Privacy Policy

How SOAPy collects, uses, and protects your information.

๐Ÿ“… Effective date: March 28, 2026  ยท  Last updated: April 5, 2026

Overview

โœ… SOAPy does not sell your personal information. We do not share your data with advertisers. We collect only what is necessary to operate the App and improve your learning experience.

This Privacy Policy explains how SOAPy ("we," "us," or "our") collects, uses, stores, and shares information when you use the SOAPy app or visit soapyapp.com. By using SOAPy, you agree to the practices described in this policy.

SOAPy is operated by Francisco Sanchez, located in California, United States. This policy is governed by California law.

1. Information We Collect

We collect the following categories of personal information:

Category Examples Business Purpose Storage
Identifiers Email address, name Account creation, authentication, communications Supabase (encrypted)
Professional information Role (NP, PA, MD, etc.), specialty Personalize AI feedback to your training level Supabase
Usage and performance data Case scores, section scores, streak, practice history Track your progress, generate adaptive study plans Supabase + device localStorage
User-generated content Practice SOAP notes you write Transmitted to AI model to generate feedback; not retained on our servers after feedback is returned Sent to Anthropic API, not stored by SOAPy
Payment information Subscription status, transaction confirmation Verify and manage your subscription access Stripe (we never receive or store card details)
Device and session data Preferences (dark mode, text size), locally stored progress Restore your settings across sessions Device localStorage only

2. What We Do NOT Collect

3. How We Use Your Information

We use the information we collect for the following business purposes:

We do not use your information for behavioral advertising, retargeting, or any marketing purpose unrelated to SOAPy. We do not sell, rent, or share your personal information with third parties for their own marketing purposes.

4. Cookies and Local Storage

SOAPy uses browser localStorage (a technology similar to cookies) to store your preferences, progress, and session data directly on your device. This allows the App to remember your settings between sessions without requiring a server round-trip for every interaction.

Data stored in localStorage includes: dark mode preference, text size preference, streak data, practice history, saved pearls, and SRS flashcard schedules. This data is stored locally on your device and is not transmitted to our servers unless you have an account and sync is triggered.

Do Not Track: SOAPy does not employ cross-site tracking, behavioral advertising, or analytics tracking. We honor the intent of Do Not Track signals by design โ€” we do not track your activity outside the App regardless of your browser's DNT setting.

5. Third-Party Services and Data Sharing

SOAPy uses the following third-party services to operate. Your data may be processed by these services in accordance with their own privacy policies:

We do not sell, license, or otherwise transfer your personal information to any other third parties for their own purposes.

Legal Disclosures: We may disclose your personal information if required to do so by law, court order, or governmental authority, or if we believe in good faith that such disclosure is necessary to protect our rights, your safety, or the safety of others.

Business Transfers: If SOAPy is acquired by or merged with another company, your personal information may be transferred as part of that transaction. We will notify you via email or a prominent notice in the App before your information is transferred and becomes subject to a different privacy policy.

6. Data Retention

We retain your account data for as long as your account remains active or as needed to provide the App's services. Practice SOAP notes you write are transmitted to our AI provider to generate feedback and are not stored on our servers after the feedback is returned to you.

Progress data (scores, history, streaks) is retained to provide the core functionality of the App. You may request deletion of all your data at any time (see Section 9).

When you delete your account, we will delete or de-identify your personal information within 30 days, except where retention is required by applicable law or for legitimate business purposes such as fraud prevention.

7. Data Security

We take reasonable administrative, technical, and physical measures to protect your personal information from unauthorized access, disclosure, alteration, or destruction, including:

No method of electronic transmission or storage is 100% secure. While we take commercially reasonable precautions, we cannot guarantee absolute security of your information.

Data Breach Notification: In the event of a data breach that may compromise your personal information, we will notify affected users as required by applicable California law (California Civil Code ยง 1798.29 and ยง 1798.82) and other applicable breach notification laws, within the timeframes required by those laws.

8. No Protected Health Information (PHI)

โš ๏ธ SOAPy is not HIPAA-compliant and is not designed to handle Protected Health Information (PHI). All case scenarios in the App are fictional educational examples. Do not enter any real patient data, patient names, dates of birth, medical record numbers, or any other information that could identify a real person. Doing so violates our Terms of Service and may violate HIPAA and other applicable laws.

9. Your Privacy Rights

You have the following rights regarding your personal information:

To exercise any of these rights, email thesoapyapp@gmail.com with your request. We will respond within 45 days. We will not discriminate against you for exercising any of these rights.

10. California Privacy Rights (CCPA / CPRA)

If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA):

Categories of personal information collected in the preceding 12 months: Identifiers (email, name); Professional or employment-related information (role, specialty); Education information (practice scores, progress); Internet or electronic network activity information (app usage, localStorage data).

To submit a verifiable consumer request, email thesoapyapp@gmail.com.

11. Children's Privacy

SOAPy is intended for healthcare students and professionals who are 18 years of age or older. We do not knowingly collect personal information from children under 13. If we become aware that a child under 13 has provided us with personal information, we will take steps to delete such information from our servers promptly. If you believe a child under 13 has provided us with personal information, please contact us at thesoapyapp@gmail.com.

12. International Users

SOAPy is operated from the United States and is intended for users in the United States. If you access the App from outside the United States, including from the European Union or United Kingdom, your information will be transferred to, stored, and processed in the United States, where data protection laws may differ from those in your country.

If you are located in the European Economic Area (EEA) or United Kingdom, you acknowledge that the transfer of your personal information to the United States is necessary to provide the App's services, and you consent to such transfer. Our legal basis for processing personal information from EEA users is the performance of our contract with you (providing the App's services).

If you have questions about cross-border data transfers or your rights under GDPR, contact us at thesoapyapp@gmail.com.

13. Changes to This Policy

We may update this Privacy Policy periodically to reflect changes in our practices, technology, legal requirements, or other factors. When we make material changes, we will post the updated policy on this page with a new "Last updated" date and, where appropriate, notify you by email or by a prominent notice in the App.

Continued use of SOAPy after a revised Privacy Policy is posted constitutes your acceptance of the revised policy.

14. Contact

If you have questions, concerns, or requests regarding this Privacy Policy or our handling of your personal information, please contact us:

SOAPy โ€” Privacy
Email: thesoapyapp@gmail.com
Location: California, United States

We will respond to privacy inquiries within 45 days.