Privacy Policy for BlessSoul
Effective Date: 19 July 2026 | Last Updated: 12 August 2026
The short version. This summary is for convenience only; the full policy below governs. BlessSoul creates an anonymous profile the first time you open it and stores everything you create, so it can sync across your devices; creating an account is optional and simply links that data to your email. We do not sell your data, do not use it for advertising, and do not use your content to train AI models. Text you write in Soul Manifest is sent to OpenAI to generate affirmations — without your name, email or user ID attached. Voice notes are stored privately and are never transcribed or analysed. Nothing you write is scanned, analysed or profiled — section 5 sets out exactly who can access your data and when. If a paid subscription lapses and is not renewed, the account is deleted after 30 days.
Who We Are
BlessSoul is developed and operated by Praveena H D, a sole proprietor based in Shivamogga, Karnataka, India. For the purposes of the EU and UK General Data Protection Regulation, Praveena H D is the data controller. Under India's Digital Personal Data Protection Act, 2023, we act as the Data Fiduciary.
Contact: support@blesssoul.com
This policy explains what we collect, why, where it goes, how long we keep it and what rights you have. It should be read together with our Terms of Service.
Solo Operation — What That Means for Your Privacy
BlessSoul is run by one person. We comply with applicable data protection law, but you should understand the practical limits: there is no dedicated privacy team, no 24/7 security monitoring, and no enterprise security apparatus. Privacy requests are handled by one individual and we will generally use the full statutory response window (30 days under GDPR, extendable to 60 for complex requests; 45 days under CCPA, extendable to 90). Our security measures are described in section 7 and reflect these constraints.
1. Information We Collect
1.1 Account Information
You can use BlessSoul as a guest, without giving us any personal details. The first time you open the App we create an anonymous profile — an internal identifier with no name or email attached — so the content you create can be saved and synced (see 1.2). Creating an account is optional; if you do, your existing guest data is linked to it and we then hold:
- Email address — collected only if you create an account, and used for authentication and account emails. It is not required to use the App as a guest.
- Password — only if you register with email and password. It is hashed by our authentication provider and we never see or store it in readable form.
- Display name — optional.
- Date of birth — optional, entered in Profile if you choose. It is shown back to you in the App and is not used for any other purpose.
- Profile picture — optional. Stored on your device only. It is never uploaded to our servers, and consequently does not transfer to a new device or survive reinstalling the App.
- Sign-in provider — if you use Sign in with Apple or Google Sign-In, we receive the email address and name released by that provider. Sign in with Apple lets you hide your real address behind a private relay, and we work fine with that.
1.2 Content You Create
This is the substance of the App and is stored on your device and in our cloud database:
- Goals, milestones, subtasks, progress entries and notes
- Habits and completion records
- Manifestations — your written intentions and desires, chosen methods, affirmations, practice entries and recorded evidence or "divine signs"
- Schedules — time blocks, titles, notes, and saved Soul Plans
- Soul Awakening — your journey progress and your Soul Record, including written reflections, vows and chosen practices
- Voice notes — optional audio recordings made during Soul Awakening (see section 4)
- Quote activity — favourites and reading progress
- Feedback — survey responses if you choose to give them
Much of this is personal and reflective in nature. We treat it accordingly: it is private to your account, is not shown to other users, and is not used for advertising or model training.
1.3 Onboarding Answers
To personalise the App we ask a short series of questions:
- Phase 1 (required): how you found us, age range, gender, main motivation, primary goal, belief in manifestation, and the life area you want to focus on.
- Phase 2 (required): creating your first manifestation, from which the App generates a starting goal and habit.
- Phase 3 (optional, and skippable question by question): quote style preferences, interaction preferences, wellbeing practices, and the topics you want to follow.
Some of these answers — such as religious preference or zodiac sign, if you provide them — are used to filter content so you are not shown material that does not suit you. Under GDPR, information revealing religious or philosophical belief is a special category of data; we process it only with your explicit consent, given by choosing to answer, and solely to tailor content. You may skip these questions or change your answers later.
1.4 Subscription Information
- Plan, status (active, cancelled, expired), and start/end dates
- An anonymous customer identifier issued by RevenueCat
- Apple receipt data for validation
We never receive or store your card number, billing address or any financial information. Apple processes all payments.
1.5 Analytics and Diagnostics
Collected only in public App Store builds. Analytics and crash reporting are disabled entirely in development builds.
We record events, not content — for example: app opens and screen views; sign-up and sign-in method; that a goal was created (with its type and priority, not its title); that a quote was viewed, favourited or shared; that a schedule block was created (with its duration); Soul Awakening milestones (a day number, or a count of manifestations); onboarding progress (which question was reached, not the answer given); paywall and purchase events; settings and theme changes; and errors.
Your written content never goes to analytics. No manifestation text, goal title, reflection, journal entry or voice recording is included in any analytics event. Your user identifier is truncated before being sent to analytics, and hashed before being sent to crash reporting.
We also record in-app events about the Soul Awakening journey in our own database — such as which day was opened or sealed, and how you answered a fixed-choice question. These records contain only predefined values, never text you wrote.
1.6 Technical Information
Device model, iOS version, app version, language, network connectivity status, an anonymous device identifier used by analytics, and crash logs and stack traces. General location is derived at country or region level only — we do not collect GPS or precise location.
1.7 AI Usage Logs
When an AI feature runs, our server records the account it belonged to, which feature was used, which AI model, how much text was processed, the estimated cost, how long it took, and whether it worked. These logs do not contain the text of your prompt or of the AI's response. They exist for cost control, rate limiting and debugging.
1.8 What We Do Not Collect
- ✗ Precise or GPS location
- ✗ Contacts or address book
- ✗ Your system calendar
- ✗ Your photo library (only the single profile photo you pick, which stays on your device)
- ✗ Camera or video
- ✗ Health or HealthKit data
- ✗ Biometric data — Face ID and Touch ID are handled entirely by iOS and never shared with us
- ✗ Advertising identifiers (IDFA), ad networks or third-party ad trackers
- ✗ Browsing or search history outside the App
- ✗ Social media activity, even if you sign in with Google or Apple
- ✗ Data from other apps on your device
We do not track you across other companies' apps or websites, and we do not sell or share your personal information for cross-context behavioural advertising.
IP addresses: our own application code does not collect or log IP addresses, and our rate limiting is keyed to your account rather than your network address. However, our infrastructure providers necessarily process IP addresses at the network layer as part of ordinary server logging and security, and analytics providers use IP to derive country-level location before discarding it.
2. Why We Use It, and Our Legal Basis
| Purpose | Data | GDPR Legal Basis |
|---|---|---|
| Create and authenticate your account | Email, password or Apple/Google sign-in | Contract |
| Store and sync your content across devices | Content you create | Contract |
| Generate AI affirmations and suggestions | Manifestation text, goal titles | Contract |
| Deliver reminders you set up | Schedule and reminder settings | Contract |
| Manage subscription and entitlements | Subscription data | Contract |
| Send account and subscription emails | Email address | Contract |
| Personalise and filter content | Onboarding answers | Consent (special categories) / Legitimate interests (other) |
| Improve the App, fix bugs, measure retention | Analytics, crash data | Legitimate interests |
| Prevent fraud and abuse of trials and offers | Subscription and account records | Legitimate interests |
| Meet tax, accounting and legal obligations | Transaction records | Legal obligation |
Where we rely on legitimate interests, we have considered the impact on you and limited the processing accordingly — for example by excluding your written content from analytics entirely. You may object to processing based on legitimate interests by emailing us with the subject "Privacy Request — Object to Processing."
2.1 Withdrawing Consent
Where we rely on consent, you can withdraw it at any time: turn off notifications in iOS Settings; remove your profile picture in Profile; revoke microphone access in iOS Settings; or change or clear optional onboarding answers. Withdrawal does not affect processing already carried out. Withdrawing consent for essential processing may make the App unusable.
2.2 Marketing
We send transactional emails only — welcome messages, subscription status and expiry notices, deletion warnings, password resets, security notices and support replies. We do not send marketing email and do not sell your address to anyone.
3. Artificial Intelligence
3.1 Where AI Is Actually Used
Only Soul Manifest sends your data to an AI service. To be precise:
- Soul Manifest — yes. Your manifestation text and related details are sent, via our own server, to the OpenAI API to generate affirmations, method suggestions, goal suggestions and celebration messages.
- Soul Awakening — no. Its 7-day content is written by hand and ships inside the App. No AI is involved, and nothing you write or record in it is sent to any AI service.
- Sleep affirmations — no. Written in advance and served from our database.
- Soul Portal — no. Cosmic event content is stored in advance.
- Soul Spark quotes — no. Served from our database. No personal data is sent anywhere when you view quotes.
3.2 What Is Sent — and What Is Not
When an AI request runs, the request is made by our server, not by your device. It includes the manifestation text you wrote, your chosen category, and where relevant the titles of your existing goals.
No personal identifiers are sent to OpenAI. Your name, email address and user ID are not included in the request. Your identity is used by our own server only, to check your subscription and apply rate limits — it is not forwarded onward.
However, the text itself is personal. What you write about what you want in life is sent to OpenAI in order to generate a response. Please keep that in mind and avoid entering information you would not want processed by a third-party provider — such as health details, financial account details, or information identifying other people.
3.3 OpenAI's Handling
OpenAI processes these requests as our service provider. Under its API terms, API inputs and outputs are not used to train its models, and are retained for a limited period (currently up to 30 days) for abuse monitoring before deletion. Processing takes place in the United States. See OpenAI's privacy policy.
3.4 AI Content Is Not Human-Reviewed
AI-generated content is shown to you without human review and without an automated safety filter. It may be inaccurate or inappropriate. See section 12 of our Terms of Service.
3.5 We Do Not Train on Your Data
We do not use your content to train, fine-tune or improve any AI model, ours or anyone else's.
4. Voice Recordings
Parts of Soul Awakening let you record a short voice note. Because audio is sensitive, here is exactly how it is handled:
- Optional. Recording requires microphone permission, which you may decline or revoke at any time in iOS Settings. The feature is not required to use the journey.
- Stored privately. Recordings are saved on your device and uploaded to a private cloud storage area that is not publicly accessible. Access rules restrict each file to the account that created it.
- Never analysed. Recordings are never transcribed, never sent to any AI or speech-recognition service, and never listened to by us. They exist only for you to play back.
- Deleting one. You can re-record or discard while the relevant day is still open. Once a day is sealed the recording can no longer be deleted in the App — email us and we will delete it.
- On account deletion. Deleting your account from within the App removes your recordings from storage. This step is best-effort; if it fails, a file may remain in private storage, inaccessible to anyone else. Contact us and we will confirm removal.
- On automatic deletion. Where an account is deleted automatically under section 8.2, voice recording files are not currently removed by that automated process and may persist in private storage after the rest of the account is gone. Email us to have them deleted.
5. Who Can See What You Write
What you write in BlessSoul is personal, so we want to be exact about this rather than reassuring and vague.
5.1 Other Users and the Public Cannot See It — Ever
BlessSoul has no social, sharing, public or community features. Your content is never published, never shown to another user, and never made publicly accessible.
This is enforced technically, not just by policy. The database itself applies the restriction: when the app asks for information, it can only ever be handed records belonging to your account. It does not depend on the app remembering to be careful — the database will not return anyone else's records. Your voice recordings sit in a private storage area that is not reachable from the open internet, and each file is locked to the account that made it. There is no setting or configuration in which another user, or a member of the public, can read your entries.
5.2 What Administrative Access Exists
We would rather state this plainly than imply something we cannot guarantee.
As the operator of the service, the developer holds administrative credentials to the database. That level of access sits above the restrictions described above — it is what makes it possible to run, maintain, back up and repair the service at all, and every app you use has an equivalent. It means the technical capability to read stored content exists.
What we actually do with it is work with data in aggregate: counting how many people started a journey, where they stopped, whether a feature is used. Statistical questions about behaviour, not reading about individual lives.
5.3 We Analyse Behaviour, Never Content
No text you write ever reaches our analytics. Every analytics event records a fixed value — a screen name, a day number, a goal's type, a count, whether something succeeded. Your manifestation text, goal titles, reflections, vows, journal entries and voice recordings are excluded entirely and by design, both from third-party analytics and from our own in-app measurement.
So when we look at how BlessSoul is used, we are looking at patterns of behaviour. We are not reading what you wrote.
5.4 When We Might Look at Individual Content
We do not read individual entries as a matter of routine, and we have no interest in doing so. There are three narrow situations where it could happen:
- Technical support you asked for — if you report a problem with a specific item and we need to inspect that record to fix it.
- A serious technical fault — investigating data corruption, a failed sync or a bug affecting stored records.
- Legal compulsion — where a valid legal order requires it. Where we are permitted to tell you, we will.
Outside these, your entries are not opened.
5.5 Nothing You Write Is Judged, Scored or Profiled
Your reflections are not scanned, screened, keyword-matched, sentiment-analysed, scored or profiled — not by a person and not by any automated system. Nothing you write changes what we think of you, and there is no assessment of your mental state, beliefs, progress or character anywhere in this app. We do not use your content to train AI models, and we do not use it for advertising.
The journey is yours. We built it to be somewhere you can be honest.
5.6 Which Also Means Nobody Is Watching
The other side of that privacy is important, and we would rather you know it: because nothing is monitored, writing or recording something in BlessSoul will not alert anyone and will not summon help. There is no crisis detection, and the App cannot tell that you are struggling.
If you are in crisis, contact your local emergency services or a crisis helpline — a directory is at findahelpline.com. Our support inbox is one person's email, is not monitored continuously, and is not staffed by clinicians.
6. Who Processes Your Data
We use the following providers. Each processes data on our instructions or, where noted, as an independent controller under its own policy.
6.1 Supabase — database, authentication, file storage
Stores your account, your content and your voice recordings. The database is configured so that each account can reach only its own data. Privacy policy
6.2 Apple — distribution, payments, Sign in with Apple
Processes all payments and subscription billing. We receive subscription status and receipt validation only. Privacy policy
6.3 RevenueCat — subscription management
Receives an anonymous customer ID, subscription status and dates, and receipt data. Not your card details. Privacy policy
6.4 OpenAI — AI generation
Receives manifestation text and goal titles, without identifiers. See section 3. Privacy policy
6.5 Google Firebase — analytics and crash reporting
Receives event data, device information, crash logs and country-level location, in public App Store builds only. Analytics data is retained by Firebase for up to 14 months and crash data for around 90 days. Privacy policy
6.6 Google Sign-In — optional authentication
Used only if you choose it. We receive your email address, name and profile picture URL. We do not receive your contacts, Gmail content, search history or location. Privacy policy
6.7 Resend — email delivery
Receives your email address and the content of the account emails we send. Not your password or your content. Privacy policy
We do not sell your personal information, and we do not share it with data brokers, advertisers or ad networks.
7. Security
- In transit: all traffic between the App and our servers uses HTTPS/TLS.
- At rest: our database provider encrypts stored data. Passwords are hashed and salted by our authentication provider; we never see them.
- Access control: the database returns only records belonging to the signed-in account. Voice recordings are kept in a private storage area, not reachable from the open internet, and locked to the account that made them.
- On your device: the credentials that keep you signed in are stored in the iOS Keychain — Apple's secure store — locked to that device and readable only while it is unlocked. Your profile picture is written with file protection applied. App data sits inside the iOS application sandbox.
- Secrets: AI provider keys are held only on our server and are never present in the App.
- Rate limiting is applied to AI requests to limit abuse.
Honest limitation: as a one-person operation we cannot offer a dedicated security team, 24/7 monitoring, formal penetration testing or a certified compliance programme. No system is perfectly secure and we cannot guarantee absolute security.
7.1 If There Is a Breach
If a personal data breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours where GDPR requires it, notify the Data Protection Board of India as required under the DPDP Act, and notify affected users without undue delay where the risk is high.
8. How Long We Keep Data
8.1 While Your Account Exists
We keep your account and content for as long as your account exists, so the App can work. There is no automatic expiry of your content while your account is active.
8.2 Automatic Deletion After a Lapsed Subscription
If you have previously held a paid subscription and it lapses without renewal, your account and its data are permanently and irreversibly deleted 30 days later by an automated process. We send email warnings during that period, including one about 7 days before deletion. Resubscribing before day 30 cancels the deletion.
This applies only to accounts that have previously been paid. An account that has never had a paid subscription is not deleted for inactivity under this process.
You may request a copy of your data at any time before deletion — see section 9.
8.3 Other Retention Periods
- Analytics: retained by Firebase for up to 14 months; crash data around 90 days.
- AI usage logs: retained for cost and abuse monitoring. They contain no prompt or response text.
- Transaction records: retained as required by Indian tax law, currently up to 7 years.
- Backups: purged on our providers' ordinary cycle, within approximately 30 days.
8.4 What Survives Account Deletion
When you delete your account we remove your profile, goals, milestones, subtasks, progress and practice entries, manifestations and evidence, schedules and templates, Soul Awakening records and captures, voice recordings, quote favourites and progress, survey responses, paywall and AI logs, and your authentication record — together with local data and cached credentials on your device. A confirmation email is sent.
The following is deliberately retained:
- A subscription record with your user identifier removed and its status marked as deleted. It no longer identifies you, and is kept to prevent repeated abuse of free trials and promotional offers and to satisfy tax and accounting obligations.
- Records required by law, such as transaction records.
- Aggregated or anonymised analytics that cannot be traced back to you. Note that analytics already sent to Firebase is not individually recalled on deletion.
- Backups, until purged on the ordinary cycle.
- Voice recordings in the circumstances described in section 4 — in particular after automatic deletion.
Records held by Apple and RevenueCat about your subscription are outside our control and governed by their policies.
9. Your Rights
Subject to your location and applicable law, you have the right to:
- Access the personal data we hold about you
- Correct inaccurate or incomplete data
- Delete your data — available directly in the App at any time
- Port your data — receive a copy in a common file format you can open and reuse
- Restrict or object to processing, including profiling based on legitimate interests
- Withdraw consent where processing relies on it
- Complain to a supervisory authority
- Not be discriminated against for exercising these rights
9.1 Deleting Your Account
Go to Settings → Data Management → Delete Account. You will re-authenticate, then deletion is immediate and permanent. Deleting your account does not cancel your Apple subscription — cancel that separately through Apple or you will keep being charged.
9.2 Getting a Copy of Your Data
The App does not currently offer a self-service export. To obtain a copy, email support@blesssoul.com from your registered address with the subject "Data Request." We will confirm your identity using your registered email address and reply within 30 days, sending your data in a common file format you can open and reuse.
9.3 Other Requests
Email us with the subject "Privacy Request" and describe what you want. We may need to verify your identity. We do not charge for these requests unless they are manifestly unfounded or excessive.
9.4 If You Are in the EU or UK
You may lodge a complaint with your national data protection authority. In the UK this is the Information Commissioner's Office (ico.org.uk).
9.5 If You Are in California
Under the CCPA/CPRA you may request disclosure of the categories and specific pieces of personal information collected, the purposes, and the categories of third parties involved; request deletion or correction; and opt out of sale or sharing. We do not sell or share personal information as those terms are defined, and we do not use or disclose sensitive personal information for purposes requiring a right to limit. You may use an authorised agent.
9.6 If You Are in India
Under the Digital Personal Data Protection Act, 2023 you may access, correct, update and erase your personal data, nominate another person to exercise your rights in the event of death or incapacity, and seek grievance redressal. Contact us at the address in section 13; if unresolved, you may approach the Data Protection Board of India.
10. International Transfers
Your account and everything you create is stored in the United Kingdom (London). That is where our main database and file storage sit, so for users in the UK and Europe, the substance of your data — your goals, manifestations, reflections, schedules and voice notes — stays within the UK and Europe.
Some things necessarily happen elsewhere:
- We operate from India. As the people running the service, we access it from there.
- Some service providers are based in the United States — OpenAI (AI generation), Google Firebase (analytics and crash reporting), RevenueCat (subscriptions) and Resend (email). Only the specific data described in section 6 reaches each of them, not your whole account.
- Apple handles payments under its own global infrastructure and privacy policy.
This means some of your data is transferred outside your country of residence, and in some cases outside the United Kingdom and the European Economic Area. Where those transfers involve personal data protected by UK or EU data protection law, they rely on the Standard Contractual Clauses (or the UK's International Data Transfer Addendum), or another lawful transfer mechanism offered by the provider concerned, alongside the security measures described in section 7.
If you would like details of the safeguards applying to a particular transfer, contact us and we will explain.
11. Children's Privacy
BlessSoul is not intended for children under 13 and is not directed at or marketed to them. Where a higher minimum age applies to data-processing consent — commonly 16 in parts of the EEA and the UK — that higher age applies.
We do not verify age. The App does not perform an age check at sign-up, and we rely on the user's representation that they meet the requirement. We do not knowingly collect personal data from a child below the applicable age.
If you believe a child has created an account without proper consent, contact support@blesssoul.com and we will investigate and delete the account and its data.
12. Changes to This Policy
We may update this policy as the App develops or the law changes. The "Last Updated" date above will change. For material changes affecting your rights, we will give reasonable notice by email or in-app notice before they take effect. Where the change requires your consent under applicable law, we will ask for it. Continued use after a change takes effect indicates acceptance.
We recommend reviewing this page periodically.
13. Contact and Grievance Redressal
Praveena H D (sole proprietor) — Data Controller / Data Fiduciary
Shivamogga, Karnataka, India
Email: support@blesssoul.com
Please use these subject lines so requests are routed correctly:
- "Data Request" — to obtain a copy of your data
- "Privacy Request" — access, correction, deletion, objection or restriction
- "Grievance" — a complaint about how your data has been handled
Typical response is 2–5 business days; formal requests are answered within the statutory period. Under the DPDP Act, Praveena H D is the point of contact for grievance redressal.
This inbox is not for emergencies. It is one person's email, is not monitored continuously, and is not staffed by clinicians. If you are in crisis, contact local emergency services or a helpline at findahelpline.com.
Effective 19 July 2026.
© 2026 Praveena H D. All rights reserved.