Your Privacy

Privacy Policy

How Somyn collects, uses, and protects your personal information — including sensitive health and wellness data — when you use our mobile app and website.

Last updated: August 15, 2026

Encrypted & access-controlled

Data is protected in transit and at rest with role-based access.

HIPAA-aligned framework

Business Associate Agreements and safeguards for protected health information.

You stay in control

Access, export, or delete your data anytime.

Data Handling Summary

This summary mirrors the disclosures provided to the Apple App Store and Google Play Store and is intended to help you quickly understand how each category of data is collected and shared. All data transmission is encrypted (TLS) in transit, and data is encrypted at rest. Somyn does not collect precise or approximate location data.

Personal information

Name, email address, phone number (assessment forms), user IDs, and provider profile details. Used for account management, coaching relationships, and the affiliate program.

Shared: Stripe (payment processing). Never shared for advertising.

Health & fitness data

Food, hydration, movement, body check-ins (including weight and sleep), menopause symptom tracking, emotional reflections, habits, and work reflections. Treated as health information under the FTC Act.

Shared: Third-party AI providers (ephemerally, to generate SomaGuide responses and insights); linked coach only with per-category permission. Employers receive only anonymized, threshold-gated aggregates.

Photos & audio files

Optional meal and profile photos, voice reflections, and AI-chat image attachments. Stored encrypted.

Shared: Third-party AI providers (ephemerally — transcription and vision/language models to generate responses). Never used to train Somyn's or advertising models.

Files and documents

PDF, CSV, DOC, TXT, and JSON files attached to SomaGuide chats or uploaded as coach resources.

Shared: Third-party AI providers (ephemerally, to extract or summarize content). Coach resources are visible only to the coach's connected clients.

In-app messages

SomaGuide AI conversations, provider–client messaging, and in-app notifications.

Shared: SomaGuide messages are sent to third-party AI providers (ephemerally). Provider messaging stays within the coach–client relationship. Your provider never sees SomaGuide conversations unless you explicitly share them.

App activity

Page views, taps, feature-usage events, and other user-generated content (free-text reflections, tarot intentions, relational mirror entries, homework). Used to improve the Service.

Shared: Aggregated, de-identified analytics only. Free-text content is processed by AI providers only when you use AI-assisted features.

Financial information

Subscription status and affiliate payout data (Stripe customer/subscription IDs, commission amounts). No full card numbers are stored by Somyn.

Shared: Stripe (payment processing and Connect payouts to affiliates).

Usage & device information

Approximate device type, operating system, app version, referral source, and interaction events. No device advertising IDs, IMEI, or hardware identifiers are collected.

Shared: Service providers under written agreements (hosting, analytics). No third-party advertising SDKs.

Encrypted in transit & at rest Deletable in-app (full or selective) Not sold; no ad training

Where data is sent to third-party AI providers, it is processed ephemerally to generate your requested response and is not retained by those providers to train their models beyond what their own terms permit (see Section 3). Workplace (Somyn for Work) reflections are private; employers receive only anonymized, threshold-gated aggregated reports.

1. Overview

Somyn ("Somyn," "we," "us," or "our") operates a mindful wellness journal application (the "Service") available via mobile app (iOS and Android) and website. This Privacy Policy explains what information we collect, how we use it, who we share it with, and the rights you have over it.

Somyn is designed around body awareness and reflection. Because users may entrust us with sensitive information about their physical and emotional health, we have built our privacy and security practices to align with the requirements of the Health Insurance Portability and Accountability Act ("HIPAA") where applicable, the Federal Trade Commission Act and the FTC's Health Breach Notification Rule, the California Consumer Privacy Act ("CCPA"/"CPRA"), the EU General Data Protection Regulation ("GDPR"), and the consumer privacy expectations of the Apple App Store and Google Play Store. Under the FTC Act, "health information" includes any information that conveys or enables an inference about a consumer's health — not just diagnoses or treatment records. Somyn therefore treats all journal entries, food and movement logs, body check-ins, emotional reflections, and SomaGuide conversations as health information, and the protections in this Policy apply to them accordingly.

By creating an account or using the Service, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with its terms, please do not use the Service.

2. Information We Collect

Account & contact information: name, email address, password (stored as a one-way hash), and role (e.g., individual user, provider/coach, employer administrator).

Wellness & reflection entries: food and fluid journal entries, movement logs, hydration logs, body check-ins (including interoception and sensory body scan data), sleep and energy observations, emotional reflections, guided prompt responses, habit intentions, relational mirror entries, and free-text journaling.

Sensitive health information: menopause and symptom tracking, body image and eating-disorder-recovery reflections, and other notes that may constitute protected health information ("PHI") under HIPAA. This data is treated with the heightened safeguards described in Section 4.

Provider & coaching data: when you use Somyn with a therapist, dietitian, or coach, your provider may view journal entries you choose to share, assign homework, and record session notes. Sharing is permission-based and revocable.

Workplace data: if your employer sponsors Somyn for Work, we collect work reflections and check-ins. Individual employee entries are never shown to employers — only anonymized, aggregated reporting that meets a minimum group-size threshold.

Assessment submissions: responses to workplace wellbeing and provider practice maturity assessments, along with contact details you provide to receive results.

Usage & device information: approximate device type, operating system, app version, referral source, and interaction events (e.g., features used) used to improve the Service.

Payment information: billing is processed by our payment processor (Stripe). We do not store full card numbers on our servers; we retain only transaction status and a processor-issued customer identifier.

3. How We Use Information

We use your information to:

  • Provide, maintain, and improve the Service, including your journal, check-ins, reflections, and AI-assisted insights;
  • Generate personalized, AI-assisted reflections and pattern observations (you can disable AI features in Settings; see "AI Assistance & Model Training" below for how your content is handled);
  • Facilitate provider–client relationships when you opt in, including homework and session notes;
  • Produce anonymized, aggregated reports for sponsoring employers — never individual employee data;
  • Process subscription payments and send account and billing notifications;
  • Communicate with you about updates, security, and support;
  • Detect, prevent, and respond to fraud, abuse, and security issues;
  • Comply with legal obligations and enforce our terms.

We do not sell your personal information, and we do not use your personal journal content to train advertising models.

AI Assistance & Model Training

When you use SomaGuide AI or other AI-assisted features, your journal entries, reflections, voice notes, and chat messages are sent to our AI service providers (large language model and transcription services) to generate a response. Here is exactly how that data is handled:

  • 1Somyn does not train its own models on your content. We do not build, fine-tune, or train proprietary AI models using your journal entries, body check-ins, reflections, or SomaGuide conversations.
  • 2Your conversations are used only to generate your response. When you send a message to SomaGuide, your input is transmitted to our AI provider as an API request, processed to produce a reply, and returned to you.
  • 3Third-party AI provider practices. Our AI providers' handling of your data is governed by their own terms and privacy policies. We select providers that offer API-based processing and, where available, contract for submitted data not to be used to train their models. Each provider's practices remain subject to their own terms, which we encourage you to review. Somyn does not warrant or control the internal data practices of third-party AI providers beyond what our agreements require.
  • 4No advertising training. Your journal content and SomaGuide conversations are never used to train advertising, ad-targeting, or recommendation models.
  • 5You can turn AI features off. SomaGuide and AI-assisted insights are optional. You can disable them at any time in Settings, and your journal will continue to work without any AI processing. Your provider never sees your SomaGuide conversations unless you explicitly share them.

4. Sensitive Health Information & HIPAA Framework

Some information you provide may be "protected health information" (PHI) under HIPAA. Where Somyn acts as a business associate to a covered entity (for example, a healthcare provider or employer health plan that directs how PHI is used), we handle that PHI in accordance with the HIPAA Privacy, Security, and Breach Notification Rules and the related HITECH Act requirements.

Minimum necessary. We limit collection, use, and disclosure of PHI to the minimum necessary to provide the Service and fulfill our obligations.

Permitted uses. We use PHI only to provide the Service to you and your authorized provider, to perform services on behalf of a covered entity under a Business Associate Agreement, to maintain the Service, and as required by law.

Safeguards framework. We implement the three categories of safeguards required by the HIPAA Security Rule:

  • Administrative safeguards — designated privacy and security responsibility, workforce training, access management, and incident response procedures.
  • Physical safeguards — facility and media controls managed by our cloud infrastructure providers.
  • Technical safeguards — encryption in transit and at rest, unique user authentication, role-based and row-level access controls, audit logging, and automatic session handling.

De-identification. Employer and analytics reporting is de-identified and aggregated in accordance with the HIPAA de-identification standard (Safe Harbor and/or Expert Determination) before disclosure.

If you use Somyn purely as a personal wellness journal without a covered entity relationship, HIPAA may not legally apply to your data. Even so, we apply the same protective safeguards described here to all sensitive wellness information.

5. How We Share Information

We share information only as described in this policy or as required by law:

  • With your provider or coach — only entries you choose to share, when you have an active relationship and grant permission.
  • With sponsoring employers — only de-identified, aggregated group data that meets our anonymity threshold. Individual reflections are never shared with employers.
  • Service providers & subprocessors — vendors that help us operate (hosting, database, email, payments, analytics) under written agreements that obligate them to protect the data, including Business Associate Agreements where PHI is processed.
  • Legal compliance — when required by law, court order, or to protect rights, safety, or property.
  • Business transfers — in connection with a merger, acquisition, or asset sale, with notice of any material change.

We never sell your personal information or rent it to third parties for their marketing.

No advertising use of health data. We do not share your health, wellness, or mental health information — including journal entries, body check-ins, emotional reflections, or SomaGuide conversations — with advertising platforms, ad networks, social media companies, or data brokers for targeted advertising, ad measurement, or ad optimization. We do not use behind-the-scenes tracking technologies that disclose your health data to third parties for advertising. We do not condition access to the Service on your agreement to let us share your health information for advertising. This commitment reflects the FTC's guidance that disclosing consumers' health information for advertising without affirmative express consent is an unfair practice.

6. Business Associate Agreements

Where Somyn creates, receives, maintains, or transmits PHI on behalf of a covered entity, we enter into a Business Associate Agreement (BAA) that defines the permitted uses and disclosures of PHI and obligates us to safeguard it appropriately. Covered-entity customers (healthcare providers, health plans, and their business associates) may request a BAA by contacting our Privacy Office (Section 15).

Our subprocessors that may access PHI are engaged under agreements that include HIPAA-compliant confidentiality and security terms, and we maintain a list of such subprocessors available to BAA customers upon request.

7. Data Security & Safeguards

We take reasonable administrative, technical, and physical measures to protect your information:

  • Encryption of data in transit (TLS) and at rest in our databases and storage;
  • Unique user authentication with password hashing;
  • Role-based and row-level access controls so each user can access only their own data, with administrators restricted to operational needs;
  • Separation of personal wellness data from employer and provider contexts;
  • Anonymity thresholds and de-identification before any group reporting;
  • Audit logging and monitoring to detect unauthorized access;
  • Limited, need-to-know workforce access with confidentiality obligations.

No system is perfectly secure. If you believe an unauthorized party has accessed your account, contact us immediately at ashley@somynjournalapp.com.

8. Data Retention

We retain your information for as long as your account is active and as needed to provide the Service. After account deletion, we remove your personal data from active systems within 30 days, except where we are required to retain limited records for legal, accounting, or compliance purposes (retained only as long as necessary and then securely deleted).

De-identified, aggregated data that can no longer be linked to you may be retained indefinitely for analytics and Service improvement.

9. Your Rights

Depending on your location, you may have the right to:

  • Access the personal and health information we hold about you;
  • Request a copy (export) of your data in a portable format;
  • Request correction or amendment of inaccurate or incomplete information;
  • Request restriction on certain uses or disclosures;
  • Request an accounting of disclosures of PHI where applicable under HIPAA;
  • Request deletion of your account and associated data (available in-app via Settings → Delete Account);
  • Withdraw consent for provider sharing or AI features at any time;
  • Rely on privacy-protective defaults — sensitive sharing (provider data access, employer visibility, and AI-assisted features) is off by default and requires your affirmative opt-in before any data is shared or processed;
  • Opt out of the "sale" or "sharing" of personal information (we do not sell personal information) and limit use of sensitive personal information under CPRA.

To exercise these rights, use the in-app controls or contact our Privacy Office. We will verify your identity before responding and respond within the timeframes required by applicable law (generally 30–45 days).

10. Breach Notification

If you suspect a privacy or security incident, contact us immediately.

In the event of a breach of unsecured PHI, we follow the HIPAA Breach Notification Rule. We will notify affected individuals without unreasonable delay and no later than 60 days following discovery, include required content, and notify the U.S. Secretary of Health and Human Services and, where applicable, the media, as required by law.

For non-HIPAA personal data, we will notify affected users and relevant authorities in accordance with applicable state and international breach-notification laws.

FTC Health Breach Notification Rule. Because Somyn collects health information through a consumer-facing app, the Federal Trade Commission's Health Breach Notification Rule may apply when the Service is used outside of a HIPAA-covered relationship. If we experience a breach of unsecured personal health records not covered by HIPAA, we will notify affected individuals, the FTC, and, where applicable, the media, without unreasonable delay and as required by that Rule.

11. Cookies & Tracking

The Somyn app does not use third-party advertising cookies. Our website and app may use essential cookies or local storage to keep you signed in, remember preferences (such as theme), and understand aggregate usage. You can control cookies through your browser or device settings; disabling them may affect some features.

12. Children's Privacy

The Service is not directed to children under 13 (or the equivalent minimum age in your jurisdiction), and we do not knowingly collect personal information from them. If you believe a child has provided us with personal information, please contact us and we will delete it.

13. International Users

Somyn is hosted in the United States. If you access the Service from outside the U.S., your information is transferred to and processed in the U.S. We apply appropriate safeguards (such as Standard Contractual Clauses where required) for cross-border transfers of personal data originating in the EEA, UK, or other regions with data-transfer requirements.

14. Changes to This Policy

We may update this Privacy Policy from time to time. When we make material changes, we will revise the "Last updated" date above and, where appropriate, notify you through the app or by email. Continued use after changes take effect constitutes acceptance of the updated policy.

15. Contacting Us

If you have questions about this Privacy Policy, your data, or HIPAA-related requests (including requests for a Business Associate Agreement), please contact our Privacy Office:

Somyn Privacy Office

ashley@somynjournalapp.com

We respond to privacy requests within the timeframes required by applicable law.