Skip to content

Security · safety

How the data is held, and how a ban sticks.

Two different things live on this page, because people arrive looking for both. The first half is how Menula LLP protects the data behind Sole. The second half is how you stay safe from another person, which no amount of encryption helps with.

The company behind Sole

Sole. is a product of Menula LLP, a limited liability partnership registered in India (LLPIN ACZ-4363), at HIG-A-16, Dr. A S Rao Nagar, Hyderabad, Telangana 500062, India.

01

How the data is held

  • Encrypted in transit. Every connection to Sole is over TLS 1.2 or better. The soledating.app domain is on the HSTS preload list, which means browsers refuse to connect to it unencrypted at all, before any request is made.
  • Encrypted at rest. Databases, backups and stored media are encrypted on disk.
  • Held in India. Personal data, including every face signature, sits on infrastructure in India.
  • Least privilege. Access to production data is limited to the people whose work requires it, granted individually rather than by default, and reviewed when someone’s role changes or ends.
  • Logged. Access to production systems is recorded, and the log is kept separately from the thing it describes.
  • Separated. Face signatures are stored apart from profiles and from the content of rooms, so no single stolen table is a complete picture of a person.
  • Hashed, never stored plainly. Passwords are stored as salted hashes with a modern algorithm and cannot be read back by us.
  • Rate limited. Sign-in, verification and the waitlist form are throttled, so guessing at scale does not work.
02

What we are not claiming

Larger apps put certification logos on this page. Being straight about where we actually are:

  • Sole is not ISO 27001 certified. We have not been audited to that standard, or to ISO 27017 or ISO 27701, and we will not put those numbers on a page until we have.
  • There is no paid bug bounty programme yet. Reports are still read, still acted on, and still credited if you want the credit.
  • No independent penetration test has been published. When one is done, this line changes to say when and by whom.
  • No system is unbreakable, including this one. Anyone who tells you otherwise is selling something.

The honest summary: this is a small team building carefully, not a certified enterprise. We would rather you knew which one you were dealing with.

03

Verification, and why a ban means something

Everyone on Sole passes a liveness check and a face match once, at sign-up. It is the load-bearing safety feature, and it is the reason for most of the rest of this page.

  • It confirms a live human, not a photograph, a screen or a generated image.
  • It confirms that the human matches the profile photos.
  • It confirms the human is not already on Sole under another account.
  • Because of the last one, a ban attaches to the person rather than the email address. A new inbox does not get anyone back in, and that is the entire point of doing this at the door.

What the check keeps, and for how long, is in the sensitive data policy. The one-line version: the recording is deleted within 24 hours, and the derived signature lives as long as your account, or three years on a blocklist if you were banned for harming someone.

What it is not: a criminal record check. We do not run background checks, we cannot vouch for anyone’s intentions, and verification is a protection rather than a guarantee. Section 5 is what to do about that.

04

Reporting, blocking and what follows

Every profile and every room has a report control and a block control. Blocking is immediate and silent: the other person is not told.

Reports are read by a person. Automated detection flags things, but it does not decide anything, and no account is banned by software alone. Depending on what happened, the outcome is a warning, a restriction, a suspension or a permanent ban, and anything involving a child or a credible threat goes straight to a ban and to the authorities where the law requires it.

Content showing a person nude, in a sexual act, or in a state of undress, and content that impersonates someone including by morphing their image, is removed within 24 hours of a valid complaint. That deadline is set by Rule 3(2)(b) of the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, and it is not one we get to negotiate. Report it to grievance@soledating.app if the in-app route is not available to you.

If you were banned and think it was wrong, appeal to the Grievance Officer. A person who did not make the first decision looks at it again.

05

Staying safe from a person

Verification tells you someone is real. It cannot tell you they are kind. The following is worth reading once even if you have been dating online for years, because the scams change and the advice does not.

  • Never send money. Not a loan, not a customs fee, not a crypto tip, not an emergency, not a sure thing, not to anyone you have not met, no matter how long you have been talking or how good the story is. This is the single most common way people lose money on dating apps and it is not close.
  • Meet in public the first few times, and arrange your own way there and back.
  • Tell a friend where you are going and who with. Share your live location with them for the evening.
  • Keep the conversation on Sole until you trust the person. Someone pushing hard to move to another app in the first ten messages is a pattern, not a coincidence.
  • Do not share your home address, your workplace, your bank details or your government ID numbers.
  • Video call before meeting if you want a second check. There is no rule against asking.
  • Trust the feeling. Leaving early needs no explanation and costs you nothing.
  • If someone frightens you, block and report them. If you are in immediate danger in India, call 112, or the women’s helpline on 181, or the cyber crime helpline on 1930.
06

If something goes wrong

We have a written procedure for a breach, and it starts with containing it and ends with telling people, in that order but without a long gap between them.

If personal data is breached, we notify the Data Protection Board of India, and we notify you, as the Digital Personal Data Protection Act, 2023 requires. That duty applies whether or not anyone turns out to have been harmed, and we are not going to wait for certainty about harm before telling you. Where the GDPR applies, the supervisory authority is told within 72 hours.

The notice will say what happened, what data was involved, what we have done, and what you should do. If we do not know something yet, it will say that too.

07

Reporting a vulnerability

Found a hole? Tell us at security@soledating.app and we will thank you for it. Encrypt it if you want to; ask and we will send you a key.

Wheresecurity@soledating.app
AcknowledgementWithin 72 hours, from a person
First assessmentWithin 7 days, with what we think the severity is and why
DisclosurePlease give us 90 days, or until it is fixed if that is sooner. We will not use that window to go quiet on you
CreditNamed on this page if you want it, anonymous if you do not
RewardNo paid bounty yet. We will say so honestly rather than imply one

Safe harbour

If you research in good faith within the boundaries below, we will not pursue legal action against you, and we will say so in writing to anyone who asks, including a court.

  • Use only your own account and your own test data. Do not access, modify or keep anyone else’s.
  • Stop as soon as you have confirmed a vulnerability. Proving it is enough; exploiting it further is not research.
  • Do not degrade the service for anyone else.
  • Do not extract, retain or publish personal data. If you see some by accident, stop, tell us, and delete it.

Out of scope

  • Denial of service, load testing and volumetric attacks of any kind.
  • Automated scanner output submitted without a working proof of concept.
  • Social engineering of our team, our users, or our providers.
  • Physical attacks on offices or people.
  • Reports about missing best-practice headers with no demonstrated impact.
  • Anything found in a third party’s system rather than ours. Report that to them.
08

Which address to use

If it is aboutWrite to
A vulnerabilitysecurity@soledating.app
Someone on Sole, or content that should not be theregrievance@soledating.app
Your data: access, correction, deletion, consentprivacy@soledating.app
Anything legallegal@soledating.app
Anything elsehello@soledating.app

By post: Menula LLP, HIG-A-16, Dr. A S Rao Nagar, Hyderabad, Telangana 500062, India.

Last updated 31 July 2026 · questions to legal@soledating.app

Back to Sole