Privacy policy
Last updated: 4 October 2026
Summary
- You can use Soul without an account. In that case, your workouts, meals and weight remain on your iPhone and do not reach our servers. If you later create an account or sign in to an existing one, the data you had on that iPhone is added to it.
- With an account, your data syncs to our servers in the European Union (Ireland), so that you do not lose it if you change device. Before we sync the data that reveals information about your health, we ask for your explicit consent, separately (section 3). If you do not give it, the rest of your data still syncs. Your email address is stored in the sign-in system, separate from the database that holds your training and food data.
- We do not sell data, we show no advertising and we do not track you across apps or websites.
- Apple Health data is read on your iPhone and is not sent to our servers.
- Even without an account, crash reports and usage statistics leave your iPhone by default. They include no account and nothing you log, and they are sent to our error-reporting provider in the European Union. Both can be turned off in Settings. Other data leaves only when you use the relevant feature: the barcode scanner, the catalog download, Report a problem or sharing (section 2.1).
- You can export your data and erase your account from within the app.
- Data controller
- Data we process and purposes
- Health data and legal basis
- Recipients of the data
- Location of the data and international transfers
- Retention periods
- Your rights and how to exercise them
- Security
- Minors
- This website
- Changes to this policy
1. Data controller
The data controller, that is, the party that decides why and how your personal data is processed, is Soul Movement, based in Barcelona, Spain.
For any question about your data, or to exercise your rights, write to support@soulmovement.app. We have not appointed a data protection officer.
2. Data we process and purposes
2.1 Using Soul without an account
Everything you log is stored on your iPhone and does not reach our servers.
Nevertheless, certain data does leave the device:
- Crash reports and usage statistics (sections 2.6 and 2.7).
- A barcode lookup, if you use the scanner (2.9).
- The download of the recipe catalog (2.10).
- What you choose to send us from Report a problem (2.8).
- What you choose to share (2.13).
What Soul stores on your iPhone is included in the iPhone backup, if you have it turned on (in iCloud or on your computer). Apple manages that backup, not us. The data Soul reads from Apple Health is not included in it (2.4).
If you later create an account or sign in to an existing one, the data you had logged on that iPhone is added to the account in the first sync. From then on, section 2.3 applies.
If the account already had its own profile, goals or preferences, those of the account take precedence and those of the iPhone are not retained.
2.2 Your account
To create an account we need your email address and a password.
Currently that is the only way to sign in. Your password is managed by the sign-in system of our cloud provider, and we cannot see it.
We process your email address to identify you, to send you the verification code (that same system sends it) and to recover the account. We never send you advertising.
If you wish, you can add two-step verification with an authenticator app. The key that links that app to your account is stored in the sign-in system, and we cannot see it. If you lose the app, you can recover the account by email.
With the account we also store your name and, if you choose one, your @username. Currently your @username only appears on your profile and in the images you decide to share.
Signing out does not erase your data from your iPhone: it remains there and stops syncing. Only your recent searches are cleared.
- Requirement
- Creating an account requires an email address. Everything else is your choice: without an account, Soul works on your iPhone, and without your consent to the processing of health data, your account still works (section 3).
- Legal basis
- The legal basis is the ground that permits us to process your data. Here, it is the performance of the contract you accept by using Soul (Article 6(1)(b) of the General Data Protection Regulation, GDPR).
2.3 Data that syncs with an account
With an account, the following data is stored on your iPhone and on our servers:
| Category | Data included | Legal basis |
|---|---|---|
| Body data and plan | Age, sex, height, weight, target weight, your calorie and macro plan, your level, where you train, your equipment, the days you have free, the area you want to focus on and your totals (workouts, volume and streak). | Performance of the contract and, because it is health data, your explicit consent, which you give separately (section 3) |
| Your log | Your weight, each time you log it; the meals you log (name, calories, macros, servings, time of day and the recipe they come from); your workouts (sets, loads, reps, effort, warm-up, exercises replaced or skipped, rating and any notes you write); the activities you log (type, duration, calories if you enter them and the name you give them); steps you enter manually; your goals and your achievements. | Performance of the contract and explicit consent (section 3) |
| Planning and your own content | Routines, recipes you create, ingredients you replace in a recipe, favourites, shopping list, foods you add and what you plan in the calendar, activities included. | Performance of the contract |
| App preferences | Theme, units, language, rest between sets and its alert, daily reminders, keeping the screen on during a workout, workout view, shopping list by recipe, routine guide length and the training plan you chose. | Performance of the contract |
These always remain on your iPhone: a routine you are still building and have not saved, your choice about usage statistics (it is made on each device) and the data Soul reads from Apple Health (2.4).
The purpose of this processing is to calculate your plan, show your progress and keep your data available on all your devices.
Soul calculates your calorie and macro plan, and the loads it suggests, automatically, from your profile and what you log. It is an aid: it produces no legal effects and decides nothing for you, and you can change your goals at any time.
To protect the service, we count how many requests each account makes per minute and per day. That counter is erased together with the account.
2.4 Apple Health and Apple Watch
Connecting Apple Health is optional and Soul works without it.
If you authorise it, the iPhone app reads your steps and your workouts (with each workout's energy). With them it shows your day and your streak, and marks the activities you plan as completed. The iPhone app writes nothing to Health.
That data is read on your iPhone and is not sent to our servers or to our crash-reporting service, and it is not stored in iCloud either.
What Soul shows you on the basis of it, such as a planned activity being completed, is calculated on the device each time and is not stored.
For the widgets, the app stores your steps for the last seven days and your streak on the device itself, in a file that is excluded from the iCloud backup and erased when you erase your data.
On Apple Watch, during a workout, Soul reads your heart rate and calories to show them on your wrist and, if you authorise it, saves the workout to Health. Those values remain on the watch and in Apple Health: they do not reach us.
The sets you mark on the watch are passed to the iPhone and become part of your workout (2.3).
We never process Health data for advertising or data mining purposes. You can withdraw the authorisation at any time in the iPhone Settings, under Health.
2.5 Recipe import with AI
Currently this is the only Soul feature that uses artificial intelligence.
It requires an account and has a monthly usage limit, higher with Soul Pro.
If you import a recipe from a screenshot or a photo, the text is read on your iPhone, with Apple's text recognition. The image never leaves the device: we only send that text, up to 6,000 characters, together with your session.
Our server transmits that text to a language model hosted by our cloud provider, which processes the request inside the European Union. According to that provider's documentation, the service does not store the text or the response by default and does not share them with the model's developer.
We do not retain them either: we only record how many imports you have made each month, to apply the usage limit.
The model proposes the name, ingredients, quantities and steps. It does not calculate calories or macros: those come from Soul's ingredient catalog.
The result is a proposal: nothing is saved until you review and confirm it. We do not use AI to make automated decisions that produce legal effects concerning you or similarly significantly affect you (Article 22 GDPR).
The legal basis for this feature is the performance of the contract you accept by using Soul (Article 6(1)(b) GDPR), because it is a feature you request.
We also retain three kinds of data related to this feature:
- An alert when you reach 80% of the monthly quota, only with Soul Pro. The server records one line with your account's internal identifier (never your email) to alert us, and it is erased after 14 days. The legal basis is our legitimate interest, that is, a basis the GDPR accepts when our interest is real and is not overridden by your rights and freedoms: anticipating that the service is about to run out and being able to assist you before you reach that point (Article 6(1)(f) GDPR).
- Error lines of the AI service. They include your account's internal identifier, never the text or your email, and are erased after 14 days.
- A higher quota. We can temporarily raise the quota of a specific account, with a short reason and an expiry date; that record is erased if you erase your account. The legal basis is the performance of the contract (Article 6(1)(b) GDPR), as for the rest of this feature.
2.6 Crash reports
If the app crashes, freezes or encounters one of the errors on a closed list that we monitor, it sends a technical report.
The report is sent to our error-reporting provider, in the European Union (Frankfurt). It contains:
- the iPhone model;
- the iOS and app versions;
- the point in the code where the failure occurred;
- system performance data (processor use and disk writes);
- a list of the app's last steps (from a closed list, with no text of yours);
- a random installation identifier, used to calculate the share of users who experience no crashes.
It includes no account, no email address, no screenshots and nothing you log. The list of steps does not include the identifier of any workout or any record of yours either.
As with any internet connection, that provider's server sees the IP address from which the report arrives, but it does not store it: we have configured it that way.
The legal basis is our legitimate interest in the app working and being secure (Article 6(1)(f) GDPR). We have weighed that interest in writing against your rights and freedoms and concluded that they do not override it. You can request that assessment from us at support@soulmovement.app.
You can turn the reports off in Profile › Settings › Privacy › Send crash reports. They are on by default and the choice is made on each device. Once they are off, no report leaves from that moment; the closing notice of the visit in progress may still be sent.
Because the reports contain nothing that identifies you, we cannot exclude yours if you request it by email: the switch is the means to exercise your right to object.
2.7 Usage statistics
The app uses usage statistics to measure which parts of Soul are used.
It counts:
- which screens and features are used;
- how long is spent in each main section;
- how long a visit lasts, in seconds;
- how many times each of a few main buttons is pressed, added up per visit.
Each count includes only:
- its name;
- a value from a closed list that describes it (which section, which button on that list, which page of the tour or step of the set-up wizard, where a workout was started, whether it was saved), or else the seconds or the number of times;
- the time;
- the app version;
- the build environment (the same for all users who install it).
It includes nothing that identifies the user or the installation, no iPhone model, no iOS version and no data of yours. Each count is sent with a random identifier of its own that links it neither to other counts nor to crash reports. They are stored with the same provider, in the European Union.
You can turn this off in Profile › Settings › Privacy › Share usage statistics. It is on by default, the choice is made on each device and, once it is off, the next count is not sent.
The legal basis is our legitimate interest in knowing which features are useful, in line with the criteria of the Spanish Data Protection Agency (AEPD) for audience measurement (Article 6(1)(f) GDPR). The same legitimate interest assessment compares this set-up with those criteria, and you can request it from us too.
That provider is our data processor: it processes this data only on our instructions, under a contract that prohibits it from using it for other purposes. We have also switched off the option that would allow it to use identifying data to improve its product.
2.8 Report a problem
If you write to us from Report a problem, we receive your message and an image.
When you open Report a problem from a screen, a capture of that screen is attached. You can remove it or choose another before sending. The image is re-encoded on the device to remove the metadata it contains, such as location.
Together with them we also send:
- your email address, if you enter it so that we can reply;
- the app version;
- the iPhone model;
- and, if crash reports are on, the list of the app's last steps.
All of it is sent to our error-reporting provider, in the European Union. The legal basis is the handling of your request (Article 6(1)(b) GDPR). Check the screenshot before sending: if it shows your data, we receive it.
The Diagnostic log (Profile › Settings › Diagnostics) remains on your iPhone. It only leaves the device if you share it, through whichever channel you choose.
2.9 Barcode scanner and the photo of your recipes
The camera reads the code or the nutrition label on your iPhone, and the image is neither stored nor sent anywhere.
To locate the product, we send only the barcode number to an open food database. We send no data about your account. As with any internet connection, its server sees the IP address from which the lookup is made.
If you add a photo to a recipe of your own, whether you take it with the camera or choose it from your library (Soul cannot access the rest of your library), that photo is stored on your iPhone and not on our servers: it does not leave the device.
Soul saves it again at a smaller size and without the location or any other data it was taken with. It is erased when you remove it or with Delete the data on this iPhone. Like everything Soul stores on your iPhone, it is included in the backup if you have it turned on (section 2.1).
2.10 Catalogue and recipe photos
Photos and the catalog are downloaded from our content delivery network, from servers located in Europe or North America.
That network's access logs record the IP address, the device type and the file requested, for the purpose of operating and protecting the service. The legal basis is our legitimate interest (Article 6(1)(f) GDPR).
2.11 Soul Pro subscription
Apple handles payment.
We do not receive your payment details or your Apple ID. The app checks on your iPhone whether you have Soul Pro and stores the purchase identifier and its expiry date in the device's keychain.
If you buy while signed in to Soul, the purchase also includes your account's internal identifier (an identifier that does not reveal your identity: it is neither your email nor your name). Apple retains it with the purchase so that we can tell which account it belongs to. Currently no data about your purchase reaches our servers.
Apple processes that data on its own account, as an independent controller, in accordance with its privacy policy.
2.12 Reminders
Soul's reminders are local notifications scheduled by your own iPhone.
They are the reminder two days before a free trial ends and the daily reminders, if you turn them on. We do not use a notification server.
2.13 Sharing a workout
If you share or save a workout card, the image is generated on your iPhone and goes to the destination you choose (Photos, a messaging app or a social network).
It contains what you see on it, including your @username if you have one. To save it to Photos, Soul only requests permission to add: it cannot access the rest of your library.
2.14 Other legal bases
For this data, the legal basis is the following:
- Server technical and security logs, the list of deleted accounts, the counters that limit the number of requests and the IP address of visitors to this website: our legitimate interest in the security and operation of the service (Article 6(1)(f) GDPR).
- The AI import counter, a barcode lookup and the check of your purchase: they are necessary for the feature you request (Article 6(1)(b)).
- The record of your consent to health-data processing: to comply with our obligation to be able to demonstrate it (Articles 6(1)(c) and 7(1)).
3. Health data and legal basis
Your weight, height, what you eat and how you train can reveal information about your health.
The GDPR defines data concerning health (Article 4(15)) and includes it among the special categories, whose processing is prohibited unless an exception applies (Article 9(1)).
We regard as health data what section 2.3 identifies as such:
- your body data and your plan;
- your weight;
- your meals;
- your workouts;
- your activities;
- steps entered manually;
- your goals and your achievements.
For the copy we keep on our servers, the exception we rely on is your explicit consent, that is, an express statement for a specific purpose (Article 9(2)(a)). We request it in order to store and sync that data and provide the service.
Without an account, that data never leaves your iPhone and never reaches us, so we do not request your consent.
We request it on a screen of its own, separate from the other terms, when you link an account to your iPhone and before the first sync. The screen contains:
- a sentence in which you state that you give your consent;
- a box that starts unticked;
- a save button that remains inactive until you tick the box;
- next to it, of the same size, the option not to give it.
The consent also covers what you had logged on that iPhone without an account, which is uploaded in that same sync.
If you do not give it, Soul keeps working in full and your health data remains only on your iPhone. Everything that is not health data still syncs with your account:
- routines;
- recipes;
- replaced ingredients;
- favourites;
- shopping list;
- foods;
- what you plan;
- your preferences.
Of your profile only your name syncs, and your @username stays with your account. The account also continues to give you access to AI import.
You can withdraw your consent at any time, and withdrawing it is as easy as giving it (Article 7(3) GDPR). The processing carried out before you withdraw it remains lawful.
You withdraw it in Profile › Settings › Privacy › Health data in your account. We then erase your health data from our servers, including what was already marked as deleted (Article 17(1)(b) GDPR). The rest of your account keeps syncing and nothing is erased on your iPhone.
To be able to demonstrate that you gave it (Article 7(1) GDPR), we retain with your account, without any health data:
- when you gave or withdrew it;
- the version of the text you accepted;
- the language;
- the app version.
If you erase the account, that record is kept blocked for five years: set aside, not used for any other purpose and available only to courts and data protection authorities.
The period is five years because it covers the three years in which the infringements the record could evidence become time-barred and the five years of a claim based on the contract. After that period, it is erased (Articles 32 and 72 of Spanish Organic Law 3/2018 and Article 1964.2 of the Spanish Civil Code).
Soul is not a medical device, is not intended to diagnose or treat any disease and does not replace advice from a professional. Calories and macros are indicative, and allergens depend on the brand you buy: always read the label.
4. Recipients of the data
We do not sell your data or disclose it to advertisers or to companies that trade in personal data.
These providers process it on our behalf, under a data processing agreement, and are therefore our processors:
| Provider | Purpose | Location |
|---|---|---|
| Cloud hosting | Account and verification email, servers, database, catalog and AI | Ireland; AI in EU regions; the public catalog is also served from North America |
| Error reporting | Crash reports, usage statistics and the problems you report | Frankfurt (Germany); account settings in the US |
| Web hosting | Hosting and protecting this website (visitors' IP addresses) | Its global network |
They are three different companies. If you wish to know which, write to support@soulmovement.app and we will tell you.
Our email provider hosts the support@, hello@ and security@soulmovement.app mailboxes: what you email us is stored there.
There are also two recipients that are not our processors: Apple (payments, Health and your iPhone's backups) and an open food database (the barcode only).
The developer of the model behind AI import does not receive your data: according to our cloud provider's documentation, neither what you send nor the response is shared with it.
We would only disclose data to an authority if the law required us to do so.
5. Location of the data and international transfers
Your account and training data are stored in the European Union (Ireland), and AI import is processed inside the European Union.
The three providers in section 4 are US companies. If any data leaves the European Union, the transfer is covered by their certification under the EU-U.S. Data Privacy Framework and by the European Commission's standard contractual clauses included in their data processing agreements.
The error-reporting provider stores its data in Germany. The public catalog and its photos are also served from servers in North America, which log the IP address of whoever requests them.
You can request a copy of those clauses from us at support@soulmovement.app.
6. Retention periods
| Data | Retention period |
|---|---|
| Account and synced data | As long as you have the account. When you delete it, the data is erased at once from the database; from the sign-in system also at once or, if that step fails, as soon as we detect it. |
| Health data if you withdraw your consent | Erased from our servers when you withdraw it, including what was marked as deleted; it disappears from the backups within 35 days. It remains on your iPhone. |
| Record of your consent to health-data processing | As long as you have the account. Once the account is deleted, it is retained blocked for five years and then erased (section 3). |
| Encrypted backups | 35 days. Deleted data is put beyond use and, if a backup ever had to be restored, it is erased again before the backup is put into service. |
| A single record you delete (a meal, a workout) | When you delete a meal, a workout or another record, its content is emptied at once on your iPhone and on our servers; you have 5 seconds to undo it. What remains is an empty marker with its identifier and the date, so that it also disappears from your other devices, until you delete the account. |
| List of deleted accounts | The account's internal identifier and the date, with no email address or name. It is retained for as long as Soul operates: it prevents a session still open on another device from recreating the account. |
| AI import counter | As long as you have the account. |
| Near-quota alert for AI imports (Soul Pro) | 14 days. |
| An account's temporary higher AI import quota | As long as you have the account; erased with it. |
| Crash reports and statistics | 30 days. The random installation identifier remains on your iPhone until you remove the app. |
| Problems you report | The period our error-reporting provider applies to these messages. If you gave us your email address and ask us to delete it, we delete it manually. |
| Emails you send us | As long as necessary to assist you and up to one year after the matter is closed; requests concerning your rights, three years. |
| Server technical logs | 14 days; database engine logs, 30 days, without the content of your data; content delivery logs, 90 days. |
| Security log of the sign-in system | Every sign-up, sign-in, session renewal, password change and account deletion, with the date, the IP address and the account's internal identifier. 1 year. Legal basis: our legitimate interest in the security of the service and in being able to investigate improper access (Article 6(1)(f) GDPR). |
| What is on your iPhone | Until you delete it: by removing the app, with Delete my account or, without an account, with Delete the data on this iPhone. App preferences (theme, units) remain until you remove the app. The proof of your purchase remains in the iPhone's keychain, which may retain it even after you remove the app. |
7. Your rights and how to exercise them
You can exercise your rights from the app or by writing to us.
These are the rights you hold:
- Access: knowing what data of yours we process.
- Rectification: correcting inaccurate data.
- Erasure: requesting that we delete your data.
- Objection: objecting to our processing of your data.
- Restriction of processing: requesting that we limit the processing of your data.
- Data portability: receiving your data to transfer it to another controller.
- Withdrawing your consent at any time.
From the app you can do the following:
- Correct: edit your profile, your goals and your records. The weight you log cannot be edited or deleted in the app: write to us and we will correct or delete it.
- Export: Profile › Settings › Export my data creates three CSV files (your sets, your meals and your weight). It is free of charge, with or without Soul Pro and with or without an account. If you want a full copy of all the data we process, write to us.
- Delete: Profile › Settings › Delete my account. It deletes your account and your data on the server, then on the device. Without an account, the same row is called Delete the data on this iPhone. Deleting the account does not cancel an Apple subscription: you must cancel it yourself in your Apple ID settings.
- Withdraw the health-data consent: Profile › Settings › Privacy › Health data in your account (section 3).
- Crash reports and statistics: Profile › Settings › Privacy.
Your right to object
You can object to the processing of your data when it is based on our legitimate interest, at any time and on grounds relating to your particular situation (Article 21 GDPR).
That is the case for crash reports, usage statistics, the content delivery logs and the security log of the sign-in system. This is how you can do so for each one:
- Usage statistics: turn them off in Profile › Settings › Privacy › Share usage statistics.
- Crash reports: turn them off in Profile › Settings › Privacy › Send crash reports.
- Content delivery logs: without them we cannot serve you the catalog or the photos. If you object, write to us.
- Security log: write to us.
The first time you open the app, a screen of its own informs you of this and lets you switch them off before you continue (Article 21(4) GDPR).
For any other request, write to support@soulmovement.app. We will answer without undue delay and within one month at most. For a complex request, that period can be extended by two further months, and we would inform you within the first (Article 12(3) GDPR).
If you are not satisfied with the answer, you have the right to lodge a complaint with the Spanish Data Protection Agency (AEPD) at www.aepd.es, or with the supervisory authority of the EU country where you live.
8. Security
Connections are encrypted, the database and its backups are encrypted and your data can only be accessed with your session.
Your email address is not stored in the same database as your training and food data.
If you detect a security problem, write to security@soulmovement.app.
If a personal data breach affecting your data were ever to occur, we would notify the AEPD within 72 hours of becoming aware of it, unless it is unlikely to result in a risk. We would also inform you without undue delay if it is likely to result in a high risk to you (Articles 33 and 34 GDPR).
9. Minors
Soul is not aimed at anyone under 14, and the app does not accept a lower age when you set up your profile.
In Spain, a child under 14 cannot consent on their own to the processing of their data; from that age, you give the consent for health data yourself (Article 7 of Organic Law 3/2018).
If you live in another country and its law sets a higher age for consenting yourself to the processing of your data, you must have reached that age to use Soul and to give us that consent.
10. This website
soulmovement.app uses no cookies of its own or for analytics and loads no content from third parties.
It is hosted by a web hosting provider, which processes visitors' IP addresses on our behalf to deliver and protect it.
11. Changes to this policy
If we make any significant change, we will inform you in the app before it applies.
If what we ask for in the health-data consent changes, we will ask you again. The date at the top indicates the latest version.
This policy is written in Spanish and translated into English. All versions have the same content; if you notice a difference, write to support@soulmovement.app and we will correct it.
We treat your data the way we would want ours treated: as little as possible, and in plain sight. If anything on this page is unclear, ask us.
DaniCybersecurity Engineer · Cloud & App Architect