Back

Privacy Policy

Effective date: 6 August 2026

Provided by Soham Collective Pty Ltd (ABN 580987731), trading as Soham Collective, Soham Inner Calm, Prakash Bhattarai, and Meditationforbeginners.com (“we”, “us”, “our”)

This Privacy Policy explains what personal information the Soham Inner Calm mobile application (the “App”) and our associated websites, including prakashbhattarai.com and meditationforbeginners.com (together with the App, the “Services”), collect, why we collect it, who we share it with, how long we keep it, and the choices and rights available to you depending on where you live. It should be read together with our Terms & Conditions. By using the Services you acknowledge this Policy. If you do not agree with this Policy, please do not use the Services.

1. Who we are

The Services are provided by Soham Collective Pty Ltd (ABN 580987731) of Australia, trading as Soham Collective, Soham Inner Calm, Prakash Bhattarai, and Meditationforbeginners.com, and offering the mobile application listed on the app stores as “Soham Inner Calm: personalised Sessions for meditation & Growth” (together, “Soham Inner Calm”, “we”, “us”, “our”). For any privacy question, or to exercise your rights, contact us at prakasbhattarai@gmail.com. If you are in Australia, this Policy is intended to be consistent with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). Sections 16 to 18 below set out additional information for users in the United States, the European Economic Area, the United Kingdom, and other regions.

Soham Inner Calm is not affiliated with, endorsed by, or sponsored by Meta Platforms, Inc. (including Facebook and Instagram) or Google LLC. Where we refer to “Google Sign-In” or “Sign in with Apple”, we are describing sign-in options we integrate with; this does not imply any partnership, endorsement, or affiliation with those companies.

2. A note on sensitive information

The Services handle information about your wellbeing. Journal entries, onboarding answers, the emotional context you provide to generate meditations, and mood/emotion labels can reveal sensitive information about your mental state. In some jurisdictions, this information is treated as a special or sensitive category of personal information, for example “health data” under the GDPR and UK GDPR, “sensitive personal information” or “consumer health data” under various US state laws, or “sensitive information” under the Australian Privacy Principles.

Where the law requires your explicit or opt-in consent before we collect this information, we treat your affirmative action of choosing to enter it into a specific feature, such as writing a journal entry, selecting a mood label, or describing how you feel to the AI coach, as your explicit consent to that specific use, given at the point of use. You can withdraw that consent at any time by not using the relevant feature, by deleting past entries in the App where that option is available, or by deleting your account (see Section 12).

3. Information we collect

Account information you provide when you register or edit your profile:

  • Full name — collected at registration/profile.
  • Email address — collected at registration; used for sign-in and service emails.
  • Password — collected at registration; stored only in hashed form (bcrypt); never stored on your device.
  • Date of birth (optional) — collected in profile settings; used for age-appropriate content.
  • Profile photo (optional) — collected on profile upload; stored with our object-storage provider.
  • Google / Apple account ID — collected via social sign-in; a third-party identifier; Apple may provide a private-relay email.

Wellbeing and activity information you create in the App (stored on our servers):

  • Onboarding questionnaire answers (meditation experience, goals, time available, format, motivation).
  • Journal entries — free text you write.
  • The free-text emotional context you enter to generate an AI meditation, and AI coach conversation content.
  • Meditation session emotion labels (e.g. Great / Calm / Okay / Low / Stressed).
  • Course and challenge enrolments and progress; course reviews (rating + comment); feedback and bug reports.

Stored on your device only, not sent to us: your daily mood check-in selection, and your meditation streaks/history. These stay on your device and are removed if you delete the App.

Technical and security information generated by using the App: authentication tokens (stored in hashed form), email-verification and password-reset codes, and an audit log of account actions (such as deletion requests).

4. What we do not collect

We want to be clear about what the Services do not do:

  • We do not use analytics, advertising, attribution, or cross-app tracking technologies, and we do not serve ads. We answer “No” to tracking in the App Store privacy labels.
  • We do not collect your location, contacts, calendar, or health-app (e.g. Apple Health) data.
  • We do not sell your personal information, and we do not “share” it for cross-context behavioural advertising as that term is used under US state privacy laws.
  • The App does not currently process payments; it is provided free of charge.
  • Our websites do not currently use cookies or similar technologies for advertising, analytics, or cross-site tracking (see Section 19).

The App may ask your permission to use the camera, photo library, and microphone (for your profile photo and audio features) and Face ID (for secure on-device storage). These are used for the stated feature on your device; declining a permission simply disables that feature. Face ID data is processed entirely on your device by Apple's operating system and never reaches our servers; see Section 16 for more detail.

5. Information collected before you create an account

The App asks some onboarding questions before you create an account. While you are unauthenticated, we generate a temporary local session identifier and store your answers against it so your experience is personalised. If you later create an account, we link those answers to it. If you never create an account, you can clear this data by deleting the App.

6. How we use your information

  • To provide, personalise, and improve the Services, including recommending sessions and generating AI-guided meditations and coach replies.
  • To create and secure your account, verify your email, and support password resets.
  • To respond to your support requests, feedback, and bug reports.
  • To keep the Services safe, prevent misuse, and comply with our legal obligations.

Where the law requires us to identify a lawful basis for processing (for example, under the GDPR, the UK GDPR, or the Australian Privacy Principles), we rely on:

  • your explicit consent, for the sensitive/wellbeing information described in Section 2;
  • the performance of our agreement with you (our Terms & Conditions), to provide the core features of the Services;
  • our legitimate interests, to keep the Services secure, understand how they are used, and improve them, balanced against your rights and interests; and
  • compliance with a legal obligation, where applicable.

7. Artificial-intelligence features and third-party processing

The AI coach and the personalised meditation generator send the text you provide to a third-party AI provider to produce a response or script.

  • Our current AI provider is OpenAI. The content you enter into these features (and, for the coach, recent conversation turns) is transmitted to OpenAI to generate the reply.
  • OpenAI applies its own retention practices. Under its standard API terms, submitted content is not used to train its models by default, but standard operational retention (up to around 30 days for abuse monitoring) may apply. We do not currently have a zero-retention arrangement in place.

Because AI content leaves your device and is processed by a third party, please do not enter information you would not want processed by an external provider. AI output may also be inaccurate and is not a substitute for professional advice.

8. Who we share your information with

We share personal information only with the service providers needed to run the Services, and as required by law. We do not sell it. The providers we currently use:

  • Our hosting / backend provider — receives all stored data; runs the service and database.
  • Google — receives your sign-in identity token (email, name); used for Google Sign-In.
  • Apple — receives your sign-in identity token (email or relay email, name); used for Sign in with Apple.
  • Apple App Store / Google Play — receive app download, device, and (if applicable) purchase information; for app distribution, governed by Apple's and Google's own privacy policies.
  • OpenAI — receives AI coach and meditation free-text; for generating AI responses and scripts.
  • Cloudflare R2 — receives uploaded media (profile photos, audio); for object storage.
  • Resend — receives your email address and message content; for verification and account emails.

We may also disclose information if required by law, to enforce our Terms, or to protect the rights, safety, or property of our users or others. If we introduce paid features, we will update this list to name the payment processor we use before that feature launches.

9. International data transfers

Some of our providers (including OpenAI, Cloudflare, and our email provider) process data outside Australia, including in the United States. Where we transfer personal information originating in the European Economic Area or the United Kingdom to a country that has not been recognised as providing an adequate level of protection, we rely on an approved transfer mechanism, such as the European Commission's Standard Contractual Clauses or, for UK transfers, the UK's International Data Transfer Addendum, together with additional safeguards where appropriate. For Australian users, we take the steps required by Australian Privacy Principle 8 before disclosing personal information overseas. By using the Services you acknowledge that your information may be processed in these locations.

10. Our representatives in the EU and UK

Because we are established outside the European Economic Area and the United Kingdom but may process the personal information of individuals located there, Article 27 of the GDPR and the equivalent provision of the UK GDPR may require us to appoint a local representative.

  • [EU representative name, address, and contact details to be inserted] acts as our representative in the EEA for GDPR purposes.
  • [UK representative name, address, and contact details to be inserted] acts as our representative in the United Kingdom for UK GDPR purposes.

You may contact our representatives, or us directly, on any matter relating to the processing of your personal information. These appointments should be finalised, and the placeholders above completed, before the Services are actively marketed to, or used at meaningful scale by, individuals in the EEA or UK.

11. How we store and protect your information

  • Passwords are stored only in hashed form (bcrypt) and are never stored on your device. Authentication and reset tokens are stored hashed.
  • Access to our systems is restricted to those who need it to operate the service.

Your journal entries and the free-text you provide to AI features are stored on our servers in plaintext; they are not encrypted at the application level, which means our operators could technically read them, and they are not end-to-end encrypted. No method of transmission or storage is completely secure. Please keep this in mind when deciding what to write.

12. How long we keep your information, and deletion

We keep your personal information for as long as your account is active and as needed to provide the Services. You can delete your account in the App via Settings → Account → Delete account.

  • Deletion is subject to a 30-day grace period, during which you can cancel and keep your account. After it ends, an automated process permanently deletes your account data, including journal entries, onboarding responses, enrolments, reviews, progress, and meditation requests, or, in limited fallback cases, anonymises the record so it no longer identifies you.
  • Some records may be retained where we are legally required to keep them.

Two current limitations we disclose openly: (1) media you uploaded (such as profile photos and audio) held with our object-storage provider is not automatically removed by the account-deletion process today; and (2) anonymised accounts retain a scrubbed, non-identifying record. You can contact us at prakasbhattarai@gmail.com to request removal of uploaded media.

13. Data breach notification

If we experience a data breach that is likely to result in serious harm to you, we will notify you and, where required, the Office of the Australian Information Commissioner, in accordance with the Notifiable Data Breaches scheme under the Privacy Act 1988 (Cth). Where the GDPR or UK GDPR applies, we will notify the relevant supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of a qualifying breach, and will notify affected individuals where the breach is likely to result in a high risk to their rights and freedoms. Where a US state breach-notification law applies to you, we will notify you and, where required, the relevant state regulator, within the timeframe that law prescribes.

14. Your privacy rights

Depending on where you live, you have rights over your personal information. In all cases you can contact us to:

  • access the personal information we hold about you, and request a copy;
  • correct information that is inaccurate or out of date (you can edit much of it directly in the App);
  • delete your account and associated data (see Section 12);
  • withdraw consent to sensitive-information features by ceasing to use them;
  • object to or restrict certain processing, and request portability, where the law provides for it.

To exercise any right, email us at prakasbhattarai@gmail.com.

15. Australia

If you are in Australia and are not satisfied with our response to a privacy request or complaint, you may contact the Office of the Australian Information Commissioner (OAIC). We handle eligible data breaches in accordance with the Notifiable Data Breaches scheme (see Section 13). If we ever send you marketing or promotional email, rather than transactional account emails, we will do so consistently with the Spam Act 2003 (Cth), including an unsubscribe option.

16. United States

If you are a resident of a US state with a comprehensive consumer privacy law in effect, which as at the effective date of this Policy includes California, Colorado, Connecticut, Virginia, Utah, Texas, and a number of other states, you may have the right to:

  • confirm whether we process your personal information, and access it;
  • correct inaccurate personal information;
  • delete your personal information;
  • obtain a portable copy of your personal information;
  • opt out of the sale of personal information, the “sharing” of personal information for cross-context behavioural advertising, and profiling used for decisions with legal or similarly significant effects; and
  • appeal a decision we make in response to your request, by emailing prakasbhattarai@gmail.com with “Privacy Appeal” in the subject line.

We do not sell personal information and do not use it for cross-context behavioural advertising, so the opt-out rights above are not currently applicable in practice, but you may still exercise the other rights listed.

Sensitive personal information and consumer health data: Several US states, including Washington, Nevada, and Connecticut, have enacted laws that apply specifically to “consumer health data”, a category that can include journal entries, mood labels, and similar wellbeing information you provide in the App. We have published a separate US Consumer Health Data Notice describing this in more detail (see Settings → About). Where these laws apply to you, we obtain your opt-in consent before collecting or sharing this data (see Section 2), do not sell it, and do not use geofencing around healthcare facilities to track you or send you notifications.

Biometric information: Face ID, where you choose to enable it, is processed entirely on your device by Apple's operating system and Secure Enclave. We do not receive, transmit, or store any biometric identifier or biometric information derived from Face ID, and this feature is offered subject to Apple's own terms and privacy practices.

Not a HIPAA covered entity: We are not a healthcare provider, health plan, or healthcare clearinghouse, and the Services are not covered by the US Health Insurance Portability and Accountability Act (HIPAA). Information you provide in the App is protected under this Policy and applicable state law, not under HIPAA.

Children (COPPA): The Services are not directed at children under 13, and we do not knowingly collect personal information from children under 13. If we learn that we have collected personal information from a child under 13 without verifiable parental consent, we will delete it. See also Section 20 (Children's Privacy).

California “Shine the Light”: California residents may request information about our disclosure of personal information to third parties for their own direct marketing purposes. As noted above, we do not sell or share personal information for such purposes.

17. European Economic Area and United Kingdom

If the GDPR or UK GDPR applies to you, you have the rights described in Section 14, plus:

  • the right to lodge a complaint with your local supervisory authority, or the Information Commissioner's Office (ICO) if you are in the United Kingdom;
  • the right not to be subject to a decision based solely on automated processing, including profiling, that produces legal or similarly significant effects, without human involvement; our AI coach and meditation generator produce content and suggestions but do not make legal or similarly significant decisions about you;
  • the right to data portability, in a structured, commonly used, machine-readable format, for information you have provided to us and which we process on the basis of your consent or our agreement with you.

Our lawful bases for processing are set out in Section 6. Where we rely on consent for sensitive/health data under Article 9(2)(a) GDPR, you may withdraw that consent at any time as described in Section 2. See Section 10 for details of our EU and UK representatives, and Section 9 for how we handle transfers of your personal information outside the EEA/UK.

18. Canada and other regions

If you are in Canada, we handle your personal information consistently with the Personal Information Protection and Electronic Documents Act (PIPEDA) and applicable provincial privacy laws. If you are in another country not specifically addressed in this Policy, we will handle your personal information in accordance with this Policy and applicable local law, and you may contact us with any questions or requests. Users in regions not specifically named above may have the right to complain to their local data-protection authority.

19. Cookies and similar technologies on our websites

Our websites (prakashbhattarai.com and meditationforbeginners.com) may use strictly necessary cookies to operate basic functionality, such as remembering your cookie preferences. We do not currently use cookies or similar technologies for advertising, analytics, or cross-site tracking. If this changes, we will update this Policy and, where required by law (including for EEA/UK visitors), ask for your consent before setting any non-essential cookies.

20. Children's privacy

The Services are not directed at young children. You must be at least 16, or the minimum age of digital consent in your country (in the United States, 13, in accordance with COPPA, subject to Section 16 above), to create an account. If you are under this age, you may only use the Services with the involvement of a parent or guardian. If you believe a child has provided us with personal information without appropriate consent, contact us and we will take reasonable steps to delete it.

21. Changes to this Policy

We may update this Policy from time to time. When we make material changes, we will update the “Effective date” above and, where appropriate, notify you in the App, and where required by applicable law, provide that notice before the change takes effect. Please review this Policy periodically.

22. How to contact us

For any question about this Policy or your personal information, contact Prakash Bhattarai / Soham Collective Pty Ltd at prakasbhattarai@gmail.com or via prakashbhattarai.com.

About this document

This document was prepared with AI drafting assistance, in the style of experienced privacy counsel, based on the information Soham Collective Pty Ltd provided about how its Services collect and use data, and on publicly available summaries of the Privacy Act 1988 (Cth), GDPR, UK GDPR, and relevant US state privacy laws current as of August 2026. It is provided for convenience and does not constitute legal advice, and no attorney-client relationship is formed by its use or by this drafting process. Before publishing, a qualified lawyer licensed in each jurisdiction where you operate should review and approve this Policy, confirm whether an EU/UK Article 27 representative must be formally appointed (Section 10), verify the ABN and entity details above, and re-check all disclosures if the Services later add analytics, advertising, crash reporting, payments, or other data flows. Host the approved version at a stable public URL and enter that URL in App Store Connect and the Google Play Console.