← Back

Privacy Notice

Last updated: July 9, 2026

This Privacy Notice explains how SomaPhil LLC ("SomaPhil", "we", "us") collects, uses, shares, and protects personal data when you use the SomaPhil application and related services (the "Service"). This page is maintained by SomaPhil LLC.

1. Controller

SomaPhil LLC acts as the data controller for personal data processed in connection with your account and use of the Service. Contact: support@somaphil.com.

2. Personal data we collect

  • Account data: name, email address, password (hashed by our authentication provider), profile handle, avatar, bio, date of birth (if provided), and linked social sign-in identifiers (e.g. Google).
  • Fitness and health-related content you submit: workout logs, exercise history, PRs, cardio and athletic logs, hydration and water logs, weight and body-measurement logs, meal and food logs, macro targets, supplement logs, recovery entries, streaks, goals, mesocycles, and saved plans and recipes. This may include health-related information you choose to enter.
  • Social content: posts, comments, likes, shares, saved posts, mentions, direct messages, crew chats and memberships, follow relationships, and reports you submit.
  • Media: images and videos you upload (e.g. progress photos, post media, chat attachments, verification submissions).
  • Location data: approximate location derived from IP; precise location only when you use the nearby-gyms feature and grant permission.
  • Verification data: for athlete or creator verification, identity information processed by our identity provider (Stripe Identity); we receive only the pass/fail outcome and non-sensitive metadata.
  • Device and push data: device push tokens (FCM) for notifications, notification preferences, browser/device identifiers, app version, timezone.
  • Usage and diagnostic data: pages viewed, actions taken, timestamps, crash and error logs, performance metrics.
  • AI feature inputs and outputs: prompts and context you send to AI features (workout plan survey, meal plan preferences, daily inspiration, coaching), and generated outputs.
  • Support data: messages you send us and related metadata.

Payment card details are collected directly by our reseller Paddle and are not stored by SomaPhil. Identity-document details submitted for verification are collected directly by Stripe Identity and are not stored by SomaPhil.

3. Purposes and legal bases

  • Provide the Service (contract): account creation, sign-in, workout/meal/hydration/PR logging, social feed, DMs, crews, notifications, marketplace, creator payouts.
  • AI features (contract / consent where required): generating workout plans, meal plans, daily inspiration, and other assisted content from inputs you provide. Prompts and outputs may be processed by our AI gateway and underlying model providers to deliver the feature; they are not used to train third-party models by default.
  • Content moderation and safety (legitimate interests / legal obligation): auto-moderation of posts, comments, DMs, crew messages, and media using automated and, where necessary, human review.
  • Security and fraud prevention (legitimate interests): abuse detection, rate limiting, audit logging, refund and chargeback protection.
  • Product improvement and analytics (legitimate interests): aggregate usage analysis to improve the Service.
  • Push and email notifications (contract / consent): delivering notifications you have enabled, including social, streak, and workout reminders.
  • Customer support (contract / legitimate interests): responding to your requests.
  • Legal compliance (legal obligation): tax, accounting, and other obligations.

4. How we share data

  • Merchant of Record — Paddle. Our order process is conducted by our online reseller Paddle.com. Paddle is the Merchant of Record for all our orders and handles payment processing, subscription billing, tax compliance, invoicing, refunds, and related customer service. See Paddle's privacy notice at paddle.com/legal/privacy.
  • Identity verification — Stripe Identity. When you apply for athlete or creator verification, identity documents and biometric checks are processed by Stripe; we receive only the verification outcome and non-sensitive metadata.
  • Infrastructure subprocessors: our hosting, database, authentication, storage, and realtime provider (Supabase); our edge/CDN and serverless runtime provider (Cloudflare); Google Firebase Cloud Messaging for push notifications.
  • AI providers: our AI gateway and underlying model providers process prompts and generate outputs for AI features (plan generation, meal planning, daily inspiration, moderation). Inputs are used to deliver the feature and are not used to train third-party models by default.
  • Content moderation: automated moderation systems (including AI-based classifiers) scan submitted text and media; flagged content may be reviewed by SomaPhil moderators.
  • Other users: your public profile, posts, comments, PRs, streaks, crew activity, and messages you send are visible to the audiences you choose (public, followers, crew members, or DM recipients).
  • Professional advisers: legal, accounting, and similar advisers under confidentiality.
  • Authorities: where required by law or to protect rights, safety, or property.

We do not sell your personal data and we do not share it for cross-context behavioural advertising.

5. Retention

We retain personal data only as long as needed for the purposes above, or as required by law. Account, log, and content data are retained while your account is active. If you delete specific content (e.g. a post, message, workout, or meal log) it is removed from active systems promptly and purged from backups on our standard rotation. If you close your account, personal data is deleted or anonymised within a reasonable period, subject to backups, dispute resolution, fraud prevention, and legal, tax, or accounting retention requirements. You can export or delete your data from Settings → Data, and manage notification preferences from Settings → Notifications.

6. Your rights

Depending on your jurisdiction, you may have the right to access, correct, delete, restrict, port, or object to processing of your personal data, and to withdraw consent. Residents of California, the EEA, the UK, and other regions with equivalent laws have these rights under CCPA/CPRA, GDPR, and UK GDPR respectively. You may also lodge a complaint with your local data protection authority. To exercise these rights, use the tools in Settings or contact support@somaphil.com.

6a. Children

The Service is not directed to children under 13 (or the minimum digital-consent age in your jurisdiction). We do not knowingly collect personal data from such children. If you believe a child has provided us data, contact support@somaphil.com and we will delete it.

7. International transfers

Your data may be processed in countries other than your own. Where required, we rely on appropriate safeguards (such as Standard Contractual Clauses or adequacy decisions) for transfers from the UK/EEA.

8. Security

We use appropriate technical and organisational measures including encryption in transit, access controls, and audit logging. No system is perfectly secure, and we cannot guarantee absolute security.

9. Cookies

We use cookies and similar technologies that are strictly necessary for authentication and session management. We may also use limited analytics cookies to measure aggregate usage. You can manage cookies through your browser settings.

10. Changes

We may update this Notice. Material changes will be notified through the Service or by email.