Privacy Policy for BlessSoul

Effective Date: 19 July 2026 | Last Updated: 12 August 2026

The short version. This summary is for convenience only; the full policy below governs. BlessSoul creates an anonymous profile the first time you open it and stores everything you create, so it can sync across your devices; creating an account is optional and simply links that data to your email. We do not sell your data, do not use it for advertising, and do not use your content to train AI models. Text you write in Soul Manifest is sent to OpenAI to generate affirmations — without your name, email or user ID attached. Voice notes are stored privately and are never transcribed or analysed. Nothing you write is scanned, analysed or profiled — section 5 sets out exactly who can access your data and when. If a paid subscription lapses and is not renewed, the account is deleted after 30 days.

Who We Are

BlessSoul is developed and operated by Praveena H D, a sole proprietor based in Shivamogga, Karnataka, India. For the purposes of the EU and UK General Data Protection Regulation, Praveena H D is the data controller. Under India's Digital Personal Data Protection Act, 2023, we act as the Data Fiduciary.

Contact: support@blesssoul.com

This policy explains what we collect, why, where it goes, how long we keep it and what rights you have. It should be read together with our Terms of Service.

Solo Operation — What That Means for Your Privacy

BlessSoul is run by one person. We comply with applicable data protection law, but you should understand the practical limits: there is no dedicated privacy team, no 24/7 security monitoring, and no enterprise security apparatus. Privacy requests are handled by one individual and we will generally use the full statutory response window (30 days under GDPR, extendable to 60 for complex requests; 45 days under CCPA, extendable to 90). Our security measures are described in section 7 and reflect these constraints.


1. Information We Collect

1.1 Account Information

You can use BlessSoul as a guest, without giving us any personal details. The first time you open the App we create an anonymous profile — an internal identifier with no name or email attached — so the content you create can be saved and synced (see 1.2). Creating an account is optional; if you do, your existing guest data is linked to it and we then hold:

1.2 Content You Create

This is the substance of the App and is stored on your device and in our cloud database:

Much of this is personal and reflective in nature. We treat it accordingly: it is private to your account, is not shown to other users, and is not used for advertising or model training.

1.3 Onboarding Answers

To personalise the App we ask a short series of questions:

Some of these answers — such as religious preference or zodiac sign, if you provide them — are used to filter content so you are not shown material that does not suit you. Under GDPR, information revealing religious or philosophical belief is a special category of data; we process it only with your explicit consent, given by choosing to answer, and solely to tailor content. You may skip these questions or change your answers later.

1.4 Subscription Information

We never receive or store your card number, billing address or any financial information. Apple processes all payments.

1.5 Analytics and Diagnostics

Collected only in public App Store builds. Analytics and crash reporting are disabled entirely in development builds.

We record events, not content — for example: app opens and screen views; sign-up and sign-in method; that a goal was created (with its type and priority, not its title); that a quote was viewed, favourited or shared; that a schedule block was created (with its duration); Soul Awakening milestones (a day number, or a count of manifestations); onboarding progress (which question was reached, not the answer given); paywall and purchase events; settings and theme changes; and errors.

Your written content never goes to analytics. No manifestation text, goal title, reflection, journal entry or voice recording is included in any analytics event. Your user identifier is truncated before being sent to analytics, and hashed before being sent to crash reporting.

We also record in-app events about the Soul Awakening journey in our own database — such as which day was opened or sealed, and how you answered a fixed-choice question. These records contain only predefined values, never text you wrote.

1.6 Technical Information

Device model, iOS version, app version, language, network connectivity status, an anonymous device identifier used by analytics, and crash logs and stack traces. General location is derived at country or region level only — we do not collect GPS or precise location.

1.7 AI Usage Logs

When an AI feature runs, our server records the account it belonged to, which feature was used, which AI model, how much text was processed, the estimated cost, how long it took, and whether it worked. These logs do not contain the text of your prompt or of the AI's response. They exist for cost control, rate limiting and debugging.

1.8 What We Do Not Collect

We do not track you across other companies' apps or websites, and we do not sell or share your personal information for cross-context behavioural advertising.

IP addresses: our own application code does not collect or log IP addresses, and our rate limiting is keyed to your account rather than your network address. However, our infrastructure providers necessarily process IP addresses at the network layer as part of ordinary server logging and security, and analytics providers use IP to derive country-level location before discarding it.


2. Why We Use It, and Our Legal Basis

PurposeDataGDPR Legal Basis
Create and authenticate your accountEmail, password or Apple/Google sign-inContract
Store and sync your content across devicesContent you createContract
Generate AI affirmations and suggestionsManifestation text, goal titlesContract
Deliver reminders you set upSchedule and reminder settingsContract
Manage subscription and entitlementsSubscription dataContract
Send account and subscription emailsEmail addressContract
Personalise and filter contentOnboarding answersConsent (special categories) / Legitimate interests (other)
Improve the App, fix bugs, measure retentionAnalytics, crash dataLegitimate interests
Prevent fraud and abuse of trials and offersSubscription and account recordsLegitimate interests
Meet tax, accounting and legal obligationsTransaction recordsLegal obligation

Where we rely on legitimate interests, we have considered the impact on you and limited the processing accordingly — for example by excluding your written content from analytics entirely. You may object to processing based on legitimate interests by emailing us with the subject "Privacy Request — Object to Processing."

2.1 Withdrawing Consent

Where we rely on consent, you can withdraw it at any time: turn off notifications in iOS Settings; remove your profile picture in Profile; revoke microphone access in iOS Settings; or change or clear optional onboarding answers. Withdrawal does not affect processing already carried out. Withdrawing consent for essential processing may make the App unusable.

2.2 Marketing

We send transactional emails only — welcome messages, subscription status and expiry notices, deletion warnings, password resets, security notices and support replies. We do not send marketing email and do not sell your address to anyone.


3. Artificial Intelligence

3.1 Where AI Is Actually Used

Only Soul Manifest sends your data to an AI service. To be precise:

3.2 What Is Sent — and What Is Not

When an AI request runs, the request is made by our server, not by your device. It includes the manifestation text you wrote, your chosen category, and where relevant the titles of your existing goals.

No personal identifiers are sent to OpenAI. Your name, email address and user ID are not included in the request. Your identity is used by our own server only, to check your subscription and apply rate limits — it is not forwarded onward.

However, the text itself is personal. What you write about what you want in life is sent to OpenAI in order to generate a response. Please keep that in mind and avoid entering information you would not want processed by a third-party provider — such as health details, financial account details, or information identifying other people.

3.3 OpenAI's Handling

OpenAI processes these requests as our service provider. Under its API terms, API inputs and outputs are not used to train its models, and are retained for a limited period (currently up to 30 days) for abuse monitoring before deletion. Processing takes place in the United States. See OpenAI's privacy policy.

3.4 AI Content Is Not Human-Reviewed

AI-generated content is shown to you without human review and without an automated safety filter. It may be inaccurate or inappropriate. See section 12 of our Terms of Service.

3.5 We Do Not Train on Your Data

We do not use your content to train, fine-tune or improve any AI model, ours or anyone else's.


4. Voice Recordings

Parts of Soul Awakening let you record a short voice note. Because audio is sensitive, here is exactly how it is handled:


5. Who Can See What You Write

What you write in BlessSoul is personal, so we want to be exact about this rather than reassuring and vague.

5.1 Other Users and the Public Cannot See It — Ever

BlessSoul has no social, sharing, public or community features. Your content is never published, never shown to another user, and never made publicly accessible.

This is enforced technically, not just by policy. The database itself applies the restriction: when the app asks for information, it can only ever be handed records belonging to your account. It does not depend on the app remembering to be careful — the database will not return anyone else's records. Your voice recordings sit in a private storage area that is not reachable from the open internet, and each file is locked to the account that made it. There is no setting or configuration in which another user, or a member of the public, can read your entries.

5.2 What Administrative Access Exists

We would rather state this plainly than imply something we cannot guarantee.

As the operator of the service, the developer holds administrative credentials to the database. That level of access sits above the restrictions described above — it is what makes it possible to run, maintain, back up and repair the service at all, and every app you use has an equivalent. It means the technical capability to read stored content exists.

What we actually do with it is work with data in aggregate: counting how many people started a journey, where they stopped, whether a feature is used. Statistical questions about behaviour, not reading about individual lives.

5.3 We Analyse Behaviour, Never Content

No text you write ever reaches our analytics. Every analytics event records a fixed value — a screen name, a day number, a goal's type, a count, whether something succeeded. Your manifestation text, goal titles, reflections, vows, journal entries and voice recordings are excluded entirely and by design, both from third-party analytics and from our own in-app measurement.

So when we look at how BlessSoul is used, we are looking at patterns of behaviour. We are not reading what you wrote.

5.4 When We Might Look at Individual Content

We do not read individual entries as a matter of routine, and we have no interest in doing so. There are three narrow situations where it could happen:

Outside these, your entries are not opened.

5.5 Nothing You Write Is Judged, Scored or Profiled

Your reflections are not scanned, screened, keyword-matched, sentiment-analysed, scored or profiled — not by a person and not by any automated system. Nothing you write changes what we think of you, and there is no assessment of your mental state, beliefs, progress or character anywhere in this app. We do not use your content to train AI models, and we do not use it for advertising.

The journey is yours. We built it to be somewhere you can be honest.

5.6 Which Also Means Nobody Is Watching

The other side of that privacy is important, and we would rather you know it: because nothing is monitored, writing or recording something in BlessSoul will not alert anyone and will not summon help. There is no crisis detection, and the App cannot tell that you are struggling.

If you are in crisis, contact your local emergency services or a crisis helpline — a directory is at findahelpline.com. Our support inbox is one person's email, is not monitored continuously, and is not staffed by clinicians.


6. Who Processes Your Data

We use the following providers. Each processes data on our instructions or, where noted, as an independent controller under its own policy.

6.1 Supabase — database, authentication, file storage

Stores your account, your content and your voice recordings. The database is configured so that each account can reach only its own data. Privacy policy

6.2 Apple — distribution, payments, Sign in with Apple

Processes all payments and subscription billing. We receive subscription status and receipt validation only. Privacy policy

6.3 RevenueCat — subscription management

Receives an anonymous customer ID, subscription status and dates, and receipt data. Not your card details. Privacy policy

6.4 OpenAI — AI generation

Receives manifestation text and goal titles, without identifiers. See section 3. Privacy policy

6.5 Google Firebase — analytics and crash reporting

Receives event data, device information, crash logs and country-level location, in public App Store builds only. Analytics data is retained by Firebase for up to 14 months and crash data for around 90 days. Privacy policy

6.6 Google Sign-In — optional authentication

Used only if you choose it. We receive your email address, name and profile picture URL. We do not receive your contacts, Gmail content, search history or location. Privacy policy

6.7 Resend — email delivery

Receives your email address and the content of the account emails we send. Not your password or your content. Privacy policy

We do not sell your personal information, and we do not share it with data brokers, advertisers or ad networks.


7. Security

Honest limitation: as a one-person operation we cannot offer a dedicated security team, 24/7 monitoring, formal penetration testing or a certified compliance programme. No system is perfectly secure and we cannot guarantee absolute security.

7.1 If There Is a Breach

If a personal data breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours where GDPR requires it, notify the Data Protection Board of India as required under the DPDP Act, and notify affected users without undue delay where the risk is high.


8. How Long We Keep Data

8.1 While Your Account Exists

We keep your account and content for as long as your account exists, so the App can work. There is no automatic expiry of your content while your account is active.

8.2 Automatic Deletion After a Lapsed Subscription

If you have previously held a paid subscription and it lapses without renewal, your account and its data are permanently and irreversibly deleted 30 days later by an automated process. We send email warnings during that period, including one about 7 days before deletion. Resubscribing before day 30 cancels the deletion.

This applies only to accounts that have previously been paid. An account that has never had a paid subscription is not deleted for inactivity under this process.

You may request a copy of your data at any time before deletion — see section 9.

8.3 Other Retention Periods

8.4 What Survives Account Deletion

When you delete your account we remove your profile, goals, milestones, subtasks, progress and practice entries, manifestations and evidence, schedules and templates, Soul Awakening records and captures, voice recordings, quote favourites and progress, survey responses, paywall and AI logs, and your authentication record — together with local data and cached credentials on your device. A confirmation email is sent.

The following is deliberately retained:

Records held by Apple and RevenueCat about your subscription are outside our control and governed by their policies.


9. Your Rights

Subject to your location and applicable law, you have the right to:

9.1 Deleting Your Account

Go to Settings → Data Management → Delete Account. You will re-authenticate, then deletion is immediate and permanent. Deleting your account does not cancel your Apple subscription — cancel that separately through Apple or you will keep being charged.

9.2 Getting a Copy of Your Data

The App does not currently offer a self-service export. To obtain a copy, email support@blesssoul.com from your registered address with the subject "Data Request." We will confirm your identity using your registered email address and reply within 30 days, sending your data in a common file format you can open and reuse.

9.3 Other Requests

Email us with the subject "Privacy Request" and describe what you want. We may need to verify your identity. We do not charge for these requests unless they are manifestly unfounded or excessive.

9.4 If You Are in the EU or UK

You may lodge a complaint with your national data protection authority. In the UK this is the Information Commissioner's Office (ico.org.uk).

9.5 If You Are in California

Under the CCPA/CPRA you may request disclosure of the categories and specific pieces of personal information collected, the purposes, and the categories of third parties involved; request deletion or correction; and opt out of sale or sharing. We do not sell or share personal information as those terms are defined, and we do not use or disclose sensitive personal information for purposes requiring a right to limit. You may use an authorised agent.

9.6 If You Are in India

Under the Digital Personal Data Protection Act, 2023 you may access, correct, update and erase your personal data, nominate another person to exercise your rights in the event of death or incapacity, and seek grievance redressal. Contact us at the address in section 13; if unresolved, you may approach the Data Protection Board of India.


10. International Transfers

Your account and everything you create is stored in the United Kingdom (London). That is where our main database and file storage sit, so for users in the UK and Europe, the substance of your data — your goals, manifestations, reflections, schedules and voice notes — stays within the UK and Europe.

Some things necessarily happen elsewhere:

This means some of your data is transferred outside your country of residence, and in some cases outside the United Kingdom and the European Economic Area. Where those transfers involve personal data protected by UK or EU data protection law, they rely on the Standard Contractual Clauses (or the UK's International Data Transfer Addendum), or another lawful transfer mechanism offered by the provider concerned, alongside the security measures described in section 7.

If you would like details of the safeguards applying to a particular transfer, contact us and we will explain.


11. Children's Privacy

BlessSoul is not intended for children under 13 and is not directed at or marketed to them. Where a higher minimum age applies to data-processing consent — commonly 16 in parts of the EEA and the UK — that higher age applies.

We do not verify age. The App does not perform an age check at sign-up, and we rely on the user's representation that they meet the requirement. We do not knowingly collect personal data from a child below the applicable age.

If you believe a child has created an account without proper consent, contact support@blesssoul.com and we will investigate and delete the account and its data.


12. Changes to This Policy

We may update this policy as the App develops or the law changes. The "Last Updated" date above will change. For material changes affecting your rights, we will give reasonable notice by email or in-app notice before they take effect. Where the change requires your consent under applicable law, we will ask for it. Continued use after a change takes effect indicates acceptance.

We recommend reviewing this page periodically.


13. Contact and Grievance Redressal

Praveena H D (sole proprietor) — Data Controller / Data Fiduciary
Shivamogga, Karnataka, India
Email: support@blesssoul.com

Please use these subject lines so requests are routed correctly:

Typical response is 2–5 business days; formal requests are answered within the statutory period. Under the DPDP Act, Praveena H D is the point of contact for grievance redressal.

This inbox is not for emergencies. It is one person's email, is not monitored continuously, and is not staffed by clinicians. If you are in crisis, contact local emergency services or a helpline at findahelpline.com.


Effective 19 July 2026.
© 2026 Praveena H D. All rights reserved.