Privacy
What we store, and what we never ask for.
Most privacy pages describe an intention. This one is a list, and every item on it can be checked against the code that runs this site.
Last updated 25 September 2026 · Soulberry is pre-launch. The product described below is not open to the public yet, and this page will change when it is.
Soulberry is a place to put the thing you cannot say out loud. That only works if you are not quietly paying for it with the thing itself. So the design rule is simple: do not collect it, and it cannot leak.
Right now, the only thing here is a waitlist
There is no payment of any kind, and the product itself is not open. If you put your address in the box on the homepage, here is the complete list of what is written down:
- Your email address — trimmed and lower-cased, so typing a capital letter does not put you on the list twice.
- Where you came from — the tag on the link you arrived by, if it carried one. If you typed the address in yourself, that is recorded as the word
home. It says which link brought you, never who you are. - An id, and two dates — when the row was made and when it last changed.
There is an account system, and it is reachable
Being accurate about this rather than tidy: the sign-up and sign-in pages exist and anyone can open them today, because the app behind them is being built in the open. Making an account stores a name, an email address, a hashed password and the dates, and when you agreed to AI replies, if you did. It is not part of the waitlist and you do not need one to join the list.
No analytics. No trackers. No advertising.
This site loads no Google Analytics, no tag manager, no Meta pixel, no Plausible, no PostHog, no session recorder and no advertising script of any kind. There is no third-party JavaScript on the page at all. Nobody is building a profile of you here, because there is nothing running that could.
You will not be followed around the internet by an advert for Soulberry after visiting, for the straightforward reason that we have not given anybody the ability to do it.
The cookies, honestly
Two cookies may be set, and neither one is for marketing. Both come from the sign-in system that guards the private part of the app, and they carry no profile, no identifier that follows you anywhere, and no record of what you looked at.
Your conversations do not live on our servers
When the product opens, the conversations you have with a guide are stored in your own browser, on the device you wrote them on. They are not kept on our servers, and they are not mined or used as training data.
This has a consequence worth saying plainly rather than burying: it also means those conversations do not follow you to a second device, and clearing your browser data clears them. That is the honest cost of keeping them where they are, and you should know it before you rely on it.
Who writes the replies
A guide’s replies are written by Claude, an AI made by Anthropic, so what you say to a guide is sent to Anthropic to be answered. When you ask for a question about a fragment, or for your day’s story, those fragments are sent too. The app asks you first, and nothing is sent until you agree.
Reporting a reply
If you report a guide’s reply, that reply’s words, the guide’s name and any reason you give are sent to us, so we can look at it. Nothing else from the conversation is sent. The report is in your data export, and it is erased with your account.
The database has no public door
Where data does reach a server, the protection is structural. Every table is owned by a dedicated least-privilege role rather than by an administrator account, and the public API roles — the ones that would otherwise answer requests straight from the internet — hold no grants at all. There is no address on the internet where these tables answer. That is the part that matters most and it is the part that is genuinely locked.
Being precise about the rest, because a privacy page that overstates is worth less than one that does not: keeping your rows separate from another person's is done by the application, not by the database. Row-level security is switched on, but a table's owner is exempt from it unless it is forced, and the app connects as the owner — so the rule that separates one person's rows from another's is code we wrote, not a guarantee the database enforces underneath us. Saying otherwise would be the kind of claim this page exists to avoid.
Closing your account
You can close your account yourself. In Settings, choose Close your account and enter your password. It stops working at once, on every device you were signed in on.
It is not erased in that same second, on purpose: a mistaken tap at 2am should not cost a year of writing. For 30 days the account stays closed, and emailing us brings it back. After that, a job that runs once a day erases it and everything our servers hold for it — every fragment, photo and voice note, every day, moment and reminder — and every sign-in.
Anything kept in your browser: your conversations with a guide, which live only there, and the copy of your journal and your day that each browser keeps, photos and voice notes included. Closing does not clear them. On each device, use "Clear what is on this device" in Settings while you can still sign in, or clear this site's data in your browser afterwards.
A payment record. Nothing can be paid for yet; once it can, a record of each payment will be kept after the account is erased, because the law says it must be, with your name, email address and password taken off it.
A waitlist address, which is separate, as the next section says.
Taking your address back off the list
You do not need an account, a password or a reply from us. The leave page removes your address from the waitlist, and it is reachable by anyone — precisely because the people most likely to want it are the ones who never signed up for anything else.
What we will never do
- Sell your email address, or your words, to anybody.
- Use what you write to train a model that other people use.
- Show you an advert, here or anywhere else.
- Hand your data to a data broker, an insurer or an employer.
Your rights, and how to use them
If you are in the UK or the EU, the GDPR gives you the right to see what is held about you, to correct it, to have it deleted, and to object to it being processed. Given the list at the top of this page, exercising all four is not complicated. Two of them you can do yourself in Settings: Export everything downloads what your account holds, and closing your account erases it. For anything else, email hello@soulberry.ai and say what you want done.
The machine-readable summary of this site, for anyone whose assistant is reading on their behalf, lives at soulberry.ai/llms-full.txt.