Soothe — Privacy Policy

Last updated: 20 August 2026

This explains exactly what Soothe stores, where it goes, and what it never does. If anything here is unclear, assume the stricter reading and ask.

Who is responsible for your data

Soothe is published by Erdem Kılıç, established in Türkiye. This makes him the data controller (GDPR) and the veri sorumlusu (KVKK) for everything described here. You can reach him at infobicehgo@gmail.com.

Two laws apply at once, because the app is offered worldwide from Türkiye:

Where the two differ, whichever gives you more protection is what we follow.

EU representative (Article 27): Alias Finn, Mönchseestraße 41, 74072 Heilbronn, Germany — erd3m_k@hotmail.com. Appointed to receive enquiries from people in the EU and from supervisory authorities, alongside (not instead of) the controller above. Writing to the representative does not replace your right to complain to a supervisory authority.

What Soothe is and is not

Soothe is emotional pre-support for adults. It is not therapy, not a medical service, and not a crisis service. It does not diagnose, does not prescribe, and cannot give medical advice.

If you are in immediate danger, contact your local emergency services. Soothe cannot call anyone for you, and nobody is monitoring what you write.

Who can use it

You must be 18 or older. The app is not designed for children, and we do not knowingly collect data from anyone under 18. You confirm your age before the app opens. If we learn that someone under 18 has used the app, their data is deleted.

What is stored

What is not collected

No name, no email address, and no phone number unless you later create an account with one. No contacts, no location, and no health-app data. There is no analytics SDK in the app.

No advertising identifier is collected, and nothing you write is used to choose which ads you see — see Advertising below.

Why we are allowed to store it

Your check-ins and messages describe how you feel, which the GDPR treats as data concerning health — a special category needing stronger protection. Our legal basis is your explicit consent (Article 6(1)(a) together with Article 9(2)(a)), which you give on the welcome screen before the app opens.

You can withdraw that consent at any time by requesting deletion (see below). Withdrawing it does not affect anything done before you withdrew.

Where it is stored

On Google Firebase, in European data centres. Data is encrypted in transit and encrypted at rest. Security rules restrict every record to the account that created it, so no other user can read your check-ins or messages.

To be precise about what that encryption does and does not mean: it protects the data on disk and on the wire. It is not end-to-end encrypted. Google, and anyone with administrative access to the project, is technically able to read what you write.

The AI service

To write a reply, Soothe sends your check-in context and your most recent messages to an AI service. The full conversation history is never sent — only recent turns.

Two services are used: Google Gemini, and Groq once Gemini's daily allowance is spent.

Read this part carefully. On Gemini's free tier, Google may have people review what you write and may use it to improve and train its models. Google's own guidance for that tier is not to submit sensitive or personal information. Groq states that it does not use inputs or outputs to train models and does not retain them.

Please treat anything you write here as something a third party may read.

Where your data goes across borders

Storage stays in the EEA, but the AI services do not. When a reply is generated, the text of that request is processed by Google and Groq, both established in the United States.

If you are in the EEA: that is a transfer outside the EEA. Both providers offer Standard Contractual Clauses approved by the European Commission, which is the safeguard relied on here.

If you are in Türkiye: your data leaves the country twice over — it is stored in European data centres and the reply text is processed in the United States. Under KVKK Article 9 this is a transfer abroad (yurt dışına aktarım), and the basis relied on is your explicit consent (açık rıza), given on the welcome screen before the app opens. Nothing you write is stored or processed inside Türkiye.

Either way, the practical protection for that specific request text is weaker than for the data at rest — which is the reason for the warning in the section above.

Crisis detection

Your notes and messages are checked against a fixed list of words and phrases on your own device, before anything is sent anywhere. It is a plain word list, not an AI, and it makes no judgement about you.

If something matches, the conversation stops and you are shown a message suggesting professional support. Nothing is reported to anyone, no human reviews it, and the matching text is never stored or logged — only a general category is recorded.

Advertising

The free version shows ads. They appear in one place only — the home screen — and never during a check-in, never in a conversation, and never on the screen that appears if you write something suggesting you are in danger.

The ads are not personalised. Every request Soothe makes is explicitly marked non-personalised, which means the ad network is not given an advertising identifier and does not build a profile of you from this app.

This is deliberate, and it costs us money: personalised ads pay several times more. Nothing you write here should end up helping an advertiser work out that you use a mental-health app.

Nothing you write is ever sent to an advertiser. Your check-ins and messages are not used to select ads, are not shared with the ad network, and play no part in what you see.

Ads are served by Google AdMob. To show an ad at all, it reads and stores limited technical information on your device. If you are in the EEA or the UK, you are asked about this the first time the app opens, and you can decline — declining means no ads, and the app works exactly the same.

The paid version removes ads entirely.

Sharing

Your data is never sold. It is never shared with advertisers or data brokers. The only third parties that receive anything you write are:

WhoWhat they getWhy
Google (Firebase) Check-ins, messages, settings Storage and anonymous sign-in
Google (Gemini) Check-in context and recent messages To generate a reply
Groq Check-in context and recent messages To generate a reply when Gemini is unavailable
Google AdMob Nothing you write. Only the technical data needed to deliver a non-personalised ad To show ads in the free version

Nothing you write is shared for advertising or profiling, and nothing is used for automated decisions that produce legal effects.

Keeping and deleting

Your check-ins and conversations are kept so you can look back at them. They are kept until you ask for them to be deleted, or until the app is discontinued, whichever comes first.

You can delete everything yourself, from inside the app. Open the shield icon on the home screen, scroll to the bottom of the Privacy screen and tap Delete my data. It asks once to confirm, then removes every check-in, every message and your account — from the device and from our servers. It takes effect immediately; there is no waiting period and nothing to email us about.

Because it also deletes your account, it is how you withdraw consent. You will be asked to accept the terms again if you keep using the app.

If the deletion reports that something could not be removed, tell us at infobicehgo@gmail.com and quote your account identifier, shown just above the button. We will finish it by hand within 30 days.

Uninstalling the app does not delete anything on its own; the records stay under the anonymous account until deletion is requested.

Your rights

If you are in the EEA or the UK, you have the right to:

Access
Get a copy of what is stored about you.
Rectification
Have inaccurate data corrected.
Erasure
Have your data deleted, as described above.
Portability
Receive your data in a machine-readable format.
Restriction and objection
Ask us to stop processing your data.
Withdraw consent
At any time, without giving a reason.

Erasure is the one you can exercise yourself, immediately, using the button described above. For the others, email infobicehgo@gmail.com and include your account identifier — anonymous sign-in means we have no name to look you up by, and we will not guess which records are yours.

You also have the right to complain to a data-protection authority — normally the one where you live. Because the controller is established in Türkiye, you can also complain to the Kişisel Verileri Koruma Kurumu (Turkish Personal Data Protection Authority), kvkk.gov.tr.

If you are in Türkiye

KVKK Article 11 gives you the same substance under different names: to learn whether your data is processed and to ask for a copy, to have it corrected or deleted, to be told who it was transferred to at home and abroad, to object to a result produced solely by automated analysis, and to claim compensation for damage caused by unlawful processing. The same address and the same account identifier apply, and the deletion button covers erasure immediately.

Changes to this policy

If this policy changes in a way that affects what happens to your data, the app will ask for your consent again rather than quietly updating the date at the top. The date always reflects the current version.

Contact

Questions, or a deletion request: infobicehgo@gmail.com