Privacy Policy
Last updated: 2 October 2026
Version 2.2 — replaces version 2.1 of 21 September 2026
Intersoul is a private practice. The short version: without an account, what you make stays on your phone and none of it reaches us; with an account, we hold only what the app needs to give your own rites back to you; and none of it is ever sold, used to advertise to you, or handed to anyone for their own purposes.
Who we are
Intersoul is the trading name of Erdem Ergin LLC, a Texas limited liability company. We decide what happens to the personal data described here, which makes us its controller under the EU and UK General Data Protection Regulation (GDPR) and its data controller (veri sorumlusu) under Turkey's Personal Data Protection Law No. 6698 (KVKK). Write to us about anything on this page at info@intersoul.app; our postal address is under Contact.
This policy covers the Intersoul app for iPhone and Android, and this website, intersoul.app.
Without an account, nothing reaches us
Intersoul works fully without an account, and that is a real way to use it rather than a trial. Everything you make in that state — your sealed rites, your captured stars, your streak, your reminder setting — is kept in the app's own storage on your phone. None of it is sent to us or to anyone working for us. If you never create an account, we hold nothing about you at all. You never have to give us anything: the only consequence of having no account is that your practice lives on your phone alone.
- If your phone backs itself up to Apple's iCloud or to Google's backup service, that backup can include the app's storage. The backup belongs to your Apple or Google account, and we never see it.
- To remove what the app keeps on a phone, delete the app. On Android you can also clear its storage in your phone's settings. There is nothing for us to delete, because nothing ever reached us.
What we hold once you have an account
An account exists so your practice survives a lost phone. Creating one, and using the app while signed in, gives us:
- your email address — it is how you sign in, and where your codes are sent;
- your password, which our sign-in service stores only as a one-way hash: nobody can read it back, including us;
- a display name, if you gave one. You can change it or remove it in Profile;
- an account ID, a random string the system gives your account;
- your sealed rites — for each one, the day, the intention you wrote or chose, the weight you released if you chose to release one, and the time it was sealed;
- your captured stars — for each one, the day, the line you wrote, the time you captured it, and which node of which month's figure it lit;
- your streak and the time of your last seal, both worked out from your rites, and whether Shield reminders are on;
- account records kept by the sign-in service: when the account was created, when its address was confirmed, and when it last signed in;
- security records. When the app talks to our server — to sign in, to check a code, to reset a password, or to save and fetch your rites — our providers record technical details of the request: its time, the IP address it came from, the kind of app or browser that sent it, and for sign-in events the account involved. They exist to keep the service secure and to repair it when it breaks, and they are not a copy of your rites or your stars.
That is the whole list. We do not collect your location, your contacts, your photos, your phone's advertising identifier or any other device identifier, or anything about what you do in other apps, and we do not use IP addresses to work out where you are. There is no analytics, advertising or crash-reporting software in the app.
What you write is private. An intention is words you write or a Mote you choose, a line is your own words, and a weight is one of six you may choose to release — you decide what goes into all of them. Nobody at Intersoul reads them as a matter of course: the database is opened only to keep the service working, to act on a request from you, or when the law requires it. Intersoul does not ask about your health, your religion or your beliefs. If something you write reveals them, it is kept like everything else — for you alone, and deleted with your account. If you would rather some of your practice never left your phone, use Intersoul without an account.
What we never do
- No advertising, anywhere in the app.
- No tracking of you across other apps or websites.
- No sale of your data, and no sharing of it with anyone for their own purposes.
- No profiling. We do not analyse your rites or your stars to build a picture of you, and no decision about you is made by automated means.
- No training of any artificial intelligence on what you write.
- No newsletters and no marketing email. The app sends two kinds of email, and only when you ask for them: the code that confirms your address, and the code that resets a forgotten password.
Why we use it, and the legal basis
- To give you your account and keep your practice on our server, so it is there on a new phone — your email, password, name, account ID, rites, stars, streak and reminder setting. This is necessary to provide the service you asked for: our contract with you (GDPR Art. 6(1)(b); KVKK Art. 5(2)(c)).
- To send the two emails — your email address. The same basis.
- To keep the service secure and working — the security and account records. Our legitimate interest in a service that is protected from abuse and can be repaired (GDPR Art. 6(1)(f); KVKK Art. 5(2)(f)).
- To answer you when you write to us — your address and what you tell us. Our contract with you when it is about your account, and otherwise our legitimate interest in answering (GDPR Art. 6(1)(b) and (f); KVKK Art. 5(2)(c) and (f)).
- To meet a legal obligation, or to establish or defend a legal claim, if that ever arises — only what it requires (GDPR Art. 6(1)(c) and (f); KVKK Art. 5(2)(ç) and (e)).
All of it is collected electronically: through the app when you create an account or use it while signed in, and by email when you write to us.
Who handles it for us
A few companies run parts of Intersoul for us. Supabase, Resend and Google handle your data only to provide their service to us, on our instructions, under data processing terms that bind them to keep it confidential and secure, and they may not use it for anything of their own. That is a different thing from sharing your data, which we do not do.
- Supabase (Supabase Pte. Ltd., Singapore) — the database and the sign-in service. Your account data is stored on servers in Frankfurt, Germany.
- Resend (Plus Five Five, Inc., United States) — delivers the two emails. It sends them from Ireland and keeps its records in the United States.
- Google, through Google Workspace — our email inbox. If you write to us, your message is kept there.
- Cloudflare (Cloudflare, Inc., United States) — serves this website; its part is described under This website.
Each of these companies relies on providers of its own — for hosting, storage or support — and publishes the list. What you make in the app is handled by Supabase alone; Resend sees only your address and the message it delivers.
We would give your data to anyone else only if the law required us to — for example, a valid court order — and only as much as it required. If Intersoul were ever taken over by another company, your data would pass to it only under this policy, and we would tell you before it did.
Where it is kept, and transfers abroad
Your account data is stored in the European Union, in Frankfurt. But Supabase is a Singapore company, we and the other companies above are in the United States, and their own providers work in further countries — so your data can also be reached from, or sent to, Singapore, the United States and the other countries where we and they work.
- From the EU or the UK: where such a transfer needs a safeguard under the GDPR, it relies on the European Commission's standard contractual clauses, which are part of Supabase's and Resend's data processing terms, with the UK's addendum to them for the UK. Ask us and we will tell you where to read them.
- From Turkey: using Intersoul with an account means your personal data is transferred abroad — to Germany, where it is stored, and to Singapore, the United States and Ireland, where the companies above operate — for the purposes in the section above.
How long we keep it
- Your account data — for as long as your account exists. When you delete the account, it is removed from our database at once.
- A sign-up you never finished — if you asked for an account and never entered the code, what was started (the address, the name and the hashed password) stays until you finish it or ask us to remove it.
- Security records — the server's request logs are kept for one day on our current plan, and the sign-in service's log of account events — a sign-up, a sign-in, a sign-out, a password change, each with its time, the IP address and the email address used — for one hour. Each signed-in session keeps the IP address and the browser it last connected from until you sign out or delete the account.
- Emails — Resend keeps each email it delivers, with the record of its delivery, for 30 days, and then deletes it; its backups follow within a week.
- Backups — our current plan with Supabase makes no scheduled backups of the database. If we move to one that does, a deleted account will leave the backups as they expire, within 30 days.
- Messages you send us — for as long as we need them to answer you and to show that we did what you asked. Ask us and we will delete them, unless the law requires us to keep them.
Deleting your Intersoul account
In the app, at any time: Profile → Delete my account → Delete everything. Your account, your rites, your stars, your name and your streak are deleted from our database at once, and only then is the app on that phone emptied. It is not a request we process later, and it is never hidden behind a web page or an email. It cannot be undone.
If you no longer have the app: write to info@intersoul.app from the address on the account and ask us to delete it. We will reply to that address to make sure the request is yours, and then delete the account and everything in it within 30 days — usually within the week.
What remains afterwards: nothing of your account itself. The records described above can outlast it until they expire — a day for the request logs, an hour for the sign-in log, 30 days for the emails — and so can any messages you sent us.
Without an account there is nothing on our side to delete. Deleting the app removes what it kept on your phone.
Your rights
Wherever you live, you can ask us to:
- tell you whether we hold data about you, and give you a copy of it;
- correct anything that is wrong — your name you can change yourself, in Profile;
- delete it — though the app will do it faster than we can;
- give it to you in a form you can take elsewhere;
- limit how we use it, or object to our using it where we rely on a legitimate interest — for security, or to answer you.
Write to info@intersoul.app. It costs nothing. We answer without delay and within the time the law sets where you live — at the latest within one month under the GDPR and within 30 days under KVKK. If we need to be sure a request is yours, we will ask you to send it from the address on the account.
In the European Union and the United Kingdom these are your rights under Articles 15 to 22 of the GDPR: access, rectification, erasure, restriction, portability and objection, and the right not to be subject to a decision based solely on automated processing — we make none. You can also complain to the data protection authority where you live or work; in the UK that is the Information Commissioner's Office.
In Turkey, under Article 11 of KVKK you may ask us: whether your personal data is processed; for information about it if it is; for the purpose of the processing and whether the data is used for that purpose; which third parties in Turkey or abroad it is transferred to; to correct it if it is incomplete or wrong; to delete or destroy it under Article 7; to tell those third parties about a correction or deletion; to object to a result against you that comes from analysis made only by automated systems; and to compensate you for damage caused by unlawful processing. Apply by email from the address registered on your account, or in writing to our postal address under Contact. If we turn the request down, do not answer in time, or you find the answer inadequate, you may complain to the Personal Data Protection Board (Kişisel Verileri Koruma Kurulu) within 30 days of our answer, and in any case within 60 days of your application.
In the United States, we do not sell or share personal information as the California and other state privacy laws define those words, and we do not use it for targeted advertising. The rights above are yours too.
Children
Intersoul is not meant for children. You must be at least 13 to use it, and we do not knowingly collect personal data from anyone younger. Below the age of majority where you live, you need a parent or guardian's permission, as the Terms say. If you believe a child under 13 has created an account, write to us and we will delete it.
Security
Everything the app sends to our server travels encrypted, and our database provider encrypts what it stores. Every table is protected by row-level security, which means the database itself refuses to let one account read or write another account's rows — it is not a rule the app is trusted to follow, it is enforced underneath the app. Passwords are stored only as hashes. No system is perfectly secure; if a breach ever put your data at risk, we would tell you, and the authorities, as the law requires.
Notifications
Intersoul sends one notice for each Shield you raise, and nothing else. It is scheduled on your own phone: no server sends it, and no push token for your device exists anywhere. You can turn it off in Profile → Shield reminders, or in your phone's settings, and turning it off asks nobody's permission. If you have an account, whether reminders are on is saved with it.
This website, and the app stores
The pages you are reading are not the app, and they hold nothing about you: no account, no cookies, no analytics, no sign-up. Everything on them — the stylesheet, the images, the fonts — comes from this same address; your browser is not asked to fetch anything from anywhere else. They are served by Cloudflare, which records each request — the IP address and the browser included — as any web host does, and handles those records under its own privacy notice. The app's Privacy and Terms links open these same pages.
You get Intersoul through Apple's App Store or Google Play. They handle your download, your store account and any review you write under their own privacy policies, not this one. They show us counts, such as how many people installed the app, and — if you have allowed your phone to share diagnostic data, with app developers on an iPhone or with Google on Android — crash reports. These describe the app and the kind of device, not who you are or anything you wrote.
Changes to this policy
When this policy changes, the new version is posted here with a new date and version number. If a change affects what we hold or what we do with it, we will say so in the app before it takes effect. Earlier versions are available on request.
Contact
Intersoul
5900 Balcones Dr Ste 4784, Austin, TX 78731-4257, United States
info@intersoul.app