Privacy Policy
Effective 24 August 2026 · v1.1
Short version: we collect the minimum needed to run a location-based bottle service, we never share your live position, we never sell your data, and you can delete everything with one tap.
1. Who we are & how to reach us
Soul Map is operated by the Soul Map team (“we”, “us”), contactable at privacy@soul-map.xyz. For GDPR purposes, we are the data controller for the personal data processed through the Service.
2. What we collect & why
- Account data — email or Google identity, display name, birth year (age verification), intent and vibe preferences. Basis: contract — needed to create your account.
- Bottle content — text, voice recordings, photos/video you place in bottles, and chat messages. Basis: contract.
- Location — precise GPS position, used only in-memory to compute distances and anchor bottles. Basis: consent (explicit, revocable at any time).
- Obfuscated bottle coordinates — when you drop a bottle, we store a server-side randomized position 50–100 m from your true spot, so your exact location is never recorded.
- Moderation data — reports, block lists, AI-classification flags. Basis: legitimate interest / legal obligation (safety, DSA).
- Technical logs — IP, user agent, timestamps in security and error logs. Basis: legitimate interest (security, abuse prevention).
- Usage analytics — anonymous product events (e.g. “bottle dropped”) with no advertising identifiers.
3. Adults only — no data from minors
Soul Map is 18+ only. We do not knowingly collect data from anyone under 18 (COPPA; GDPR Art. 8). Age is declared at registration and checked at sign-up. Suspected minor accounts are deleted with all data.
4. Location — what we never do
- We never display your live position to other users — there are no user markers for anyone else.
- We never store your precise GPS position; bottle anchors are randomized 50–100 m away from you.
- We never build movement histories or profiles from your location.
- Location access is optional: you can explore without granting it.
5. Sharing, processors & transfers
We do not sell personal data and do not share it for cross-context advertising. We share data only with processors needed to run the Service:
- Supabase (EU-hosted) — database, authentication, storage, realtime.
- Vercel — application hosting and delivery.
- Resend — transactional email (verification, invites).
- Google — optional sign-in identity (name/email you consent to share).
- AI moderation provider — content classification for safety, configured without training on your data.
Where data leaves the EEA, transfers rely on adequacy decisions or Standard Contractual Clauses. Law enforcement requests are honoured only where valid and legally binding; unless legally prohibited, we will notify you.
6. Your rights
Depending on your jurisdiction (GDPR, CCPA/CPRA, LGPD, PIPEDA and others), you have the right to: access, correct, delete, port, and restrict processing of your data; object to processing; withdraw consent (e.g. location) at any time; and non-discrimination for exercising your rights. Californian users: we do not sell or share personal information as defined by the CCPA/CPRA. To exercise any right, email privacy@soul-map.xyz — we respond within 30 days. You may also lodge a complaint with your local supervisory authority.
7. Retention & deletion
Bottles expire and are removed automatically (typically 24 hours after being dropped, or immediately when collected). Chat history stays until you delete it or delete your account. Deleting your account removes your profile, content and personal data from production systems within 30 days, excluding backups (deleted on rotation) and records we must keep by law. Analytics events are aggregated and contain no direct identifiers.
8. Security
Data is encrypted in transit (TLS) and at rest. Row Level Security restricts every table to its owner. The service-role key never leaves the server. Location is obfuscated before persistence. We apply least-privilege access, rate limiting, and audit logging. No system is perfect — report vulnerabilities to security@soul-map.xyz and we will act quickly and credit responsible disclosure.
9. Jurisdiction-specific notes
- EU/EEA (GDPR) — lawful bases are listed per data type in section 2; you have the rights in section 6.
- California (CCPA/CPRA) — we do not sell or share personal information; no financial incentives programs.
- Brazil (LGPD) — controller contact in section 1; rights mirrored in section 6.
- Serbia (ZZPL) — processing aligned with the Serbian Personal Data Protection Law.
10. Changes to this policy
We will announce material changes in the app at least 7 days before they take effect, and update the effective date above. Continued use after that means you accept the updated policy.
11. Contact the controller
Privacy questions, data requests, and deletion: privacy@soul-map.xyz. We aim to answer everything within 30 days, usually much faster.