Legal
Last updated: 20 September 2026
This policy explains what personal data DUNE collects, why we collect it, who we share it with, how long we keep it, and what control you have over it. We have written it in plain language rather than legal boilerplate, because a policy nobody reads protects nobody.
DUNE (“DUNE”, “we”, “us”) is a platform that lets adults discover and book companionship services and host or attend social events.
This policy explains what personal data we collect, why, who we share it with, how long we keep it, and what control you have over it.
DUNE is a product of Vauxer Enterprises Private Limited. Vauxer operates the service, publishes the app, arranges for payments to be collected and disbursed through a third-party payment partner, and is responsible for your data — it is the company you deal with for everything.
Vauxer is the Data Fiduciary for all the personal data described here.
Under India’s Digital Personal Data Protection Act, 2023 (“DPDP Act”), we are the Data Fiduciary for the personal data described here, and you are the Data Principal.
This policy also serves as our privacy policy under the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 and the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021.
This policy is governed by the laws of India, and the courts at Bhubaneswar, Odisha have jurisdiction over any dispute arising from it, subject to the dispute-resolution clause in our Terms of Service.
You must be 18 or older to create a DUNE account. We do not knowingly collect personal data from anyone under 18. If we learn that a user is under 18, we will suspend the account and delete the data.
If you believe a minor is using DUNE, tell us at support@dunexplore.com and we will act on it.
You can turn location permission off in your device settings. Sessions still work without it — but we recommend leaving it on, because it helps us resolve disputes quickly if one ever arises.
DUNE asks for these, and only these. Each is optional — you can refuse any of them, and the table says what stops working if you do. You can change your mind at any time in your device settings.
| Permission | What we use it for | If you say no |
|---|---|---|
| Camera | Taking profile photos, and the face and liveness check | You cannot complete verification, so you cannot book or be booked |
| Photos and media | Uploading photos you already have | You can still use the camera instead |
| Location — approximate and precise, and only while the app is open | Showing people and events near you; recording where each of you was when a session starts and closes; recording your position across an event | Discovery falls back to the city on your profile. PINs still work, sessions still start and close, and you can still attend events |
| Microphone — only during a voice call you start or answer | Voice calls in the 1-to-1 chat of a paid booking. Nowhere else — not in event chats, not when hosting an event, not from a profile | You cannot make or take voice calls. Everything else, including chat, works normally |
| Notifications | Booking requests, acceptances, chat messages, reminders, safety alerts | You will miss time-sensitive things — a request expires in 10 minutes |
| Google Play Billing | Nothing personal — it is how Gold and Elite are purchased | You cannot buy a membership. Everything else works |
DUNE has voice calling, and only in one place: the 1-to-1 chat of a paid booking, and only while that booking is still running. The moment it is cancelled, expires, is declined, or finishes, calling stops.
There is no calling anywhere else — not in event group chats, not when you create or host an event, not from someone’s profile, and not before a booking is paid for. There is no video calling at all.
We ask for the microphone at the moment you start or answer a call — never at signup. Say no and the call does not connect; nothing else in the app changes.
Calls are not recorded. The audio travels live through Agora (Agora Lab, Inc.), our calling provider, and is gone the moment it is delivered. Neither we nor Agora keep a copy, and there is no way for us to listen to a call, then or later.
We do keep a record that the call happened — who called whom, when, and how long it lasted — attached to that booking. We need it to settle disputes about whether a session took place, and to act on reports of abusive calls. It is kept with the booking record and never contains any audio.
The microphone is used only while a call is on screen. The app releases it as soon as the call ends, and it cannot record in the background — if you leave DUNE during a call, the call drops.
We never ask for background location. DUNE does not track you when the app is closed. Location is recorded only while you are using the app.
We never ask for your contacts, SMS, your phone’s call log, calendar, phone state, or any always-on sensor. The microphone is the one sensor we ask for, and only for the calls described above — it is never listening otherwise. We do not use an advertising ID — the app removes it explicitly, so you are not tracked for advertising anywhere on DUNE.
We ask at the moment the permission is needed, not all at once at signup, and we explain why before your device shows its own prompt.
| What we use it for | Data involved |
|---|---|
| Create and secure your account | Name, phone, email, password, device data |
| Verify you are a real, unique adult | Face scan, date of birth |
| Show you relevant people and events | Location, age, interests, preferences |
| Let others decide whether to meet you | Profile, photos, verification status, ratings |
| Run bookings — requests, timers, PINs, completion | Booking data, device data |
| Take payments and pay companions | Payment and payout data |
| Enable messaging on confirmed bookings | Messages |
| Connect voice calls inside a paid, running booking | Live call audio (not recorded); who called whom, when, and for how long |
| Safety: live location, reporting, blocking, moderation | Location, reports, messages, profile |
| Fraud prevention and enforcing our Terms | Most of the above |
| Notify you about bookings, messages and events | Push tokens, email, phone |
| Support | Tickets, booking history |
| Improve the app and fix bugs | Usage and error data |
| Meet legal, tax and regulatory obligations | Identity, payment, booking records |
Our lawful bases under the DPDP Act are your consent for most processing, and certain legitimate uses permitted by the Act — including compliance with law, and responding to a medical or safety emergency.
This is the most sensitive data on the platform, so we are specific about it.
We do not ask for a government identity document, and we do not collect one. No Aadhaar, no driving licence, no voter ID, no passport. Verification on DUNE is a face check and nothing else.
What happens. When you verify, our verification partner Amazon Rekognition (AWS) captures a short face scan on your device, checks that a live person is present, and compares it against your profile photos.
What it is for. Two things, and no others:
Where it goes. The scan is processed by our verification partner. We receive only the outcome — approved or rejected, a reference number, and the timestamp. We do not build or keep a face template, and we do not use face data for any purpose other than the two above.
What this verification does not do. It does not confirm your identity against any government record, and it is not a background check or a criminal-records check. A verified badge on DUNE means a real, live person who matches these photos, and who holds only this account. It does not mean we have checked who they are with any authority.
We never use face data for surveillance, advertising, or matching you against any external database.
Retention. Our verification partner retains data under their own published privacy policy and their contract with us. We keep only the verification outcome and reference, for as long as your account exists plus the period in section 9.
Consent. Verification is optional in the sense that you may decline it — but you cannot book or offer companionship without it, because it is what makes the platform safe. If you withdraw consent, we will delete the verification record and your account will lose access to bookings.
Other users never see your exact location. Discovery shows an approximate distance (“1.2 km away”) and your general area, never your coordinates or address.
Live location is shared only:
Live location is held briefly in memory to deliver it, then discarded. We do not keep a continuous history of your movements.
Where available, we keep two location records per booking. When you start a session and when you close it, we record where each of you was at that moment, and whether you were within 1 kilometre of each other.
This is recommended, not required. Your session will start and close normally whether or not location is switched on. But if a dispute later arises — about whether a meeting happened, when, or for how long — being able to show you were there puts you in a much stronger position. That is the whole reason we ask.
We keep only those two moments per booking — not the journey, and nothing in between. Retention is set out in section 9.
Events work differently from bookings, because there is a check-in but no check-out. Between an event’s start and end time, we record your position while the DUNE app is open. We do not track you in the background, and we do not record anything once the event’s end time passes.
This is recommended, not required. You can attend an event with location switched off, and check-in works either way. We ask because an event can run for up to 6 hours and only the host can check you in — so if a host fails to check you in, or an event is later disputed, this is the record that shows you were there.
What is visible on your profile to other users: your first name, age, photos, bio, city or area, interests, verification badge, rating and reviews, and whatever optional fields you filled in.
What is never visible to other users: your phone number, email address, date of birth, exact location, payment details, or the content of your conversations with anyone else.
Photo privacy is a paid monthly option that covers your face, or your eyes, in the photos other people see. Two things about it belong in a privacy policy:
The blurring is done by us, on our own servers. No third party receives your photos for this, and the covered copy is stored the same way as the original — see section 10.
We do not read your messages routinely, and no automated system reads them for advertising or profiling. Your conversations are not visible to other users and are not visible to our staff in the ordinary course.
A named member of our team may read the messages relating to a specific booking or event in these situations, and only these:
In every case we look at the conversation attached to that booking or event, not your message history at large. Access is logged. If we read your messages because of a report you were not party to, we will tell you unless doing so would compromise a safety investigation.
We share personal data only with the following, and only as needed:
| Who | What they get | Why |
|---|---|---|
| Other DUNE users | Your public profile; your live location during a meetup | To let people decide whether to meet, and to meet safely |
| Razorpay | Payment details | To process payments made by Requesters |
| Razorpay | Bank account number, IFSC code, and PAN | To pay out Companions |
| Amazon Rekognition (AWS) | Face scan | To confirm a live person, match your photos, and enforce one account per person |
| Resend | Phone number, email address | To send OTPs and notifications |
| Google Maps Platform (Google) | Approximate location | To show maps and meeting points |
| Agora (Agora Lab, Inc.) | Live call audio, and a temporary call token | To connect voice calls inside a booking. The audio passes through and is not stored — by them or by us |
| Railway (hosting) and Cloudflare R2 (file storage) | Data at rest and in transit | To run the service |
| Firebase Cloud Messaging (Google) | Device token | To send notifications |
| Analytics and crash reporting | Usage and error data | To fix and improve the app. We do not currently use any analytics, attribution or advertising SDK — if we add one, we will name it here first |
Each of these is bound by contract to use the data only for the service they provide to us.
We may also disclose data:
We do not sell personal data, and we do not share it for third-party advertising.
We store data on servers located in Asia (Singapore). Some of our service providers may process data outside India. Where they do, we require appropriate contractual protection, and we comply with any restrictions the Central Government notifies under the DPDP Act.
| Data | Retention |
|---|---|
| Account and profile | While your account is active |
| After you delete your account | 180 days, then deleted or anonymised |
| Verification records | Account lifetime + 180 days |
| Booking records | 7 years — needed for disputes and tax |
| Payment and payout records | 7 years — required by tax and accounting law |
| Messages, on an active account | 7 days after the booking or event closes, then deleted — unless the booking has been reported or disputed, in which case they are held until that is settled |
| Messages, when you delete your account | 15 days after deletion, then deleted |
| Live location (during a session) | Not retained |
| Voice call audio | Not recorded, not retained |
| Call records — who called whom, when, how long | Retained with the booking record (7 years) |
| Session start/close location proofs | Retained with the booking record |
| Reports, blocks and safety records | Retained after deletion where needed to keep other users safe |
| Support tickets | 3 years |
| Usage and error logs | 90 days |
The 180-day period after deletion is required of intermediaries under the IT Rules, 2021 and gives us a window to respond to investigations and disputes.
Some records must be kept even after you ask us to delete your account, where the law requires it (tax, financial records) or where deletion would let someone evade a safety enforcement action.
We should be direct about one thing, because it is a genuine limit on erasure.
DUNE allows one account per person, enforced by checking your face against existing users at signup. If you delete your account voluntarily, you are free to come back — we release your record and you can sign up again normally.
But if your account was removed for a serious violation — anything on the zero-tolerance list in our Community Guidelines — we retain a reference held by our verification partner that lets us recognise the same person attempting to register again. It is not a photograph and not a face template; we cannot reconstruct your face from it, and we do not use it for any other purpose.
We keep it because a safety removal that can be undone by deleting and re-registering protects nobody. If you believe you were removed in error, or matched incorrectly — this can happen with siblings and identical twins — contact our Grievance Officer, and a person will review it.
Under the DPDP Act you have the right to:
How to exercise them: in the app under Profile → Settings & privacy, or by emailing support@dunexplore.com. We will respond within 30 days. You can also request account deletion here.
We may ask you to verify your identity before acting on a request — this protects you from someone else making requests in your name.
If you have a complaint about how we handle your data, or about content or conduct on DUNE, contact our Grievance Officer:
We will acknowledge your complaint within 24 hours and resolve it within 15 days, as required by the IT Rules, 2021.
For data protection matters specifically, you may also contact our Data Protection Officer at support@dunexplore.com.
If you are not satisfied with our response, you may complain to the Data Protection Board of India.
No system is perfectly secure. If a breach affects your personal data, we will notify you and the Data Protection Board as the DPDP Act requires.
If we make a significant change, we will notify you in the app or by email before it takes effect. The “Last updated” date at the top always reflects the current version.
Questions about this page? Write to support@dunexplore.com.