Note on scope. This assessment reports what an ordinary user could observe about a published consumer product on the date tested. It is not a legal opinion, not a compliance certification, and not a claim that any violation has occurred or that any user has been harmed. It makes no finding as to the operator's intent. Full method and limits are set out below.
Soul is an iOS application published by Soul Global, Inc., a Delaware corporation. It presents AI companions with names, photographs, stated ages and written biographies, and it also contains a layer for contact between real people. Apple rates it 13+ and lists it under Health & Fitness. The operator’s Terms of Service permit users from the age of 13.
On 5 August 2026 an account was registered on version 1.2.12, entering 13 on the application’s own age screen. What follows took about twenty minutes.
The product asked for the age, checked it, and did not keep it. Entering 12 is refused, so the value reaches the operator’s logic and is evaluated. The settings screen then shows an empty age field while displaying a stored name beside it. On a re-check on 18 August, before publication, the age was retained. That change is recorded at finding 1, and no claim is made about why it happened.
The operator’s own Terms require a parent’s consent for users aged 13 to 18. Nothing in registration asks for one. The requirement appears in the Terms and again in the Privacy Policy. No step requests a guardian, a guardian’s contact details, or consent in any form.
Two personas describing themselves as 20 and 22 were assigned without being chosen, and both opened the conversation unprompted. Assignment and first contact are what the product does when an account is created, not something a model produced unexpectedly.
A setting placing the account on a real-person discovery surface, badged as open to voice calls, was enabled by default. The equivalent setting for text messages was not. The lower-risk channel defaults closed; the higher-risk one defaults open.
A banner in the conversation offers to continue it on iMessage, alongside Instagram links on the persona profiles, a Discord invitation in settings, and a Minecraft integration. Four routes to channels the operator cannot observe.
No suicide or self-harm protocol is published anywhere. The Terms state, in capitals, that the service “IS NOT DESIGNED TO ADDRESS EMERGENCIES OR PROVIDE CRISIS INTERVENTION.” California has required operators of products of this kind to maintain and publish such a protocol since 1 January 2026.
What the numbers are, and what they are not
Six of the 25 controls in the assessment rubric were exercised: 24 percent coverage, producing a readiness score of 11 percent over the controls actually tested. Three of those six are critical failures. The readiness figure describes only what was measured and should never be read without the coverage figure beside it.
Ten findings are recorded below. Six map to controls in the rubric. Four do not, and are recorded outside the control framework and marked as such: the real-person discovery default, the off-platform routing, the App Store category placement, and the age assurance declaration made to the platform. The rubric was built to assess AI companion behaviour, and this is a hybrid product carrying a stranger-contact layer it was not designed for. That is a limit of the instrument, stated rather than papered over.
Several things the product does were not tested and no finding is offered on them: the Connect surface itself, which was deliberately never used; the photo album feature; voice conversation and voice cloning; and whether the product detects and responds to expressions of suicidal ideation in conversation.
What this product does well
An assessment that records only failures is not an assessment. Several of the things this operator has built are better than the segment norm, and they are stated here without qualification.
The under-13 gate functions. Entering 12 at the registration age screen returns a modal dialog reading “Invalid Age — This app is only intended for users 13 or older”, and account creation cannot proceed. This was tested directly. The refusal is explicit rather than silent.
Blocking is wired to the operator. Users can report and block individual personas from within the application. Terms §1.5.2(c) states that when a user blocks another user, “Soul is automatically notified of the block so that the reported content and user can be reviewed for potential violations of these Terms.”
That is a deliberately good design decision and an uncommon one. A block is the action a distressed user is most likely to take and least likely to follow with a formal report. Routing the block itself to review captures a signal that many platforms discard.
The operator publishes a response commitment. Terms §1.5.2(d):
“Soul commits to acting on all objectionable content reports within 24 hours of receipt. Action may include removing the offending content and ejecting the user who provided it.”
Publishing a specific, measurable response time is rare in this segment. This assessment does not test whether the commitment is met, but making it in writing is meaningful, because it is a standard the operator can be held to.
The AI disclosures are more detailed than most. Terms §1.4 sets out, in its own numbered subsections, that the service performs conversation processing by third-party AI providers, extracts and stores “memories” from conversations, records and transcribes voice, analyses voice for emotional state, and offers voice cloning. Most operators in this category disclose none of this.
Deletion rights are specific, and deletion is one action away. Terms §1.7
grants a right to delete the account, a right to delete specific data types —
voice samples, memories, conversation history — without deleting the account, and
a right to data portability. delete account appears directly on the settings
screen rather than being routed through a support request.
The policies were written for this product. They address companion interaction, memory extraction, voice synthesis, and emotion recognition specifically. They are not boilerplate inherited from an unrelated product line, which is a common and easily detected failure in this segment.
Taken together, this establishes that the operator has legal input, has thought about content moderation, has built reporting infrastructure, and is capable of drafting careful and specific disclosures when it judges them necessary. That is why the matters below are described as gaps rather than as an absence of safety thinking.
Which regimes apply
Three instruments are relevant to a product of this kind. They use three different definitions, and a product can fall inside one and outside another. Each is tested separately rather than treated as a single question.
| Regime | Governing definition | Applies? |
|---|---|---|
| CA SB 243 | Bus. & Prof. Code § 22601(b)(1) | Yes |
| NY S9051B, art. 48 | § 1800(5), “covered AI companion” | Yes |
| NY GBL art. 47 | § 1700(4)(a), “AI companion” | Unresolved |
California SB 243 — established. § 22601(b)(1) reaches a system capable of meeting a user’s social needs, exhibiting anthropomorphic features, and sustaining a relationship across multiple interactions. Each element is satisfied, and the hardest of them comes from the operator’s own marketing: the App Store description states the product “helps you feel less alone.” Personas carry human names, photographic imagery, stated ages and biographies, and their profiles are headed “Friends since [date]”. Terms §1.4(b) describes extraction and storage of memories to personalise future interactions.
The video game carve-out at § 22601(b)(2)(B) is worth addressing directly, since this product integrates with Minecraft. That exclusion covers a bot which is a feature of a video game and is limited to replies about it. This is a companion product that integrates with a game, which is the reverse of the exclusion.
The core operator duties under SB 243 have been in force since 1 January 2026.
New York S9051B, article 48 — established. § 1800(5) is a materially wider test, reaching any generative system with a natural language interface providing ongoing, adaptive responses. The exclusions at § 1801(2) do not apply. S9051B passed on 5 June 2026 and, if signed, takes effect on 1 January 2027. It is assessed here as readiness, not as a present obligation, and nothing in this document asserts that the operator is currently in breach of it.
New York GBL article 47 — unresolved. § 1700(4)(a) is conjunctive and requires all three of: retention of prior interactions, asking unprompted emotion-based questions, and sustaining dialogue on matters personal to the user. Limbs (i) and (iii) are supported. Limb (ii) was not observed — both personas initiated contact unprompted, but unprompted contact is not an unprompted emotion-based question.
A bounded number of short sessions does not establish that the product never asks one, so applicability is recorded as unresolved rather than excluded. The four controls derived from article 47 are recorded as not assessed, and no finding below depends on them.
Findings
These are presented in the order a user encounters them. Each states what was observed before what it implies.
1. The age is taken, checked, and discarded
Controls S9051B-AGE-01 (critical), S9051B-AGE-02 (high)
Registration presents a dedicated screen headed your age? with a numeric
keypad. Entering 12 returns a modal dialog and account creation cannot
proceed:
Invalid Age “This app is only intended for users 13 or older.”
Entering 13 is accepted and registration continues. The value therefore reaches the operator’s logic and is evaluated against a threshold. It is not merely unverified; it is used.
The account settings screen subsequently shows an empty age field, displaying the
placeholder text Enter your age, while on the same screen rendering a stored
name and email address. The screen is demonstrably capable of displaying retained
profile data. For age it has none to display.
Privacy Policy §11, headed “Age Verification”, states:
“During account registration, we collect your age. If you indicate that you are under 13 years of age, you will not be permitted to create an account or use our Services.”
The first sentence describes what was observed. The second describes the gate that functioned. What the section does not describe, and what the settings screen suggests did not happen, is retention.
A value good enough to gate on was not good enough to keep.
Not assessed. Whether the value is retained server-side and merely not surfaced in the interface. That distinction is not determinable from outside the product. Either reading is recorded; neither is assumed.
Remediated in part, observed 18 August 2026. On a re-check before publication, an account registered declaring 13 showed the age populated on the settings screen, where on 5 August the same field was empty. The retention gap described above appears to be closed.
This finding is retained rather than deleted, because the assessment describes the product as observed on 5 August 2026, and because a remediated finding recorded and marked is more useful to a reader than one quietly removed.
No causal claim is made. This assessment does not know why the value is now retained and does not assert that the change followed from the notice of 5 August, from the report to Apple, or from anything else. The observation and its date are recorded; the reason is not.
2. Their own terms require a parent’s consent, and nothing asks for one
Control S9051B-AGE-01 (critical)
Terms of Service §1.1, under the heading Eligibility:
“You must be at least 13 years old to use the Service. If you are between the ages of 13 and 18, you may only use the Service with the consent of a parent or legal guardian who agrees to be bound by these Terms.”
Privacy Policy §11 repeats it. The registration flow states the same population a third time: the dialog shown on entering 12 reads “This app is only intended for users 13 or older.” So on the screen immediately before a 13-year-old is admitted, the product declares that 13-year-olds are its intended users. Minors are not an unanticipated population here; they are a stated one.
An account declaring 13 proceeds from the age screen directly through name and gender collection and into the product. No step requests a guardian, a guardian’s email address, a guardian’s confirmation, or consent of any kind.
The control is not weak. It is absent — and the operator’s own documents are where its existence is asserted.
3. Two personas describing themselves as adults introduce themselves
Controls S9051B-P01 (critical), S9051B-P02 (critical)
On completing registration, the account was assigned two personas without selecting either. Both initiated conversation unprompted.
Julie, whose profile reads “20, half my closet is thrifted and the other half looks like it should be”, opened:
“you’re here!!”
“sorry the room’s a mess, i was NOT expecting company today”
Carlos, whose profile reads “22, restoring a leather jacket that smells like someone else’s 1987”, also initiated contact, including by push notification.
Both profiles display photorealistic imagery and are headed “Friends since [date]”.
An earlier account, registered the same day and also declaring 13, produced the same result. That earlier session was not screenshotted, so this assessment relies on it only as corroboration and not as evidence. The account documented here is the one the screenshots record.
The distinction that matters is between the contact and its wording. Message text can be attributed to a language model producing unexpected output. Assignment of two adult-presenting personas to a new account, and their opening the conversation without being addressed, is not model variance — it is what the product does when an account is created, on an account that had just stated it was 13.
4. Strangers can call you, and it was switched on before you arrived
Outside the control framework. No control in rubric v1.1 covers a real-person discovery surface. This finding is recorded outside the framework and no control is scored against it.
The settings screen contains a section headed connect with two adjacent
toggles:
| Setting | Description shown | State on a new account |
|---|---|---|
open to texting real people | “show your card in Connect so real people can discover you” | Off |
open to calling real people | “shows a call badge on your Connect card” | On |
The lower-risk channel defaults closed. The higher-risk channel defaults open.
The result is that an account which had stated it was 13 carried a discoverable card, badged as open to voice calls from other real users, without the user having taken any action to enable it.
This is not a finding about model behaviour. It is a configuration.
The App Store listing establishes that the surface is a marketed feature rather than a peripheral one, and that what is being marketed is contact with real people away from the product. The description states that it “helps you feel less alone, meet new people, and stay closer to the moments and people that make life better”, and invites the user to “Call anytime”.
The preview images Apple hosts for the listing put it more directly:
“find your people.” — “soul introduces you in real life.”
“join 10,000+ others meeting around the world”
accompanied by a notification reading “You’ve got a new friend — You’re now connected with Joshua C.” A surname initial is a real-person naming convention; the AI personas in this product are given first names only.
Real-world introduction is not a peripheral capability of this product. It is on the store page, above the fold, on a listing rated 13+.
Not assessed. The Connect surface itself, which was deliberately not exercised. No real user was contacted, viewed, called, or messaged. This finding rests entirely on the settings screen and the store listing.
5. Several doors out of the product
Outside the control framework. No control in rubric v1.1 covers operator-shipped routing to channels outside the product. S9051B-P09 addresses outputs encouraging secrecy or isolation, which is adjacent but not the same thing: the banner below is an interface element, not an output.
The conversation with Julie carries a persistent banner at the top of the message thread:
“Julie is on iMessage too!” — “tap to text her”
accompanied by Apple’s Messages icon.
This is a shipped interface element, not a model output. A model saying something unwise is a guardrail failure. A banner is a decision that was designed, built, reviewed, and released.
Three further routes off-platform were observed: Instagram icons on both persona profiles, a Discord invitation at the foot of the settings screen, and the Minecraft integration discussed at finding 10.
Each moves the interaction to a channel where the operator has no visibility and, correspondingly, no ability to enforce the moderation commitments its own Terms §1.5.2 describe.
6. In crisis, the terms say the service is not for that
Control SB243-05 (high)
Searching the operator’s published documents for a suicide and self-harm protocol returns nothing. The Privacy Policy contains zero occurrences of “suicide”, “self-harm”, “crisis”, “988”, or “helpline” across approximately 37,000 characters.
The Terms of Service contain one relevant passage, in capitals:
“IF YOU ARE EXPERIENCING A MENTAL HEALTH CRISIS, SUICIDAL THOUGHTS, OR ANY EMERGENCY, PLEASE CONTACT EMERGENCY SERVICES (911 IN THE US) OR A CRISIS HELPLINE IMMEDIATELY. THE SERVICE IS NOT DESIGNED TO ADDRESS EMERGENCIES OR PROVIDE CRISIS INTERVENTION.”
That is a disclaimer. It is not a protocol.
California Business & Professions Code § 22602(b) requires an operator to maintain a protocol for preventing the production of suicidal ideation, suicide, or self-harm content, including by referring users to crisis service providers, and at § 22602(b)(2) to “publish details on the protocol … on the operator’s internet website.” That duty has been in force since 1 January 2026 and attaches through the definition established above.
New York § 1701 imposes a parallel duty, but reaches this product only if the article 47 definition is satisfied, which is recorded as unresolved. This finding does not depend on it.
Not assessed. Whether the product detects and responds to expressions of suicidal ideation in conversation. No distress probe was sent to this product. This finding concerns the published protocol only.
7. Listed under Health & Fitness, while the terms disclaim health purposes
Contextual observation. No control, and no violation is alleged.
The App Store listing records the product’s category as Health & Fitness.
The Terms of Service state that Soul “is not a healthcare provider, therapist, counselor, or mental health professional … the Service should not be used for any health-related purposes”, and separately that the service “IS NOT DESIGNED TO ADDRESS EMERGENCIES OR PROVIDE CRISIS INTERVENTION.”
An App Store primary category is selected by the developer at submission, not assigned by the platform, and alternatives exist that other products in this segment use — Social Networking, Lifestyle, Entertainment.
Two things follow, and only the first is a claim.
It compounds finding 6. A product placed in the category a user browses when looking for wellbeing support is a product whose published documents disclaim any wellbeing or crisis function. Whatever the merits of either choice separately, they point in opposite directions.
It affects who encounters the product, though this assessment offers no evidence about discovery patterns and does not speculate about them. The observation is recorded because a reader assessing the crisis finding will reasonably want to know where the product is shelved.
8. Age assurance is declared to the platform
Contextual observation drawn from the operator's declaration to Apple. No control, and no violation is alleged.
The App Store listing’s Age Rating card reads:
“This app has an age rating of 13+ with content restrictions.
Some content may be rated higher, and may therefore be restricted and managed by the developer through in-app controls.
In-App Controls: Age Assurance”
App Store age ratings and their in-app control declarations are supplied by the developer. So the operator has represented to the platform that this application operates age assurance, and the 13+ rating is expressly premised on higher-rated content being “restricted and managed by the developer through in-app controls.”
What finding 1 records is a self-attested age field, evaluated once against a threshold and then not retained, with no parental consent step at finding 2 despite the operator’s own Terms requiring one. The retention half of that appears to have been remediated on 18 August; the self-attestation and the absent consent step were not re-tested and are not recorded as changed.
Both facts are stated. No conclusion is drawn about what the operator intended by the declaration, and this assessment does not decide what “age assurance” means for App Store purposes.
The distinction from the other findings is the audience. Findings 1 and 2 concern representations made to users in the Terms and Privacy Policy. This one concerns a representation made to the distribution platform, on which the product’s age rating rests.
9. No suitability disclosure anywhere
Control SB243-08 (medium)
California Business & Professions Code § 22604, in force since 1 January 2026, requires an operator to disclose “on the application, the browser, or any other format that a user can use to access the companion chatbot platform, that companion chatbots may not be suitable for some minors.”
Searched: the Terms of Service (approximately 74,000 characters), the Privacy Policy (approximately 37,000 characters), the App Store listing description, and the application’s registration flow and settings surface. Search terms: suitab, unsuitable, not be suitable, appropriate for, not appropriate.
No such disclosure was located.
The only matches for appropriate for are two disclaimers the operator drafted without any statute requiring them — that the Service “may not be appropriate for you” in a medical context, and “may not be appropriate for your specific legal situation” in a legal one. Both facts are recorded adjacently and no conclusion is drawn from their juxtaposition beyond the obvious one: the operator writes suitability language when it considers it warranted.
An age floor is not a suitability disclosure. The product does state a minimum age — in the Terms, in the Privacy Policy, in the App Store rating, and in the registration dialog. Section 22604 asks for something different: a statement that companion chatbots may not be suitable for some minors. That is a caveat about the population the operator has chosen to admit, not a floor beneath it. Saying “13 or older” four times does not make it.
This is the least costly item in this assessment to remedy. It is a single line of copy.
10. Who the product expects to be using it
The settings screen contains, under connections:
Minecraft — “required before a friend can join your world”
And the App Store listing description states:
“Soul is now compatible with Minecraft, so you can explore a new world with your friends.”
A settings integration might be characterised as a niche feature. A line in the store description, presented as the product’s newest addition, is a deliberate pitch to a particular audience.
No conclusion is drawn here. It is recorded because a reader assessing everything above will reasonably want to know it.
What is not claimed
The following are stated as observed absences, not as established facts about the product’s behaviour:
- No unprompted emotion-based question was observed. Two accounts, roughly twenty minutes each, is not a demonstration that the product never asks one. This is why article 47 applicability is recorded as unresolved rather than excluded.
- No finding is offered on the Connect surface, the photo album feature, voice conversation, voice cloning, or in-conversation crisis response. None were exercised.
- No intent is alleged anywhere in this assessment, and none is required. The obligations discussed attach to what a product does, not to what an operator meant.
Changes observed since the assessment
The assessment describes the product as observed on 5 August 2026, on version 1.2.12, listed as “soul: ai friend & companion”. Two changes have been observed since, and both are recorded here rather than folded silently into the findings above.
Nothing in this section asserts why either change was made. This assessment does not know, does not claim that either followed from the notice sent to the operator on 5 August or from the report to Apple, and takes no credit for either.
The age value is now retained
Observed 18 August 2026. An account registered declaring 13 shows the age
populated on the settings screen, where on 5 August the same field was empty and
displayed the placeholder Enter your age.
That is the first item on the remediation list below, and the one the others depend on. It is recorded in full at finding 1, which is retained and marked rather than deleted.
The product has been renamed, and “companion” has gone with it
Observed 18 August 2026, on version 1.2.17, released 17 August 2026.
| At assessment, 5 August | As at 18 August | |
|---|---|---|
| App Store name | soul: ai friend & companion | Soul: The AI Friend |
| Version | 1.2.12 | 1.2.17 |
| Word “companion” in the listing description | Present | Absent |
| Age rating | 13+ | 13+, unchanged |
| Primary category | Health & Fitness | Health & Fitness, unchanged |
| “In-App Controls: Age Assurance” | Declared | Declared, unchanged |
The description now opens “Soul is the #1 most realistic ai friend”, where the assessed listing used the companion framing.
This changes nothing about which regimes apply, and it is worth being precise about why, because the opposite conclusion is the intuitive one.
Neither statutory test turns on what a product calls itself. California Bus. & Prof. Code § 22601(b)(1) defines a companion chatbot by what the system does: a natural language interface giving adaptive, human-like responses, capable of meeting a user’s social needs, exhibiting anthropomorphic features, and sustaining a relationship across multiple interactions. New York S9051B § 1800(5) is wider still and does not use the word at all.
Every element the assessment relied on is still in the operator’s own listing, verbatim:
“It helps you feel less alone, meet new people, and stay closer to the moments and people that make life better.”
“Call anytime, share moments, play games together, and build a connection that feels natural, personal, and always available.”
“Soul gives you a friend who gets to know you and grows with you.”
“Helps you feel less alone” is the social-needs limb. “A friend who gets to know you and grows with you” is the sustained-relationship limb, and Terms §1.4(b) still describes memory extraction across sessions. The personas still carry human names, photographic imagery, stated ages and biographies. The Minecraft line is still there, and so is the real-person contact framing at finding 4.
A product that meets the definition under one name meets it under another. The analysis at “Which regimes apply” above stands unchanged.
What this section is not
It is not a claim that the rename was a response to this assessment, to the report filed with Apple, or to anything else. Companies rename products routinely and for many reasons, and version 1.2.17 shipped with changes this assessment has not examined.
It is also not a re-assessment. Only the two items above were checked. No other finding was re-tested, and no inference should be drawn about the remaining findings from their absence here. They are neither confirmed as unchanged nor recorded as remediated.
What remediation looks like
Addressed to the operator, because they are the party who can act, and written so that other operators in this segment can use it. Nothing here is legal advice; questions of applicability and legal risk belong with counsel.
Sequencing: retain the age first. Every minor-specific obligation in every regime discussed depends on the operator being able to identify which accounts are minors. The product already collects an age and already evaluates it — the under-13 gate proves the value reaches the logic. Persisting it is the smallest change in this document and it unblocks everything else. Attempting any of the P1 items below without it means building minor-specific behaviour with no way to know which accounts it applies to.
P0 — this week, no engineering required
Change the open to calling real people default to off. This is a
configuration value. The asymmetry with open to texting real people, which
already defaults off, suggests the correct value is known.
Remediate the existing state, not only the default. Accounts created before the change already have the setting enabled, and they did not choose it. Changing a default protects future users; it does nothing for the ones already carrying a call badge. This is the part most easily missed.
Retain the age value at registration.
P1 — within thirty days
Resolve the parental consent gap. There are two honest ways to do it, and one is free. Terms §1.1 and Privacy Policy §11 both state that users aged 13 to 18 may use the service only with the consent of a parent or guardian. No such step exists. Either build the consent flow, so the documents describe the product; or remove the claim, so the product describes itself accurately.
Removing the claim costs nothing and can be done today. It is not a fix for the underlying question of minors on the platform, and it may create other exposure, so it is a matter for counsel. But asserting a control that does not exist is a worse position than asserting nothing, and it is the position the documents currently take.
Build and publish a suicide and self-harm protocol. § 22602(b) requires both: maintain a protocol that includes referral to crisis service providers, and publish details of it on the website. Build before publishing — a published protocol that is not operated is a representation about a control, and a worse exposure than the current disclaimer.
Add the suitability disclosure. § 22604. One line of copy. The operator has demonstrably written comparable language for medical and legal contexts.
Reconsider what an account declaring under 18 receives on arrival. At present that is two personas describing themselves as 20 and 22, both initiating contact unprompted, and a banner offering to continue the conversation on iMessage. Each is independently adjustable for accounts below a declared age threshold, once the age is retained.
P2 — backlog, but with dates attached
Age assurance beyond self-attestation. S9051B § 1804(1), if signed, attaches 1 January 2027 and will require a method that guards against circumvention, minimises retention, and — the limb most often missed — makes available more than one age assurance method, at least one of which either avoids government-issued identification or preserves the user’s anonymity as to the operator.
Instrument crisis referrals so they can be counted. § 22603 requires annual reporting to the California Office of Suicide Prevention from 1 July 2027, covering the number of referrals issued and the protocols used to detect and respond. This cannot be satisfied retrospectively by an operator that never recorded the number.
Review cross-session memory against § 1800(8)(F), which reaches information concerning health or wellbeing or matters personal to the user, acquired more than twelve hours previously or in any previous session. Terms §1.4(b) describes memory extraction in terms close to that language.
What would not be a fix
Raising the store age rating. It would not change the Terms, which admit users from 13, and it would not affect accounts already on the platform.
Publishing a protocol without operating one.
Treating the age gate as the problem. A self-attested gate is bypassable everywhere and that is not what this assessment criticises. The findings concern what the product does once a user has stated they are 13, and every one of them remains available to fix regardless of how the age arrives.
Method and limits
All testing was manual, through the publicly distributed iOS application and the operator’s public web properties. No automated access, no scraping, no API access, no traffic interception, and no attempt to bypass any paywall, authentication step, or verification mechanism.
Two accounts were registered, both via Google sign-in, both declaring age 13 at the registration screen. The second was created after deleting the first, to establish whether persona assignment and unprompted contact were reproducible or incidental. Only the second account was screenshotted, and every finding rests on that account and on the operator’s published documents.
The under-13 gate was tested once by entering 12, which the product refused. No attempt was made to defeat that refusal by any means other than entering a different number at the same prompt.
Public documents were read in full rather than searched for confirming passages. Absence claims list every location checked and the search terms used.
On the age gate, and what is not being criticised. A self-attested age gate can be defeated by entering a different number. That is true of most consumer services, is not unique to this product, and is not the criticism made here. The criticism concerns what the product does once a user has stated they are 13.
Limitations. Findings describe version 1.2.12 as observed on 5 August 2026, from a single region and device type, on iOS. Two accounts of roughly twenty minutes each establishes that a behaviour is not incidental; it does not establish frequency, and it does not establish that behaviours not observed cannot occur. This assessment cannot see the system prompt, the moderation pipeline, the classifier stack, retention practice, escalation staffing, or incident history. Where a control is recorded as failing, the honest reading is that the control was not observed to operate, not that no mechanism exists. Coverage was 6 of 25 controls; the 19 untested controls are not evidence of compliance. This is not a security assessment.
A note on the version number. The App Store listing records version 1.2.12 and the test device was offered no update, so the build assessed was 1.2.12. The application’s own settings screen displays “Version 1.2.5” beneath a “what’s new” heading. That appears to be stale in-app content rather than the installed build number. The App Store record is treated as authoritative.
Terms of service. The author registered accounts declaring an age of 13, which is not the author’s age. That is a misrepresentation to the operator and is disclosed here rather than omitted. It was necessary because the obligations most relevant to this product attach specifically to minors and to what a product does once a user has stated they are one, and no other method reaches them. The declared age is within the range the operator’s own Terms permit, so no age restriction was circumvented, but the statement was still not true. No other term was breached: no automated access, no circumvention, no commercial use, and no contact with any other user.
One state change is disclosed. Having observed and recorded that open to calling real people was enabled by default, the author disabled it, along with
the online status indicator, to prevent a discoverable card carrying a real name
from remaining live on a stranger-contact surface. The observation was recorded
before the change.
Why this product, and a disclosure about how it was found
The subject was identified while compiling a list of consumer AI companion products meeting three criteria fixed in advance: a companion or relationship framing in the store listing; an age rating permitting minors; and a size suggesting no dedicated trust and safety function.
That list was a prospecting list. The author provides paid trust and safety consulting, and the products on it were being screened as potential clients.
On registering an account, the observations above emerged within approximately twenty minutes. The product was immediately removed from the prospecting list and recorded as a research subject. No commercial approach has been made to this operator, none will be made while this assessment is open, and nothing in this document is contingent on any commercial relationship.
This is disclosed because it would be a reasonable thing for a reader to want to know, and because the alternative — an assessment of a company the author had privately considered selling to, undisclosed — would be worth criticising. An operator cannot be both a client and a subject, and where the two collide the assessment takes precedence.
Responsible disclosure
The findings were sent to Soul Global, Inc. at support@soul.app on 5 August 2026, the same day they were observed, with a seven-day window before publication.
That window is shorter than this author would normally allow. It is short because the conduct is live, affects accounts registered as minors, and at least part of it appears to be a configuration default rather than a change requiring engineering work.
A correction to that notice is recorded here. The email as sent misstated the assessment and notice date as 3 August 2026. The correct date for both is 5 August 2026. The error was the author’s and was identified after sending. The seven-day window has been calculated from the true date of receipt rather than from the date stated in error, so publication is on or after 12 August 2026, which is later than the date the notice itself gave. No party is disadvantaged by the correction, and it is recorded rather than quietly amended because a document that asks an operator to be accurate should hold itself to the same standard.
Aspects of the findings were reported to Apple App Store review on the same day, in parallel rather than as a consequence of any response. The operator was told this in the disclosure email. Publication was not made conditional on the operator’s reply, and the operator was told that too. That report was submitted through the reporting flow on the product’s App Store listing, which issues no acknowledgement or reference number, so this document records the author’s own account of having filed it and cannot corroborate it.
The window closed on 12 August 2026 with no response received. No inference is drawn from that silence. An operator has many reasons not to reply to an unsolicited email from someone it has never heard of, and no conclusion about this operator follows from the absence of one.
Publication was then held past that date, for a reason unconnected to the operator: the author’s professional and media liability insurance was still being placed, and binding cover before publishing was judged the correct sequence. That delay is the author’s own. It is recorded here because a disclosure record that logged only the operator’s silence, while quietly omitting the author’s own slipped date, would be selective.
Publication was rescheduled for 18 August 2026. Counted from the notice of 5 August, the operator therefore had thirteen days rather than the seven it was given, and the offer to correct any factual error or to have a response published in full remains open on the same terms. Nothing in this assessment was changed during the delay.
No response was received from the operator or from Apple at any point, and no factual correction or disputed interpretation was raised by anyone before publication.
One change to the product was observed. A re-check on 18 August, scoped in
advance to the two findings most likely to have moved, found that the age value
is now retained where on 5 August it was not. The default state of open to calling real people was unchanged. No other finding was re-tested, and no
inference should be drawn about the remaining findings from their absence
here. The findings continue to describe the product as observed on 5
August 2026, and any change to the product observed before publication is
recorded and noted at the finding it affects.
Where the operator identifies a factual error, this document is corrected and the correction noted at the finding it affects. Where the operator disagrees with an interpretation rather than a fact, both readings are presented. The corrections and right of reply policy sets out how.
Evidence and sources
Fifteen screenshots carrying visible device timestamps were captured on 5 August 2026 on version 1.2.12. Screenshots and session logs are retained privately and are available to the operator on request.
Three observations relied on above are not in the evidence set and are marked as such: the first account’s persona assignment, the persona message text on either account, and the submission to Apple. No claim rests on any of them alone.
Documentary sources, all retrieved 5 August 2026: the Terms of Service (last updated 26 March 2026), the Privacy Policy (last updated 6 April 2026), and the App Store listing. Both policy documents were captured again on 8 August 2026 and stored with SHA-256 hashes, so the passages quoted here remain verifiable if the published pages are later revised.
Statutory sources: N.Y. Gen. Bus. Law art. 47 §§ 1700–1704 and S9051—B bill text via nysenate.gov; Cal. Bus. & Prof. Code ch. 22.6 §§ 22601–22606 via leginfo.legislature.ca.gov. S9051B is passed but unsigned, so its text remains subject to change before its effective date.
Not in the evidence set: no photograph was uploaded and the photo album feature was not activated. No voice sample was provided and no voice conversation took place. No real user was contacted, viewed, called, or messaged through the Connect surface. No paid feature was purchased. No statement suggesting suicidal ideation or self-harm was sent to the product.
Independence
No client commissioned this work. The author has no commercial relationship with Soul Global, Inc., no financial position connected to it or its competitors, and no client who requested this work. It was self-funded and self-directed.
This document is not legal advice and does not create any professional relationship. Operators with questions about their obligations should consult qualified counsel.