Legal
Privacy Policy
soft-live policy for CalmStep.AI. We collect what is needed to run soft-live, accounts, and operations. With your agreement at sign-up, we may also use data for internal product quality and research — not, by default, to train third-party foundation models. This is not a clinical record system.
Last updated: 8 August 2026 · soft-live
Who we are
CalmStep.AI provides soft-live — a 45-minute AI-assisted text→audio practice beside care, not therapy. Our team operates in Hong Kong; the website and soft-live are open to access from anywhere in the world, especially Chinese-speaking communities. Organisation programmes are on the roadmap.
What we collect
- Account details you provide (email, name, optional profile fields)
- soft-live conversation content (so we can show history and continue your last conversation)
- Technical logs needed for reliability, abuse prevention, and soft-live analytics
- Demo / donation / contact form submissions you send us
- Your acceptance of Terms and Privacy at soft-live sign-up
How we use data
- To deliver and improve soft-live sessions, voice replies, and safety handoffs
- To operate accounts, show conversation history, and continue your last conversation
- To respond to demos, media, and partnership enquiries
- To understand soft-live funnel usage at an aggregate level
- For internal product quality and research (for example evaluating soft-live safety, coaching craft, and access) — as agreed when you create your account
Product quality & model training
By creating a soft-live account and accepting this Privacy Policy and the Terms of Service, you agree that CalmStep.AI may use account and conversation data for internal product quality and research related to soft-live (for example evaluating reply quality, safety handoffs, and usability). We are not a licensed clinic and soft-live is not a clinical record system. That use does not change that soft-live is not therapy and does not provide medical advice.
By default, we do not use your soft-live content to train third-party vendor or foundation models. Processors (for example LLM and text-to-speech providers) receive content only as needed to generate replies and audio for your session, under their service terms. If that default ever changes, we will update this policy and seek agreement where required.
Security & architecture (honest)
Soft-live traffic is protected with TLS encryption in transit between your device and our servers. Conversation text is processed by our application and by third-party LLM and TTS providers so we can generate replies and speak them aloud. That means soft-live is not end-to-end encrypted in the messaging sense: providers that power the coach must process content to serve you. We do not claim “true E2E encryption” while cloud AI processes your words.
Hong Kong (PDPO)
For users in Hong Kong, we aim to handle personal data in line with the Personal Data (Privacy) Ordinance principles: purpose limitation, retention only as needed for soft-live operations and agreed product-quality use, and reasonable security. Contact us for access/correction requests.
Mainland China & worldwide access
soft-live is open to access worldwide. Organisation programmes that may process personal information under Mainland China rules are Upcoming; when they launch we will publish region-specific notices (including PIPL where relevant). Crisis contacts for Mainland China appear on Safety & efficacy.
Processors
We use service providers for hosting, authentication/database (e.g. Supabase), AI language models (LLM inference), and text-to-speech. They process data only to provide those services. Session content is sent to LLM/TTS processors as needed to generate replies and audio — see Security & architecture above.
Cookies
See our Cookie Policy.
Contact
Privacy questions: use contact / book demo or the partnerships email when configured.