tugethr

Privacy Policy

Last updated: 12 September 2026

This policy explains how Rahul Baghel, sole proprietor, trading as Tugethr ("Tugethr", "we", "us", "our"), with its principal place of business at B-59A, Rajat Vihar, Sector 62, Noida, Uttar Pradesh 201309, India, collects and handles your personal data when you use the Tugethr mobile application, the Tugethr website and the Tugethr merchant portal (together, the "Platform").

Tugethr is a sports community app. It helps adults find players, organise matches, join crews, book venues and message each other. Handling your data carefully matters more here than in most apps, because the Platform knows where you are, who you play with and what you say to them.

Under India's Digital Personal Data Protection Act, 2023 ("DPDP Act") you are the Data Principal and we are the Data Fiduciary for your personal data. We also follow the Information Technology Act, 2000 and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 ("SPDI Rules").

Four things worth knowing up front. Your chat messages are encrypted in transit and at rest, but we hold the key that unwraps your chat key, so message content can be accessed for safety and legal reasons (section 4). A nightly encrypted backup of your own chat history is uploaded to our servers, and it is on by default (section 4.1). Your precise location is stored on our servers so that discovery works, but other users are only ever shown a distance rounded to the nearest 100 metres and your city (section 5). AI help inside chat is off by default, and switching it on sends recent decrypted messages to a third-party AI provider (section 6).

1. The data we collect

1.1 Data you give us

1.2 Data your device sends us

1.3 Data generated by your use of the Platform

1.4 What we do not collect

2. Why we use your data, and our legal basis

Under the DPDP Act we process your personal data on the basis of the consent you give when you create an account and when you grant a permission such as location or notifications, and for certain legitimate uses permitted by the Act, such as complying with a legal obligation. Payment details, passwords and financial information are treated as sensitive personal data under the SPDI Rules.

We do not use your personal data to make any decision that produces a legal effect on you without a human being involved.

3. What other users can see

4. Encrypted chat and calls

Messages and chat media are encrypted on the sending device, encrypted in transit, and stored encrypted on our servers. The keys are managed by us (section 4.3), so we are technically able to decrypt message content. We access it to investigate a report, to deal with abuse or fraud, and where the law requires it.

4.1 Your chat backup

Your phone, not our server, is the permanent home of your chat history, so losing the phone would lose the history. To prevent that, the app makes an encrypted backup of your own messages and uploads it to us.

4.2 Message metadata

Delivering a message requires us to know where to send it. We hold, in readable form:

4.3 Your account key

Your account identity key is what unlocks your message history on a device. It is held on our servers in wrapped form and released to devices signed in to your account, so signing in on a new device restores your history. Because we hold the wrapping key, we can unwrap your account key, and any backup encrypted with it. A backup passphrase you set yourself is separate: we do not hold it, and if you lose it we cannot reset or recover it.

4.4 Push notifications for messages

When a message arrives while your app is closed, we send a push through Firebase Cloud Messaging. The visible text of that push is only the sender's name and the words "New message". For short text messages we also attach the encrypted copy addressed to your own device, and your device decrypts it locally to replace the notification with a preview. This means Google receives the sender's display name, the conversation and message identifiers and the encrypted payload, which Google cannot read. Longer messages and media stay as "New message".

4.5 The limits of encryption

5. Location data

6. AI features

Some features use artificial intelligence. To provide them we send the relevant input from our servers to a third-party AI model provider over an encrypted connection. The text provider is selected in our admin console from a small registry and can be changed without a release; today it is Microsoft Azure AI Foundry, and the registry also supports OpenAI and Anthropic. Image generation, image editing and speech-to-text run on Azure AI Foundry in every configuration.

6.1 What is sent, feature by feature

6.2 Your control over AI in chat

6.3 How AI data is handled

7. Payments

8. Communications and notifications

9. Cookies, storage and identifiers

10. Who we share your data with

We do not sell your personal data. We share it only as set out below.

10.1 Other users

As described in section 3, and with anyone you choose to message.

10.2 Service providers who process data on our behalf

This is the complete list. There are no others.

These providers may only use your data to provide their service to us, under contract.

10.3 Venue partners

When you book a slot, we share the booking details and the contact details needed for the venue to honour it.

10.4 Legal and corporate

10.5 Sponsored content

If we show sponsored or featured placements, we select them ourselves using signals such as your city, sport, age range and gender. We do not use third-party advertising networks, we do not track you across other apps or websites, and we do not send your personal data to advertisers.

11. How long we keep your data, and account deletion

11.1 While your account is open

11.2 Taking a break instead

Settings → Deactivate account hides your profile, matches and crews from everyone without deleting anything. Signing in again restores the account exactly as it was. If you are unsure, this is the reversible option.

11.3 When you delete your account

There are three ways to delete, and they do not behave the same way:

Full details of each route are on the delete your account page.

We permanently delete:

We anonymise your account record itself: your email, phone number, username, password, name, bio, date of birth, gender, addresses and device identifiers are erased and the account is marked as deleted. We keep the empty record so that financial and moderation references do not break.

We keep:

Chat data lives in a different service from your account, so the purge makes a second, separate call to erase it. If that call fails it is retried by hand rather than skipped. If you want us to confirm what remains after your deletion, or to remove something specific, contact the Grievance Officer in section 15.

An active paid plan ends when you delete and is not refunded. Cancel it first if you want the unused part of the term back (see the Terms of Service, section 11.3).

12. Security

13. Transfers outside India

The Platform itself runs in Mumbai. Your profile, your location, your messages, your bookings and your payment records all sit on servers in Google Cloud's asia-south1 region. The geospatial index used for nearby search runs on MongoDB Atlas and holds your account number, your coordinates and their accuracy, your city, state and country, whether you are online and when you were last active. Nothing else.

Six of the providers in section 10 process data outside India: Microsoft Azure AI Foundry for AI features, Firebase Cloud Messaging for push, Twilio for SMS one-time passwords, Brevo for email, and Mapbox and Giphy, which your device contacts directly. Where data is transferred outside India we do so under contractual protections and in accordance with the DPDP Act and any restrictions notified by the Central Government.

14. Your rights

Subject to the DPDP Act and the SPDI Rules, you can:

To exercise a right, write to support@tugethr.com or to the Grievance Officer in section 15 from the email address or phone number registered to your account. We may ask you to verify your identity. We will respond within the time allowed by law, and normally within 30 days.

15. Grievance redressal

If you have a question, a complaint, or a request about your personal data, contact our Grievance Officer, appointed under the Information Technology Act, 2000, the rules made under it, and the DPDP Act:

We will acknowledge your complaint within 24 hours and resolve it within 15 days of receipt. If you are not satisfied with our response, you may escalate to the Data Protection Board of India.

16. Children

Tugethr is for adults aged 18 and over. We do not knowingly collect personal data from anyone under 18, and we do not offer a version of the Platform for children. If you believe a person under 18 has created an account, tell us at support@tugethr.com or through the Grievance Officer and we will suspend the account and delete the data.

17. Changes to this policy

We may update this policy as the Platform changes or as the law changes. We will revise the "Last updated" date above, and for material changes we will notify you in the app or by email before the change takes effect.

18. Contact us

Rahul Baghel, sole proprietor, trading as Tugethr, B-59A, Rajat Vihar, Sector 62, Noida, Uttar Pradesh 201309, India.
General enquiries and data requests: support@tugethr.com.

Terms of Service  ·  Delete your account