Privacy policy
Last updated: July 23, 2026
1. Who we are and how to contact us
Soulmaper ('we', 'us', 'our') is operated by Mehmet Kubilay Tekin, an individual sole proprietor based in Gaziantep, Türkiye, under the Soulmaper trade name ('Provider'). We are the data controller for personal data processed through the Soulmaper mobile application and website at soulmaper.com (together, the 'Service'). Contact (support, privacy and legal notices): support@soulmaper.com This Privacy Policy ('Policy') explains what personal data we collect, why we collect it, how we use and protect it, with whom we share it, how long we keep it, and the rights available to you. It applies to all users of the Service regardless of where they are located.
2. Personal data we collect
2.1 Account and identity data. When you sign in via Google or Apple OAuth we receive your email address and display name from the OAuth provider. We do not collect or store your password. 2.2 Profile and reading data. To generate personalised readings you may provide: date, time and city of birth; dominant hand. This data is stored in your profile and used each time you request a reading or forecast. 2.3 Palm images (sensitive / biometric category — see Section 3 for full disclosure). 2.4 Subscription and payment data. Web purchases are processed by Lemon Squeezy as Merchant of Record; we receive a subscription status record, your email address, a Lemon Squeezy customer identifier and subscription plan details. Your payment-card data never reaches our servers. 2.5 Usage and analytics data. With your consent we collect anonymised product-analytics events (pages visited, features used, session duration, approximate country) via PostHog. 2.6 Technical and device data. We collect browser type, operating system, device category and IP address for security, rate limiting and fraud prevention. This data is also transmitted to our error-monitoring service (Sentry) when an application error occurs. 2.7 Communications data. If you contact us by email we retain the correspondence to handle your enquiry and for our own records. 2.8 Data we do not collect. We do not collect: precise GPS location; contacts or calendar data; social-network data; financial account information beyond what is described in 2.4.
3. Palm images and biometric / sensitive personal data
3.1 Nature of the data. You may upload a photograph of your palm so that the Service can identify the lines, mounts and features used in palmistry interpretation. Depending on the jurisdiction, palm images may qualify as: • Biometric data under GDPR Article 4(14) and UK GDPR where used to uniquely identify a person (which is not our purpose — see 3.3 below); • Sensitive personal information under the California Consumer Privacy Act as amended (CCPA/CPRA); • Biometric information under U.S. state laws including the Illinois Biometric Information Privacy Act (BIPA), Texas CUBI and Washington MHMDA; • Special-category (özel nitelikli) personal data under KVKK Article 6 (Türkiye). 3.2 Explicit consent. You must affirmatively consent before uploading a palm image. By choosing to upload, you give your free, specific, informed and unambiguous consent to the processing of that image for the sole purpose described in 3.3. You may withdraw consent at any time by closing your account (which permanently deletes all stored palm images) or by contacting support@soulmaper.com to request deletion of a specific image; withdrawal does not affect the lawfulness of prior processing. 3.3 Purpose and strict restriction. Your palm image is used exclusively to generate a palmistry interpretation for you. It is: • NOT used for biometric identification, verification or tracking of your identity; • NOT used to build, train or improve biometric identification systems or AI models; • NOT shared with third parties except as strictly necessary to generate the interpretation (see Section 7); • NOT retained in combination with other identifying data beyond what is necessary; • NOT sold, leased, traded or otherwise profited from, in any form. 3.4 Retention of palm images. Palm images are retained for as long as your account is active and are permanently deleted when you delete your account. We do not currently run automatic time-based deletion; to request deletion of a specific image sooner, contact support@soulmaper.com. 3.5 Your responsibility. Upload only an image of your own hand. Do not upload an image of another person's hand. By uploading you confirm that you are the natural person depicted and that you hold all rights necessary to submit the image.
4. Lawful basis for processing — GDPR and UK GDPR
For users in the European Economic Area (EEA) and United Kingdom we rely on the following lawful bases: Account creation, service delivery, subscription fulfilment → Article 6(1)(b): performance of a contract. Palm images and other special-category data → Articles 6(1)(a) and 9(2)(a): explicit consent. Analytics cookies and marketing communications → Article 6(1)(a): consent. Security, fraud prevention, service reliability → Article 6(1)(f): legitimate interests of the Provider, balanced against your rights. You may object at any time (see Section 13). Retaining tax and accounting records; responding to lawful requests → Article 6(1)(c): legal obligation. Where we rely on consent you may withdraw it at any time without affecting the lawfulness of prior processing.
5. Processing under KVKK (Turkish data protection law)
5.1 Applicable law. Personal data of users in Türkiye is processed in accordance with 6698 sayılı Kişisel Verilerin Korunması Kanunu (KVKK) and the secondary regulations and guidelines of the Kişisel Verileri Koruma Kurumu (KVKK Authority). 5.2 General personal data. Account data, birth data and usage data are processed on the following KVKK Article 5 bases: account and service delivery — necessary for performance of a contract (Art. 5(2)(c)); security and fraud prevention — legitimate interests of the data controller not overriding fundamental rights (Art. 5(2)(f)); analytics — explicit consent (Art. 5(1)); legal compliance — fulfilment of a legal obligation (Art. 5(2)(ç)). 5.3 Sensitive personal data. Palm images constitute özel nitelikli kişisel veri under KVKK Article 6. They are processed solely on the basis of your açık rıza (explicit consent) pursuant to Article 6(2). Consent may be withdrawn at any time as described in Section 3.2. 5.4 VERBİS. Where registration with the Veri Sorumluları Sicil Bilgi Sistemi (VERBİS) is required under applicable thresholds, the Provider will complete registration before processing data as required. 5.5 Disclosure to Turkish authorities. Personal data may be disclosed to Turkish public authorities (tax authorities, courts, law enforcement) where required by applicable law.
6. How we use your data
Service provision: creating and authenticating your account; generating palmistry and astrology readings; delivering daily, weekly and monthly forecasts; recognising your subscription and unlocking premium features. Customer support: responding to your enquiries, support requests and complaints. Payments and compliance: passing your email and subscription data to payment processors; maintaining tax and accounting records as required by law. Security and integrity: detecting fraud, abuse and security threats; enforcing our Terms of Service; protecting other users. Service improvement: analysing aggregated, anonymised usage data to improve features, performance and reliability. Legal compliance: retaining records as required; responding to lawful requests from public authorities. We do NOT use your data for: targeted advertising or ad profiling; selling or renting data to third parties; automated decisions that produce legal or similarly significant effects on you.
7. Service providers and data processors
We share personal data only with the following service providers, strictly limited to what each needs to perform their service. All processors are contractually bound to process data only on our instructions and with appropriate security. Supabase Inc. (USA). Database, authentication, server-side storage. Stores account data, profile data, subscription status and reading results. EU (Ireland) region used. Transfer mechanism: Data Processing Agreement incorporating EU SCCs and UK IDTA. OpenRouter, Inc. (USA). AI model routing for generating interpretations; requests are currently served by Google's Gemini model. Your birth data and palm image are transmitted server-to-server through OpenRouter to the underlying model provider to produce the interpretation. We configure our account to instruct providers not to use submitted data to train their models. Transfer mechanism: vendor DPA / EU SCCs. Lemon Squeezy Ltd. Payment processing and Merchant of Record for web purchases, tax collection, affiliate programme. Operates as an independent controller for its payment and tax obligations. Shared data: email address, subscription plan, transaction data. Google LLC (USA). Google Sign-In (OAuth). Provides authenticated email and display name on sign-in. Google's Privacy Policy governs Google's own processing. Transfer mechanism: SCCs / adequacy decision. Apple Inc. (USA). Apple Sign-In (OAuth). Same scope as Google above. PostHog, Inc. (USA / EU-hosted option). Product analytics, consent-only. Receives anonymised usage events, device category, approximate country, session duration. Transfer mechanism: EU SCCs. Functional Software, Inc. dba Sentry (USA). Error monitoring. Receives error stack traces, device/browser information and your user ID when an application error occurs. Transfer mechanism: EU SCCs. We do not sell, rent or broker your personal data to any third party for their own commercial purposes.
8. International data transfers
Our service providers operate servers in the United States and, in some cases, the EU/EEA. When personal data is transferred outside the EEA or UK we ensure an adequate level of protection by relying on one or more of: • Standard Contractual Clauses (SCCs) approved by the European Commission (Decision 2021/914/EU); • The UK International Data Transfer Addendum (IDTA) issued by the ICO; • An adequacy decision by the European Commission or UK Secretary of State, where applicable. For transfers from Türkiye under KVKK Article 9, we rely on KVKK Board-approved data transfer agreements or, where necessary, your explicit consent. To request a copy of the applicable transfer safeguard contact support@soulmaper.com.
9. Retention periods
We retain personal data only as long as necessary for the purposes described in this Policy, or as required or permitted by law. Account and profile data (email, name, birth details): retained while your account is active. On account closure, personal identifiers are deleted or irreversibly anonymised within 60 days, subject to mandatory retention obligations. Palm images: retained while your account is active; permanently deleted when you delete your account. No automatic time-based deletion is currently applied — contact support@soulmaper.com to request earlier deletion of a specific image. Subscription and payment records: 10 years from the transaction date, as required by Turkish commercial and tax law (VUK Article 253; TTK Article 64) and equivalent international rules. Usage analytics (PostHog): up to 24 months, then automatically deleted or anonymised. Error logs (Sentry): 90 days, then automatically purged. Support correspondence: 2 years from resolution, or longer if required for legal proceedings. After the applicable period, data is securely deleted or irreversibly anonymised using industry-standard methods.
10. Cookies and similar technologies
10.1 What we use. We use cookies and similar client-side storage to operate the Service. 10.2 Strictly necessary (always active). Essential for the Service to function: authentication session cookies (maintaining your signed-in state); and the cookie-preference cookie (remembering your accept/decline choice). These cannot be disabled. 10.3 Analytics cookies (consent required). These collect anonymised information about how you use the Service. They are set only if you click 'Accept' in the cookie banner; declining or ignoring the banner means they are never activated. ph_* (PostHog) — pages visited, features used, session duration, approximate country — up to 1 year. 10.4 Marketing and advertising cookies. We do not use marketing, advertising or retargeting cookies. 10.5 Managing preferences. Change your preference at any time via the cookie settings link in the site footer. You may also delete cookies via your browser; this may affect Service functionality.
11. AI-assisted processing and automated decisions
11.1 How AI is used. Your birth data and palm image are processed by an AI model, accessed via OpenRouter (currently served by Google's Gemini model), to generate palmistry and astrology interpretations, daily forecasts and related content. 11.2 No automated decisions with legal effects. All interpretations are for entertainment and personal reflection only. We do not make automated decisions that produce legal effects or similarly significantly affect you (e.g. creditworthiness, employment, insurance or health decisions). If you believe an automated process has significantly affected you, contact support@soulmaper.com. 11.3 No routine human review. Readings are generated automatically. There is no routine human review of individual outputs unless you contact our support team with a specific concern.
12. Children's privacy
The Service is strictly for users aged 18 and over. We do not knowingly collect personal data from anyone under 18. If we learn that a user is under 18 we will promptly suspend their account and delete their data. If you believe a child under 18 has created an account, notify us at support@soulmaper.com and we will act promptly.
13. Your privacy rights
13.1 GDPR and UK GDPR rights (EEA and UK users). • Access: obtain a copy of your personal data and information about how we process it. • Rectification: request correction of inaccurate or incomplete data. • Erasure: request deletion where there is no overriding reason for continued processing. • Restriction: ask us to halt active processing while a dispute is resolved. • Portability: receive your data in a portable, machine-readable format and transfer it to another provider. • Object: object to processing based on legitimate interests or profiling. • Withdraw consent: where processing is based on consent, withdraw it at any time without affecting prior lawful processing. • Human review: not to be subject to solely automated decisions with significant effects, and to request human review. 13.2 KVKK rights (users in Türkiye). Under KVKK Article 11: learn whether your personal data is processed; obtain information if it is; learn the purpose and whether data is used accordingly; know third parties to whom data is transferred; request rectification; request erasure or destruction; request notification of rectification/erasure to third parties; object to automated results that are to your detriment; claim compensation for damages from unlawful processing. 13.3 How to exercise your rights. Send requests to support@soulmaper.com. We respond within 30 days after verifying your identity (GDPR/UK GDPR: extendable to 3 months for complex requests; KVKK: 30 days). No fee for reasonable requests. 13.4 Right to complain. • Türkiye: Kişisel Verileri Koruma Kurumu — kvkk.gov.tr • EU Member States: supervisory authority in your country of habitual residence • United Kingdom: Information Commissioner's Office — ico.org.uk • Ireland (EU lead DPA): Data Protection Commission — dataprotection.ie
14. Additional rights for California residents (CCPA / CPRA)
14.1 Applicability. The CCPA as amended by the CPRA grants additional rights to California residents. 14.2 Categories collected. Identifiers (email, name); commercial information (subscription history); internet/network activity (usage data); and sensitive personal information including biometric data (palm images — see Section 3). 14.3 Your rights. • Know: request disclosure of categories and specific pieces of personal information collected in the past 12 months. • Delete: request deletion, subject to exceptions. • Correct: request correction of inaccurate personal information. • Opt-out of sale or sharing: we do not sell personal information or share it for cross-context behavioural advertising. • Limit sensitive PI use: direct us to limit use of sensitive personal information (including palm images) to what is necessary to provide the Service — which is already our default. • Non-discrimination: we will not discriminate against you for exercising any CCPA/CPRA right. 14.4 How to submit a request. Email support@soulmaper.com, subject: 'CCPA Rights Request'. Response within 45 days (extendable by 45 days with notice). We verify identity before acting. 14.5 Shine the Light. We do not share personal information with third parties for their own direct marketing.
15. Additional rights for Brazilian residents (LGPD)
Users in Brazil are protected by the Lei Geral de Proteção de Dados Pessoais (LGPD — Law No. 13,709/2018). You have the rights under LGPD Article 18: access; correction; anonymisation, blocking or deletion of unnecessary or non-compliant data; portability; information about entities with which data is shared; information about withdrawing consent and consequences; withdrawal of consent; review of automated decisions; and the right not to be subject to discriminatory decisions. Submit LGPD requests to support@soulmaper.com. Complaints may be directed to the Autoridade Nacional de Proteção de Dados (ANPD) — gov.br/anpd.
16. Security
16.1 Measures. We apply technical and organisational security measures proportionate to the risks, including: TLS 1.2+ encryption for all data in transit; encryption at rest for stored personal data; row-level security (RLS) ensuring each user can only access their own data; access controls based on the principle of least privilege; regular security reviews. 16.2 Breach notification. In the event of a personal data breach likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours where feasible, and notify affected users without undue delay where a high risk to you is likely. 16.3 Your responsibility. You are responsible for the security of your OAuth provider credentials (Google or Apple account). Enable two-factor authentication on your provider account for maximum protection. 16.4 Limitation of liability. No method of transmission or storage is 100% secure, and we cannot guarantee absolute security. Except where caused by our gross negligence or wilful misconduct, we are not liable for unauthorised access, loss or disclosure of data that occurs despite the reasonable measures described in clause 16.1. Any liability arising from the processing of your personal data is subject to the limitations and cap set out in the Terms of Service, clause 12, which apply equally to claims made under this Policy.
17. Changes to this policy
We may update this Policy to reflect changes in our practices, technologies, legal requirements or business operations. When we make material changes — particularly to how we process sensitive personal data — we will notify you by email and/or in-app notification at least 30 days before the changes take effect. The 'Last updated' date at the top of this page reflects the most recent revision. Your continued use of the Service after the effective date constitutes acceptance of the revised Policy.
18. Contact
All enquiries — general support, privacy and data-subject rights, legal notices: Email: support@soulmaper.com We acknowledge requests within 5 business days and aim to resolve them within the statutory deadline for your jurisdiction.