Legal
Privacy Policy
Last updated: July 28, 2026
Sorella is built on a simple promise: you can talk about your health without giving up your identity. This policy explains what data we collect, why we collect it, how long we keep it, and the choices you have. We wrote it to be read — if anything is unclear, write to us at privacy@sorella.app.
1. Who we are
Sorella ("we", "us") is the publisher of the Sorella mobile application and of sorella.app. We operate from France and act as the data controller for the personal data described in this policy. For any privacy matter, you can reach us at privacy@sorella.app.
2. What we collect
We deliberately collect as little as the service needs to work:
- Account data. An email address and authentication credentials. Your email is never shown to other members.
- Profile data. A username you choose and an avatar (a color, a symbol, or an image if you decide to upload one). We never ask for your real name.
- Health context. The condition(s) you tell us you are navigating (for example endometriosis, PCOS, menopause). This is health data and we treat it with the protections described in section 4.
- Messages. The content of your 1:1 conversations and circle posts, kept only for the retention periods in section 6.
- Safety data. Reports you make or that are made about you, blocks, and — when a conversation signals a risk of self-harm — the signals needed to surface crisis resources and alert a safety operator.
- Subscription data. If you subscribe to Sister+, the purchase is processed by Apple or Google. We receive a subscription status, never your payment card details.
- Technical data. Device type, app version, language, and diagnostic logs needed to keep the service running and secure.
We do not collect your real name, phone contacts, precise location, or advertising identifiers. There is no ad tracking in Sorella.
3. How we use your data
- To provide the service — creating your account, matching you 1:1 with a peer, and running condition-specific circles (performance of our contract with you).
- To match by condition — using the health context you give us, based on your explicit consent, which you can withdraw at any time by removing conditions from your profile or deleting your account.
- To keep the community safe — reviewing reports (triaged by a human, not an algorithm), enforcing our guidelines, and preventing abuse (our legitimate interest in a safe service, and our legal obligations).
- To respond to crisis situations — surfacing localized hotlines and alerting a safety operator when a conversation signals self-harm (protection of vital interests).
- To operate and improve the app — diagnostics, security, and aggregate, non-identifying usage statistics (legitimate interest).
We never use the content of your conversations for advertising, and we never sell your data to anyone.
4. Health data
The conditions you share with Sorella are special-category data under the GDPR. We process them only with your explicit consent, only to match you with peers and circles, and never for advertising, profiling beyond matching, or resale. You can remove a condition from your profile at any time; matching based on it stops immediately.
5. Who can see what
Other members see your username and avatar — never your email, and never your real name unless you choose to share it yourself in a conversation. Sorella staff access message content only when required to review a report, investigate abuse, or respond to a crisis signal, and that access is logged.
6. How long we keep your data
- Messages. Free tier: 30 days. Sister+: 365 days. After that they are deleted from our systems.
- Account and profile data. Kept while your account is active. If you delete your account, your profile, conditions, and remaining messages are deleted.
- Safety records. Reports and enforcement records may be kept longer where we need them to prevent repeat abuse or to comply with legal obligations.
7. Who we share data with
We share data only with service providers who process it on our behalf and under contract — hosting, email delivery, and crash diagnostics — and with Apple and Google for subscription management. We may disclose data where the law requires it, or where strictly necessary to protect someone's life or safety. We do not sell personal data and we do not share it with advertisers.
8. International transfers
Our data is hosted in the European Union. Where a provider processes data outside the EU/EEA, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses.
9. Your rights
You can access, correct, export, or delete your data, restrict or object to certain processing, and withdraw consent at any time. Most of this you can do directly in the app — including deleting your account, which removes your data as described in section 6. To delete your account and its associated data — from the app or by request — see sorella.app/delete-account. For anything else, email privacy@sorella.app. You also have the right to lodge a complaint with your supervisory authority — in France, the CNIL (cnil.fr).
10. Children
Sorella is not directed to children. You must be at least 16 years old to use the service. If we learn that an account belongs to someone under 16, we will delete it.
11. Security
Data is encrypted in transit, access to production systems is restricted and logged, and we design features so that the most sensitive data — your conversations — expires by default. No system is perfectly secure, but minimizing what we hold and how long we hold it is our first line of defense.
12. Changes to this policy
If we change this policy in a meaningful way, we will notify you in the app before the change takes effect and update the date at the top of this page.
13. Contact
Questions, concerns, or requests: privacy@sorella.app.