Privacy Policy

Somaura. Last updated: September 2026.

Camera and body scans

Somaura analyses live camera frames on your device with its own on-device models and, on Android only, Google ML Kit subject segmentation; on iOS no ML Kit is involved. A body-part scan may temporarily hold one still in app memory or cache, but Somaura does not add it to your photo library, scan history, or database. Google says ML Kit may collect technical SDK diagnostics such as device and app information, performance data, API configuration, input/output size, events, and error codes; camera content is not listed as collected diagnostic data.

An AI evaluating your mark is a fixed part of every body-part scan and cannot be switched off. Before an image leaves your device for the first time, Somaura asks once for your explicit consent: in the introduction or, if you did not give it there, at your first scan. Per scan, after you mark a spot, exactly one image is sent over HTTPS to Somaura and from there to Google (Gemini API): only the isolated body part with your mark, without background, downscaled to no more than 1024 pixels. The AI reads the body part, view and marked area from it. The complete camera frame is not sent. Somaura does not store the image and does not use it for training. Without a connection, or if the AI cannot answer reliably, the app asks you which body part you scanned. You can withdraw your consent by deleting all data in the app; after that, no image is sent until you consent again before a new scan.

For the AI note on a full-body result, Somaura sends Anthropic six tension values, the main focus area, and shoulder and hip angles. No image is included. Guidance on the body-part result page is written by Anthropic from the points Somaura itself selected; no image and no name is sent with it. A scan can only be started with a connection; if it drops mid-scan, you get the fixed wording from our catalogue instead.

Other data we process

Full-body scan summaries, guided-practice records, app settings, and a random installation identifier are stored locally and sync automatically over HTTPS with Somaura and Neon PostgreSQL when a connection is available. Scan photos are never part of that sync. Body-part scan selections and marks are currently stored locally only. If you sign in with Google, we process your Google account identifier, email address, and display name to authenticate your account and link synced records across devices. If you sign in with Apple, we process your Apple account identifier, email address, and name for the same purpose; Apple releases the name only at the first sign-in, so we store it then. With Apple’s “Hide My Email” we receive a relay address ending in privaterelay.appleid.com instead of your own, and never learn your actual address.

If you choose Auralis or Relief guidance, the text or voice content you submit, selected body area, relevant wellbeing history, and limited posture values needed for the request are sent to Somaura's backend. Somaura may use Anthropic for coaching text, OpenAI for speech output, and Groq for speech-to-text. Auralis speaks with a synthetic voice; it is not a recording of a real person. When you speak with her live, the app opens a direct, encrypted audio connection to OpenAI: your audio does not travel through the Somaura API but goes straight there, continuously for as long as the conversation is open. Somaura only issues a short-lived entry ticket and does not record the conversation or keep a transcript. Auralis and Relief do not receive camera images; the only image Somaura sends is the marked cutout described above.

Optional payments are processed by Stripe. Somaura does not store full payment-card numbers. For physical orders, order, delivery, and receipt details may be processed to fulfil the order.

Why and how long we keep data

We use data to provide scans, guidance, sync, authentication, purchases, and support. Synced data is retained until you delete it or delete your Somaura account, unless we must keep it longer by law. Somaura does not retain the marked cutout from a scan; Google processes it under its Gemini API terms. Under Anthropic's standard commercial API terms, API inputs and outputs are generally deleted within 30 days unless a shorter zero-data-retention arrangement or an exception for abuse monitoring or legal obligations applies. Anthropic says commercial API data is not used for model training without explicit permission. We do not sell, rent, or share personal data with advertisers or data brokers.

Our service providers

Google ML Kit and Firebase provide on-device subject segmentation on Android plus SDK configuration and diagnostics. Neon PostgreSQL stores synced records and account data. Google Sign-In and Sign in with Apple provide optional authentication. Google (Gemini API) evaluates the marked cutout of a body-part scan. Anthropic provides the structured full-body scan note, Auralis, and Relief text. OpenAI and Groq provide optional speech output and speech-to-text. Stripe provides optional payment processing.

Your choices and rights

The AI evaluation of your mark belongs to the scan and has no separate switch; you withdraw consent to it by deleting all data in the app. You can turn outline contributions off under Camera & Privacy. Outline contributions contain only geometry, calculated features, and the body part you confirmed — never camera pixels — and remain linked to your device or account identifier so export and deletion work. You can export or delete local and synced data in the app under You > Your Data. Signed-in users can delete their Somaura account in the app. You can also submit an account-deletion request through our account deletion page.

Contact

Somaura – Annika Jordi
Seefeldstrasse 24
8280 Kreuzlingen
Switzerland
somaura.app@gmail.com