Privacy Policy and Personal Data Processing
This Policy explains how Soulmate processes personal data of users of soulmateapp.ru, the profile area and the Soulmate app, why this data is used, and how users can exercise their rights.
1. Data Controller
The data controller is Soulmate Software FZCO.
License: 84737745.
Address: Dubai Digital Park, Dubai Silicon Oasis, UAE.
Privacy contact: privacy@slmt.app.
For users in the Russian Federation, personal data processing is organized with regard to Federal Law No. 152-FZ “On Personal Data”, including initial database localization, separate consent, data subject request handling and security measures.
2. Data We Collect
- identity data: name, birth date, gender, profile photo;
- contact data: phone number, email;
- profile data: interests, tags, in-product reactions;
- technical data: IP address, device model, OS version, browser language and session data;
- interaction data: pinches, connects, messages, reports, blocks;
- safety data: moderation signals, abuse reports and data required to prevent misuse.
We do not sell personal data and we do not use advertising trackers.
Profile photos are used as user content and avatars. They are not used for biometric identification unless the user goes through a separate clearly marked verification flow. If such a flow requires biometric personal data, it must be covered by separate consent.
3. Purposes of Processing
- account creation and user authentication;
- operation of website and app features, including compatibility, profile and communication tools;
- platform safety, fraud prevention and abuse mitigation;
- support requests and legally significant user requests;
- performance of our obligations and compliance with applicable law.
4. Processing Matrix
| Purpose | Data subjects | Data | Actions | Basis | Retention |
|---|---|---|---|---|---|
| Registration, login and profile area | website visitors, registered users | phone, email, name, session data, IP address, device data | collection, recording, organization, storage, updating, use, blocking and deletion | user consent; performance of the Terms of Use | while the account is active, then according to deletion timelines |
| Profile, compatibility and communications | registered users | profile, birth date, gender, photos, interests, reactions, messages, connects | storage, alteration, use, automated and mixed processing, deletion | consent; provision of service requested by the user | while needed for service features or until account deletion |
| Safety, moderation and anti-fraud | users, reporting persons, incident participants | reports, blocks, technical events, limited moderation records | collection, analysis, storage, access restriction, blocking, deletion | controller rights and legitimate interests where data subject rights are not violated; legal requirements | for the period needed to review incidents and protect users |
| Support, data deletion and consent withdrawal | users and request submitters | contacts, account ID, request text, technical destruction record | collection, registration, verification, storage, de-identification, destruction | consent; processing of a legally significant data subject request | until request completion; technical records are kept without profile content |
| Payments and subscriptions | paid feature users | purchase identifiers, subscription status, payment events without full card data | receipt, storage, reconciliation, update, deletion | performance of obligations and payment platform requirements | for the subscription term and mandatory transaction records |
5. AI-Assisted Logic
Soulmate uses algorithmic processing to provide compatibility insights and personalization. These outputs are informational only, are not psychological or medical evaluations, and do not make decisions for the user.
6. Legal Basis
- user consent;
- contractual necessity and operation of the service;
- exercise of the controller’s rights and legitimate interests in safety and fraud protection, provided that the rights and freedoms of the data subject are not violated;
- legal compliance, platform requirements and legally significant user requests.
7. Localization, Storage and Security
Personal data of users in Russia is initially recorded in databases located in Russia. Timeweb Cloud and Yandex Cloud may be used for core infrastructure. We use HTTPS/TLS, role-based access, multi-factor protection for administrative access, administrator audit logging and encrypted backups. Operational backups follow a retention cycle of no more than 90 days.
If a personal data incident is identified and it affects data subject rights, the controller organizes an internal review and submits notifications to the competent authority within the timeframes required by applicable law.
8. Processors and International Transfers
Depending on the feature selected by the user, we may use:
- Timeweb Cloud and Yandex Cloud for API, database and file hosting in Russia;
- SMS.ru, MAX, Telegram, VK and Yandex ID for code delivery and authentication;
- YooKassa, Apple and Google for payments, subscriptions and purchase validation;
- Expo for push delivery;
- Firebase Crashlytics and AppsFlyer for crash diagnostics and product analytics only after separate optional consent;
- OpenAI, xAI or Anthropic for selected AI-generated descriptions, using the minimum request data and excluding phone numbers and contact details;
- MailerSend for transactional email delivery.
Some processors may operate outside Russia or the UAE, including authentication, analytics, push notification, AI infrastructure and payment providers. Transfers are limited to the selected function and are performed only with an applicable legal basis, contractual safeguards and required transfer compliance steps. For users in the Russian Federation, a cross-border transfer notice must be submitted to Roskomnadzor before such transfer where Federal Law No. 152-FZ requires it. Third-party authentication methods remain optional.
9. Retention and Deletion
- data is retained while the account is active and while required for processing purposes;
- self-service deletion removes active account data and local files without undue delay; manually submitted requests are processed within 30 days after account ownership is verified;
- requests to stop personal data processing are reviewed within 10 business days; where objectively necessary, the period may be extended by up to 5 business days with a reasoned notice to the user;
- backups and system logs may be removed within 90 days as part of the technical cycle;
- safety or legal records may be retained longer if required for investigations or legal obligations.
Users may delete data in three ways: in the app via Settings → Delete Account, via the data deletion page, or alternatively by email at support@slmt.app.
10. User Rights
- request information about data processing;
- update or correct data;
- request deletion or export of data;
- withdraw consent;
- report privacy misuse or abuse.
To exercise privacy rights, contact privacy@slmt.app or use the website request form if your request concerns account and data deletion.
11. Children’s Privacy
Soulmate is strictly for users aged 18+. Accounts of minors are removed once the age violation is confirmed.
12. Updates
We may update this Policy to reflect changes in the product, infrastructure, safety or legal framework. The current version is published at soulmateapp.ru/en/privacy/.
13. Contact
Privacy and personal data: privacy@slmt.app.
General support: support@slmt.app.
Support hours: 10:00–22:00 (UTC+3).