Privacy Policy

We value your privacy and are committed to transparently explaining how we use, and protect your information.

Alchemy Soul Privacy Policy

Effective date: 9 September 2026
Last updated: 9 September 2026

This Privacy Policy explains how Alchemy Soul Technologies Limited (“Alchemy”, “we”, “us”, or “our”) collects, uses, shares, retains, and protects personal data when you use the Alchemy Soul mobile application, our websites, and related services (together, the “Services”).

We have written this Policy to cover ordinary account and app data, private journal and reflection data, nutrition and wellness information, camera-based heart-rate readings, optional Apple HealthKit and Google Health Connect integrations, analytics and attribution technologies, subscriptions, and AI-assisted features such as Aerin.

  1. Who is responsible for your data

For the purposes of the UK General Data Protection Regulation (“UK GDPR”) and applicable data-protection law, the data controller is:

Alchemy Soul Technologies Limited
Company number: 16500393
167–169 Great Portland Street, 5th Floor
London W1W 5PF
United Kingdom
Email: connect@alchemysoultech.com

You can contact us at that address or email for privacy questions, requests, or complaints.

  1. Who this Policy applies to

This Policy applies to people who:

•  create or use an Alchemy Soul account;

•    use our mobile app or websites;

•    use free or paid features;

•    connect supported health-data services;

•    communicate with support or subscribe to permitted marketing; or

•    otherwise interact with the Services.

The Services are intended only for users aged 18 or over.

  1. Personal data we collect

The data we collect depends on the features you use, the permissions you grant, and the information you choose to provide.

3.1 Account and identity data

This may include:

•     name;

•     email address;

•     account identifiers;

•     authentication information and tokens;

•     age or date-of-birth information where collected to enforce age eligibility;

•     country, language, timezone, or region settings; and

•     communication and consent preferences.

We do not need or receive your full payment-card number when payment is processed by Apple, Google, or another independent payment provider.

3.2 Wellness, check-in, and personalisation data

You may choose to provide information about your wellbeing, habits, goals, routines, sleep, activity, nutrition, mood, stress, reflections, preferences, and other lifestyle factors.

Depending on the content, some of this information may constitute or reveal health data or other special-category personal data under UK/EU data-protection law.

We use this information to provide the user-facing wellness functions you request, such as check-ins, recommendations, summaries, trends, reports, and relevant practices.

3.3 Journal entries, reflections, and conversational inputs

If you use journaling, reflection, Aerin, or similar features, we process the text or other content you submit, together with relevant context needed to provide the requested function.

Private journal content is not treated as advertising content and is not sold to data brokers.

Please remember that free-text fields can contain highly sensitive information. Avoid including another person’s confidential or sensitive information unless you have a lawful and appropriate reason to do so.

3.4 Nutrition and meal-planning data

If you use Alchemy Kitchen or related nutrition features, we may process:

•     age, height, weight, sex or other inputs used by the selected calculation;

•     activity level and goals;

•     dietary preferences and restrictions;

•     selected plan type or calorie/protein targets;

•     recipes, meals, substitutions, grocery selections, and plan history; and

•     feedback or interactions with meal-planning features.

Some of these inputs may constitute or reveal health data. We process them only for the purposes described in this Policy and the app.

3.5 Apple HealthKit and Google Health Connect data

If you voluntarily connect a supported health-data platform, the app requests access only to the data types needed for user-facing Alchemy features. At present this means:

•     heart rate and resting heart rate.

We do not receive all information held in HealthKit or Health Connect. Access is limited to the data types requested by the app and the permissions you grant. If we add further data types in future, we will update this Policy and the relevant permission request before requesting them.

Health-platform access is optional. You can refuse or revoke permissions through Apple Health / iOS settings or Health Connect / Android settings, although this may reduce or disable features that depend on that data.

3.6 Camera-based heart-rate readings

If you do not use a connected health platform, or choose to take a reading manually, the app can estimate your heart rate using your phone’s camera and flash (photoplethysmography). Camera frames are processed on your device to derive the reading and are not stored, uploaded, or used for any other purpose. Only the derived value (for example, a resting heart-rate figure and the time of the reading) is kept in your Alchemy account and used for the same wellness functions as connected health data.

Camera-based readings are wellness indicators, not medical measurements, and can be affected by lighting, movement, skin tone, device hardware, and other factors. The camera permission is optional and can be revoked in your device settings.

3.7 Device, technical, and log data

We may collect:

•     device type, model, operating system, app version, language, and settings;

•     IP address and approximate region derived from network information;

•     app instance, installation, advertising, or other device identifiers where permitted

•     network, diagnostic, security, and authentication logs;

•     crash reports and technical error information;

•     timestamps, session information, and feature events; and

•     information needed to detect abuse, fraud, or technical problems.

We do not describe all analytics data as anonymous. Some analytics or attribution identifiers can constitute personal data even when they do not directly contain your name.

3.8 Usage and analytics data

We may record how users interact with the Services, for example:

•     feature opens and completions;

•     recommendation shown, meditation start or completion, and report views;

•     screen or feature engagement;

•     subscription or paywall events;

•     app performance and crashes; and

•     aggregate product usage patterns.

Where required by law or platform rules, non-essential analytics, attribution, or advertising technologies are used only after the required consent or device permission.

We aim to minimise event payloads and not send private journal text or HealthKit, Health Connect, or camera-based heart-rate data to advertising platforms.

3.9 Subscription and transaction data

We may receive limited purchase information from Apple, Google, or subscription infrastructure providers, such as:

•     subscription product and status;

•     purchase or renewal date;

•    transaction or receipt identifier;

•     trial or entitlement status; and

•     country or storefront information.

Payment-card details are generally processed by the relevant store or payment provider rather than Alchemy.

3.10 Communications and support data

If you contact us, we may process your contact details, message contents, attachments, support history, and information reasonably needed to investigate or resolve your request.

3.11 Website, cookie, and similar technology data

Our websites may use cookies, local storage, pixels, or similar technologies for essential operation and, where permitted, analytics or marketing.

Where consent is legally required for non-essential cookies or similar tracking, we will request it through an appropriate consent mechanism. You can also use browser or device controls, although those controls may not replace a legally required in-service consent choice.

  1. Where personal data comes from

We may receive personal data:

•     directly from you;

•    from your use of the Services;

•    from Apple HealthKit or Google Health Connect when you authorise access;

•    from Apple, Google, or another platform in connection with subscriptions, app distribution, or device functionality;

•  from analytics, crash-reporting, attribution, or security providers acting on our behalf or under their own applicable terms; and

•   from other third parties where you direct or authorise an integration.

Where we obtain personal data from another source, we process it only for compatible and disclosed purposes and subject to applicable law.

  1. Why we use personal data and our legal bases

The legal basis depends on the data and purpose. More than one basis may apply to different processing activities.

5.1 Providing the account and core Services

Purpose: create and administer your account; deliver features; save settings; provide requested content; process entitlements; respond to support requests.

UK/EU legal basis: performance of a contract, or steps taken at your request before entering a contract.

5.2 Wellness personalisation and recommendations

Purpose: use your check-ins, goals, preferences, and relevant history to personalise the app, produce summaries, and recommend practices.

UK/EU legal basis for ordinary personal data: performance of our contract with you and, where appropriate, our legitimate interests in providing and improving a personalised consumer service.

If this processing intentionally involves health data or another special category of personal data, we also require a valid Article 9 condition. Where appropriate for Alchemy’s consumer wellness features, we rely on explicit consent under Article 9(2)(a).

You can withdraw consent for future special-category processing at any time. Withdrawal does not make earlier lawful processing unlawful, but it may mean that features requiring that data no longer work.

5.3 HealthKit and Health Connect

Purpose: import only the data you authorise and use it for the connected, user-facing wellness functions described to you.

UK/EU legal basis: consent under Article 6(1)(a) and, for health data, explicit consent under Article 9(2)(a), where those provisions apply.

Platform permission and data-protection consent are related but not identical. We provide appropriate in-app disclosures and permission controls and keep records of consent where required.

5.4 Nutrition and meal planning

Purpose: calculate and provide meal plans, nutrition estimates, recipe selections, grocery outputs, and associated personalisation.

UK/EU legal basis: performance of the service you request. Where inputs constitute special-category health data, we additionally rely on explicit consent where required.

5.5 Analytics, reliability, and product improvement

Purpose: understand feature use, diagnose errors, improve performance, test product changes, and maintain service quality.

UK/EU legal basis: our legitimate interests in operating and improving the Services for essential or low-impact analytics, balanced against user rights; and consent where law or platform rules require it for non-essential tracking or device identifiers.

We do not rely on legitimate interests to override a requirement for consent under applicable ePrivacy, platform, or tracking rules.

5.6 Security, fraud prevention, and legal protection

Purpose: protect accounts and systems, detect abuse, investigate incidents, maintain logs, enforce Terms, prevent fraud, and establish or defend legal claims.

UK/EU legal basis: our legitimate interests in security and legal protection, and compliance with legal obligations where applicable. If special-category data is strictly necessary for legal claims, Article 9(2)(f) may apply.

5.7 Transactions, accounting, and compliance

Purpose: administer subscriptions, maintain transaction records, comply with tax, accounting, regulatory, and legal requirements.

UK/EU legal basis: performance of contract and compliance with legal obligations.

5.8 Marketing

Purpose: send product news, educational material, offers, or promotional communications where permitted.

UK/EU legal basis: consent where required, or another lawful basis permitted for a particular communication under applicable direct-marketing law.

You can opt out of marketing at any time. Opting out does not stop essential service communications.

5.9 Advertising attribution and campaign measurement

Purpose: measure whether marketing campaigns lead to installs, trials, or purchases and improve acquisition reporting.

UK/EU legal basis: consent or device permission where required, and otherwise a lawful basis permitted by applicable law.

We do not use HealthKit or Health Connect data for advertising, cross-context behavioural advertising, credit, insurance, employment, data-broker activity, or unrelated commercial profiling.

  1. Special-category data and explicit consent

Wellness apps can process information that directly constitutes health data or that reveals health, religion, philosophical beliefs, sex life, sexual orientation, or other special-category information, particularly through free-text journals.

We do not infer explicit consent merely because you typed something into a field.

Where we intentionally use health data or another special category for a feature that requires an Article 9 condition, we will identify an appropriate condition. For optional consumer wellness personalisation and connected health data, this will generally be explicit consent where applicable.

Consent requests should be specific, separate from unrelated consents, affirmative, and capable of withdrawal.

Withdrawal may stop future use of the relevant data for the consent-based feature but does not automatically require deletion where another legal basis requires limited retention, for example to resolve a legal claim.

  1. Important HealthKit and Health Connect commitments

HealthKit and Health Connect information is especially sensitive. We apply the following restrictions to data obtained through those platforms:

•     we use it only for user-facing health, fitness, or wellness functions that are clearly described to you;

•     we request only data types reasonably necessary for those functions;

•      we do not sell HealthKit or Health Connect data;

•      we do not use HealthKit or Health Connect data to serve advertising;

•      we do not transfer it to advertising platforms, data brokers, information resellers, credit providers, insurers, or employers for their independent purposes;

•        we do not share it with a third party unless the sharing is permitted by the relevant platform rules, legally permitted, and supported by any required explicit user permission;

•         we do not use it for unrelated commercial exploitation; and

•         access can be revoked using the relevant Apple or Google health-data controls.

Revoking platform permission stops future access by Alchemy but may not automatically delete information that was previously imported into Alchemy’s systems. You may use available account controls or contact us to request deletion, subject to lawful retention requirements.

Deleting data from Alchemy does not necessarily delete the original record from Apple HealthKit, Google Health Connect, a wearable, or another source. Those systems have their own deletion controls.

  1. Automated systems, profiling, and AI

Alchemy uses rule-based systems and may use AI-assisted technology to provide features such as conversational support, summaries, reflections, navigation assistance, and personalisation.

Aerin is an automated or AI-assisted feature, not a human. Where EU AI Act or other transparency rules apply, we provide a clear disclosure at or before the relevant interaction.

Personalisation may amount to profiling under data-protection law because the system evaluates preferences, behaviour, or wellness inputs to decide which content is more relevant.

Alchemy does not use automated decision-making to make decisions that produce legal or similarly significant effects on users, such as decisions about employment, insurance, credit, healthcare entitlement, or access to essential services.

If this changes, we will update this Policy and provide any additional information, safeguards, or human-review rights required by law before implementing the change.

AI service providers

Some AI-assisted functions, such as Aerin and periodic reflective summaries, require relevant user inputs and context to be processed by a contracted technology provider. At present this processing is carried out using Anthropic’s Claude models accessed through Google Cloud (Vertex AI) under commercial terms.

We limit the data sent to what is reasonably needed for the function, use contractual and security measures appropriate to the service, and assess international-transfer requirements where applicable. Under our commercial terms the provider does not use your inputs or outputs to train its models.

We do not send HealthKit, Health Connect, or camera-based heart-rate data to an AI provider for advertising or unrelated model training.

  1. Analytics, crash reporting, and attribution providers

Depending on app version, platform, consent status, and configuration, Alchemy may use services such as:

•     Google/Firebase analytics and Crashlytics for analytics, diagnostics, and crash reporting;

•     Mixpanel for product analytics;

•     Meta technologies for permitted campaign measurement or marketing integration; and

•     AppsFlyer for app attribution and campaign measurement where enabled.

These services may receive limited device, app, event, technical, or identifier information depending on configuration and user permissions.

They must not be used as a route to send private journal text or HealthKit, Health Connect, or camera-based heart-rate data for advertising.

We may replace or add vendors as our technology changes. Material changes to how personal data is used or shared will be reflected in this Policy and, where required, additional consent will be obtained.

  1. Payments and subscriptions

Apple, Google, and other payment or subscription providers may process payment and transaction data as independent controllers or processors under their own privacy terms.

Alchemy generally receives only the information needed to confirm entitlement, manage access, troubleshoot purchases, and maintain appropriate financial records.

If we introduce a subscription-management infrastructure provider, it may process receipt and entitlement information on our behalf.

  1. Who we share personal data with

We may disclose personal data to the following categories of recipients only as reasonably necessary for the stated purpose:

Service providers and processors

Providers supporting:

•     cloud hosting, databases, authentication, and storage;

•     analytics, crash reporting, and product measurement;

•     app attribution and permitted marketing measurement;

•     AI or automated feature processing;

•    customer support and communications;

•     subscription and entitlement management;

•     security, fraud prevention, and monitoring;

•     website hosting and operational tools; and

•      professional services such as legal, accounting, audit, or compliance support.

Processors are required to handle personal data under appropriate contractual obligations.

Apple, Google, and connected platforms

We may exchange limited data with Apple, Google, or another platform where necessary for app distribution, purchases, sign-in, device features, or health integrations you choose to connect.

Legal and safety disclosures

We may disclose personal data where reasonably necessary to:

•             comply with law, regulation, court order, or lawful authority request;

•             establish, exercise, or defend legal claims;

•             investigate fraud, abuse, security incidents, or unlawful activity; or

•             protect the rights, safety, and security of users, Alchemy, or others where legally permitted.

Corporate transactions

If Alchemy is involved in a merger, financing, reorganisation, acquisition, sale of assets, insolvency process, or similar transaction, personal data may be disclosed under confidentiality and data-protection safeguards.

Any successor that becomes controller of your data will be required to process it in accordance with applicable law and provide any required notice.

12. What we do not do

Subject to the specific qualifications elsewhere in this Policy:

•             we do not sell private journal entries;

•             we do not sell HealthKit or Health Connect data;

•             we do not use HealthKit or Health Connect data for advertising;

•             we do not provide health-platform data to data brokers, insurers, employers, or credit providers for their independent decision-making;

•             we do not knowingly provide Services to children under 18; and

•             we do not use automated systems to make legal or similarly significant decisions about you.

We also do not describe data as “anonymous” merely because it lacks your name. Pseudonymous identifiers can still be personal data and are treated accordingly.

13. International data transfers

Alchemy is established in the United Kingdom, but some service providers or technical infrastructure may process personal data in other countries.

Where UK GDPR or EU GDPR restricted-transfer rules apply, we use an appropriate lawful transfer mechanism, which may include:

•             a UK or EU adequacy regulation/decision;

•             the UK International Data Transfer Agreement or UK Addendum to EU Standard Contractual Clauses;

•             EU Standard Contractual Clauses;

•             another legally approved transfer mechanism; or

•             a permitted statutory derogation used only where appropriate.

Where required, we assess transfer risks and implement supplementary technical, contractual, or organisational measures.

You can contact us for further information about safeguards relevant to a particular transfer.

14. Data retention

We keep personal data only for as long as reasonably necessary for the purpose for which it was collected, including to provide the Services, comply with law, resolve disputes, maintain security, and enforce agreements.

Retention periods vary by data type.

Account and profile data

Generally retained while your account is active and for a limited period after closure where needed for security, support, legal, or operational purposes.

Journal, reflection, and wellness data

Generally retained while you choose to keep it in the Services. When you delete content or your account, we delete or de-identify the relevant live-service data in accordance with our deletion process, subject to technical backup cycles and any lawful retention requirement.

Connected health data

Retained only as long as needed for the connected feature, your account, or another disclosed lawful purpose. You can revoke future platform access separately from requesting deletion of copies already imported into Alchemy.

Analytics and diagnostics

Retained according to configured product and provider retention periods, which we periodically review and aim to keep proportionate to the analytics purpose.

Support and security records

Retained for as long as reasonably necessary to resolve the request, investigate an incident, maintain auditability, or protect legal rights.

Financial and transaction records

Retained for the periods required by applicable tax, accounting, corporate, or anti-fraud law.

Backups

Deleted information may remain temporarily in encrypted or access-restricted backups until those backups are overwritten or expire under normal backup cycles. Backup copies are not restored for ordinary product use except where needed for disaster recovery, security, or legal reasons.

We may retain de-identified or aggregated information that no longer identifies an individual.

15. Account and data deletion

You may request deletion through available in-app tools or by contacting connect@alchemysoultech.com.

We may need to verify your identity before completing a request.

Deletion of your Alchemy account:

•             does not automatically cancel an Apple App Store or Google Play subscription;

•             does not necessarily delete information retained independently by Apple, Google, HealthKit, Health Connect, a wearable provider, or another third party; and

•             may not delete limited records we must retain to comply with law, prevent fraud, protect security, or establish or defend legal claims.

Where law gives you a right to erasure, we will apply it subject to the statutory exceptions.

16. Security

We use technical and organisational measures designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access.

Depending on the system, measures may include:

•             encrypted transmission using modern transport security;

•             encryption at rest where supported and appropriate;

•             authentication and access controls;

•             role-appropriate restriction of administrative access;

•             logging, monitoring, patching, and technical safeguards;

•             vendor and processor controls;

•             backup and recovery measures; and

•             data-minimisation and environment-separation practices where appropriate.

No online service can guarantee absolute security. You should use a strong password, protect your device and account, and tell us promptly if you suspect unauthorised access.

We do not claim that all Alchemy data is end-to-end encrypted unless a specific feature expressly states that it is.

  1. Personal-data breaches

If a personal-data breach occurs, we will investigate and take appropriate containment and remediation steps.

Where UK GDPR requires notification to the Information Commissioner’s Office, we will notify it without undue delay and, where feasible, within 72 hours after becoming aware of the breach.

Where applicable law requires us to notify affected individuals, including because a breach is likely to result in a high risk to their rights and freedoms, we will do so without undue delay and provide information required by law.

Not every security incident legally requires user notification.

  1. Your UK and EEA data-protection rights

Depending on the circumstances, you may have the right to:

•     access personal data we hold about you;

•    rectify inaccurate or incomplete data;

•    erase personal data;

•    restrict certain processing;

•    object to processing based on legitimate interests;

•    data portability for certain data processed by automated means on the basis of consent or contract;

•     withdraw consent at any time where processing is based on consent;

•     object to direct marketing at any time;

•     receive information and safeguards relating to certain international transfers; and

•     not be subject to a solely automated decision producing legal or similarly significant effects except where law permits it with appropriate safeguards.

These rights are not absolute. We may need to verify your identity and may refuse or limit a request where the law permits.

We normally respond within the period required by applicable law. Under UK/EU GDPR this is generally one month, subject to lawful extensions for complex or multiple requests.

To exercise a right, email connect@alchemysoultech.com with “Data Protection Request” in the subject line.

  1. Complaints and supervisory authorities

Please contact us first if you have a privacy concern so we can investigate it.

If you are in the United Kingdom, you also have the right to complain to the Information Commissioner’s Office (ICO).

If EU GDPR applies to you, you may have the right to complain to the data-protection supervisory authority in your EEA country of habitual residence, place of work, or place of the alleged infringement.

You do not have to complain to us before using a statutory supervisory-authority right.

  1. Additional rights in the United States

Residents of certain U.S. states may have additional privacy rights, subject to thresholds, exemptions, and definitions in the applicable state law.

Depending on the law, these may include rights to:

•      confirm whether we process personal information;

•      access or obtain a copy;

•      correct inaccuracies;

•      delete certain personal information;

•      opt out of certain sales, targeted advertising, profiling, or “sharing”;

•      limit certain uses of sensitive personal information; and

•      appeal a refusal of a privacy request.

Alchemy does not sell HealthKit or Health Connect data and does not sell private journal entries.

We do not sell personal information for money. However, some advertising or attribution technologies can be legally characterised in certain states as “sharing” or targeted-advertising processing even when no money changes hands. Where such law applies and Alchemy engages in that activity, we will provide the legally required opt-out mechanism and honour recognised choices where required.

We do not knowingly sell or share personal information of users under 18 because the Services do not permit under-18 accounts.

You may submit a U.S. privacy request through connect@alchemysoultech.com. We will verify and respond as required by applicable law.

  1. Tracking permissions and advertising choices

On platforms that require a device-level permission before accessing an advertising identifier or tracking across other companies’ apps or websites, we will use that identifier only if the required permission has been granted.

Refusing tracking permission does not prevent you from using core Alchemy wellness features, although campaign measurement may be less precise.

HealthKit and Health Connect data is not used to decide which advertisements you see.

  1. Marketing communications

Where permitted, we may send service news, wellness content, product announcements, or offers.

You can unsubscribe from marketing emails using the link in the message or by contacting us.

We may still send non-marketing communications necessary for account security, subscription administration, important service changes, or legal notices.

  1. Children

Alchemy Soul is intended only for people aged 18 or over.

We do not knowingly create or maintain accounts for children and do not rely on parental consent to provide the standard Services to under-18s.

If you believe a person under 18 has provided personal data through an Alchemy account, contact us so we can investigate and take appropriate deletion or account action.

  1. Third-party websites and independent services

The Services may contain links to external websites or interact with services controlled by third parties.

Their independent processing is governed by their own privacy notices. We are not responsible for a third party’s independent privacy practices merely because a link or integration appears in Alchemy.

This does not affect responsibility we have where a third party acts as our processor or where applicable law otherwise makes us responsible.

  1. Changes to this Privacy Policy

We may update this Policy to reflect changes in law, technology, vendors, security, features, or our processing practices.

We will update the “Last updated” date and, where a change is material, provide appropriate additional notice through the app, email, website, or another reasonable channel.

If a new use of personal data requires consent, we will obtain that consent rather than treating continued use of the Services as consent where the law requires an affirmative choice.

  1. Contact

For privacy enquiries or rights requests:

Alchemy Soul Technologies Limited
167–169 Great Portland Street, 5th Floor
London W1W 5PF
United Kingdom

Company number: 16500393
Email: connect@alchemysoultech.com
Website: https://alchemysoultech.com

For rights requests, you may use the subject line: Data Protection Request.

Get App

Q1 2026