Last updated: 5 October 2026
Welcome to amarjibon (আমার জীবন). This Privacy Policy explains what personal information we collect, how we use it, and what choices you have. By creating an account, you agree to the practices described here.
amarjibon is operated by Safe Care Services, a sole proprietorship registered in Bangladesh under trade licence TRAD/DNCC/027461/2024 issued by the Dhaka North City Corporation. Registered address: House 60, Road 06, Section 12, Block A, Pallabi, Mirpur, Dhaka 1216, Bangladesh. We can be reached at help@amarjibon.com for any privacy question. Our designated data protection contact is privacy@amarjibon.com.
We do not sell your personal data to anyone. Ever. We do not run third party ad networks inside the app.
verifications.view_documents permission, or to an authenticated owner through the system's explicit owner-role authorization bypass. Never displayed publicly. Never shown to other users.We treat NID documents as sensitive personal information. Here is exactly how we handle them:
amarjibon-attachments) under your own user namespace. Never indexed, never public.verifications.view_documents permission can view your NID images, raw document metadata or contact fields, except that an authenticated owner may use the explicit owner-role authorization bypass. Access is limited to the purpose of verification. The verifications.read, verifications.approve and verifications.reject permissions alone do not expose them to a non-owner; decision responses stay redacted unless the caller holds the document grant or owner bypass. A raw-document URL request makes a best-effort access-audit attempt, and StaffGuard makes a separate best-effort break-glass attempt when owner bypass carries the route. An audit-write failure does not prevent the view. Reading the permission-graded queue is not guaranteed to create a per-row access receipt.Profile photos are uploaded to amarjibon-photos, served via short-lived signed URLs. They are visible to other signed-in users. Voice and video introductions are treated the same. If you delete a photo, it is permanently removed from storage within 7 days.
You can, at any time:
Optional email has two separate choices: Marketing and Daily updates. Both stay off unless you make an explicit, unchecked choice during signup, the one-time account prompt, or Settings. Turning either choice off takes effect locally at once and is synchronized to Resend; if amarjibon and Resend disagree, we treat you as unsubscribed. Required account, security, payment, privacy and safety messages do not depend on these optional choices.
We currently use Neon for structured account data and Cloudflare R2 for photos, identity documents, media and export files. Our hosting, cache and other service providers may process data in their configured regions, including outside Bangladesh. We protect transfers with encryption and access controls and apply the retention and deletion periods stated in this policy. Provider regions and backup schedules vary by service; we do not rely on a single AWS region or one universal 30-day backup period.
We use essential cookies for keeping you signed in and remembering your language preference. With your optional choice, we also use product analytics to measure feature use and improve amarjibon — our own systems together with PostHog, our analytics processor. Analytics event payloads do not include your name, email address or phone number. PostHog receives a pseudonymous identifier; while you are signed in, amarjibon links its first-party copy of the events to your internal account ID so authorized staff can view daily usage totals for account support and product analytics. Like any service receiving an internet request, PostHog receives the connection IP as transport metadata. Our web and mobile clients mark every analytics event to disable GeoIP enrichment and do not include an IP address as a custom event property. PostHog's project-wide “Discard client IP data” setting has been on since 3 September 2026, so PostHog does not store the connection IP with any event it ingests from then on; PostHog may still use the IP inside its ingestion pipeline before discarding it, and our clients disable GeoIP enrichment. We must update this disclosure and the checked-in inventory if that setting changes. Foreground time-in-app measurement is enabled on the web from 3 September 2026, and in the mobile apps from app version 1.1.0. Earlier installed versions continue under the previous scope until they are updated. Where it is enabled, and with your optional choice, the app counts only whole seconds while it is in the foreground, stops counting while it is hidden or in the background, sends the completed duration without start or end timestamps in the event properties, and caps any single foreground period at four hours. We do not use this duration for billing, access, matching or moderation, and a missing measurement does not mean zero use. Your choice also allows session recordings: a replay of how the product was used, with all text, form fields and images hidden before the recording leaves your device, so we can see where people get stuck without seeing what they wrote or who they viewed. On the web this has been on since the analytics choice existed; in the mobile apps it starts with app version 1.2.0, masked the same way, and earlier versions do not record. Retention differs by store: amarjibon keeps its first-party raw analytics events for at most 400 days; once foreground time is enabled, its account-linked daily usage totals are kept for at most 180 days. On our current PostHog Free plan, PostHog keeps product-analytics events for one year and session recordings for 30 days. A PostHog plan change requires us to revalidate and update this disclosure and our checked-in analytics inventory. Analytics data is not sold or shared for advertising. You can decline or withdraw your choice at any time in Privacy Center. Older installed versions may continue sending the previous optional analytics scope to PostHog under your prior choice until they are upgraded or retired; the withdrawal control remains available in Privacy Center. Withdrawal immediately stops new capture and clears the device identifier and queued events. For signed-in analytics linked to your pseudonym, amarjibon records a durable deletion request, retries the provider delete, and requires a later quiet-window check to report the person profile absent before marking that request delivered. PostHog processes queued event and recording deletion separately, so that external work may finish later. Anonymous analytics created before durable account-owner binding, or by older software, is terminally unresolved: later server-owned evidence never promotes it into an account binding. Its event bodies are not automatically attached to an export or account erasure. If persisted evidence indicates that history may relate to your account, the request is marked incomplete for manual review; the history remains subject to the applicable retention or provider-cleanup process. We do not use third-party advertising cookies or trackers.
Optional marketing and update emails do not use open tracking or tracking pixels. We record delivery outcomes supplied by Resend and use a first-party, approved amarjibon redirect to count link use and connect it to later aggregate conversion results. We do not retain an IP address, user-agent, device or inferred location for email interaction measurement. Public email links expire, are stored only as cryptographic hashes, and are excluded from search indexing.
Session recordings run on the web and, from app version 1.2.0, in the mobile apps. Withdrawal destroys the on-device replay queue on both, including a recording written in the moments after you withdrew, which would otherwise have been uploaded the next time you opted in. Mobile recording was held back until that was true on each platform. If you upgrade from 1.1.0, the app asks for your choice again before recording starts: the earlier choice was made under a disclosure that said mobile recording was off.
We send text messages in two situations. First, one-time passcodes (OTP) to verify your phone number, sign in, or reset your password — you get these because you asked us for a code, and they keep your account secure. Second, account alerts, match updates and the occasional offer — we send these only if you ticked the optional "Text me at this number" box when you signed up. Consent to receive that second kind is not a condition of creating an account, of using amarjibon, or of any purchase: leave the box unticked and everything still works. You can turn it on or off whenever you like in Settings → Notifications.
amarjibon is strictly for adults aged 18 and older. We verify age via NID. If we discover a user is under 18, we immediately delete the account.
When we make material changes, we update this policy and its "Last updated" date and let you know in the app or by email; changes take effect when we publish them. Optional analytics works differently, and deliberately so: publishing a disclosure never activates collection, and no waiting period can either. The optional analytics terms — foreground time-in-app measurement and session recording alike — take effect only when you make an explicit affirmative choice for the current analytics scope, and there is no other route to switching them on. We changed this activation condition on 3 September 2026: it previously also required the notice to have aged 14 days, and we activated foreground-duration measurement on the web that same day, having sent the notice the same day. On 4 September 2026 we stated plainly that the same rule covers session recording, which reaches the mobile apps in app version 1.2.0: we still notify you of the change, and your own opt-in is still the only thing that starts it. We are telling you the date plainly rather than leaving you to infer it. Nothing was or is collected from anyone who has not opted in, and turning the choice off stops collection immediately. Continued use after an effective date may constitute acceptance of other general policy changes, but it never grants optional analytics consent.
Privacy questions or requests: privacy@amarjibon.com. General support: help@amarjibon.com. Postal address: Safe Care Services, House 60, Road 06, Section 12, Block A, Pallabi, Mirpur, Dhaka 1216, Bangladesh.