🔮 Luvris is coming soon to the App Store and Google Play

✦ LEGAL ✦

Privacy Policy & Data Protection Notice

Last updated: 13 August 2026

This English translation is provided for convenience only. TheTurkish version is the legally binding text and governs in the event of any discrepancy.

1. Who we are (Data Controller)

Luvris (the "App") is a mobile application developed and operated byZYA AI TECH. Under Turkish Personal Data Protection Law no. 6698 ("KVKK"), the data controller is:

Luvris aims to operate in accordance with applicable KVKK provisions. Any registration and notification obligations arising from legislation will be fulfilled as required.

2. In short: our approach to data

The readings and content provided by Luvris are generated by artificial intelligence. This content is for entertainment, personal development and experience purposes only; it does not constitute legal, medical, psychological or financial advice.

Luvris is designed to run on the least data possible:

3. What data we process

DataExample / fieldWhere it comes from
Identity and contactEmail address, display nameYou, at sign-up; from the provider when signing in with Google/Apple
ProfileYour zodiac sign, your app settingsYou enter it
Reading contentDream texts, questions, tarot selections, reading interpretations (your reading history)You enter it / the App generates it
ImagesPalm and coffee cup photosYour camera/gallery (with your permission)
Confidant contentYour chat messages, mood recordsYou enter it
Derived insightsThemes Luvris remembers, chat summary, bond levelThe App generates it
Energy and purchasesYour ⚡ balance, spend/refund records, subscription statusThe App generates it
TechnicalDevice notification token, app version, platform, IP, crash and usage logsAutomatic

What we do not process: national ID number, home address, phone number, location, contacts, card/bank details (payments are taken byApple/Google; your card details never reach us).

About the content you enter: Users may enter text and visual content at their own discretion. This content is processed solely to provide the service the user requested and is not used for advertising profiling.

Palm photos are processed solely to generate the reading.They are not used for identity verification or biometric identification.

4. Why we process it and the legal basis

PurposeLegal basis (KVKK art. 5)
Creating your account, signing you inEstablishment/performance of a contract (art. 5/2-c)
Providing the reading, guidance and Confidant servicePerformance of a contract (art. 5/2-c)
Managing your energy balance and purchasesPerformance of a contract (art. 5/2-c)
Preventing abuse, fraud and bot trafficLegitimate interest (art. 5/2-f)
Fixing errors, measuring performanceLegitimate interest (art. 5/2-f)
Sending notificationsExplicit consent (you can revoke it from your device)
Luvris remembering you (Memory)Explicit consent (you can turn it off/clear it in Settings)
Keeping financial recordsLegal obligation (art. 5/2-ç)
Processing data abroadExplicit consent (see §6)

5. Who we share it with

We do not sell your data. We use the following service providers to run the service:

ProviderWhat forWhat reaches them
Google LLC / Google Ireland Ltd (Firebase)Authentication, database, servers, notifications, crash and usage measurementHosting of the data above
Google LLC (AI processing)Generating the reading and the Confidant's replyOnly the text/image of that request — your account details are not sent
Apple Inc. / Google LLC (app stores)Purchases and subscriptionsYour payment details (they do not reach us)
RevenueCat, Inc. (once paid features go live)Verifying subscription statusYour user ID, your subscription status
Google AdMob (once paid features go live)Rewarded adsAdvertising ID, device information

We may also share data with authorised public authorities where legally required (KVKK art. 8/2-a).

6. Where your data is processed

Luvris' technical infrastructure (servers and database) runs on globally used cloud providers, and these servers are located in the United States. Your personal data is therefore processed on the servers of US-based service providers (Google/Firebase) in order to provide the service to you.

This transfer relies on the explicit consent you give when you start using the app, and is carried out in accordance with applicable personal data protection legislation. You may withdraw your consent; because the entire service runs on this infrastructure, your account would then become unusable and will be deleted upon your request.

7. How long we keep it

DataPeriod
Account, profile, reading history, Confidant content, memoryFor as long as your account is open. You can delete reading records one by one; you can clear the memory
Reading photosNot stored on the server (dropped at the moment of processing); the copy stays only on your device
Daily contentDeleted when the account is deleted
Abuse prevention record (HMAC)Anonymised device/account hash retained for up to 180 days to prevent abuse of welcome bonuses or trial credits (welcome-farming); contains no direct or indirect personal data
Energy/purchase records10 years, even if the account is deleted — statutory retention and financial audit obligation. Contains no reading content
Feedback forms2 years
Crisis case recordThe limited record described in §11 becomes eligible for automatic deletion 30 days after it is created; technical deletion is generally completed within the following 24 hours. If you delete your account, this record is also deleted
Account deletion security recordTo prevent requests made with session information that may remain valid for a short time after account deletion from recreating deleted data, only the account's technical user ID and two timestamps (the deletion time and the time when the record becomes eligible for deletion) are kept. It contains no messages, reading text, feedback, email address, name or any other content. It cannot be read from the app and is accessible only on the server side. Deleting your account does not immediately delete this record. The record becomes eligible for automatic deletion on day 30; technical deletion is generally completed within the following 24 hours
Crash/usage logsThe provider's standard period (Firebase)

8. Deleting your account

From within the app: Settings → Account → Delete My Account. After two confirmations, your profile, reading history, Confidant data, memory and daily content arepermanently deleted; your sign-in record is removed.This action cannot be undone.

The financial record of energy and purchase transactions is retained for statutory periods. An anonymised HMAC hash is retained for up to 180 days to prevent welcome-bonus abuse; these two record types contain no readings, chats or photos.

In addition, the account deletion security record described in §7 is kept temporarily after account deletion to prevent late requests from recreating your data. Deleting your account does not immediately delete this record; it becomes eligible for automatic deletion on day 30. It contains only the technical user ID and two timestamps—no messages, reading text, feedback, email address, name or other content.

9. Your rights (KVKK art. 11)

By applying to the data controller, you have the right to: learn whether your personal data is being processed; request information if it has been processed; learn the purpose of processing and whether it is used in line with that purpose; know the third parties to whom it is transferred in Türkiye or abroad; request correction if it has been processed incompletely or inaccurately; request its erasure or destruction; request that correction/ erasure be notified to the third parties it was transferred to; object to an adverse outcome arising from analysis solely by automated systems; and claim compensation if you suffer damage due to unlawful processing.

You can send your requests to [email protected]; they are answered within 30 days at the latest. You can also delete your account from within the app without waiting on a deletion request (§8).

10. Children

Luvris is not an app aimed at children and we do not knowingly collect data from children. If you are under 18, you may use the App only with your parent's or guardian's permission. If we learn that we have processed a child's data, we delete it —[email protected].

11. Safety, Security and Crisis-Risk Management

Data is transmitted over an encrypted connection and protected server-side with access authorisation. Balance and purchase data can only be written by the server.

To help maintain service safety and review whether our safety mechanisms are working correctly, a limited incident record may be generated automatically when an AI model used in Companion, Reading Assistant or Palm Reading Assistant produces an indicator of crisis, self-harm or vital risk during an interaction.

The record contains the user's technical user identifier (UID), the relevant feature, the user's latest message in the request in which the indicator appeared, and up to four (4) preceding messages needed to review the context, along with technical timing, retention and review fields. The indicator is not a definitive diagnosis attached to a particular user message; it is derived from the AI model's response and may reflect the conversation as a whole.

Message content is not written to general system logs in Cloud Logging; it is not used for advertising or shared with independent third parties. The incident record is stored separately from general logs on our service-provider cloud infrastructure, cannot be read or written through the app, and is accessible only to authorized operations personnel. General system logs may contain the technical user identifier, incident ID and feature name so that the relevant record can be located.

Depending on the type of event, other operational information such as counters, status fields and technical error codes may also be recorded in general system logs; not every log entry contains all of these fields. Error logs contain no free-form text, only a standard error code and the operation in which the error occurred. System logs are kept for approximately 30 days and are not automatically deleted when you delete your account. This is a limitation we accept in order to operate the service securely; content information such as conversation topics is not written to system logs.

The incident record becomes eligible for automatic deletion 30 days after it is created; technical deletion is generally completed within the following 24 hours. If the user deletes their account, the incident record is deleted together with the account data.

This mechanism is not a healthcare service, medical diagnosis, professional intervention or automatic emergency-services notification. It is used to review the operation of the safety mechanism.

12. Changes

We may update this text. We will inform you in the app about significant changes. The effective date is stated above.

13. Contact

[email protected] · ZYA AI TECH ·Akatlar Mah., Beşiktaş / İstanbul, Türkiye