Skip to content

Privacy

What we hold, and what you can make us do about it.

Sole is a dating app. It runs on things that are nobody else’s business: your face, who you are drawn to, and what you say to one person in a closed world. This page is the full account of what Menula LLP collects, why, for how long, and how you get it back or get it deleted.

The company behind Sole

Sole. is a product of Menula LLP, a limited liability partnership registered in India (LLPIN ACZ-4363), at HIG-A-16, Dr. A S Rao Nagar, Hyderabad, Telangana 500062, India.

01

Who holds your data

Menula LLP, a limited liability partnership registered in India, LLPIN ACZ-4363, at HIG-A-16, Dr. A S Rao Nagar, Hyderabad, Telangana 500062, India. Sole is a product of that company. Under the Digital Personal Data Protection Act, 2023 (opens in a new tab) we are the Data Fiduciary for your personal data. If the GDPR (opens in a new tab) applies to you, the same company is the controller.

Privacy questions and requests go to privacy@soledating.app. Formal grievances go to the Grievance Officer at grievance@soledating.app, and section 12 says what happens to them.

Sole opens in India first. the Digital Personal Data Protection Act, 2023 is the law that governs us today. Everything below is also written to GDPR standard, so if you are reading this from the EU or the UK, the rights described here are already yours in practice, and will be yours in law the day we open there.

02

What this covers

Two surfaces: this website at soledating.app, including the waitlist, and the Sole mobile app on iOS and Android. It covers both because there is one company behind both and one policy is easier to hold us to than two.

It does not cover what other companies do with data you give them directly. If you pay through the App Store, Apple is the merchant and Apple’s policy governs the payment. Same for Google Play. If you leave Sole to talk to someone on another app, this page stops at the door.

03

What we collect

What you give us

  • Account data: your email address and your date of birth. Sole uses email, not a phone number, as the account primitive. There is no social sign-in, so we do not receive anything from Facebook, Google or Apple beyond what a payment requires.
  • Profile data: your photos, of which at least three must show your own face, your written prompts, your voice note, your name or the name you go by, your gender, who you want to meet, and anything else you choose to put on a profile that other people will read.
  • Face data: a short liveness capture taken once at sign-up, and the face map derived from it. Section 5 is entirely about this, because it deserves its own section.
  • What you say in a world: the messages between you and the one person you are connected to. We hold them so the world works across your devices and so a report can be looked at. We do not read them for any other reason, and we do not train models on them.
  • Reports and support: what you write to us, what you report about someone else, and what someone else reports about you.
  • The waitlist: one email address, and nothing else. Section 14.

What the app generates

  • Usage data: when you signed in, which screens you opened, when a world opened and closed, and whether a verification passed. This is what tells us the product works, and it is what a safety investigation runs on.
  • Device and technical data: device model, operating system version, app version, language, a Sole-generated install identifier, IP address, and crash diagnostics.
  • Approximate location, only if you grant the permission, and only to show distance. Turning it off in your device settings stops the collection. Sole does not track you in the background, and there is no location history.

What we deliberately do not collect

  • Card numbers. Apple and Google take the payment; we receive a transaction record and a subscription status, never the card.
  • Your contacts, your photo library beyond the images you pick, your calendar, your microphone outside a voice note, or your camera outside a photo or the verification check.
  • An advertising identifier. Sole carries no advertising SDK, so there is nothing to collect it for.
04

Why we use it, and what makes that lawful

Under the Digital Personal Data Protection Act, 2023 (opens in a new tab), consent is the basis for almost everything a private company does with your data in India, and consent has to be free, specific, informed, unconditional and unambiguous, given for a stated purpose, and as easy to withdraw as it was to give. The GDPR (opens in a new tab) column is what we would rely on if you are in the EU or the UK.

What forWhat we useIndia (DPDP)If the GDPR applies to you
Running your account and showing you one person at a timeAccount, profile, usage, device, location if grantedYour consent, given at sign-up for this purposeArt. 6(1)(b), performing the contract you entered by using Sole
Confirming you are one real person, onceLiveness capture, face map, profile photosYour separate consent, asked for immediately before the check and refusableArt. 9(2)(a), explicit consent for biometric data, plus Art. 6(1)(b)
Keeping the world closed and the app safe: reports, bans, duplicate and impersonation checksReports, the reported content, usage, device, face mapYour consent, and where an order or the law compels it, section 7(d)Art. 6(1)(f), our legitimate interest in a safe service, and Art. 9(2)(f) where a claim is involved
Taking payment and honouring a free trial or a subscriptionAccount data, transaction record and subscription status from Apple or GoogleYour consent, and compliance with tax and accounting lawArt. 6(1)(b), and Art. 6(1)(c) for the tax records
Emailing you about your account and about launchYour email address, account statusYour consent, given for this purpose when you joined the waitlist or made an accountArt. 6(1)(b), performing the contract, and Art. 6(1)(a) for the waitlist notice
Answering you when you write to usSupport messages, account dataYour consent, and the legitimate use in section 7(a) for what you volunteerArt. 6(1)(b) and Art. 6(1)(f)
Fixing crashes and making the product less badUsage, device, crash diagnosticsYour consentArt. 6(1)(f), our legitimate interest in a working app
Complying with the law, and defending or bringing a legal claimWhatever the specific obligation reachesSection 7(d), compliance with a judgment or order, and the Information Technology Act, 2000 (opens in a new tab)Art. 6(1)(c) and Art. 6(1)(f)

Nothing on that list is advertising, because Sole does not carry advertising. That is the point of charging for it. Marketing email is not on it either: we write to you about your account and about launch, and anything promotional needs a separate yes from you first, asked for on its own and as easy to withdraw as it was to give.

05

Your face: the liveness check, and the map we keep

Everyone verifies once, at sign-up, and it takes about thirty seconds. This is the section people actually came here to read, so it is the whole pipeline, in order, with nothing left out.

The liveness check

The app asks you to record a few seconds of your own face. It is checking one thing: that a living person is in front of the camera at that moment. Not a photograph held up to the lens, not a screen playing a recording, not a mask, and not an image a model generated. That check is the entire basis on which Sole can tell you the people here are real.

Everyone has done it, with no exceptions

There is no route into Sole that skips this. No invite that waives it, no early-access list, no staff accounts exempted, and nobody grandfathered in from before the check existed. If a profile exists, the person behind it passed a liveness check.

That is worth stating plainly, because the value of it is not really about your own account. It is the assurance that every other person you will ever see on Sole went through the same door you did.

The face map

From that video we create a face map: a set of numbers describing the geometry of your face, the distances and proportions that make it yours rather than someone else’s. It is not a photograph. It is not a frame of the video. It cannot be turned back into either, so a person who somehow obtained it could not use it to see what you look like.

The video does not survive it

The moment the map is created, the video is deleted, and every frame of it with it. Not archived, not moved to cheaper storage, not kept back for training a model, not held "just in case". Deleted as soon as the map exists, and within 24 hours in every case regardless. The map is the only thing that stays.

What the map is checked against

  • The photos you upload. The map is matched against the pictures on your profile, so that the account is genuinely yours and has not been assembled out of somebody else’s photographs.
  • The maps of accounts already on Sole, so that one person cannot hold two accounts, and so that a person we have banned cannot come back with a new email address.
  • Every face photograph you add later. Your profile has to carry at least three photographs of your own face for as long as it exists, and each replacement is checked against the map before it goes live. That is an ongoing use rather than a one-off one, and it is the second reason the map is kept instead of discarded at sign-up.

How the map is stored

  • Encrypted, in transit and at rest.
  • On our own infrastructure, in India. We built and run this ourselves, so the video is never sent to a third-party verification vendor and no outside company ever sees your face.
  • In its own store, held apart from your profile and from anything you have said inside a world, so that no single stolen table is a complete picture of a person.
  • Reachable only by the few people whose work requires it, granted individually, with every access logged.
  • Never shared. Not with another person on Sole, not with an advertiser, not with a data broker, not with an affiliate, because there is no affiliate. There is no exception to that sentence and no price at which it changes.

How long the map stays

For as long as your account exists, and no longer. Delete your account and the map is deleted with it, inside 30 days. If your account was banned for harming someone, the map stays on a blocklist for three years and is used for nothing except refusing that person a new account, because a ban that a new inbox defeats is not a ban.

Saying yes, and saying no

The app asks for this separately, in its own step, in plain words, immediately before the check, and tells you what it will keep. It is not folded into a single "I agree to everything" at sign-up.

You can refuse. Refusing means you cannot finish sign-up, because an unverified account is the specific thing verification exists to prevent. We would rather tell you that plainly than pretend the choice is freer than it is.

Under the GDPR (opens in a new tab) a face map used to identify a unique person is biometric data under Article 9, which starts from a prohibition and needs your explicit consent to lift it. That is why the app asks separately rather than in a bundle. Under the Digital Personal Data Protection Act, 2023 (opens in a new tab) it is ordinary personal data, but we hold it to the Article 9 standard anyway. The sensitive data policy has the fuller version.

If a check fails, a person looks at it. You are never shut out of Sole by a machine alone: write to the Grievance Officer and a human reviews it.

06

Who else sees it

Sole has no advertising business, no data business, and no parent company to pool data with. So this list is short, and it is exhaustive.

WhoWhat they getWhy
The one person you are connected toYour profile, and what you say in the worldThat is the product. Nothing is shared with anyone you have not opened a world with.
Our hosting and infrastructure providerEverything, encrypted, as the place it is storedThe app has to run somewhere. Bound by a written processing agreement, acting only on our instructions.
Our email providerYour email address and the message we are sendingSending you the emails Sole owes you: a launch note, a password reset, a receipt.
Apple and GoogleA transaction, and the fact that you have a subscriptionThey take the money. We never see your card.
Law enforcement, a court, or a regulatorOnly what the specific order compelsWhen there is a valid, written, lawful order. We check that it is one, we push back when it is not, and we tell you unless the order forbids it.
A buyer, if the company is ever soldWhatever transfers with the serviceYou will be told before it happens, and the new owner is bound by this policy until you are told otherwise and given a choice.

What we will not do

  • We do not sell your personal data. Not to anyone, not in any form, not for any consideration.
  • We do not share it with advertisers or data brokers, and there is no advertising or analytics SDK in the app collecting on their behalf.
  • We do not train models on the contents of a world.
  • We do not use your profile or your face in marketing without asking you first, in writing, for that specific use.
07

Where it is held

In India. Personal data, including every face map, is stored on infrastructure in India.

If a service provider we depend on processes something outside India, section 16 of the Digital Personal Data Protection Act, 2023 (opens in a new tab) permits it except to a country the Central Government has restricted, and we will not use a provider in a restricted country. When Sole opens in the EU or the UK, transfers out of those regions will run on the European Commission’s Standard Contractual Clauses and the UK Addendum, with a transfer risk assessment behind them. Ask at privacy@soledating.app and we will send you the current list of providers and where each one sits.

08

How long we keep it

Personal data does not get kept because it might be useful one day. Each item below has a stated life and a reason for it.

WhatHow longWhy that long
Waitlist email addressUntil you are inside Sole, or 30 days after we open, whichever comes firstIt exists to tell you the morning Sole opens. After that it has no purpose.
Account and profile dataWhile your account is open, then deleted within 30 days of you deleting itThe 30 days is the window to undo an accidental deletion and to finish removing it from backups.
The liveness capture (the video)Deleted the moment the match completes, and within 24 hours regardlessIt has served its purpose the second the comparison is done.
Face mapWhile your account is open, then deleted within 30 daysIt is what stops one person holding two accounts. When there is no account, there is nothing to protect.
Your profile photographsUntil you replace them or delete them, then deleted within 30 daysThey are yours, and they stay exactly as long as you want them to.
Face map of a banned accountThree years from the ban, on a blocklist and nothing elseA ban that a new email address defeats is not a ban. Three years, then it goes.
Messages in a worldWhile the world is open, and 30 days after it closesSo a report made just after a world ends can still be looked at. Then deleted.
Reports, and the records of what we did about themThree years from the reportSafety patterns take longer than one incident to see, and a banned person may dispute it.
Support conversationsThree yearsSo we can pick up a thread you started, and defend a claim if one is made.
Server logs, including IP address180 daysRule 3(1)(g) of the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021 (opens in a new tab).
Registration records after you leave180 days after the account is closedRule 3(1)(h) of the same Rules requires it. This is a legal floor we cannot go under.
Payment and tax recordsEight yearsSection 34 of the Limited Liability Partnership Act, 2008 (opens in a new tab), plus GST and income tax record keeping.
Anything under a live legal claim or a lawful orderUntil the claim or the order is finishedWe are not permitted to delete evidence, and neither is anyone else.

Aggregate counts that cannot identify anyone, for example how many worlds opened in a week, are kept indefinitely. That is not personal data and it is not about you.

09

How it is protected

Encrypted in transit and at rest, access limited to the few people whose job needs it, every access logged, and a written breach procedure. The security page has the detail, including how to report a hole you have found.

If a breach happens that is likely to affect you, we will tell the Data Protection Board of India (opens in a new tab) and we will tell you, without waiting to be asked. Under the Digital Personal Data Protection Act, 2023 (opens in a new tab) that duty sits on us whether or not anyone was actually harmed. Where the GDPR (opens in a new tab) applies, the supervisory authority is told within 72 hours.

10

What you can make us do

Write to privacy@soledating.app from the address on your account, or use the controls in the app where they exist. We acknowledge within 24 hours and answer within 30 days. There is no fee, no form, and no need to say why.

RightWhat it gets youWhere it comes from
Know and accessA summary of the personal data we hold about you, what we are doing with it, and who we have shared it withDPDP s.11 · GDPR (opens in a new tab) Art. 15
Correct and completeAnything wrong or out of date fixed, and anything half-entered completedDPDP s.12 · GDPR Art. 16
EraseYour data deleted, unless a law makes us keep a specific piece, in which case we tell you which piece and which lawDPDP s.12 · GDPR Art. 17
Withdraw consentProcessing stops for whatever you withdrew. It is as easy as giving it was. Withdrawing consent for the face check ends the account, because there is no unverified Sole.DPDP s.6(4) to s.6(6) · GDPR Art. 7(3)
Take it with youA machine-readable copy of what you gave usGDPR Art. 20. Not in the DPDP Act, offered anyway.
Object, and restrictProcessing paused or stopped where we relied on a legitimate interestGDPR Arts. 18 and 21. Offered in India too.
Nominate someoneName a person to exercise these rights for you if you die or lose capacityDPDP s.13. This one is specific to India and genuinely useful.
ComplainEscalate past us, to a regulator, without our permissionDPDP s.13 then the Data Protection Board of India (opens in a new tab) · GDPR Art. 77

We will ask you to confirm you are you before we act, because handing an account over to whoever asks loudest is its own privacy failure. We can refuse a request that is unlawful, or that would expose someone else’s data, and if we refuse we say so in writing and say why.

the Digital Personal Data Protection Act, 2023 (opens in a new tab) also puts duties on you: do not impersonate anyone when you register, do not suppress material information, and do not file a false or frivolous grievance. Section 15 of the Act, and the terms of use say the same thing in product language.

11

Decisions made by machines

Two things in Sole are decided automatically, and both can end an account, so both get a human.

  • The face match at sign-up. A failed check does not by itself close the door: ask, and a person reviews the check.
  • Automated safety detection, which flags content and behaviour for review. It flags. It does not ban. A person makes the call on every ban, and every ban can be appealed to the Grievance Officer.

Sole does not profile you to sell you anything, and does not make decisions about you based on inferred sensitive traits. There is no advertising model here to make that profitable.

12

Under 18

Sole is for adults only, 18 and over. We ask for your date of birth at sign-up and the face check is a second, harder gate: it is difficult to pass as an adult to a liveness check when you are not one. If we find an account belonging to someone under 18, we close it and delete the data.

Section 9 of the Digital Personal Data Protection Act, 2023 (opens in a new tab) requires verifiable parental consent before a child’s data is processed, and forbids tracking or targeted advertising to children. We meet that by not admitting children at all. If you believe a minor is on Sole, write to grievance@soledating.app and we will treat it as urgent.

13

If we get it wrong

Start with the Grievance Officer at grievance@soledating.app, or by post to the Grievance Officer, Menula LLP, HIG-A-16, Dr. A S Rao Nagar, Hyderabad, Telangana 500062, India. We acknowledge within 24 hours and resolve within 15 days.

If that does not fix it, you can complain to the Data Protection Board of India (opens in a new tab). You are required to come to us first under the Digital Personal Data Protection Act, 2023 (opens in a new tab), but you are not required to accept our answer. If you are in the UK, the Information Commissioner’s Office (opens in a new tab); elsewhere in the EU or the EEA, your national supervisory authority.

14

When this page changes

The date at the bottom is the date it last changed. If a change means we want to do something materially new with data we already hold, we will tell you before it takes effect and, where the change needs your consent, ask for it rather than assume it from your silence.

15

The waitlist, specifically

Before the app opens, this website does one thing, and it is worth stating separately because it is so much smaller than everything above.

  • We collect one email address, given by you on this site. No name, no password, no social sign-in.
  • Alongside it we store the moment you sent it, which of the two fields on the page you used, and your browser’s user agent string, so we know what worked and can spot a flood of bot signups.
  • We email you about the list and about launch: a note confirming you joined, and one on September 1st, the day Sole opens, with a way in. If you go on to make an account, we email you about that account.
  • Nothing promotional. We do not send marketing off the back of a waitlist signup, and we will not start without asking you first and getting a yes. Withdrawing that later costs you one reply.
  • It is deleted once you are inside Sole, or 30 days after we open, whichever comes first.
  • Ask us to remove it at hello@soledating.app and we will, without a form, an account or a reason, and confirm when it is done.

This site sets no cookies, runs no analytics and loads no third-party scripts. The typefaces are served from this domain rather than a font CDN, so opening this page does not tell anyone else you were here. The cookie policy is one page long and says the same thing at more length.

Last updated 31 July 2026 · questions to legal@soledating.app

Back to Sole