✦ LEGAL ✦
Privacy Policy & Data Protection Notice
Last updated: 13 August 2026
This English translation is provided for convenience only. TheTurkish version is the legally binding text and governs in the event of any discrepancy.
1. Who we are (Data Controller)
Luvris (the "App") is a mobile application developed and operated byZYA AI TECH. Under Turkish Personal Data Protection Law no. 6698 ("KVKK"), the data controller is:
- Data Controller: ZYA AI TECH
- Address: Akatlar Mah., Beşiktaş / İstanbul, Türkiye
- Contact: [email protected]
Luvris aims to operate in accordance with applicable KVKK provisions. Any registration and notification obligations arising from legislation will be fulfilled as required.
2. In short: our approach to data
The readings and content provided by Luvris are generated by artificial intelligence. This content is for entertainment, personal development and experience purposes only; it does not constitute legal, medical, psychological or financial advice.
Luvris is designed to run on the least data possible:
- Your reading photos (palm, coffee) are not stored on our servers. They are sent to be interpreted and dropped the moment the process ends; the image stays onlyon your own device.
- You can clear Luvris' memory whenever you want (Settings → Memory → "Clear memory").
- You can delete your account entirely from within the app — no need to email us or ask permission.
- We do not use reading content for ad targeting, and we do not sell it to third parties.
3. What data we process
| Data | Example / field | Where it comes from |
|---|---|---|
| Identity and contact | Email address, display name | You, at sign-up; from the provider when signing in with Google/Apple |
| Profile | Your zodiac sign, your app settings | You enter it |
| Reading content | Dream texts, questions, tarot selections, reading interpretations (your reading history) | You enter it / the App generates it |
| Images | Palm and coffee cup photos | Your camera/gallery (with your permission) |
| Confidant content | Your chat messages, mood records | You enter it |
| Derived insights | Themes Luvris remembers, chat summary, bond level | The App generates it |
| Energy and purchases | Your ⚡ balance, spend/refund records, subscription status | The App generates it |
| Technical | Device notification token, app version, platform, IP, crash and usage logs | Automatic |
What we do not process: national ID number, home address, phone number, location, contacts, card/bank details (payments are taken byApple/Google; your card details never reach us).
About the content you enter: Users may enter text and visual content at their own discretion. This content is processed solely to provide the service the user requested and is not used for advertising profiling.
Palm photos are processed solely to generate the reading.They are not used for identity verification or biometric identification.
4. Why we process it and the legal basis
| Purpose | Legal basis (KVKK art. 5) |
|---|---|
| Creating your account, signing you in | Establishment/performance of a contract (art. 5/2-c) |
| Providing the reading, guidance and Confidant service | Performance of a contract (art. 5/2-c) |
| Managing your energy balance and purchases | Performance of a contract (art. 5/2-c) |
| Preventing abuse, fraud and bot traffic | Legitimate interest (art. 5/2-f) |
| Fixing errors, measuring performance | Legitimate interest (art. 5/2-f) |
| Sending notifications | Explicit consent (you can revoke it from your device) |
| Luvris remembering you (Memory) | Explicit consent (you can turn it off/clear it in Settings) |
| Keeping financial records | Legal obligation (art. 5/2-ç) |
| Processing data abroad | Explicit consent (see §6) |
5. Who we share it with
We do not sell your data. We use the following service providers to run the service:
| Provider | What for | What reaches them |
|---|---|---|
| Google LLC / Google Ireland Ltd (Firebase) | Authentication, database, servers, notifications, crash and usage measurement | Hosting of the data above |
| Google LLC (AI processing) | Generating the reading and the Confidant's reply | Only the text/image of that request — your account details are not sent |
| Apple Inc. / Google LLC (app stores) | Purchases and subscriptions | Your payment details (they do not reach us) |
| RevenueCat, Inc. (once paid features go live) | Verifying subscription status | Your user ID, your subscription status |
| Google AdMob (once paid features go live) | Rewarded ads | Advertising ID, device information |
We may also share data with authorised public authorities where legally required (KVKK art. 8/2-a).
6. Where your data is processed
Luvris' technical infrastructure (servers and database) runs on globally used cloud providers, and these servers are located in the United States. Your personal data is therefore processed on the servers of US-based service providers (Google/Firebase) in order to provide the service to you.
This transfer relies on the explicit consent you give when you start using the app, and is carried out in accordance with applicable personal data protection legislation. You may withdraw your consent; because the entire service runs on this infrastructure, your account would then become unusable and will be deleted upon your request.
7. How long we keep it
| Data | Period |
|---|---|
| Account, profile, reading history, Confidant content, memory | For as long as your account is open. You can delete reading records one by one; you can clear the memory |
| Reading photos | Not stored on the server (dropped at the moment of processing); the copy stays only on your device |
| Daily content | Deleted when the account is deleted |
| Abuse prevention record (HMAC) | Anonymised device/account hash retained for up to 180 days to prevent abuse of welcome bonuses or trial credits (welcome-farming); contains no direct or indirect personal data |
| Energy/purchase records | 10 years, even if the account is deleted — statutory retention and financial audit obligation. Contains no reading content |
| Feedback forms | 2 years |
| Crisis case record | The limited record described in §11 becomes eligible for automatic deletion 30 days after it is created; technical deletion is generally completed within the following 24 hours. If you delete your account, this record is also deleted |
| Account deletion security record | To prevent requests made with session information that may remain valid for a short time after account deletion from recreating deleted data, only the account's technical user ID and two timestamps (the deletion time and the time when the record becomes eligible for deletion) are kept. It contains no messages, reading text, feedback, email address, name or any other content. It cannot be read from the app and is accessible only on the server side. Deleting your account does not immediately delete this record. The record becomes eligible for automatic deletion on day 30; technical deletion is generally completed within the following 24 hours |
| Crash/usage logs | The provider's standard period (Firebase) |
8. Deleting your account
From within the app: Settings → Account → Delete My Account. After two confirmations, your profile, reading history, Confidant data, memory and daily content arepermanently deleted; your sign-in record is removed.This action cannot be undone.
The financial record of energy and purchase transactions is retained for statutory periods. An anonymised HMAC hash is retained for up to 180 days to prevent welcome-bonus abuse; these two record types contain no readings, chats or photos.
In addition, the account deletion security record described in §7 is kept temporarily after account deletion to prevent late requests from recreating your data. Deleting your account does not immediately delete this record; it becomes eligible for automatic deletion on day 30. It contains only the technical user ID and two timestamps—no messages, reading text, feedback, email address, name or other content.
9. Your rights (KVKK art. 11)
By applying to the data controller, you have the right to: learn whether your personal data is being processed; request information if it has been processed; learn the purpose of processing and whether it is used in line with that purpose; know the third parties to whom it is transferred in Türkiye or abroad; request correction if it has been processed incompletely or inaccurately; request its erasure or destruction; request that correction/ erasure be notified to the third parties it was transferred to; object to an adverse outcome arising from analysis solely by automated systems; and claim compensation if you suffer damage due to unlawful processing.
You can send your requests to [email protected]; they are answered within 30 days at the latest. You can also delete your account from within the app without waiting on a deletion request (§8).
10. Children
Luvris is not an app aimed at children and we do not knowingly collect data from children. If you are under 18, you may use the App only with your parent's or guardian's permission. If we learn that we have processed a child's data, we delete it —[email protected].
11. Safety, Security and Crisis-Risk Management
Data is transmitted over an encrypted connection and protected server-side with access authorisation. Balance and purchase data can only be written by the server.
To help maintain service safety and review whether our safety mechanisms are working correctly, a limited incident record may be generated automatically when an AI model used in Companion, Reading Assistant or Palm Reading Assistant produces an indicator of crisis, self-harm or vital risk during an interaction.
The record contains the user's technical user identifier (UID), the relevant feature, the user's latest message in the request in which the indicator appeared, and up to four (4) preceding messages needed to review the context, along with technical timing, retention and review fields. The indicator is not a definitive diagnosis attached to a particular user message; it is derived from the AI model's response and may reflect the conversation as a whole.
Message content is not written to general system logs in Cloud Logging; it is not used for advertising or shared with independent third parties. The incident record is stored separately from general logs on our service-provider cloud infrastructure, cannot be read or written through the app, and is accessible only to authorized operations personnel. General system logs may contain the technical user identifier, incident ID and feature name so that the relevant record can be located.
Depending on the type of event, other operational information such as counters, status fields and technical error codes may also be recorded in general system logs; not every log entry contains all of these fields. Error logs contain no free-form text, only a standard error code and the operation in which the error occurred. System logs are kept for approximately 30 days and are not automatically deleted when you delete your account. This is a limitation we accept in order to operate the service securely; content information such as conversation topics is not written to system logs.
The incident record becomes eligible for automatic deletion 30 days after it is created; technical deletion is generally completed within the following 24 hours. If the user deletes their account, the incident record is deleted together with the account data.
This mechanism is not a healthcare service, medical diagnosis, professional intervention or automatic emergency-services notification. It is used to review the operation of the safety mechanism.
12. Changes
We may update this text. We will inform you in the app about significant changes. The effective date is stated above.
13. Contact
[email protected] · ZYA AI TECH ·Akatlar Mah., Beşiktaş / İstanbul, Türkiye