Privacy Policy

Last updated: August 2026

This is a translation of our German privacy policy. In case of any discrepancy, the German version prevails.

1. Controller

The controller within the meaning of the General Data Protection Regulation (GDPR) is:

Digital App Group GmbH
Ferdinand-Koch-Str. 31
26133 Oldenburg
Germany

Email: digitalappgroupde@gmail.com
Phone: +49 441 3793132

2. Overview

This privacy policy explains which personal data we collect, process and use when you use our mobile app “Lisora” (the “app”) and the associated website lisora.app.

Lisora is an entertainment application for spiritual topics. Users chat with advisor characters about astrology, tarot and life questions. Usage is billed through a credit system.

Note on AI: The advisors in Lisora are fictional characters. Their replies are generated by AI models. To make that possible, your chat messages and, if you provide them, your birth details are transmitted to an AI service provider (see sections 6 and 7).

We process personal data on the following legal bases:

  • Performance of a contract (Art. 6 (1) (b) GDPR): registration, provision of the chat functions, processing of credit purchases and billing
  • Consent (Art. 6 (1) (a) GDPR): push notifications, app tracking (ATT on iOS), voluntary submission of birth details, processing of your messages by the AI provider
  • Legitimate interest (Art. 6 (1) (f) GDPR): troubleshooting and stability (Crashlytics), fraud prevention (Play Integrity), basic usage analytics
  • Legal obligation (Art. 6 (1) (c) GDPR): retention of transaction data under tax and commercial law

Where we process special categories of personal data, for example birth details for astrological purposes, we do so on the basis of your explicit consent pursuant to Art. 9 (2) (a) GDPR.

4. Registration and authentication

4.1 Sign in methods

You can register using the following methods:

  • Sign in with Apple: transmission of email address and name via OpenID Connect secured with PKCE. Apple allows you to hide your real email address.
  • Sign in with Google: transmission of email address and name via OAuth 2.0.
  • Email and password: direct registration with an email address and a password you choose.
  • Email OTP: sign in with a six digit one time code sent to your email address.

4.2 Data collected during registration

  • Email address (required)
  • Name (optional, transmitted automatically by Apple and Google)
  • User ID (automatically generated UUID)
  • IP address and user agent (automatically on server requests)
  • Timestamp of registration

Authentication runs through our hosting provider Supabase (see section 11). Passwords are stored as hashes only and are not visible to us.

5. Profile and onboarding data

5.1 Required information

Using the app only requires a display name.

5.2 Optional information (onboarding)

For personalised content you can optionally provide the following data:

  • Gender
  • Date of birth
  • Time of birth (hour and minute)
  • Place of birth including geographic coordinates, determined via Google Places

Your star sign is calculated from your date of birth. This data is used solely to create horoscopes and natal charts. Birth details may also be asked for and stored during a conversation with an AI character.

5.3 Profile picture

You can upload a profile picture (JPEG, max. 500 KB). It is stored in our cloud storage and is not publicly visible to other users.

6. Chat and AI processing

6.1 Chat messages

When you chat, your messages are stored on our servers. Each message contains the content, the sender type (user, AI or human advisor), the status and the timestamp.

6.2 AI processing

Your message is processed as follows:

  1. Your message is transmitted together with the previous conversation history to a third party AI provider (see section 7).
  2. The AI provider generates a reply based on your context, your profile data (if available) and the character profile.
  3. The reply is stored and delivered to your device in real time.

For users in the EU we obtain your consent to this processing before the first message is sent.

6.3 Context memory

To improve conversation quality we store one context text per user. It contains summaries of earlier conversations and allows the AI character to refer back to previous topics. In addition, memories such as important life events you have mentioned are stored per character.

6.4 Image messages

You can send images in the chat (max. 5 MB, JPEG, PNG or WebP). They are stored in our cloud storage and analysed by the AI model so it can give a contextual reply.

7. Third party AI providers

To generate AI replies we use the service OpenRouter (OpenRouter, Inc., USA), which forwards the requests to the following AI models:

  • Google Gemini (Google LLC, USA)
  • Anthropic Claude (Anthropic, PBC, USA)

7.1 Data transmitted

The following data is transmitted to the AI providers:

  • Your chat messages (content of the current session)
  • Context summary of earlier conversations
  • Your profile context (birth details and star sign, if provided)
  • Uploaded images, if any, for image analysis
  • Character profile and conversation context

7.2 Processing by the AI providers

The AI providers process your data solely to generate the reply. The AI models are not trained on your personal data, because we use API access. The providers may log requests temporarily in accordance with their own privacy policies. Standard contractual clauses apply to transfers to third countries.

8. Astrology data

To create natal charts and transit calculations we use an external astrology API. Your date of birth, time of birth and place of birth (as geographic coordinates) are transmitted to that service. The results are cached on our servers to avoid unnecessary repeat requests.

Horoscopes are created based on your star sign and precalculated transit data. Daily affirmations are generated automatically and can be delivered as push notifications.

9. Human advisors

In exceptional cases a human advisor can take over an ongoing chat (human takeover). The human advisor then has access to the previous message history of that chat session. Human advisors are bound to confidentiality.

10. Payment data and credits

10.1 Payment processing

Payments for credit purchases are processed through the respective app stores (Apple App Store and Google Play Store). We do not receive credit card or bank details. In app purchases and credit balances are managed through RevenueCat (RevenueCat, Inc., USA).

10.2 Data processed by RevenueCat

  • Your user ID, to assign purchases
  • Email address and display name
  • Purchase history (packages, timestamps, amounts)
  • Current credit balance

10.3 Per minute billing

During a chat your credit balance is billed by the minute. The cost per minute varies by character. The billing data (start time, duration, credits used) is stored by us.

10.4 Transaction history

We keep a transaction ledger of all credit movements (purchases, deductions, refunds, bonuses). This data is retained for tax and commercial law purposes in line with the statutory retention periods.

10.5 Bonuses and referral programme

Under certain conditions we grant bonus credits, for example a welcome bonus on first registration, a referral bonus or a returning user bonus. These grants are logged. For the referral programme we additionally store the link between the referring and the referred person as well as the respective bonus amounts.

11. Hosting and infrastructure

We use Supabase (Supabase, Inc., USA) as our backend platform, providing the following services:

  • Database: PostgreSQL database for user data, messages and transactions
  • Authentication: management of user accounts and sign in methods
  • Storage: cloud storage for profile pictures and chat images
  • Realtime: WebSocket connections for real time message delivery
  • Serverless functions: server side processing of AI requests, billing, notifications and data management

11.1 Server location

Our Supabase project is hosted in the EU region (eu-central-1, Frankfurt). Your data is stored primarily within the EU.

11.2 Access control

All database access is protected by row level security. Each user can only access their own data. Server side functions use privileged credentials that are available only in the secure server environment.

12. Firebase services

We use the following Google Firebase services (Google Ireland Ltd., Ireland and Google LLC, USA):

12.1 Firebase Analytics

To analyse app usage we collect anonymised usage statistics (app opens, screen views, basic interactions). No plain text names or message content is transmitted to Firebase Analytics.

12.2 Firebase Crashlytics

To detect and fix app crashes we use Crashlytics. In the event of an error, technical information is transmitted (device type, operating system, app version, error message and stack trace). A pseudonymised user ID is used to correlate error reports. This link is removed when an account is deleted.

12.3 Firebase Cloud Messaging

We use Firebase Cloud Messaging to send push notifications. A device specific token is stored for this purpose (see section 16). The token is deleted when you sign out.

12.4 Firebase Remote Config

We use Remote Config to control app configuration parameters from the server. No personal data is transmitted to Remote Config.

13. AppStack (marketing attribution)

We use AppStack as a marketing attribution tool. AppStack records events such as registrations, sign ins and purchases in order to measure the effectiveness of our marketing campaigns.

Data processed by AppStack:

  • Anonymous device ID
  • Registration and sign in events
  • Purchase events (amount and currency, no payment details)
  • Platform (iOS or Android)

On iOS devices, AppStack tracking is only enabled with your explicit consent through the App Tracking Transparency framework.

We use Google Mobile Ads (Google LLC, USA) to display advertising inside the app, together with Google Consent Mode: before personalised advertising data is collected, your consent is obtained through a consent form (User Messaging Platform). Without consent, no personalised ads are shown.

15. Google Places API

To search for locations when you enter your place of birth we use the Google Places API (Google LLC, USA). Your search input is transmitted to Google in order to display location suggestions. The selected place is stored as a name and geographic coordinates. No GPS location is determined, the location data comes solely from your manual input.

16. Push notifications

With your consent we send you push notifications. A device specific token is stored for this purpose. We distinguish the following types:

  • Chat messages: notification about new messages in your chats
  • Daily affirmations: messages generated daily based on current transit data
  • Availability: notification when a favourite character comes online
  • Engagement notifications: reminders after longer periods of inactivity

On iOS the permission is requested through a system dialog. On Android the standard operating system permissions apply. The token is refreshed automatically when you change devices and deleted when you sign out or delete your account.

17. Images and media

17.1 Profile pictures

Profile pictures are stored as JPEG files (max. 500 KB) in our cloud storage. Access is restricted to authenticated users. You can change or delete your profile picture at any time.

17.2 Chat images

Images sent in the chat (max. 5 MB, JPEG, PNG or WebP) are stored in a separate storage area. These images are deleted along with all other data when you delete your account.

17.3 Device permissions

To upload images the app needs access to your camera or photo library. This permission is requested through the operating system and can be revoked at any time in your device settings.

18. Local storage on your device

The app stores the following data locally on your device:

  • Settings: name, birth details, onboarding status, language setting, cached credit balance for offline display
  • Offline queue: messages sent without an internet connection are cached locally and synchronised once the connection is restored
  • Chat cache: recently displayed messages and character data are stored locally to reduce loading times

All locally stored data is deleted when you sign out or delete your account.

19. Encryption and security

We apply the following security measures:

  • Transport encryption: all connections between your device, our servers and third party providers use TLS 1.2 or higher.
  • Authentication: access tokens with limited validity and automatic renewal.
  • PKCE: Proof Key for Code Exchange for OAuth sign ins, in particular Sign in with Apple.
  • Row level security: access control at database level, so each user can only read and modify their own data.
  • Passwords: passwords are stored exclusively as cryptographic hashes.
  • Play Integrity (Android): device integrity checks for payment related operations to prevent fraud.

20. Transfers to third countries

Some of our service providers are based in the USA. Personal data is transferred to the USA on the basis of the following safeguards:

  • EU-US Data Privacy Framework: Google, Anthropic and Apple are certified under the framework.
  • Standard contractual clauses: with providers that are not certified under the framework, for example Supabase, RevenueCat and OpenRouter, we have agreed standard contractual clauses pursuant to Art. 46 (2) (c) GDPR.

21. Retention periods

Data categoryRetention period
User account and profileUntil the account is deleted
Chat messagesUntil the account is deleted
Context memory and memoriesUntil the account is deleted
Birth details and star signUntil the account is deleted or consent is withdrawn
Profile and chat imagesUntil the account is deleted
Credit transactions10 years (German commercial and tax law)
Billing data10 years (German commercial and tax law)
Push tokensUntil sign out or account deletion
Crashlytics data90 days (Firebase default)
Analytics data14 months (Firebase default)
Referral dataUntil both accounts are deleted
Feedback ratingsUntil the account is deleted

Deleted accounts are first marked as deleted and then removed permanently from the database by an automated process.

22. Your rights as a data subject

Under the GDPR you have the following rights:

  • Right of access (Art. 15 GDPR): you can request information about the personal data we process.
  • Right to rectification (Art. 16 GDPR): you can request correction of inaccurate data. Profile data can be changed directly in the app.
  • Right to erasure (Art. 17 GDPR): you can request deletion of your data, see section 23.
  • Restriction of processing (Art. 18 GDPR): under certain conditions you can request restriction of processing.
  • Data portability (Art. 20 GDPR): you can receive your data in a structured, machine readable format, see section 23.
  • Right to object (Art. 21 GDPR): you can object to processing that is based on legitimate interest.
  • Withdrawal of consent: you can withdraw consent at any time with effect for the future.

To exercise your rights, please contact digitalappgroupde@gmail.com.

23. Data export and account deletion

23.1 Data export

You can export your data directly in the app (Settings, Data export). The export contains your profile data, chat histories, transaction history, billing data and feedback ratings in JSON format.

23.2 Account deletion

You can delete your account directly in the app (Settings, Delete account). The following steps are carried out:

  1. Ongoing billing sessions are ended
  2. All data on our servers is deleted irrevocably (profile, chats, messages, billing data, feedback, referrals, push tokens, stored images)
  3. All locally stored data on your device is deleted
  4. The Crashlytics user identifier is removed
  5. You are logged out of RevenueCat
  6. You are signed out of your user account

Please note: transaction data subject to statutory retention periods is anonymised and kept for the prescribed period. Purchases already made through the app stores cannot be reversed, please contact Apple or Google for those.

24. Overview of third party providers

ProviderPurposeLocationTransfer safeguard
Supabase, Inc.Backend, database, authentication, storageUSA (servers: EU)SCC
OpenRouter, Inc.Routing of AI requestsUSASCC
Google LLCAI model, Analytics, Crashlytics, FCM, Ads, Places, Play IntegrityUSADPF
Anthropic, PBCAI modelUSADPF
RevenueCat, Inc.In app purchases, credit managementUSASCC
Apple Inc.App Store, Sign in with Apple, payment processingUSADPF
AppStackMarketing attributionsee provider's siteSCC / DPF
Astrology APINatal charts, transit calculationssee provider's siteSCC

25. Supervisory authority

You have the right to lodge a complaint with a data protection supervisory authority. The authority responsible for us is:

Die Landesbeauftragte für den Datenschutz Niedersachsen
Prinzenstraße 5
30159 Hannover, Germany
Phone: +49 511 120-4500
Email: poststelle@lfd.niedersachsen.de
Website: lfd.niedersachsen.de

26. Changes to this privacy policy

We reserve the right to adapt this privacy policy to changes in the law, technical changes or new features. The current version is always available at lisora.app/en/privacy. We will inform you about material changes by in app notification or push message.

Questions about privacy? Write to us any time at digitalappgroupde@gmail.com or call +49 441 3793132.