Privacy Policy
Last updated: 2026-05-10
Mental-health context — what to know first
SharedSoul is a tool for reflection and relational understanding, not a medical service. It is not HIPAA-compliantand not designed to hold information that requires HIPAA protection. Please don't enter Protected Health Information (PHI) in the legal sense — diagnostic records, medical chart data, insurance claims info, etc. If you need a HIPAA platform, your clinician's patient portal is the right place.
The content you do enter — reflections, conversations, voice transcripts, Mirror answers — is sensitive. We treat it as such. The protections below describe what that looks like in practice.
The short version
- We collect what we need to make SharedSoul work for you. Nothing else.
- Your conversations are yours. We don't sell your data, advertise on your data, or train AI on your data.
- You can export everything we have on you, or delete it all, any time, from your account settings.
- The AI learns YOU through your Mirror profile. It doesn't know you across other users.
- If you mention self-harm, abuse, or imminent danger, the AI surfaces real human resources. We log that the trigger fired (no message body) for safety auditing.
What we collect
- Account data: email, display name, password hash (Supabase Auth handles this).
- Your conversations: messages you send to the AI Mediator and Mirror, attached images.
- Your Mirror profile: the psychological summary the AI builds from your self-analysis.
- Space membership: which Shared Spaces you're in, who joined them.
- Usage counts: message volume per month, for billing tier enforcement.
- Billing data: handled entirely by Stripe — we never see your card details.
- Voice data: when you use voice input or read-aloud, audio is processed in your browser (Web Speech API) and via ElevenLabs for premium voices. Audio is NOT stored on our servers.
- Product analytics: via PostHog when enabled — only event names + anonymized identifiers, no message contents.
Where your data lives
- Supabase (US) — database + authentication.
- Vercel (US) — application hosting.
- Anthropic — processes messages to generate AI replies. Anthropic does not train on customer-submitted data per their policy.
- ElevenLabs (when you use a premium voice) — generates audio from the AI's text reply.
- Stripe — handles all payment information.
- PostHog (when enabled) — handles product analytics events.
What your partner sees
In a Shared Space, you have your own private AI thread that your partner never sees. Only curated, anonymized insights from the AI cross over — never your raw words. Voice calls and merged sessions are explicitly opt-in by both partners; merging requires both of you to agree before the thread becomes shared.
Your rights
- Access: ask for everything we have on you. We'll send a JSON export.
- Deletion: wipe your account and all associated data. This cannot be undone.
- Correction: edit or update your profile data any time.
- Portability: the export is machine-readable so you can take it elsewhere.
- Withdraw consent: stop using SharedSoul any time, no questions.
You can use the in-app endpoints (Account → Export / Delete) or contact privacy@sharedsoul.org for any of the above. We respond within 7 days.
Crisis safety
SharedSoul is not a crisis service. The AI runs a safety classifier on every message. When it detects mentions of self-harm, abuse, or imminent danger, it surfaces real human resources (988 Lifeline, country-specific hotlines) and gently encourages you to reach out. We log that a safety trigger fired in a safety_eventstable — only the category and a short matched phrase, never your full message. This is for audit + product safety. If you're in immediate danger, call your local emergency number (988 / 911 in the US).
Children
SharedSoul is not for users under 13 (or 16 in the EU/UK). We don't knowingly collect data from minors. If you believe a minor has signed up, contact privacy@sharedsoul.organd we'll remove the account.
Cookies
We use essential cookies (auth session) and a small amount of localStorage (your locale, voice preferences, dismissed UI state). Optional analytics cookies (PostHog) only set when analytics is enabled.
Changes to this policy
When we change anything material we update the "Last updated" date at the top and notify active users via email. Substantive changes never apply retroactively without your re-consent.
Contact
SharedSoul
Adolfo Badillo, Founder
hello@sharedsoul.org · privacy@sharedsoul.org