Ranmuthu Privacy Policy
Last updated 6 August 2026
This policy explains what personal information MADE BY MATTER PTY LTD (ACN 699 846 896) collects through Ranmuthu, why we collect it, and what you can do about it. It sits alongside our general privacy policy, and where the two differ, this one applies to Ranmuthu.
Ranmuthu is a matrimonial app for Sri Lanka. It asks for more about you than most apps do — including an identity document and photographs of your face — so this policy is specific about what happens to each of those things.
We handle personal data under Sri Lanka's Personal Data Protection Act, No. 9 of 2022. Because we are an Australian company, the Australian Privacy Principles in the Privacy Act 1988 (Cth) also apply to how we hold it. If you are in the United Kingdom or the European Economic Area, the UK GDPR and GDPR apply to you as well.
The short version
- We never store your NIC, passport or licence number. We read it, check it, and keep only a one-way fingerprint that cannot be turned back into the number.
- We never keep the photograph of your identity document, except in one narrow case described below, and then for no more than seven days.
- We never store your address book. If you ask us to hide you from your contacts, the numbers are converted to fingerprints on your phone's behalf and the numbers themselves are discarded.
- We do not collect your location. We ask which district you live in, and nothing more precise than that.
- We show no advertising, run no third-party analytics, and never sell or share your information with anyone for marketing.
- You can delete your account from inside the app, and it really is deleted.
What Ranmuthu collects
To create your account: your phone number, and your name and email address if you sign in with Google or Apple. Your phone number is verified by SMS.
Your profile: your name, date of birth, gender, civil status, the district and city you live in, religion, ethnicity, height, education, profession, employment status, languages you speak, whether you have children, and your answers to the profile prompts. You choose all of this and you can edit it.
Your photographs: the photos you add to your profile.
Birth details: your time and place of birth, for horoscope matching. This is optional to the extent that you may say you do not know your birth time. It is stored and is not used for anything yet.
If you verify your identity: a photograph of your NIC, passport or driving licence, and a selfie. What happens to these is set out under Identity documents below — it is the most important part of this policy.
If you turn on “Hide me from my contacts”: your phone's address book is read on your device, the numbers are sent to us, converted immediately into one-way fingerprints, and the numbers themselves are discarded. We never write a phone number from your address book to disk. We store only the fingerprints, so that we can hide you from those people without ever knowing who they are.
What we do not collect: your GPS or precise location, advertising identifiers, your contacts' names, your browsing on other apps or sites, or anything about people under 18 — Ranmuthu is not open to them.
We strip the hidden camera data (including any GPS coordinates) from every photograph you upload, before it leaves your phone.
Identity documents
This is the part people worry about most, so here it is in full.
When you verify your identity, you photograph your NIC, passport or driving licence. That image is uploaded to a private location that no user of the app can read — including you, once it is sent.
A program reads the document, checks the number is structurally valid, and compares the name, date of birth and gender against what you told us. The image is then deleted in the same operation — on success, on failure, and even if something crashes part-way. We do not keep it, and we do not keep the number.
What we keep instead is a one-way fingerprint of the document number, made with a secret key. It lets us notice if the same document is used to make a second account, or if a banned person comes back. It cannot be reversed into your number.
The one exception. Some documents — driving licences above all — cannot be read automatically, because they have no machine-readable strip and no consistent layout. Rather than refuse you, we keep that image so a person at Made by Matter can look at it. When that happens:
- it is stored where no app user can reach it;
- a reviewer sees it only through a link that expires after ten minutes;
- every single view is recorded — who looked, at whose document, and when;
- it is deleted the moment a decision is made; and
- it is deleted automatically after seven days regardless, even if nobody has looked at it.
The seven-day limit is deliberate. It means that in the worst case there is a week of pending reviews in existence, and never a growing archive of identity documents.
The selfie. If you verify your photo, we compare your selfie against your profile picture to check you are the same person. The comparison is done by Amazon Rekognition, the images are sent for that one comparison only, and neither we nor Amazon keeps them afterwards. We keep only the result: yes or no, and when.
Why we are allowed to hold it
Under the PDPA and the Australian Privacy Principles, we rely on:
- Your consent, which you give at sign-up and can withdraw by deleting your account. Identity verification and contact hiding are separately optional, and each asks you first.
- Performing our agreement with you — we cannot run a matrimonial service without a profile.
- Our legitimate interest in keeping people safe, which is why we screen photographs, verify identities, and keep fingerprints of banned documents.
Who else handles it
We keep this list short on purpose.
- Google Firebase — accounts, database and file storage. Your profile data is held in Firebase's Mumbai region (India).
- Cloudflare R2 — profile photographs.
- Google Cloud Vision — checks photographs for nudity and confirms there is a face in them; reads identity documents. Images are sent for the check and not retained.
- Amazon Rekognition — the face comparison described above. Images are sent for the comparison and not retained.
Some of these process data outside Sri Lanka, including in the United States. We use providers who commit to appropriate safeguards for that transfer. We do not sell your information, and we do not share it for anyone's advertising.
How long we keep it
- Identity document images — deleted in the same operation, or within seven days in the manual review case above.
- Selfies for photo verification — deleted as soon as the comparison finishes.
- Your profile and photographs — until you delete your account.
- Document fingerprints — kept while the account exists. If an account is banned for a serious safety reason, we keep the fingerprint afterwards so the same document cannot be used to come back.
- Reviewer access records — kept as a record of who looked at identity documents. When you delete your account, your identifier is removed from these records, so what remains shows that a review happened without showing whose.
Deleting your data
Settings → Delete account. It is immediate and permanent. It removes your profile, your photographs from our storage, your privacy settings, your verification history, any identity document still awaiting review, and your sign-in account itself.
If your photographs cannot be removed at that moment, we stop and tell you, rather than deleting your account and leaving the images behind.
If you have already uninstalled the app, email hello@madebymatter.com.au and we will action it within 30 days.
Your rights
You can see everything we hold about you from inside the app: Settings → Download my data gives you a file containing your profile and settings, which you can save or send wherever you like.
You can also correct anything from your profile, withdraw consent by deleting your account, and ask us for a copy or a correction by email. Under the PDPA you may complain to Sri Lanka's Data Protection Authority. If you are in the UK or EEA you may object to processing, ask for portability, and complain to your local supervisory authority.
Security
Your data is held in Google Firebase and Cloudflare, both of which encrypt it in transit and at rest. Access rules are enforced on our servers, not merely in the app, so a modified copy of the app cannot read another person's information. Identity document storage cannot be read by any app user at all. The secret keys used to make fingerprints are held in Google Secret Manager and are not in our source code.
No system is perfectly secure. If a breach affects you, we will tell you and the relevant authority as the law requires.
Children
Ranmuthu is for adults seeking marriage and is strictly 18+. We check your date of birth at sign-up and refuse and delete accounts that are under 18. If you believe a child has made an account, email us and we will remove it.
Changes
We may update this policy. If we do, we will change the date at the top of this page, and if the change is significant we will tell you in the app.
Complaints and contact
Email hello@madebymatter.com.au and we will respond within 30 days.
MADE BY MATTER PTY LTD
ACN 699 846 896
Brisbane, Australia