SocialFit
P Labs FZE · UAE

Legal

Privacy Policy

Last updated: 19 September 2026

Contents

  1. 1. Who We Are and What This Policy Covers
  2. 2. Eligibility and Age Assurance
  3. 3. Personal Data We Collect
  4. 4. Sensitive Personal Data and Consent
  5. 5. Why We Use Personal Data and Our Legal Grounds
  6. 6. AI, Profiling, the Trust or Relational Evidence Graph, and Human Agency
  7. 7. Visibility, Member Sharing, and User Control
  8. 8. When We Disclose Personal Data
  9. 9. International Transfers
  10. 10. Retention and Deletion
  11. 11. Cookies and Similar Technologies
  12. 12. Security and Personal Data Breaches
  13. 13. Your Rights and Choices
  14. 14. Third-Party Providers and Member-Organized Activities
  15. 15. Accountability, Impact Assessments, and Policy Changes
  16. 16. Contact and Complaints

1. Who We Are and What This Policy Covers

SocialFit is a consumer brand and operating business unit of P Labs FZE, a company registered in the Ajman Free Zone, United Arab Emirates. P Labs FZE ("P Labs", "we", "us", or "our") is the controller of personal data processed through SocialFit unless a separate notice states otherwise. SocialFit is not a separate legal entity.

This Privacy Policy covers the SocialFit website, mobile application, membership application and onboarding processes, and membership network (the "Service"). It applies to visitors, applicants, registered users (each a "Member"), nominees and invited contributors. Where enabled, it covers Story and StoryBuilder, Signals, Pulse, Rooms, Pods, Scene curation, Philia-mediated meetings, Philia ID, Philia Keys, Ask SocialFit, Relational Feedback, Social Perception, Philia Taps or check-ins, attendance and operational reliability controls, Rewards, safety reporting and related support. Describing a feature does not mean that it is available in every tier or at launch.

SocialFit uses distinct matching, curation, relational-intelligence, safety, reliability and reward systems (the "Platform Systems"). The Signal Matching Engine identifies contextual fit for a Member's present Signal; the Scene Curation Engine composes eligible groups or experiences; and the Trust or Relational Evidence Graph stores and analyses contextual evidence arising from Philia-mediated interactions. These systems may interact, but serve different purposes and are not treated as a single universal trust score.

A provider may act as our processor or as an independent controller for particular processing, as explained in Section 8. The Terms of Service and applicable feature rules govern prices, membership obligations, acceptable conduct, the legal nature of Rewards, event risks and contractual consequences. This Policy governs our personal-data disclosures and choices; acceptance of the Terms is not, by itself, consent to optional or consent-dependent processing.

Our primary legal framework is Federal Decree-Law No. 45 of 2021 Concerning the Protection of Personal Data (the "UAE PDPL"), including Articles 4-6 on lawful processing, Articles 13-18 on data-subject rights, Articles 20-23 on security and transfers, and any binding implementing requirements. Additional privacy laws may apply based on where a user is located or how the Service is offered. Where those laws provide stronger rights, we will apply them to the extent required.

2. Eligibility and Age Assurance

The Service is intended only for individuals aged eighteen (18) or older. SocialFit does not permit individuals under eighteen to create or maintain an account, and parental or guardian consent does not make an under-eighteen individual eligible for the Service.

Explorer onboarding requires the Member to provide their date of birth and complete verification of the mobile number associated with the account. These measures form part of SocialFit’s age-assurance and eligibility process for the Explorer tier. Where applicable law or a particular risk requires stronger age verification, SocialFit may require an additional age-assurance step before permitting continued access.

Paid membership and specified higher-trust features additionally require government-issued identity verification through SocialFit’s approved identity-verification provider. SocialFit currently uses Didit for this purpose through an integrated in-app verification flow.

Age assurance and identity verification are separate controls. An Explorer may therefore remain identity-unverified while still being required to satisfy the age-assurance requirements applicable to the Explorer tier.

Where SocialFit cannot reasonably establish eligibility, onboarding or access may be restricted or suspended. If we identify use by an individual under eighteen, we may restrict the account and delete or isolate the associated personal data, except for minimum records reasonably necessary for safeguarding, fraud prevention, legal claims or preventing repeat registration.

3. Personal Data We Collect

We collect data directly from you, automatically from your device and use of the Service, from members who nominate or interact with you, and from approved service providers. The data collected depends on your relationship with SocialFit and the features you choose to use.

3.1 Application, nomination, and onboarding data

  • Identity and contact data: name, email address, telephone or WhatsApp number, age confirmation, city or area, and professional or public-profile identifiers.
  • Application context: your responses about what you are known for, how you contribute to the community, why you wish to join, availability, interests, and membership-tier preferences.
  • Nomination and referral data: nominator or referrer details, relationship context, nomination acknowledgement, and information a nominator provides about you. We will identify the source where required and will not treat third-party statements as verified facts.
  • Permissions and choices: records of notices shown, consent provided or withdrawn, featured-profile preferences, communication choices, and visibility settings.

A WhatsApp number collected for onboarding is used for time-sensitive token delivery, account or safety communications, and member-requested network routing. It is not used for promotional broadcasting unless you separately opt in.

3.2 Account, profile, Story, and Signal data

  • Account and profile data: Philia ID, username, profile image, biography, membership status, professional context, geography, interests, boundaries, preferences, connections and account settings.
  • SocialFit Story: self-declared reflections and StoryBuilder responses, including Worlds, values or archetypes where used, life chapter, social rhythms, needs, goals and boundaries. These declarations may change and are not verified statements about personality.
  • Live Signals: expressions of present intent about people, activities, energy, timing and interactions sought or avoided, as further described in Section 3.9.
  • Member content: messages, posts, responses, invitations, RSVPs, feedback, and other content you share within a Room, Pod, event, or direct interaction.

Stories and Signals describe changing context; they are not intended to define fixed personality traits. Members control whether and how relevant elements are surfaced, subject to essential safety and service controls.

3.3 Interaction, matching, and inferred data

We derive aggregate Experiential Contribution and Social Capital Contribution signatures, contextual relational patterns, confidence or sufficiency indicators, curation-relevance indicators and other probabilistic inferences from permitted declarations, current intent, interactions and Relational Feedback. These remain personal data whenever linked or linkable to a Member. They are not objective statements about personality, character, safety or future behaviour. The different Platform Systems and their effects are explained in Section 6.

3.4 Location data

StoryBuilder may collect location information that a Member chooses to provide about where they live, work or frequently spend time. SocialFit may process these locations through approved mapping or geocoding services and convert them into coordinates, approximate geospatial cells or similar location references.

These location references may be used to assign or route a Member to a Home Pod or related Pod field, support proximity-based routing, identify contextually relevant people, Rooms, Scenes or other experiences, and provide location-relevant Service functionality.

StoryBuilder location information is distinct from live device location. Ordinary Pod assignment does not require continuous GPS or background device-location tracking.

Where a particular feature requires precise device location, SocialFit will request the relevant device permission or another clear affirmative choice and explain the purpose before collection. Members may withdraw device-location permission through their device or available account settings.

We do not use precise location for unrelated advertising.

3.5 Identity-verification data

Government identity verification is not ordinarily required for the Explorer tier. Paid membership and specified higher-trust features may require identity verification through an approved provider.

SocialFit currently uses Didit as its launch identity-verification provider. Verification is completed through an integrated in-app flow. Depending on the verification checks enabled, Didit may process government identity-document information, document images, facial images, selfies, biometric or liveness information, and related verification attributes necessary to establish identity or eligibility.

P Labs determines why verification is required for the SocialFit Service and seeks to receive only the minimum verification information reasonably necessary to operate Philia ID, membership eligibility, trust controls and fraud-prevention measures. Such information may include verification status, an age or identity-match result, provider reference and relevant liveness or assurance status where supplied.

Where the verification process is completed entirely through the provider’s verification environment, P Labs does not intentionally retain raw copies of government identity documents or biometric templates within SocialFit’s core application systems.

Identity verification confirms only the information established through the applicable verification process. It is not a criminal-background check, professional vetting service, character assessment, endorsement of the Member or guarantee of the Member’s conduct or safety.

The verification provider applies the retention and deletion configuration applicable to the production verification flow. P Labs periodically reviews those settings and requires verification information to be retained only for as long as reasonably necessary for the applicable verification, fraud-prevention, legal or security purpose.

3.6 Voice and Ask SocialFit data

Microphone access is activated only when you initiate a voice feature and grant device permission. Raw audio is processed to transcribe or complete the requested feature and is deleted after successful processing. A transcript, vector representation, or resulting Signal may be retained where needed to provide the feature; it then follows the retention period for the relevant Story, Signal, or account data.

3.7 Payment and transaction data

Stripe is our payment provider for paid services. Stripe processes payment credentials, billing, authentication and fraud-screening information; P Labs receives transaction status, amount, currency, date, provider reference, billing details, subscription, refund and dispute records, and tax or invoice information rather than full payment credentials. Stripe may act as our processor for payment services and as an independent controller for certain fraud-prevention, authentication, regulatory and payment-network purposes. Its privacy notice is available at https://stripe.com/privacy. Reward credits with a financial or billing effect are recorded with the relevant transaction.

3.8 Device, usage, cookie, and support data

  • Technical data: IP address, device or browser type, operating system, app version, session and authentication identifiers, crash data, security events, and timestamps.
  • Usage data: screens or features used, interaction sequence, referring page, performance diagnostics, and aggregate service metrics.
  • Support and communications: messages to our team, reports, complaints, survey responses, call or meeting notes, and records needed to resolve a request.

3.9 Present Intent, Pulse and Current State

Where enabled, we process Signals, Pulse, current receptivity, availability, reach, Room activity and temporary visibility settings.

Pulse is a periodic current-state input that may reflect temporary context such as availability, receptivity, energy or present social intention. Subject to the Member’s choices and applicable Service rules, Pulse may support Signal matching, Circle functionality, Room or Scene relevance, Pod routing and other current-context features.

Signals and Pulse represent changing context. They are not intended to define a permanent personality trait, psychological assessment or continuing consent. A current Signal, Pulse or receptive status does not override a block, do-not-match choice, consent withdrawal or other applicable Member control.

3.10 Interaction records and Relational Feedback

Interaction records include Philia-mediated meetings, introductions, invitations, mutual connections, Philia Taps or check-ins, repeat interactions, expressly created Circle relationships, Room and Scene participation, and member-to-member controls. After a confirmed interaction, directed Relational Feedback may include experiential contributions such as Warmth, Energy, Insight or Opportunity; social-capital contributions such as Bonding, Bridging or Linking; neutral responses indicating insufficient experience; and pair-specific meet-again preferences. Feedback is subjective, contextual input and is separate from a safety report.

A Circle is a Member-controlled relationship layer through which a Member may expressly establish or manage selected relationships for supported SocialFit functionality. Circle status does not automatically expose another Member to the full contents of a Member’s Story, Signals, Pulse, individual Relational Feedback, safety information or other private account data. Access and use remain subject to applicable feature permissions, Member choices and governance controls.

3.11 Safety, integrity and operational reliability

Safety and integrity data includes blocks, do-not-match controls, safety reports, moderation cases, restrictions, one-time-password abuse, suspicious device or account patterns, duplicate-account indicators, fraud telemetry and investigation evidence. Separately, operational reliability data includes RSVPs, check-ins, attendance, late cancellations, verified no-shows, severe lateness, hosting history and participation restrictions. Reliability controls are not public scores; an attendance failure does not automatically mean that a Member is unsafe.

3.12 Philia Keys and Rewards

Philia Key records may include issuer, designated nominee, issuance and expiry timestamps, activation, revocation, return or snap-back to the Vault, direct nomination lineage and misuse indicators. SocialFit does not create multi-generational economic attribution. Where Rewards are enabled, we process Bonus Keys, Signal Boost entitlements, membership or contribution credits, eligibility, issuance, use, expiry, reversal and fraud controls. Ordinary Relational Feedback answers are not directly rewarded. Reward conditions and legal character are governed by the Terms and feature rules.

3.13 Social Perception

Where enabled, Social Perception processes inviter details, invited contributor contact information, submitted relational input, moderation status and the element displayed privately in Philia ID. Before collecting input, the invitation explains who initiated it, the source of the data, its intended use, visibility and applicable choices. An invitation is not consent to marketing. Contact information must be supplied lawfully and used only for the disclosed invitation purpose.

4. Sensitive Personal Data and Consent

Story, Signal, relational, or psychographic data is not automatically classified as Sensitive Personal Data solely because it concerns relationships or wellbeing. It may, however, contain or reveal information about health or psychological condition, family, religious or philosophical beliefs, racial or ethnic origin, biometric identity, criminal history, or other data protected as Sensitive Personal Data under the UAE PDPL. Because the risk can be high even when the statutory category is uncertain, P Labs applies heightened controls to the full Story-and-Signal dataset.

Where consent is required, we seek a clear, specific, informed, and separate affirmative action. We maintain a record of the notice, purpose, date, and consent status. Separate choices are used, where relevant, for sensitive-data processing, precise location, microphone access, marketing, featured profiles, and optional research or product-learning activities. Consent can be withdrawn through available settings or by contacting us. Withdrawal does not affect processing already lawfully completed, but it may prevent features that necessarily depend on the relevant data.

We do not bundle sensitive-data, location, microphone, public-profile, marketing or optional-research choices with acceptance of the Terms. Consent records include the notice version, purpose, timestamp, status and withdrawal. Before Relational Feedback is submitted, a concise notice explains confidentiality, permitted uses, the absence of public ratings, handling of meet-again preferences and the separate safety-reporting channel. Feature-level notices also apply to Social Perception invitations, Scene photography and non-essential analytics.

5. Why We Use Personal Data and Our Legal Grounds

Under Articles 4-6 of the UAE PDPL, we obtain consent unless an applicable statutory exception permits processing without it. Contract-related processing is limited to what is necessary to perform the membership agreement or take requested pre-contractual steps; legal obligations, legal claims and protection of Data Subject interests are relied on only where the relevant statutory conditions are met. Sensitive Personal Data must also satisfy the applicable statutory conditions. The principal purposes and grounds are set out below.

  • Application and onboarding: to assess eligibility, process direct nominations, communicate outcomes and issue or activate Philia Keys, based on steps requested before membership or consent where that exception does not apply. Meaningful human review is required for the limited Origins cohort; other application workflows may include automated eligibility or routing controls subject to Section 6.
  • Account and membership administration: to establish Philia ID, maintain declared information, administer entitlements and provide requested features, on the basis of necessary contract-related processing. Optional uses and consent-dependent sensitive-data processing require separate consent.
  • Signal matching and Scene curation: to identify fit for present intent and compose eligible groups or experiences, using necessary contract-related processing for the requested feature and separate consent for optional or consent-dependent inputs. Relational Feedback and contribution signatures support contextual curation only to the extent necessary for the requested relational service; otherwise we obtain consent before the additional use. We document necessity, protect confidential third-party input and do not treat ordinary curation relevance as a safety finding.
  • Interaction and event administration: to manage Philia-mediated meetings, invitations, Rooms, Scenes, check-ins and requested accessibility arrangements, based on necessary contract-related processing and consent for sensitive information where required. Safety-related disclosures require an applicable legal ground and are limited to the incident.
  • Operational reliability: to verify attendance facts, administer participation and hosting controls, and resolve attendance disputes, based on necessary contract-related processing or the applicable legal-claims exception. We separate these records from safety findings and provide a route to challenge material factual errors.
  • Philia Keys and Rewards: to record direct nomination provenance, manage eligibility and entitlements, issue or reverse Rewards and prevent misuse, based on necessary contract-related processing; financial records also support legal accounting duties. Optional behavioural uses require consent where no statutory exception applies. We do not reward ordinary feedback answers or build multi-generational economic attribution.
  • Social Perception: to invite contributors and display the disclosed private Philia ID element when a Member chooses this optional feature. We obtain consent for optional profiling and sensitive-data processing where required, explain the invitation purpose to contributors before collection, and do not use invitation contact details for marketing.
  • Network trust and safety: to verify eligibility or identity, authenticate users, apply participation standards, prevent fraud or impersonation, investigate reports, protect members, and preserve evidence. Basis: performance of the user agreement, compliance with law, protection of the Data Subject's interests, and establishment or defence of legal claims, as applicable.
  • Service communications and support: to deliver authentication or transactional messages, answer requests, troubleshoot, and communicate material policy or service changes. Basis: performance of the user agreement, consent, and compliance with law, as applicable.
  • Payments and business administration: to process purchases, issue invoices, maintain records, prevent payment fraud, and meet accounting, tax, audit, and corporate obligations. Basis: contract and legal obligation.
  • Security and reliability: to monitor system health, detect attacks or misuse, investigate incidents, maintain backups, and enforce access controls. Basis: contract, legal obligation, and protection of users' interests, as applicable.
  • Improve and evaluate SocialFit: to test feature performance, calibrate system thresholds, measure fairness and safety, and improve usability. We use anonymized or aggregated data where reasonably possible. Identifiable or pseudonymous data is used only under a documented lawful basis and with additional safeguards; optional research uses separate consent where required.
  • Legal and emergency purposes: to comply with valid legal obligations, respond to competent authorities, protect vital interests, and establish, exercise, or defend legal claims. Basis: the applicable statutory exception under Article 4 of the UAE PDPL.

If we wish to use personal data for a materially different purpose, we will assess compatibility, update this notice, and obtain consent where required before that use.

6. AI, Profiling, the Trust or Relational Evidence Graph, and Human Agency

6.1 The Co-Pilot Rule

SocialFit follows a functional separation: the Measurement Spine measures defined system signals, the Governance Layer applies permissions and rules, and the AI Co-Pilot communicates permitted outputs. The Co-Pilot is not treated as an independent source of psychological truth. It is not authorized to diagnose users or create unrestricted psychological interpretations from raw narratives.

6.2 Contextual matching and profiling

The Signal Matching Engine may consider permitted Story declarations, present Signals, Pulse, availability, reach and visibility settings to route or rank contextual possibilities. The Scene Curation Engine may consider fit, eligibility, group context, contribution signatures and relevant participation controls to compose groups and experiences. The Trust or Relational Evidence Graph records contextual evidence from confirmed interactions, directed feedback and expressly created relationships to support longitudinal relational patterns. Relevant outputs may pass between these systems subject to purpose and access controls; none is a universal trust score.

6.3 Human choice and review

Platform Systems may influence visibility, routing, Scene invitations, hosting privileges, Reward eligibility and operational restrictions. Members choose whether to accept an introduction, join or create a Room, attend a Scene or act on a recommendation. Urgent safety action may be taken promptly, with review where appropriate. We do not use solely automated processing to make decisions producing legal or similarly significant adverse effects. Applications for the limited Origins cohort receive meaningful human review; other Founder Key or Philia Key workflows may use automated eligibility and routing subject to these safeguards. Members may challenge material factual inaccuracies and seek human consideration for qualifying automated decisions under Article 18 of the UAE PDPL.

SocialFit does not publish a universal trust score or star rating. Relational Feedback, reliability information and safety records serve different purposes. A pair-specific preference, neutral insufficiency response or attendance failure is not automatically treated as a safety finding or a general judgment about the Member. Meaningful explanations of inputs, purposes and effects are available subject to protections for other Members and system security; this does not require disclosure of source code, model weights or proprietary thresholds.

6.4 Data boundaries and model-training restrictions

We minimise raw narrative and prefer structured signals for AI-assisted processing. Limited text may be processed by approved AI providers for Member-initiated features, moderation, support or security under confidentiality, access, restricted-retention and no-training controls. Private narratives and communications must not be entered into public or consumer-grade AI accounts. Approved providers are not permitted to use identifiable or pseudonymous SocialFit personal data to train or fine-tune general-purpose or foundation models. Any provider retention needed for the approved purpose is governed by documented limits; this is not a claim that all external text processing is prohibited or that every provider has zero retention.

Population-level learning is permitted only through properly governed processes. We prefer irreversibly anonymized or aggregated information. If information remains identifiable or pseudonymous, it continues to be personal data and may be used for evaluation or calibration only under a documented lawful basis, an approved impact assessment, access restrictions, and retention controls.

6.5 Non-clinical positioning

SocialFit supports social intelligence, relational coordination, and wellbeing. It is not a medical device, clinical service, crisis service, or substitute for medical, psychological, psychiatric, or emergency advice. This statement does not reduce the protection given to health or psychological information that may appear in user content.

7. Visibility, Member Sharing, and User Control

SocialFit does not publish full private Stories or raw Signals to an unrestricted public feed. Governance permissions, feature rules and Member settings determine which limited context is surfaced for a connection or experience. Individual Relational Feedback and one-sided meet-again preferences are confidential and are not ordinarily disclosed to the subject Member. Aggregate or derived patterns may affect future curation without exposing the responding Member or individual answer, subject to applicable rights and lawful disclosures.

  • Profiles and featured profiles: the fields and audience shown in the interface determine what other members or the public can see. Featured or public use requires a separate affirmative choice.
  • Introductions and matches: another member may receive a limited introduction, Signal, compatibility context, or invitation when permitted by settings and product rules.
  • Rooms, Pods and Scenes: shared content is available to the intended participants. Limited profile, relevant Signal, attendance and necessary accessibility information may be shared with attendees, hosts, authorised staff and venues for the particular experience. Member-hosted Rooms are distinct from P Labs-operated events. Scene photography or recording requires a separate notice and consent where required; attendance alone is not consent to promotional use. Participant copies and exceptions are addressed in Section 10.
  • Safety disclosures: limited information may be provided to a host, venue, responder, insurer, or relevant authority when reasonably necessary to manage an incident or protect people.

No community or partner insight product is authorised merely by this Policy. If introduced, it requires a prior notice and impact assessment; any partner output must be aggregated, thresholded and assessed against re-identification risk, excluding individual Signals, Pulse, Relational Feedback, safety records, Rewards and contribution signatures.

Privacy controls can be changed in account or feature settings where available. Some information must remain available to operate an active membership, maintain trust and safety, or comply with law.

8. When We Disclose Personal Data

We do not sell or rent personal data, disclose it to data brokers, or permit third parties to use it for their own targeted advertising. We disclose data only as reasonably necessary in these categories:

  • Other members and participants, according to Section 7 and your choices.
  • Service providers acting for P Labs, including cloud hosting, databases, communications, customer support, authentication, cybersecurity, analytics configured for service operations, identity verification, payments, document storage, and approved AI infrastructure. They receive only necessary data and are bound by confidentiality, security, purpose, deletion, and subprocessor terms.
  • Independent controllers, including Stripe for its independent purposes, the selected identity provider where applicable, insurers, venues, accessibility providers and professional advisers. Roles are assessed by purpose, not merely by vendor label; their own notices apply to processing they independently control.
  • Authorities and legal recipients, where disclosure is required by applicable law, a valid and proportionate legal process, or is necessary to protect vital interests, investigate serious misuse, or establish, exercise, or defend legal claims. We seek to verify requests and limit disclosure where legally permitted.
  • Corporate transaction recipients, in connection with financing, due diligence, merger, acquisition, restructuring, insolvency, or sale of all or part of the business, subject to confidentiality and continued privacy safeguards.

P Labs maintains a current internal register of processors and material subprocessors. Information about relevant recipient categories or transfer destinations may be requested through Section 16, subject to security and confidentiality limitations.

9. International Transfers

P Labs operates from the UAE and may use providers or personnel located in other countries. Personal data may therefore be accessed, stored, or processed outside the UAE. Before a transfer, we assess the destination, recipient, data category, purpose, and available safeguards.

Transfers are made in accordance with Articles 22 and 23 of the UAE PDPL, including to an approved adequate jurisdiction or under another permitted mechanism. Depending on the circumstances, safeguards may include a binding data-transfer agreement requiring UAE-equivalent protections, processor and subprocessor controls, encryption, pseudonymization, access restrictions, transfer-risk review, or express consent where legally valid and appropriate. We do not describe a contract as an official UAE standard clause unless it has been formally recognized as such.

Our transfer register records the recipient, country, data categories, purpose, legal mechanism and safeguards. Overseas access by personnel, contractors or support teams is treated as a transfer where applicable and governed by least privilege, logging, device controls, confidentiality and time-bound access. Production processing locations and material providers must be confirmed in the applicable notice: these may be requested through Section 16, subject to security and confidentiality limitations.

10. Retention and Deletion

We keep personal data only for the period reasonably necessary for the purpose collected, and then delete or irreversibly anonymize it unless law, safety, dispute, or evidence-preservation requirements justify longer retention. The following periods apply unless a just-in-time notice specifies a shorter period.

  • Rejected, withdrawn, or unclaimed Founder Key applications: deleted within 30 days after the applicant is notified, the application is withdrawn, or the relevant review wave closes, unless a fraud, safety, legal, or suppression record must be retained.
  • Active account, profile, Story, Signals, and Trust or Relational Evidence Graph outputs: retained while the account is active and the data is needed for the requested service. Following verified deletion or closure, the data is removed from active systems within 30 days, subject to the exceptions stated below.
  • Rooms, Pods, invitations, and event records: retained while needed for the interaction and account functionality. User-deleted content is removed from active display, although limited records may remain for safety, disputes, participant integrity, or legal claims.
  • Raw Ask SocialFit audio: deleted after successful transcription or completion of the initiated feature. Any retained transcript, vector representation, or resulting Signal follows the retention period applicable to the relevant account feature.
  • Identity-verification records: the minimum verification status or reference is retained while needed for an active trust level, then deleted or de-linked within 30 days after account closure unless law or an unresolved incident requires longer. The identity provider applies its own retention policy to data it independently controls.
  • Technical and security logs: normally retained for up to 12 months. Incident-specific logs may be retained longer while an investigation, security obligation, or legal claim remains active.
  • Support, complaints, and rights requests: normally retained for 24 months after closure to demonstrate resolution, unless a longer period is required for a legal claim or compliance record.
  • Payment, invoice, accounting, and tax records: retained for the legally required period, generally at least seven years following the end of the relevant UAE tax period for applicable corporate-tax records.
  • Backup systems: Personal data removed from active systems may remain in encrypted backup rotation for up to 60 days. Backup information is not restored for ordinary operational use. Where restoration becomes necessary for security, disaster recovery or another legitimate purpose, restored information remains subject to the applicable deletion and access controls.
  • Irreversibly anonymized data: may be retained for service measurement, statistical analysis, safety evaluation, and system improvement because it no longer identifies a person.

Deletion from active systems does not require P Labs to delete information that another member lawfully controls, or records that must be preserved for tax, fraud prevention, safety, regulatory, or legal-claim purposes. Any retained exception is isolated, access-restricted, and used only for that exception.

Relational Feedback and graph records: following account deletion, feedback given by or about the departing Member, pair-specific edges and aggregate contribution signatures are deleted, irreversibly anonymised or de-linked within the applicable active-system deletion period, unless a documented lawful exception requires limited retention. De-linking is not anonymisation if the record remains reasonably re-identifiable; such records continue to receive personal-data protection.

Account deletion will not leave an active, secretly identifiable Member profile in the Trust or Relational Evidence Graph. Any retained safety, fraud, dispute or legal record is isolated from ordinary matching and curation, access-restricted and used only for the applicable exception.

Operational reliability records: Attendance, lateness, verified no-show, cancellation and similar operational reliability records are normally retained for 12 months after the relevant event or activity. Where an active restriction, dispute, investigation or legal claim remains unresolved, the minimum information necessary may be retained until resolution and is then deleted or irreversibly aggregated unless another lawful retention requirement applies.

Philia Key and Reward records: A Philia Key is consumed upon successful redemption and does not remain an ongoing entitlement. P Labs retains only the minimum provenance and audit information reasonably necessary to record the direct issuer or nominator, recipient or redeemer, issuance date, redemption, expiry or revocation date, status and relevant misuse or fraud indicators.

Such records are normally retained for 24 months following redemption, expiry or revocation, unless longer retention is reasonably necessary for an active fraud investigation, dispute, legal claim or other documented legal requirement. SocialFit does not retain multi-generational nomination chains merely because a Key has existed.

Safety case records: An unsubstantiated safety report is normally retained for 12 months after case closure and remains classified as unsubstantiated rather than as an established misconduct finding, a closed low-risk safety case is normally retained for 24 months after case closure. A substantiated serious safety case may be retained for 5 years after case closure, and for longer only where continued retention is reasonably necessary for safeguarding, prevention of prohibited re-registration, an active or reasonably anticipated legal claim, lawful authority request or another documented legal requirement.

Where SocialFit maintains a suppression record to prevent a banned or seriously abusive individual from re-registering, the record is limited to the minimum identifiers necessary for that purpose and is kept separate from ordinary matching and curation systems.

Social Perception and invitation data: Where Social Perception is enabled, contact information associated with an invitation that is not accepted is deleted within 30 days after the invitation expires or is otherwise closed, unless another lawful basis requires limited retention. Submitted input follows the retention applicable to the relevant Social Perception feature and Member account.

11. Cookies and Similar Technologies

We currently use essential cookies, local storage, authentication tokens, and similar technologies needed to log users in, maintain sessions, remember core settings, prevent fraud, balance traffic, and operate the Service. These technologies cannot always be disabled without affecting functionality.

We do not currently use third-party advertising cookies, social-media advertising pixels, or cross-site tracking for targeted advertising. If we introduce non-essential analytics or marketing technologies, we will update this Policy, provide a preference mechanism, and obtain consent where required before activation.

12. Security and Personal Data Breaches

P Labs maintains technical and organizational measures proportionate to the nature, volume, context, and risk of the processing. Measures may include encryption in transit and at rest, role-based access control, least-privilege permissions, environment separation, secrets management, authentication controls, logging and monitoring, vendor due diligence, staff confidentiality, secure development practices, backup controls, and periodic access review. Security measures evolve and no internet service can guarantee absolute security.

Graph-specific safeguards include purpose-based separation of Relational Feedback, operational reliability and safety datasets; restricted moderator access; graph access controls; audit logging; controls against bulk discovery or enumeration of Member records; approved-provider no-training configurations; and periodic privilege reviews.

We maintain an incident-response process to identify, contain, investigate, document, remediate, and learn from suspected personal data breaches. Where a breach is likely to prejudice privacy, confidentiality, or security, P Labs will notify the UAE Data Office and affected Data Subjects in the form and timeframe required under Article 9 of the UAE PDPL and applicable implementing requirements. Notices will describe the nature and likely impact of the incident and the protective steps taken or recommended, to the extent legally permitted.

Users should protect their credentials, use device security, and report suspected account compromise promptly. Do not include information about another person in a Story, Signal, Room, or Pod unless there is a lawful and respectful basis to do so.

13. Your Rights and Choices

Subject to legal conditions and exceptions, Articles 13-18 of the UAE PDPL provide rights to obtain information, receive or request transfer of personal data, correct or erase data, restrict or stop processing, and object to qualifying automated processing. Where applicable, you may:

  • request confirmation and information about the personal data, purposes, decisions involving automated processing, recipients, retention controls, transfer safeguards, and breach response;
  • receive eligible data in an orderly, machine-readable format or request transfer to another controller where technically feasible;
  • correct inaccurate or complete incomplete personal data;
  • request erasure where the data is no longer needed, consent has been withdrawn and no other basis applies, or processing is unlawful;
  • request restriction or cessation of processing in circumstances provided by law, including direct marketing;
  • withdraw consent for a specific purpose; and
  • object to a decision based solely on automated processing, including profiling, where it produces legal consequences or seriously affects you, and request human consideration where available.

You may also seek meaningful information about matching, Scene curation, profiling and significant automated effects; correct inaccurate declared information; challenge material factual attendance or reliability data; and withdraw optional consent. Access is assessed alongside other Members' privacy, safety, confidentiality and legal rights. It does not automatically entitle a Member to another person's identity, confidential feedback, one-sided preference or safety report. Where necessary, we provide a summary, redacted information or another meaningful explanation without exposing protected third-party content.

13.1 How to exercise a right

Send a request through the in-app privacy route, if available, or the email in Section 16. State the right requested and the relevant account email or telephone number. We will acknowledge a complete request as soon as reasonably practicable, ordinarily within five business days, and respond within the period required by applicable law. We may ask for proportionate identity verification and clarification necessary to locate the data.

We do not ordinarily charge for a rights request. We may limit or refuse a request where permitted by law, including where disclosure would prejudice another person's privacy, security, intellectual property, legal privilege, an active investigation, or a statutory obligation. If we cannot fully comply, we will explain the reason and available escalation route unless prohibited by law.

13.2 Marketing and communication choices

Transactional, account, security, and safety communications are necessary for the Service and are not marketing. Where we send optional marketing, you may unsubscribe through the message or account settings. We may retain a minimal suppression record so the preference remains effective.

14. Third-Party Providers and Member-Organized Activities

The Service may connect to third-party identity, payment, maps, communications, venue, event, or external-link services. When a third party independently determines why and how it processes data, its own privacy terms apply. P Labs is not responsible for an independent third party's practices, although we assess providers and integrations within our control.

Members participating in or organizing Rooms, Pods, or events may exchange information directly. Unless SocialFit expressly states otherwise, members are not appointed as P Labs employees, agents, or data processors merely because they participate. P Labs' participation rules and safety controls still apply to their use of SocialFit data.

15. Accountability, Impact Assessments, and Policy Changes

P Labs assigns privacy responsibility and maintains processing records, vendor reviews, consent records, retention decisions and incident records. Before launching or materially changing Relational Feedback, contribution signatures, systematic profiling, precise location, government verification, Scene curation, Social Perception, behaviour-linked Rewards or community insight products, we require documented privacy, security and fairness assessment. We assess and maintain any Data Protection Officer appointment required under Article 10 of the UAE PDPL.

We may update this Policy to reflect changes in law, product design, providers or processing. Material changes will be communicated prominently in advance through the Service, email or an equivalent channel, with any legally required exception explained. Renewed consent will be obtained before a materially different purpose or consent-dependent activity begins where required. Changing the displayed date or continued use of the Service does not replace a required consent choice.

16. Contact and Complaints

Privacy questions, rights requests, complaints, and suspected incidents should be sent to:

P Labs FZE
Registered address: Ajman Free Zone (AEZ), Ajman, UAE
Privacy contact / DPO: Akshay
Email: privacy@social.fit For routing, use the subject line: “Legal / Privacy Operations - SocialFit”.

We ask that you contact P Labs first so we can investigate and respond. You may also submit a complaint to the UAE Data Office or another competent authority where applicable.

© P Labs FZE · SocialFit

Privacy Policy Terms ← Back to SocialFit