Privacy policy
Your journey is personal. This page says plainly what we collect, why, and how you stay in charge of it.
Last updated
The short version
- No ads, no ad tracking, no data sale. The app has no advertising software and no ad identifier.
- Health related data needs your yes. We store it only after you agree on a separate screen. Say no and the app still works, with your data on your phone only.
- A second yes for AI. Nothing you write to Sori reaches an AI model until you agree to that too.
- A private vault for each person. Your habits, journal, check ins and chats live in a database that belongs to your account alone, encrypted at rest.
- Export and delete in the app. One tap gives you a copy. Deleting your account erases it.
- Adults only. SoberChamp is for people aged 18 and over.
1. Who we are
SoberChamp is provided by [LEGAL ENTITY NAME], [REGISTERED ADDRESS] (“SoberChamp”, “we”, “us”). We are the controller of the personal data described here.
Questions about privacy: privacy@soberchamp.com.
Representative in the European Union and the United Kingdom: [EU AND UK REPRESENTATIVE, IF REQUIRED].
This policy covers the SoberChamp mobile apps, the API behind them, and this website.
2. What we collect
Your account
- An account id that we create for you.
- How you sign in: as a guest, with an email code, with Apple, or with Google. For email sign in we hold your email address. For Apple or Google we hold the identifier they give us, and your email address if you choose to share it.
- Sessions and devices: the type of phone, the app version, and a push token if you allow notifications.
- Preferences: language, country, time zone, notification choices, and similar settings.
- Your confirmation that you are 18 or over, and a record of each consent you give or withdraw, with the date.
- Subscription status, once memberships are switched on.
A guest account holds no name, no email address and no phone number. We never ask for a phone number.
Your private vault (health related data)
Only if you agree to storage, we keep the following in your personal vault:
- The habits you track, your goals, start dates, slips and pauses.
- Pledges, reviews, check ins, mood and craving logs.
- Journal entries, your reasons, your triggers, and the people you lean on, including any emergency contact you add.
- Your first name or nickname.
- SOS sessions (which tool you used and when).
- Conversations with Sori, the short memories Sori keeps about you, and conversation summaries.
- Safety events: when a message suggested you might be at risk, we record the time, the level and the category. We do not record the text of the message in that event.
Information about a habit such as drinking, smoking, drug use or gambling can reveal something about your health. We treat all of it as health data.
Community content
If you use the Circle: your handle, posts, comments, reactions, group memberships, and any reports or blocks you make. Other members can see what you post, under your handle.
Things we see for a moment and do not keep
- IP address. Used at the edge of the network to limit abuse and route your request. We do not write IP addresses to our databases.
- Request logs. The method, path, status and duration of each request. Never message bodies, tokens or search terms.
This website
This website sets no cookies and runs no analytics. If you join the waitlist we store your email address, the phone type you picked (iPhone, Android or either), the version of the consent text you agreed to, and the date. If you send a web deletion request we store the email address, the kind of request, your optional note, and the date. If you email us, we keep the email.
What we do not collect
No advertising identifier. No contacts list. No precise location. No data bought from other companies. Voice and video calls with Sori are not available yet. We will update this policy before they launch.
3. Why we use it, and our legal basis
| Purpose | Data | Legal basis (GDPR) |
|---|---|---|
| Run your account and the app | Account data | Performance of our contract with you, Article 6(1)(b) |
| Back up and sync your journey | Vault data | Your explicit consent, Articles 6(1)(a) and 9(2)(a) |
| Let you talk with Sori | Chat messages, the reasons, triggers and memories needed for a reply | Your explicit consent, given separately, Articles 6(1)(a) and 9(2)(a) |
| Check chat messages for signs of crisis so Sori can point to human help | Chat messages, safety events | Part of the chat you consented to. Where your life may be at risk we also rely on vital interests, Article 6(1)(d) |
| Run the community and keep it safe | Community content, reports, blocks | Contract, Article 6(1)(b), and our legitimate interest in a safe community, Article 6(1)(f) |
| Send notifications you turned on | Push token, notification choices | Your consent, Article 6(1)(a) |
| Prevent abuse and keep the service secure | IP address in memory, request logs, sessions | Legitimate interests, Article 6(1)(f) |
| Understand how the product is used, when analytics is enabled | Coarse events tied to a pseudonymous id, never free text or habit names | Legitimate interests, Article 6(1)(f). You can switch this off in settings |
| Manage memberships, when enabled | Subscription status from the app stores | Contract, Article 6(1)(b), and legal obligations, Article 6(1)(c) |
| Email you at launch | Waitlist email | Your consent, Article 6(1)(a) |
| Answer you and handle your rights requests | Emails, deletion requests | Legitimate interests and legal obligations, Article 6(1)(c) and (f) |
You can withdraw any consent at any time in the app under Me, Privacy and security, or by writing to us. Withdrawing consent to AI stops the chat. Withdrawing consent to health data storage stops new writes straight away and offers you the deletion of what is already stored. Withdrawal does not affect what happened before it.
We never use your data for advertising, never sell it, and never share it for anyone else’s marketing. We do not use your conversations to train AI models, and we do not give them to anyone for that purpose.
4. Where it lives
| Data | Where |
|---|---|
| Habits, trackers, slips, mood, cravings, journal, chats, memories, SOS, reasons, triggers, name | Your personal vault, a separate database for your account only |
| Account settings, sign in methods, sessions, push tokens, subscription state | Our core database. It has no column that names a habit |
| Community content | Our community database, under your handle |
| Search index for Sori’s memory | A vector index with a separate namespace per account. It holds numbers derived from short memory sentences, not the text |
| Uploaded media, when available | Object storage, under a folder for your account |
Everything is encrypted in transit with TLS and encrypted at rest by our hosting provider. Sign in tokens are stored as hashes.
5. Who helps us process it
We use a small number of service providers. They act on our instructions under data processing terms.
| Provider | What for | What they receive |
|---|---|---|
| Cloudflare, Inc. | Hosting, databases, storage, queues, sign in emails, this website | All data described above, encrypted at rest |
| Cloudflare Workers AI | Running the AI models behind Sori, the safety classifier and memory search. The models run on Cloudflare’s own infrastructure | The chat messages and the context needed for a reply, only after your AI consent |
| Expo (650 Industries, Inc.) | Delivering push notifications through Apple and Google | Your push token and the notification text. By default our notifications name no habit |
| RevenueCat, Inc. (when enabled) | Checking purchases with the App Store and Google Play | Your account id and purchase status. No payment card data |
| PostHog (when enabled) | Product analytics, hosted in the European Union | Coarse events with a pseudonymous id. No free text, no habit names, no message content |
Apple and Google also process data when you sign in with them, receive notifications, or buy a subscription. They do so under their own privacy policies.
We will update this page before we add a provider or switch one on.
We may disclose data when the law requires it, and only as much as it requires. We do not hold the text of your conversations in any place other than your vault.
6. International transfers
Cloudflare runs a global network and several of our providers are based in the United States, so your data may be processed outside your country. Where the law requires it, transfers are covered by an adequacy decision or by standard contractual clauses. You can ask us for a copy of the safeguards.
7. How long we keep it
| Data | How long |
|---|---|
| Account and vault | Until you delete them. We do not delete inactive accounts automatically today. If that changes we will tell you first |
| Sori’s memories and chats | Until you delete them. You can edit or clear what Sori remembers at any time |
| Community posts | Until you delete them or your account, or until moderation removes them |
| Backups | Erased within 30 days of deletion |
| Proof of deletion | A one way hash, kept so we can show that a deletion happened. It cannot be turned back into your data |
| Waitlist email | Until you ask to be removed, or 12 months after launch, whichever comes first |
| Web deletion requests | Removed once handled, and in any case after 90 days |
| Support emails | Up to 24 months |
8. Your rights
Wherever you live, you can:
- Get a copy. In the app: Me, Your data, Export everything. You receive one file with your account, your vault and your community content.
- Correct it. Edit anything in the app, including what Sori remembers.
- Delete it. In the app: Me, Your data, Delete all my data, or Me, Account, Delete account. On the web: delete your account.
- Withdraw consent, restrict or object to processing, by changing your settings or writing to us.
- Complain to your data protection authority. We would be glad to hear from you first.
We answer requests within one month. We will never treat you worse for using your rights.
If you live in the United States
We do not sell personal information and we do not share it for cross context behavioural advertising. We collect and share consumer health data only as described in this policy and only with your consent. You can access and delete it as described above. This applies to residents of Washington, Nevada, California and every other state.
9. Sori and automated processing
Sori’s replies are written by an AI model. Each message is also checked by automated safety systems for signs of crisis. If they find one, Sori changes how it answers and shows you human help. In the community, automated checks may hold back a post until a person reviews it. None of this produces legal effects for you, and you can always reach a person at support@soberchamp.com. More on the AI page.
10. Children
SoberChamp is for adults. You must be 18 or over to create an account, and we do not knowingly collect data from anyone younger. If you believe a child has used SoberChamp, write to us and we will delete the account.
11. Security
Each person’s sensitive data sits in its own database, so one account cannot read another. Data is encrypted in transit and at rest. Secrets are kept out of our code. We do not look at your journal or chats unless you ask us to help with a specific problem and share them with us, or the law requires it. No system is perfectly secure. If a breach affects you, we will tell you and the authorities as the law requires.
12. Changes
If we change this policy in a way that matters, we will tell you in the app before the change takes effect, and ask again for consent where the law requires it. The date at the top always shows the latest version.
13. Contact
[LEGAL ENTITY NAME], [REGISTERED ADDRESS]
Privacy: privacy@soberchamp.com. Everything else: support@soberchamp.com.