Privacy Policy
Last updated: March 19, 2026
This policy explains what data Somi stores, why it is stored, and how you can export or permanently delete it. This policy reflects current system behavior in the web and mobile app backed by Supabase.
1) What we collect
- Account data: authentication account identifiers and email via Supabase Auth, plus app profile fields in `users`.
- Conversation data: conversation records and message content you and the assistant send in chat.
- Personalization data: memory summaries, retrieval metadata, intake responses, profile inference fields, and session summaries.
- Wellness and product data: check-ins, journal entries, habits, homework tasks, insights, ROM checks, micro-screen results, session ratings, gamification state, XP ledger, badges, and virtual pet state.
- Safety data: crisis-related events used for safety monitoring and intervention quality.
2) Why we process it
- To provide account access, authenticated sessions, and user-specific data access.
- To generate assistant responses and maintain conversation continuity.
- To personalize support using bounded memory and profile inference.
- To enable product features like journaling, habits, homework, and insights.
- To run safety logic for crisis detection and emergency resource routing.
- To track engagement systems like XP, streaks, and badges.
3) AI and infrastructure processors
- Supabase: authentication, PostgreSQL storage, and row-level access controls.
- Anthropic: text generation for assistant responses and selected inference tasks.
- OpenAI embeddings: embedding generation for memory retrieval when configured.
- Hosting infrastructure: application hosting and runtime processing for web API routes.
4) Retention and deletion
Data is retained while your account is active so the product can function. You can clear selected data in settings, export your data, or permanently delete your account.
When you choose account deletion, we delete your Supabase Auth user account. App data linked to that account is removed through database relationships and cascade deletion rules.
5) Your data rights in-app
- Access and portability: use the in-app data export action to download your stored data as JSON.
- Clinician support summary: you can also generate an AI-produced clinician summary report designed for intake discussions. This report is summary-only support material and excludes raw message quote excerpts.
- Erasure: use the in-app account deletion action to permanently delete your account and associated stored app data.
6) Clinical and safety boundaries
Somi is a self-reflection tool and does not provide therapy, diagnosis, or medical treatment. If you may be in immediate danger, contact emergency services or a crisis hotline right away.
Clinician summary reports are generated from aggregated app data for conversation support. They are not a diagnosis, treatment recommendation, or medical advice.