SoulSinq

Privacy Policy

Effective date: [GO-LIVE DATE] · Version 2026-XX

Welcome to SoulSinq. We are committed to protecting your personal information and your right to privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our mobile application and related services (the “Service”). If you disagree with its terms, please discontinue use of the Service.

1. Who is responsible for your data

The data controller for the Service is the person who operates it:

[OPERATOR: FULL LEGAL NAME]
[POSTAL ADDRESS, COUNTRY]
Email: soulsinq@gmail.com

Because the operator is established in Switzerland, outside the European Union, the following represent SoulSinq in the Union. You can write to them about anything in this policy:

2. Information we collect

2.1 Information you provide directly

2.2 Information collected automatically

2.3 Information from third parties

If you sign in with Google (or, on iOS, with Apple), we receive your name and email address from that provider, subject to your settings there.

3. How and why we use your information

PurposeLegal basis (GDPR)
Creating and managing your account; operating the matching algorithm; suggesting compatible profiles; the progressive photo-reveal feature; messaging, voice notes and games between Connects Performance of a contract (Art. 6(1)(b))
Using who you want to meet (which can reveal your sexual orientation) to suggest peopleYour explicit consent (Art. 9(2)(a)), asked before it is stored. The Service cannot suggest anyone without it; you withdraw it by deleting your account
Storing your religion/spirituality, politics/worldview and physical intimacy answers and using them in matchingYour explicit consent (Art. 9(2)(a)) - optional, revocable in Settings → Privacy choices, which erases the answers
Telling you by email of a moderation decision about your account, or about a report you madeLegal obligation (Art. 6(1)(c)): Articles 16 and 17 of the EU Digital Services Act
Push notifications about your matches and conversations Performance of a contract; you control categories in Settings and can disable them entirely in your device settings
Screening uploaded photos for prohibited content (automated screening by Google Cloud Vision, followed - where it flags something - by review of that photograph by an authorised member of our team), handling reports and blocks (including reading the conversation a report is about, and keeping the copy described in Section 2.1), preventing fraud and abuse, rate limiting Legitimate interest (Art. 6(1)(f)): keeping the Service safe
Writing a short AI summary of why two people are compatible, with Google Gemini (on Vertex AI, in the EU)Your consent (Art. 6(1)(a)), given by both people: a summary is written only when you and the other person have both turned it on. Only the names of the shared topics that are not private are sent - never people's names, photos, messages or answers. Withdraw it at any time in Settings → Privacy choices; any summary can be reported from the app, which takes it down at once. No automated decision with legal effect is made about you.
Crash reporting and service diagnostics Legitimate interest: a working, secure app
Anonymous usage analyticsOnly with your consent (Settings → Privacy choices); currently no analytics SDK is active in the app
Complying with legal obligations and enforcing our Terms Legal obligation (Art. 6(1)(c)); legitimate interest

We do not use your photographs for facial recognition, and we do not make automated decisions about you that produce legal or similarly significant effects.

4. The progressive photo-reveal feature

When you upload photographs, they are stored securely on our EU servers and are never shown directly to other users. A match first sees a fully blurred rendering; as you and your match interact, tiles of the photo become visible. No other user ever receives the original file - only the composited, partially revealed image is delivered to them. Where our automated screening flags a photograph, an authorised member of our team views the original in order to decide it, and every such access is logged. You keep full control and can delete your photos at any time.

5. Sharing of your information

5.1 With other users

Your profile information (first name, age, city, and the profile content you chose to share) is shown to users you are suggested to or matched with, and your photos progressively per Section 4. A match also sees how compatible you two are, overall and on your three strongest topics in common (which can include finances, closeness or family history), as percentages, never your answers themselves. Your last name, email, exact birthdate and your special-category answers are never shown to other users.

5.2 With service providers (processors)

We use a small set of providers, bound by data-processing agreements, to run the Service:

ProviderRoleLocation
Google Cloud / Firebase (Google Ireland Ltd.) Hosting, file storage, realtime updates, AI summaries (Gemini on Vertex AI) EU (Belgium; realtime updates in Google's EU multi-region)
Google Firebase and Google Cloud (Google Ireland Ltd.) Authentication, push delivery (FCM), crash reporting (Crashlytics), automated photo screening (Cloud Vision) Google's global infrastructure, which can include the United States (see Section 10)
Neon Inc.Database hosting EU (Frankfurt, Germany)
[EMAIL PROVIDER]Sending the emails about moderation decisions [EMAIL PROVIDER LOCATION]
Apple / Google app stores & RevenueCat Payment processing for optional subscriptions, when offered Per their own policies

5.3 For legal reasons and business transfers

We may disclose information if required by law or to protect the rights and safety of our users, and in the event of a merger, acquisition or asset sale your information may be transferred to the acquiring entity (you would be notified of any such change).

5.4 No sale of personal data

We do not sell your personal information, and we do not share it with advertisers.

6. Data retention

7. Data security

All traffic is encrypted in transit (TLS) and stored encrypted at rest. Free-text answers from the earlier version of our questionnaire carry an additional application-layer encryption, with a key held separately from the database. Access is restricted, uploads are size- and content-validated, and abuse is rate-limited. No method of transmission or storage is 100% secure, but we apply current industry practice and monitor continuously.

8. Your privacy rights

Under the GDPR (and similar laws where applicable) you have the right to: access a copy of your data; rectify inaccurate data; erasure; restriction of processing; data portability (a structured, machine-readable export); object to processing based on legitimate interests; and withdraw any consent at any time without affecting prior processing.

Users in Switzerland have the same rights under the Federal Act on Data Protection (FADP), and can complain to the Federal Data Protection and Information Commissioner (FDPIC). Religious and political views and the intimate sphere are sensitive data under the FADP too, handled with the same explicit consent.

9. Children's privacy

SoulSinq is intended solely for users who are 18 years of age or older. You tell us your date of birth when you create your account and we refuse any sign-up below 18; we do not check that date against an identity document, so the age you give us is a declaration you make. If we learn that an account belongs to someone under 18 we close it at once and erase its data, once any report involving it has been decided and, where an adult was involved, the evidence has gone to the authorities. If you believe a minor is using the Service, or has given us information, contact us at soulsinq@gmail.com and we will act on it without delay.

10. International data transfers

The Service is hosted in the European Union (Belgium and Germany). Some Google services we rely on run on Google's global infrastructure and can process limited data outside the EU, notably in the United States: sign-in (Firebase Authentication), push delivery (Firebase Cloud Messaging), crash reports (Crashlytics) and photo screening (Cloud Vision). For those transfers we rely on the EU-US and Swiss-US Data Privacy Frameworks, under which Google is certified, and on the European Commission's Standard Contractual Clauses.

11. Changes to this policy

When we make material changes we will update the effective date above and notify you in the app or by email. Continued use of the Service after the effective date constitutes acceptance.

12. Contact

SoulSinq - Privacy
[OPERATOR: FULL LEGAL NAME], [POSTAL ADDRESS, COUNTRY]
Email: soulsinq@gmail.com

The same address is our single electronic point of contact under Articles 11 and 12 of the EU Digital Services Act, for users and for authorities alike. Write in English and we will reply in English; a person reads it, not only an automated system.