2U

Privacy Policy

Last updated 11 September 2026 · 2U is operated by Growthpond Technology Private Limited, Bengaluru, India.

2U is a dating app whose deck is your own phone contacts. This policy describes exactly what reaches our servers, what never does, and what you can have deleted. It describes the software as it is actually built, not as it would be convenient to describe.

What never leaves your device

Your address book. The deck is assembled on your phone or Mac from your local contacts. The names, phone numbers, photos and notes of people in your contacts are read on the device and are not uploaded.

What the server receives instead is HMAC-SHA256(secret, phone number) — a one-way code of each number. It cannot be reversed into a phone number, and the app resolves a code back to a person locally, from your own address book.

What we do store

DataWhy
Your own phone number, in full It is your account identifier and the address we send your login code and notifications to. It is stored in readable form, not as a code.
Your profile: name, bio, one photo, gender, who you are looking for, age Shown to people who already have your number saved and swipe you.
Codes of the people you swipe, and which way you swiped To create matches and to stop showing you the same card.
MatchesSo both sides can see them.
Login codesDeleted the moment they are used, and expire in ten minutes.
A record that a number was messaged, and what each message cost So one person is not invited twice and so we can see what the service costs to run.
Payment records from Razorpay To credit swipes you have bought. Card details never reach us.
Usage events — screens opened, swipes made, errors To find where the app is broken. Keyed to your account code.

A correction worth stating plainly. Some of our own in-app copy has said "we store a code, never a number". That is true of everyone in your address book. It is not true of your own number, which we store in full because we have to be able to message you. We are fixing that wording rather than leaving it overstated here.

Contacts you bring in from Google

If you choose "Use my Google contacts" in the browser, we read your Google contacts once, with your consent, using the contacts.readonly scope. We use them for one purpose: to build your deck. The list is held on our server only until your browser collects it, and is deleted as it is handed over. We do not keep a copy, do not use it to target advertising, and do not sell or transfer it. You can revoke access at any time at myaccount.google.com/permissions.

Google user data is handled in line with the Google API Services User Data Policy, including its Limited Use requirements.

Contacts you sync from the app

To use 2U in a browser, the phone or Mac app can publish an encrypted copy of your deck. It is encrypted on your device with a key derived from a pairing code that is shown only on your screen and never sent to us. We hold ciphertext we cannot read.

Messages we send

We send WhatsApp messages through AiSensy on the official WhatsApp Business Platform: your login code, an anonymous nudge when someone swipes you, and match notifications. A nudge never names the person who swiped you. Your number is shared with that provider only to deliver the message.

Who else sees anything

No advertising networks, no data brokers, no sale of personal data — ever. We use Razorpay for payments, AiSensy for WhatsApp delivery, Google for the optional contacts import, and Hostinger for hosting. Each receives only what it needs to perform that function.

How long we keep it

Your account and profile until you delete it. Login codes for ten minutes. Imported Google contacts until your browser collects them, then not at all. Usage events for up to twelve months. Payment records for as long as Indian tax law requires.

Your choices

Children

2U is for adults. You must be 18 or older. The apps filter anyone recorded as under 18 out of your deck, and we delete accounts we learn belong to minors.

Security

Everything travels over TLS. Contact codes are keyed with a secret that is not in our source code. Vault contents are end-to-end encrypted. No system is perfect, and we will tell you if something happens that affects you.

Changes

If this policy changes in a way that matters, we will say so in the app rather than quietly editing this page.

Contact

Growthpond Technology Private Limited, Bengaluru, Karnataka, India · hello@2uapp.site