afterall Open the app

Privacy Policy

Your data, in plain words

Last updated: 1 October 2026

After All puts strangers around a table: small group dinners and plans in Indian cities. To do that safely we need to know a little about you. This page explains exactly what, why, who else sees it, how long we keep it and how to get it deleted.

The short version

1. Who we are

After All is run by Social Sailor Entertainment LLP, a limited liability partnership registered in India ("After All", "we", "us"). We are the Data Fiduciary for the personal data described here under India's Digital Personal Data Protection Act, 2023 (the "DPDP Act"). This policy covers the After All iPhone app, the web app at app.afterall.world and this website (afterall.world).

Questions or requests: hello@afterall.world.

2. What we collect

You give us

WhatDetails
Sign-inYour mobile number (we text you a one-time code to confirm it). If you use Sign in with Apple or Google, the email address they give us (which may be an Apple private relay address).
ProfileFirst name, last initial, what you do, birth date, gender (woman, man, non-binary or prefer not to say), home city, the languages you speak and your app language.
Personality quiz and preferencesYour quiz answers and the "social type" they produce, your conversation starters ("ask me about", "I talk too much about"), up to five comfort preferences, age-range preference, whether you want women-only groups or alcohol-free plans.
Food needsDiet, religious diet and allergies, if you tell us. Allergies can reveal health information, so only add what you want the venue to plan around.
Verification selfieOne live selfie before your first booking. See section 3.
Profile photo (optional)A photo you choose to add. See section 4.
Trusted contact (optional)The name, phone number and preferred language of someone you choose. If you turn sharing on, we text them on plan nights. Please only add someone who is happy to hear from us.
Bookings and plansThe plans you book, join the waiting list for, cancel or attend; check-ins; seat credits and promo codes; membership pauses.
After the nightYour rating and comments about a plan, and the people you would like to see again ("yes" picks). When two people both say yes, they join each other's Circle.
MessagesMessages you send to people in your Circle.
ReportsReports you make about another member (the reason, your note, whether you never want to be seated with them again) and reports made about you.
Invites and waitlistsYour referral code, who invited you, and the contact you type when you invite a friend or ask us to open your city.
SupportWhatever you write to us by email or WhatsApp.

Created when you use After All

What we do not collect

3. Your verification selfie

Every member takes one live selfie before their first booking so that everyone at the table knows the others are real people who look like their profile.

4. Your profile photo

Adding a photo is optional, and you can change or remove it at any time in Edit profile. It is stored privately, not on a public link. It can be seen only by:

Nobody you have reported can see your photo, and once a member is removed from After All their photo is hidden from everyone except our safety team. We may remove a photo that breaks our rules.

5. Why we use your data

PurposeData used
Create and secure your account; stop fake, duplicate or banned accountsPhone number, Apple or Google email, verification selfie, hashed identifiers of deleted and removed accounts
Check you are 18 or older and mix groups by ageBirth date
Build balanced groups and honour your preferences (women-only, alcohol-free, age range, language)Gender, birth date, quiz answers, preferences, languages, city
Run the plan: bookings, waiting lists, the venue reveal, reminders, cancellations, creditsBookings, device tokens, notification settings
Tell the venue what to prepareGroup size and dietary needs, without your name or contact details
Keep people safe: trusted-contact texts, check-ins, reports, warnings, removals, never seating two people together againTrusted contact, reports, safety notes, group records
Take payment and manage your membershipMembership and payment records
Answer you when you write to usSupport messages
Understand which ads and invites work, and measure the businessAttribution data, lifecycle events (see section 8), totals and trends
Send offers and news by WhatsApp, only if you opted inPhone number, first name, city
Meet legal, tax and law-enforcement obligationsWhatever the law requires

We process your data on the basis of the consent you give when you sign up and when you turn on optional features, and for the "legitimate uses" the DPDP Act allows (for example, complying with law, responding to a medical emergency or a threat to someone's safety). You can withdraw consent at any time (see section 12); some features, such as booking a seat, cannot work without the data they need.

6. What other members see

7. Who we share it with

We do not sell personal data. We share it only with the service providers below, who process it on our behalf for the purposes listed, and when the law requires.

WhoWhat forWhat they get
Supabase (on Amazon Web Services)Our database, sign-in, file storage and server functionsAll the data in this policy, stored for us
TwilioText messages: sign-in codes, trusted-contact texts, backup remindersThe phone number and the message
AppleSign in with Apple, push notifications, App Store subscriptionsPush tokens and notification text; Apple already holds your Apple ID and payment
GoogleSign in with Google; fonts on our websiteWhat Google needs to sign you in; your IP address when a page loads a font
RevenueCatKeeping track of App Store subscriptionsYour After All account ID and your App Store purchase records
RazorpayWeb payments (UPI, cards, net banking, wallets)Your name, phone number and email to pre-fill the payment page, and the amount. You enter payment details on Razorpay's page, not ours.
Meta PlatformsMeasuring ads (Conversions API) and WhatsApp messages (WhatsApp Business Platform)See sections 8 and 9
VenuesPreparing your tableGroup size and dietary needs; no names or contact details
Your trusted contactKnowing where you are on a plan nightOnly if you turn sharing on: your first name, the plan, place and time
Police, courts or regulatorsWhen the law requires it, or to protect someone in an emergencyOnly what is required

If After All is ever sold or merged, your data would move to the new owner under this policy, and we would tell you first.

8. Advertising and attribution

We advertise on Meta (Facebook and Instagram). To learn which ads bring people who actually enjoy After All, our server sends Meta's Conversions API a short record when one of these happens: you sign up, finish your profile, book, pay, renew or stop your membership.

When you open an invite or ad link, we note the tags in the link (described in section 2) once, the first time, so we can credit the friend who invited you and see which campaigns work. Our marketing team sees totals and a masked list (first name, initial, city, where you came from), never your contact details or safety records.

9. Texts, WhatsApp and notifications

10. How long we keep it

DataKept for
Your profile, preferences, trusted contact, photoWhile your account is open. Removed when you delete your account.
Verification selfie (the picture)30 days after approval or a retake request; 90 days if declined; deleted at once if you delete your account. The result is kept.
Messages, Circle, push tokens, waitlist entriesWhile your account is open. Deleted when you delete your account (for both sides of a conversation).
Attribution data and WhatsApp opt-inWhile your account is open. Wiped when you delete your account. Events already sent to Meta are held by Meta under its own terms.
Reports, never-seat-together pairs, ratings, safety notes and our staff access logKept after you delete your account, against an anonymous ID with no name or contact details, so that we can keep members safe and answer complaints.
Payment and membership recordsAs long as Indian tax and accounting law requires (generally up to 8 years), against an anonymous ID after deletion.
A keyed one-way hash of your phone number and emailKept after deletion so the same number cannot claim a second free first plan, and so removed members cannot rejoin. The hash cannot be turned back into your number.
BackupsOur hosting provider keeps rolling backups that are overwritten within 30 days.

11. Deleting your account

In the iPhone app or the web app: Profile → Delete account → Delete for good. You can also email hello@afterall.world from anywhere and we will do it for you after confirming it is you.

When you delete your account, straight away:

What we keep is listed in section 10: anonymous safety records, payment records the law requires, and the one-way hash that stops a deleted number taking another free plan.

Deleting your account does not cancel an App Store subscription. Apple bills it, so cancel it in Settings → your name → Subscriptions on your iPhone. Web memberships do not renew, so there is nothing to cancel.

12. Your rights under the DPDP Act 2023

You have the right to:

Write to hello@afterall.world. We will confirm it is you (usually by replying from the app or texting a code to your number) and respond within 30 days. If you are not satisfied with our answer, you may complain to the Data Protection Board of India.

If you live outside India, you may have similar rights under your local law. Write to us and we will honour them.

13. Security

No system is perfect. If a breach affects your data, we will tell you and the Data Protection Board of India as the law requires.

14. Age

After All is for adults. You must be at least 18 (or the age of majority where you live, if higher). We check your birth date at sign-up and do not knowingly collect data from anyone younger. If we learn that a member is under 18, we delete the account. If you think a child is using After All, write to us.

15. Where your data is stored

Our database and files are hosted by Supabase on Amazon Web Services in Mumbai, India. Some of our service providers (Apple, Google, Meta, Twilio, RevenueCat) process data in other countries, including the United States, under their own safeguards. We transfer data outside India only as the DPDP Act allows.

16. This website and the web app

The web app stores your sign-in session and small settings (like light or dark theme) in your browser's local storage so you stay signed in. We do not use advertising or analytics cookies on this website. Pages load fonts from Google Fonts, which receives your IP address. Payments open on Razorpay's own page, under Razorpay's privacy policy.

17. Changes to this policy

If we change this policy in a way that matters, we will tell you in the app before the change takes effect and, where the law needs it, ask for your consent again. The date at the top always shows the latest version.

18. Contact and grievances

Social Sailor Entertainment LLP (After All)
Registered office: Shop No. 6, 2nd floor, Hebbal Kempapura, Bengaluru, Karnataka 560024, India
Email: hello@afterall.world

Grievance Officer: Ismail (Founder), hello@afterall.world
We acknowledge grievances within 48 hours and resolve them within 30 days.