Privacy Notice
Last updated: 8/9/2026
1. Who we are
This Service is operated under the trading name My Soul Compass, based in Malaysia ("we", "us"). We act as the data controller for personal data processed through the Service. You can reach us at wecare@mysoulcompass.ai or via our contact form.
2. What we collect
- Account data — name, email, password hash, profile preferences.
- Content you create — daily check-ins, journal entries, mood logs, Soul Card reflections, meditation goals and the generated scripts/audio.
- Support messages — anything you send via the contact form or email.
- Usage data — pages viewed, features used, sessions generated and played, device/browser type, approximate location derived from IP, error logs.
- Billing data — collected and processed by Paddle, our Merchant of Record. We receive limited information such as plan, status, and the last four digits of a card to display in your account; we do not store full card numbers.
3. Why we use it (and on what legal basis)
- Provide the Service (contract): create your account, generate check-ins, scripts and audio, sync your library, deliver support.
- Keep it safe (legitimate interests & legal obligation): fraud, abuse and safety monitoring, including automated safety classification of inputs.
- Improve the Service (legitimate interests): aggregate analytics, debugging, model-output quality review. We do not sell your data and we do not use the content of your check-ins or journal to train third-party AI models.
- Communicate with you (contract & legitimate interests): service notices, replies to support requests, important policy updates. Marketing emails only with your consent — you can opt out at any time.
- Comply with law (legal obligation): tax, accounting and lawful requests from authorities.
4. AI processing
Your inputs (check-ins, journal text, meditation goals, etc.) are sent to our AI providers via secured server-side connections only to generate the response you asked for. Providers process the request on our behalf as subprocessors and are contractually restricted from using your content to train their public models. Generated outputs are stored in your account so you can revisit them.
5. Who we share data with
- Service providers: cloud hosting and database (Supabase / cloud infrastructure providers), AI model providers (for generating check-in replies, scripts and voice audio), email delivery providers, customer-support tooling.
- Merchant of Record: Paddle.com Inc. and its affiliates, for processing payments, subscription management, tax compliance and invoicing. Paddle is an independent data controller for payment data — see Paddle's Privacy Notice.
- Professional advisers (legal, accounting) where reasonably required.
- Authorities where required by law or to protect rights, safety and security.
We do not sell your personal data.
6. International transfers
Because we serve a global audience and rely on cloud providers, your data may be processed in countries outside your own, including the United States, the European Union and Singapore. Where required, we use appropriate safeguards such as the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum, and equivalent mechanisms.
7. How long we keep it
We keep account data, check-ins, journal entries and generated sessions for as long as your account is active. If you delete your account, we delete or anonymise this content within 30 days, except where we are required to keep limited records for legal, tax or fraud-prevention purposes (typically up to 7 years). Backups are overwritten on a rolling basis.
8. Your rights
Depending on where you live, you may have the right to:
- Access a copy of your personal data;
- Correct inaccurate data;
- Delete your data ("right to erasure");
- Restrict or object to certain processing;
- Port your data to another service;
- Withdraw consent at any time, without affecting prior processing.
To exercise any of these rights, email wecare@mysoulcompass.ai or use our contact form. We aim to respond within 30 days.
Malaysia (PDPA 2010): you may submit a data-access or correction request and lodge a complaint with the Personal Data Protection Commissioner.
EU / EEA / UK (GDPR / UK GDPR): you also have the right to lodge a complaint with your local supervisory authority.
California (CCPA/CPRA): you have the right to know what we collect, to delete it, to correct it, and to opt out of any "sale" or "share" of personal data — we do not sell or share personal data as defined by those laws.
9. Security
We use industry-standard technical and organisational measures to protect your data, including encryption in transit (HTTPS/TLS), encryption at rest, row-level security on the database, restricted production access, and audit logging of admin actions. No system is 100% secure, so we cannot guarantee absolute security.
10. Cookies and similar technologies
We use a small number of cookies and local storage entries that are strictly necessary to keep you signed in, remember your preferences, and protect the Service from abuse. We do not use third-party advertising cookies. If we add analytics or marketing cookies in the future, we will update this notice and request consent where required.
11. Children
The Service is not directed to children under 18. We do not knowingly collect personal data from anyone under 18. If you believe a minor has provided us with personal data, contact us so we can delete it.
12. Changes to this notice
We may update this Privacy Notice from time to time. Material changes will be highlighted in-app or by email. Continued use of the Service after the effective date means you accept the updated notice.
13. Contact
Questions, requests or complaints: email wecare@mysoulcompass.ai or use our contact form.