Soulberry Join the waitlist

Privacy

What we store, and what we never ask for.

Most privacy pages describe an intention. This one is a list, and every item on it can be checked against the code that runs this site.

Last updated 25 September 2026 · Soulberry is pre-launch. The product described below is not open to the public yet, and this page will change when it is.

Soulberry is a place to put the thing you cannot say out loud. That only works if you are not quietly paying for it with the thing itself. So the design rule is simple: do not collect it, and it cannot leak.

Right now, the only thing here is a waitlist

There is no payment of any kind, and the product itself is not open. If you put your address in the box on the homepage, here is the complete list of what is written down:

Checkable That is the entire database record — an id, your address, the link tag, and two dates. There is no column for an IP address, no column for a browser or device, and no column for a location, so none of those can be recorded even by accident. The shape of the record is the guarantee, not our word for it.

There is an account system, and it is reachable

Being accurate about this rather than tidy: the sign-up and sign-in pages exist and anyone can open them today, because the app behind them is being built in the open. Making an account stores a name, an email address, a hashed password and the dates, and when you agreed to AI replies, if you did. It is not part of the waitlist and you do not need one to join the list.

No analytics. No trackers. No advertising.

This site loads no Google Analytics, no tag manager, no Meta pixel, no Plausible, no PostHog, no session recorder and no advertising script of any kind. There is no third-party JavaScript on the page at all. Nobody is building a profile of you here, because there is nothing running that could.

You will not be followed around the internet by an advert for Soulberry after visiting, for the straightforward reason that we have not given anybody the ability to do it.

The cookies, honestly

Two cookies may be set, and neither one is for marketing. Both come from the sign-in system that guards the private part of the app, and they carry no profile, no identifier that follows you anywhere, and no record of what you looked at.

Your conversations do not live on our servers

When the product opens, the conversations you have with a guide are stored in your own browser, on the device you wrote them on. They are not kept on our servers, and they are not mined or used as training data.

This has a consequence worth saying plainly rather than burying: it also means those conversations do not follow you to a second device, and clearing your browser data clears them. That is the honest cost of keeping them where they are, and you should know it before you rely on it.

Who writes the replies

A guide’s replies are written by Claude, an AI made by Anthropic, so what you say to a guide is sent to Anthropic to be answered. When you ask for a question about a fragment, or for your day’s story, those fragments are sent too. The app asks you first, and nothing is sent until you agree.

Reporting a reply

If you report a guide’s reply, that reply’s words, the guide’s name and any reason you give are sent to us, so we can look at it. Nothing else from the conversation is sent. The report is in your data export, and it is erased with your account.

The database has no public door

Where data does reach a server, the protection is structural. Every table is owned by a dedicated least-privilege role rather than by an administrator account, and the public API roles — the ones that would otherwise answer requests straight from the internet — hold no grants at all. There is no address on the internet where these tables answer. That is the part that matters most and it is the part that is genuinely locked.

Being precise about the rest, because a privacy page that overstates is worth less than one that does not: keeping your rows separate from another person's is done by the application, not by the database. Row-level security is switched on, but a table's owner is exempt from it unless it is forced, and the app connects as the owner — so the rule that separates one person's rows from another's is code we wrote, not a guarantee the database enforces underneath us. Saying otherwise would be the kind of claim this page exists to avoid.

Closing your account

You can close your account yourself. In Settings, choose Close your account and enter your password. It stops working at once, on every device you were signed in on.

It is not erased in that same second, on purpose: a mistaken tap at 2am should not cost a year of writing. For 30 days the account stays closed, and emailing us brings it back. After that, a job that runs once a day erases it and everything our servers hold for it — every fragment, photo and voice note, every day, moment and reminder — and every sign-in.

What closing does not reach

Anything kept in your browser: your conversations with a guide, which live only there, and the copy of your journal and your day that each browser keeps, photos and voice notes included. Closing does not clear them. On each device, use "Clear what is on this device" in Settings while you can still sign in, or clear this site's data in your browser afterwards.

A payment record. Nothing can be paid for yet; once it can, a record of each payment will be kept after the account is erased, because the law says it must be, with your name, email address and password taken off it.

A waitlist address, which is separate, as the next section says.

Taking your address back off the list

You do not need an account, a password or a reply from us. The leave page removes your address from the waitlist, and it is reachable by anyone — precisely because the people most likely to want it are the ones who never signed up for anything else.

What we will never do

Your rights, and how to use them

If you are in the UK or the EU, the GDPR gives you the right to see what is held about you, to correct it, to have it deleted, and to object to it being processed. Given the list at the top of this page, exercising all four is not complicated. Two of them you can do yourself in Settings: Export everything downloads what your account holds, and closing your account erases it. For anything else, email hello@soulberry.ai and say what you want done.

The machine-readable summary of this site, for anyone whose assistant is reading on their behalf, lives at soulberry.ai/llms-full.txt.