the how & the why
How this stays your secret.
The short version: your picks are scrambled on your own phone with a key that never leaves it. An unreturned crush is something no one can uncover, including us.
You pick, in secret
Log in with your @iith.ac.in email — that is also how we know you’re a real IITH student, and it doubles as your roll number. Pick up to three people, ranked, each with an optional note that’s only ever revealed on a mutual match.
Your phone does the sealing
When you pick someone, your browser mixes your private key with their public key into a shared secret, and turns it into a scrambled code. If they pick you back, their phone lands on the exact same code. Only the code, a rank, and your encrypted note leave your device. Your picks themselves never do.
A match is two matching codes
Two identical codes mean two people chose each other. A one-sided pick is a code no one can trace back or reverse — not other students, not the database, not us. That’s the whole point, and it’s a property of the math, not a promise we’re asking you to trust.
Even you can't reopen it
Once you seal your picks, they’re gone from view — your own device keeps only meaningless codes, never names. So nobody can ever pressure you into showing your list, because there’s nothing to show.
Everyone finds out at once
At 12:01 am on reveal night, results go live for everyone together. A match unseals the other person’s note and name. No match? A soft landing, never a cold rejection. It never tells anyone what number you ranked them.
The honest limits
Anyone can promise privacy. Here’s what you can actually check, and what you can’t.
- You can verify this yourself. Our code is open source, the deployed version is pinned in the footer, and if you open your browser’s network tab while submitting, the only thing you’ll see leave is one scrambled code.
- What we can technically see: that an account submitted, and which anonymous codes matched — never whose they are. We deliberately never store the link between you and your picks.
- What we can’t see: who you picked when it wasn’t returned, or the contents of any note.
- Cleanup: all the pick data is deleted three days after reveal.
Don’t take our word for it
Our entire code is open. You don’t have to trust us — you can check.
- Read the whole thing. Frontend and backend are public at our repository, and the version running right now is pinned in the footer.
- Not a coder? That’s fine. Copy the code into any AI and ask, “does this actually keep my picks private?” It’ll walk you through it. Honestly, we’d rather you did.
- Watch it live. Open your browser’s network tab while you submit. The only thing that leaves your phone is a scrambled code — no name, no roll number, nothing readable.
- The one honest caveat. On reveal night we can see that some anonymous codes matched, and roughly how many. We can never tell whose they are, who matched with whom, or that any particular person matched. And if you do go to prom together, everyone finds out anyway — so there’s genuinely nothing left for us to know.
- You submit once. No edits, no take-backs — pick carefully.
- You must log in and submit to take part. No lurking.
- Keep your recovery password. Without it, a lost phone means lost results.
- This edition is first-year BTech only.