Privacy

Privacy Policy

Effective 12 October 2026

The short version

  • Your conversations, your profile, your mood check-ins and your photos stay on your device and in your private cloud backup. We do not store them.
  • When a reply is written on our server, your words pass through it to an AI model for that reply. Our server does not keep them.
  • Photos are read on your device. Our server never receives a photo.
  • We keep only a random ID. No ads, no tracking, and we never sell data.

Who we are

Soyo (“Soyo”, “we”, “us”) makes the Soyo app and this website. This policy explains what happens to your information when you use them. If you have a question, write to hello@heysoyo.com.

What stays on your device

Soyo keeps the following on your device. If cloud backup is on for Soyo, a copy is also kept in your private cloud storage, so that it can sync to your other devices:

  • Conversations: what you write, Soyo’s replies, and when they were written.
  • Photos you add to a conversation, and the short description of each photo that Soyo makes on your device.
  • Your profile: the name or nickname you choose, your age range, why you came to Soyo, the topics on your mind, how you want Soyo to talk and how long its replies should be, your daily check-in time, and your avatar (a photo, or a color with your initial).
  • Mood check-ins: the mood you pick, and when.
  • Your settings, such as light or dark appearance.

Your private cloud storage belongs to your own account with your device’s maker. On iPhone, it is your private iCloud database (Apple CloudKit). We cannot read it. If cloud backup is off, this information stays only on your device.

Daily check-in reminders are notifications scheduled on your device. We do not run a notification server.

How a reply is written

Depending on your device, and on your choice in Soyo’s Settings under “Replies come from”, a reply is written in one of these ways:

On your device

Some devices can write the reply with an AI model that runs on the device itself (on iPhone, Apple Intelligence). The conversation does not leave the device.

In your device maker’s private cloud

On iPhone, Soyo can use Apple Private Cloud Compute. Apple processes the request on its own servers and states that the data is not stored and is not made available to anyone, including Apple. On devices whose model can understand images, the photo you just shared may be sent with the request, so that the model can see it.

On Soyo’s server

For each reply, the app sends our server:

  • the recent messages of the conversation;
  • your language, and the language Soyo should reply in;
  • a short summary of your profile: your name, age range, reasons, topics, preferred reply style and length, today’s mood check-in, and the part of the day and day of the week where you are;
  • the descriptions of your photos that Soyo made on your device. Never the photos themselves.

Our server adds our own instructions and sends the request to an AI model provider, which writes the reply. The reply streams back to you. Our server does not store the conversation, the profile summary or the photo descriptions, and we do not use them to train AI models. The provider processes the request under its own terms, which may allow it to keep a request for a limited time to detect abuse.

Some smaller features work the same way. For example, when you ask Soyo for a single line to reflect on, the app sends your language and, if you wrote one, your question.

Read aloud

When you use Read aloud with one of Soyo’s voices, the app sends the text of that reply to our server. Our server asks a speech model to read it aloud and sends the sound back. Nothing is stored on our server.

What our server keeps

  • A random user ID. Your device makes it. It is not your name, email address or phone number. Your device keeps it in its secure keychain (on iPhone, iCloud Keychain), so that it stays the same after a reinstall and on your other devices.
  • A signed device token that contains only that ID, so that our server can tell requests from the app apart from other traffic.
  • If you sign in with Apple: a link between the user identifier that Apple gives us for Soyo and your random ID, so that your devices share one ID. We do not receive or keep your email address. If Apple shares your first name, the app uses it to fill in your name on your device; it is not sent to our server.
  • Technical data to run and protect the service. Our hosting provider processes your IP address and basic request details to deliver each request and to limit abuse, for example by limiting how many replies one device can ask for each minute. Our error logs do not contain your conversations.

We may block a device ID that abuses the service.

Service providers

We use a small number of companies to run Soyo. Each one processes your information only to provide its part of the service.

ProviderWhat it does for SoyoWhat it receives
CloudflareHosts our server and this website. Runs AI models (Workers AI) when our main provider is not available.Requests to our server and website; for Workers AI, the reply request described above.
GoogleWrites replies (Gemini API) and reads replies aloud.The reply request described above; the text of a reply you want read aloud.
Apple (on iPhone)Your private cloud storage (iCloud), Private Cloud Compute, Apple Intelligence on the device, and Sign in with Apple.Only what is described in this policy, under Apple’s own terms.

What we never do

  • We do not show ads.
  • We do not track you across apps or websites, and the app contains no advertising or analytics tools.
  • We do not sell or share your information for advertising.
  • We do not read your private cloud storage.

This website

heysoyo.com uses no cookies, no analytics and no trackers, and loads nothing from other companies. Our hosting provider processes basic request data, such as your IP address, to deliver the pages and protect them from abuse.

Your choices and rights

  • Delete your data. In Soyo’s Settings you can delete your conversations, or everything, at any time. This deletes the data on your devices and in your private cloud storage.
  • Choose where replies come from. In Soyo’s Settings, under “Replies come from”, you can choose where replies are written: for example, only on your device, where this is available.
  • Remove the Sign in with Apple link. Stop using Sign in with Apple for Soyo in your Apple Account settings, and write to us. We will delete the link from our server.
  • Your rights. Depending on where you live (for example under the GDPR, the UK GDPR, Japan’s Act on the Protection of Personal Information, or California law), you may have the right to access, correct, delete or move your information, to object to or restrict its use, and to complain to a data protection authority. Because almost everything stays on your devices, you can do most of this yourself in the app. For anything else, write to hello@heysoyo.com.

Legal bases (EEA and UK)

We process the information described here to provide the service you ask for (writing a reply), and for our legitimate interest in keeping the service secure and free of abuse.

Where data is processed

Our providers run their services on global networks, so a request may be processed in a country other than yours, including the United States.

Children

Soyo is not for children under 13. If the law where you live requires a higher age to use a service like Soyo on your own (for example 16 in some countries of the European Union), please use Soyo only with permission from a parent or guardian. If you tell Soyo that you are under 18, it takes extra care in its replies. If we learn that a child under 13 has used our server, we will delete the related data.

Security and retention

Connections between the app and our server are encrypted. Your private cloud storage is protected by its provider’s security. Our server keeps no conversations. We keep the random ID and the Sign in with Apple link while you use Soyo, or until you ask us to delete them. Our hosting provider keeps technical logs for a short time.

Changes and contact

If we change this policy, we will update the date at the top. If a change is important, we will also tell you in the app before it applies.

Questions or requests: hello@heysoyo.com.