This policy explains how Azorean Studios (“we”, “us”) handles information in the SoMi iPhone app and on azorean.io. It applies to the app and this website, and to nothing else.
The short version: SoMi collects the account details it needs to sign you in, the practice data you deliberately enter, and a small amount of usage and crash data to keep the app working. We do not sell your data, we do not share it with advertisers, and there are no advertising trackers in the app.
1. What we collect
Account information
When you create an account we store an account identifier and either the email address you registered with, or the identifier Apple provides when you use Sign in with Apple. If you choose Apple’sHide My Email option, we only ever receive Apple’s relay address — not your real one.
Passwords for email accounts are handled by our authentication provider and stored only as salted hashes. We never see or store your password in readable form.
Practice information you enter
This is the data SoMi exists to hold. It is stored against your account so that the app can show you your own history:
- Check-ins. The energy and safety values you set on the state map, recorded as two numbers from 0 to 100, before and after a session.
- Somatic tags. Any experience tags you select at check-out, such as sighing, shaking, warmth or laughter.
- Journal notes. Free text you choose to write. This is optional and always initiated by you.
- Session records. Which exercises played, in what order, for how many seconds, and when the session happened. These drive your streak, calendar and stats.
Usage and diagnostic information
- Product analytics. We use PostHog to understand how the app is used in aggregate — which screens are opened, and a fixed set of flow events such as starting a flow, completing a block, skipping an exercise, and finishing or leaving a session. Events are linked to your account identifier so we can measure things like completion rate. Analytics events never include your journal text, your tags, or your email address. Analytics data is processed on PostHog’s United States cloud.
- Crash and error reports. We use Sentry to capture crashes and errors, along with the device model, operating system version and app version needed to reproduce them. Our error reporting is configured to strip sensitive fields — including anything named like a token, password, session, or journal entry — before a report is sent.
What we do not collect
- No location data, precise or coarse.
- No contacts, photos, calendar or health-app data. SoMi does not read from Apple Health.
- No microphone or camera access. The app plays audio and video; it does not record any.
- No advertising identifiers, and no third-party advertising SDKs.
- No payment information. SoMi is free and has no in-app purchases.
2. How we use it
| Information | Why we have it |
|---|---|
| Account identifier and email | To sign you in and keep your practice history attached to you |
| Check-ins, tags and journal notes | To show you your own history and to shape the flow the app composes for you |
| Session records | To calculate your streak, calendar, minutes and completion stats |
| Analytics events | To see, in aggregate, where the app is confusing or where people drop out, so we can fix it |
| Crash reports | To find and fix bugs |
We do not use your information to build advertising profiles, and we do not run automated decision-making that produces legal or similarly significant effects.
3. Legal bases (UK and EEA users)
Where the UK GDPR or EU GDPR applies, we rely on: contractfor account and practice data, because without it the app cannot function; and legitimate interests for analytics and crash reporting, to keep the app working and improve it. You can object to processing based on legitimate interests at any time by writing to connect@azorean.io.
4. Who else processes your data
We use a small number of service providers. They process data on our instructions and are not permitted to use it for their own purposes.
| Provider | Role |
|---|---|
| Supabase | Account authentication, database, and exercise video storage |
| Vercel | Hosting for the app’s backend API and this website |
| PostHog | Product analytics (United States cloud) |
| Sentry | Crash and error reporting |
| Apple | App distribution and Sign in with Apple |
We may also disclose information if we are legally required to, or to protect the rights and safety of our users or ourselves.
5. International transfers
We are based in Los Angeles, California, and our providers process data in the United States. If you use SoMi from outside the United States, your information will be transferred there. Where required, our providers rely on Standard Contractual Clauses or equivalent safeguards for these transfers.
6. How long we keep it
Account and practice data is kept for as long as your account exists, because its whole purpose is to be your history. When you delete your account we delete it — see the next section. Aggregated analytics and crash reports are retained by our providers on rolling retention windows and are not tied to a usable identity once your account is gone.
7. Your rights and your controls
You can, at any time:
- Delete your account and everything in it from inside the app, in two taps from the Profile tab. This is a permanent deletion, not a deactivation. Step-by-step instructions are on ouraccount deletion page.
- Ask for a copy of your data, or ask us to correct something, by emailing connect@azorean.io.
- Object to or restrict analytics processing by emailing us.
- Withdraw consent where we relied on it, without affecting processing that already happened.
We answer requests within 30 days. If you are in the UK or EEA you also have the right to complain to your local data protection authority. If you are a California resident, you have the rights described in the CCPA/CPRA to know, delete, and correct your personal information, and not to be discriminated against for exercising them. We do not sell or share personal information as those terms are defined under California law.
8. Children
SoMi is not directed at children. You must be at least 13 years old to create an account, and at least 16 in regions where that is the minimum age for consent to data processing. We do not knowingly collect information from children under those ages. If you believe a child has given us information, write to connect@azorean.io and we will delete it.
9. Security
Data is encrypted in transit. Access to your practice records is enforced at the database level, so one account cannot read another’s rows. No system is perfectly secure, but we keep the amount of data we hold deliberately small, which is the most reliable protection there is.
10. Changes to this policy
If we change this policy we will update the date at the top of this page. For material changes we will also notify you in the app before the change takes effect.
11. Contact
Azorean Studios
Los Angeles, CA 90012, United States
connect@azorean.io