Your Privacy
How Somyn collects, uses, and protects your personal information — including sensitive health and wellness data — when you use our mobile app and website.
Last updated: August 15, 2026
Data is protected in transit and at rest with role-based access.
Business Associate Agreements and safeguards for protected health information.
Access, export, or delete your data anytime.
This summary mirrors the disclosures provided to the Apple App Store and Google Play Store and is intended to help you quickly understand how each category of data is collected and shared. All data transmission is encrypted (TLS) in transit, and data is encrypted at rest. Somyn does not collect precise or approximate location data.
Name, email address, phone number (assessment forms), user IDs, and provider profile details. Used for account management, coaching relationships, and the affiliate program.
Shared: Stripe (payment processing). Never shared for advertising.
Food, hydration, movement, body check-ins (including weight and sleep), menopause symptom tracking, emotional reflections, habits, and work reflections. Treated as health information under the FTC Act.
Shared: Third-party AI providers (ephemerally, to generate SomaGuide responses and insights); linked coach only with per-category permission. Employers receive only anonymized, threshold-gated aggregates.
Optional meal and profile photos, voice reflections, and AI-chat image attachments. Stored encrypted.
Shared: Third-party AI providers (ephemerally — transcription and vision/language models to generate responses). Never used to train Somyn's or advertising models.
PDF, CSV, DOC, TXT, and JSON files attached to SomaGuide chats or uploaded as coach resources.
Shared: Third-party AI providers (ephemerally, to extract or summarize content). Coach resources are visible only to the coach's connected clients.
SomaGuide AI conversations, provider–client messaging, and in-app notifications.
Shared: SomaGuide messages are sent to third-party AI providers (ephemerally). Provider messaging stays within the coach–client relationship. Your provider never sees SomaGuide conversations unless you explicitly share them.
Page views, taps, feature-usage events, and other user-generated content (free-text reflections, tarot intentions, relational mirror entries, homework). Used to improve the Service.
Shared: Aggregated, de-identified analytics only. Free-text content is processed by AI providers only when you use AI-assisted features.
Subscription status and affiliate payout data (Stripe customer/subscription IDs, commission amounts). No full card numbers are stored by Somyn.
Shared: Stripe (payment processing and Connect payouts to affiliates).
Approximate device type, operating system, app version, referral source, and interaction events. No device advertising IDs, IMEI, or hardware identifiers are collected.
Shared: Service providers under written agreements (hosting, analytics). No third-party advertising SDKs.
Where data is sent to third-party AI providers, it is processed ephemerally to generate your requested response and is not retained by those providers to train their models beyond what their own terms permit (see Section 3). Workplace (Somyn for Work) reflections are private; employers receive only anonymized, threshold-gated aggregated reports.
Somyn ("Somyn," "we," "us," or "our") operates a mindful wellness journal application (the "Service") available via mobile app (iOS and Android) and website. This Privacy Policy explains what information we collect, how we use it, who we share it with, and the rights you have over it.
Somyn is designed around body awareness and reflection. Because users may entrust us with sensitive information about their physical and emotional health, we have built our privacy and security practices to align with the requirements of the Health Insurance Portability and Accountability Act ("HIPAA") where applicable, the Federal Trade Commission Act and the FTC's Health Breach Notification Rule, the California Consumer Privacy Act ("CCPA"/"CPRA"), the EU General Data Protection Regulation ("GDPR"), and the consumer privacy expectations of the Apple App Store and Google Play Store. Under the FTC Act, "health information" includes any information that conveys or enables an inference about a consumer's health — not just diagnoses or treatment records. Somyn therefore treats all journal entries, food and movement logs, body check-ins, emotional reflections, and SomaGuide conversations as health information, and the protections in this Policy apply to them accordingly.
By creating an account or using the Service, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with its terms, please do not use the Service.
Account & contact information: name, email address, password (stored as a one-way hash), and role (e.g., individual user, provider/coach, employer administrator).
Wellness & reflection entries: food and fluid journal entries, movement logs, hydration logs, body check-ins (including interoception and sensory body scan data), sleep and energy observations, emotional reflections, guided prompt responses, habit intentions, relational mirror entries, and free-text journaling.
Sensitive health information: menopause and symptom tracking, body image and eating-disorder-recovery reflections, and other notes that may constitute protected health information ("PHI") under HIPAA. This data is treated with the heightened safeguards described in Section 4.
Provider & coaching data: when you use Somyn with a therapist, dietitian, or coach, your provider may view journal entries you choose to share, assign homework, and record session notes. Sharing is permission-based and revocable.
Workplace data: if your employer sponsors Somyn for Work, we collect work reflections and check-ins. Individual employee entries are never shown to employers — only anonymized, aggregated reporting that meets a minimum group-size threshold.
Assessment submissions: responses to workplace wellbeing and provider practice maturity assessments, along with contact details you provide to receive results.
Usage & device information: approximate device type, operating system, app version, referral source, and interaction events (e.g., features used) used to improve the Service.
Payment information: billing is processed by our payment processor (Stripe). We do not store full card numbers on our servers; we retain only transaction status and a processor-issued customer identifier.
We use your information to:
We do not sell your personal information, and we do not use your personal journal content to train advertising models.
When you use SomaGuide AI or other AI-assisted features, your journal entries, reflections, voice notes, and chat messages are sent to our AI service providers (large language model and transcription services) to generate a response. Here is exactly how that data is handled:
Some information you provide may be "protected health information" (PHI) under HIPAA. Where Somyn acts as a business associate to a covered entity (for example, a healthcare provider or employer health plan that directs how PHI is used), we handle that PHI in accordance with the HIPAA Privacy, Security, and Breach Notification Rules and the related HITECH Act requirements.
Minimum necessary. We limit collection, use, and disclosure of PHI to the minimum necessary to provide the Service and fulfill our obligations.
Permitted uses. We use PHI only to provide the Service to you and your authorized provider, to perform services on behalf of a covered entity under a Business Associate Agreement, to maintain the Service, and as required by law.
Safeguards framework. We implement the three categories of safeguards required by the HIPAA Security Rule:
De-identification. Employer and analytics reporting is de-identified and aggregated in accordance with the HIPAA de-identification standard (Safe Harbor and/or Expert Determination) before disclosure.
If you use Somyn purely as a personal wellness journal without a covered entity relationship, HIPAA may not legally apply to your data. Even so, we apply the same protective safeguards described here to all sensitive wellness information.
Where Somyn creates, receives, maintains, or transmits PHI on behalf of a covered entity, we enter into a Business Associate Agreement (BAA) that defines the permitted uses and disclosures of PHI and obligates us to safeguard it appropriately. Covered-entity customers (healthcare providers, health plans, and their business associates) may request a BAA by contacting our Privacy Office (Section 15).
Our subprocessors that may access PHI are engaged under agreements that include HIPAA-compliant confidentiality and security terms, and we maintain a list of such subprocessors available to BAA customers upon request.
We take reasonable administrative, technical, and physical measures to protect your information:
No system is perfectly secure. If you believe an unauthorized party has accessed your account, contact us immediately at ashley@somynjournalapp.com.
We retain your information for as long as your account is active and as needed to provide the Service. After account deletion, we remove your personal data from active systems within 30 days, except where we are required to retain limited records for legal, accounting, or compliance purposes (retained only as long as necessary and then securely deleted).
De-identified, aggregated data that can no longer be linked to you may be retained indefinitely for analytics and Service improvement.
Depending on your location, you may have the right to:
To exercise these rights, use the in-app controls or contact our Privacy Office. We will verify your identity before responding and respond within the timeframes required by applicable law (generally 30–45 days).
If you suspect a privacy or security incident, contact us immediately.
In the event of a breach of unsecured PHI, we follow the HIPAA Breach Notification Rule. We will notify affected individuals without unreasonable delay and no later than 60 days following discovery, include required content, and notify the U.S. Secretary of Health and Human Services and, where applicable, the media, as required by law.
For non-HIPAA personal data, we will notify affected users and relevant authorities in accordance with applicable state and international breach-notification laws.
FTC Health Breach Notification Rule. Because Somyn collects health information through a consumer-facing app, the Federal Trade Commission's Health Breach Notification Rule may apply when the Service is used outside of a HIPAA-covered relationship. If we experience a breach of unsecured personal health records not covered by HIPAA, we will notify affected individuals, the FTC, and, where applicable, the media, without unreasonable delay and as required by that Rule.
The Service is not directed to children under 13 (or the equivalent minimum age in your jurisdiction), and we do not knowingly collect personal information from them. If you believe a child has provided us with personal information, please contact us and we will delete it.
Somyn is hosted in the United States. If you access the Service from outside the U.S., your information is transferred to and processed in the U.S. We apply appropriate safeguards (such as Standard Contractual Clauses where required) for cross-border transfers of personal data originating in the EEA, UK, or other regions with data-transfer requirements.
We may update this Privacy Policy from time to time. When we make material changes, we will revise the "Last updated" date above and, where appropriate, notify you through the app or by email. Continued use after changes take effect constitutes acceptance of the updated policy.
If you have questions about this Privacy Policy, your data, or HIPAA-related requests (including requests for a Business Associate Agreement), please contact our Privacy Office:
Somyn Privacy Office
ashley@somynjournalapp.comWe respond to privacy requests within the timeframes required by applicable law.