Privacy Policy
The short version
- Soulfia creates guided meditations from what you tell it. To do that, your intake answers are sent to OpenAI, which writes the meditation script, and the script text is sent to xAI, which turns it into spoken audio. The app asks for your permission before your first meditation, and you can withdraw it at any time in Profile > Settings > AI data & consent.
- Your meditations are private by default. If you choose Public, the meditation and its audio can be found and played by anyone in Explore, including people who are not signed in. We never show your intake answers publicly, except that the feeling tags on a public meditation are usually the feelings you picked. If you signed in with Google, your Google profile photo is shown with it. You can make a meditation private again, or delete it, at any time in the app.
- We do not sell your personal information, and the app has no ads.
- You can delete your account and everything in it at any time in the app: Profile > Settings > Account > Delete account.
- Soulfia is a relaxation and wellbeing app, not a medical or mental health service.
1. Who we are
Soulfia (also styled SOULFIA) is a mobile app for iPhone and Android that creates personalized guided meditations. It is developed and operated by Nicholas Robinson, an individual developer (“we”, “us”, “our”). We are responsible for the personal information described in this policy.
This policy covers the Soulfia app and the online services behind it. It explains what we collect, why, who helps us process it, how long we keep it, and the choices you have. If you have questions, email roycerobins95@gmail.com.
You can open this policy, the Terms of Use and account deletion at any time in the app under Profile > Settings.
2. Information we collect
Account information
- Email sign-up: your email address, your password, and the name you enter when you sign up. Your password is stored in hashed form by our sign-in provider; we cannot see it.
- Sign in with Apple: an Apple user identifier, the email address Apple shares with us (which may be a private relay address if you choose “Hide My Email”), and your name if you choose to share it the first time you sign in.
- Google sign-in: your Google account identifier, email address and name, and a link to your Google profile photo if you have one. We use that photo as your avatar.
- Basic account records, such as when your account was created, your active sign-in sessions, and the IP address and device or browser type (user agent) used to sign in.
- An audit log of account events, such as sign-ins, password resets and account deletion, kept by our sign-in system. Each entry includes your email address or account ID, your IP address and the time.
Your display name is the name you entered at sign-up, or the name Apple shared. If you sign in with Google, you have no display name. Your display name and avatar are shown with any meditation you make public (see section 6).
If you sign in with Google, your Google profile photo is shown publicly next to any meditation you publish, even though your name is not. The app cannot change or remove it yet. Email roycerobins95@gmail.com and we will remove it.
What you tell us to create a meditation (“intake”)
- Quick create: a short free-text description of how you are arriving (up to 240 characters).
- Guided create: the feelings you select, what you want to move toward, some context about your situation, the guidance style you prefer, and optionally something to include or avoid.
- Your choices of length, voice, background (ambient) sound, and whether the meditation is private or public.
Intake answers can describe your mood, emotions and personal circumstances. Please share only what you are comfortable with. We store your answers with the meditation they produced.
Content we generate for you
- The meditation script written by AI (a title, a short introduction, the spoken sections and a closing), feeling tags, and the narrated audio file.
- Status details, such as when the meditation was created, whether it was generated successfully, and whether it passed the automated safety check for public meditations.
Listening activity
When you are signed in and play a meditation that another member published, we record that your account played it and when. We use this to count plays: each listener is counted at most once per meditation every 30 minutes. Creators see only the total play count, never who listened. Playing your own meditations is not recorded this way.
Your AI permission
When you allow the app to send your answers to our AI providers (see section 4), we store the time you agreed and which version of the explanation you agreed to. If you withdraw your permission, we clear both.
Reports and hidden creators
- If you report a public meditation, we store your account ID, which meditation you reported, the reason you chose, any details you add (up to 500 characters), when you reported it, and whether we have reviewed it. The creator is not told who reported it.
- If you report a problem with the AI output of one of your own meditations, we store the same details. To review it, we read that meditation’s script, even if it is private.
- If you hide a creator, we store your account ID, the creator’s account ID and when you hid them. The creator is not told.
Purchases and subscription status
Purchases are made through the App Store or Google Play and managed with RevenueCat. The RevenueCat software in the app runs for everyone who opens the app: under an anonymous RevenueCat ID until you sign in, and under your Soulfia account ID after that. We receive and store your subscription status: whether you have Premium, which product you bought, whether it is a trial, renewal and expiry dates, and your RevenueCat customer ID (normally linked to your Soulfia account ID). We never receive your card number or other payment details.
Device and notification information
- If you allow notifications, we store a push token for your device (an identifier that lets us send notifications to it) and whether the device is iOS or Android. We use it only to tell you when a meditation you created is ready. The app first asks for permission right after you submit your first meditation.
- The app keeps some information on your device: your sign-in session (in the device’s secure storage), a copy of your basic profile, preferences such as your preferred voice and volume levels, your notification token, and the analytics identifier described below.
Usage analytics (PostHog)
We use PostHog to understand how the app is used. The app sends basic app events, such as when the app is installed, updated, opened or moved to the background, along with device and app details (for example device model, operating system, app version, language and time zone). The app removes links and web addresses from these events before they are sent, so a link that opens the app, such as the link in a sign-up confirmation or password reset email, is not sent to PostHog. PostHog gives the app on your device a random identifier; once you sign in, events are also linked to your Soulfia account ID. PostHog receives your IP address with these events and uses it to estimate an approximate location, such as your country or city. We do not send your name, email address, intake answers or meditation content to PostHog.
Crash and error reports (Sentry)
When the app crashes or hits an error, a report is sent to Sentry. It includes technical details about the error, your device model and operating system, the app version, recent technical app activity leading up to the error (such as network requests the app made), and your Soulfia account ID if you are signed in. Sentry also receives a small session record each time you open the app, even if nothing goes wrong: the app version, your device and operating system, whether the session ended in a crash, and your account ID if you are signed in. We use this information only to find and fix problems and to measure how stable the app is.
Server logs
Our servers log technical events, such as when a meditation was requested, finished or failed, together with account and meditation identifiers. Our hosting provider also records your IP address and device or browser type (user agent) when the app connects to our servers and when you sign in. The logs are designed to record identifiers and technical details, not your intake answers or meditation text.
Messages you send us
If you email us, we keep your message, your email address and our reply so we can help you.
What we do not collect
The app does not access your precise location, contacts, photos or microphone. We do not use advertising identifiers, and we do not track you across other companies’ apps or websites.
3. How we use information
- To provide Soulfia: create your account and sign you in; generate, store and play your meditations; show your library; and run Explore.
- To send account emails, such as sign-up confirmation and password reset emails, to the email address on your account.
- To create meditations with AI, as described in section 4.
- To publish meditations you choose to make public, after an automated safety check.
- To manage subscriptions: check whether you have Premium and keep your status up to date.
- To notify you that a meditation is ready, if you allow notifications.
- To keep Soulfia safe and working: prevent abuse (for example, limits on how many meditations can be created per hour), review reports about public meditations, secure accounts, investigate problems, and fix crashes.
- To show you the Explore you chose: leave out creators you hid and meditations you reported.
- To understand and improve the app, using the usage analytics described above.
- To respond to you when you contact us, and to meet legal obligations.
We do not sell your personal information. We do not share it for targeted or cross-context behavioral advertising, and the app contains no ads. We do not use your intake answers or meditations for marketing.
4. How AI creates your meditation
Each time you create a meditation:
- Script (OpenAI). Your intake answers, chosen length and guidance style are sent to OpenAI, which writes the meditation script.
- Safety check for public meditations (OpenAI). If you chose Public, your intake answers and the generated script are also sent to OpenAI’s moderation service, which checks them for harmful content. If anything is flagged, or the check cannot be completed, the meditation is saved as private instead. The same check runs if you publish a private meditation later.
- Narration (xAI). The script text is sent to xAI, which turns it into spoken audio in the voice you chose.
- Storage. The script and audio are stored with your account, and the app tells you when the meditation is ready.
We send each provider only the content it needs for its step. We do not send your name, email address or account ID to OpenAI or xAI. They process this content only to provide their service to us, under written agreements described in section 7. Under their API terms, OpenAI and xAI do not use this content to train their models, and they keep it for up to 30 days to check for abuse, unless the law requires them to keep it longer.
We ask for your permission first. Before your first meditation, the app explains what is sent to OpenAI and xAI and why, and asks you to tap Agree and continue. Nothing from your intake is sent to them until you do. We record when you agreed (see section 2).
You can withdraw your permission at any time in Profile > Settings > AI data & consent, where you can also see when you gave it. After you withdraw, the app cannot create new meditations or publish private ones (publishing runs the safety check) until you allow it again. Withdrawing does not undo processing that already happened: a meditation that was already being created is finished, and your existing meditations stay in your library until you delete them (see section 9).
5. Not a medical service
Soulfia is for relaxation and general wellbeing. It is not a medical, therapy or mental health service. We do not use your answers to diagnose, treat or provide care, and we do not keep medical or treatment records. Because your answers may still be sensitive, we keep them private, use them only as described in this policy, and never show them publicly, except for the feeling tags on meditations you publish (see section 6).
6. Public meditations and Explore
Meditations are private unless you choose otherwise. If you choose Public when you create a meditation, it is published to Explore automatically as soon as it is ready, provided it passes the automated safety check. You can also publish a private meditation later, which runs the same check. Explore can be browsed by anyone using the app, including people who are not signed in.
A public meditation shows:
- its title, short introduction and feeling tags;
- its length, the voice and background sound used, whether it was made with Quick or Guided create, and some technical details about how its audio was made;
- its play count, and when it was created, finished and published;
- your display name if you have one (otherwise it is labeled “SOULFIA member”), your avatar if you have one, and your account ID (a random code, not your name or email);
- its audio, which anyone can play. The audio speaks the whole script.
If you sign in with Google, your avatar is your Google profile photo, so it is shown publicly next to any meditation you publish, even though your name is not. People viewing Explore load the photo directly from Google’s servers. Email roycerobins95@gmail.com and we will remove it.
Your account ID is the same ID we use with RevenueCat, PostHog and Sentry (see section 7). Public meditations can be read through our public API (the online interface the app uses to load Explore) as well as in the app, so anyone can look up the details listed above.
We never show your intake answers publicly, but the feeling tags shown on a public meditation are usually the feelings you selected in Guided create (or, in Quick create, feelings picked from what you wrote). The script, title and introduction are also written by AI from your answers. The AI is instructed to keep private details out of the title and introduction, but the spoken script is personal to what you shared and the AI may not always get this right. If you would rather keep what a meditation is about to yourself, keep it private.
Taking a meditation down. In the Library tab, tap … next to a meditation. Make private removes a public meditation from Explore and keeps it in your library. Delete permanently removes the meditation, its audio and its play records. Deleting your account removes all of your meditations, including published ones.
Reporting. If someone else’s public meditation seems harmful or breaks our Terms, tap … on it in Explore (or Report on its page, or … in the player), choose Report this meditation and pick a reason. You need to be signed in; you can also email roycerobins95@gmail.com with its title. We review reports within 24 hours. A meditation you reported no longer appears for you. When three different people have reported the same meditation, it is removed from Explore automatically until we have reviewed it. See Terms section 7 for what happens next.
Hiding a creator. From the same menu, choose Hide to stop seeing every meditation from that creator in Explore. They are not told. You can unhide them in Profile > Settings > Hidden creators.
If your meditation is reported, we do not tell you who reported it. If it is removed from Explore while we review it, your library shows it as private and under review, and you cannot publish it again until the review is finished.
Reporting a problem with your own meditation. If the AI wrote or said something offensive, harmful or wrong in one of your own meditations, public or private, tap … next to it in the Library tab (or … in the player), choose Report a problem and pick a reason. We review these reports within 24 hours and use them to improve how meditations are made. Reporting does not change who can see the meditation.
7. Who we share information with
We use the service providers below to run Soulfia. Each receives only the information it needs to do its job for us, and processes it on our behalf under a written agreement (such as data processing terms). These agreements require each provider to use the information only to provide its service to us and to protect it in a way that is the same as or equal to the protections described in this policy.
When you use Sign in with Apple, Google sign-in, the App Store or Google Play, Apple and Google also handle your sign-in and purchase details as part of their own services. Each provider’s name below links to its privacy information if you want to learn more.
| Provider | What it does for Soulfia | Information involved |
|---|---|---|
| Supabase | Hosting, database, sign-in, account emails (sign-up confirmation and password reset), file storage and server functions | Account information, intake answers, meditations and audio, listening activity, your AI permission record, reports and hidden creators, subscription status, push tokens, server logs and sign-in audit logs, including IP addresses and device or browser type |
| OpenAI | Writes the meditation script; runs the safety check for public meditations | Intake answers, chosen length and guidance style; the generated script (for the safety check) |
| xAI | Text-to-speech narration | The meditation script text and the voice you chose |
| RevenueCat | Subscription management | An anonymous RevenueCat ID for everyone who opens the app, linked to your account ID once you sign in; purchase and subscription details from the App Store or Google Play; and device details and IP address needed to process purchases |
| Apple | Sign in with Apple, App Store purchases, and delivering notifications to iPhones (Apple Push Notification service) | Sign-in details, purchases, push tokens and notification content |
| Google sign-in, Google Play purchases, and delivering notifications to Android devices (Firebase Cloud Messaging) | Sign-in details, purchases, push tokens and notification content | |
| Expo | Relays push notifications to Apple and Google | Your device’s Apple or Google push token and an installation identifier for the app (to create your Expo push token); the Expo push token; and each notification’s content (“Your meditation is ready”, the meditation’s title and its ID) |
| PostHog | Product analytics | App events, device and app details, IP address and the approximate location estimated from it, and your account ID |
| Sentry | Crash and error reporting | Error details, a session record each time the app is opened, device and app details, recent technical app activity, and your account ID |
We may also disclose information:
- to other people, when you choose to make a meditation public (see section 6);
- if required by law, or to respond to valid legal requests;
- to protect the rights, safety or property of our users, the public or us, or to prevent fraud or abuse;
- as part of a sale or transfer of Soulfia. If that happens, this policy will continue to apply to your information unless you are told otherwise and given a choice where the law requires.
8. How long we keep information
- Your account, profile, meditations (including intake answers, scripts and audio), listening activity, AI permission record, reports you made, creators you hid, subscription status and push tokens are kept for as long as your account exists, and are deleted when you delete your account. Meditations that failed to generate are kept with your account in the same way.
- A meditation you delete is removed straight away, with its audio, its play records and any reports about it. Reports about a meditation are also deleted when its creator deletes their account.
- Push tokens are also removed when you sign out on that device, or when Expo reports, while sending a notification, that the device is no longer registered.
- After you delete your account, your data is removed from our live database and file storage straight away, except for the sign-in audit records described below. Copies may remain in our hosting provider’s automatic database backups for up to 7 days.
- Server logs and sign-in audit records (which can include your account ID, email address, IP address and device type) are kept for up to 7 days for security and to fix problems, then deleted. This includes the record of your account deletion.
- Crash reports and app-session records (Sentry) are deleted automatically after 90 days at most.
- Analytics (PostHog) are kept for up to 12 months.
- Analytics and crash reports are linked to your account ID, not your name or email, and are not deleted when you delete your account. Email us if you want the analytics linked to your account ID deleted sooner, and we will delete them.
- Purchase records are kept by Apple, Google and RevenueCat under their own policies and legal obligations (for example, tax and accounting rules).
- Content sent to OpenAI and xAI is kept by them for up to 30 days to check for abuse, unless the law requires them to keep it longer.
- Emails you send us are kept while we handle your request, and deleted within 12 months after it is resolved.
9. Your rights and choices
- Access. You can see and play your meditations in the app. Email us for a copy of your intake answers or any other personal information we hold about you.
- Correction. The app does not yet have a profile editor. Email us to correct your display name or other information.
- Deletion. Delete your account in the app at Profile > Settings > Account > Delete account, or email us from your account’s email address. See Delete your account for exactly what is removed.
- Unpublishing and deleting meditations. In the Library tab, tap … next to a meditation and choose Make private or Delete. Deleting is permanent.
- AI permission. See or withdraw your permission for AI processing at any time in Profile > Settings > AI data & consent (see section 4).
- Hidden creators. Unhide creators at any time in Profile > Settings > Hidden creators.
- Notifications. You can turn notifications off at any time in your device settings. Signing out also stops meditation-ready notifications to that device.
- Analytics and crash reports. The app does not currently have a setting to turn these off. If you object to them, email us and we will delete the analytics linked to your account ID. Crash reports are deleted automatically within 90 days.
- Subscriptions. Manage or cancel your subscription in your App Store or Google Play account settings. Deleting your account does not cancel a subscription.
Depending on where you live (for example in the European Economic Area, the United Kingdom, California or other US states), you may have additional rights, such as the right to receive your data in a portable format, to restrict or object to certain processing, and to withdraw consent. To use any of these rights, email roycerobins95@gmail.com. We may need to confirm the request comes from the account’s owner, and we will respond within the time the law requires. We will not treat you differently for exercising your rights. If you are in the EEA or UK, you may also complain to your local data protection authority.
10. Legal bases (EEA and UK)
If data protection laws such as the GDPR apply to you, we rely on these legal bases:
- Performing our contract with you: creating your account, generating, storing, playing and publishing your meditations, and managing your subscription.
- Your explicit consent: your intake answers, which may reveal information about your health or emotional state. You decide what to enter, and before your first meditation the app asks for your explicit permission to send your answers to OpenAI and xAI (section 4). We use your answers only to create the meditation you ask for and, if you choose Public, to run the automated safety check and show feeling tags with the meditation (section 6). You can withdraw your consent at any time in Profile > Settings > AI data & consent; this does not affect processing that already happened. You can also delete meditations in the app or delete your account.
- Your consent: push notifications, which you can withdraw in your device settings.
- Legitimate interests: keeping Soulfia secure, preventing abuse, reviewing reports and protecting people from harmful content in Explore, fixing crashes and understanding how the app is used so we can improve it.
- Legal obligations: where we must keep or disclose information by law.
11. Children
Soulfia is not directed to children under 13, and we do not knowingly collect personal information from children under 13 (or under the minimum age required in their country). The app does not ask for your age. If you believe a child has created an account, email roycerobins95@gmail.com and we will delete it.
12. Security
- Information travels between the app and our services over encrypted connections (HTTPS).
- Database rules limit each account to its own private data. Meditation audio is stored privately and played through temporary links that expire after one hour.
- Your sign-in session is kept in your device’s secure storage.
- The secret keys for our AI, payment and database services are kept on our servers, never in the app.
No system is perfectly secure, so we cannot guarantee absolute security. If a data breach affects your personal information, we will notify you and the authorities where the law requires.
13. International transfers
Our database and file storage are hosted by Supabase on Amazon Web Services in the United States (AWS region us-east-1, N. Virginia). Our other providers may process information in the United States and other countries. If you use Soulfia from outside the United States, your information will be transferred to and processed in the United States, where data protection laws may differ from those where you live. Where the law requires, we rely on safeguards such as the Standard Contractual Clauses offered by our providers.
14. Changes to this policy
We may update this policy as Soulfia changes. When we do, we will post the new version on this page and update the effective date. If a change is significant, we will also let you know by reasonable means, such as a notice in the app or an email, before it takes effect.
15. Contact
Nicholas Robinson, developer of Soulfia
Email: roycerobins95@gmail.com