Sensitive data
Your face, who you want, and what you tell one person.
A dating app holds the most sensitive things a person has. This page separates that data out from everything else in the privacy policy and says exactly what happens to it, because it deserves to be found without reading nine other sections first.
The company behind Sole
Sole. is a product of Menula LLP, a limited liability partnership registered in India (LLPIN ACZ-4363), at HIG-A-16, Dr. A S Rao Nagar, Hyderabad, Telangana 500062, India.
Why this page exists at all
Most of what Sole holds is unremarkable: an email address, a device model, when you last opened the app. Three things are not, and they are the three things that make a dating app worth being careful about.
- Your face, as a biometric. Not a photograph, but a signature derived from one, which can identify you uniquely.
- Who you are drawn to. Your gender, who you want to meet, and the pattern of who you actually connect with. Together that is your sexual orientation, whether or not you have ever typed the word.
- Whatever you decide to say. People tell each other about therapy, sobriety, a diagnosis, a disability, a pregnancy, a faith, a divorce. Sole does not ask for any of it. It is a place where people say it anyway.
Under the GDPR, all three sit in Article 9: biometric data used to identify a person, data about sex life or sexual orientation, and data concerning health. That article starts from a prohibition and then lists narrow exceptions, one of which is your explicit consent. Under India’s Digital Personal Data Protection Act, 2023, which is the law that governs Sole at launch, there is no special category at all: it is personal data like any other. We are writing this page anyway, and holding ourselves to the stricter of the two, because the Indian law being quieter about it does not make the data less yours.
Your face
Everyone verifies once, at sign-up. It takes about thirty seconds: a short liveness capture, matched against your profile photos.
| What is captured | A short video of your face, taken live, on your device |
| What is derived | A face signature: numbers describing the geometry of your face. It cannot be turned back into a photograph of you |
| What it is used for | Three things, and nothing else: confirming a live human, matching that human to the photos on the profile, and checking the signature against existing accounts so one person cannot hold two and a banned person cannot return |
| Who runs it | We do. Our own system, our own servers, in India. No third-party verification vendor sees your face |
| The video | Deleted the moment the match finishes, and within 24 hours regardless |
| The signature | Kept while your account exists. Deleted within 30 days of you deleting your account |
| If you are banned | The signature stays on a blocklist for three years, and is used for nothing except refusing you a new account |
| Shared with | Nobody. Not another user, not an advertiser, not an affiliate. There is no affiliate |
The app asks for this separately, in its own step, in plain words, immediately before the check. It is not folded into a single "I agree to everything" at sign-up, because explicit consent under Article 9 means exactly that, and because burying it would be a tell about how seriously we take it.
You can say no. Saying no means you cannot finish sign-up, because an unverified account is the specific thing verification exists to prevent. We would rather tell you that plainly than pretend the choice is freer than it is.
Who you are drawn to
You tell Sole your gender and who you want to meet, because otherwise it cannot show you anyone. That is the whole of why we ask, and it is the whole of what we do with it.
- It is used to decide which profiles you see and who sees yours.
- It is shown to other people on Sole only to the extent you put it on your profile.
- It is never used to target advertising, because Sole carries none.
- It is never sold, never shared with a data broker, and never handed to an affiliate, because there is no affiliate.
- We do not infer it from your behaviour and store the inference. What you told us is what we hold.
This matters more in some places than others. Being outed by a dating app is a real danger for real people, in India and elsewhere. That is the reason the list above is short and the reason it has no exceptions.
Anything health shaped
Sole has no health questions. There is no field for a diagnosis, a medication, a mental health status, a disability, a fertility detail or a sobriety date. We do not want that data and we have not built anywhere to put it.
What we cannot prevent is people saying it, because that is what talking to someone is. If you write about your therapist in a prompt, or tell the person in your room that you are six months sober, that is health data sitting inside ordinary content.
So the rule is simple: whatever you say gets treated as the content it lives in. Profile text is visible to people who are shown your profile. Room messages go to one person, are held while the room is open and for 30 days after it closes, and are deleted with your account. Nothing in either place is scanned to infer a health condition, build a profile of you, or feed a model. The only time a person at Sole reads a message is when it has been reported.
And the advice, which is the same advice as for your address and your bank details: a profile is read by strangers. Decide what you want strangers to know, then write that.
What never happens to any of it
- It is not sold. Not for money, not for anything else of value, in any form, to anyone.
- It is not shared with advertisers or data brokers. There is no advertising SDK in the app and no analytics SDK collecting on a third party’s behalf.
- It is not used to train models.
- It is not pooled with a parent company or a sister app. Sole has neither.
- It is not used to make an automated decision about you that a person will not review on request.
The only circumstance in which any of it leaves us is a valid, written, lawful order from a court or an authority entitled to make one, and then only the part that the order actually reaches. We check that an order is real, we push back when it overreaches, and we tell you unless we are forbidden to.
Taking it back
Everything in the privacy policy applies here, and these three are the ones people actually want. Write to privacy@soledating.app from the address on your account, or use the app where the control exists.
| What you want | What happens | How long |
|---|---|---|
| Delete your face signature | Delete your account and it goes with it. The signature cannot outlive the account it protects, except on the ban blocklist described above | Within 30 days |
| Change or remove what you said about yourself | Edit or delete it in the app. Profile changes take effect at once; room messages follow the retention schedule | Immediately, then 30 days for the copies |
| Withdraw consent | Tell us which consent. Face verification is the one that cannot be withdrawn while keeping the account, because it is the condition of having one | Acted on within 30 days |
| Get a copy of all of it | Ask, and we send you a machine-readable export of what you gave us | Within 30 days |
| Complain about how we handled any of this | The Grievance Officer at grievance@soledating.app, and past us, the Data Protection Board of India | Acknowledged in 24 hours, resolved in 15 days |
If you are reading this from outside India
Sole opens in India first. When it opens elsewhere, this page is the one that grows, and here is what will be added rather than discovered later.
- EU and UK: everything above already meets the Article 9 standard. What is added is a named Article 27 representative in the EU and in the UK, a Data Protection Officer, and Standard Contractual Clauses for the transfer of data to India.
- Washington and Nevada, if we ever open there: their consumer health data laws define health data extremely broadly, wide enough to catch some of what is on this page. This document becomes the consumer health data policy required by those Acts, with their specific rights to withdraw consent, to delete, and to appeal a refusal, and with the signed authorisation their law requires before any sale, which is easy for us because we do not sell anything.
- Illinois and Texas, if we ever open there: their biometric statutes require a written policy, a stated retention schedule and written consent before a face signature is collected. All three exist above; what changes is the deadline attached to them.
None of that is in force for us today, and saying it is would be a lie of the kind legal pages specialise in. It is here so you can see the shape of what we have committed to, and hold us to it when the day comes.
Last updated 31 July 2026 · questions to legal@soledating.app
The rest of it
- Terms of useThe agreement between you and Menula LLP when you use Sole.
- Privacy policyWhat we collect, why, for how long, and what you can make us do about it.
- Cookie policyA short page, because the answer is close to none.
- SecurityHow the data is held, how bans stick, and how to report a hole.
- Accessibility statementWhere we meet WCAG 2.2 AA, and the three places we do not yet.