Who We Are
Data Controller: LVIM LTD, a UK-based company.
Registered Address: 20 Wenlock Road, N1 7GU, London, United Kingdom.
Contact Email: support@vitrai.app
This Privacy Policy explains how Vitrai, operated by LVIM LTD, collects, uses, and protects your personal information. If you have any questions about this Policy or your data rights, please contact us at the email above.
Information We Collect
We only collect information necessary to operate the Vitrai app and manage your account. This includes:
Account Information
When you register, we collect your email address and a password (stored in a hashed form for security).
Subscription & Purchase Data
Details about your subscription plan, in-app purchases, and transaction history (managed via Apple App Store and RevenueCat, and in the future, Google Play). We do not collect or store full payment card information – purchases are handled by the app store providers.
Usage Data (Token Activity)
We record your in-app activity such as the number of tokens/credits you use, which text-based features you access, and your engagement streaks. These tokens and stats are tied to your account. This data helps us manage your token balance, track your progress, and prevent abuse.
Community Interaction Data
When you interact with community features (e.g., clicking 'Amen' on a Daily Prayer Intention), we collect aggregate, anonymous statistics to display community engagement.
To prevent abuse (such as spamming reactions), we may temporarily process your User ID or Device ID to enforce limits (e.g., one reaction per day). This linkage is transient and is reset daily; we do not create a permanent history of which specific prayer intentions you have supported.
AI Chat Content (Transient)
The content of your prompts/questions and the AI's responses. Important: These messages are processed in real-time by our AI provider (such as OpenAI's GPT-4 or successor models) to generate replies, but we do not store the content of your chats on our servers after delivering the response.
The chat data is handled transiently – once the AI response is provided, the prompt and response are not retained in our databases.
While we do not store chat content on our own servers after delivering a response, our AI provider (OpenAI) may retain API request logs for up to 30 days for abuse monitoring purposes, in accordance with their Data Processing Addendum. These logs are held by OpenAI, not by LVIM LTD, and are not used to train foundational AI models.
AI Transparency Marking: In compliance with EU AI Act Article 50, AI-generated outputs may carry machine-readable metadata or digital watermarks to verify the content's origin as machine-generated. This data is used solely for transparency and regulatory compliance.
Special Category Data (Religious Beliefs)
As a spiritual application, Vitrai may process data that reveals your religious or philosophical beliefs (e.g., prayers, spiritual biographies, faith-based questions). Under GDPR Article 9 and equivalent frameworks (such as KVKK Article 6), this constitutes 'Special Category Personal Data'.
Processing of this data is strictly voluntary and requires your separate explicit consent, which is requested independently from these General Terms. You may withdraw this consent at any time without affecting the lawfulness of prior processing.
Local Device Storage (Journal)
Certain features (such as 'Sticky Journal') store data locally on your device using SQLite. By default, journal data resides solely on your device and LVIM LTD cannot access it unless you explicitly enable cloud synchronization.
Device and Technical Information
We may automatically receive basic technical details when you use Vitrai, such as your device type, operating system, IP address, and device identifiers. We use this information only for security and performance monitoring (for example, to detect and throttle excessive usage or protect against fraudulent activity).
Customer Support Communications
If you contact us for support or feedback, we will collect the information you choose to provide in that correspondence (such as your email and the content of your message) in order to assist you and improve our services.
How We Use Your Information
We use the collected information for the following purposes:
We collect usage data to manage token allocation and ensure compliance with our Fair Use Policy.
- Provide and Improve Our Services: To create and maintain your account, authenticate your login, and allow you to use Vitrai's features.
- AI Content Generation: Your prompts and messages are sent to our third-party AI service (OpenAI) to generate the responses you see in the app.
- Subscription Management: To manage your subscription status and token balance.
- Communication: To send you important service-related communications (e.g., account verification, password resets).
- Customer Support: To respond to your inquiries and troubleshoot issues.
- Security and Abuse Prevention: To monitor, investigate, and prevent fraudulent, unauthorized, or unlawful activities.
- Legal Obligations: To comply with applicable laws, regulations, and legal processes.
Companion AI Disclosures
VitrAI is an AI-based system that simulates human-like spiritual interaction. It is NOT a human being. While it may personalize its tone, language, and responses to create a supportive experience, all interactions are machine-generated.
Data collected during your sessions (such as your preferences and interaction patterns) is used to personalize the AI experience for you. This personalization does not constitute profiling for the purpose of automated decision-making with legal effects.
In compliance with regional safety regulations (such as California SB 243), you will receive periodic in-app notifications during extended sessions reminding you that you are interacting with an AI system.
Legal Basis for Processing (GDPR / UK DPA)
If you are in a region governed by data protection laws like the EU's GDPR or the UK DPA 2018, we process your personal data under the following legal bases:
- Contractual Necessity: Necessary for the performance of our contract with you (the Terms of Service).
- Legitimate Interests: To pursue our legitimate interests in maintaining and improving our app's security and performance.
- Explicit Consent: For the processing of Special Category Data (religious beliefs), we rely on your separate, freely given, and withdrawable explicit consent under GDPR Article 9(2)(a).
- Legal Obligation: If we are subject to a legal obligation that requires processing of your data.
International Data Transfers
Your personal data may be transferred to and processed in countries outside your country of residence, including the United States. This occurs primarily when your prompts are sent to OpenAI for AI processing.
- Our primary database infrastructure is hosted within the European Economic Area (EEA), which provides strong data protection standards for users worldwide. For users outside the EEA, this means your data benefits from EU-level privacy protections.
- We ensure appropriate safeguards are in place for international transfers, including Standard Contractual Clauses (SCCs) with our service providers.
- OpenAI operates under a Data Processing Agreement that includes EU Standard Contractual Clauses.
- For UK users, we comply with the UK International Data Transfer Agreement (IDTA) requirements.
Data Retention
We retain personal data only as long as necessary for the purposes described above, or as required by law.
- Account Information: Stored for as long as your account is active.
- AI Chat Data: Transient only. Each message is used in the moment to generate a reply and is not saved for long-term use.
- Activity Logs: Short duration for security or debugging, then periodically overwritten or anonymized.
- Account Deletion: Upon deletion, we erase or anonymize data from production. Backups purged within 30 days.
- Subscription Records: Retained as long as required for financial reporting and compliance.
Data Sharing and Disclosure
We do not share your personal information with third parties for their own marketing. We share data with trusted providers who process data on our behalf:
AI Service Provider (OpenAI)
Prompts are sent to OpenAI (GPT-4 or successor models) in real-time. OpenAI only receives the text you input. Content is not stored by us after you receive the answer. Your data is not used to train foundational AI models.
Cloud Hosting & Data Storage
We use secure infrastructure providers compliant with global standards (e.g., Railway, MongoDB) to host our servers and databases. While our hosting provider may change in the future, we will ensure they meet or exceed our current privacy and security levels.
Subscription Management & Payments
Apple App Store and RevenueCat handle transactions and status management. We do not store credit card numbers.
Your Rights
Depending on your residency or location (GDPR, UK DPA, LGPD, PIPA, etc.), you have certain rights:
- Right to access, correction, and deletion ("right to be forgotten").
- Right to restrict or object to certain processing.
- Right to data portability.
- Right to withdraw consent at any time.
- Right to lodge a complaint with a supervisory authority (e.g., UK Information Commissioner's Office at ico.org.uk, or your local data protection authority).
- Right to Object to Automated Decision-Making: Under GDPR Article 22, you have the right to contest any AI-generated analysis and request human review of decisions that have significant effects on you.
Global Privacy Control (GPC)
We recognize and honor Global Privacy Control (GPC) signals sent by your browser or device. When a GPC signal is detected, we automatically disable non-essential analytics tracking for that session, in compliance with applicable US state privacy laws (including CCPA/CPRA).
Children's Privacy
Vitrai is not intended for children under the minimum age specified in our Terms of Service (13 years in most countries, 16 years in certain EU jurisdictions).
- We do not knowingly collect personal information from children under these age limits.
- If we learn that we have collected personal information from a child without appropriate parental consent, we will take steps to delete that information promptly.
- Parents or guardians who believe their child has provided us with personal information should contact us immediately at support@vitrai.app.
Data Breach Notification
In the event of a personal data breach that is likely to result in a high risk to your rights and freedoms, we will:
- Notify the relevant supervisory authority (e.g., UK ICO) within 72 hours of becoming aware of the breach, as required by GDPR/UK DPA.
- Notify affected users without undue delay if the breach is likely to result in a high risk to their rights and freedoms.
- Document all data breaches, including the facts, effects, and remedial actions taken.
California Residents (CCPA)
If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA):
- Right to Know: You can request information about the categories and specific pieces of personal information we have collected about you.
- Right to Delete: You can request deletion of your personal information, subject to certain exceptions.
- Right to Opt-Out: We do not sell your personal information. If this changes, we will provide a "Do Not Sell My Personal Information" link.
- Right to Non-Discrimination: We will not discriminate against you for exercising your CCPA rights.
- To exercise these rights, contact us at support@vitrai.app.
Third-Party Links
Within Vitrai, we may provide links to external content. This Privacy Policy no longer applies if you follow a link to an external site.
Bible Licensing
Some Bible translations in the App are subject to specific licensing terms. A full list of these licenses, source information, and links is available within the App under Settings → Bible Licenses.
Data Accuracy and Corrections
Scripture Accuracy: If you notice formatting or content errors resulting from XML-to-JSON conversion of Bible texts, please report them to support@vitrai.app. We prioritize correcting these technical discrepancies promptly.
Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or legal obligations.
Material Changes: If we make material changes (e.g., changes in the types of personal data we collect, how we use it, or with whom we share it), we will notify you by posting a prominent notice within the App or via email before the changes take effect.
Non-Material Changes: Non-material changes (e.g., clarifications, formatting, or contact information updates) will be effective immediately upon posting the updated version with a new 'Effective Date'.
Your continued use of the App after we post changes constitutes your acceptance of the updated Policy. If you do not agree with any changes, you should stop using the Service and delete your account.
You can find the updated Privacy Policy at lvim.io/vitrai/privacy.