Privacy Policy
Last updated: August 2026
Soom is a habit and protocol tracking app for iPhone, developed by Litchi s.r.o., based in Slovakia ("we", "us"). This policy explains what data Soom handles, where it lives, and what leaves your device.
The short version: your protocol and health data stay on your phone. We do not operate servers that store your personal records.
The design principle
Soom is built local-first. Your habits, micros, completion history, and health metrics are stored in a database strictly on your device. Soom works fully offline, and there are no user accounts in this version of the app.
Data stored on your device
- Your protocol and preferences. Micros, sessions, schedules, completion history, and settings (day window, goals, start screen, and an optional display name).
- Apple Health data (only with your explicit consent). With your permission, Soom reads sleep, steps, heart rate variability, and resting heart rate to display them alongside your day and to compute on-device summaries, such as comparing last night's sleep to your own recent average. Health data is processed entirely on your device and is never transmitted to us or to third parties. Soom does not write data to Apple Health. You can revoke access at any time and Soom keeps working without it.
- Calendar events (only with your explicit consent). With your permission, Soom reads events from your iOS calendar to display them alongside your micros on the timeline and, if you choose, on the home-screen widget. Soom's calendar access is read-only: it never creates, edits, or deletes events. Calendar data is displayed live, is never stored in Soom's database, and never leaves your device. You can choose which calendars are shown, and you can revoke access at any time via iPhone Settings — Soom keeps working without it.
- A device identifier. A randomly generated ID created on first launch, used to keep your data consistent on your device. It is not linked to your identity or any real-world information.
Deleting the app removes your protocol and health-derived data. (A residual random identifier stored by iOS in the system Keychain may briefly outlive deletion; Soom clears it automatically if the app is ever reinstalled.) A data export feature is planned for a future version; until then, your data can be deleted at any time via Settings, Your Data, Delete all data.
What leaves your device (and what doesn't)
- Analytics. We use PostHog to gather basic usage analytics, such as which screens are opened and whether features work, to help us improve the app. Analytics are tied to the random device identifier, never to your name, contact information, or health data. Health metrics never appear in analytics, logs, or crash reports.
- Crash reporting. We use Sentry to capture crash reports so we can fix bugs. Crash reports contain technical information (device model, iOS version, stack traces) and never include your protocol, health, or calendar data. When a report is received, Sentry's EU servers may derive an approximate, city-level location from the network connection; we do not store this with your data.
Our third-party service providers process this technical data in compliance with EU data protection regulations.
TestFlight. If you use Soom through Apple's TestFlight beta program, Apple may collect crash logs and any feedback you submit through the TestFlight app, in accordance with Apple's own privacy policy.
What we never do. No advertising SDKs. No data brokers. No selling or monetization of your personal data.
Apple HealthKit compliance
Soom's integration with Apple HealthKit strictly follows Apple's developer guidelines. Health data is used exclusively to provide core app features directly on your device. It is never used for advertising or marketing, never sold, and never transferred to data brokers or analytics platforms. You can grant or revoke Soom's HealthKit permissions at any time via iPhone Settings, Privacy & Security, Health, Soom.
Legal bases and your rights (EU/EEA)
Under the EU General Data Protection Regulation (GDPR), we process data under the following legal bases:
- Contractual necessity (Art. 6(1)(b) GDPR): to provide the app's core functionality on your device.
- Explicit consent (Art. 9(2)(a) GDPR): for accessing and processing Apple Health data on-device, granted by you via the iOS permission prompt and revocable at any time.
- Legitimate interest (Art. 6(1)(f) GDPR): for anonymized usage analytics and crash reporting to maintain and improve the app.
Because your protocol and health data reside strictly on your device, we do not hold a copy of them. You can access, modify, or delete this data directly inside the app or by deleting the application. For inquiries regarding analytics data or to exercise your GDPR rights, contact us at hello@dailysoom.com. You also have the right to lodge a complaint with a supervisory authority; in Slovakia this is the Úrad na ochranu osobných údajov (Office for Personal Data Protection of the Slovak Republic).
Children's privacy
Soom is not intended for or directed at children under the age of 16. We do not knowingly collect personal data from children.
Changes to this policy
If our data practices change, for example if optional cloud sync launches in a future version, this policy will be updated and the app will note the change before any new data processing occurs.
Contact
Litchi s.r.o.
Bratislava, Slovakia
hi@soomprotocol.com