Soundscaperby Kenjin
  • Approach
  • Support areas
  • Methods
  • Science
  • Mobile app
  • Plans
  • Help
Sign inGet early accessOne email, when it opens.
  • Approach
  • Support areas
  • Methods
  • Science
  • Mobile app
  • Plans
  • Help
Sign inGet early accessOne email, when it opens.

Data policy

What runs where, and what we never transmit.

A plain-English account of how Soundscaper handles your data. The formal privacy policy lives at /privacy-policy; this page sets out what runs on our own servers and what we never send to third parties.

Last updated:2026-05-08Status:in force

On this page

  1. 01What runs where
  2. 02Your intake and your journal
  3. 03What we collect, and why
  4. 04What we do not do
  5. 05Controls you have
  6. 06Third parties we rely on
  7. 07Changes to this policy

01

What runs where

Soundscaper's composition pipeline runs on our own servers — not on a third-party AI API. A language model Kenjin self-hosts parses your intake. The safety classifier runs against the same input on our servers. The composition planner assembles the session manifest on our servers. The audio is composed on our servers. Your intake is never sent to OpenAI, Google, or any other third-party AI service.

What we host on our servers: your account state — display name, email, hashed password, subscription / entitlement, push tokens you opt to register — and cloud copies of the master files of your composed soundscapes while you have an active subscription (plus a 90-day grace period after lapse).

What we never hand to any outside company — not to a third-party AI API like OpenAI or Google, not to an analytics or ad vendor: your raw intake text, your journal entry text, your listening behaviour beyond what's needed to deliver downloads, your device health data, your microphone input, your location.

02

Your intake and your journal

The wizard's intake — the words you write or speak about your state — is sent to our own server and parsed there by a language model Kenjin self-hosts. Out of that reading comes a structured profile (intent, length, headphones, listening context, chosen surface, embedding visibility, cue selections), sent as part of the POST /sessions request that queues composition. Your intake is handled only by our own systems, under this Data Policy — it is never sent to a third-party AI service such as OpenAI or Google.

The optional free-text “state narrative” field on the Review step issent to our server as part of the request, and stored alongside the rest of the session profile. Treat that field like any text you put into a service: don't paste anything you wouldn't want stored. Our self-hosted parser handles the load-bearing intake; the narrative field is optional context.

Journal entries (pre-session, post-session, standalone) are stored on our server because they need to be available to you across devices. They're tied to your account, never shared with anyone, and never analysed by us.

The Insights surface includes an opt-in “reflection signals” card. When opted in, only structured fields (entry type, optional 1–10 stress / energy values) are aggregated for your own dashboard. The body text of your entries is never read by the analytics path.

03

What we collect, and why

The minimum needed to run the product.

  • Account fields: email (for sign-in and confirmation), hashed password, optional display name.
  • Subscription state: plan, recording credit count, archive flag, billing identifiers from your payment provider.
  • Recording metadata: session id, length, listening context, support areas, your optional display title, favourite flag, last-played-position seconds.
  • Device tokens: push notification tokens you opt to register.
  • Operational telemetry: backend access logs (request id, IP, status code) for uptime and abuse prevention only — never tied to user behaviour analytics.

04

What we do not do

This list is shorter than most. That's the point.

  • We don't run third-party analytics — Google, Meta, TikTok, Mixpanel, Amplitude, Segment, Plausible, Fathom, or anything similar — on the public site or in the app.
  • We don't sell, share, or trade any of your account data. Not to advertisers. Not to data brokers. Not to clinical research consortia. Not to anyone, ever.
  • We don't train any AI model — ours or anyone else's — on your intake text, journal entries, or composed soundscapes.
  • We don't retain logs of what you listened to, when, or for how long, beyond the last-played-position field that lets the player resume.
  • We don't transmit anything from the app to our server in the background unless you've explicitly opted in to a feature that requires it (push registration, sync across devices, Insights reflection signals).

05

Controls you have

Every account has these controls in the Account hub at /account:

  • Export: request a full export of your account data, journal entries, and recording metadata. Delivered by email.
  • Delete: permanently delete your account, journal entries, server-stored masters, and all account state. Compressed downloads on your devices remain in your possession.
  • Notifications: opt in or out of push and email notifications, per device and per channel.
  • Insights signals: opt in or out of the structured reflection-signals aggregation on the Insights dashboard. Off by default.

06

Third parties we rely on

We use the following processors. Each is in scope for the formal privacy policy. We list them here for transparency.

  • Supabase — account database, authentication, file storage for cloud-hosted master recordings.
  • Stripe — web payment processing for subscriptions and Single Session purchases.
  • Apple App Store / Google Play — mobile in-app purchases per platform policy.
  • RevenueCat — cross-platform subscription state reconciliation between web and mobile.
  • Sentry — anonymised crash reporting on the mobile app. No personal data attached.
  • Apple Push Notification service / Firebase Cloud Messaging — push delivery when you opt in.

We never share data with these providers beyond what each one needs to deliver its specific function.

07

Changes to this policy

We'll post material changes to this page with a new “last updated” date. Substantive changes affecting what we collect or share are notified by email to active accounts at least 14 days before they take effect.

Contact

Questions about this policy? Email [email protected].

Soundscaperby Kenjin

Sound, composed for the hour you're in — to help you sleep, focus, settle, or recover.

  • Science
  • What we won't claim
  • Methods
  • Support areas
  • Safety
  • Data policy
  • Privacy
  • Terms
  • Companion app
  • For carers
  • For clinicians

Soundscaper is wellness-adjacent listening, not clinical treatment. © 2026 Kenjin.