Privacy policy
The canonical copy of this policy ships with the app.
Soya — Privacy Policy
Last updated: 5 August 2026
Soya turns articles and book summaries into reading practice in Chinese, Japanese and Korean. This policy describes what the app does with your information. It is written to be checked against the app rather than to cover us: where the app makes a narrow promise, this says the narrow thing.
The short version
Your library — the things you have read, the words you have looked up, your practice history and where you got to in each article — lives in a database on your phone. It stays there and goes nowhere unless you sign in, which is optional and off by default.
Three kinds of information do leave your phone:
- The text you are reading, sent to a model provider so it can be translated, defined or explained.
- A request for news articles, which are the same articles for every reader and carry nothing about you.
- Your library, but only if you choose to sign in and turn on sync.
Nothing else is collected. There is no analytics, no advertising, no tracking, no profiling and no third-party SDK that reports on your use of the app.
What stays on your device
Stored in a private database inside the app, and not transmitted anywhere unless you sign in:
- The articles and book summaries you have imported, and their translations
- The words you have saved, their definitions, examples and sentence breakdowns
- Your practice history, scores and review scheduling
- Your reading position in each article
- Your settings — target language, level, appearance, voice, reminders
- Your recent searches
Your recent searches are a special case: they are never included in a backup file and never synced to an account, even when you are signed in. They are a local convenience and are treated as something that should not travel.
Your API key, if you set one, is held in the device keychain. It is never uploaded, never synced and never included in a backup. Neither is your record of what you have spent.
What leaves your device
1. The text you are reading, for translation
Soya works by sending text to a large language model. This is the core function of the app and it cannot be switched off, because without it there is nothing to read. There are two ways it happens, and which one applies depends on whether you have set your own API key.
If you have set your own API key, the text goes directly from your phone to the provider you chose — Anthropic, OpenAI, Google, DeepSeek, or any OpenAI-compatible endpoint you configure. It does not pass through our servers. Your relationship is with that provider, and their privacy policy and data retention terms govern what happens to it. Where the provider offers a setting that prevents the request being stored, the app sets it.
If you have not set an API key, the text is sent to our server, which passes it to a model provider on our account and returns the result. We do not keep it: no article text, no word and no sentence you send this way is written to any database table or log file of ours. The only thing recorded is a count of how much of the monthly free allowance you have used, stored against an anonymous identifier (see below).
In both cases the text is necessarily held by the model provider for the duration of the call. We configure every provider we use on our own account to not store the request. We should be precise about the limit of that: it prevents the request being retained in the provider’s conversation history, and it does not override any short-term retention a provider carries out for abuse monitoring under its own terms.
2. News
The app can show a corpus of news articles, already translated. Reading them is a plain request for rows that are identical for every reader. The request carries no account, no identifier and nothing about you, and it is not logged against you.
News articles are generated from public sources and are not personal data.
3. Your library, only if you sign in
See the next section.
Accounts and sync (optional)
Soya works fully without an account. There is no sign-up wall, no prompt, and no feature that nags you toward one. Signing in exists for one reason: to move your library between your own devices.
If you choose to sign in, at Settings › Account, you may use:
- Sign in with Apple — we receive an identifier, and an email address, which may be Apple’s private relay address if you chose Hide My Email
- Google — we receive an identifier and the email address on the account
- Email — you give an address and receive a six-digit code; we store the address
Once signed in, the app syncs your library to our database: your articles and their translations, your saved words and definitions, your practice history, your reading positions and your settings. This is stored so it can be sent back to your other devices, and for no other purpose. It is not analysed, not sold, not shared, and not used to train anything.
Your API key and your spending record are not synced, even when signed in. Your recent searches are not synced.
Sync is what an account is for. If you sign out, syncing stops, and you choose whether the copy on that phone stays or goes.
The anonymous identifier
If you use the app without an API key, the app creates an anonymous session so that the free monthly allowance has something to count against. This is a random identifier. It is not linked to your name, your email or your device’s hardware identifiers, and we make no attempt to connect it to a person. The only data stored against it is a number: how many tokens of the monthly allowance have been used, and in which month.
This is not an account. It gives you no sign-in, and it does not turn on sync.
What we do not do
- No analytics or telemetry SDK
- No advertising, and no advertising identifier
- No tracking across apps or websites
- No selling or sharing of personal information
- No profiling, and no automated decisions about you
- No collection of contacts, photos, location, microphone or camera data — the app requests none of these permissions
Deleting your data
If you have not signed in, we hold nothing to delete. Removing the app removes your library with it. You can also clear it inside the app.
If you have signed in, you can delete your account and everything in it from inside the app: Settings › Account › Delete account. This permanently removes your articles, words, practice history, settings and usage records from our servers, and takes effect immediately. You choose separately whether the copy on your phone is also erased.
If you have already uninstalled the app and cannot reach that screen, email the address below from the address you signed in with, and we will delete the account for you.
Backups you have exported yourself are files on your own device or wherever you saved them; we cannot reach those, and deleting your account does not affect them.
Retention
- Library data in your account is kept until you delete it or delete your account.
- Free-tier usage counts are kept per calendar month, and are removed when the account is deleted.
- Text sent for translation is not retained by us at all.
- News articles are removed from the corpus on a rolling basis, currently after about 14 days.
Children
Soya is not directed at children and we do not knowingly collect personal information from children. If you believe a child has created an account, contact us and we will delete it.
International transfers
Our servers and the model providers we use may process data outside your country, including in the United States. Where required, transfers rely on standard contractual clauses or an equivalent mechanism offered by the provider.
Your rights
Depending on where you live, you may have the right to access, correct, export or delete the personal information we hold, and to object to or restrict its processing. For most of these the app is faster than we are: your library is on your device, Settings › Backup exports it as a file, and Settings › Account deletes it. For anything else, contact us.
Changes to this policy
If this policy changes in a way that affects what leaves your device, the change will be described here with a new date. Continued use after a change means the updated policy applies.