Last updated: 28 August 2026
Nikahee Ltd, trading as Soulsfinity ("Soulsfinity", "we", "our", or "us"), is committed to protecting your personal data. This Privacy Policy explains how we collect, use, store, and share your information when you use the Soulsfinity app and website (soulsfinity.com).
Nikahee Ltd is registered in England and Wales (company number 17116863) and is registered with the Information Commissioner's Office (ICO registration number CSN9687198).
Nikahee Ltd is the data controller responsible for your personal data.
Nikahee Ltd
Company number: 17116863
Registered office: Unit 18 Neills Road, Bold, St Helens, England, WA9 4TU
ICO registration: CSN9687198
Data Protection Officer: Musaab Sharief
Email: [email protected]
Website: soulsfinity.com
We collect the following categories of personal data:
Account information: Your name, email address, phone number, and date of birth when you register.
Profile information: Information you choose to share including height, ethnicity, languages, education, occupation, income range, and relationship preferences.
Special category data: With your explicit consent, we collect your religion and religious practice — including your Islamic sect, religiosity level and prayer practices — your marital history, and information about children. This is special category data under UK GDPR Article 9. We process it only on the basis of your explicit consent, for the purpose of matching you with compatible marriage partners, and you can withdraw that consent at any time in Settings.
Age data: We ask for your date of birth when you register and use it to confirm that you are 18 or over and to show your age on your profile. This is a date you tell us yourself. We do not use facial age estimation and we do not send you to a third-party age-verification provider. Your age is never estimated from your selfie or your verification video. We do hold biometric data for a different purpose — confirming that you are a real, live person — which is described under Verification video data.
Identity verification data: If you choose to verify your identity, we collect a selfie and a photograph of a government-issued identity document (a passport, driving licence or national ID card). These are stored in a separate, access-restricted location, are never shown to other members, and are seen only by our own reviewers — we do not send them to a third-party verification provider. If we approve your submission, we delete the document 14 days later and keep the selfie as the evidence behind your badge, for as long as your account exists. If we refuse it, we keep both images with no deletion date while your account is unverified, and delete them the moment we later approve you on any document; the full rule, including the one exception for documents labelled fake or fraudulent, is in section 8. The decision itself is kept either way. Submitting an identity check does not on its own give you the verified badge shown on profiles.
Verification video data: If you complete the video verification challenge, we collect the short video you record, a still frame taken from it, and a transcript of the phrase you are asked to say. This is the check that grants the verified badge on your profile. Unlike the identity images above, this material is kept for as long as your account exists; it is deleted when you delete your account.
Communications: Messages you send through the app, and anything attached to them — photos, voice notes, documents, stickers, and contact details you choose to share. We moderate messages to ensure platform safety but do not read private conversations unless required for moderation or legal purposes. Conversations are encrypted in transit and at rest, but deliberately not end-to-end encrypted, so that a guardian you have linked can supervise them and our safety team can act on abuse — see section 6.
Call data: If you use in-app voice calling, your audio is carried by our calling provider so that it reaches the other person. We do not record calls and we do not store call audio. See section 5.
Usage data: How you use the app including swipes, matches, and activity patterns. We use this to improve the service and for our matching algorithm.
Device and technical data: Your device type, operating system, IP address, and app version.
Location data: Your city and country. Your device works out which city you are in and sends us only the name of that city — we never receive a precise position from your device, and the coordinates we store are the centre point of the city, not of you. This is a property of how the app is built, not just a policy: the server has no way to record anything finer than a city for your profile. Travel mode changes which city you appear in. The one exception is a location you deliberately send as a message in a chat: that message does carry precise coordinates, and everyone who can see that conversation — including a guardian you have linked — can see them.
We use your personal data for the following purposes:
We process your data under the following legal bases:
We share your data with the following third parties:
Your data is also visible to two categories of person rather than company: other members, who see your profile in discovery and in conversations; and a guardian you have chosen to link, who sees a great deal more than that. Because the second is easy to underestimate, it has a section of its own — see section 6.
We do not sell your personal data to third parties. We do not share your data with advertisers.
Soulsfinity lets you link a guardian — a wali, parent or other trusted relative — to supervise your conversations. Linking a guardian is your choice, and the service works without one. But if you do link one, supervision is total, and you should understand exactly what you are agreeing to before you do it.
Your guardian can see everything in a supervised conversation. That means the messages themselves, and also every kind of thing sent in them: photos, stickers, documents, contact details and voice notes. It includes messages you have since removed from your own view of the conversation — deleting a message for yourself does not remove it from his. You cannot link a guardian and then choose which parts of a conversation he is allowed to see; there is no setting that narrows it, by design.
If you have granted him that permission, your guardian can also send messages into the conversation. Those messages are attributed to him and never appear as coming from you, and you are notified when he sends one. He is not reported to you each time he reads. Where voice calling is available he may join a call in your conversation as a silent observer, and everyone on the call is told on screen when he does.
You can end supervision yourself, at any time, from your settings. Your guardian cannot prevent it and cannot undo it; if you want supervision back afterwards you have to invite him again. Note separately that a guardian who deletes a ward's account is the only person who can restore it during the 30-day window described in section 8.
The person you are talking to is shown that you are supervised — a supervision badge appears on your profile whenever a guardian is actually linked, and it cannot be displayed otherwise.
Your data is stored on Amazon Web Services servers in London (eu-west-2). We use industry-standard encryption for data in transit and at rest. Sensitive data including email addresses and phone numbers are encrypted at the application level.
We implement technical and organisational measures to protect your data including access controls, audit logging, and regular security reviews.
We retain your personal data for as long as your account is active. When you delete your account:
Verification retentions are worth stating separately, because they are not the same. The identity document is deleted 14 days after we approve it. While a submission is still waiting for a decision, no deletion clock runs, so a delay on our side can never destroy your evidence before anyone has looked at it.
If we refuse a submission, we keep its selfie and document while your account is unverified, with no deletion date. We do this because a refusal is a live decision and those images are the evidence for it, both for us and for you if you challenge it. There are two ways they end. The first is in your hands: if we later approve you on any document, we delete every earlier submission of yours — selfies and documents alike — at that moment. The second is your right to erasure, which reaches all of these images at any time. We should be plain about the consequence: if a submission of yours was refused and you never come back to verify or to ask for erasure, those images stay with us indefinitely. We would rather say that than promise you a deadline we do not actually keep.
One exception, and it is deliberate. If a document is labelled fake or fraudulent, that submission is kept indefinitely and is not deleted by a later approval — a forged document does not stop having been forged because the person holding it later produced a real one. The label applies to the individual submission, not to you: your other refused submissions are still deleted when you verify.
Separately from the images, we keep an anonymous record of every refusal — a one-way fingerprint of the document number, the outcome and the date, linked to no account — for 6 years, so that the same document cannot simply be sent in again. The identity selfie of an approved submission is kept for as long as your account exists and is deleted with it, because it is the evidence behind your badge. A verification video, the still frame taken from it and the transcript of the spoken phrase are kept for as long as your account exists, and are removed when the account is deleted.
We also delete data we no longer need even while your account is active: accounts inactive for two years are closed, messages in deleted conversations are removed after a year, and notification tokens and login sessions are cleared after 90 days.
Under UK GDPR you have the following rights:
You can exercise the most important of these yourself, in the app: Settings → Privacy gives you a complete copy of your data in a portable format, and you can delete your account from your account settings. For anything else — including rectification, restriction, objection, or a question about this policy — email [email protected]. We will respond within 30 days.
Two things are left out of the copy of your data, and both are required by law rather than chosen by us. We do not include credentials such as passwords and session tokens, because they are not information about you. And we do not include the identity of another member — anyone who reported or moderated you, or who blocked, reported, liked, favourited or viewed your profile — because their identity is their personal data and not yours (Article 15(4)). Where a record involves someone else you will see the record itself, with their identity replaced by a note.
The Soulsfinity app does not use advertising cookies. We use essential cookies only for app functionality including session management and security. Our website (soulsfinity.com) uses minimal analytics to understand traffic patterns.
Soulsfinity is strictly for adults aged 18 and over. We ask for your date of birth at registration and you confirm that you are 18 or over; we do not currently carry out any further check of your age. If we discover a user is under 18 their account will be immediately deleted and their data removed.
We may update this Privacy Policy from time to time. We will notify you of significant changes via email or in-app notification. The current version will always be available at soulsfinity.com/privacy.
If you are unhappy with how we handle your data, you have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk or by calling 0303 123 1113.
Contact our Data Protection Officer:
Musaab Sharief
Nikahee Ltd, registered in England and Wales, company number 17116863