reviewed by our moderation team before they are shown to other users.
  • Face verification: when you submit a selfie for identity verification, our self-hosted face recognition software automatically compares your selfie to your ID photo and runs a liveness check. The system produces an advisory result (pass, fail, or uncertain) and numerical scores. A trained human moderator reviews every result before making the final approval or denial decision. No account is approved or denied solely by the automated system.
  • Duplicate face detection: when you verify your account, your face embedding is compared against those of other verified users to detect potential duplicate accounts. Potential matches are flagged for human review. No automated action is taken against your account based on this comparison alone.
  • Automated content moderation: user-uploaded photos, profile text (biographies and prompt answers), voice notes, and sampled chat messages may be processed by AI-powered classification systems to detect potential violations of our community guidelines, including explicit content, harassment, spam, and deceptive behavior. Voice notes are transcribed to text before classification; the transcription is retained for moderator review. These systems produce an advisory classification and confidence score. Content flagged by AI is routed to a human moderator for final review. No content is automatically removed based solely on an AI classification unless a human moderator has previously approved automatic handling for that specific violation category and confidence level. You may appeal any moderation decision by re-uploading your content or contacting support@fazool.org.
  • Safety systems: automated tools may flag accounts or content for review based on patterns associated with spam, fraud, or policy violations.
  • Age signal enforcement: we automatically evaluate age signals received from your device's app store. If the signal confirms you are under 18, or that your account is supervised by a parent or guardian, account creation is denied. This automated decision is based solely on the age information provided by Google Play or Apple. If the age signal is unavailable or inconclusive, we fall back to our standard date-of-birth verification.

None of these automated systems make final decisions about your account without human review. If you are located in the EU, EEA, or UK, you have the right to request human review of any automated decision that significantly affects you. Contact us at privacy@fazool.org to exercise this right.

10

Your rights and choices

All users

  • Access and correction: you can view and update most of your profile information directly in the app.
  • Account deletion: delete your account at any time in Settings → Account → Delete Account.
  • Notifications: manage push notification preferences in your device settings and in-app notification settings.
  • Location: revoke location permission in your device settings at any time.

EEA, UK, and Swiss residents (GDPR)

If you are located in the European Economic Area, United Kingdom, or Switzerland, you have the right to:

  • Access the personal data we hold about you.
  • Rectify inaccurate personal data.
  • Erasure ("right to be forgotten") of your personal data.
  • Restrict or object to certain processing of your data.
  • Data portability: receive your data in a structured, machine-readable format.
  • Withdraw consent at any time where processing is based on consent.
  • Lodge a complaint with your local data protection authority.

If you request data portability, we will provide your data in a structured, machine-readable format within 30 days of your request.

EU Digital Services Act (DSA)

If you are located in the European Union, you have additional rights under the Digital Services Act, including the right to access out-of-court dispute settlement mechanisms, to seek court remedies, and to lodge complaints with your local Digital Services Coordinator.

California residents (CCPA / CPRA)

California residents have the right to:

  • Know what personal information we collect, use, and share.
  • Delete your personal information (subject to certain exceptions).
  • Opt out of the sale or sharing of personal information. We do not sell or share your personal information for cross-context behavioral advertising.
  • Non-discrimination for exercising your privacy rights.

To exercise any of these rights, contact us at privacy@fazool.org.

Biometric data rights

If you reside in a jurisdiction with biometric privacy laws (including Illinois, Texas, Washington, and other states with biometric data protections), you have the right to:

  • Request disclosure of any biometric data we hold about you, including your face embedding.
  • Request deletion of your biometric data. We will delete your face embedding within 30 days of a verified request, unless we are required by law to retain it.
  • Withdraw your consent to the collection and storage of biometric data at any time. Withdrawing consent may limit your ability to use features that require identity verification.

To exercise any biometric data rights, contact us at privacy@fazool.org.

Biometric data retention schedule

Your face embedding is retained for as long as your account is active and you remain a verified user. If you delete your account, your face embedding is permanently deleted when your account data is purged (30 days after account deletion, as described in the Data Retention section above). If you request deletion of your biometric data without deleting your account, we will delete your face embedding within 30 days. Your selfie and ID photos are deleted promptly after verification is complete; they are not retained long-term.

11

Cookies and tracking technologies

Our website uses cookies and similar tracking technologies. We use:

  • Essential cookies: required for the site to function (e.g., authentication tokens, security).
  • Analytics cookies: help us understand how users navigate the site so we can improve it. Analytics data is aggregated and anonymous.
  • Preference cookies: remember your settings and preferences.

You can control cookies through your browser settings. Disabling essential cookies may prevent you from using certain features of the Service.

12

Security

We use industry-standard technical and organizational measures to protect your personal information, including:

  • TLS encryption for all data in transit.
  • Encryption at rest for sensitive fields.
  • Access controls limiting who within Fazool can access personal data.
  • Regular security assessments and penetration testing.

No method of transmission or storage is 100% secure. If you believe your account has been compromised, contact us immediately at support@fazool.org.

13

Voice and video calls

When matched users mutually opt in, Fazool offers scheduled voice and video calls. Calls are processed by our self-hosted LiveKit infrastructure in Virginia, USA. Media is encrypted in transit between your device and our servers using DTLS-SRTP. Calls are not recorded under any circumstance.

We retain call metadata (date, scheduled time, type, duration, participant IDs) for moderation, safety, and analytics purposes. Both parties must turn on voice and/or video calling per match before either can propose a call, and either party can revoke consent at any time. Calls are capped at 30 minutes and scheduled in advance — there is no ringing or instant calling.

Call metadata is included in your account export and is purged when you delete your account, with the same retention rules that apply to message history.

14

Children's privacy

Fazool is not directed to children under 18. We do not knowingly collect personal information from anyone under 18. If we become aware that a user is under 18, we will immediately terminate their account and delete their information. If you believe a minor has registered on our platform, please report it to support@fazool.org.

15

International data transfers

Fazool is headquartered in the United States. If you access the Service from outside the United States, your information may be transferred to, stored, and processed in the US or other countries where our service providers operate. We rely on appropriate safeguards for such transfers, including Standard Contractual Clauses approved by the European Commission where applicable.

16

Changes to this policy

We may update this Privacy Policy from time to time. When we do, we will update the "Last updated" date at the top of this page. For material changes, we may, at our discretion, provide additional notice through the Service. Your continued use of the Service after the updated policy is posted constitutes acceptance of the revised policy. We encourage you to review this page periodically.

17

Contact us

If you have questions, requests, or concerns about this Privacy Policy or our data practices, please contact our Privacy Team:

Fazool LLC
Attn: Privacy Team
Privacy: privacy@fazool.org
Support: support@fazool.org

Terms of ServiceHome

Questions? support@fazool.org