Privacy Policy

How Soul Space collects, uses, and protects your information.

Last updated: May 2026

1. Who We Are

Soul Space is operated by Soul Space Health, Inc. (“we”, “us”, “our”). Soul Space is a guided emotional reflection tool — not a therapy service, mental health provider, or medical device. Questions about this policy can be sent to privacy@soulspacehealth.org.

2. What We Collect

Account information. If you create an account, we collect your email address. We do not collect passwords — authentication is via magic link only.

Session content. If you are signed in and choose to save a session, your inputs (resonance branch, emotion tags, context text) and the Mirror reflection are encrypted with AES-256-GCM before being written to our database. We never store session content in plaintext.

Usage events. We collect anonymised interaction events (e.g. “session started”, “mirror rendered”, “resonance tapped”) in our own database. We do not use Google Analytics, Meta Pixel, or any third-party tracking script.

Payment information. Payments are processed by Stripe. We never see or store your card number, CVV, or banking details. Stripe provides us only with subscription status and a customer ID.

Safety events. When our AI safety classifier flags a session for potential crisis content, a safety event is logged (without the original text) so we can monitor platform safety.

3. How We Use Your Information

We use the information we collect to:

  • Deliver and improve the Soul Space reflection experience
  • Send you magic-link sign-in emails and subscription confirmation emails
  • Maintain the safety and security of the platform
  • Understand aggregate usage patterns (using only our own analytics)
  • Process and manage your subscription via Stripe

We do not use your session content to train AI models, and we do not sell, rent, or share your personal information with third parties for marketing purposes.

4. How We Protect Your Data

Session content is encrypted with AES-256-GCM (a military-grade symmetric cipher) before it is stored. The encryption key is never stored alongside the ciphertext.

Our database is hosted on Supabase with row-level security (RLS) enforced on every table — each user can only access their own rows.

All data is transmitted over HTTPS with HSTS enforced. Our servers and database infrastructure are hosted in the United States.

5. Data Retention

We retain your account and session data for as long as your account is active. Anonymised usage events are retained for up to 24 months for product analytics.

You can delete your account and all associated session data at any time from your account settings. Deletion is permanent and processed within 30 days.

6. Third-Party Service Providers

We share limited data with the following sub-processors in order to operate the service:

  • Supabase — database, authentication, and row-level security (United States)
  • Anthropic — AI model inference for the Mirror reflection and safety classification. Session text is sent to Anthropic’s API for processing and is subject to Anthropic’s Privacy Policy. We do not share identifying information alongside session content.
  • Stripe — payment processing (United States)
  • Brevo — transactional email delivery (France / EU)
  • AWS Amplify — application hosting (United States)

7. Your Rights

Depending on where you live, you may have rights including:

  • Access. Request a copy of the personal data we hold about you.
  • Correction. Request correction of inaccurate data.
  • Deletion. Request deletion of your account and associated data.
  • Opt-out of sale. We do not sell personal information. If you are a California resident, this satisfies your CCPA/CPRA opt-out right.
  • Data portability. Request a machine-readable export of your session data.

To exercise any of these rights, email privacy@soulspacehealth.org from the address associated with your account. We will respond within 30 days.

8. Cookies

Soul Space uses only essential session cookies required for authentication and age-gate consent. We do not use advertising cookies, tracking pixels, or fingerprinting. See our Cookie Notice for full details.

9. Children

Soul Space is not directed at children under 13. We do not knowingly collect personal information from anyone under 13. If you believe a child under 13 has provided us with personal information, please contact us at privacy@soulspacehealth.org and we will delete it promptly.

10. Changes to This Policy

We may update this policy from time to time. When we do, we will update the “Last updated” date at the top. If changes are material, we will notify signed-in users by email before they take effect.