Privacy Policy
Being noticed should feel safe, never watched. This is exactly what that means for your data.
The short version
- Compliments are anonymous. Nobody can find out who sent one, not even by asking us.
- Your name stays hidden until you and someone else both choose to connect.
- We never collect photos, your contacts, your precise location or a history of where you’ve been.
- We don’t sell your data, we don’t show ads, and we don’t track you across other apps or websites.
- You’re in control. Download or delete everything, anytime, from the app.
Who we are
Complimee is operated by Gourhit Ventures Private Limited, a private limited company registered in India under the Companies Act, 2013 (CIN U62011DL2026PTC470554), with its registered office at 808B, DLF Prime Tower, Pocket F, Okhla Phase I, Okhla Industrial Estate, New Delhi, Delhi 110020, India (“we”, “us”).
We decide why and how your personal data is used, so we are the data fiduciary under India’s Digital Personal Data Protection Act, 2023 (the “DPDP Act”) and the controller under the EU and UK General Data Protection Regulation (the “GDPR”).
This policy covers:
- the Complimee app for Android and iPhone;
- Complimee for venues, the web app where venues apply and print their posters;
- this website, www.complimee.com.
What we collect and why
Your account
- Sign-in details: your email address and how you sign in (Google, Apple or a code sent by email). With Apple, you can hide your real address. We use these to sign you in and to contact you about your account.
- Your profile: your first name, an optional one-line bio and a generated avatar. Other people see these only after you both choose to connect.
- Your age: you enter your date of birth to confirm you’re 18 or older. We keep only the year, and never show it to anyone.
- Your agreement: which version of this policy and our Terms you agreed to, and when.
While you’re visible
You choose when to be visible, and for how long.
- Where you’re visible: either the venue you checked in to, or, if you choose “right here”, a rough area about 170 metres across. Your phone works this area out itself: your coordinates are never sent to us for it. When you move, the new area replaces the old one; we keep no trail.
- Venue suggestions: to suggest venues near you, the app sends us an approximate location. We use it only to answer that request, and we don’t store it.
- Your look: the colour and the few items you chose to show (like “Lavender top · Sneakers”), and the spot in the venue you picked, if any.
- Your session: when it started and when it ends, and whether “keep me open” is on. While it’s on, your phone checks in about every 10 minutes; the session lapses 30 minutes after the last check-in, and after 12 hours at most.
- Moves: so nobody can sweep a city by claiming to be everywhere, we count how often you move far while visible. We count the moves, not the places.
People nearby see your look and a cute animal face that changes every session. They never see your name, photo or account.
Compliments, connections and chats
- Compliments you send and receive: which compliment or phrase, the look or item it was about, and when. We know who sent each compliment so we can deliver it, apply limits and act on reports, but we never reveal the sender to the person who receives it.
- Thanks and connection requests, and whether they were accepted.
- Chat messages with people you’ve connected with. Chats are text only.
Safety
- Blocks you make and reports you send, with the reason and any details you add.
- Enforcement records: limits, strikes and suspensions on accounts that break our rules.
- Verification: if we ask you to verify your age or identity, whether you’re verified.
Your device
- A notification token from Google’s Firebase Cloud Messaging or Apple’s push notification service, so we can send the notifications you’ve allowed, and which kinds you’ve turned on.
- Regional settings: your phone’s language and time-zone offset, so times and messages read right for you.
We don’t collect advertising identifiers, your contacts or your photos.
Usage counts
To learn whether Complimee works, we count events such as “a compliment was sent” or “a session started”. These counts carry no user, device or venue, and their times are rounded to the hour, so they can’t identify anyone.
Venues
If you apply in Complimee for venues, we collect:
- the venue’s name, type, address, map pin, website and the spots guests can pick;
- the contact person’s name, role and phone number, and your sign-in email;
- the logo or photo you upload. It’s stored privately, so only you can see it. Your poster is made in your own browser.
When you press Search in the address step, what you typed is sent to OpenStreetMap’s Nominatim service, and the map shows OpenStreetMap tiles. Both receive your IP address, as any website you load does.
Venues never receive any information about guests, not even how many there are.
When you contact us
Your email address and what you write, so we can answer you.
This website
www.complimee.com sets no cookies, runs no analytics and loads nothing from other companies. Our host, Cloudflare, processes your IP address and request details to deliver pages and protect the site from abuse.
What we never collect
Photos, your contacts, your precise location or location history, advertising identifiers, or anything that could tell someone who sent them a compliment.
Our legal grounds
- Your consent. You agree to this policy when you join, and you allow location and notifications through your phone’s own prompts. You can withdraw consent anytime: turn the permission off, or delete your account. Withdrawing doesn’t affect what happened before.
- Our contract with you. To provide the service you signed up for under our Terms of Service.
- Legitimate interests. To keep Complimee safe and secure: enforcing limits, looking into reports, preventing abuse and fraud, and keeping anonymous usage counts. We weigh these against your rights, and you can object.
- Legal obligations. To answer lawful requests and keep the records the law requires.
Under the DPDP Act, we process your data with your consent, and for the legitimate uses the Act allows, such as complying with the law.
Who sees your data
- Other people. Before you both connect: your look, your animal face, and compliments you send, never with your identity. After you connect: your first name, avatar and one-line bio, and your chat.
- Venues. Nothing about guests.
- Our team. A small number of authorised people, only to run the service, look into reports and keep people safe. This is the only place the sender of a compliment is ever visible, and access is restricted.
- Service providers that process data for us, under contract and only on our instructions:
| Provider | What for | Where |
|---|---|---|
| Supabase | Database, sign-in and server functions for the app and the venue web app | European Union (Frankfurt, Germany) |
| Google (Firebase Cloud Messaging) | Notifications on Android | Worldwide |
| Apple (Apple Push Notification service) | Notifications on iPhone | Worldwide |
| Google, Apple | Signing in, if you choose them | Worldwide |
| Our email delivery provider | Sending sign-in codes | Varies |
| Cloudflare | Hosting this website and the venue web app | Worldwide |
| OpenStreetMap Foundation | Map tiles and address search in the venue web app | Europe |
- Authorities, when the law requires it, or to protect someone from serious harm. We check every request.
- A buyer, if Complimee or our company is ever sold or merged. They would have to honour this policy.
We never sell personal data, and we never share it for advertising.
International transfers
We’re based in India, and we store app data with Supabase in Frankfurt, Germany. Some providers process data in other countries, including the United States. Where the law requires it, we use safeguards such as the European Commission’s Standard Contractual Clauses, and we transfer data out of India only as the DPDP Act allows.
How long we keep it
| Data | How long |
|---|---|
| Visible sessions (where, your look) | Deleted 24 hours after the session ends |
| Location sent for venue suggestions | Not stored |
| Compliments that don’t lead to a connection | Deleted after 30 days |
| Connection requests nobody answers | Lapse after 48 hours |
| Chats | Until either of you ends the chat, blocks the other or deletes their account |
| Account, profile, blocks and settings | Until you delete your account |
| Strikes | Count for 90 days; deleted with the account |
| Reports you made about others | Kept after you delete your account, without anything that identifies you |
| Notification records | Deleted shortly after they’re sent |
| Usage counts | Kept as statistics; they identify no one |
| Backups | Overwritten within 30 days |
Your rights
You can, anytime and for free:
- see and download everything we hold about you: in the app, You → Your data → Download my data;
- correct your name and line: You → Edit name and line;
- delete your account and data: You → Your data → Delete my account (or see Delete your account);
- withdraw consent: turn off location or notifications in your phone’s settings, or delete your account;
- ask us to stop or limit how we use your data, or object to it;
- name someone to exercise your rights for you if you can’t;
- complain: to us first (see below), and then to a data protection authority. In India, that’s the Data Protection Board of India. In the EU and EEA, it’s the supervisory authority where you live; in the UK, it’s the Information Commissioner’s Office.
If you live in the United States, you can also ask to know what we hold, and to correct or delete it. We don’t sell or share personal information for targeted advertising, so there’s nothing to opt out of, and we won’t treat you differently for using your rights.
Your right to see your data covers your data, not other people’s: we won’t tell you who sent you a compliment.
We reply within 7 days where we can, and always within the time the law sets (one month under the GDPR). We may need to confirm it’s you, usually by asking you to write from the email address you sign in with.
Keeping your data safe
Data is encrypted in transit and stored encrypted by our hosting provider. The database itself enforces who can read what, so the app can only ever reach what each person is allowed to see. Staff access is restricted. No system is perfectly secure: if a breach affects you, we’ll tell you and the authorities as the law requires.
Found a security problem? Write to hello@gourhit.com with “Security” in the subject.
Children
Complimee is only for people aged 18 and over. We don’t knowingly collect data from anyone younger. If we learn that an account belongs to someone under 18, we delete it. If you think a child is using Complimee, report them in the app (“Seems under 18”) or write to us. See our Child Safety Standards.
Changes to this policy
When we change this policy, we update the date and version at the top. If a change matters, we’ll tell you in the app before it takes effect and ask for your agreement again where the law requires it.
Contact and grievances
For anything about your data, write to hello@gourhit.com with “Complimee privacy” in the subject, or by post to Gourhit Ventures Private Limited, 808B, DLF Prime Tower, Pocket F, Okhla Phase I, Okhla Industrial Estate, New Delhi, Delhi 110020, India.
Grievance Officer (India). For complaints under the DPDP Act and the Information Technology Rules, 2021, write to the Grievance Officer, Gourhit Ventures Private Limited, at hello@gourhit.com with “Complimee grievance” in the subject. We acknowledge complaints within 24 hours and resolve them within 15 days.