Privacy Policy
Last Updated: December 30, 2025
Effective Date: December 30, 2025
1. Introduction
Welcome to Soymilk. We protect your privacy and personal information. This Privacy Policy explains how we collect, use, disclose, and safeguard your information.
By using Soymilk, you agree to this Privacy Policy. If you don't agree, please don't use our services.
Important Notice for Chinese Users
Before using this app, please read this Privacy Policy carefully. By using the app, you fully understand and agree to all its contents. If you disagree with any part of this policy, please stop using immediately.
Our Commitments:
- Follow principles of lawfulness, legitimacy, and necessity
- Process personal information transparently
- Collect only minimum information necessary
- Never provide your information to third parties without consent
2. Service Provider Information
For International Users
Data Controller: Jingtong Hu
Service Provider: Independent Developer (Canada)
GST/HST Registration: Registered
Contact Email: jingtonghu@soymilkfocus.com
Website: soymilkfocus.com
For Chinese Users
Service Provider: æ¦æ±‰å¸‚东西湖区豆软软件工作室 (Wuhan DouRuan Software Studio)
Type: Individual Proprietorship (个体工商户)
Address: Room 503, Unit 2, Building 11, Metro Times Changqing City, Jiangjun Road Street, Dongxihu District, Wuhan, Hubei Province, China
Contact Email: jingtonghu@soymilkfocus.com
Website: soymilkfocus.cn
3. Information We Collect
We collect only the minimum information necessary to provide and improve our services.
3.1 Account Information (via Apple Sign In)
When you sign in using Apple Sign In, we receive:
- Apple User Identifier - A unique ID from Apple to identify your account
- Email (optional) - Only if you choose to share it
- Name (optional) - Only if you choose to share it
- Email Verification Status - Whether Apple has verified your email
- Authentication Time
Note: Your Apple identity token is used only for verification and immediately discarded.
Apple's Privacy Policy: https://www.apple.com/legal/privacy/
3.2 Local Data (Stored on Your Device)
The following is stored locally on your device and never synced to our servers:
- Tasks - Content, titles, descriptions, due dates, completion status
- Focus Sessions - Duration, times, associated tasks
- Chat Messages - Your AI conversations
- Achievements & Progress
- Ice Coins - Balance and transaction history
- Daily Check-ins
- Task Templates - Custom templates and modification history
Important: This data stays on your device using Core Data (SQLite). We don't support iCloud sync. If you delete the app or reset your device, this data is permanently lost unless you've backed up your device.
3.3 AI Conversation Data
When you use the AI assistant (available for premium members):
- Conversation Content - Your messages and AI responses sent to our backend and processed by Alibaba Cloud DashScope (Qwen AI)
- Usage Statistics - Request count, tokens used, model, response time, success/error status
- Purpose - Providing AI service, enforcing usage limits, debugging
Data Processing: AI conversations are processed by Alibaba Cloud DashScope within mainland China. Your data stays in China and does not cross borders.
Important: We do not use your conversations to train AI models. Data retention follows Alibaba Cloud's standard practices as specified in their service agreement.
Alibaba Cloud Privacy Policy: https://www.aliyun.com/legal/privacy
DashScope Service Agreement: View Agreement
3.4 Subscription & Purchase Information
When you purchase a subscription, we collect:
- Transaction ID - Apple-provided identifier
- Product ID - Your subscription plan (Free, Lite, Pro, or China Standard)
- Purchase Date & Expiration Date
- Status - Active, expired, or cancelled
Note: All payments go through Apple's App Store. We never see your credit card or payment information.
Apple App Store Privacy: https://www.apple.com/legal/privacy/data/en/app-store/
3.5 Screen Time API Data (App Lock Feature)
When you enable App Lock using Apple's Screen Time API, we collect:
- Selected Apps & Categories - What you choose to block
- Web Domains - Websites you block
- Usage Time - Time spent on blocked apps/websites
Important: This data stays in the App Group shared container on your device. Nothing is sent to our servers. All monitoring and blocking is handled by Apple's APIs.
Apple Screen Time Privacy: https://support.apple.com/en-us/HT208982
3.6 Device Information & Logs
For debugging and security:
- Device Model (e.g., iPhone 15 Pro) and iOS version
- App Version
- IP Address - For login history and security
- User Agent - Browser/device info from HTTP requests
- Location - Country and city from IP address
- Login History - Time, success/failure, error codes
- User Actions - Timestamps for terms acceptance, data deletion, account deletion
- Conversion Tracking - Which features led you to the upgrade page and whether you purchased
Purpose: Better support, debugging, fraud detection, and security.
4. How We Use Your Information
We use your information to:
- Provide Services - Core functionality: task management, focus sessions, AI assistance, app lock
- Manage Your Account - Authentication and identity verification
- Handle Subscriptions - Process payments, verify status, enforce limits, enable member features
- Improve the App - Analyze usage, fix bugs, enhance performance
- Support You - Respond to inquiries and provide technical help
- Keep Things Secure - Detect fraud, abuse, and security threats
- Comply with Laws - Meet legal obligations and respond to legal processes
- Send Important Updates - Service updates, security alerts, subscription notifications (no marketing emails)
5. Data Storage and Security
5.1 Storage Location
Server Location: All server-side data is stored on Alibaba Cloud servers located in Hong Kong, China.
Local Storage: Task, session, and other personal data is stored locally on your device and is not synced to cloud servers.
5.2 Data Security
We protect your data using industry-standard measures:
- Encryption in Transit - HTTPS/TLS for all data between your device and our servers
- Encryption at Rest - Alibaba Cloud RDS default encryption for stored data
- Access Control - JWT authentication or API key verification required for all endpoints
- Secure Storage - Sensitive data like authentication tokens stored in iOS Keychain
- Security Logging - Automatic filtering of sensitive information (passwords, tokens, keys)
5.3 Data Retention
How long we keep your data:
- Account Data - Until you delete your account
- AI Usage Data - Until account deletion
- Purchase Records - 7 years for tax compliance, but anonymized after account deletion
- Login History - Deleted with account
- Local Data - On your device until you delete the app or reset local data
6. Data Sharing and Disclosure
We do not sell, rent, or trade your personal information. We may share your information only in the following limited circumstances:
6.1 Third-Party Service Providers
- Apple Inc.: For authentication (Apple Sign In) and payment processing (In-App Purchase). See Apple's Privacy Policy: https://www.apple.com/legal/privacy/
- Alibaba Cloud: For server hosting and AI services (DashScope/Qwen). See Alibaba Cloud Privacy Policy: https://www.aliyun.com/legal/privacy
6.2 Legal Requirements
We may disclose your information if required by law, court order, or government request, or to:
- Comply with legal obligations
- Protect our rights, property, or safety
- Prevent fraud or security threats
- Protect the rights and safety of our users
6.3 Business Transfers
If we are involved in a merger, acquisition, or sale of assets, your information may be transferred. We will notify you before your information is transferred and becomes subject to a different privacy policy.
7. Your Rights and Choices
Depending on your location (GDPR, CCPA, PIPL), you have rights regarding your personal information:
7.1 Access and Correction
Update your account information (name and email) through Apple Sign In. Your information automatically syncs when you sign in again with Apple.
7.2 Data Deletion
Delete your data in two ways:
- Delete Account - In app settings. Permanently deletes account data from servers and anonymizes purchase records.
- Reset Local Data - In settings. Deletes local data (tasks, sessions) without touching your account.
Warning: Account deletion is permanent. Your subscription cancels and you lose all paid features.
7.3 Data Export (Portability)
You can request a copy of your personal data in machine-readable format. Contact us at jingtonghu@soymilkfocus.com. We'll provide your data within 30 days.
Note: Automated in-app data export is currently in development.
7.4 Withdraw Consent
Withdraw consent by deleting your account. Note this prevents you from using our services.
7.5 Object to Processing
Object to certain data processing by contacting us. May limit feature access.
7.6 Manage Subscriptions
Manage subscriptions in iPhone Settings > [Your Name] > Subscriptions. Cancel anytime - takes effect at the end of your current billing period.
8. Children's Privacy
Our services are not directed to children under the age of 13 (or the applicable age in your jurisdiction). We do not knowingly collect personal information from children under 13.
If you are a parent or guardian and believe your child has provided us with personal information, please contact us at jingtonghu@soymilkfocus.com. We will promptly delete such information from our systems.
9. International Data Transfers
Your data is stored on servers located in Hong Kong, China. If you are accessing our services from outside Hong Kong, please be aware that your information may be transferred to, stored, and processed in Hong Kong.
By using our services, you consent to the transfer of your information to Hong Kong and its processing in accordance with this Privacy Policy and applicable laws.
10. Cookies and Tracking Technologies
Our mobile application does not use cookies or similar tracking technologies. We do not use third-party analytics services such as Google Analytics, Firebase, or Mixpanel.
Our website (soymilkfocus.com) may use basic cookies for language preferences and session management.
11. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors.
When we make changes, we will:
- Update the "Last Updated" date at the top of this policy
- Notify you through the app if the changes are significant
- Require you to review and accept the updated policy if the changes materially affect your rights
We encourage you to review this Privacy Policy periodically to stay informed about how we protect your information.
12. Legal Compliance
GDPR (European Users)
We process your data based on: Consent (AI conversations), Contract (services you requested), Legal Obligation (tax records), and Legitimate Interests (security, fraud prevention).
CCPA (California Residents)
You can request to know what we collect, delete your data, and we don't sell your information. We won't discriminate against you for exercising these rights. Contact: jingtonghu@soymilkfocus.com
PIPL (Chinese Users)
We comply with China's Personal Information Protection Law (Personal Information Protection Law of the People's Republic of China). You can access, correct, delete, and port your data. We follow the principles of lawfulness, legitimacy, necessity, and good faith when processing personal information.
13. Contact Us
Questions or requests about this Privacy Policy?
Email: jingtonghu@soymilkfocus.com
Website: soymilkfocus.com (International) / soymilkfocus.cn (China)
We'll respond within 30 days.
© 2025 Soymilk. All rights reserved.
This Privacy Policy is effective as of December 30, 2025.