Privacy Policy
What Soulmate AI collects, why, who receives it, and the control you have over it.
Last updated: September 6, 2026 · Version 1.0
Soulmate AI is an app in which you talk with an artificial-intelligence companion. Conversations like that can be personal, so this policy is written to describe what actually happens to your data — checked against how the app is built — rather than what would be convenient to say. A few facts belong to the company rather than to the app; they are marked.
1. Who we are
The company responsible for your personal data (the "controller") is AdMetric OÜ, a private limited company registered in Estonia, registry code registry code 17314613, registered address Ruunaoja tn 3, 11415 Tallinn, Estonia ("AdMetric", "we", "us").
Privacy questions and requests: contact@admetric.app. Anything else: contact@admetric.app.
Soulmate AI is offered in English, to adults aged 18 or over, and is distributed primarily in the United States. This policy also explains your rights under United States state privacy laws (§12) and, because we are an EU company, under the GDPR (§13).
2. What we collect
Account
- Email address — if you sign in with email. We send a 6-digit sign-in code to it; there is no password.
- Guest accounts — you can also start as a guest, with no email at all. A guest account is tied to the app installation on your device, and we hold no contact details for it.
- Display name, a short "About me" text and a profile photo — all optional. The photo comes from your photo library only.
- An 18+ confirmation — a yes/no flag. See §3 for what we deliberately do not keep.
- Your consent choices, the version of the terms you accepted and when.
- App language setting.
Your conversations
- The messages you send and the replies you receive, stored in full on our servers.
- A rolling summary of each conversation, written by the AI so that your companion can keep context once a thread grows long.
- Remembered facts ("memories") — a short list of notes per companion that the AI extracts from your conversation (a preference, a detail you mentioned). You can see and delete them in Settings › Companion memories.
- The "today's mood" you pick in your profile, which is sent along with your messages to shape the reply.
- A safety or content classification on a message, when one occurred — see §7.
- Technical measurements of each reply: how long it took and how much text the model processed.
- Virtual gifts you send and photos you unlock with coins, and a record of which of our curated companion photos or voice notes you received. (These are items from our catalog — never recordings or images of you.)
Your companion settings
- Which companions you chose or liked, the personality preset and the two trait sliders you set (warmth, playfulness), and how many days you have talked with each one.
Usage and limits
- How many messages you sent on a given day (to apply the daily limit), your check-in streak, your coin balance and every coin transaction (earned, purchased, spent), rewarded ads you claimed, and likes you placed.
- If you joined through an invite link, which account invited you; if you invited others, whom and when the referral was paid out (when the referral program is active).
Purchases
- Subscription and coin-pack records: the product you bought, whether it is active, when it expires, and the store event that granted it. We never see your card or bank details — payment is handled by Apple or Google.
Notifications
- A push notification token and your platform (iOS/Android), only if you turn notifications on. Notification texts are fixed reminders and never contain your conversation.
Reports you file
- Which message you reported, the reason you selected and when. The optional note you can type in the report form stays on your device and is not sent to us.
Analytics and diagnostics
- Product events from our servers — for example "message sent", "message blocked (and why)", "purchase completed", "onboarding completed", "report filed" — tied to your account number, an opaque identifier that means nothing outside our database. Never your messages, email, name or age. Event names come from a fixed list and free text is stripped before anything is sent. One deliberate exception: when a message is blocked because it suggests a crisis (§7), the event carries no account number and no identifier at all — only an anonymous count.
- Crash reports: the type of error, where in the code it happened, the screen you were on, device model and OS version, and an identifier generated for the app installation (not your account number or email). Message content, emails, quoted text and long numbers are removed before the report leaves your phone.
Advertising and attribution — only if you opt in
- This is off by default. If you turn on "Allow Hotfy analytics and attribution" (during setup or in Settings › Privacy and consent), the app starts the Hotfy SDK, which includes Google's advertising SDK (AdMob). It then receives app events and screens, your opaque account number, device identifiers and, when you watch a rewarded ad, ad-interaction data. Google's SDK may also infer an approximate location from your IP address and collect diagnostics.
- On iOS, cross-app attribution (which campaign brought you to the app) runs only if you also allow tracking in the iOS "Allow tracking" prompt. On Android, the SDK may use the Google advertising ID and the Play install referrer.
- Hotfy and Google never receive your date of birth, your age, or the content of your conversations.
Support
- If you email us, we receive your address and what you wrote.
3. What we do not collect
- Your date of birth is never stored and never leaves your device. When you enter it, your age is calculated on the phone itself and only the result — "18 or older: yes/no" — is sent to us. It is not in your data export because we do not have it.
- No voice or audio recordings of you. The app can play voice notes from your companion, but it never records you and does not use the microphone.
- No camera. A profile photo comes from your library only, if you choose one.
- No location from your device. (If you opt in to advertising, Google's SDK may infer an approximate location from your IP address — see §2.)
- No contacts, no calendar, no files.
- No payment card or bank details.
- No advertising identifier unless you opt in to advertising and attribution as described in §2.
4. Why we use your data
- To generate your companion's replies. This is the service itself and requires sending your messages to our AI provider (§5).
- To keep your account and let you sign back in.
- To give your companion memory across conversations.
- To keep the service safe: classifying messages so we can block sexually explicit output and show support resources when a message suggests a crisis (§7).
- To apply usage limits and honor your purchases and coins.
- To send notifications, only if you allowed them.
- To understand how the app is used and to fix crashes, through analytics and error reports that never contain your messages or your identity.
- To measure marketing and show rewarded ads, only if you opted in.
- To review reports you file and to investigate abuse of the service.
- To meet legal obligations, for example tax records for purchases, and to respond to lawful requests.
The legal bases for each of these under the GDPR are listed in §13.
5. How the AI works with your data
Each time you send a message, our servers assemble a prompt made of: the companion's persona, your personality settings for that companion, the mood you picked, the rolling summary, the remembered facts, and the most recent turns of the conversation. That prompt is sent to OpenRouter, our AI provider, which runs it on Google Gemini models and returns the reply. Your email and display name are not part of the prompt.
The same provider is also used, with the same data, to:
- classify a message for safety when our own keyword check is inconclusive (§7);
- write the rolling summary and extract the remembered facts;
- decide whether your companion should send one of our curated photos or voice notes, when that feature is enabled.
Replies are generated by a machine. Nobody at AdMetric reads your conversation or writes replies (see §8 for the one, audited exception when you report a message).
Training. We do not train AI models on your conversations. OpenRouter and Google process your prompts under their business terms. We have not agreed to any use of your prompts for training, and we are configuring our AI provider to disable data retention where that control is offered; until then, their business terms govern.
6. Who receives your data
These are the companies that receive any of your data. Each acts as our service provider ("processor") and may only use the data to provide its service to us. All of them are based in the United States, and your data is processed there.
| Who | What they receive | Why |
|---|---|---|
| Convex | Everything described in §2 — this is our database, authentication and file storage | Runs the app's backend |
| OpenRouter, which runs Google Gemini models | The content of your messages, the companion's persona, your personality settings and mood, the rolling summary and the remembered facts | To generate replies, classify unclear messages for safety, and write summaries and memories |
| Resend | Your email address, the sign-in code, and the contents of your data export | Delivers sign-in emails and data exports |
| PostHog | Event names, your opaque account number and technical metadata. Never messages, email, name or age — and a crisis detection is counted with no identifier at all (§7) | Product analytics |
| Sentry | Crash and error reports, scrubbed of message content and personal data | Detecting and fixing crashes |
| RevenueCat | Your opaque account number (used as your customer ID) and the purchase and subscription events reported by Apple or Google | Subscriptions and coin packs |
| Expo, and through it Apple or Google | Your push token and the text of the notification (never your conversation) | Delivering notifications |
| Hotfy (our technology partner) and Google AdMob — only if you opt in | App events, device and advertising identifiers, campaign attribution, ad-interaction data | Analytics, install attribution and rewarded ads |
| Apple / Google | App distribution and payment, under their own privacy policies | App stores and billing |
We do not sell your data, and we do not give it to data brokers. The companion voice notes in the app are produced by our team with ElevenLabs from scripts we write — none of your data is sent to ElevenLabs.
7. Safety classification and sensitive topics
Every message you send is checked automatically before your companion replies, and every reply is checked before it is shown. The first check is a keyword list on our servers; when it is inconclusive, the message is sent to our AI provider for a one-word classification. Details of what we look for and what happens are on our Safety & Crisis Protocol page.
If a message appears to describe suicidal thoughts or self-harm, your companion does not reply. Instead the app shows a message from Soulmate AI with crisis resources. We record that this classification happened on that message, in our database. Our analytics provider (PostHog) receives only an anonymous count that the safety feature triggered and whether the keyword check or the AI classifier caught it — no account number, no identifier and no text. It is built so that nothing in analytics can show which user was involved.
This is an inference about your mental health, which privacy laws treat as sensitive. We use it only to show you resources and to keep the service safe. We do not use it for advertising, marketing, pricing or any commercial purpose; we do not share it with anyone other than the processors above; and it is deleted with your account. We do not notify anyone, and we do not contact emergency services on your behalf.
Messages that ask for sexually explicit content, and replies that would contain it, are also classified: the companion steers away in the first case, and the reply is blocked in the second. Those classifications are recorded on the message the same way.
Soulmate AI is not an emergency service and not a substitute for professional care. If you are in danger, contact the emergency services where you are.
8. Who can see your conversations
Your conversations are never written to our logs, analytics or crash reports. This is enforced by the code — free text is stripped at the boundary — not by policy alone.
Your messages leave our database in only two situations:
- To the AI provider, for the purposes in §5.
- To a member of our team, if — and only if — you report a specific message. In that case we can read the reported message and at most one message immediately before and after it, within that one conversation. Every such access is recorded in an internal audit log.
Our administrators can otherwise see account-level information — email, display name, plan, usage counts, coin balance, consent choices and filed reports — to provide support, and can delete an account when you ask us to. They cannot browse conversations.
9. How long we keep your data
We keep your data for as long as your account exists. There is currently no automatic expiry or inactivity deletion. When you delete your account, everything listed in §2 is erased from our database at once, in a single transaction (see Delete your account for the exact list).
What survives account deletion:
- Entries in our administrator audit log that referred to your account are kept for accountability, but your email address in them is replaced by an anonymous marker.
- Purchase records held by Apple, Google and RevenueCat under their own retention rules, and our accounting records where the law requires them.
- Data already sent to the processors in §6 is deleted according to their retention schedules (for example, email delivery logs at Resend, or analytics events at PostHog keyed to an account number that no longer exists).
- If our hosting provider keeps encrypted backups, deleted data may persist in them for a limited period before it is overwritten. Encrypted backups of the production database are kept for up to 30 days and then destroyed, so deleted data can persist in a backup for at most that long.
If we introduce a retention period for inactive accounts, we will update this policy first.
10. Your rights and how to use them
These rights are available to everyone, wherever you live. §12 and §13 add the details specific laws require.
- Access and export. Settings › Your data › Export my data emails you a file with your email, account settings, consent choices, companions (name, persona and a summary of memories), usage counts, purchase and subscription records, and the list of companion media you received. It does not include the text of your conversations, your "About me" text, your photo, your coin history, gifts or likes. If you want a full copy including messages, write to contact@admetric.app.
- Correct. Edit your name, photo and "About me" in the app. See and delete individual memories — or all of them — in Settings › Companion memories. For anything else, write to us.
- Delete. Settings › Your data › Delete my account erases everything immediately and permanently. If you no longer have the app, see Delete your account.
- Withdraw consent. Turn off Hotfy analytics and attribution in Settings › Privacy and consent › Manage consents; turn off notifications in Settings › Notifications; change the iOS tracking permission in iPhone Settings › Privacy & Security › Tracking. Consent to AI processing of your messages cannot be withdrawn while keeping the account, because generating replies is the service — you withdraw it by deleting the account.
- Opt out of targeted advertising and of "sharing" for advertising. Same controls as above (the Hotfy toggle and the OS tracking setting). With them off, no advertising SDK runs and nothing is shared for advertising.
- Object to analytics. The server-side product analytics (§2) cannot currently be switched off for one account while you keep using the app. If you object, write to us and we will review your request; deleting your account ends it entirely.
- Appeal. If we decline a request, reply to our answer and we will have someone who was not involved in the first decision review it, within 45 days.
How we handle requests. Requests are free. We answer within 30 days if you are in the EU/EEA and within 45 days otherwise; if we need longer, as the law allows, we will tell you why. To protect your data we verify requests by sending a code to the email address on the account — so a guest account, which has no email, can only be exported or deleted from inside the app. You may use an authorized agent to make a request if they can show your written permission. We never treat you differently for exercising a right.
11. Children
Soulmate AI is for people 18 and over. We ask for your date of birth once and check it on your device; anyone under 18 is blocked before the chat is reachable. We rely on what you tell us — we do not verify documents. We do not knowingly collect data from anyone under 18, and if we learn that we have, we delete the account. If you believe someone under 18 is using the app, write to contact@admetric.app.
12. United States state privacy rights
Whether a given state law formally applies to a company of our size depends on thresholds (revenue, number of consumers, share of revenue from data). As of the date of this policy, AdMetric OÜ is below the CCPA "business" thresholds; we honor the rights described here for all US residents regardless. We honor the rights below for all US residents regardless.
12.1 California (CCPA / CPRA)
In the last 12 months we have collected these categories of personal information:
| Category | Examples in Soulmate AI | Disclosed to (business purpose) |
|---|---|---|
| Identifiers | Email, display name, account number, push token; device and advertising identifiers only if you opt in to ads | Convex, Resend, Expo, RevenueCat; Hotfy/Google if opted in |
| Personal records (Cal. Civ. Code §1798.80) | Name, email | Convex, Resend |
| Commercial information | Subscription and coin-pack purchases, coin transactions | Convex, RevenueCat, Apple/Google |
| Internet or network activity | App events, screens viewed, crash data | PostHog, Sentry; Hotfy/Google if opted in |
| Geolocation | None collected by us; Google's ad SDK may infer approximate location from IP if you opt in | Google, if opted in |
| Audio, visual | Optional profile photo | Convex |
| Inferences | Remembered facts, companion preferences, safety classification | Convex, OpenRouter/Google |
| Sensitive personal information | Sign-in codes and session tokens; the safety classification (a mental-health inference, §7) | Convex, OpenRouter/Google |
| Other personal information | The content of your conversations with your companion (we are the intended recipient of those messages) | Convex, OpenRouter/Google |
Sources: you, your device, our own processing, Apple/Google/RevenueCat for purchases, and — if you opt in — the advertising SDK. Purposes: §4.
We do not sell personal information and have not in the last 12 months. "Sharing" for cross-context behavioral advertising happens only if you turn on Hotfy analytics and attribution and, on iOS, allow tracking: the advertising SDK then receives advertising identifiers and ad data, which California law may treat as "sharing". To opt out of sale or sharing: Settings › Privacy and consent › Manage consents › turn off the Hotfy toggle; iPhone Settings › Privacy & Security › Tracking; on Android, Settings › Google › Ads. You can also email us with the subject "Do Not Sell or Share". We do not knowingly sell or share the personal information of anyone under 16 — the app has no users under 18.
Sensitive personal information is used only to provide the service you asked for, to keep it secure and to show safety resources — purposes California permits without a "limit" right. We honor requests to limit its use anyway, to the extent the service can still function.
Your California rights: to know what we collect and how it is used and disclosed; to delete; to correct; to opt out of sale or sharing; to limit the use of sensitive personal information; and not to be discriminated against for exercising them. Use the controls in §10 or email contact@admetric.app. We do not disclose personal information to third parties for their own direct marketing ("Shine the Light").
12.2 Consumer health data — Washington, Nevada, Connecticut and similar laws
One thing we hold counts as consumer health data: the automated safety classification described in §7, which is an inference that a message may indicate a risk of suicide or self-harm.
- Source: derived from your own messages by our keyword check and, when inconclusive, by our AI provider's classification. We do not collect health data from anyone else.
- Purpose: to show you crisis resources at that moment and to keep the service safe; in aggregate, to know how often the safety feature triggers. Never for advertising, marketing, pricing or profiling.
- Who receives it: our processors only — Convex (storage) and OpenRouter/Google (classification of unclear messages). Our analytics provider receives only an anonymous count that the feature triggered, with no account number or identifier of any kind — nothing that can be linked to you. We do not sell it or share it with any other third party or affiliate. No affiliated company receives your personal data.
- Consent: the check runs on every message and cannot be separated from chatting. It happens only after you have accepted the processing of your messages by the AI during setup. You withdraw by deleting your account. The setup consent names this safety analysis explicitly.
- Your rights: to confirm whether we hold such data and access it; to know who received it (the list above); to withdraw consent; to delete it (deleting your account deletes it, or write to us); and to appeal a refusal within 45 days. Email contact@admetric.app.
- We do not use geofencing of any kind.
12.3 Other states
If you live in Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, Iowa, Indiana, Tennessee, Delaware, New Jersey, New Hampshire, Kentucky, Nebraska, Maryland, Minnesota, Rhode Island or another state with a comprehensive privacy law, you have the right to: confirm whether we process your data and access it; correct it; delete it; obtain a portable copy; opt out of targeted advertising, sale, and profiling in furtherance of decisions with legal or similarly significant effects (we do none of that profiling); and appeal a refusal. We process sensitive data (the safety classification, §7) only with your consent as described above. Exercise these rights through §10. If we deny your appeal, you may contact your state's Attorney General.
13. European Union, EEA and the GDPR
Because AdMetric is established in Estonia, the General Data Protection Regulation applies to our processing of personal data, wherever you live. This section states what the GDPR requires; the rights in §10 are the same rights, in plain language.
Legal bases
| Processing | Legal basis |
|---|---|
| Your account, storing your conversations, memories, limits, purchases and coins | Performance of our contract with you (Art. 6(1)(b)) |
| Sending your messages to the AI provider to generate replies | Performance of the contract (Art. 6(1)(b)); you also expressly accept it during setup |
| The safety classification (a health-related inference, §7) | Your explicit consent given during setup (Art. 9(2)(a)); where a life may be at risk, the protection of vital interests (Art. 9(2)(c)). We rely on your explicit consent, given during setup when you agree to AI processing of your messages, as the legal basis for this safety analysis (GDPR Article 9(2)(a)); you can withdraw it at any time in Settings. |
| Server-side product analytics and crash reports (pseudonymous, no content) | Our legitimate interest in understanding, securing and improving the service (Art. 6(1)(f)) |
| Push notifications | Your consent (Art. 6(1)(a)) |
| Hotfy analytics, attribution and advertising | Your consent (Art. 6(1)(a)), off by default |
| Reviewing reports, preventing abuse, security | Legitimate interest (Art. 6(1)(f)) |
| Tax and accounting records, responding to lawful requests | Legal obligation (Art. 6(1)(c)) |
International transfers
Our processors (§6) are in the United States, so your data is transferred outside the EU/EEA. We rely on the European Commission's Standard Contractual Clauses with each processor and, where the processor is certified (for example PostHog), the EU-US Data Privacy Framework. You can ask us for a copy of the relevant safeguards.
Your GDPR rights
Access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), portability (Art. 20), objection to processing based on legitimate interest (Art. 21), and withdrawal of consent at any time without affecting earlier processing. You are not subject to decisions based solely on automated processing that produce legal or similarly significant effects: the safety classification only shows you resources, and the daily message limit is a fixed rule, not profiling.
You may complain to the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon, www.aki.ee) or to the supervisory authority where you live. Data protection officer: we have not designated a data protection officer; privacy requests go to contact@admetric.app and are handled by the management board.
14. Security
Your data is held by Convex and encrypted in transit and at rest by that platform. Sign-in uses a one-time code valid for a short period; there is no password to steal or reuse. API keys for our providers live only on our servers, never in the app. Conversation content is structurally kept out of logs, analytics and crash reports. Staff access to conversation content is limited to reported messages and is audited. We do not add a separate layer of end-to-end encryption, which means our hosting provider — and, in the narrow case of a report, our team — is technically able to access stored content. No system is perfectly secure; if a breach affects your data we will notify you and the authorities as the law requires.
15. Changes to this policy
We may update this policy. If we make a material change — in particular, if we begin sharing data with a new company or for a new purpose — we will ask for your consent again inside the app before the change takes effect. The date at the top tells you when it was last revised.
16. Contact
Privacy and your rights: contact@admetric.app
Anything else: contact@admetric.app
Post: AdMetric OÜ, Ruunaoja tn 3, 11415 Tallinn, Estonia, Estonia