1. Who we are
SoulAI is a Dutch sole proprietorship operating under the trade name SoulAI, registered in the Netherlands under KVK number 91394066.
SoulAI
Dutch sole proprietorship
Groningen, The Netherlands
KVK 91394066
For GDPR purposes, the controller of personal data described in this Policy is the Dutch undertaking operating under the SoulAI trade name and KVK number above.
This Policy presents SoulAI as its own brand and trade name.
2. Scope of this Privacy Policy
This Privacy Policy explains how SoulAI processes personal information when you use:
- the SoulAI website at soulai.best;
- the SoulAI mobile experience (including Android);
- SoulAI Adult (web / progressive web app), where available;
- related account, support, and eligibility features linked from those surfaces.
It covers both the ordinary SoulAI experience and SoulAI Adult. Separate Adult Terms may apply to Adult eligibility and Adult content rules; those terms do not replace this Privacy Policy.
This Policy does not cover unrelated third-party websites or apps that we do not control, including a verification provider's own hosted flow once you leave SoulAI to complete identity checks.
3. Information we collect
SoulAI collects only categories that the product actually uses. Depending on how you use SoulAI, this may include:
- Account identifiers: email address, internal user ID, Google account identifier (when you sign in with Google), account status, and session version.
- Profile information: display name, optional gender, sexuality, interested-in, bio, and profile photo URL (often supplied by Google sign-in).
- Preferences: selected preference options (personality, relationship vibe, interests, soft boundaries) and free-text preference fields such as role preference, relationship vibe, and free-text preferences.
- Matching activity: likes, passes, matches, relationship-stage scores, and related match metadata.
- Conversations: messages you send, AI companion replies, optional message media references, and character memories used to personalise ongoing chats.
- Usage information: daily swipe and message usage counters used for plan limits.
- Subscription / entitlement status: plan code, subscription status, provider references (for example Google Play product/subscription identifiers when billing is live), and admin entitlement overrides/audits where applicable.
- Adult Access and Adult Terms data: Adult Access status, request/verified/revoked timestamps, access method, provider name, accepted Adult Terms version, acceptance timestamp, and age-confirmed self-attestation where recorded.
- Age-verification metadata: limited provider session identifiers, verification status strings, and related event timestamps needed to record eligibility outcomes.
- Authentication security data: hashed email one-time codes, attempt/lock/expiry metadata, and hashed rate-limit keys derived from email and IP (raw IP is not stored in those records).
- Account-deletion workflow data: deletion request status, hashed re-authentication proofs, and completion audit rows.
- Technical / operational logs: limited routing and security metadata (for example AI provider/model metrics, latency, correlation identifiers, Adult Mode flags). Message bodies are not written into those routing logs.
SoulAI does not, under the current architecture, store ID-document images, selfies, biometric templates, full dates of birth, or document numbers from age verification. See Section 9.
SoulAI does not currently operate a push-notification device-token system, and this Policy does not claim collection of advertising or analytics cookies that are not implemented.
4. Why we use your information
We use personal information to:
- create and secure your account, and sign you in;
- provide matching, profiles, conversations, and memories;
- generate AI companion responses and personalise the experience;
- enforce usage limits and entitlement/plan features;
- manage Adult Terms acceptance, Adult Access status, and age eligibility;
- process account-deletion requests and protect against abuse;
- send transactional emails such as one-time sign-in or deletion codes;
- maintain security, diagnose faults, and meet legal obligations where they apply.
Depending on the activity, SoulAI may rely on one or more of the following GDPR bases:
- Performance of a contract — operating your account, chats, matches, preferences, and core service features you request.
- Legitimate interests — security, rate limiting, fraud/abuse prevention, service reliability, and limited operational logging, balanced against your rights.
- Legal obligation — where age-assurance or record-keeping duties apply under applicable law.
- Consent — only where SoulAI relies on consent for a specific processing activity that requires it. Adult Terms acceptance is a contractual eligibility step and 18+ self-attestation; it is not treated as blanket GDPR consent for Article 9 / sexual-orientation / sex-life data. Consent is not used as a blanket basis for every processing activity.
5. Account and authentication data
You can sign in with Google and/or email one-time codes (OTP), depending on which methods are enabled.
Google sign-in: when enabled, SoulAI receives identity information needed to create or link your account (such as email, Google subject identifier, and optionally display name and profile photo URL). SoulAI then issues its own session token for continued access.
Email OTP: SoulAI sends a one-time sign-in code to your email address. The code is stored only in hashed form, with expiry, attempt, and lock metadata. Codes are used for authentication (and, where enabled, account-deletion confirmation). Raw codes are not kept as long-term credentials.
Session access is based on a client-held token tied to your account and a session version. Signing out, rotating session version, or starting deletion can invalidate prior sessions. SoulAI does not maintain a separate long-lived server-side session store beyond that account/session-version model.
6. Conversations and AI interactions
Messages you send to AI companions, and related profile, preference, and memory context, must be processed to generate replies. Conversation content is therefore not “private from all processors”: the AI inference provider selected for a request receives the prompt material needed to produce a response.
SoulAI's current architecture can route inference through external AI providers configured for the service, including DeepSeek, Mistral, Novita, and Venice. Which provider is used for a given request depends on product routing and content-policy controls. Adult-capable providers may be blocked while Adult Mode is disabled.
SoulAI stores conversations and character memories in its own database so chats can continue across sessions. Operational AI routing logs record limited metrics (provider/model, tokens, latency, correlation identifiers, and related flags) and are designed not to store full message bodies.
SoulAI does not claim that AI providers do or do not train on your prompts. Provider retention and training practices are governed by their own terms and by SoulAI's contracts with those providers.
7. Character and profile preferences
SoulAI stores profile fields and preference selections that help match you with characters and shape conversations. Catalog preferences currently cover personality, relationship vibe, interests, and soft boundaries.
Free-text fields (including role preference, relationship vibe, and free-text preferences) and profile fields such as sexuality or interested-in may reveal intimate aspects of your private life. Those fields are treated as potentially sensitive preference / profile data.
Character-admin metadata (for example adult fantasy tags on a character record) is not the same as your personal preference profile and is not exposed as your user preference data in mobile character DTOs.
8. Adult Access and Adult Terms consent
For SoulAI Adult, SoulAI may record:
- Adult Access status (for example not requested, pending, verified, revoked);
- Adult Terms acceptance timestamp;
- accepted Adult Terms version;
- age-confirmed self-attestation where you confirm you are 18+ in the product flow;
- related timestamps and method/provider labels used to manage eligibility.
Age-confirmed self-attestation means you acknowledged that you are at least 18. It is an eligibility acknowledgement only. It is not Didit verification, not Adult Access VERIFIED status, and not permission to use Adult Mode or explicit Adult media/chat.
Accepting Adult Terms is contractual acceptance of the Adult Terms plus 18+ self-attestation for that flow. It is not blanket GDPR consent for processing Article 9 / sexual-orientation / sex-life data. Self-declaring that you are 18+ is also different from successful age verification. Accepting Adult Terms alone does not grant Adult Access VERIFIED status. Adult Mode and Adult capabilities may remain unavailable even after Terms acceptance and, where applicable, verification.
Adult Terms acceptance is stored against your account so SoulAI can show the correct version and require re-acceptance when Terms change.
9. Age verification
Where age verification is required, SoulAI uses an approved verification provider. The current integrated provider is Didit (verification.didit.me). You may be redirected to the provider's hosted flow to complete checks.
SoulAI aims to follow a data-minimising design: SoulAI stores limited verification metadata needed to determine and record eligibility, such as:
- provider name;
- verification session identifier;
- verification status;
- relevant timestamps and event identifiers for webhook idempotency.
Under the current architecture, SoulAI does not receive or store ID-document images, selfies, biometric templates, full dates of birth, or document numbers from the verification flow. The verification provider may process additional identity or biometric information under its own privacy terms when you complete verification with that provider.
Review Didit's own disclosures at didit.me (and any privacy notice presented in the verification flow).
This description reflects SoulAI's intended privacy-by-design architecture. Absolute guarantees beyond that architecture are not made here.
10. Media and images
Character images and media are stored using configured media providers (currently Cloudinary for public/safe character assets and Bunny for private/hidden character media where enabled). Those systems primarily host character content, not your private photo library.
Your profile photo, when present, is typically stored as a URL (for example a Google profile photo URL) on your user profile rather than as a SoulAI-hosted upload pipeline.
Chat messages may reference image/media identifiers when the product attaches media to a message. SoulAI does not claim a general user-upload media library beyond what the live product supports.
11. Payments and subscriptions
SoulAI maintains subscription and entitlement records (plan code, status, period dates, and provider references). The data model supports Google Play billing identifiers, but live Play Billing purchase processing is not fully shipped in the current codebase.
No card payment processor (such as Stripe or PayPal) is currently integrated in project configuration. If paid checkout goes live later, this Policy will need an update naming the payment provider and payment data categories actually processed.
Admin or system grants of entitlements may also be recorded for operational reasons.
12. Notifications and communications
SoulAI sends transactional emails needed to operate the service, such as one-time authentication codes and account-deletion related messages, via an operator-configured SMTP relay.
SoulAI does not currently maintain push-notification device tokens or a third-party push stack in the product database. In-product “proactive” companion messages are chat features, not device push notifications.
Marketing email programmes are not described here because they are not confirmed as a live, configured feature in the current implementation.
13. Technical and security information
To protect accounts and keep the service reliable, SoulAI processes limited technical and security information, including:
- hashed rate-limit keys derived from email and IP for OTP abuse prevention (raw IP is not persisted in those OTP records);
- authentication attempt, lock, and expiry metadata for email codes;
- AI routing metrics and correlation identifiers without full message bodies;
- verification webhook event identifiers and status strings for Adult Access eligibility updates.
Server and hosting platforms may also generate standard infrastructure logs under their own operating practices.
14. Service providers and processors
SoulAI uses service providers to operate the product. Categories currently reflected in project configuration and code include:
- Hosting / infrastructure: Coolify-managed hosting on infrastructure such as Hetzner (as described in deployment documentation).
- Database: PostgreSQL.
- Authentication: Google (sign-in).
- Transactional email: operator-configured SMTP via nodemailer (no named ESP such as Resend/SendGrid/Postmark is hard-wired in code).
- AI inference: DeepSeek, Mistral, Novita, and Venice (as configured).
- Age verification: Didit.
- Media storage / CDN: Cloudinary and Bunny (where enabled).
- Payments: Google Play billing references are modelled; live purchase processing is not fully integrated yet.
Providers only receive what is needed for their role. Additional processors added later must be reflected in an updated Policy.
15. International data transfers
Some processors may process data outside the European Economic Area (EEA). For example, Google, certain AI providers, and some media providers commonly operate global infrastructure. SoulAI does not claim that all personal data remains in the EU.
16. How long information is kept
SoulAI does not invent retention periods that the system does not enforce. Confirmed behaviour today includes:
- Email OTP records: cleaned up on a short TTL (currently designed around 24 hours).
- Account-deletion proofs: short-lived hashed proofs (currently designed around 24 hours after consume/expiry).
- Account content: profile, preferences, matches, conversations, memories, and related account data are kept while the account remains active, then removed through the account-deletion hard-delete path when that flow completes.
- Completed deletion request rows: retained as workflow audit records with the user link cleared after hard delete.
Other categories — including longer operational or security logs, verification webhook/event metadata, Adult Terms acceptance records, media/CDN copies, and residual backup copies after account deletion — are retained only as needed to operate, secure, and administer the Service and to meet legal obligations. Exact fixed durations for those categories are not published as public promises here.
17. Account deletion
SoulAI provides an account-deletion path. When enabled in the API, deletion typically involves identity confirmation (including email OTP where configured), moving the account to a deletion-pending state, invalidating sessions, and then asynchronously hard-deleting account-linked data such as profile, preferences, matches, conversations, memories, usage limits, and related entitlement records.
Public information about requesting deletion is available on the Delete account page. Depending on product rollout, the public web form may still be informational rather than a live submission endpoint.
Deletion of SoulAI account records does not automatically erase every copy held by a processor (for example AI provider logs, verification-provider records, email relay logs, CDN caches, or infrastructure backups) on the same timetable. SoulAI also retains limited deletion-workflow audit rows after the user record is removed.
18. Your privacy rights
If the GDPR applies to you, you may have rights to:
- access your personal data;
- correct inaccurate personal data;
- erase personal data in certain circumstances;
- restrict processing in certain circumstances;
- object to certain processing based on legitimate interests;
- receive a portable copy of data you provided, where applicable;
- withdraw consent where processing relies on consent, without affecting the lawfulness of processing before withdrawal;
- lodge a complaint with a supervisory authority.
These rights are not absolute. Applicable exceptions, identity verification, and legal limitations may apply. To exercise rights, contact SoulAI using the details in Section 23.
19. Children and 18+ eligibility
You must be at least 18 years old to create or use a SoulAI account. The ordinary SoulAI Service (including the Google Play app) and SoulAI Adult are both for adults aged 18 or older. People under 18 must not create an account or use SoulAI.
Standard SoulAI is a romantic / flirty companion experience and does not include explicit Adult Mode content, explicit Adult media, or Adult AI routing. SoulAI Adult is a separate web/PWA experience that may require stronger age verification before restricted Adult features.
Self-attestation of age is not the same as successful age verification. SoulAI may require additional age assurance before Adult features become available. Ordinary SoulAI does not require Didit verification for account use unless a specific Adult feature flow separately requires it.
20. Security
SoulAI uses technical and organisational measures appropriate to the nature of the service, including access controls, hashed one-time codes, session invalidation on sensitive account events, and careful handling of verification metadata.
No online service can be guaranteed completely secure. SoulAI does not claim that personal data can never be accessed, disclosed, or altered without authorisation.
21. Browser storage and cookies
SoulAI's public web experience currently relies on browser sessionStorage for certain Adult-flow state, not on first-party advertising cookies. Relevant items include:
- a tab-scoped session token for authenticated Adult web use;
- a temporary Adult Terms acknowledgement marker used to carry pre-auth consent through sign-in;
- a short-lived verification-return marker used only as a UX hint after returning from the verification provider.
These are browser storage mechanisms, not cookies, unless a cookie is separately set by the browser or a third party. SoulAI does not currently implement analytics or advertising cookies on the public website.
The SoulAI Adult progressive web app may use a service worker to cache static shell assets. That cache is not intended to store JWTs, API responses with personal data, or Didit verification pages.
The Android / mobile app may store session credentials in platform-secure storage and limited account identifiers in local app preferences.
22. Changes to this Privacy Policy
SoulAI may update this Privacy Policy from time to time. Material changes will be indicated by updating the version and/or last-updated date on this page. Where required by law or product design, SoulAI may provide additional notice.
The current version identifier is 2026-08-15.
23. Contact
Privacy questions, GDPR requests, and Privacy Policy contact may be sent to: privacy@soulai.best
SoulAI
Dutch sole proprietorship
Groningen, The Netherlands
KVK 91394066
24. Complaints to a supervisory authority
If you believe SoulAI has processed your personal data unlawfully, you may lodge a complaint with a competent supervisory authority. For the Netherlands, that authority is the Autoriteit Persoonsgegevens:
https://www.autoriteitpersoonsgegevens.nl/
You may also have the right to complain to the supervisory authority in your own EEA member state of habitual residence, place of work, or place of the alleged infringement.