Privacy Policy
Effective Date: August 15, 2026
Last Updated: August 15, 2026
This is a standalone policy, separate from our Terms and Conditions.
1. Introduction and Scope
This Privacy Policy explains how Bina AI Private Limited ("we", "us", "our"), which operates Milne Se Pehle (milnesepehle.in), collects, uses, shares, retains, and protects your personal data when you use our website, app, or verification services (together, the "Platform").
We've written this policy to be a standalone document, kept separate from our Terms and Conditions, and in plain language wherever the law allows, so you can actually read and understand it, not just scroll past it.
By logging into or otherwise using the Platform, you agree to this Privacy Policy governing how we handle your data. That is separate from the specific consent required before we actually process your data for a given purpose, such as running a verification check or sending you marketing, which is captured individually as described in Section 7, in line with the DPDP Act's requirement for free, specific, and granular consent.
2. Who We Are
Legal entity: Bina AI Private Limited
Trade name / brand: Milne Se Pehle
GSTIN: 05AAOCB6112F1ZY
Registered office: House, Jaydev Pur, Kotdwar, Lokmanipur, Pauri Garhwal, Uttarakhand, 246149, India.
Milne Se Pehle is a consent-based pre-matrimonial self-verification platform. We help individuals verify their own facts, including identity, education, employment, financial, and background records, using official and licensed sources, and turn them into a shareable certificate.
3. Definitions
A few terms used in this policy, explained simply:
- Data Fiduciary: the entity that decides why and how personal data is processed. That is us, Bina AI Private Limited.
- Data Principal: the individual the personal data is about. That is you.
- Personal Data: any data that identifies you, directly or indirectly.
- Processing: anything done with personal data, including collecting, storing, using, sharing, or deleting it.
- Consent Manager: an upcoming, government-registered service that will let you view and manage your consents across platforms from one place. Not yet operational nationally; see Section 19.
4. What Personal Data We Collect
What we collect depends on the plan and checks you choose. In line with what's shown on our pricing page, this can include:
Account and contact information
- Name, phone number, email address, and login credentials.
- Phone number or email of someone you invite to a multi-person plan, collected only to deliver the invite (see Section 10).
Verification data (per person being verified)
- Identity: Aadhaar, PAN, driving licence, passport.
- Address: address history, physical verification.
- Education: degree verification.
- Employment: employer details, ITR history, EPFO history.
- Financial: credit history (e.g. via authorised credit information companies), past and active loans.
- Criminal and court: court records, eFIR.
- Social media: public presence review.
- Business details (if applicable): Udyam registration, company details.
- Medical registration (if applicable): doctor / nurse council registration.
Payment information
Billing details and transaction records. We do not store your full card details; payments are processed through licensed payment gateways.
Technical and usage information
Device type, IP address, browser type, and how you interact with the Platform.
Cookies and tracking data
See Section 13 for full detail on cookies, pixels, and analytics tools.
5. How We Collect It
Not everything is pulled silently in the background. Depending on the check:
- Some data is fetched directly via API from official and licensed sources (e.g. identity and court-record checks) once you give OTP-based consent.
- Some checks need a quick extra step from you, like logging into DigiLocker or your ITR portal, or uploading a payslip, offer letter, or degree certificate. These are still verified against the official record, not just self-reported.
- Technical and cookie data is collected automatically when you use our website or app (see Section 13).
- Every check, whether it's about you or someone you're asking to verify, requires that person's own OTP-based consent. No exceptions, not even for family members.
6. Why We Collect It
- To perform the verification checks you've requested and generate your certificate.
- To let you share your certificate with, or view a certificate shared by, another consenting user.
- To process payments and meet our tax and accounting obligations.
- To detect and prevent fraud or misuse of the Platform.
- To maintain, secure, and improve the Platform.
- To communicate with you about your account, checks, or support requests.
- With your separate, specific consent, for marketing communications. You can opt out anytime.
7. Consent
Under India's Digital Personal Data Protection Act, 2023 ("DPDP Act"), consent must be free, specific, informed, and unambiguous, and, following a 2026 Supreme Court clarification, granular: we ask for consent separately for each distinct purpose, rather than bundling everything into one blanket "I agree."
- You give explicit, OTP-based consent before any verification check runs, yours or someone else's, with their own OTP.
- Withdrawing consent is as easy as giving it. You can do this from your account settings or by contacting our Grievance Officer (Section 16).
- Withdrawing consent doesn't affect processing already lawfully carried out before withdrawal.
8. How We Use and Share Your Data
- We do not sell your personal data. Ever, to anyone, for any purpose.
- With licensed verification partners and official sources, solely to perform the specific checks you've requested, under contractual data-protection obligations.
- With another user, only when you actively choose to share your certificate with them. You control this, and can revoke it anytime.
- Within multi-person plans (Vishwas, Bandhan), shared only between the specific participants on that plan, based on each person's own consent. See Section 10 for exactly how this works.
- With authorities, only where legally required, such as in response to a valid court order or law enforcement request.
- We do not share your data with third parties for their own marketing purposes.
9. Our Fetch, Verify, Certify, Discard Model
This is core to how Milne Se Pehle is built, so it's worth explaining plainly:
- Fetch: we pull the relevant record from an official or licensed source, with your consent.
- Verify: we confirm the record is accurate and current.
- Certify: we compile the verified facts into your certificate.
- Discard: once your certificate exists, we discard the original records and documents we used to verify you (e.g. the source API response, an uploaded document). The verified findings that make up your certificate are retained as your certificate and audit record, not as a separate copy of your raw source data.
Your finished certificate is view-only and cannot be downloaded. This is an intentional design choice, not a limitation: anything downloadable can be edited, faked, or regenerated using AI, which would undermine the very trust the certificate is meant to provide. You choose who can view it, and you can revoke that access at any time. If you revoke access, the other person immediately loses the ability to view it, though we can't retroactively erase anything they may have already saved or screenshotted before revocation.
10. Multi-Person Plans: How Invites and Shared Verification Work
Vishwas and Bandhan are multi-person plans, but only one person pays. Here's exactly how consent and access work when that happens:
- The person who purchases the plan invites the other people it covers (a partner, or a partner plus one parent per side).
- Invites work in one of two ways: you can enter the invitee's phone number or email so we send the invite on your behalf, in which case we collect their basic contact details solely to deliver that invite and don't use it for anything else unless they accept and give their own consent; or you can share an invite link or code with them yourself, in which case we don't collect their contact details until they use it.
- If someone doesn't accept an invite, we currently retain their contact information in case they choose to accept it later. There's no fixed expiry for unaccepted invites today.
- Each invited person verifies independently. When they log into their own dashboard to begin, that login itself is their own OTP-based consent, both to being verified and to sharing their resulting certificate with the person who invited them.
- Once both people complete verification, each can view the other's certificate, based on this mutual, individually-given consent, not on anyone else's behalf.
- Every participant owns their own data and certificate, regardless of who paid. The plan purchaser has no special control over another participant's data; each person can revoke the other's access to their own certificate at any time.
- Invited participants can exercise all the rights described in Section 15 directly, through their own dashboard or by contacting our Grievance Officer, without needing to go through the person who invited them.
11. Data Retention
All personal data we store is retained and handled in compliance with the DPDP Act, 2023's storage-limitation principle, meaning we keep data only as long as it's actually needed for the purpose it was collected for, or as required by law. In practice:
- Raw verification source data: discarded once your certificate is generated. This is not retained.
- Account and profile data: retained only for as long as necessary to provide the service, or as required by law; deleted or anonymised on verified account-closure request, subject to the points below.
- Audit and compliance logs: include the verified findings from your checks, not just metadata about when a check ran. Retained only as long as necessary to meet our grievance-redressal and legal obligations, even after the original source records or documents have been discarded, not retained indefinitely.
- Payment and invoice records: retained for up to 8 years, as required under the Companies Act, 2013 and applicable GST / tax law, regardless of account closure or refund status.
12. Data Security
- Personal data is encrypted, both in transit and at rest.
- Access to personal data is restricted through role-based access controls; only authorised personnel can access it, and only as needed.
- We follow the reasonable security safeguards required under the DPDP Act, 2023.
- We do not currently hold ISO 27001 or similar third-party security certifications. If and when we do, this policy will be updated to reflect that accurately.
13. Cookies and Tracking Technologies
Our website and app use cookies and similar technologies, including:
- Essential cookies: required for the Platform to function (e.g. keeping you logged in).
- Analytics cookies: to understand how the Platform is used, so we can improve it.
- Advertising cookies: including the Meta (Facebook / Instagram) Ads pixel, used to measure and improve our marketing campaigns.
You can control or disable cookies through your browser settings. Note that Meta and other advertising / analytics providers operate under their own separate privacy policies for how they handle data collected via their pixels and tools.
14. Children's Data
Milne Se Pehleis a marriage-verification platform intended only for adults. It is not intended for use by anyone under 18. We do not knowingly collect personal data from minors. If we become aware that we've inadvertently collected a minor's data, we will delete it promptly.
15. Your Rights as a Data Principal
- Access: request a copy of the personal data we hold about you.
- Correction: ask us to correct inaccurate or incomplete data.
- Erasure: ask us to delete your data, subject to our legal retention obligations (Section 11).
- Withdraw consent: at any time, as easily as you gave it.
- Grievance redressal: raise a complaint about how your data has been handled.
- Nominate: name a nominee who can exercise these rights on your behalf in the event of your death or incapacity.
If you were invited into a multi-person plan (Vishwas or Bandhan), you hold all of these rights independently, regardless of who purchased the plan; see Section 10.
To exercise any of these rights, contact our Grievance Officer below. We aim to acknowledge requests within 3 business days and resolve them within 30 days. If you're not satisfied with how we've handled your grievance, you may escalate it to the Data Protection Board of India (DPBI), established under the DPDP Act, 2023.
16. Grievance Officer and Contact
Name: Saurabh Joshi
Designation: Grievance Officer, Bina AI Private Limited
Email: saurabh@milnesepehle.in
For general support (non-grievance queries), you can also reach us at support@milnesepehle.in.
17. Data Breach
In the event of a personal data breach, we are committed to notifying the Data Protection Board of India and affected Data Principals without undue delay, consistent with the DPDP Act, 2023. India's breach-notification framework is being phased in through 2027; we intend to meet these obligations on or ahead of the applicable timelines, not just at the point they become mandatory.
This commitment extends to breaches at our verification partners or other processors handling data on our behalf. If we become aware that a breach at a partner has affected your data, we will notify you and the Data Protection Board under this same commitment, regardless of where the breach originated.
18. Cross-Border Data Transfer
Milne Se Pehle's verification services currently operate only within India, and the personal data used to generate your certificate is processed within India. We do not currently transfer verification data outside India, and if this changes, for example if we expand to support NRI or international verification, we will update this policy before doing so.
Separately, like the great majority of Indian businesses that run online advertising, we use third-party tools, including the Meta Ads pixel, that may process limited technical and usage data (such as device and browser information) on infrastructure located outside India, under that provider's own privacy policy and security practices. India does not currently have a general law requiring this kind of data to be stored only in India; the specific Indian data-localisation requirements that do exist apply to payment-system data and statutory accounting records, not to advertising or analytics data. This is standard, disclosed practice, and is entirely separate from the verification data used to build your certificate, which stays within India throughout.
19. Looking Ahead: Regulatory Roadmap
- Consent Manager integration: as India's Consent Manager framework becomes operational (from November 2026 onward), we intend to integrate with a registered Consent Manager so you can view and manage your consents from a single dashboard.
- Multi-language availability: this policy is currently available in English. We intend to add regional-language versions over time, in line with evolving regulatory expectations for accessibility.
20. Third-Party Links and Services
Our Platform may contain links to third-party websites or services. We don't control these, and we're not responsible for their content or privacy practices. We encourage you to review the privacy policy of any third-party site or service you visit.
21. Changes to This Policy
We may update this policy from time to time. If we make a material change, we'll notify you by email and / or a notice on the Platform before it takes effect. Where a change requires fresh consent under the DPDP Act, we'll ask for it separately, not bundle it into a general update notice.
22. Governing Law and Jurisdiction
This policy is governed by the laws of India. Courts in Uttarakhand have exclusive jurisdiction over any disputes arising from this policy, consistent with our registered office and our Terms and Conditions.
23. Contact Us
Questions about this policy, or about your data: support@milnesepehle.in, or reach our Grievance Officer directly at saurabh@milnesepehle.in.
Prepared in compliance with the Digital Personal Data Protection Act, 2023; the Information Technology Act, 2000; and other applicable Indian data protection laws. Provisions referencing DPDP Rules not yet in force (Consent Manager integration, full breach-notification infrastructure) are forward commitments and will be updated as those rules are phased in through May 2027.
Bina AI Private Limited · milnesepehle.in · support@milnesepehle.in