Skip to main content

Who we are

SoulVriti is operated by SetKernel Digital Inc., the data controller under GDPR Article 4(7) and the Data Fiduciary under India's Digital Personal Data Protection Act 2023. You can reach us about anything in this policy at hello@soulvriti.com.

How SoulVriti handles your data

SoulVriti is local-first. You do not need an account to use it: if you stay signed out, your bookmarks, journal entries, mood logs, reading history, goals, achievements, challenges, reading plans, memorization and ritual progress, margin notes, memorial dedications, streaks, and preferences live only in the app's storage on your device, and we cannot see them.

Signing in is optional. It enables cross-device sync and account-bound features such as saved AI history, reminders and browser push, circles, and invitations: the practice data listed below is synced to your account on our servers so your other devices can see it. Signing in does not enable advertising, profiling, or any other secondary use.

What we collect, and when

Account data (only if you sign in): your email address (when you use an email sign-in link) or the identity your provider shares with us (Sign in with Apple or Google — typically a stable identifier, and your name and email if you choose to share them), plus session records. Sessions expire after 30 days; email sign-in links expire after 15 minutes and work once.

Push notification data (only if you turn on reminders): to deliver reminders to a device we store a per-device push subscription — the device's push address or token, the encryption keys used for web push, and its language and timezone. We use it only to send the reminders you schedule, and it is deleted with your account.

Transactional email — a welcome note when you create your account. Weekly reading and gentle return emails are two separate choices, both off until you explicitly turn each one on; push-notification choices never subscribe you to email, and every optional message carries an unsubscribe link.

Invitation data (only if you invite someone): when you create an invite we store the invitations you make and whether each one was accepted. An invite is just a shareable link with a random code — we never collect your friend's email or any other detail about them. When someone signs up through your link, we record an internal link between your two accounts so your invite shows as accepted; that link is deleted with either account.

AI conversation data (only if you sign in, explicitly consent to AI processing, and use the feature): your AI conversations — the messages you send and the AI's replies — are saved to your account. Learned "AI memory" is a separate choice, off unless you turn it on; only then may the AI retrieve or distil short notes about your stated practices, concerns, preferences, context, and beliefs. See "Ask SoulVriti AI" below for the detail. Signed-out AI message content is processed to answer the request but is never saved to an account or our databases.

Synced practice data (only while you are signed in):

Content delivery, server logs, analytics and cookies

Verse content (scriptures, translations, commentary) is delivered from our servers, so the app does make network requests. These are ordinary web requests: our infrastructure sees your IP address and standard request metadata, which we use only to deliver content, prevent abuse (rate limiting), and keep the service secure. We do not use it to build profiles.

Mobile server-error diagnostics. The mobile app does not automatically upload crash reports and contains no crash-reporting SDK. It does attach its app version, platform, and OTA build identifier to API requests. If a request fails with an unexpected server error, our Cloudflare Workers error log records those build fields together with the request ID, route and method, internal user ID when signed in, and error details so we can diagnose the failure. We do not intentionally put journal, mood, search, or AI message text in these logs. Cloudflare Workers Logs retains them for no more than 7 days; they are not used for analytics, advertising, or profiling.

Web browser diagnostics. The web app does not automatically upload browser Error objects, messages, or stack traces. If you consent to Google Analytics, a shown error state may produce only a coarse, allowlisted event such as load or network failure, never the error text, response body, dynamic route, or anything you typed. The manual Report a problem action opens your email app; you decide whether and what to send.

Anonymous AI requests include a random app-install identifier used only to enforce the shared allowance of two questions per rolling 24 hours across AI Chat and Ask the Traditions. The identifier and request timestamps contain no message content and expire automatically from Cloudflare KV within 48 hours after the latest request. Ordinary request infrastructure also sees the IP address as described above; the raw IP address is never stored in an AI allowance record — to bound automated abuse we keep only a keyed, non-reversible code derived from the network address, with the same 48-hour expiry. Signed-out AI requests may additionally require completing a Cloudflare Turnstile verification (an anti-abuse challenge provided by Cloudflare, Inc.) before the question is processed. Apart from the consent-based website analytics described in this section, we do not use advertising or tracking SDKs anywhere in the product.

Website analytics. On our marketing website (soulvriti.com) and web app we use Google Analytics 4 (provided by Google LLC, United States) to understand aggregate feature-area usage. Microsoft Clarity (provided by Microsoft, United States) is used only on the public marketing website for masked session replay and heatmaps; it is never loaded in the web app, where people read scripture, journal, set religious preferences, or use AI. These are the only analytics tools we use. We do not use a tag manager, any other product-analytics or error-tracking SDKs, or advertising pixels.

Consent first where the law requires it. In the EEA, the United Kingdom, and Switzerland these tools are off by default: our legal basis there is your consent (GDPR/UK-GDPR Art 6(1)(a) and the ePrivacy/PECR cookie rules), we use Google Consent Mode v2 with every signal set to denied, and no analytics script loads or cookie is set until you opt in through our cookie banner. Everywhere else, these analytics run by default on the basis of our legitimate interest in understanding aggregate feature use, and you can opt out at any time from the cookie-policy page — an explicit opt-out is always honored on every surface.

Analytics cookies: Google Analytics may set _ga and _ga_<id> on either web surface; Microsoft Clarity may set _clck, _clsk, and CLID on the marketing website only. In consent-required regions no analytics cookie is set before you opt in; elsewhere they may be set by default until you opt out. Withdrawing consent or opting out sends the denied signal immediately, stops future events, and removes accessible analytics cookies.

What we never measure. Analytics events never include scripture text, scripture or verse identifiers, journal, reflection, mood, search or AI content, invite or circle codes, account identifiers, or anything you type. Web-app paths are reduced to broad feature buckets such as /reader or /ai before a page view is sent. The web app has no session replay. On the marketing website, Clarity uses strict masking and the site contains no signed-in practice or AI surfaces.

These tools are not used for advertising, profiling, or selling data. Google and Microsoft are based in the United States, so where this involves an international transfer of data it is covered by Standard Contractual Clauses and the providers' standard transfer safeguards.

You stay in control. You can decline analytics from the start, and you can change your mind at any time using the cookie banner or the "Manage analytics & cookies" control on our site — turning analytics off withdraws your consent going forward.

Ask SoulVriti AI

In the EEA, the United Kingdom, and Switzerland we ask for explicit permission before the first AI request — and again if the disclosure materially changes — before sending your message and selected context to our server and Cloudflare Workers AI. Elsewhere, using an AI surface starts this processing under these terms, with the same versioned processing record applied to your requests. Context can include the passage or tradition you selected, your language, server-retrieved catalog passages, and prior messages in the same signed-in conversation. In every region you can withdraw AI processing for future requests from the AI disclosure screen; when processing is withdrawn — or, in consent-required regions, never granted — no AI request is sent.

Learned AI memory is a separate, optional choice and remains off unless a signed-in user turns it on. With memory off, the service neither retrieves saved memory for a prompt nor extracts new memory from the completed turn. With it on, the AI may retrieve or distil a short set of notes about your stated practices, concerns, preferences, context, and beliefs so later replies can stay relevant. Turning processing consent on never turns memory on automatically.

If you are signed in, AI Chat conversations are saved to your account so you can return to them across devices: we store your messages, the AI replies, verified citation references, the model and prompt versions used for each new message, and any optional up/down rating you choose for an AI reply. Ratings contain no free-text feedback. You can delete individual conversations; conversation history and any opted-in AI memory are included in your data export and erased when you delete your account. If you are signed out, your message and reply content are processed transiently and are not saved to an account, D1, KV, or AI Gateway payload logs.

Workers AI first applies crisis-safety checks and, for completed replies, an output-safety check. A crisis-flagged message is sent only to the Cloudflare-hosted safety check, never to the conversational generation model; the service shows support resources instead of an AI reply and does not save the message to your account. Application logs record request shape and safety result only, never message or reply text, and AI Gateway payload logging and caching are disabled.

AI replies are generated from bounded passages retrieved from SoulVriti's published corpus. Citation references are checked against those supplied passages before they are shown, but the model can still misunderstand a source or be wrong. Treat the feature as a reading companion, not as religious authority or professional advice.

Why we process this data

To provide the service you ask for: delivering verse content, keeping your signed-in devices in sync, generating consented AI replies, saving signed-in AI conversation history, using learned AI memory only when separately enabled, sending the sign-in emails you request, and producing your data export when you ask for it.

To keep the service secure and working: rate limiting, abuse prevention, and operational logs.

Nothing else. We do not advertise, we do not sell or share personal data, and we do not use your content — including your AI conversations and AI memory — to train AI models. Your AI memory is used only to personalise your own replies, never to profile you for any other purpose.

Performance of a contract (GDPR Art 6(1)(b)) — operating your account, syncing your data, and fulfilling export/deletion requests.

Legitimate interests (GDPR Art 6(1)(f)) — security, rate limiting, and operational logging, in ways that do not override your rights.

Consent and legitimate interest (GDPR Art 6(1)(a)/(f); DPDP §6) — sync happens because you chose to sign in and can be withdrawn by deleting your account. In consent-required regions (the EEA, the UK, and Switzerland), sending content to Workers AI requires a versioned, explicit processing choice, and web analytics run only after you opt in under the ePrivacy/PECR cookie rules. Elsewhere, AI processing begins when you use an AI surface and analytics runs by default under our legitimate interest — each with an always-honored off switch. Learned AI memory requires a second, independent opt-in everywhere. Google Analytics may run on both web surfaces; Microsoft Clarity is marketing-site-only.

Religious and inner-life data

Your choice of traditions, journal entries, mood logs, AI conversations, and opted-in AI memory can reveal religious beliefs or emotional state — special-category data under GDPR Article 9. We process synced practice data only because you chose to create and sync it, and AI content only after the explicit processing choice described above (with learned memory separately chosen), relying on explicit consent where GDPR Article 9 applies. We use it only to provide the requested feature, never for advertising, profiling, ranking traditions, model training, or another secondary purpose. Signed-out AI content reaches the server and Cloudflare Workers AI only for transient processing; it is not stored in our account databases.

How long we keep data

Synced data and signed-in AI conversation history are kept while your account exists. Learned AI memory is created and retained only if you separately enable it. Sessions expire after 30 days; email sign-in tokens after 15 minutes. Anonymous AI allowance identifiers and timestamps expire from KV within 48 hours after the latest request.

When you delete an AI conversation, it is permanently erased from our servers straight away — there is no tombstone and it is not retained for sync.

When you delete a synced item on one device, our server keeps a soft-deleted copy of the record (a "tombstone") so the deletion can propagate to your other devices. Tombstones are invisible in normal app screens and excluded from the server-account portion of your portable export. The complete mobile device snapshot does include any tombstone still physically present on that device, clearly marked with its deletion time, so the export does not conceal retained local data. An automated daily job permanently erases server tombstones after 90 days; device reconciliation removes stale local copies, and reset or account deletion removes them immediately.

Cloudflare Workers request and server-error logs, including the mobile build metadata described above, are retained for no more than 7 days. They expire independently of the app account database; deleting your account immediately removes the account data we control in D1/KV, while an already-written infrastructure log remains only until this short automatic limit expires.

Security and accountability audit records may contain your internal user ID, IP address, user-agent, the action (sign-in, export, or deletion), and its time. They never contain scripture, journal, mood, search, or AI content. They are automatically erased after 400 days.

Deleting your account immediately removes your account, provider tokens, synced items and tombstones, AI conversations/messages/memory, social and practice data, and linked text suggestions. If you used Sign in with Apple, we first revoke the Apple authorization when a usable token is available; if an older account has no usable token, the deletion confirmation gives you Apple's manual revocation step.

At account deletion, every audit row linked to your user ID — including its IP and user-agent — is removed. We retain only one pseudonymous deletion receipt containing a domain-separated SHA-256 value, the fact that deletion occurred, and its time. It cannot authenticate you and contains no account ID, contact details, device details, or content; the same 400-day automatic limit applies.

Your rights, and exactly where to exercise them

Access & portability (GDPR Art 20) — Privacy & data → "Export my data" on mobile or web downloads JSON containing your profile; bookmarks; journal, reading and mood history; notifications and daily-verse assignments; goals, achievements, rewards, challenges and share events; invitations; AI conversations, messages and memory; discovery-quiz results and text suggestions; margin notes, reading plans and memorial dedications; memorization items, recall reviews and ritual sessions; your family/Sangha circles, memberships and sends; resonance candles; and preferences. Mobile also includes every personal record cached or created on that device, including not-yet-synced rows.

The portable export excludes live push endpoints/keys, session and OAuth credentials, internal sync cursors, re-downloadable public scripture packs, and operational audit records. These are withheld for security or are not user-provided portable content; they remain subject to the deletion and retention limits above.

Erasure (GDPR Art 17; DPDP §12) — Privacy & data → "Delete all my data" erases your account and server-side personal content immediately, subject only to the pseudonymous deletion receipt described above. You can also delete individual AI conversations from AI history. Signed-out data can be removed by resetting the app or uninstalling it.

Rectification — edit your content and preferences directly in the app at any time.

Withdraw AI consent — use the AI disclosure screen to stop future AI processing or to turn learned memory off independently. Turning memory off stops future retrieval and extraction; delete existing memory from Manage AI memory, or delete the account to erase it with all other account data.

Withdraw analytics consent — on our website or web app, use the cookie banner or the "Manage analytics & cookies" control to turn analytics off at any time. This withdraws consent to Google Analytics on both surfaces and to marketing-site-only Microsoft Clarity going forward. See "Content delivery, server logs, analytics and cookies" above.

Complaint — you may lodge a complaint with your local data-protection authority (EU residents: via edpb.europa.eu; Indian residents: the Data Protection Board of India).

Who processes data for us

We share personal data only with the infrastructure providers needed to run the service, and with no one else:

No ads, no sale of data

SoulVriti is free and carries no advertising. The only analytics we use are the consent-based website measurement tools described under "Content delivery, server logs, analytics and cookies" above; the app itself contains no advertising or in-app analytics SDKs. We do not sell or share personal data for advertising or any other consideration, and we never have.

Children

SoulVriti is not directed at children under 13, and we do not knowingly collect personal data from them. Used signed-out, the app stores nothing about you on our servers beyond the transient infrastructure logs described above.

Changes to this policy

If this policy changes, we will update this page and its effective date. For material changes we will give notice in the app before they take effect, and you can always export your data and delete your account first.

Contact

Questions about this policy or your data: hello@soulvriti.com.