Privacy Policy

Last Updated: December 26, 2025

1. Introduction

Soul Compass ("the App", "we", "us", or "our") respects your privacy and is committed to protecting your personal information. This Privacy Policy explains what information we collect, how we use it, and your rights regarding your data.

This policy applies to users worldwide, including those in the European Economic Area (EEA), United Kingdom, and United States.

2. Data Controller

Soul Compass is the data controller responsible for your personal data. For contact information, please see Section 15 below.

3. Information We Collect

3.1 Information You Provide

  • Account information (email address, display name)
  • Profile information (avatar, language preferences)
  • Reflection responses and journal entries
  • App settings and preferences
  • Communications with us (support requests, feedback)

3.2 Automatically Collected Information

  • Usage data (access times, feature usage, session duration)
  • Device information (browser type, operating system, device type)
  • IP address and approximate location (country/region level)
  • Anonymous analytics data via Google Analytics

4. Legal Basis for Processing (GDPR)

For users in the EEA and UK, we process your personal data based on the following legal grounds:

  • Contract: Processing necessary to provide our services to you
  • Consent: Where you have given explicit consent (e.g., marketing emails, cookies)
  • Legitimate Interests: For service improvement and security, where balanced against your rights
  • Legal Obligation: Where required by applicable law

5. How We Use Your Information

We use the collected information for the following purposes:

  • Providing and improving our services
  • Personalizing your experience
  • Improving AI-generated question quality
  • Providing customer support
  • Analyzing usage statistics
  • Sending service-related communications
  • Sending marketing communications (with your consent)
  • Detecting and preventing fraud or abuse

6. Information Sharing and Third Parties

We do not sell your personal information. We may share your data with:

  • Service Providers: Firebase (Google Cloud Platform) for data storage, OpenAI for AI features, email service providers
  • Analytics Partners: Google Analytics for usage analysis
  • Legal Requirements: When required by law or to protect our rights
  • Business Transfers: In connection with a merger, acquisition, or sale of assets

All third-party providers are contractually obligated to protect your data and use it only for specified purposes.

7. Data Retention

We retain your personal data for as long as necessary to provide our services and fulfill the purposes described in this policy. Specifically:

  • Account data: Until you delete your account
  • Reflection entries: Until you delete them or your account
  • Analytics data: Up to 26 months
  • Email communications: Up to 3 years after last interaction

After deletion, data may be retained in backups for up to 30 days before permanent removal.

8. Data Security

We implement appropriate technical and organizational measures to protect your data:

  • Data is stored on Firebase (Google Cloud Platform) with enterprise-grade security
  • All communications are encrypted using SSL/TLS
  • Access to personal data is limited to authorized personnel
  • Regular security assessments and updates

9. International Data Transfers

Your information may be transferred to and processed in Japan and the United States. For transfers from the EEA/UK, we ensure appropriate safeguards through:

  • Standard Contractual Clauses (SCCs) approved by the European Commission
  • Data processing agreements with all service providers
  • Compliance with applicable data protection laws

10. Your Rights (All Users)

You have the following rights regarding your personal data:

  • Access: Request a copy of your personal data
  • Correction: Request correction of inaccurate data
  • Deletion: Request deletion of your data
  • Portability: Receive your data in a portable format
  • Opt-out: Unsubscribe from marketing communications

To exercise these rights, use the in-app settings or contact us at the address below.

11. Additional Rights for EEA/UK Residents (GDPR)

If you are located in the EEA or UK, you have additional rights under GDPR:

  • Restriction: Request restriction of processing in certain circumstances
  • Objection: Object to processing based on legitimate interests
  • Withdraw Consent: Withdraw consent at any time where processing is based on consent
  • Automated Decisions: Not be subject to decisions based solely on automated processing
  • Lodge Complaint: File a complaint with your local data protection authority

We will respond to your requests within 30 days as required by GDPR.

12. California Privacy Rights (CCPA/CPRA)

If you are a California resident, you have the following rights under CCPA and CPRA:

  • Right to Know: What personal information is collected, used, and shared
  • Right to Delete: Request deletion of your personal information
  • Right to Correct: Request correction of inaccurate information
  • Right to Opt-Out: Opt out of the sale or sharing of personal information
  • Right to Limit: Limit the use of sensitive personal information
  • Non-Discrimination: Equal service and price regardless of exercising privacy rights

Do Not Sell or Share: We do not sell or share your personal information for cross-context behavioral advertising.

To exercise your rights, contact us at support@soulcompass-journey.com or use the "Do Not Sell My Personal Information" link.

13. Cookies and Tracking Technologies

We use cookies and similar technologies for:

  • Essential Cookies: Required for basic site functionality
  • Analytics Cookies: Google Analytics to understand usage patterns
  • Preference Cookies: To remember your settings and preferences

You can manage your cookie preferences through our cookie consent banner or your browser settings. Note that disabling certain cookies may affect site functionality.

14. Children's Privacy

This App is intended for users 18 years of age and older. We do not knowingly collect personal information from anyone under 18 years of age. If we learn that we have collected personal information from a person under 18, we will promptly delete it. If you believe someone under 18 has provided us with personal information, please contact us.

15. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by:

  • Posting a notice on our website
  • Sending an email notification
  • Displaying an in-app notification

Your continued use of the App after changes constitutes acceptance of the updated policy.

16. Contact Us

For questions, requests, or complaints regarding this Privacy Policy or your personal data, please contact us:

Email: support@soulcompass-journey.com

For EEA/UK residents, you also have the right to lodge a complaint with your local supervisory authority.