Privacy Policy

What Soulmate AI collects, why, who receives it, and the control you have over it.

Last updated: September 6, 2026 · Version 1.0

Soulmate AI is an app in which you talk with an artificial-intelligence companion. Conversations like that can be personal, so this policy is written to describe what actually happens to your data — checked against how the app is built — rather than what would be convenient to say. A few facts belong to the company rather than to the app; they are marked.

1. Who we are

The company responsible for your personal data (the "controller") is AdMetric OÜ, a private limited company registered in Estonia, registry code registry code 17314613, registered address Ruunaoja tn 3, 11415 Tallinn, Estonia ("AdMetric", "we", "us").

Privacy questions and requests: contact@admetric.app. Anything else: contact@admetric.app.

Soulmate AI is offered in English, to adults aged 18 or over, and is distributed primarily in the United States. This policy also explains your rights under United States state privacy laws (§12) and, because we are an EU company, under the GDPR (§13).

2. What we collect

Account

Your conversations

Your companion settings

Usage and limits

Purchases

Notifications

Reports you file

Analytics and diagnostics

Advertising and attribution — only if you opt in

Support

3. What we do not collect

4. Why we use your data

The legal bases for each of these under the GDPR are listed in §13.

5. How the AI works with your data

Each time you send a message, our servers assemble a prompt made of: the companion's persona, your personality settings for that companion, the mood you picked, the rolling summary, the remembered facts, and the most recent turns of the conversation. That prompt is sent to OpenRouter, our AI provider, which runs it on Google Gemini models and returns the reply. Your email and display name are not part of the prompt.

The same provider is also used, with the same data, to:

Replies are generated by a machine. Nobody at AdMetric reads your conversation or writes replies (see §8 for the one, audited exception when you report a message).

Training. We do not train AI models on your conversations. OpenRouter and Google process your prompts under their business terms. We have not agreed to any use of your prompts for training, and we are configuring our AI provider to disable data retention where that control is offered; until then, their business terms govern.

6. Who receives your data

These are the companies that receive any of your data. Each acts as our service provider ("processor") and may only use the data to provide its service to us. All of them are based in the United States, and your data is processed there.

WhoWhat they receiveWhy
Convex Everything described in §2 — this is our database, authentication and file storage Runs the app's backend
OpenRouter, which runs Google Gemini models The content of your messages, the companion's persona, your personality settings and mood, the rolling summary and the remembered facts To generate replies, classify unclear messages for safety, and write summaries and memories
Resend Your email address, the sign-in code, and the contents of your data export Delivers sign-in emails and data exports
PostHog Event names, your opaque account number and technical metadata. Never messages, email, name or age — and a crisis detection is counted with no identifier at all (§7) Product analytics
Sentry Crash and error reports, scrubbed of message content and personal data Detecting and fixing crashes
RevenueCat Your opaque account number (used as your customer ID) and the purchase and subscription events reported by Apple or Google Subscriptions and coin packs
Expo, and through it Apple or Google Your push token and the text of the notification (never your conversation) Delivering notifications
Hotfy (our technology partner) and Google AdMobonly if you opt in App events, device and advertising identifiers, campaign attribution, ad-interaction data Analytics, install attribution and rewarded ads
Apple / Google App distribution and payment, under their own privacy policies App stores and billing

We do not sell your data, and we do not give it to data brokers. The companion voice notes in the app are produced by our team with ElevenLabs from scripts we write — none of your data is sent to ElevenLabs.

7. Safety classification and sensitive topics

Every message you send is checked automatically before your companion replies, and every reply is checked before it is shown. The first check is a keyword list on our servers; when it is inconclusive, the message is sent to our AI provider for a one-word classification. Details of what we look for and what happens are on our Safety & Crisis Protocol page.

If a message appears to describe suicidal thoughts or self-harm, your companion does not reply. Instead the app shows a message from Soulmate AI with crisis resources. We record that this classification happened on that message, in our database. Our analytics provider (PostHog) receives only an anonymous count that the safety feature triggered and whether the keyword check or the AI classifier caught it — no account number, no identifier and no text. It is built so that nothing in analytics can show which user was involved.

This is an inference about your mental health, which privacy laws treat as sensitive. We use it only to show you resources and to keep the service safe. We do not use it for advertising, marketing, pricing or any commercial purpose; we do not share it with anyone other than the processors above; and it is deleted with your account. We do not notify anyone, and we do not contact emergency services on your behalf.

Messages that ask for sexually explicit content, and replies that would contain it, are also classified: the companion steers away in the first case, and the reply is blocked in the second. Those classifications are recorded on the message the same way.

Soulmate AI is not an emergency service and not a substitute for professional care. If you are in danger, contact the emergency services where you are.

8. Who can see your conversations

Your conversations are never written to our logs, analytics or crash reports. This is enforced by the code — free text is stripped at the boundary — not by policy alone.

Your messages leave our database in only two situations:

Our administrators can otherwise see account-level information — email, display name, plan, usage counts, coin balance, consent choices and filed reports — to provide support, and can delete an account when you ask us to. They cannot browse conversations.

9. How long we keep your data

We keep your data for as long as your account exists. There is currently no automatic expiry or inactivity deletion. When you delete your account, everything listed in §2 is erased from our database at once, in a single transaction (see Delete your account for the exact list).

What survives account deletion:

If we introduce a retention period for inactive accounts, we will update this policy first.

10. Your rights and how to use them

These rights are available to everyone, wherever you live. §12 and §13 add the details specific laws require.

How we handle requests. Requests are free. We answer within 30 days if you are in the EU/EEA and within 45 days otherwise; if we need longer, as the law allows, we will tell you why. To protect your data we verify requests by sending a code to the email address on the account — so a guest account, which has no email, can only be exported or deleted from inside the app. You may use an authorized agent to make a request if they can show your written permission. We never treat you differently for exercising a right.

11. Children

Soulmate AI is for people 18 and over. We ask for your date of birth once and check it on your device; anyone under 18 is blocked before the chat is reachable. We rely on what you tell us — we do not verify documents. We do not knowingly collect data from anyone under 18, and if we learn that we have, we delete the account. If you believe someone under 18 is using the app, write to contact@admetric.app.

12. United States state privacy rights

Whether a given state law formally applies to a company of our size depends on thresholds (revenue, number of consumers, share of revenue from data). As of the date of this policy, AdMetric OÜ is below the CCPA "business" thresholds; we honor the rights described here for all US residents regardless. We honor the rights below for all US residents regardless.

12.1 California (CCPA / CPRA)

In the last 12 months we have collected these categories of personal information:

CategoryExamples in Soulmate AIDisclosed to (business purpose)
IdentifiersEmail, display name, account number, push token; device and advertising identifiers only if you opt in to adsConvex, Resend, Expo, RevenueCat; Hotfy/Google if opted in
Personal records (Cal. Civ. Code §1798.80)Name, emailConvex, Resend
Commercial informationSubscription and coin-pack purchases, coin transactionsConvex, RevenueCat, Apple/Google
Internet or network activityApp events, screens viewed, crash dataPostHog, Sentry; Hotfy/Google if opted in
GeolocationNone collected by us; Google's ad SDK may infer approximate location from IP if you opt inGoogle, if opted in
Audio, visualOptional profile photoConvex
InferencesRemembered facts, companion preferences, safety classificationConvex, OpenRouter/Google
Sensitive personal informationSign-in codes and session tokens; the safety classification (a mental-health inference, §7)Convex, OpenRouter/Google
Other personal informationThe content of your conversations with your companion (we are the intended recipient of those messages)Convex, OpenRouter/Google

Sources: you, your device, our own processing, Apple/Google/RevenueCat for purchases, and — if you opt in — the advertising SDK. Purposes: §4.

We do not sell personal information and have not in the last 12 months. "Sharing" for cross-context behavioral advertising happens only if you turn on Hotfy analytics and attribution and, on iOS, allow tracking: the advertising SDK then receives advertising identifiers and ad data, which California law may treat as "sharing". To opt out of sale or sharing: Settings › Privacy and consent › Manage consents › turn off the Hotfy toggle; iPhone Settings › Privacy & Security › Tracking; on Android, Settings › Google › Ads. You can also email us with the subject "Do Not Sell or Share". We do not knowingly sell or share the personal information of anyone under 16 — the app has no users under 18.

Sensitive personal information is used only to provide the service you asked for, to keep it secure and to show safety resources — purposes California permits without a "limit" right. We honor requests to limit its use anyway, to the extent the service can still function.

Your California rights: to know what we collect and how it is used and disclosed; to delete; to correct; to opt out of sale or sharing; to limit the use of sensitive personal information; and not to be discriminated against for exercising them. Use the controls in §10 or email contact@admetric.app. We do not disclose personal information to third parties for their own direct marketing ("Shine the Light").

12.2 Consumer health data — Washington, Nevada, Connecticut and similar laws

One thing we hold counts as consumer health data: the automated safety classification described in §7, which is an inference that a message may indicate a risk of suicide or self-harm.

12.3 Other states

If you live in Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, Iowa, Indiana, Tennessee, Delaware, New Jersey, New Hampshire, Kentucky, Nebraska, Maryland, Minnesota, Rhode Island or another state with a comprehensive privacy law, you have the right to: confirm whether we process your data and access it; correct it; delete it; obtain a portable copy; opt out of targeted advertising, sale, and profiling in furtherance of decisions with legal or similarly significant effects (we do none of that profiling); and appeal a refusal. We process sensitive data (the safety classification, §7) only with your consent as described above. Exercise these rights through §10. If we deny your appeal, you may contact your state's Attorney General.

13. European Union, EEA and the GDPR

Because AdMetric is established in Estonia, the General Data Protection Regulation applies to our processing of personal data, wherever you live. This section states what the GDPR requires; the rights in §10 are the same rights, in plain language.

Legal bases

ProcessingLegal basis
Your account, storing your conversations, memories, limits, purchases and coins Performance of our contract with you (Art. 6(1)(b))
Sending your messages to the AI provider to generate replies Performance of the contract (Art. 6(1)(b)); you also expressly accept it during setup
The safety classification (a health-related inference, §7) Your explicit consent given during setup (Art. 9(2)(a)); where a life may be at risk, the protection of vital interests (Art. 9(2)(c)). We rely on your explicit consent, given during setup when you agree to AI processing of your messages, as the legal basis for this safety analysis (GDPR Article 9(2)(a)); you can withdraw it at any time in Settings.
Server-side product analytics and crash reports (pseudonymous, no content) Our legitimate interest in understanding, securing and improving the service (Art. 6(1)(f))
Push notificationsYour consent (Art. 6(1)(a))
Hotfy analytics, attribution and advertisingYour consent (Art. 6(1)(a)), off by default
Reviewing reports, preventing abuse, securityLegitimate interest (Art. 6(1)(f))
Tax and accounting records, responding to lawful requestsLegal obligation (Art. 6(1)(c))

International transfers

Our processors (§6) are in the United States, so your data is transferred outside the EU/EEA. We rely on the European Commission's Standard Contractual Clauses with each processor and, where the processor is certified (for example PostHog), the EU-US Data Privacy Framework. You can ask us for a copy of the relevant safeguards.

Your GDPR rights

Access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), portability (Art. 20), objection to processing based on legitimate interest (Art. 21), and withdrawal of consent at any time without affecting earlier processing. You are not subject to decisions based solely on automated processing that produce legal or similarly significant effects: the safety classification only shows you resources, and the daily message limit is a fixed rule, not profiling.

You may complain to the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon, www.aki.ee) or to the supervisory authority where you live. Data protection officer: we have not designated a data protection officer; privacy requests go to contact@admetric.app and are handled by the management board.

14. Security

Your data is held by Convex and encrypted in transit and at rest by that platform. Sign-in uses a one-time code valid for a short period; there is no password to steal or reuse. API keys for our providers live only on our servers, never in the app. Conversation content is structurally kept out of logs, analytics and crash reports. Staff access to conversation content is limited to reported messages and is audited. We do not add a separate layer of end-to-end encryption, which means our hosting provider — and, in the narrow case of a report, our team — is technically able to access stored content. No system is perfectly secure; if a breach affects your data we will notify you and the authorities as the law requires.

15. Changes to this policy

We may update this policy. If we make a material change — in particular, if we begin sharing data with a new company or for a new purpose — we will ask for your consent again inside the app before the change takes effect. The date at the top tells you when it was last revised.

16. Contact

Privacy and your rights: contact@admetric.app
Anything else: contact@admetric.app
Post: AdMetric OÜ, Ruunaoja tn 3, 11415 Tallinn, Estonia, Estonia