We know dating apps require trust. Tangles protects your data using industry-standard security practices across our app, APIs, and infrastructure. This page explains what we do—and what you can do—to keep your account safe.
How we protect your data
Transport security
- All traffic uses HTTPS (TLS 1.2+) between your device and our servers.
- Modern cipher suites; HSTS on production domains.
Encryption at rest
- Databases and backups are encrypted at rest by our cloud provider.
- Sensitive fields (e.g., auth tokens) are additionally protected in the application layer where appropriate.
Password & login safety
- Passwords (if used) are hashed with
bcrypt—never stored in plain text. - Phone, Facebook, and X logins use short-lived codes or OAuth with scoped permissions.
- Session cookies are HttpOnly and use SameSite protections.
Account verification
- Email verification and SMS code flows help prevent account takeovers.
- Abuse and fraud checks detect suspicious sign-ins and spam behavior.
Access controls
- Role-based access for staff; access is logged and reviewed.
- Production data access is limited to authorized personnel for legitimate support needs.
Security by design
- Input validation, rate limiting, and CSRF protections on sensitive routes.
- Regular dependency updates and vulnerability scanning.
Privacy & data use
- Data minimization: we ask only for what’s needed to run the service (e.g., email or phone to log in, profile info you choose to share).
- Your control: you can edit or delete profile info at any time from Settings.
- No selling of messages: your private messages are not sold to advertisers.
- Third parties: we use trusted providers (e.g., for SMS, email) strictly to deliver Tangles features.
See our Privacy Policy for full details on data categories, purposes, and retention.
How you can keep your account safe
- Use unique credentials: Don’t reuse passwords from other sites. If you log in with phone, keep your number secure.
- Verify before sharing: Never send money or sensitive info (ID numbers, banking, codes). Meet in public places.
- Beware of off-platform moves: Scammers push to email/WhatsApp/crypto quickly. Report suspicious behavior in-app.
- Lock your device: Use a screen lock and keep OS/browsers updated.
- Check the URL: Only sign in on our official domain; look for
https://.
Common questions
Are my messages end-to-end encrypted?
Messages are encrypted in transit and stored securely on our servers so we can deliver them and enforce our safety policy (e.g., spam/scam investigations). Do not share highly sensitive information in chat.
Who can see my profile?
You control what’s on your profile. Use visibility and block/report tools to manage who can interact with you.
How long do you keep my data?
We retain account data as long as needed to provide the service and meet legal requirements. You can request deletion in Settings—some records (e.g., fraud logs) may be retained where required or permitted by law.
Report a security issue
If you believe you’ve found a vulnerability or your account has been compromised:
- Email our security team: security@tangles-llc.com
- Include steps to reproduce and any screenshots or request IDs (no sensitive data, please).
© 2025 Tangles LLC • Back to Help Center