Solis — Privacy Policy
Effective Date: April 7, 2026
This Privacy Policy explains how Higher Mind Publishing LLC (“Solis,” “we,” “us,” or “our”) collects, uses, shares, and protects personal information when you use the Solis mobile applications, web application at solisapp.com, and related services (collectively, the “Service”). This Policy applies to information about Service users and visitors to our websites worldwide and is incorporated into our Terms of Service.
PLEASE READ THIS PRIVACY POLICY CAREFULLY. By using the Service, you acknowledge that you have read and understood this Policy. Where consent is required, we will ask for it separately within the Service.
Solis is operated by Higher Mind Publishing LLC, a New Jersey limited liability company. For the purposes of the EU and UK General Data Protection Regulation (collectively, “GDPR”) and similar laws, Higher Mind Publishing LLC is the controller of the personal data we process about you through the Service. Contact details are provided in Section 16.
2.1 Scope. This Policy covers personal data we process through the mobile and web Service and related communications. It does not apply to third-party services or websites that we do not own or control, even where they are linked from or integrated with the Service. Their privacy practices are governed by their own policies.
2.2 Updates. We may update this Policy from time to time. If we make material changes, we will notify you through the Service, by email, or by other reasonable means before the changes take effect. The “Last Updated” date above reflects the most recent revision. Your continued use of the Service after the effective date constitutes your acceptance of the updated Policy, except where additional consent is required by applicable law.
We collect personal data in the following categories. The specific data we collect about you depends on how you interact with the Service.
Account information: name, email address, and authentication tokens received from Sign in with Apple or Google Sign-In. You may also choose to use other authentication options we offer.
Onboarding responses: personal goals, aspirations, preferences, and self-described information (which may include age, gender if you choose to share, work, current daily life, struggles, dream lifestyle, career and wealth goals, health goals, relationships, experiences, desired day, motivations, and similar fields).
Generated content and journal entries: visualization scripts, affirmations, narrated audio, journal entries, and other content you generate or save within the Service.
Custom prompts and inputs: text you submit to request new content or to refine generated content.
Voice preferences: your selected voice or audio settings for text-to-speech narration.
Communications: the contents of messages you send us (e.g., support requests, feedback).
Marketing preferences: your choices about receiving marketing emails or push notifications.
Device and usage data: device type, operating system and version, browser type, app version, language and locale, time zone, IP address (which may be used to derive coarse geolocation), session duration, screens or pages viewed, feature use, crash logs, performance metrics, and similar diagnostic information.
Identifiers: pseudonymous user IDs we generate, device identifiers (such as IDFV on iOS), and identifiers provided by Apple, Google, or other authentication providers.
Cookies and similar technologies (web): on our web Service, we and our service providers use cookies, local storage, and similar technologies for authentication, security, preferences, analytics, and (where applicable) marketing. See Section 8 for details and your choices.
Subscription events: purchase, renewal, refund, and cancellation events received from the applicable App Store or our subscription provider.
Authentication providers: Apple and Google provide us with limited account identifiers and, if you choose, your email address. We do not receive your password or other credentials.
Subscription management: RevenueCat and the App Stores provide us with information about your Subscription status.
AI providers: OpenAI and ElevenLabs return Generated Output to us in response to inputs we submit on your behalf.
Full payment card numbers, bank account numbers, or other full payment credentials. Payments are processed by the App Stores or our payment processor.
Passwords for third-party services (we use OAuth tokens only).
Special categories of data within the meaning of GDPR Article 9 (such as data revealing racial or ethnic origin, religious beliefs, biometric data, or health data), except to the limited extent you voluntarily include such information in your onboarding responses or journal entries. We do not solicit such data, and you should avoid including it.
We use personal data for the following purposes:
Providing the Service, including authenticating you, generating personalized visualizations, affirmations, audio, journaling content, and recommendations, and storing your generated content for retrieval.
Managing your Account, including processing Subscriptions, renewals, cancellations, and customer-support requests.
Personalizing your experience based on your onboarding responses and use of the Service.
Communicating with you about the Service, including transactional notices, security alerts, changes to terms or policies, and responses to your inquiries.
Sending marketing communications about new features, content, or offers, where permitted by applicable law and subject to your right to opt out at any time.
Operating and improving the Service, including diagnostics, troubleshooting, analytics, testing new features, and improving content quality. We do not use your User Inputs or Generated Output to train our own foundation models.
Ensuring safety and security, including detecting and preventing fraud, abuse, security incidents, and other harmful activity.
Complying with legal obligations, responding to lawful requests from public authorities, and enforcing our Terms of Service.
Other purposes for which we obtain your consent or for which the law expressly permits us.
If you are located in the European Economic Area, the United Kingdom, Switzerland, or another jurisdiction with similar requirements, we rely on the following legal bases under GDPR (or its UK equivalent):
| Legal Basis | When We Rely on It |
|---|---|
| Performance of a contract (Art. 6(1)(b)) | To deliver the Service to you, manage your Account and Subscription, and respond to requests you submit. |
| Legitimate interests (Art. 6(1)(f)) | To secure the Service, prevent fraud and abuse, conduct analytics, improve the Service, and communicate with you about features. We balance these interests against your rights. |
| Consent (Art. 6(1)(a); and Art. 9(2)(a) where applicable) | For data transmission to third-party AI providers (OpenAI, ElevenLabs); for non-essential cookies and similar tracking; for marketing communications where required; and for any processing of special-category data you voluntarily include. You may withdraw consent at any time. |
| Legal obligation (Art. 6(1)(c)) | To comply with tax, accounting, consumer-protection, and other legal obligations. |
| Vital interests (Art. 6(1)(d)) | In rare cases, to protect someone's life or physical safety. |
Where we rely on consent, you may withdraw it at any time, which will not affect the lawfulness of processing carried out before withdrawal. Where we rely on legitimate interests, you have the right to object as described in Section 11.
To produce your personalized visualizations, affirmations, and audio, we transmit specified data to the third-party AI providers described below. We provide notice of these data transmissions in this Privacy Policy, and by creating an Account and using the AI-powered features of the Service, you acknowledge and agree to the transmissions described in this Section. Where applicable law requires explicit, separate consent for these transmissions (including in the European Economic Area, the United Kingdom, and other jurisdictions with similar requirements), we will obtain such consent through an in-app prompt before transmitting your data. These providers are contractually required to maintain at least equivalent privacy and security protections. You may revoke your agreement or consent at any time as described in Section 6.3, but the core AI-generation features will not function without it. We may add or substitute providers from time to time and will update this Policy if material changes affect what data is shared or how it is used.
We send the text inputs described below to one or more of the following providers to generate visualization scripts, affirmations, and related content:
OpenAI (operator of the OpenAI / ChatGPT API)
Anthropic (operator of the Claude API)
What we send: your onboarding responses, including name, age (if shared), gender (optional), description of your work, current day, struggles, dream lifestyle, dream career and wealth goals, dream health goals, dream relationships, dream experiences, ideal day, motivations, and any custom prompts you submit when generating or refining content.
What we do not send: your email address, password, payment information, device identifiers, authentication tokens, or other credentials.
Purpose: to generate personalized visualization scripts and affirmations tailored to you.
Provider retention and training: OpenAI and Anthropic each operate under API terms providing that customer API inputs and outputs are not used to train their foundation models. OpenAI retains API data for up to 30 days for abuse monitoring and then deletes it. Anthropic retains API data for a limited period for abuse-monitoring and policy-enforcement purposes, after which it is deleted in accordance with its published retention practices. See OpenAI's privacy policy at https://openai.com/privacy and Anthropic's at https://www.anthropic.com/legal/privacy.
We send the generated script text and your voice preferences to one or more of the following providers to convert text into narrated audio:
ElevenLabs
Fish.Audio
What we send: the generated script text (which may include references to your name and goals) and your selected voice preference.
What we do not send: your email, password, raw onboarding responses, payment information, or authentication credentials.
Purpose: to convert your personalized scripts into narrated audio.
Provider retention: see ElevenLabs' privacy policy (https://elevenlabs.io/privacy) and Fish.Audio's privacy policy for current retention practices and opt-out controls.
By creating an Account and using the AI-powered features of the Service, you acknowledge and agree that we will transmit the data described in Sections 6.1 and 6.2 to the applicable AI providers in order to generate the content you request. You may withdraw this agreement at any time by disabling AI features through in-app settings, by contacting us at support@solisapp.com, or by deleting your Account; upon withdrawal, the corresponding AI-generation features will be disabled. If you are located in a jurisdiction that requires explicit, separate consent for this processing (including the European Economic Area and the United Kingdom), we will obtain such consent through an in-app prompt before transmitting your data, and you may withdraw consent at any time as described above. Deleting your Account removes your stored data from our systems in accordance with Section 9.
In addition to the AI providers in Section 6, we share personal data with the following categories of recipients:
Authentication providers: Apple (Sign in with Apple) and Google (Google Sign-In) for account creation and authentication.
Cloud hosting and storage: our self-hosted Supabase deployment, which runs on infrastructure we control, used to store account data and generated content.
Subscription management: RevenueCat, which receives a pseudonymous user identifier and Subscription events. See https://www.revenuecat.com/privacy.
App Stores and payment processors: Apple App Store, Google Play, and, for web Subscriptions, our payment processor Stripe, which handles billing.
Analytics and diagnostics: RevenueCat, AppsFlyer, and Google Analytics, used to understand how the Service is used, to attribute installs and campaigns, and to detect errors.
Customer-support tools: our customer-support tools, used to handle support requests.
Communications providers: our email-delivery and push-notification providers, used to send transactional and (with consent where required) marketing communications.
Professional advisors and auditors: lawyers, accountants, and other advisors, bound by confidentiality obligations.
Public authorities and law enforcement: where we are required by law, regulation, court order, or other legal process, or where disclosure is necessary to protect the rights, property, or safety of Solis, our users, or others.
Corporate transactions: in connection with a merger, acquisition, financing, reorganization, sale of assets, or similar event, we may transfer personal data to the relevant counterparty, subject to confidentiality and continued protection consistent with this Policy.
We do not sell personal data for money. See Section 12 for additional information about “sale” and “sharing” under California law.
8.1 What They Are. On our web Service, we and our service providers use cookies, web beacons, pixels, local storage, and similar technologies (“cookies”) to operate the site, remember your preferences, secure your session, conduct analytics, and (where applicable) provide marketing.
8.2 Categories We Use. Strictly necessary (authentication, security, load balancing) — used without consent because they are essential. Functional (preferences, language) — set with consent where required. Analytics (usage and performance) — set with consent where required. Marketing (where applicable) — set only with consent.
8.3 Your Choices. Where required by law (including the EU/UK), we present a cookie banner allowing you to accept or reject non-essential cookies and to manage granular preferences. You can also control cookies through your browser settings. Rejecting non-essential cookies will not prevent you from using the Service but may reduce functionality.
8.4 Do Not Track / Global Privacy Control. Our web Service responds to the Global Privacy Control (“GPC”) signal as an opt-out of “sale” and “sharing” for residents of jurisdictions that recognize it (such as California). We do not currently respond to legacy “Do Not Track” signals because no industry standard exists.
We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, including to provide the Service, comply with legal obligations, resolve disputes, and enforce our agreements. Specific retention periods are determined by the following criteria: (a) the nature and sensitivity of the data; (b) the purposes of processing and whether those purposes can be achieved by other means; (c) applicable legal, accounting, tax, and reporting requirements; and (d) risk of harm from unauthorized use or disclosure.
As a guide:
Account data: retained while your Account is active and for a reasonable period thereafter for record-keeping, dispute resolution, and legal-compliance purposes.
Generated content and journal entries: retained while stored in your Account; deleted upon Account deletion or upon your specific deletion request.
Transmission to AI providers (OpenAI, ElevenLabs): retained by those providers per their published policies (OpenAI: up to 30 days for abuse monitoring).
Transactional and Subscription records: retained for as long as required by applicable tax and accounting law (typically 7 years in many jurisdictions).
Support communications: retained for a reasonable period to provide continuity of support and improve service quality.
Logs and diagnostics: retained for a limited period for security and troubleshooting.
When personal data is no longer needed, we will delete, anonymize, or aggregate it. If deletion is not technically feasible (for example, because data is stored in backup archives), we will isolate the data from further processing until deletion is possible.
Solis is based in the United States, and our service providers may be located in the United States and other countries that may not provide the same level of data protection as your country of residence. Where we transfer personal data from the European Economic Area, the United Kingdom, or Switzerland to a country that has not been deemed adequate by the relevant authorities, we implement appropriate safeguards, which may include:
Standard Contractual Clauses approved by the European Commission and, where relevant, the UK International Data Transfer Agreement or UK Addendum.
Supplementary technical and organizational measures, such as encryption in transit and at rest, access controls, and data minimization.
Reliance on derogations under GDPR Article 49 only in limited circumstances, such as where you have given explicit consent.
You may request a copy of the relevant transfer mechanism by contacting us as described in Section 16.
Subject to applicable law and verification of your identity, you have the following rights regarding your personal data:
Access: request confirmation of whether we process personal data about you and obtain a copy.
Rectification / correction: request that inaccurate or incomplete personal data be corrected or completed.
Erasure / deletion: request that we delete your personal data, subject to lawful exceptions.
Restriction: request that we restrict the processing of your personal data in certain circumstances.
Portability: request a copy of certain personal data in a structured, commonly used, machine-readable format and ask us to transmit it to another controller where technically feasible.
Objection: object to processing based on our legitimate interests, including profiling, and to processing for direct marketing at any time.
Withdrawal of consent: withdraw any consent you have provided at any time, without affecting the lawfulness of prior processing.
Automated decision-making: request not to be subject to a decision based solely on automated processing, including profiling, that produces legal or similarly significant effects. The Service does not make such decisions about you.
Lodging a complaint: lodge a complaint with your local data-protection authority. Contact information for EU authorities is available at https://edpb.europa.eu/about-edpb/board/members_en. UK residents may contact the ICO at https://ico.org.uk.
To exercise your rights, email support@solisapp.com. We will respond within the time required by applicable law (generally one month under GDPR, with possible extension). We may need to verify your identity before fulfilling certain requests, and we may decline requests where permitted by law (for example, where they are manifestly unfounded or excessive).
This Section applies to California residents and supplements the rest of this Policy. It is provided under the California Consumer Privacy Act, as amended by the California Privacy Rights Act (collectively, the “CCPA”).
In the preceding 12 months, we may have collected the following categories of personal information identified by the CCPA:
Identifiers: name, email address, device and online identifiers, IP address.
Customer records (Cal. Civ. Code § 1798.80(e)): name and contact information you provide.
Commercial information: Subscription and transaction history.
Internet or electronic-network activity: app and website usage information, interactions, and diagnostics.
Geolocation: approximate location derived from IP address.
Inferences: inferences drawn from the foregoing to personalize content.
Sensitive personal information: account login credentials in conjunction with required security information; and any sensitive content you voluntarily include in onboarding or journal entries. We use sensitive personal information only for purposes permitted under Cal. Civ. Code § 1798.121(a), such as providing the Service you request.
Sources: directly from you; automatically through your use of the Service; and from third parties such as authentication providers and Subscription processors. Purposes: as described in Section 4.
We disclose personal information to the categories of recipients described in Sections 6 and 7. We do not “sell” personal information for monetary consideration. To the extent that any data sharing with analytics or marketing providers may be deemed “sharing” for cross-context behavioral advertising under the CCPA, we honor opt-out requests and the Global Privacy Control signal.
We do not knowingly sell or share personal information of consumers under 16 years of age.
Right to know what categories and specific pieces of personal information we collect, use, disclose, and (where applicable) sell or share.
Right to delete personal information, subject to legal exceptions.
Right to correct inaccurate personal information.
Right to opt out of “sale” or “sharing” for cross-context behavioral advertising.
Right to limit the use of sensitive personal information.
Right to non-discrimination for exercising your rights.
To exercise these rights, email support@solisapp.com or use the “Do Not Sell or Share My Personal Information” / “Limit Use of Sensitive Personal Information” links on our website (where applicable). You may use an authorized agent; we will require written authorization and identity verification.
“Shine the Light” (Cal. Civ. Code § 1798.83): California residents may request information about disclosures of personal information to third parties for those parties' direct-marketing purposes. We do not currently make such disclosures.
Residents of Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, and other U.S. states with comprehensive privacy laws have substantially similar rights, including rights of access, correction, deletion, portability, opt-out of targeted advertising and sale of personal data, and (where applicable) opt-out of profiling that produces significant effects. To exercise these rights, contact us at support@solisapp.com. If your request is denied, you may appeal by replying to our response or contacting us at the same address; we will respond to appeals within the time required by your state's law.
We implement administrative, technical, and physical safeguards designed to protect personal data, including: encryption of data in transit (HTTPS/TLS) and at rest, access controls and least-privilege provisioning, network protections, logging and monitoring, secure software-development practices, vendor risk management, and incident-response procedures. No security control is perfect, however, and we cannot guarantee absolute security. If we become aware of a security incident affecting your personal data, we will notify you and the relevant authorities as required by applicable law.
The Service is intended for users 13 and over. We do not knowingly collect personal data from children under 13 (or the equivalent minimum age under applicable law, including 16 in some EU jurisdictions). If you are between 13 and the age of majority in your jurisdiction, you may use the Service only with the consent and supervision of a parent or legal guardian. If you believe a child under 13 has provided personal data to us without appropriate consent, please contact us at support@solisapp.com and we will take steps to delete the information and terminate the relevant account.
Solis (Data Controller): Higher Mind Publishing LLC, 89 US Highway 206 North, Chester, New Jersey 07930, United States. Email: support@solisapp.com / privacy@solisapp.com.
If you have a complaint about how we handle your personal data and we are unable to resolve it, you have the right to lodge a complaint with your local data-protection authority (for EU residents, see https://edpb.europa.eu; for UK residents, see https://ico.org.uk; for Swiss residents, https://www.edoeb.admin.ch).
By using the Service, you acknowledge that you have read this Privacy Policy and understand how Solis collects, uses, and shares your personal data.
© 2026 Higher Mind Publishing LLC. All rights reserved.