← Back to Softly Said

PRIVACY, IN PLAIN LANGUAGE

Your words are personal.

You deserve to know where they go, who can see them, and what you can change.

Private-testing privacy notice · Last updated September 2, 2026

Who we are

Softly Said is developed by Chase Nunn under the Softlilt Studio name. This notice describes the current private-test app and this website. For a privacy question, email support@softlysaid.app or use the support options.

What the app stores

When you create an account, we process your email address and authentication information, your chosen profile name, and an optional profile photo. To provide the experience, we store circle membership, invitations, question offers, your drafts and submitted words, delivery and opening state, kept choices, and private acknowledgements.

If you set a feeling signal, it’s shared with your trusted circle members for up to 24 hours unless you clear it sooner. Optional notifications use device push tokens and your notification preferences. Help requests contain the note you submit and limited information such as app revision and platform. Safety reports record the category and relevant relationship or exchange metadata; private message text is not automatically attached.

The app also keeps some preferences and state on your device. Device-local storage is not a separately encrypted vault; use your device passcode and appropriate device security.

Who can see your words

A cloud draft is accessible to its writer through the app. A delivered exchange is available to its writer and named recipient—not a public audience or the whole circle. Profile information and optional feeling signals are visible to authorized circle members, subject to safety controls.

Softly Said is not end-to-end encrypted. Access controls restrict what other users can read, but the service operator and infrastructure providers may technically access stored information as needed to operate, secure, troubleshoot, or meet legal obligations. We don’t claim that nobody but you can ever read stored content.

Your recipient can still choose to copy or screenshot what you send. Share thoughtfully, even in a private circle.

Why we use this information

We use it to authenticate you, connect the people you choose, save and deliver your words, restore your account across devices, apply safety controls, send requested alerts, and respond to support needs. We do not sell relationship data, serve advertising, or send private writing to a generative-AI service as part of the app.

The services that help us

Supabase provides account, database, and file-storage services. Expo and Apple support app delivery and push notifications. The website is hosted through Sites and Cloudflare. Google Workspace handles our support email, including your email address and the contents you choose to send. These providers process the information necessary to provide their services, which may include request, network, security, and delivery logs. The current app backend is hosted in the United States; provider processing may occur in other locations.

Notification messages exclude personal words. If you enable sender-name previews, those names may appear in your alerts. Infrastructure providers have their own terms and privacy practices.

This website

The site has no advertising pixels, optional analytics, newsletter collection, or account sign-in. The sample notes and color previews run locally in your browser and do not create real messages. Fonts and sound samples are hosted with the site rather than fetched from advertising or font-tracking services.

Visiting a website still sends basic connection information, such as your IP address and browser request, to its hosting providers. An invitation token in a URL query may also reach infrastructure logs. We remove an invite token from the address bar after the page loads, avoid browser storage for it, and use a no-referrer policy. This does not erase infrastructure logs that already received the original request. Do not post invitation links publicly.

Your controls and deletion

You can change profile information, remove a profile photo, clear a feeling signal, adjust alerts, delete an unsent draft, remove a kept item, leave a circle, block a person, or delete your account. Signing out and deleting the app are not account deletion.

Account deletion is in You → Settings → Account & circles → Delete my account. It removes the account and connected app data, including authored words that may have been kept by other people. A recipient’s independent screenshots or copies are outside our control.

We retain information needed to run your account until it is removed through the relevant controls or account deletion, except where security, support, legal obligations, or provider backup retention require it to remain longer. This notice does not promise an immediate purge of all provider backups or logs. Contact support if you need help accessing, correcting, or deleting your information.

Private testing and children

This is a small, personally invited test, not a public service directed at children. Please do not invite children into the private test. If you believe a child’s information has been provided without appropriate authorization, contact the test organizer so it can be addressed.

When things change

We’ll update this notice as the product changes and provide appropriate notice before materially different data practices take effect. This page describes the current test—not planned features such as widgets, public subscriptions, or additional sign-in providers.