Privacy Policy

Last updated: March 2026

This English version is provided for your convenience. The legally binding version is the German Datenschutzerklärung.

Table of Contents

  1. Controller
  2. Overview
  3. Legal Bases
  4. Registration & Authentication
  5. Profile & Onboarding Data
  6. Chat & AI Processing
  7. Third-Party AI Providers
  8. Astrology Data
  9. Human Advisors
  10. Payments & Credits
  11. Hosting & Infrastructure
  12. Firebase Services
  13. AppStack (Marketing Attribution)
  14. Google Ads & Consent Mode
  15. Google Places API
  16. Website Analytics & Marketing Tools
  17. Push Notifications
  18. Images & Media
  19. Local Storage on Your Device
  20. Encryption & Security
  21. Third-Country Transfers
  22. Storage Periods
  23. Your Rights as a Data Subject
  24. Data Export & Account Deletion
  25. Third-Party Overview
  26. Supervisory Authority
  27. Changes to This Privacy Policy

1. Controller

The controller within the meaning of the General Data Protection Regulation (GDPR) is:

Digital App Group GmbH
Ferdinand-Koch-Str. 31
26133 Oldenburg
Germany

Email: digitalappgroupde@gmail.com
Phone: +49 441 3793132

2. Overview

This privacy policy explains which personal data we collect, process and use when you use our mobile app "Lisora" (the "App") and the associated website lisora.app, including the chat experience available directly on the website.

Lisora is a platform for spiritual guidance. Users can chat with AI-powered and human advisors specialising in astrology, life coaching and other spiritual topics. Chats are billed through a credit system.

We process personal data on the following legal bases:

Where we process special categories of personal data (for example birth data for astrological purposes), we do so on the basis of your explicit consent under Art. 9(2)(a) GDPR.

4. Registration & Authentication

4.1 Sign-in methods

You can register using the following methods:

4.2 Data collected at registration

Authentication is handled by our hosting provider Supabase (see section 11). Passwords are stored exclusively as cryptographic hashes and are never visible to us.

5. Profile & Onboarding Data

5.1 Required information

Only a display name is required to use the App.

5.2 Voluntary information (onboarding)

For personalised guidance you can optionally provide:

Your zodiac sign is calculated from your date of birth. This data is used exclusively to create horoscopes and natal charts. Birth data can also be asked for and stored during a conversation with an AI advisor.

5.3 Profile picture

You can upload a profile picture (JPEG, max. 500 KB). It is stored in our cloud storage and is not publicly visible to other users.

6. Chat & AI Processing

6.1 Chat messages

When you chat with an advisor, your messages are stored on our servers. Each message contains the content, the sender type (user, AI or human advisor), the status and the timestamp.

6.2 AI processing

With AI advisors, your message is processed as follows:

  1. Your message is transmitted to a third-party AI provider together with the previous conversation history (see section 7).
  2. The AI provider generates a response based on your context, your profile data (if provided) and the advisor profile.
  3. The response is stored and delivered to your device in real time.

6.3 Context memory

To improve the quality of guidance we store one context text per user. It contains summaries of earlier conversations and allows the AI advisor to refer back to previous topics. In addition, memories (for example important life events you mentioned) are stored per advisor to enable more personal guidance.

6.4 Image messages

You can send images in the chat (max. 5 MB, JPEG/PNG/WebP). They are stored in our cloud storage and analysed by the AI advisor to give a context-aware response.

7. Third-Party AI Providers

To generate AI responses we use OpenRouter (OpenRouter, Inc., USA), which routes requests to the following AI models:

7.1 Data transmitted

The following data is transmitted to the AI providers:

7.2 Processing by AI providers

The AI providers process your data exclusively to generate the response. The AI models are not trained on your personal data, as we use API access. The providers may temporarily log requests in accordance with their own privacy policies. Standard Contractual Clauses (SCC) apply to transfers to third countries.

8. Astrology Data

To create natal charts and transit calculations we use an external astrology API. Your date of birth, time of birth and place of birth (transmitted as geographic coordinates) are sent to the service. Results are cached server-side (per date and location) to avoid unnecessary repeat requests.

Horoscopes are created based on your zodiac sign and pre-calculated transit data. Daily affirmations are generated automatically and can be delivered as push notifications.

9. Human Advisors

In addition to AI advisors we also offer chats with human advisors (human takeover). In this case a human advisor can take over an ongoing chat. The human advisor has access to the previous message history of that chat session to ensure a seamless experience. Human advisors are bound to confidentiality.

10. Payments & Credits

10.1 Payment processing

Payments for credit purchases made in the App are processed by the respective app stores (Apple App Store / Google Play Store). Purchases made on our website are processed by Stripe (Stripe Payments Europe, Ltd., Ireland / Stripe, Inc., USA). In both cases we never receive your credit card or bank details. In-app purchases and credit balances are managed via RevenueCat (RevenueCat, Inc., USA).

10.2 Data processed by RevenueCat

10.3 Per-minute billing

During a chat your credit balance is charged per minute. The cost per minute varies by advisor. The billing data (start time, duration, credits used) is stored with us.

10.4 Transaction history

We keep a transaction ledger of all credit movements (purchases, deductions, refunds, bonuses). This data is retained for tax and commercial-law purposes for the statutory retention periods.

10.5 Bonuses

Under certain conditions we grant bonus credits (for example a welcome bonus on first registration, a referral bonus, a comeback bonus). Grants are logged.

10.6 Referral programme

Lisora offers a referral programme. If you share a referral link and another person registers through it, both parties receive bonus credits. For this we store the association between referrer and referred user as well as the respective bonus amounts.

11. Hosting & Infrastructure

We use Supabase (Supabase, Inc., USA) as our backend platform. Supabase provides:

11.1 Server location

Our Supabase project is hosted in the EU region (eu-central-1, Frankfurt). Your data is primarily stored within the EU.

11.2 Access control

All database access is protected by Row Level Security (RLS). Every user can only access their own data. Server-side functions use privileged credentials that are available only in the secure server environment.

12. Firebase Services

In the App we use the following services from Google Firebase (Google Ireland Ltd., Ireland / Google LLC, USA):

12.1 Firebase Analytics

To analyse App usage we collect anonymised usage statistics (app opens, screen views, basic interactions). No clear-text names or message contents are transmitted to Firebase Analytics. This is based on our legitimate interest in improving our services.

12.2 Firebase Crashlytics

We use Crashlytics to detect and fix app crashes. In the event of an error, technical information is transmitted (device type, operating system, app version, error message and stack trace). A pseudonymised user ID is used to correlate crash reports. This association is removed when your account is deleted.

12.3 Firebase Cloud Messaging (FCM)

We use Firebase Cloud Messaging to deliver push notifications. A device-specific token is stored for this purpose (see section 17). The token is deleted when you sign out.

12.4 Firebase Remote Config

We use Remote Config to control app configuration parameters server-side. No personal data is transmitted to Remote Config.

13. AppStack (Marketing Attribution)

We use AppStack as a marketing attribution tool. AppStack records events such as registrations, sign-ins and purchases to measure the effectiveness of our marketing campaigns.

Data processed by AppStack:

On iOS devices, AppStack tracking is only activated with your explicit consent via the App Tracking Transparency framework (ATT).

We use Google Mobile Ads (Google LLC, USA) to display advertisements within the App, together with Google Consent Mode: before any personalised advertising data is collected, your consent is requested via a consent form (UMP, User Messaging Platform). Without consent, no personalised ads are shown.

15. Google Places API

For the place search when entering your place of birth we use the Google Places API (Google LLC, USA). Your search input is transmitted to Google to display place suggestions. The selected place is stored as a name and geographic coordinates. There is no GPS-based location tracking: the location data comes exclusively from your manual input.

16. Website Analytics & Marketing Tools

On our website lisora.app we use the following services. Each of them is loaded only after you have given your consent via the cookie banner (Art. 6(1)(a) GDPR); without consent, none of these tools are active. You can withdraw your consent at any time by clearing your cookies for lisora.app.

17. Push Notifications

With your consent we send you push notifications. A device-specific token (FCM token) is stored for this purpose. We distinguish the following types:

On iOS, permission is requested via the system dialog. On Android, the operating system's standard permissions apply. The FCM token is updated automatically when you change devices and deleted when you sign out or delete your account.

18. Images & Media

18.1 Profile pictures

Profile pictures are stored as JPEG files (max. 500 KB) in our cloud storage. Access is restricted to authenticated users. You can change or delete your profile picture at any time.

18.2 Chat images

Images sent in the chat (max. 5 MB, JPEG/PNG/WebP) are stored in a separate storage area. These images are deleted together with all other data when your account is deleted.

18.3 Device permissions

To upload images, the App needs access to your camera or photo library. This permission is requested via the operating system and can be revoked at any time in your device settings.

19. Local Storage on Your Device

The App stores the following data locally on your device:

All locally stored data is deleted when you sign out or delete your account.

20. Encryption & Security

We apply the following security measures:

21. Third-Country Transfers

Some of our service providers are based in the USA. Transfers of personal data to the USA take place on the basis of the following safeguards:

22. Storage Periods

Data categoryStorage period
User account & profileUntil account deletion
Chat messagesUntil account deletion
Context memory & memoriesUntil account deletion
Birth data & zodiac signUntil account deletion or withdrawal of consent
Profile and chat imagesUntil account deletion
Credit transactions10 years (German commercial/tax law, Sec. 257 HGB, Sec. 147 AO)
Billing data10 years (commercial/tax law)
Push tokensUntil sign-out or account deletion
Crashlytics data90 days (Firebase default)
Analytics data14 months (Firebase default)
Referral dataUntil both accounts are deleted
Feedback ratingsUntil account deletion

Deleted accounts are first marked as deleted and then permanently removed from the database by an automated process.

23. Your Rights as a Data Subject

Under the GDPR you have the following rights:

To exercise your rights, please contact digitalappgroupde@gmail.com.

24. Data Export & Account Deletion

24.1 Data export

You can export your data directly in the App (Settings, then Data Export). The export includes your profile data, chat histories, transaction history, billing data and feedback ratings in JSON format.

24.2 Account deletion

You can delete your account directly in the App (Settings, then Delete Account). Account deletion performs the following steps:

  1. Termination of any running billing sessions
  2. Irrevocable deletion of all data on our servers (profile, chats, messages, billing data, feedback, referrals, push tokens, stored images)
  3. Deletion of all locally stored data on your device
  4. Removal of the Crashlytics user identifier
  5. Sign-out from RevenueCat
  6. Sign-out from the user account

Note: transaction data subject to statutory retention periods is anonymised and retained for the required period. Purchases already made through the app stores cannot be reversed by us; please contact Apple or Google for those.

25. Third-Party Overview

ProviderPurposeLocationTransfer basis
Supabase, Inc.Backend, database, auth, storageUSA (servers: EU)SCC
OpenRouter, Inc.AI request routingUSASCC
Google LLCAI model, Analytics, Crashlytics, FCM, Ads, Places, Play IntegrityUSADPF
Anthropic, PBCAI modelUSADPF
RevenueCat, Inc.In-app purchases, credit managementUSASCC
Stripe Payments Europe, Ltd.Payment processing (website purchases)Ireland / USADPF
Apple Inc.App Store, Sign in with Apple, payment processingUSADPF
Meta Platforms Ireland Ltd.Ad measurement on the website (Meta Pixel, consent-based)Ireland / USADPF
Microsoft CorporationSession analytics on the website (Clarity, consent-based)USADPF
DataFastWebsite visitor and revenue analytics (consent-based)see provider's siteSCC / DPF
AppStackMarketing attribution (App)see provider's siteSCC / DPF
Astrology APINatal charts, transit calculationssee provider's siteSCC

26. Supervisory Authority

You have the right to lodge a complaint with a data protection supervisory authority. The authority responsible for us is:

Die Landesbeauftragte für den Datenschutz Niedersachsen
(State Commissioner for Data Protection of Lower Saxony)
Prinzenstraße 5
30159 Hannover, Germany
Phone: +49 511 120-4500
Email: poststelle@lfd.niedersachsen.de
Website: lfd.niedersachsen.de

27. Changes to This Privacy Policy

We reserve the right to adapt this privacy policy as needed to reflect changes in the law, in our technology or in our features. The current version is always available at lisora.app/privacy. In the event of significant changes we will inform you via an in-app notification or push message.

Questions about privacy? Contact us any time at digitalappgroupde@gmail.com or by phone at +49 441 3793132.