This service is operated by Aionlabs Private Limited, India (“we”). Contact for anything in this policy: support@soma.ninja.
What we collect and why
- Account & sign-in — Google sign-in (we receive your name, e-mail and avatar from Google) or an e-mail magic-link (delivered by Resend; we store your e-mail). Used to provide your account.
- Learning & usage data — decks, reviews, progress, points, feature usage. Used to run the service and your learning history.
- AI features — when you use one, the content it needs (a word or line you tap, a story or dialogue to write, a photo you turn into vocabulary, or the audio of a YouTube video you ask us to transcribe) is processed by our AI service providers to produce the explanation, story or transcript. In shadowing, your voice recording is processed by a speech-recognition provider to score your pronunciation; we don’t keep the recording. Photos you upload are stored with your account; e-mail support@soma.ninja to have them deleted.
- Payments — processed by Polar, our merchant of record: Polar is the seller, handles checkout, payment data, invoices and applicable taxes; we receive order/subscription status and never see card numbers.
- Hosting & infrastructure — Vercel (web hosting and the cookieless analytics below; short-lived server logs incl. IP address, for security and operations), Neon (PostgreSQL database hosting; infrastructure on AWS, US), Google Cloud Storage (audio/media delivery).
- Transactional e-mail — sign-in links and service notices, via Resend. No marketing e-mail without your separate consent.
- Usage analytics — Vercel Analytics: cookieless, aggregated page/usage metrics with no personal profiles; no advertising or cross-site tracking.
- Product analytics — PostHog (EU-hosted, eu.posthog.com): cookieless usage events — pages viewed, feature clicks, and aggregated interaction data (heatmaps) — to understand how the app is used and improve it. No session recording. No advertising or cross-site tracking. Basis: our legitimate interest in improving the service; you can object at any time via support@soma.ninja.
- Cookies — only what sign-in and session security strictly require; no advertising or analytics cookies.
- Institute enquiries — if you use the “Get in touch” form on our pages for schools, we receive your name, institute, e-mail or phone and message (delivered to our support inbox by Resend) and use them only to reply.
Schools and teachers we contact
We write to language schools, universities and teachers to offer Soma for their learners. We take work contact details (name, role, institution, e-mail) from the institution’s own public website or official listing, and keep them with our correspondence. Links in these e-mails carry a short tag, so we can see which institution opened the page; the tag names the institution, and nothing else about the visitor is linked to it. Basis: our legitimate interest in offering Soma to educators. Reply “no” or write to support@soma.ninja and we won’t contact you again; we then keep only a do-not-contact note. Otherwise we delete these details 12 months after our last exchange.
AI-generated content
Songs and videos on this service are generated using AI and checked by people. We say so with a visible label wherever they play, in captions, and with the platform’s own AI label when we post them on social media.
Where data is processed
Our processors run in the US, the EU and Singapore (Vercel, Google Cloud, Neon, Polar, PostHog (EU), Resend, and our AI service providers); we are established in India. For users in the EU/EEA, transfers rely on EU Standard Contractual Clauses and/or the EU-US Data Privacy Framework where applicable.
Retention
Account and learning data: life of the account, deleted within 30 days of account deletion. Server logs: up to 30 days. Payment/tax records are retained by Polar as merchant of record per applicable law.
Your rights
You can access, correct, export or delete your data — e-mail support@soma.ninja. We aim to respond within 1 day, and in any case within 30 days as required by law. EU/EEA users have the GDPR rights (Art. 15–21: access, rectification, erasure, restriction, portability, objection) and may complain to their local supervisory authority.
No profiling with legal effect; no sale of personal data.
Changes
We’ll post updates here with the date.