Back to Home

Aphelion Pvt. Ltd.

Privacy Policy

Effective Date: May 24, 2026

1. Introduction and Scope

Aphelion Pvt. Ltd. (referred to as "Aphelion," "we," "our," or "us"), a private limited company incorporated under the laws of India with its registered office in Hyderabad, Telangana, India, operates the Maleu mobile application and associated web services at maleu.online and aphelion.life (collectively, the "Platform").

This Privacy Policy explains how we collect, use, store, process, and safeguard your personal data. It has been prepared in strict compliance with the Digital Personal Data Protection Act, 2023 ("DPDPA"), the Information Technology Act, 2000 ("IT Act"), and the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021 ("IT Rules 2021"). By creating an account or using the Platform, you provide your specific, informed, and unconditional consent to the collection and processing of your personal data as described herein.

2. Age Limit and Account Creation

Maleu is exclusively intended for individuals who are 18 years of age or older. We do not knowingly collect or process personal data from minors. During registration, you must self-declare your age. If we discover that we have inadvertently collected data from anyone under the age of 18, we will immediately and permanently delete all associated data and terminate the account without delay.

Registration is permitted via email and password, mobile phone number with OTP verification, or social authentication (Google Sign-In or Sign in with Apple). Providing real names is preferred and encouraged, though display names remain optional.

3. Information We Collect

We collect and process the following categories of information to provide the Platform services and to match our App Store privacy and Google Play Data Safety disclosures:

  • Account and Profile Data: Email address, user id, username/handle, display name, profile biography, profile avatar, cover image, authentication records, and account settings.
  • User Content: Posts, chat messages, comments, reactions, reports, saved items, circles, Bloom Rays and notes, Wrex activity content, Poses photos, Poses guidance metadata, and other content you create, send, save, report, or upload.
  • Photos, Videos, Audio, and Files: Camera captures, photo library uploads, profile/circle/post/chat/Poses media, video attachments, voice or video audio where enabled, thumbnails, and related media metadata. User-uploaded media is stored in Cloudflare R2; media files are not stored in Supabase Storage.
  • Location and Fitness Information: If you start a Wrex run or walk, we process precise location coordinates, route points, distance, pace, speed, elevation, and related activity metrics for that active tracking session. Wrex can continue collecting location in the background, when your phone is locked, or when the app is closed or not in use, only until you pause, save, or discard the run or walk. If you choose to share a location in chat, we process that one-time location for the message you send. We do not use location data for ads.
  • Fitness and Wellness Data: Workouts, workout sets, previous set history, personal records, run/walk metrics, route summaries, diet and meal logs, hydration logs, progress, streaks, and Wrex settings.
  • Notification Data: Expo/Firebase/APNs push tokens, notification preferences, notification records, delivery logs, read state, and notification metadata used to deliver account, chat, guest session, circle, Bloom, Wrex, safety, and moderation updates.
  • AI-Related Poses Data: Poses uploaded image input, generated suggestion title/text, model provider/model id, generation proof id, safety/error status, usage quota records, and report records for AI suggestions. We do not claim AI generation when the configured model does not return a verified result.
  • Diagnostics and Security Data: Supabase authentication/session records, IP-derived security context, device characteristics (operating system version, device model, app version), abuse-prevention counters, admin audit logs, technical errors, API failures, upload errors, and app crash diagnostics where applicable.

4. Specialized Feature Data Handling

4.1 The Poses Feature

The Poses feature can provide AI-assisted photography guidance when you request it. The captured or selected image is sent through our Cloudflare Worker to Cloudflare Workers AI for image analysis, and the resulting guidance, model metadata, and daily usage record are stored only when needed to deliver the feature and enforce quotas. Saved Poses photos are stored in Cloudflare R2 with access controlled by the app backend. We do not collect, process, or store facial biometric templates or identity verification geometry maps.

4.2 Message Privacy and Servers

Direct messages and group chat contents are stored on our servers (Supabase infrastructure). Messages are encrypted in transit and access-controlled via Supabase Row-Level Security, but they are not end-to-end encrypted. We only access message content under valid legal requirements or in-app reports of abuse. In-app chat locks (PIN or biometrics) operate purely at the device level.

4.3 Blocked and Muted Accounts

When you block a user, all visibility between your accounts is permanently hidden. This block hides past, present, and future posts, profiles, and messages, preventing any form of mutual interaction unless explicitly unblocked.

5. How We Use and Share Information

Your personal data is used to provide the social, chat, AI photography, learning, and fitness tracking services, authenticate sessions, process handshakes, deliver push notifications, enforce safety controls, and maintain security. We do not send marketing, promotional, or advertising emails or notifications.

We do not sell, rent, or trade your personal data. Data is shared only with trusted infrastructure providers acting as data processors strictly under our instructions:

  • Supabase Inc. (USA) - for secure database hosting, user management, and authentication.
  • Cloudflare Inc. (Global) - for CDN optimization, secure media storage (R2), Workers backend functions, and Workers AI processing for Poses guidance.
  • Google LLC (Firebase) (USA) and Apple Push Notification service - for push notification delivery.
  • Resend Inc. (USA) - for sending transactional account emails (e.g., OTPs and password resets).

6. Data Deletion and Portability

You have the right to erase, correct, or update your personal data. You can delete your account permanently directly within the app at the following path:

Profile Page -> Settings -> Delete Account

Account deletion is permanent once confirmed in the app. Your authentication account, profile, posts, messages, saved items, fitness data, Poses records, and related active database rows are removed immediately, and owned media objects are queued for backend deletion from active Cloudflare R2 storage. This self-service deletion cannot be cancelled by logging back in. Data exports are not offered via self-service currently but are planned for the future; until then, you may contact our Grievance Officer before deleting your account.

7. Grievance Officer and Redressal

In accordance with the Information Technology Act, 2000 and Rules made thereunder, and the DPDPA 2023, the name and contact details of our designated Grievance Officer are published below:

Dharantej Reddy Poduvu

Title: Grievance Officer & Intermediary Compliance lead

Company: Aphelion Pvt. Ltd.

Address: Hyderabad, Telangana, India

Email: fuy.aphelion@gmail.com

Grievance emails will be acknowledged within 24 hours of receipt, and resolved systematically within 15 working days as required under Indian Intermediary Guidelines.

Terms of ServiceHome

© 2026 Aphelion Pvt. Ltd. All rights reserved.