Privacy Policy
Effective Date: July 14, 2026
SoulCode ("we", "our") values your privacy. This Privacy Policy explains what information we collect, how we use and disclose it, the choices available to you, and how we protect it. SoulCode is an 18+ social-discovery service.
1. Information We Collect
1.1 Information You Provide
- Account Information: Email address and password provided during registration.
- Profile Information: Nickname, age, gender, and city.
- Avatar: Profile photo you upload.
- AI Generation Content: The prompts, answers, and guided-conversation content you choose to submit to generate a Soul Code.
- Messages and Safety Reports: Messages you send after a mutual match and information you submit when reporting or blocking another user.
1.2 Automatically Collected Information
- Derived Soul Code and Match Data: Personality dimensions, attachment and values signals, interest tags, compatibility scores, match status, and optional AI-generated match interpretations.
- Subscription Information: Product, purchase, entitlement, renewal, and restore status. We do not receive your full payment-card number.
- Device and Diagnostic Information: Device type, OS/app version, product interactions, crash data, and limited diagnostic context used to operate and secure the service.
- Push Token: Device identifier for delivering notifications.
2. How We Use Your Information
- Generate your personalized Soul Code (personality analysis).
- Calculate deterministic compatibility, recommend matches, and, with permission, generate match interpretations.
- Provide real-time chat between matched users.
- Send match notifications and message alerts.
- Process and restore Premium subscriptions.
- Prevent abuse, investigate reports, diagnose failures, and protect the service.
3. AI Data Permission and Disclosures
Before SoulCode sends eligible content to a third-party generative-AI provider, the app asks for your explicit permission. The disclosure identifies the recipients — Google Gemini and Anthropic Claude — the purposes of Soul Code generation and compatibility-match interpretation, and the data categories involved. Permission applies only to the displayed policy version. You can withdraw it at any time from Account > Privacy; withdrawal stops future AI-provider requests but does not automatically delete Soul Codes, deterministic match results, or interpretations that were already stored.
- Guided generation: Gemini may receive a recent window of the generation conversation, your current answer, and the current inference state used to select the next question.
- Final Soul Code synthesis: Claude may receive the complete conversation for the current generation attempt.
- Match interpretation: Gemini may receive both participants' derived Soul Code fields: soul name, MBTI, attachment and values signals, interest tags, and numeric dimension scores. A new AI interpretation is requested only when both participants have a current permission grant. Otherwise, SoulCode returns the deterministic compatibility result without contacting an AI provider for that interpretation.
SoulCode does not automatically append your structured profile fields — nickname, email address, age, gender, city, avatar, or raw user ID — to Gemini or Claude model prompts. However, information you choose to type in an AI generation chat or prompt is part of the generation content described above and is sent to the applicable provider after permission. Match-interpretation requests separately exclude those profile fields and raw user IDs. Closing the generation disclosure sends nothing to an AI provider. Declining also prevents generation-provider access; a share-link match may still return a deterministic result without an AI-provider request.
4. Service Providers and Other Platforms
We use service providers only for the functions described below. Depending on your location, information may be processed in countries other than your own. We select and configure providers to apply protections appropriate to the data and service, limit use to the contracted service and documented purposes, and require compliance with applicable confidentiality, security, and legal obligations.
- Google Gemini: Provides guided generation questions and compatibility-match interpretations through server-side API calls. Under Google's current Gemini API terms, prompts and responses for a project with active Cloud Billing are treated as a Paid Service and are not used to improve Google products, although limited data may still be processed for abuse monitoring. Zero Data Retention is available only for eligible projects that Google approves and that are configured accordingly. We do not claim in this policy that SoulCode's current API project has verified active-billing status or approved Zero Data Retention. See Google's Gemini API Terms and Zero Data Retention documentation.
- Anthropic Claude: Provides final Soul Code synthesis through server-side commercial API calls. Anthropic states that commercial API inputs and outputs are not used to train its generative models by default unless the customer opts in. Under standard retention, inputs and outputs are deleted within 30 days, subject to safety, legal, and approved Zero Data Retention exceptions. See Anthropic's model-training policy and commercial data-retention policy.
- Supabase: Provides authentication, database storage, Row Level Security, server-side Edge Functions, and real-time communication.
- Expo: Provides push-notification delivery. Device push tokens and notification payload content are transmitted as needed to deliver notifications.
- RevenueCat: Processes app-user identifiers and subscription purchase, entitlement, renewal, and restore status so SoulCode can unlock Premium features.
- Sentry: Processes scrubbed crash, error, app-hang, release, device, and diagnostic context used to identify and fix reliability problems. SoulCode is configured to avoid intentionally attaching profile and conversation content to diagnostic events.
- Resend: Delivers account verification and password-reset email through Supabase's configured transactional-email service.
- Apple: Processes Apple Sign In requests when you choose that method, App Store subscription transactions, and platform push-notification delivery. Apple's processing is governed by its own terms and privacy policies.
5. Data Retention and Security
- Account, profile, Soul Code, match, and message data is retained while your account is active and deleted or de-identified when no longer needed, subject to limited legal, security, fraud-prevention, and safety obligations.
- Provider-specific AI retention is described in Section 4. A provider's approved Zero Data Retention program, when applicable, is separate from SoulCode's own database retention.
- Your password is handled through Supabase Auth using secure password protection; SoulCode does not store a readable password in its application database.
- Authentication tokens are stored using device Secure Store.
- AI API keys are stored server-side only and never exposed to the client.
- We use encrypted network transport, access controls, and database Row Level Security policies to restrict data according to the signed-in user, application role, and match relationship.
6. Your Choices and Rights
- Access: You can view your profile and Soul Code at any time within the app.
- Modify: You can update your profile information in account settings.
- AI Permission: You may decline the pre-send disclosure or withdraw a prior grant from Account > Privacy. Withdrawal applies to future provider requests.
- Notifications: You can change notification permission in your device settings.
- Delete: You can delete your account and associated personal data directly within the app (Account > Delete Account). Upon deletion, your profile, Soul Code, matches, chat history, and avatar are removed from the active service, subject to limited records that we must retain for legal, security, or safety purposes. If you cannot access the app, visit our account deletion page or contact support@bdlogic.xyz.
Depending on where you live, applicable law may provide additional rights such as requesting a copy, correction, deletion, restriction, or objection. Contact us to exercise a right that is not available directly in the app. We may need to verify your identity before completing the request.
7. Age Requirement
SoulCode is intended only for people who are at least 18 years old. A completed profile requires an age from 18 through 100. We do not knowingly permit a person under 18 to complete a SoulCode profile. If you believe a person under 18 is using the service, contact us so we can investigate and take appropriate action.
8. Changes to This Policy
We may update this Privacy Policy from time to time. The updated policy will be posted on this page with a revised effective date. If a change materially expands an AI provider, purpose, or payload, SoulCode will use a new consent-policy version and request permission again before the expanded provider processing.
9. Contact Us
For any privacy-related questions, please contact: support@bdlogic.xyz