Privacy Policy

Effective date: October 5, 2026 (2026-10-05)

The short version

1. Who we are

Soulfia (also styled SOULFIA) is a mobile app for iPhone and Android that creates personalized guided meditations. It is developed and operated by Nicholas Robinson, an individual developer (“we”, “us”, “our”). We are responsible for the personal information described in this policy.

This policy covers the Soulfia app and the online services behind it. It explains what we collect, why, who helps us process it, how long we keep it, and the choices you have. If you have questions, email roycerobins95@gmail.com.

You can open this policy, the Terms of Use and account deletion at any time in the app under Profile > Settings.

2. Information we collect

Account information

Your display name is the name you entered at sign-up, or the name Apple shared. If you sign in with Google, you have no display name. Your display name and avatar are shown with any meditation you make public (see section 6).

If you sign in with Google, your Google profile photo is shown publicly next to any meditation you publish, even though your name is not. The app cannot change or remove it yet. Email roycerobins95@gmail.com and we will remove it.

What you tell us to create a meditation (“intake”)

Intake answers can describe your mood, emotions and personal circumstances. Please share only what you are comfortable with. We store your answers with the meditation they produced.

Content we generate for you

Listening activity

When you are signed in and play a meditation that another member published, we record that your account played it and when. We use this to count plays: each listener is counted at most once per meditation every 30 minutes. Creators see only the total play count, never who listened. Playing your own meditations is not recorded this way.

Your AI permission

When you allow the app to send your answers to our AI providers (see section 4), we store the time you agreed and which version of the explanation you agreed to. If you withdraw your permission, we clear both.

Reports and hidden creators

Purchases and subscription status

Purchases are made through the App Store or Google Play and managed with RevenueCat. The RevenueCat software in the app runs for everyone who opens the app: under an anonymous RevenueCat ID until you sign in, and under your Soulfia account ID after that. We receive and store your subscription status: whether you have Premium, which product you bought, whether it is a trial, renewal and expiry dates, and your RevenueCat customer ID (normally linked to your Soulfia account ID). We never receive your card number or other payment details.

Device and notification information

Usage analytics (PostHog)

We use PostHog to understand how the app is used. The app sends basic app events, such as when the app is installed, updated, opened or moved to the background, along with device and app details (for example device model, operating system, app version, language and time zone). The app removes links and web addresses from these events before they are sent, so a link that opens the app, such as the link in a sign-up confirmation or password reset email, is not sent to PostHog. PostHog gives the app on your device a random identifier; once you sign in, events are also linked to your Soulfia account ID. PostHog receives your IP address with these events and uses it to estimate an approximate location, such as your country or city. We do not send your name, email address, intake answers or meditation content to PostHog.

Crash and error reports (Sentry)

When the app crashes or hits an error, a report is sent to Sentry. It includes technical details about the error, your device model and operating system, the app version, recent technical app activity leading up to the error (such as network requests the app made), and your Soulfia account ID if you are signed in. Sentry also receives a small session record each time you open the app, even if nothing goes wrong: the app version, your device and operating system, whether the session ended in a crash, and your account ID if you are signed in. We use this information only to find and fix problems and to measure how stable the app is.

Server logs

Our servers log technical events, such as when a meditation was requested, finished or failed, together with account and meditation identifiers. Our hosting provider also records your IP address and device or browser type (user agent) when the app connects to our servers and when you sign in. The logs are designed to record identifiers and technical details, not your intake answers or meditation text.

Messages you send us

If you email us, we keep your message, your email address and our reply so we can help you.

What we do not collect

The app does not access your precise location, contacts, photos or microphone. We do not use advertising identifiers, and we do not track you across other companies’ apps or websites.

3. How we use information

We do not sell your personal information. We do not share it for targeted or cross-context behavioral advertising, and the app contains no ads. We do not use your intake answers or meditations for marketing.

4. How AI creates your meditation

Each time you create a meditation:

  1. Script (OpenAI). Your intake answers, chosen length and guidance style are sent to OpenAI, which writes the meditation script.
  2. Safety check for public meditations (OpenAI). If you chose Public, your intake answers and the generated script are also sent to OpenAI’s moderation service, which checks them for harmful content. If anything is flagged, or the check cannot be completed, the meditation is saved as private instead. The same check runs if you publish a private meditation later.
  3. Narration (xAI). The script text is sent to xAI, which turns it into spoken audio in the voice you chose.
  4. Storage. The script and audio are stored with your account, and the app tells you when the meditation is ready.

We send each provider only the content it needs for its step. We do not send your name, email address or account ID to OpenAI or xAI. They process this content only to provide their service to us, under written agreements described in section 7. Under their API terms, OpenAI and xAI do not use this content to train their models, and they keep it for up to 30 days to check for abuse, unless the law requires them to keep it longer.

We ask for your permission first. Before your first meditation, the app explains what is sent to OpenAI and xAI and why, and asks you to tap Agree and continue. Nothing from your intake is sent to them until you do. We record when you agreed (see section 2).

You can withdraw your permission at any time in Profile > Settings > AI data & consent, where you can also see when you gave it. After you withdraw, the app cannot create new meditations or publish private ones (publishing runs the safety check) until you allow it again. Withdrawing does not undo processing that already happened: a meditation that was already being created is finished, and your existing meditations stay in your library until you delete them (see section 9).

5. Not a medical service

Soulfia is for relaxation and general wellbeing. It is not a medical, therapy or mental health service. We do not use your answers to diagnose, treat or provide care, and we do not keep medical or treatment records. Because your answers may still be sensitive, we keep them private, use them only as described in this policy, and never show them publicly, except for the feeling tags on meditations you publish (see section 6).

6. Public meditations and Explore

Meditations are private unless you choose otherwise. If you choose Public when you create a meditation, it is published to Explore automatically as soon as it is ready, provided it passes the automated safety check. You can also publish a private meditation later, which runs the same check. Explore can be browsed by anyone using the app, including people who are not signed in.

A public meditation shows:

If you sign in with Google, your avatar is your Google profile photo, so it is shown publicly next to any meditation you publish, even though your name is not. People viewing Explore load the photo directly from Google’s servers. Email roycerobins95@gmail.com and we will remove it.

Your account ID is the same ID we use with RevenueCat, PostHog and Sentry (see section 7). Public meditations can be read through our public API (the online interface the app uses to load Explore) as well as in the app, so anyone can look up the details listed above.

We never show your intake answers publicly, but the feeling tags shown on a public meditation are usually the feelings you selected in Guided create (or, in Quick create, feelings picked from what you wrote). The script, title and introduction are also written by AI from your answers. The AI is instructed to keep private details out of the title and introduction, but the spoken script is personal to what you shared and the AI may not always get this right. If you would rather keep what a meditation is about to yourself, keep it private.

Taking a meditation down. In the Library tab, tap … next to a meditation. Make private removes a public meditation from Explore and keeps it in your library. Delete permanently removes the meditation, its audio and its play records. Deleting your account removes all of your meditations, including published ones.

Reporting. If someone else’s public meditation seems harmful or breaks our Terms, tap … on it in Explore (or Report on its page, or … in the player), choose Report this meditation and pick a reason. You need to be signed in; you can also email roycerobins95@gmail.com with its title. We review reports within 24 hours. A meditation you reported no longer appears for you. When three different people have reported the same meditation, it is removed from Explore automatically until we have reviewed it. See Terms section 7 for what happens next.

Hiding a creator. From the same menu, choose Hide to stop seeing every meditation from that creator in Explore. They are not told. You can unhide them in Profile > Settings > Hidden creators.

If your meditation is reported, we do not tell you who reported it. If it is removed from Explore while we review it, your library shows it as private and under review, and you cannot publish it again until the review is finished.

Reporting a problem with your own meditation. If the AI wrote or said something offensive, harmful or wrong in one of your own meditations, public or private, tap … next to it in the Library tab (or … in the player), choose Report a problem and pick a reason. We review these reports within 24 hours and use them to improve how meditations are made. Reporting does not change who can see the meditation.

7. Who we share information with

We use the service providers below to run Soulfia. Each receives only the information it needs to do its job for us, and processes it on our behalf under a written agreement (such as data processing terms). These agreements require each provider to use the information only to provide its service to us and to protect it in a way that is the same as or equal to the protections described in this policy.

When you use Sign in with Apple, Google sign-in, the App Store or Google Play, Apple and Google also handle your sign-in and purchase details as part of their own services. Each provider’s name below links to its privacy information if you want to learn more.

Provider What it does for Soulfia Information involved
Supabase Hosting, database, sign-in, account emails (sign-up confirmation and password reset), file storage and server functions Account information, intake answers, meditations and audio, listening activity, your AI permission record, reports and hidden creators, subscription status, push tokens, server logs and sign-in audit logs, including IP addresses and device or browser type
OpenAI Writes the meditation script; runs the safety check for public meditations Intake answers, chosen length and guidance style; the generated script (for the safety check)
xAI Text-to-speech narration The meditation script text and the voice you chose
RevenueCat Subscription management An anonymous RevenueCat ID for everyone who opens the app, linked to your account ID once you sign in; purchase and subscription details from the App Store or Google Play; and device details and IP address needed to process purchases
Apple Sign in with Apple, App Store purchases, and delivering notifications to iPhones (Apple Push Notification service) Sign-in details, purchases, push tokens and notification content
Google Google sign-in, Google Play purchases, and delivering notifications to Android devices (Firebase Cloud Messaging) Sign-in details, purchases, push tokens and notification content
Expo Relays push notifications to Apple and Google Your device’s Apple or Google push token and an installation identifier for the app (to create your Expo push token); the Expo push token; and each notification’s content (“Your meditation is ready”, the meditation’s title and its ID)
PostHog Product analytics App events, device and app details, IP address and the approximate location estimated from it, and your account ID
Sentry Crash and error reporting Error details, a session record each time the app is opened, device and app details, recent technical app activity, and your account ID

We may also disclose information:

8. How long we keep information

9. Your rights and choices

Depending on where you live (for example in the European Economic Area, the United Kingdom, California or other US states), you may have additional rights, such as the right to receive your data in a portable format, to restrict or object to certain processing, and to withdraw consent. To use any of these rights, email roycerobins95@gmail.com. We may need to confirm the request comes from the account’s owner, and we will respond within the time the law requires. We will not treat you differently for exercising your rights. If you are in the EEA or UK, you may also complain to your local data protection authority.

If data protection laws such as the GDPR apply to you, we rely on these legal bases:

11. Children

Soulfia is not directed to children under 13, and we do not knowingly collect personal information from children under 13 (or under the minimum age required in their country). The app does not ask for your age. If you believe a child has created an account, email roycerobins95@gmail.com and we will delete it.

12. Security

No system is perfectly secure, so we cannot guarantee absolute security. If a data breach affects your personal information, we will notify you and the authorities where the law requires.

13. International transfers

Our database and file storage are hosted by Supabase on Amazon Web Services in the United States (AWS region us-east-1, N. Virginia). Our other providers may process information in the United States and other countries. If you use Soulfia from outside the United States, your information will be transferred to and processed in the United States, where data protection laws may differ from those where you live. Where the law requires, we rely on safeguards such as the Standard Contractual Clauses offered by our providers.

14. Changes to this policy

We may update this policy as Soulfia changes. When we do, we will post the new version on this page and update the effective date. If a change is significant, we will also let you know by reasonable means, such as a notice in the app or an email, before it takes effect.

15. Contact

Nicholas Robinson, developer of Soulfia
Email: roycerobins95@gmail.com