Privacy policy
What we collect,
and what we refuse to.
Written in plain English, because a policy nobody reads protects nobody. This describes our actual systems — not aspirations.
Plain-language summary. We collect your work email to prove you are a real employee, then encrypt it and never show it to anyone. We do not store anonymous Q-Chat messages. Your employer receives nothing about you, ever. We do not sell your data. You can delete your account and data at any time.
1. Who we are
QBCLE is a brand owned and operated by T3KZ Services (OPC) Private Limited ("T3KZ", "QBCLE", "we", "us"), a One Person Company incorporated in India with its registered office in Bengaluru, Karnataka, India.
For the purposes of the Digital Personal Data Protection Act, 2023 ("DPDP Act"), T3KZ Services (OPC) Private Limited is the Data Fiduciary for the personal data described in this policy, and you are the Data Principal.
- Legal entity
- T3KZ Services (OPC) Private Limited
- Brand / product
- QBCLE
- Registered office
- Bengaluru, Karnataka, India
- Contact
- crew@qbcle.space
This policy applies to the QBCLE mobile app, the website at qbcle.com, and any related services. It does not apply to third-party services you reach from QBCLE, which have their own policies.
2. What we collect
2.1 Information you give us at sign-up
- Email address and a password. Passwords are stored only as a bcrypt hash — we cannot read your password and cannot recover it for you.
- If you sign in with Google, we receive your Google account email, display name and profile picture URL. We do not receive your Google password and cannot access your Google account.
- Display name, gender, date of birth, city and a short headline.
2.2 Verification information
- Work email address. Stored encrypted at rest using authenticated symmetric encryption, alongside a one-way SHA-256 fingerprint. The fingerprint exists solely to detect if the same work email is already registered. Your work email is never displayed to any member and is never used for marketing.
- Employer name, derived automatically from your work email domain. This is shown on your profile as a badge unless you enable Hide Organisation.
- Mobile number. You verify it by giving one missed call to a number we display. We store the number in normalised form and record that it is verified.
- One-time codes sent to your email, along with send counts and timestamps, so we can rate-limit abuse.
2.3 Profile and activity data
- Optional profile fields: designation, current city, office location, home location, LinkedIn and Instagram links, chosen pet mascot, photo visibility setting.
- Your profile photo. Uploads are auto-oriented, resized to 512×512, centre-cropped and re-encoded as JPEG. The original file is not retained.
- Content you create: gang posts, replies, reactions, community listings, Talent Board posts, Q-Lens questions and answers, Q-Help cause posts, company reviews.
- Connections and interactions: buddies, swipes, date requests, matrimony interests, blocks and reports you file.
- Optional matrimony fields including religion, community and an income bracket — never an exact figure, and only if you choose to add them.
- QSalary ledger: every Qs credit and debit with a reason, so your balance is auditable.
2.4 Messages
- Buddy, date and matrimony chats are stored on our servers so your history survives a device change. They are not end-to-end encrypted. Treat them as private-but-recoverable, not secret.
- Anonymous Q-Chat messages are never stored. See section 5.
- When a recipient is offline, an undelivered message is briefly queued and deleted the moment it is delivered.
2.5 Technical and security data
- Authentication events: sign-up, login success and failure, password reset. We record a partially masked email, the account id, the IP address and the outcome.
- Chat session metadata: the type of chat, an opaque session identifier, the initiating IP address, user agent, and the times the session started, revealed and ended. Message content is not part of this record. Retention of this metadata is mandated by the CERT-In Directions of 28 April 2022.
- Device push token and platform, if you enable notifications.
- Standard server logs including IP address, request path and timestamp.
2.6 Payment data
Subscriptions are processed by Google Play billing or Razorpay. We receive an order identifier, a payment identifier, the amount and the status. We never see or store your card number, UPI PIN, CVV or bank credentials.
3. What we never collect
- Your salary as an exact figure. Only an optional bracket, on Q-Matrimony only.
- Government identity documents. We do not ask for Aadhaar, PAN, passport or a company ID card, and we do not run selfie or document verification.
- Continuous or background location. We use the city you type, not GPS tracking.
- Your contact list, call logs, SMS, photo library or any other app's data.
- Biometric data of any kind.
- Anything from inside your employer's systems. We never connect to your company's identity provider or HR system.
4. Why we process your data, and on what basis
Under the DPDP Act we process personal data on the basis of the consent you give when you create an account and when you enable each individual feature, and for certain legitimate uses permitted by law such as complying with a legal obligation.
- Verification — to establish that you are a genuine salaried professional, which is the entire premise of QBCLE.
- Matching and discovery — to build your dating, matrimony and Q-Chat results according to the filters you set.
- Safety — to enforce blocks, act on reports, detect duplicate accounts and rate-limit abuse.
- Communication — to send verification codes, notifications you have opted into, and the optional daily email digest.
- Billing — to activate and manage your subscription.
- Legal compliance — to retain the records Indian law requires and respond to lawful requests.
Each of dating, matrimony and Q-Chat has an independent on/off switch. Turning one off stops that processing and removes you from that feature's results.
5. Anonymous Q-Chat, specifically
Q-Chat is the one place where we deliberately built ourselves out of the loop.
- Message content is never written to our database. Messages travel between the two devices over a real-time connection and are held on your device.
- Both people start anonymous. Neither name, photo nor employer is shared until you both choose to reveal.
- Your filter choices are not saved. The filter form opens empty every time, by design.
- When either person ends the session, the log is destroyed for both sides. There is no archive and no recovery.
- We retain only the session metadata described in section 2.5, because we are legally obliged to.
Because we do not hold Q-Chat content, we cannot produce a transcript for you — including if you want to report something said in a Q-Chat. Report the session while it is still open, or take your own screenshot before ending it.
6. Your employer gets nothing
This deserves its own section because it is the question we are asked most.
- We do not provide employers with any individual member data. There is no employer dashboard, admin console or export that reveals who is a member or what they do.
- An employer cannot request that we suspend, unmask or hand over a member's account. Your account is personal and is not company property.
- Where we partner with an employer, they may receive only aggregate, anonymised figures above a minimum threshold, such as total verified members or total carpool trips.
- Q-Lens questions and answers are anonymous to everyone, including to the company being discussed and to the employer of the person answering.
7. Who we share data with
We do not sell personal data. We share the minimum necessary with the following processors, each bound to use it only to provide their service to us:
- Google Cloud — application hosting and file storage.
- Neon — managed PostgreSQL database hosting.
- Google Firebase Cloud Messaging — delivery of push notifications. Receives your device token and the notification text.
- Brevo — transactional email delivery for verification codes and the daily digest. Receives your email address and the message.
- Google Play billing and Razorpay — subscription payments.
- Google AdMob — advertising for free-tier members only. See section 12.
- A telephony provider — receives the calling number for missed-call verification.
We also disclose data where we are legally required to, in response to a valid order from a court or a competent authority, or where necessary to prevent imminent harm to life or safety.
8. Where your data lives
Our servers and database are currently hosted outside India, in the United States. Your personal data is therefore transferred and stored outside India. The DPDP Act permits such transfers except to territories the Central Government restricts by notification.
We will update this section if we move to Indian hosting or if the applicable notification changes.
9. How long we keep things
- Profile and content — while your account is active. Deleted when you delete your account.
- Buddy, date and matrimony messages — while your account is active, or until you delete the conversation.
- Q-Chat content — never stored.
- Undelivered message queue — deleted on delivery.
- One-time codes — invalidated after use or after 10 minutes.
- Authentication and security logs — 180 days, as required by the CERT-In Directions 2022.
- Chat session metadata — 180 days under the same directions.
- Payment and subscription records — as long as tax and accounting law requires, generally 8 years.
- Report and block records — retained after account deletion in a de-identified form, so a banned member cannot simply rejoin.
10. How we protect your data
Honest description of what is actually in place today:
- All traffic to our servers is encrypted in transit over HTTPS/TLS.
- Passwords are hashed with bcrypt at a work factor of 12. They are never stored in a readable form.
- Work email addresses are encrypted at rest with authenticated symmetric encryption; keys are held in the server environment and never in the codebase.
- Access to the app requires a short-lived signed access token. Sessions expire and must be renewed.
- Authentication and OTP endpoints are rate-limited to frustrate brute-force attempts.
- Photo visibility, blocks and keep-away are enforced on the server, so restricted data is never sent to a client that should not receive it.
- Security headers, request size limits and strict transport security are applied to all responses.
What we do not claim: we are not currently SOC 2, ISO 27001 or PCI certified, we do not offer end-to-end encrypted messaging outside Q-Chat, and we do not operate a 24/7 security operations centre. No system is perfectly secure, and we will not tell you otherwise.
11. Your rights
As a Data Principal under the DPDP Act, you have the right to:
- Access a summary of the personal data we hold about you and how we process it.
- Correct, complete or update inaccurate data. Most fields are directly editable in the app.
- Erase your personal data, except where we must retain it by law.
- Withdraw consent as easily as you gave it. Turn any feature off in settings, or delete your account.
- Nominate another individual to exercise your rights in the event of your death or incapacity.
- Raise a grievance — see section 16 — and escalate to the Data Protection Board of India if you are not satisfied.
To exercise any of these, use the in-app option or write to crew@qbcle.space from your registered email. We respond within 30 days. We may ask you to confirm your identity first, so one member cannot access or delete another's data.
12. Advertising and analytics
- Free-tier members may see ads served by Google AdMob. Paid plans are ad-free.
- AdMob does not receive your work email, employer, income bracket, message content or Q-Chat activity.
- You can limit ad personalisation in your Android or iOS device settings; we honour that signal.
- On the website we use privacy-respecting analytics to count page views and referrers. We do not build cross-site advertising profiles of visitors.
13. Age limit
QBCLE is strictly for adults aged 18 and over. We do not knowingly collect data from anyone under 18. If we learn that a member is under 18, we suspend and delete the account. Report a suspected underage account through the in-app report flow, which includes "underage" as a reason.
14. If something goes wrong
In the event of a personal data breach we will notify the Data Protection Board of India and every affected member without undue delay, as the DPDP Act requires. Where the CERT-In Directions apply, we will report the incident to CERT-In within six hours of becoming aware of it. Our notice to you will describe what happened, what data was involved and what you should do.
15. Changes to this policy
We may update this policy. For any change that materially affects your rights or how we use your data, we will notify you in the app and by email at least 14 days before it takes effect, and give you the chance to withdraw consent or delete your account. Minor clarifications take effect on publication. The version and effective date at the top of this page always reflect the current text.
16. Grievance officer & contact
In accordance with the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021 and the Digital Personal Data Protection Act, 2023:
- Grievance Officer
- Rajiv
- Company
- T3KZ Services (OPC) Private Limited
- crew@qbcle.space
- Registered office
- Bengaluru, Karnataka, India
- Acknowledgement
- Within 24 hours of receipt
- Resolution
- Within 15 days of receipt
Any user may raise a complaint about content, conduct, a breach of these policies, or the handling of their personal data. If we do not resolve your grievance to your satisfaction, you may escalate to the Data Protection Board of India.
Related: Terms of Use · Safety charter · FAQ · Contact