Privacy Policy

Last updated: September 10, 2026

1. Controller

DIGITAL ORTHODOX PATRISTIC LIBRARY LIMITED
RM 2904-05, 29/F, Universal Trade Centre

3 Arbuthnot Road, Central

Hong Kong

Registry number (CR No.): 80382404

Email: support@theosis-app.com

2. Representative in the European Union under Article 27 GDPR

As the controller is established outside the European Union, we have appointed a representative in the Union under Article 27 GDPR. You can contact both us and our representative with any data-protection matter.

Theosis OÜ
Tornimäe 5

10145 Tallinn

Estonia

Registrikood: 17060489

Email: support@theosis-app.com

3. Overview

THEOSIS processes personal data only for the purposes described in this Policy. The data involved depends on the features you use and the consents you give.

The internal Free notice labelled "Advertising" does not use an external advertising network. No data is shared with advertising third parties for that notice.

4. Account, Sign-In, and Consent Records

For your account, we process your email address, authentication data, internal user ID, and your chosen sign-in method with Apple, Google, or email address and password. For Apple or Google, we receive the account details released by the provider and a provider ID.

During onboarding, we store timestamps for acceptance of the Terms, privacy consent, and express consent to religious personalisation in the authentication metadata.

The legal basis for the account and sign-in is Article 6(1)(b) GDPR. We process consent records under Article 6(1)(c) GDPR where this is necessary to meet legal accountability duties.

5. Profile and Usage Data

We store profile details such as handle, photo, avatar, and visibility, as well as reading progress, notes, bookmarks, streaks, quest data, weekly goals, settings, device binding, and other account data required for the features you use.

Your activity can be visible privately, to followers only, or publicly according to your selection.

The legal basis is Article 6(1)(b) GDPR. We also process technical security data under Article 6(1)(f) GDPR. Our legitimate interest is secure and stable operation.

6. Religious Personalisation and Article 9 GDPR

Religious interests, goals, and usage signals may reveal religious beliefs. We use them for religious personalisation only with your express consent under Article 9(2)(a) and Article 6(1)(a) GDPR.

You can withdraw this consent at any time in "Privacy and Data". On withdrawal, stored interests and personalisation goals are removed from the local onboarding state. Withdrawal applies to future processing.

We process content you publish publicly in Social under Article 9(2)(e) GDPR because you have manifestly made it public yourself. We process direct messages and your questions in AI Chat only to provide the function you trigger yourself. Where this content reveals religious beliefs, this is based on your explicit consent, which you give by using the function after this notice. You end it by deleting the content or withdrawing consent.

7. Social Features

For social features, we process text and image posts, comments, Upsheep reactions, Story data and Story views, direct messages, follow relationships and requests, blocks, reports, topics, individual and shared streaks, and video rounds.

Your profile includes your handle, profile photo, and activity. Content is shown privately, to followers, or publicly according to your selected visibility. Direct messages are stored for sender and recipient.

Date of birth is processed by self-declaration to apply age tiers. Under 16, the Social area is read-only. From 16 to 17, direct messages are available only for mutual follows.

The legal basis is Article 6(1)(b) GDPR. We also rely on Article 6(1)(f) GDPR for community safety and prevention of misuse.

8. Optional Contact Matching

If you activate contact matching, no more than 2,000 phone numbers are hashed on the server with a secret HMAC key and compared with existing accounts. Names from your address book remain on your device.

An SMS code only verifies your phone number for this feature. It is not used for sign-in.

The legal basis is your consent under Article 6(1)(a) GDPR. You can stop using the feature and revoke contact permission in the system settings.

9. AI Chat

When you use Apologetics or Seraph, your questions are sent through OpenRouter to Anthropic Claude. Questions, answers, and the related history are stored as ai_messages and linked to your account.

Processing is necessary for the chat feature you request under Article 6(1)(b) GDPR. Section 6 also applies to religious personalisation.

ElevenLabs processes only fixed liturgical phrases. No user input or other user data is transmitted. fal.ai is used only for an administrative image pipeline without user data.

10. Moderation and Automated Decisions

Text and images are checked automatically with the OpenAI Moderation API. In addition, an OpenAI language model accessed through OpenRouter classifies the post text according to our rules. A rules engine then applies the moderation rules. Unclear cases receive human review.

Moderation data includes the reviewed content, technical scores, reports, decision, reasons, and measures. Measures can include removal, reduced reach, and temporary or permanent account suspension.

Automated moderation can significantly affect you. Under Article 22 GDPR, you can contact support@theosis-app.com to contest a decision, express your point of view, and request human review.

The legal basis is Article 6(1)(f) GDPR. Our legitimate interests are community safety, protecting other people, and enforcing the rules.

11. Report a Problem

When you report a problem in the App, we store your description, up to three screenshots you select, App version, build number, platform, and user ID in our Supabase database.

The report is used to analyse and fix the problem. It is accessible only to our team and is deleted when you delete your account.

The legal basis is Article 6(1)(b) GDPR for the support you request and Article 6(1)(f) GDPR for stability and error resolution.

12. Push, Device Binding, and Purchases

For push notifications, we process the push token, platform, and notification settings. You can withdraw push permission in the system settings. The legal basis is Article 6(1)(a) GDPR.

For device binding, we store device and switching information. Premium is bound to one device and optionally to a second device using the same Apple ID. A previous device is blocked for 28 days after a switch. The legal basis is Article 6(1)(b) GDPR and Article 6(1)(f) GDPR for prevention of misuse.

For purchases, we process product, platform, subscription status, and identifiers needed for assignment. Payment-method data is processed by the Apple App Store, Google Play, or Stripe for web purchases. RevenueCat reconciles store entitlements. The legal basis is Article 6(1)(b) GDPR.

13. Crash Reports, Analytics, Marketing, and Attribution

Sentry processes technical crash and error data and a user ID, but no real names. The legal basis is Article 6(1)(f) GDPR. Our legitimate interest is App stability and security.

PostHog EU processes product analytics and masked session replays. Microsoft Clarity processes usage sequences for UX analysis. Klaviyo processes email and push marketing. These services are activated only with your consent under Article 6(1)(a) GDPR.

AppsFlyer processes mobile attribution and campaign measurement. The Meta SDK and TikTok SDK process conversion data. This processing occurs only after your tracking consent. On iOS, the advertising identifier is used only with additional ATT permission. Without ATT permission, Meta and TikTok operate only in limited mode.

On the web, we load the following through Google Tag Manager only after your consent: Google Analytics 4 and Conversion Linker (Google Ireland Limited, Dublin), the Meta Pixel for page views, registration, and purchases (Meta Platforms Ireland Limited, Dublin), the TikTok Pixel for registration and purchases (TikTok Technology Limited, Dublin), and Klaviyo for attribution after registration (Klaviyo, Inc., Boston, USA).

You can withdraw tracking in "Privacy and Data". Withdrawal stops future collection and does not affect the lawfulness of earlier processing.

14. Hosting and Sign-In

Supabase, Inc., USA. Our database, authentication, and file storage run in the AWS region eu-central-1 in Frankfurt. Support access from third countries is safeguarded by the EU-US Data Privacy Framework and Standard Contractual Clauses.

Vercel, Inc., USA, provides web hosting, CDN, and edge functions.

Apple Inc., USA, processes Apple Sign-In, App Store purchases, and platform services.

Google LLC, USA, processes Google Sign-In, Google Play purchases, and platform services.

15. Billing, Communication, and Push

RevenueCat, Inc., San Francisco, USA. Transfers are based on Standard Contractual Clauses.

Stripe, Inc., USA, processes web payments and web subscriptions.

Resend, Inc., USA, sends transactional and series emails for the web service.

Klaviyo, Inc., USA, processes email and push marketing only with consent.

We send push notifications through Expo's push service (650 Industries, Inc., USA), which forwards them to Apple Push Notification Service and Google Firebase Cloud Messaging. Your push token and notification content are transferred. The basis is Standard Contractual Clauses.

16. Analytics, Marketing, and Error Services

Functional Software, Inc., USA, operates Sentry for crash and error diagnostics.

PostHog, Inc., USA, operates PostHog. Our product analytics is processed in the EU cloud region in Frankfurt.

Microsoft Corporation, USA, operates Microsoft Clarity.

AppsFlyer Ltd., Herzliya, Israel. The European Commission has issued an adequacy decision for Israel; processing in the USA is based on Standard Contractual Clauses.

Meta Platforms, Inc., USA, processes conversion data through the Meta SDK only with consent and under the ATT rules in Section 13.

TikTok Technology Limited, Dublin, Ireland. Transfers to affiliated companies outside the EEA are based on Standard Contractual Clauses.

Google LLC, USA, operates Google Analytics 4 and Google Tag Manager on the web only with consent.

17. AI Services

OpenRouter, Inc., USA, routes AI requests to the model provider used for the feature.

OpenRouter is also used to classify posts with an OpenAI language model; only the post text is transmitted, without account data.

Anthropic, PBC, USA, processes AI Chat questions through Claude.

OpenAI, Inc., USA, processes text and images for moderation.

ElevenLabs, Inc., New York, USA, processes only fixed liturgical phrases without user data.

fal.ai (Features and Labels, Inc.), San Francisco, USA, processes only administrative image requests without user data.

18. International Data Transfers

The controller is established in Hong Kong. Hong Kong has no adequacy decision. Data is stored in the European Union with Supabase in Frankfurt. Access by the controller from Hong Kong is based on Standard Contractual Clauses or binding internal rules.

For recipients outside the European Economic Area, we use a permitted transfer mechanism. According to the available documentation, Google, Apple, Vercel, Supabase, Stripe, Sentry, Resend, Klaviyo, Meta, Microsoft, OpenAI, and Anthropic rely on the EU-US Data Privacy Framework and Standard Contractual Clauses.

OpenRouter and ElevenLabs use Standard Contractual Clauses. Standard Contractual Clauses are documented for TikTok. Processing is limited to the purposes described above.

PostHog processes our instance's product analytics data in the EU cloud region in Frankfurt.

RevenueCat, Expo, and OpenRouter use Standard Contractual Clauses. AppsFlyer processes in Israel on the basis of the adequacy decision. TikTok Technology Limited is based in Ireland and transfers within its group on the basis of Standard Contractual Clauses.

19. Retention and Account Deletion

Request deletion of your THEOSIS account and data

You can request deletion of your THEOSIS account and associated data without having the app installed. Email support@theosis-app.com from the email address linked to your account with the subject “Delete THEOSIS account”. If you signed in with Apple or Google, or can no longer use that address, provide the associated account email address. We verify your authorization before deleting data. Do not send us a password or verification code.

Prepare email request

We generally retain account, profile, usage, social, message, AI Chat, support, streak, quest, device-binding, and phone-hash data until you delete your account or delete an individual item earlier.

Stories normally expire 24 hours after publication and are then removed by a cleanup job. Incomplete or failed Story uploads are marked for cleanup after one day without activity.

Account deletion in the native App is irreversible. The deletion process permanently removes content, unlinks RevenueCat, deletes the Klaviyo profile, and deletes the authentication user. You must cancel a store subscription separately before or after deletion.

On the web, confirmed account deletion is permanently completed after 30 days. It can be cancelled there until the scheduled deletion time.

Problem reports are deleted no later than account deletion. Processors delete the data after the end of the engagement or according to the periods set out in their contractual terms.

Moderation and suspension records are deleted with the account. Only where we continue to need them to defend against misuse, enforce a suspension, or meet legal obligations do we retain what is necessary for the duration of that obligation.

20. Your Rights

Request deletion of individual data: Email support@theosis-app.com with the subject “Delete THEOSIS data” and describe which data you would like removed. Your account can remain active. We verify your authorization before deletion.

Under the GDPR, you have rights of access, rectification, erasure, restriction of processing, and data portability. You can object to processing based on legitimate interests.

You may withdraw consent at any time for future processing. Manage tracking and religious personalisation in "Privacy and Data". Push and ATT permissions are also managed in the system settings.

THEOSIS has no data-export button. For data portability or any other right, email support@theosis-app.com. We may require evidence that the request is genuinely from you.

21. Children and Young People

We process the self-declared date of birth to apply the protection tiers for social features. Under 16, use is read-only. For 16- and 17-year-olds, direct messages are limited to mutual follow relationships.

THEOSIS may be used from the age of 13. Anyone under 16 needs the consent of a parent or legal guardian where the law of their country of residence requires it for consent to data processing. We may request evidence of consent and suspend accounts without the required consent.

Parents and guardians can contact support@theosis-app.com with data-protection questions.

22. Right to Lodge a Complaint

You can lodge a complaint with a data-protection authority, in particular with the authority in your country of residence or with the Andmekaitse Inspektsioon, Tatari 39, 10134 Tallinn, Estonia, at the seat of our EU representative.

23. Changes

We update this Privacy Policy when services, data flows, or the law change. We will inform you of material changes in an appropriate form. The current version is available in the App and through our published legal texts.