AllFollowingSavedSearch
UploadSign in

Soup is now on the App Store.

Download for iPhone

Privacy Notice

Last updated 29 September 2026

This notice explains how Soup uses personal data. Soup is run from the UK and can be contacted at miles@soup.audio.

What we collect

We collect the information needed to run a small music community: account email; profile name, handle, biography, links and avatar; uploaded tracks, artwork, metadata, credits and collaborations; comments, follows, private Saves, invite use, reports, appeals and copyright submissions; listening and product-interaction activity; and basic device, app and request information used for notifications, security, analytics and abuse prevention. Web analytics may include an approximate country, region and city inferred by the hosting provider from the request, plus a broad device, browser and operating-system category. Optional first-party analytics are controlled in Settings. We do not store raw IP addresses in product analytics, derive precise location, or collect contacts, health data, payment-card or bank-account details.

How we use it

We use this data to provide Soup, keep accounts working, moderate abuse, limit spam, understand how the community is growing when analytics are enabled, investigate bugs, improve reliability, send requested notifications, and contact you about important account or service updates. Soup may send a small number of onboarding emails to help new account holders use the service, with an unsubscribe link included. Occasional broader Soup updates are opt-in and can be turned off in Settings. We do not sell user data, use third-party advertising or track people across other companies' apps and websites.

What is public

Public activity on Soup is designed to be visible. Profiles, tracks, comments, follows, accepted collaborations and credits may be shown to other people using the service. Saves are private. Reports, appeals, copyright submissions, account controls and unpublished drafts are not public. Do not upload or post public material that you want to keep private.

Where it is stored

Soup uses service providers to operate the app: Supabase and Vercel for authentication, hosting, storage and delivery; Apple for Sign in with Apple, StoreKit and push notifications; Google for Google sign-in and optional Android support payments; Stripe for optional support payments made on the website; and an email-delivery provider for account, onboarding and opted-in update messages. They process data only as needed to provide those services. StoreKit payments are handled by Apple and website support payments are handled by Stripe. Soup does not receive or store payment-card or bank-account details. For web support, Soup stores the Stripe customer, checkout and subscription identifiers, payment status, amount and currency needed to confirm payments, provide subscription management and prevent duplicate processing.

Android support uses Google Play Billing. Soup sends an obscured Soup account identifier to Google and processes the purchase token, product and payment status on its server to verify and complete a contribution. These purchase tokens are not saved in a Soup purchase history or deliberately logged. Google retains the payment record and provides receipts and refund options. Support payments do not affect your public profile or music.

On-device storage, cookies and permissions

Soup uses secure device storage, essential cookies and local preferences to keep you signed in, remember feed and appearance preferences, preserve playback and upload drafts, and keep the service working reliably. Search history and recent searches are kept only on the device. The iPhone app asks for Photos, Camera or notification access only when the related feature needs it, and the relevant system permission can be changed in iOS Settings. Soup does not use third-party advertising cookies or assign anonymous visitors a persistent analytics identifier. A campaign source may be stored locally for a limited time to understand which links lead to signups.

Browsing measurement

To understand whether people arriving at a shared track listen and explore more music, Soup uses a temporary random identifier held only in the current page's memory. Reloading or closing the page starts a new visit. We measure public page paths, referring websites, time spent with Soup visible, public-page navigation, listening activity and share-button actions; not search text, URL query strings, raw IP addresses, IP-address fingerprints or advertising identifiers. Approximate network-derived location and broad device categories help produce aggregate audience statistics. The live admin view may name a signed-in account only when that account has explicitly enabled Analytics; anonymous visits remain temporary and unnamed. A share action does not tell us whether you published a post. This measurement cannot recognise returning signed-out visitors. You can turn it off below. Only that preference, not a visitor identifier, is saved in this browser.

Optional browsing measurement is loading in this browser. Browser Do Not Track and Global Privacy Control signals also turn it off. Signed-in account preferences still apply.

How long we keep it

Account and profile data is normally kept while your account exists. Public material remains visible until it is deleted, replaced or moderated. Account deletion has a 14-day recovery period before permanent deletion. Soup may retain a minimal anonymous comment placeholder where needed to preserve another person's reply, and limited moderation, fraud, security, copyright or legal evidence where there is a lawful reason. Payment and subscription records may be retained and detached from a deleted account where needed for accounting, tax, fraud prevention, refunds or disputes. Security and rate-limit records are kept only as long as needed to protect the service and investigate abuse. Detailed browser session context, including approximate location and device category, is kept for no more than 90 days; older analytics retain only the less detailed information needed for longer-term totals.

Your choices and rights

In Soup Settings you can control optional analytics and Soup update emails, review blocked accounts and moderation decisions, export your account data, or schedule account deletion. Renewing web support must be cancelled before account deletion is scheduled. Deleting a Soup account does not cancel a subscription managed by Apple. Notification permission is controlled in iOS Settings, and email messages include the applicable unsubscribe control. You can also ask to access or correct information, object to certain uses or restrict processing where the law allows by emailing miles@soup.audio. If you are unhappy with how your data is handled, you can complain to the UK Information Commissioner's Office. Bugs can be reported to bugs@soup.audio.