Legal
Privacy Policy
The Rajma Company Inc. | Effective August 28, 2026
The Rajma Company Inc. — Oku
1. About This Policy
The Rajma Company Inc. (“Rajma,” “we,” “us,” or “our”), incorporated under the Canada Business Corporations Act, R.S.C. 1985, c. C-44, with its registered office at 2712-20 Bruyeres Mews, Toronto, Ontario, M5V 0G8, Canada, is the organization accountable for personal information collected through the meetoku.app website (the “Site”) and the Oku mobile application (the “App,” and together with the Site, the “Services”).
This Privacy Policy applies to all personal information we collect through the Services, whether you are joining the pre-launch waitlist or using the App after launch. No separate amendment is required when the App launches. This Policy is issued under the Personal Information Protection and Electronic Documents Act, S.C. 2000, c. 5 (“PIPEDA”), and applicable United States privacy laws.
Separate documents govern cookies and terms of use. This Policy cross-references but does not incorporate the Cookie Policy or the Terms of Service. Please read all three documents.
2. Information We Collect
2.1 Waitlist (Site)
When you join the pre-launch waitlist, we collect:
your name and email address;
your IP address;
device and browser data (device type, operating system, browser type and version, screen resolution); and
analytics data generated by your interaction with the Site (pages visited, referral source, session duration).
2.2 App
When you use the App, we collect, in addition to the categories above:
Account and profile data: name, date of birth, gender, location (city/region), profile preferences, and any other information you provide;
Voice recordings and transcripts: audio captured during guided voice conversations and automated transcriptions of those recordings;
Biometric verification data: a biometric identifier generated by our liveness-check provider for identity verification purposes;
Derived personality and preference data: personality trait scores, attachment style, communication style, preferences, and dealbreakers inferred by automated systems from your voice recordings and transcripts;
Subscription data: subscription tier, purchase date, and renewal status; we do not receive your payment card details, which are processed directly by Apple App Store or Google Play Store;
Device identifiers: advertising identifier (IDFA/GAID), device ID, and push notification token; and
Usage data: in-app actions, feature interactions, session timestamps, and crash reports.
3. Voice and Biometric Data
3.1 What We Collect and Why
During guided voice conversations in the App, we collect:
Voice recordings — audio files of your spoken responses;
Transcripts — automated text transcriptions of those recordings; and
Biometric verification data — a biometric identifier generated from a liveness check performed by didit.me to verify that you are a real, live person.
We use this data for the following purposes:
to generate your Oku profile, including personality trait scores, attachment style, communication style, preferences, and dealbreakers;
to produce compatibility scores between you and other users;
to verify your identity and prevent fraud; and
to maintain the safety and integrity of the Services.
3.2 Express Standalone Consent — Required Before Any Recording
Before your first voice session, the App will present a modal dialog that:
identifies what is being collected (voice recording, transcript, and biometric identifier);
states why it is being collected (profile generation, compatibility scoring, and identity verification);
states that raw audio is deleted within 30 days of profile extraction;
states that biometric data is not sold, leased, traded, or otherwise disclosed for anything of value;
links to this Section 3 in full; and
requires you to tap “I Agree” before any recording or biometric capture begins.
Declining means the core service cannot be provided. This consent is separate from and not bundled into your acceptance of the Terms of Service. We maintain a timestamped record of your consent.
This consent mechanism is designed to satisfy the requirements of the New York City Biometric Identifier Information Law (N.Y.C. Admin. Code § 22-1201 et seq.), the California Consumer Privacy Act as amended by the California Privacy Rights Act (Cal. Civ. Code § 1798.100 et seq.) (“CCPA/CPRA”), and analogous state biometric and sensitive personal information statutes.
3.3 No Sale or Profit from Biometric Data
We do not sell, lease, trade, or otherwise disclose your biometric data in exchange for anything of value (N.Y.C. Admin. Code § 22-1202(b)).
3.4 No Sharing of Voice Clips with Other Users
Voice recordings and clips are processed by automated systems and our AI service providers only. Voice clips are not shared with other users.
3.5 No AI Model Training
Voice recordings, transcripts, and derived personality and preference data are never used to train, fine-tune, or otherwise improve any artificial intelligence or machine-learning model, whether operated by us or any third party. This is a firm commitment.
3.6 Retention of Raw Audio
Raw audio recordings are deleted within 30 days of profile extraction. Transcripts and derived data are retained for the life of your account. See Section 10 for the full retention schedule.
3.7 Certification of Destruction
Upon written request submitted through the in-app portal or to info@meetoku.app, we will provide written certification that your biometric data and raw audio have been deleted.
3.8 Sensitive Personal Information
Voice recordings and biometric data are sensitive personal information under the CCPA/CPRA (Cal. Civ. Code § 1798.100 et seq.), the NY SHIELD Act (N.Y. Gen. Bus. Law § 899-aa et seq.), and analogous state laws. We limit our use of this data to the purposes stated in Section 3.1.
3.9 California Voice Recording Notice
If you are a California resident, you are notified that your voice is being recorded during guided voice conversations, as required by the California Invasion of Privacy Act (Cal. Penal Code § 630 et seq.). Your use of the voice feature constitutes your consent to such recording.
4. How We Use Information
We use personal information for the following purposes:
Service provision: to operate the Services, authenticate your account, and deliver features you request;
Profile generation: to create your Oku profile from voice recordings, transcripts, and derived data;
Compatibility scoring: to generate algorithmic compatibility scores between you and other users; compatibility scores reflect patterns in your responses and preferences — they are not predictions of relationship outcomes;
Verification and fraud prevention: to verify your identity using biometric liveness check and to detect and prevent fraudulent or abusive activity;
Safety and moderation: to enforce our Terms of Service and protect users;
Customer support: to respond to your inquiries and resolve issues;
Subscription administration: to manage your subscription, process renewals, and communicate billing matters;
Product improvement: to analyze aggregate usage patterns and improve the Services — not by training AI models on your personal data (see Section 3.5);
Legal compliance: to comply with applicable law, respond to lawful requests, and enforce our rights.
4.1 Automated Processing Disclosure
Matching on Oku is fully algorithmic. Your voice recordings and transcripts are analyzed by automated systems — including AI models operated by Google Gemini and Anthropic — to generate your profile and compatibility scores. No human matchmaker reviews your conversations in the ordinary course. If you have a concern about a match result, you may submit feedback or flag the concern through in-app support. We do not commit to a formal human review of individual match decisions.
5. Third-Party Processors and Disclosure
5.1 Named Processors
We share personal information with the following service providers, who process it on our behalf:
ElevenLabs — voice processing, transcription, and AI-powered conversational analysis (ElevenLabs’ agent platform uses third-party language models, including Google Gemini and Anthropic Claude, as sub-processors for this purpose).
Amazon Web Services (AWS) — cloud hosting and storage;
didit.me — biometric liveness verification;
Google Gemini — AI-powered profile and compatibility analysis;
Anthropic — AI-powered profile and compatibility analysis;
Expo — mobile app infrastructure and over-the-air updates;
Branch.io — deep linking and mobile attribution.
5.2 Analytics and Attribution Providers
We use the following analytics and attribution tools on the Site and in the App:
Google Analytics;
Meta Pixel;
Reddit Pixel;
AppLovin; and
Branch.io.
These tools collect data as described in our Cookie Policy.
5.3 App Stores and Payment Processors
Subscriptions are processed by Apple App Store and Google Play Store. We receive confirmation of purchase status but not your payment card details.
5.4 Disclosure to Other Users
Voice clips are not shared with other users. Derived profile information (such as personality traits and preferences) may be displayed to potential matches as part of the compatibility experience, to the extent you have configured your profile to permit such display.
5.5 Legal Disclosure
We may disclose personal information if required by law, court order, or lawful government request, or where we believe disclosure is necessary to protect the rights, property, or safety of Rajma, our users, or the public.
5.6 No Sale of Personal Information
We do not sell personal information (Cal. Civ. Code § 1798.100 et seq.; N.Y.C. Admin. Code § 22-1202(b)). We do not conduct targeted or behavioural advertising. The “Do Not Sell or Share My Personal Information” right under the CCPA/CPRA is preserved; because we do not sell or share personal information for cross-context behavioural advertising, no opt-out mechanism is currently required, but you may contact us to confirm our practices.
5.7 Processor Obligations
All processors are bound by data processing agreements requiring them to process personal information only on our instructions, maintain appropriate security, and not use personal information for their own purposes. We remain accountable for personal information transferred to processors (PIPEDA, S.C. 2000, c. 5, Principle 1).
5.8 FTC Act
Our privacy representations are enforceable commitments under the Federal Trade Commission Act, 15 U.S.C. § 45.
6. Cross-Border Data Transfers
Personal information collected from Canadian residents is transferred to and processed in the United States by the processors named in Section 5. Once transferred, that information is subject to the laws of the United States, including lawful access by US government authorities. We require contractual protections from all processors, but we cannot guarantee that US law will afford the same level of protection as Canadian law. By using the Services, you acknowledge this transfer and the associated risks, as required by PIPEDA, S.C. 2000, c. 5.
7. Marketing Communications — CASL and CAN-SPAM
7.1 CASL Implied Consent
By joining the Oku waitlist, you provide implied consent under the Canada’s Anti-Spam Legislation, S.C. 2010, c. 23, s. 6, to receive commercial electronic messages about Oku from The Rajma Company Inc. This implied consent is valid for up to two years from the date you joined the waitlist, unless you withdraw consent earlier.
7.2 Sender Identification
Every commercial electronic message we send will identify the sender as:
The Rajma Company Inc.
2712-20 Bruyeres Mews, Toronto, Ontario, M5V 0G8, Canada
7.3 Unsubscribe
Every commercial electronic message will include a functional unsubscribe mechanism. Unsubscribe requests will be honoured within 10 business days of receipt. After you unsubscribe, we will not send further commercial electronic messages unless you provide fresh consent.
7.4 CAN-SPAM
For recipients in the United States, our commercial emails comply with the CAN-SPAM Act, 15 U.S.C. § 7701 et seq.: each email identifies us as the sender, includes our physical postal address, and contains a clear opt-out mechanism honoured within 10 business days.
8. Cookies and Tracking
We use cookies and similar tracking technologies on the Site and in the App. Tracking technologies fall into three categories:
Necessary: required for the Site and App to function;
Analytics: used to understand how users interact with the Services (Google Analytics, Reddit Pixel, Branch.io); and
Attribution: used to measure the effectiveness of our marketing campaigns (Meta Pixel, AppLovin, Branch.io).
We do not use cookies or tracking technologies for targeted or behavioural advertising directed at our users.
For full details on the technologies we use, the data they collect, and how to manage your preferences, please read our Cookie Policy, available at meetoku.app.
9. Retention, Deletion, and Certification of Destruction
9.1 Retention Schedule
Raw audio recordings are deleted within 30 days of profile extraction from those recordings.
Transcripts and derived personality and preference data are retained for the life of your account and deleted within 30 days of account closure.
Account and profile data are deleted within 30 days of account closure.
Biometric verification data is deleted within 30 days of the completion of the verification process for which it was collected.
Subscription and transaction records are retained for 30 days following account closure, subject to any mandatory legal retention period imposed by applicable law.
Waitlist data is deleted within 30 days of account closure or, if you never create an account, within 30 days of the expiry of the inactivity period described in Section 9.3.
9.2 Legal Holds
No retention period beyond the 30-day windows above is currently required by applicable law. If a legal hold arises, we will retain only the data subject to that hold and delete it promptly when the hold is lifted.
9.3 Inactivity
If your account or waitlist registration has been inactive for 12 consecutive months, we will send an email to your registered address notifying you that your account and all associated data will be deleted in 30 days unless you log in or confirm that you wish to remain. If we receive no response within that 30-day period, we will delete all personal information associated with your account.
9.4 In-App Deletion
You may request deletion of your account and personal information at any time through the in-app settings portal. Deletion requests submitted through the portal are processed within 30 days.
9.5 Backups
Personal information may persist in encrypted backup systems for a brief period after deletion from live systems. Such data is purged at the next scheduled backup cycle and is not accessible or used during that period.
9.6 De-Identified Data
Data that has been de-identified such that it cannot reasonably be used to identify you is not subject to deletion obligations and may be retained for product improvement purposes.
9.7 Certification of Destruction
Upon written request, we will provide written certification that your biometric data and raw audio recordings have been deleted. Requests may be submitted through the in-app portal or to info@meetoku.app.
10. Your Privacy Rights
10A. Canadian Users — PIPEDA
Under PIPEDA, S.C. 2000, c. 5, you have the right to:
Access — request confirmation of whether we hold personal information about you and obtain a copy of that information;
Correction — request correction of inaccurate or incomplete personal information;
Withdrawal of consent — withdraw consent to our collection, use, or disclosure of your personal information at any time, subject to legal or contractual restrictions; and
Complaint — file a complaint with the Office of the Privacy Commissioner of Canada (www.priv.gc.ca) if you believe we have not handled your personal information in accordance with PIPEDA.
We will respond to access and correction requests within 30 days of receipt. Where we require additional time, we will notify you within the initial 30-day period and may extend the response period by up to 60 days.
10B. US Users
California (CCPA/CPRA — Cal. Civ. Code § 1798.100 et seq.)
California residents have the right to:
Know/Access — request disclosure of the categories and specific pieces of personal information we have collected about you, the sources, the purposes, and the third parties with whom we have shared it;
Deletion — request deletion of personal information we hold about you, subject to exceptions;
Correction — request correction of inaccurate personal information;
Portability — receive a copy of your personal information in a portable format;
Opt-out of sale or sharing — we do not sell or share personal information for cross-context behavioural advertising; this right is preserved but currently inapplicable;
Limit use of sensitive personal information — request that we limit our use of sensitive personal information (including voice recordings and biometric data) to the purposes permitted by the CCPA/CPRA; we already limit such use to the purposes stated in Section 3.1; and
Non-discrimination — we will not discriminate against you for exercising any of these rights.
California residents may also exercise rights under Cal. Code Regs. tit. 11, §§ 7000–7304 regarding automated decision-making. See Section 4.1.
New York
New York residents have rights under the NY SHIELD Act (N.Y. Gen. Bus. Law § 899-aa et seq.) with respect to the security of their personal information, including biometric data. New York residents may also assert rights under N.Y. Gen. Bus. Law § 349 against deceptive acts or practices. If you believe we have violated your rights, you may file a complaint with the New York Attorney General.
Other US States (Texas, Virginia, Colorado, Connecticut)
Residents of Texas (Tex. Bus. & Com. Code § 541.001 et seq.), Virginia (Va. Code Ann. § 59.1-575 et seq.), Colorado (C.R.S. § 6-1-1301 et seq.), and Connecticut (Conn. Gen. Stat. § 42-515 et seq.) may have rights to access, correct, delete, and obtain a portable copy of their personal information, and to opt out of certain processing, under those states’ respective privacy laws. Voice recordings and biometric data are sensitive personal information under each of these frameworks and are processed only with your express consent. These state laws apply subject to applicable thresholds and exemptions; we will honour verified requests from residents of these states to the extent required by applicable law.
10C. Verification and Response Timelines
Rights requests may be submitted through the authenticated in-app portal. Because you are already logged in, no additional identity verification is required beyond your existing login credentials. Requests may also be submitted by email to info@meetoku.app, in which case we will verify your identity by confirming information associated with your account before acting on the request.
We will respond to US rights requests within 45 days of receipt. Where we require additional time, we will notify you within the initial 45-day period and may extend the response period by up to an additional 45 days. We will respond to Canadian rights requests within 30 days, extendable by up to 60 days with notice.
10D. Appeal Process (US Users)
If we deny or partially deny your rights request, we will provide a written explanation of the reasons within 45 days of the denial. You may appeal the denial by emailing info@meetoku.app with the subject line “Privacy Rights Appeal.” The Privacy Officer will respond to your appeal within 60 days of receipt. If your appeal is denied, we will inform you of your right to file a complaint with the Attorney General of your state of residence.
11. Security and Breach Notification
We implement the following security measures:
encryption of personal information in transit using TLS and at rest using AES-256 or equivalent;
access controls limiting access to personal information to personnel and processors who require it for the purposes described in this Policy; and
regular review of security practices.
No security measure is infallible. If we confirm a breach of security safeguards that poses a real risk of significant harm to you, we will:
notify you by email to your registered address within 30 days of confirming the breach;
report the breach to the Office of the Privacy Commissioner of Canada within the timeframe required by the Breach of Security Safeguards Regulations, SOR/2018-64; and
report the breach to applicable US regulators, including the New York Attorney General (N.Y. Gen. Bus. Law § 899-aa et seq.; N.Y. Gen. Bus. Law § 899-bb) and other state and federal regulators, within the timeframes required by applicable law.
We maintain an internal record of all security breaches.
12. Children
The Services are intended for users who are 18 years of age or older. We require users to provide their date of birth at signup and do not permit registration by anyone under 18. We do not knowingly collect personal information from anyone under 18. If we learn that we have collected personal information from a minor, we will delete it promptly. The Services are not directed to children under 13, and we do not knowingly collect personal information from children under 13 in violation of the Children’s Online Privacy Protection Act, 15 U.S.C. § 6501 et seq.
13. Business Transfers
If Rajma is involved in a merger, acquisition, asset sale, or similar transaction, personal information — including voice recordings and biometric data — may be transferred to the successor entity as part of that transaction. Any successor will be bound by this Privacy Policy with respect to personal information transferred. We will notify you by email and by posting a notice on the Site at least 14 days before any material change in how your personal information is handled as a result of such a transaction. Any change in the collection, use, or disclosure of biometric or sensitive personal information resulting from a business transfer will require your express renewed opt-in consent before taking effect.
14. Changes to This Policy
We will notify you of material changes to this Policy by email to your registered address and by posting the updated Policy to meetoku.app at least 14 days before the changes take effect. The effective date at the top of this Policy will be updated. Your continued use of the Services after the effective date of a material change constitutes your acceptance of the updated Policy, except that any change to how we collect, use, or disclose your biometric or sensitive personal information requires your express renewed opt-in consent before taking effect — continued use alone is not sufficient. Prior versions of this Policy are available on request.
15. Contact and Complaints
Privacy Officer
The Rajma Company Inc.
2712-20 Bruyeres Mews
Toronto, Ontario, M5V 0G8
Canada
Email: info@meetoku.app
Canada: If you are not satisfied with our response to a privacy concern, you may file a complaint with the Office of the Privacy Commissioner of Canada at www.priv.gc.ca.
United States: If you are not satisfied with our response, you may file a complaint with the California Privacy Protection Agency (cppa.ca.gov), the New York Attorney General (ag.ny.gov), the Federal Trade Commission (ftc.gov), or the Attorney General of your state of residence, as applicable.
© 2026 The Rajma Company Inc. All rights reserved.
Questions: legal@meetoku.app