Skip to content
Souvéa
START WITH SOUVÉA

SOUVEA PRIVACY POLICY

Effective: May 7, 2026

This Souvea Privacy Policy ("Privacy Policy") describes how Prifina, Inc. ("Prifina," "Company," "we," "us," or "our") collects, uses, discloses, stores, transfers, and otherwise processes personal information in connection with Souvea and the Services. The Services include the Souvea websites and signup pages, including souvea.io/join, together with our applications, APIs, assistants, chat interfaces, voice interfaces, memory features, tools, content, documentation, and related paid, discounted, sponsored, or free offerings we make available under the Souvea name.

This Privacy Policy is intended to function as a standalone policy and should be read together with the Souvea Terms of Use. If there is a conflict between this Privacy Policy and a separate written agreement signed by Prifina and you or your organization, that signed agreement will control to the extent of the conflict.

Souvea is an evolving service. Features, integrations, providers, and data practices may change over time, and we will update this Privacy Policy when our practices materially change.

We do not sell your personal data. We share personal data with service providers and third-party AI providers only as needed to provide, secure, support, and improve Souvea, or as otherwise described in this Privacy Policy and disclosed in the app.

1. Scope and Acceptance

This Privacy Policy applies to personal information that we collect or process in connection with your access to or use of Souvea, including when you browse our website, join a waitlist, register for early access, subscribe to a paid plan, receive discounted or sponsored access through a partner, interact with our services, contact support, respond to surveys, connect third-party services, or otherwise communicate with us about Souvea.

By accessing or using Souvea, submitting information to us, or signing up for an account or subscription, you acknowledge the practices described in this Privacy Policy. If you do not agree with this Privacy Policy, do not use the Services.

2. Information You Should Not Submit

Unless we expressly approve it in writing, do not submit or upload any information that could create significant harm if lost, disclosed, or misused, including passwords, access tokens, private keys, payment card numbers, bank account details, government identification numbers, classified information, export-controlled information, trade secrets, or personal information relating to anyone under 18 years old. Health, fitness, and biometric information you choose to share through Apple Health, HealthKit, or similar integrations is handled as described in Section 9. If you choose to submit information despite these warnings, you do so at your own risk and subject to the Terms.

3. Categories of Information We Collect

We may collect the following categories of personal information and related data:

(a) Account and contact information, such as your name, email address, phone number if provided, organization, title, login credentials, user identifiers, invitation status, referral status, account preferences, role, and communications preferences.

(b) Subscription, billing, and transaction information, such as selected plan, subscription status, invoices, renewal dates, cancellation status, partner or sponsor code, billing country or postal code, tax information where required, and limited payment or transaction details that we receive from payment processors. We generally do not receive or store full payment card numbers unless we expressly state otherwise.

(c) User Materials and Outputs, such as prompts, messages, memory entries, notes, uploads, files, attachments, images, voice input, transcripts, feedback, survey responses, connected-content inputs, generated outputs, and related metadata.

(d) Technical, device, and usage information, such as IP address, browser type, device identifiers, operating system, language settings, approximate location derived from IP, session activity, timestamps, clicks, referring pages, crash reports, diagnostics, performance logs, app version, request identifiers, feature identifiers, and other information about how you access or use the Services.

(e) Support and communications information, such as email correspondence, support tickets, meeting notes, customer success records, waitlist or onboarding communications, and information you provide when you contact us.

(f) Integration, workspace, and third-party content information, such as metadata or content received from connected services, integrated tools, organization administrators, workspace collaborators, sponsors, or referral partners when those features or programs are enabled. This may include data from Apple Health, Calendar, and other sources you choose to connect.

(g) Security, compliance, and abuse-prevention information, such as authentication records, fraud signals, account-verification information, moderation flags, suspected policy violations, and records created to investigate misuse or protect the Services.

(h) Derived, inferred, aggregated, or de-identified information, such as usage summaries, service metrics, safety signals, quality scores, engagement patterns, and analytics derived from the information described above. Where lawful, we may use and disclose de-identified, aggregated, statistical, or derived information for any business purpose. We do not use Apple Health or HealthKit data, including derived or aggregated health data, for advertising, marketing, selling personal data, or use-based data mining.

4. How We Collect Information

We collect information in several ways:

(a) Directly from you, when you register, subscribe, fill out forms, join a waitlist, enter prompts, send messages, upload content, attach images or files, use voice features, configure roles or modes, connect services, respond to surveys, or contact us.

(b) From connected integrations, only after you choose to connect an integration and grant the required permissions. This may include Apple Health, Calendar, or other supported data sources.

(c) Automatically from your use of the app, through logs, cookies, local storage, pixels, SDKs, analytics tools, app events, generated outputs, diagnostics, error reports, and similar technologies.

(d) From third parties and service providers, such as payment processors, identity or fraud-prevention providers, hosting providers, analytics vendors, customer-support tools, AI processing providers, and other vendors that support the Services.

(e) From your organization, sponsor, employer, partner, referral source, or workspace administrator, if your account is created, funded, discounted, or managed through that party.

5. How We Use Information

We may use personal information to:

(a) create, authenticate, and manage user accounts, verify eligibility, manage seats, and administer paid, free, discounted, sponsored, referral, or partner-based access;

(b) provide chat, voice, AI-generated responses, summaries, and insights, and personalize responses using the context and integrations you choose to provide;

(c) generate proactive insights, including health, fitness, wellness, or personal context insights where applicable, when you have enabled the relevant features and integrations;

(d) store conversation history, memory entries, and user preferences where supported, and manage connected data sources and permissions;

(e) process subscriptions, payments, invoices, renewals, cancellations, refunds where required by law, taxes, and related account administration;

(f) provide customer support and communicate with you about accounts, subscriptions, product updates, policy changes, support requests, pilots, surveys, partner programs, and marketing communications where permitted by law;

(g) maintain security, prevent abuse, debug errors, monitor activity, detect and respond to fraud, misuse, security incidents, and policy violations, and improve reliability;

(h) log, review, test, troubleshoot, debug, quality-check, evaluate, and improve the Services and related internal tools, systems, and safeguards; and

(i) enforce our terms, contracts, and policies, establish or defend legal claims, and comply with law, regulation, legal process, audit requirements, or lawful government requests.

Souvea does not sell personal data.

6. Third-Party AI Processing

Souvea uses third-party artificial intelligence services to provide AI-generated responses, summaries, insights, and voice interactions requested by users.

Because AI processing is core to Souvea's chat, voice, and insight features, those features require processing by third-party AI providers.

Depending on the feature, the model selected, and system routing, Souvea may process user data with one or more of the following providers:

Anthropic models may be accessed directly or through Amazon Web Services (AWS Bedrock). Where AWS Bedrock is used, AWS acts as a subprocessor in that chain. Other model providers may similarly rely on cloud infrastructure subprocessors to host or serve their models.

Souvea discloses the applicable provider or provider set in the app before sending personal data for AI processing.

The current third-party AI providers and backend processors that may receive personal data for AI processing are listed above. If Souvea adds a new AI provider or backend processor that will receive personal data for AI processing, Souvea will disclose that provider in the app before sending personal data to that provider, where required, and will update this Privacy Policy as appropriate.

After you provide permission in the app, the data described in Section 7 may be processed by the third-party AI providers listed above and, where applicable, their underlying infrastructure subprocessors.

Model Selection

Souvea may allow you to select among different AI models or modes. Depending on the model or feature you select, your prompt, conversation context, attachments, voice input, or connected-data context may be processed by one or more of the providers listed above and, where applicable, their underlying infrastructure subprocessors such as Amazon Web Services. The same model name may be served either directly by the model provider or through a cloud subprocessor depending on routing.

7. Data That May Be Sent for AI Processing

When you use Souvea's AI features, the following categories of data may be sent to third-party AI providers or backend processors as needed to generate the response, insight, or voice interaction you request:

Souvea sends only the data reasonably needed to provide the AI feature you request.

8. Voice Features

If you use Souvea's voice features, Souvea may process your voice input, audio stream, transcripts, conversation context, and AI-generated voice responses through third-party AI services, including Google Gemini Live where applicable.

Voice data is used to provide the voice interaction you request. Souvea does not use voice data for advertising, marketing, selling personal data, or unrelated data mining.

9. Apple Health and HealthKit Data

If you choose to connect Apple Health, Souvea may request access to selected HealthKit data types through Apple's permission flow. You control which HealthKit data types you allow Souvea to access, and you can revoke HealthKit access at any time in iOS Settings.

Depending on the permissions you grant and the features you use, Souvea may access or process the following Apple Health data types:

Souvea uses Apple Health data only for user-facing health, fitness, wellness, personal insight, and context features that you request.

Souvea does not send Apple Health or HealthKit data, summaries, or derived facts to third-party AI providers unless you have granted Apple Health permissions and have allowed third-party AI processing in the app.

If you connect Apple Health, selected Apple Health data, summaries, or derived facts may be included in the context that Souvea sends to third-party AI providers for ordinary chat, voice, and insight features, not only for dedicated workout or wellness flows. You can stop this by revoking Apple Health permissions in iOS Settings or by disconnecting Apple Health in Souvea.

Before Apple Health data is first used for third-party AI processing, Souvea presents an in-app disclosure explaining that selected Apple Health data or derived summaries may be sent to the applicable AI provider to generate user-requested responses, voice interactions, or insights.

Souvea does not use Apple Health or HealthKit data for advertising, marketing, selling personal data, or use-based data mining. Souvea does not permit third-party AI providers or service providers to use Apple Health or HealthKit data for advertising, marketing, selling personal data, or use-based data mining.

10. Connected Integrations

Souvea supports optional integrations with third-party services such as Apple Health, Calendar, and other sources we may add over time. Integrations are connected only when you choose to connect them and grant the required permissions.

When an integration is connected, Souvea may receive content, metadata, and derived summaries from that source as needed to provide the feature you use. You can disconnect any integration in Souvea at any time. Revoking permissions in the underlying service (for example, in iOS Settings for Apple Health) will also stop new data from flowing into Souvea.

11. Service Providers and Protection of User Data

We use service providers to operate Souvea, including providers for hosting, authentication, backend infrastructure, storage, analytics, crash reporting, customer support, and AI processing.

We use Supabase as our backend infrastructure provider for authentication, database, storage, and edge compute. Personal data you submit, including chat messages, notes, memory entries, uploads, and connected-data summaries, is stored on this backend so that the Services can function and so that you can access your history. Supabase processes this data on our behalf under its data processing terms.

These providers may process personal data only as needed to provide services to Souvea, comply with law, maintain security, or perform other purposes described in this Privacy Policy.

We require service providers and third-party AI providers that process user data for Souvea to provide the same or equal protection for user data as described in this Privacy Policy and as required by Apple's App Review Guidelines and applicable law.

12. Consent for Third-Party AI Processing

Before Souvea sends personal data to a third-party AI provider for the first time, Souvea presents an in-app disclosure that identifies the applicable provider or provider set, describes the categories of data that may be sent, explains the purpose of the processing, and asks for your explicit permission.

Souvea does not send your personal data to a third-party AI provider for AI processing until you have provided that permission in the app.

Third-party AI processing is required for Souvea's chat, voice, and AI-generated insight features, which form the core of the Services. If you do not allow third-party AI processing, those features may not be available.

For specific integrations such as Apple Health, Souvea may present an additional just-in-time disclosure before data from that integration is first sent for AI processing.

13. Withdrawing Consent and Managing Data

Because third-party AI processing is necessary for Souvea's chat, voice, and AI-generated insight features, Souvea does not currently offer an in-app "turn off AI" toggle. You can withdraw consent for core AI processing by deleting your Souvea account and ending use of the service.

You can also reduce or stop the data available for AI processing by:

You can delete your account in the app at Settings > Privacy > Delete Account. Account deletion follows a grace period during which you can cancel the request, after which your account and associated personal data are removed from our active systems, subject to the retention exceptions described in Section 18.

You may also contact us at privacy@prifina.com to request deletion or ask privacy questions.

14. AI Features, Review, and Service Improvement

Apple Health and HealthKit data, including summaries or derived facts from that data, are not used to train models, build unrelated Company offerings, conduct advertising or marketing, sell personal data, or perform use-based data mining. Apple Health and HealthKit data are used only to provide user-facing health, fitness, wellness, personal insight, and context features requested by the user, and to maintain the security and reliability of those features.

In addition to the third-party AI processing described in Sections 6 through 12, we may process prompts, messages, uploads, memory entries, outputs, and related metadata to operate the Services, generate outputs, maintain conversation history or memory functions, conduct safety and abuse monitoring, perform human review, troubleshoot issues, and evaluate quality.

We may use personal information contained in User Materials and Outputs, as well as related usage, diagnostic, subscription, and support information, to develop, test, evaluate, improve, and enhance our own Services and related internal systems. This may include improving prompts, templates, ranking systems, retrieval systems, analytics, safeguards, classifiers, evaluators, monitoring tools, service-specific models, and other components that support Souvea or related Company offerings.

Unless we separately disclose otherwise and obtain your permission, we do not use your information to train public, general-purpose large language models for third-party use. Where supported by our agreements and provider configurations, we restrict third-party AI providers from using Souvea user data to train their general-purpose models. We do not permit third-party AI providers to use Apple Health or HealthKit data for advertising, marketing, selling personal data, unrelated data mining, or training general-purpose models.

15. How We Disclose Information

In addition to the AI provider and service provider sharing described in Sections 6 and 11, we may disclose personal information:

(a) to our affiliates and to our employees, contractors, consultants, advisors, and agents who need the information to operate, support, secure, analyze, bill for, improve, or administer the Services;

(b) to your organization, sponsor, employer, partner, referral source, or workspace administrator, if your account is created, funded, discounted, or managed through that party, in connection with administering that arrangement;

(c) to authorities, regulators, courts, or other parties when we believe in good faith that disclosure is required or permitted by law, legal process, or government request, or is necessary to protect the rights, property, safety, or security of Prifina, our users, or others;

(d) in connection with a corporate transaction, such as a merger, acquisition, financing, reorganization, or sale of assets, in which personal information may be transferred to or accessed by the parties or their advisors involved in the transaction; and

(e) with your consent or at your direction.

We do not sell your personal data.

16. Cookies and Similar Technologies

We and our vendors may use cookies, local storage, pixels, SDKs, analytics tools, and similar technologies to remember settings, maintain sessions, understand how users navigate the website and Services, measure engagement, troubleshoot issues, prevent abuse, and improve performance. These technologies may collect technical and usage information such as browser type, pages visited, actions taken, session identifiers, approximate location, and timestamps.

Some cookies or similar technologies are necessary for the Services to function. Others help us analyze traffic, understand feature usage, or improve the product. Third-party analytics providers may also set or read their own cookies or identifiers, subject to their own privacy practices. You can often control cookies through your browser or device settings, but disabling them may affect how the Services function.

We do not use analytics cookies, SDKs, or identifiers to track users across apps or websites owned by other companies for targeted advertising or advertising measurement.

17. Partner-, Employer-, and Organization-Sponsored Access

If your access to Souvea is paid for, subsidized, discounted, sponsored, referred, or managed by a partner, employer, investor, community, school, organization, or workspace owner, we may collect and share limited information as reasonably necessary to administer that arrangement. This may include your name, email address, seat status, plan type, eligibility status, account status, limited usage summaries, invoice or billing status, and similar account-administration information.

That sponsoring or administering party may have separate rights and obligations under its agreement with us and may have its own privacy policy or notice governing its handling of your information. We are not responsible for the privacy practices of third parties acting outside the Services.

18. Retention and Deletion

We retain personal information for as long as reasonably necessary for the purposes described in this Privacy Policy, including to provide and improve the Services, administer subscriptions and partner programs, maintain logs and records, conduct evaluations, protect the Services, resolve disputes, enforce agreements, meet legal or tax obligations, and maintain backups or security archives.

Account information is generally retained while your account is active. Conversation history, prompts, generated responses, connected-data summaries, and uploaded content may be retained while your account is active so that Souvea can provide continuity and context, unless you delete the data where deletion is supported.

Chat messages, notes, memory entries, generated responses, connected-data summaries, and uploaded content are stored on our backend (see Section 11) so the Services can show your history and context. Application logs, edge-function logs, diagnostics, and security records are retained for a limited operational period to maintain, secure, debug, and improve the service.

When you request account deletion, your account is first marked for deletion and is retained for a short grace period during which you can cancel the request. After that period, we delete or de-identify personal data associated with your account, except where retention is required or permitted for legal, security, fraud prevention, dispute resolution, backup, or compliance purposes.

Third-party AI providers and infrastructure providers may retain data according to their agreements with us and their role in providing the service. We require providers that process user data for Souvea to protect that data as described in this Privacy Policy.

Because Souvea is an evolving service, retention periods and data-management practices may change over time. We will update this Privacy Policy when our practices materially change. We may retain de-identified, aggregated, or derived information for longer periods, including indefinitely where lawful.

19. International Processing and Transfers

We and our service providers may process and store information in the United States and other jurisdictions where we or they operate. Those jurisdictions may have data protection laws that differ from the laws of your place of residence and may be less protective than the laws in your home jurisdiction.

Depending on the circumstances and applicable law, we may rely on one or more of the following for cross-border processing or transfers: your consent, the necessity of the transfer to provide requested services or perform a contract, our legitimate interests, approved contractual or other transfer mechanisms, or another lawful basis. If you use Souvea from outside the United States, you understand that your information may be transferred to and processed in the United States and other jurisdictions, subject to applicable law.

20. Your Choices and Rights

Subject to applicable law, you may have the right to request access to personal information we hold about you, request correction of inaccurate information, request deletion of certain information, object to or request restriction of certain processing, request portability of certain information in a structured and commonly used format, withdraw consent where processing is based on consent, and opt out of marketing communications.

You may also manage some account settings directly within the Services and can often control cookies through browser or device settings. You may unsubscribe from marketing emails by following the instructions in those messages, although we may still send service, billing, legal, or account-related communications.

We may need to verify your identity before acting on a request. We may deny, limit, or defer requests where permitted by law, where the request is technically infeasible, where it would adversely affect the rights or safety of others, where it would compromise the security or integrity of the Services, or where retention is required for legal, audit, tax, backup, contractual, or abuse-prevention reasons. If your account is managed by an organization, sponsor, or administrator, that party may also have access to or control over information associated with your account.

21. Supplemental Notice for EEA, UK, and Switzerland

If and to the extent that the GDPR, UK GDPR, Swiss data protection law, or similar laws apply to our processing of your personal information, our legal bases for processing generally include: (a) performance of a contract with you or taking steps at your request before entering into a contract; (b) our legitimate interests in operating, securing, supporting, analyzing, and improving Souvea and related services, provided those interests are not overridden by your rights and interests; (c) your consent, where required or where we otherwise request it; (d) compliance with legal obligations; and (e) the establishment, exercise, or defense of legal claims.

Where applicable, you may have the right to access, correct, erase, restrict, object, withdraw consent, or port certain personal information, and the right to lodge a complaint with the supervisory authority in your place of habitual residence, place of work, or place of the alleged infringement.

22. Security

We use administrative, technical, and organizational measures designed to protect personal information. Because no method of transmission, storage, or processing is completely secure, you should not use Souvea to store or process information that could cause significant harm if compromised, exposed, altered, or lost unless we expressly authorize that use in writing.

23. Children

Souvea is not intended for children, and we do not knowingly offer the Services to anyone under 18 years old. If you believe that a child has provided personal information to us in connection with Souvea, please contact us so that we can investigate and take appropriate action.

24. Third-Party Services and Links

Souvea may link to or interoperate with third-party websites, applications, integrations, payment processors, analytics providers, or other services. This Privacy Policy does not apply to personal information collected by third parties except to the extent they act as our service providers. Your use of third-party services is subject to the privacy policies and terms of those third parties.

25. Changes to This Privacy Policy

We may update this Privacy Policy from time to time by posting a revised version, updating the effective or revision information, or otherwise notifying you through the Services, by email, or by another reasonable method. The updated version will become effective when posted unless we state a later effective date. Your continued use of the Services after the updated Privacy Policy becomes effective means that you acknowledge the revised policy.

26. Contact

Paul Jurcys, Chief Privacy Officer
Prifina, Inc.
16193 Lewes, Delaware 19958 USA
privacy@prifina.com
contact@prifina.com