Privacy Policy
Effective: April 27, 2026
1. Who we are
SharedSoul ("we", "us") operates https://sharedsoul.org, an AI-mediated platform that helps individuals and pairs work through relational and self-reflective conversations. This policy explains what we collect, how we use it, and your rights.
2. Information we collect
Information you give us
- Account information: name, email, password (hashed), avatar URL — supplied at signup or via Google OAuth.
- Conversation content: the messages you send to the AI (Mirror solo conversations, shared-space mediator conversations) and any context notes you provide about a relationship.
- Psychological profile data: assessment scores and inferences derived from your conversations (attachment style, communication patterns, etc.).
- Voice preferences: the language and voice you choose for speech features.
- Payment information: handled entirely by Stripe. We never receive or store your card number; we only receive a customer ID and subscription metadata.
Information we collect automatically
- Usage logs: message counts, session timestamps, feature usage — used for billing limits and anti-abuse.
- Device and connection data: IP address, browser, OS — used for rate-limiting and security.
- Cookies / local storage: session tokens, voice preferences, theme settings. Strictly functional; no third-party advertising trackers.
3. How we use your information
- To provide and personalize the AI mediator and Mirror.
- To remember you across conversations — so the AI doesn't start cold every session.
- To process payments and manage subscriptions.
- To enforce usage limits and detect abuse.
- To improve the product (only on aggregated, de-identified metrics — never on the content of your conversations).
4. AI processing — what to know
Your messages are processed by Anthropic's Claude APIto generate responses. Per Anthropic's API terms, your conversations are not used to train their models. Audio generation, when enabled, is processed by ElevenLabs; their API similarly does not retain content for training purposes.
Important: AI responses are not therapy, medical advice, or a substitute for professional care. SharedSoul is a tool for self-reflection and communication — not a licensed mental-health service.
5. How conversations are shared
Solo (Mirror) conversations are private to you. No one — not your friends, not your partner — can see them unless you explicitly choose to share an insight via the share feature.
Shared-space conversations are visible to both participants of that space. The AI may surface patterns it notices in your individual conversations to help the relationship, but only with the consent flag you set on each Mirror profile.
We do not sell, rent, or share your personal data with advertisers, data brokers, or marketing companies — ever.
6. Service providers we use
- Supabase (database + auth) — US-hosted.
- Vercel (hosting) — global edge network.
- Anthropic (AI inference) — US.
- ElevenLabs (voice synthesis) — US.
- Stripe (payments) — global.
- Google (OAuth sign-in only).
Each provider is bound by their own privacy commitments and applicable data-processing agreements.
7. Data retention
- Active account: conversations and profile data are retained while your account exists.
- Deleted spaces / messages: removed from active storage immediately and from backups within 30 days.
- Account deletion: on request, all your data is erased within 30 days, except billing records we are legally required to retain (typically 7 years for tax purposes).
8. Your rights
Depending on where you live (CA, EU, UK, etc.), you may have the right to:
- Access the data we hold about you.
- Correct inaccurate data.
- Delete your data.
- Export your data in a portable format.
- Object to certain processing.
- Withdraw consent at any time.
Email privacy@sharedsoul.org to exercise any of these. We respond within 30 days.
9. Security
All traffic uses HTTPS with HSTS. Database access is restricted via Row-Level Security so users can only read their own data. Service-role credentials are server-only and never exposed to the browser. We don't store payment card numbers.
No system is perfectly secure. If you discover a vulnerability, please email security@sharedsoul.org.
10. Children
SharedSoul is not directed to children under 16. We don't knowingly collect data from anyone under 16. If you believe a child has provided us data, email privacy@sharedsoul.organd we'll delete it.
11. International users
SharedSoul is operated from the United States. By using the service, you consent to your data being processed in the US, which may have different privacy protections than your home country. We rely on Standard Contractual Clauses for transfers originating in the EU/UK.
12. Changes to this policy
If we make material changes, we'll notify you by email and/or in the app at least 14 days before they take effect. Minor wording changes are noted by the "Effective" date above.
13. Contact
Questions about this policy or our practices? privacy@sharedsoul.org