Privacy Policy
Last updated: 15 August 2026
Smilee exists to hold the relationships you care about privately — not to study them, sell them, or show them to anyone else. This page explains, plainly, what we collect and why, and it is written to meet India's Digital Personal Data Protection Act, 2023 (DPDPA), the Digital Personal Data Protection Rules, 2025, and the IT Act, 2000.
This notice is provided in English. If you'd prefer a summary in another Indian language, write to hello@smilee.co.in and we'll provide one.
What we collect
When you apply for the Founding 1,000: your name, an email or phone number, your city (optional), and — if you choose to answer — who you'd want to make smile first. That's it.
If you're accepted as a Founding Member: a phone number (used to send your WhatsApp nudges), an email address if you add one, and a securely hashed password — we never store your actual password, only a one-way hash of it.
Your Circle: the names, relationships, and optional phone numbers or important dates you add for the people you want to stay close to. This is yours — we don't message these people on your behalf without your action.
Your Moments: whatever you choose to log in SMILEE Memories — a note, a photo, a call you made. It's kept in your private archive, visible only to you and whoever you explicitly shared it with.
How we use it
- To review your Founding 1,000 application and send your Smile Challenge.
- To send you gentle nudges over WhatsApp when it's been a while since you've reached out to someone in your Circle — only to opted-in members, never to the people in your Circle directly.
- To keep your account secure and your session signed in.
We process your personal data on the basis of your consent — given when you apply, sign up, or add information to Smilee. Where we're required by law to keep certain records (for example, to respond to a lawful request from an authority), we may retain limited data even after you withdraw consent, strictly as required by that law.
Consent and withdrawal
By applying or signing up, you consent to us collecting and using your data as described here. You can withdraw consent at any time by writing to hello@smilee.co.in — withdrawal is as easy as giving it. Withdrawing consent will usually mean we can no longer provide your account (for example, we can't send WhatsApp nudges without your phone number), so we'll confirm with you before closing anything.
What we never do
- We don't run ads, and we don't build advertising profiles from your data.
- We don't sell or rent your information to anyone.
- We don't have a public feed — your Moments and Circle are never shown to other users.
- We don't message the people in your Circle without you initiating it.
Smilee runs without third-party advertising trackers or analytics pixels. The only cookie we set is a secure, session-only cookie that keeps you signed in — nothing that follows you around the web.
How it's stored and secured
Your data lives in a database accessed only through parameterized queries (so it can't be manipulated by malicious input). Passwords are hashed, never stored in plain text. Your session is protected by a secure, HTTP-only cookie that can't be read by scripts, and all traffic to Smilee is encrypted over HTTPS.
Your rights as a Data Principal
Under the DPDPA, you have the right to:
- Access a summary of the personal data we hold about you and how it's being processed.
- Correct, complete, or update your data if it's inaccurate or out of date.
- Erase your data once it's no longer needed for the purpose you gave it for, or at your request.
- Nominate another individual to exercise these rights on your behalf in the event of your death or incapacity.
- Grievance redressal — raise a complaint with us first (see below), and if unresolved, with the Data Protection Board of India.
To exercise any of these, email hello@smilee.co.in. We'll respond within a few days and resolve most requests within 15 days.
Data retention
We keep your data only as long as it serves the purpose it was collected for — for example, waitlist applications that are rejected are deleted, and account data is deleted within a reasonable period after you close your account or withdraw consent, unless we're legally required to retain it longer.
Where your data is stored
Smilee's servers and database are hosted with providers that may process data within India or, for limited technical functions (such as email or WhatsApp delivery), through service providers located outside India. Under the DPDPA, cross-border transfer is permitted by default except to countries the Central Government specifically restricts — we don't transfer data to any restricted country, and we only work with providers bound to protect your data at a comparable standard.
Age requirement
Smilee is intended for adults — you must be at least 18 years old to apply or use Smilee. This matches both the age of contractual capacity under the Indian Contract Act, 1872, and the DPDP Rules, 2025, which require verifiable parental consent to process a child's (under-18) data and prohibit behavioural monitoring or targeted advertising to children. By keeping Smilee 18-and-over only, we avoid processing children's data at all. We don't knowingly collect data from anyone under 18; if we learn that we have, we'll delete the account and associated data.
If your data is ever breached
In the unlikely event of a personal data breach, we will notify the Data Protection Board of India and every affected user without delay, followed by a detailed report — what happened, who was affected, and what we're doing about it — within 72 hours, as required under the DPDP Rules, 2025.
Changes to this policy
If this policy changes in a meaningful way, we'll update the date at the top of this page and let our Founding Members know directly.
Grievance Officer & contact
In accordance with the DPDPA and the IT Act, 2000, questions, complaints, or data requests can be sent to our Grievance Officer:
Grievance Officer, Smilee
Email: hello@smilee.co.in
We acknowledge grievances within 24 hours and aim to resolve them within 15 days. If you're not satisfied with our response, you may approach the Data Protection Board of India, established under the DPDP Act, 2023.