Soulsync

Legal

Privacy policy.

This policy describes, pursuant to Regulation (EU) 2016/679 of 27 April 2016 (GDPR) and Law No. 78-17 of 6 January 1978 as amended, the conditions under which Boost Studio SAS collects, uses and protects the personal data of its users.

Translation provided for information only. Only the French version is legally binding.

Updated on 27 May 2026
Version 2.0
01

Our commitment

At Soulsync, we believe privacy is neither an option nor a marketing argument: it is the very condition of a trustworthy dating service. Our commitments are as follows, without exception or reservation:

  • No data resale. Your information is neither sold, rented, nor made available to third parties for commercial or advertising purposes.
  • No targeted advertising. Soulsync displays no ads. Our business model relies exclusively on Soulsync+ subscriptions.
  • No model training on your conversations. Your exchanges are never used to train artificial intelligence models, whether internal or external.
  • Encrypted transit (TLS 1.3) between your device and our servers, and encryption at rest for sensitive data on the database side.
  • Fully European hosting; no personal data is processed or stored outside the European Union.

Note

This policy is written in French, the contractual language. In the event of a later translation, the French version shall prevail over any other version in case of divergent interpretation.
02

Data controller

The data controller within the meaning of Article 4-7 of the GDPR is:

Boost Studio SAS, a simplified joint-stock company with capital of €100, whose registered office is in Marseille, registered with the Marseille Trade and Companies Register under number 914 016 837, which publishes and operates the Soulsync brand.

In accordance with Article 37 of the GDPR, Boost Studio SAS has appointed a Data Protection Officer (DPO), reachable at dpo@get-soulsync.com, or by post at the registered office address, for the attention of the Data Protection Officer.

03

Data collected

We collect only the data strictly necessary to operate the Service, in accordance with the minimization principle set out in Article 5-1-c of the GDPR.

Identification data: first name, email address, date of birth (verification of the 18-year threshold), city of residence, profile photographs that you freely choose to publish.

Data relating to your emotional profile: answers to the registration questionnaire (five conversational questions), value vectors calculated from your answers, steps completed in the eleven-step journey.

Communication data: messages exchanged with your matches, voice notes, photographs sent in conversation. This content is stored encrypted and is accessed by our teams only in the strict context of a report or a judicial requisition.

Personal journal data: your answers to daily prompts, daily aura, frequency of use. This data is never shared with other users.

Technical data: IP address (anonymized within 24 hours), device model, operating system, app version, technical diagnostic data strictly necessary for fraud prevention and Service stability.

Payment data: in the case of a Soulsync+ subscription, banking information is collected and processed exclusively by our provider Stripe Payments Europe Ltd. Soulsync never has access to your full banking details.

04

Purposes and legal bases of processing

In accordance with Article 6 of the GDPR, each of our processing operations rests on an identified legal basis:

  • Performance of the contract (Article 6-1-b GDPR): provision of the Service, calculation of affinities, matching, subscription management.
  • Consent (Article 6-1-a GDPR): push notifications, approximate geolocation, marketing communications. Withdrawable at any time from the settings.
  • Legal obligation (Article 6-1-c GDPR): retention of connection data for one year (Article L. 34-1 of the Postal and Electronic Communications Code), moderation of unlawful content.
  • Legitimate interest (Article 6-1-f GDPR): fraud prevention, Service security, usability improvement, strictly excluding any advertising profiling.
05

Retention period

Data is kept for the strict period necessary for the aforementioned purposes, plus the legal limitation periods:

  • Active account data: for the entire duration of use of the Service.
  • Account inactive for 24 months: automatic deletion after notification sent to the user thirty days beforehand.
  • Account deletion on request: permanent erasure within thirty days, except for data whose retention is required by law.
  • Connection data (logs): one year from the connection, in accordance with Article L. 34-1 III of the Postal and Electronic Communications Code.
  • Accounting and tax documents: ten years from the close of the financial year (Article L. 123-22 of the Commercial Code).
06

Recipients and processors

Your data is accessible only to authorized Boost Studio SAS staff, strictly within the scope of their duties, and to a limited number of carefully selected processors, bound by an agreement compliant with Article 28 of the GDPR:

  • Supabase Pte. Ltd.: database hosting, datacenters located in the European Union.
  • Vercel Inc.: Edge distribution in Europe.
  • Stripe Payments Europe Ltd.: payment processing (Dublin, Ireland).
  • OpenAI Ireland Ltd.: Cupidon's conversational intelligence layer, operated in the European zone, without training on user content (zero-retention API agreement).
  • Sentry Inc.: anonymized technical monitoring, European zone.
  • Administrative and judicial authorities: on legal requisition only and strictly within the legal framework.
07

Transfers outside the European Union

No personal data of our users is transferred outside the European Union. All of our hosting infrastructure and processing chains are located in datacenters within the territory of the Union.

Should such a transfer become necessary in the future, it would be governed by the Standard Contractual Clauses adopted by the European Commission on 4 June 2021, supplemented where appropriate by appropriate additional measures, and the user would be informed beforehand.

08

Security and confidentiality

In accordance with Article 32 of the GDPR, Boost Studio SAS implements the appropriate technical and organizational measures to ensure a level of security appropriate to the risk:

  • TLS 1.3 for all communications between the app and our servers.
  • Encryption at rest of the database and object storage, under key management by our hosting provider.
  • Fully European hosting, infrastructure operated by our providers Supabase and Vercel.
  • Enhanced authentication via third-party identity providers (Apple, Google) or an encrypted magic link.
  • Breach notification to the CNIL within 72 hours and to affected users without undue delay (Articles 33 and 34 GDPR).
  • Continuous review of our practices by our Data Protection Officer.
09

Your rights

In accordance with Articles 15 to 22 of the GDPR, you have the following rights over your data:

  • Right of access to the data concerning you (Article 15).
  • Right to rectification of inaccurate or incomplete data (Article 16).
  • Right to erasure (the "right to be forgotten") in the cases provided for in Article 17.
  • Right to restriction of processing (Article 18).
  • Right to portability in a structured, commonly used and machine-readable format (Article 20).
  • Right to object to processing, in particular for commercial prospecting purposes (Article 21).
  • Right to withdraw your consent at any time, when processing is based on it (Article 7-3).
  • Right to set post-mortem directives regarding the fate of your data after your death (Article 85 of the Law of 6 January 1978 as amended).

These rights are exercised at dpo@get-soulsync.com, accompanied by proof of identity in the event of reasonable doubt about the person requesting the exercise of the right. We respond within a maximum of one month, which may be extended by two months in the event of a complex request (Article 12-3 GDPR).

10

Cookies and trackers

The soulsync.app site uses a strictly limited number of functional cookies essential to the proper functioning of the Service (language preference, session state). No advertising cookies, no third-party audience-measurement cookies, no social pixels are placed.

In accordance with Article 82 of the French Data Protection Act, cookies that are not strictly necessary are only placed after obtaining your prior, free, informed and specific consent. You can change your preferences at any time from the site footer.

11

Protection of minors

The Service is strictly reserved for adults (18 years of age). An age-verification mechanism is implemented at registration. In accordance with Article 8 of the GDPR and Article 45 of the French Data Protection Act, no processing is carried out on the data of a minor.

If you believe a minor has registered by circumventing our controls, please inform us without delay at protection@get-soulsync.com. We will immediately delete the account and all associated data.

12

Changes to this policy

This policy may change to reflect legislative or technical developments. Any substantial change will be notified to you by email and in-app message at least thirty days before it takes effect. All previous versions remain available on simple request at legal@get-soulsync.com.

13

Complaint to the CNIL

If, after contacting us, you believe your rights are not respected, you have the right to lodge a complaint with the French Data Protection Authority (CNIL):

3 place de Fontenoy, TSA 80715, 75334 Paris Cedex 07 — Phone: 01 53 73 22 22 — www.cnil.fr.

You may also refer the matter to the supervisory authority of your member state of residence, in accordance with Article 77 of the GDPR.

Coming soon on iPhone and Android

The app you delete together.

Four people chosen for you each day. Time to truly meet. Download Soulsync, let Cupidon do the rest.

Download on the App StoreGet it on Google Play
L'application Soulsync