HabrJuly 19, 2026🇷🇺Translated from Russian

Mimolet Dating App Shows Strong Data Protection Practices in Photo Handling, Moderation, and Infrastructure Review

The Russian dating platform Mimolet, which combines profile feeds, private chats, and public interest-based groups, has undergone a thorough examination of how it manages user data and unwanted content. The review analyzed everyday user flows, network behavior, and publicly available infrastructure details, concluding that the service implements several sound security practices while leaving room for greater transparency in two specific areas.

Photograph processing before storage is handled rigorously. When a user uploads an image, the server validates the file by its actual content rather than relying on the JPG or PNG extension. The image is decoded, metadata such as EXIF data (camera model, timestamps, and geolocation) is removed, dimensions are limited, and multiple optimized versions are generated for the mobile feed. Files that cannot be properly recognized as images are rejected outright.

The main server infrastructure is located in Russia. The core API and primary database operate within Russian data centers, while media files are stored in an S3-compatible object storage provided by a domestic cloud vendor. This separation keeps the database lean and allows efficient delivery of images to users.

AI-powered functions, including language processing, speech recognition, vector embeddings, and image moderation, primarily run on dedicated GPU infrastructure controlled by the Mimolet team. A fallback connection to external AI providers exists for redundancy, but the primary path remains internal and isolated via a private technical channel.

Images intended for profiles or public groups are checked before publication. Two distinct models analyze the content—one for prohibited visual material and another multimodal model for contextual meaning—while an additional pass can examine suspicious regions in greater detail. If a violation is confidently detected, the image is blocked and, in severe cases, the account and linked devices may also be restricted.

Complaints and blocking are available to every authorized user without a paid subscription. The reporting form offers structured categories such as scams, cryptocurrency schemes, intimate services, prohibited substances, and false information. Once submitted, the reported profile immediately disappears from the reporter’s feed, and accumulated signals from multiple users are escalated for human review.

Moderator actions are recorded in an administrative audit log that captures the decision, timestamp, and operator involved. This internal record supports later analysis of errors or disputed cases.

Built-in voice calls rely on WebRTC and internal identifiers rather than phone numbers, so users can speak without revealing personal contact details. The feature is disabled if either party has blocked the other.

Two areas were flagged for improvement. The privacy policy uses vague phrases such as “no longer than necessary” and “within a reasonable time,” leaving users without concrete retention periods for photographs, chat history, moderation records, or AI conversation data. The review recommends publishing a clear table listing data categories, processing purposes, retention periods, and post-deletion behavior. Additionally, the appeals process for blocked accounts lacks a dedicated form with a reference number, status tracking, and expected response time, making it difficult for users to follow the progress of their request.

Overall, Mimolet demonstrates several proactive security measures—metadata stripping, pre-publication image checks, subscription-free reporting, and Russian-hosted core infrastructure—that are integrated directly into the user experience rather than added as afterthoughts. The main shortcomings lie in transparency around data retention and the appeals workflow, both of which could be addressed with relatively modest updates.

Related articles

AntiMalwarePrivacy & Surveillance

VPN Services Stabilize in Russia? Expert Warns Users Not to Relax as New Blocks May Be Coming

Russian users have recently noticed that personal VPN services and anonymizers are operating more stably after months of aggressive disruptions. Technical director Sergey Shcherbakov of the company Stakhanovets explains that the current improvement is likely only a temporary pause while deep packet inspection systems recalibrate. Earlier this year, DPI equipment was blocking traffic based on crude digital fingerprints of protocols such as OpenVPN and WireGuard, causing widespread collateral damage and connection drops. Operators are now believed to be collecting detailed data on ports, reconnection patterns, and obfuscation techniques to build more precise filters. Shcherbakov predicts the next wave of restrictions will arrive by late summer or early autumn, possibly shifting from outright blocks to throttling speeds during peak hours and delaying large file transfers. Meanwhile, users have adapted by maintaining multiple VPN clients, switching protocols and ports, and enabling obfuscation when needed.

HabrPrivacy & Surveillance

Mimolet Dating App Review Highlights Privacy Protections, AI Moderation, and UX Trade-Offs in Detailed Analysis

A comprehensive review of the Mimolet dating application examines its registration process, vertical profile feed, free filters, and advanced communication tools including built-in calls and AI-assisted messaging. The analysis praises detailed profiles visible directly in the feed, free access to comprehensive search criteria, and strong privacy measures such as automatic EXIF metadata removal from photos and primary data storage within Russian server infrastructure. It also covers public interest-based groups, pre-publication image moderation using multiple AI checks, and transparent complaint handling that does not require a subscription. Concerns are raised about lengthy registration potentially reducing user completion rates, the inclusion of weight as a searchable filter, unclear data retention timelines, and the lack of a formal appeals process for blocked accounts. The app offers three paid tiers focused on visibility and extra AI features while keeping core communication and moderation tools free, with approximately 200,000 registrations and 15,000 daily active users reported alongside retention rates of 44.96% at day three and 19.11% at day thirty.

securitylab_nPrivacy & Surveillance

69% of Browsers Worldwide Vulnerable: How Chrome Sync Enables Stealth Surveillance Without Malware

Google Chrome's standard synchronization feature can be silently abused to turn any browser into a surveillance tool, requiring only brief physical access to a victim's device and the addition of an attacker's Google account. Security researchers at Certo highlighted the technique after multiple cases involving intimate partner surveillance, including one incident where a woman’s visits to a family lawyer and domestic abuse support sites were monitored in real time by her partner. Once sync is enabled, browsing history, bookmarks, open tabs, autofill data, and saved passwords are automatically transmitted to the attacker’s profile, which can be viewed from any device worldwide without needing the victim’s password or installing spyware. Chrome provides no prominent warnings about new profiles or active synchronization, and alerts about logins are sent only to the account owner rather than the device owner. With Chrome holding a 69.65% global market share according to StatCounter data from June 2026, the method potentially affects millions of users on Android, iOS, Windows, and macOS. Experts recommend regularly checking connected profiles in browser settings, using Incognito mode for sensitive activity, securing devices with strong passcodes and biometrics, and immediately removing unknown accounts while changing important passwords.

securitylab_nPrivacy & Surveillance

Russia's МВД Proposes Mandatory Purchase of Special Smartphones for Migrants to Enable Permanent Digital Location Tracking

Russia's Ministry of Internal Affairs is advancing plans to replace paper-based migration controls with continuous digital surveillance by requiring labor migrants to purchase a dedicated smartphone upon entry. Deputy Minister Igor Zubov announced that the device would create an electronic profile allowing police to monitor the owner's movements in real time and prevent unauthorized relocation between regions. The initiative builds on the existing "Amina" app already mandatory in Moscow and the Moscow region since September 2025, which has already led to more than 139,000 migrants being removed from registration. From July 2026, all visa-free foreigners must use the RuID app to create digital profiles, while a unified МВД database containing documents, employment, housing, fines, and phone numbers is already operational. The new proposal differs from current rules by making the purchase of a government-specified device a condition of entry rather than simply installing software on an existing phone. Human rights advocates, including Svetlana Gannushkina, have previously criticized similar ideas, noting that forcing migrants to buy expensive devices is unlawful given financial and technical barriers. The plan remains a future proposal and has not yet been enacted into law.