Home
Legal

Privacy Policy for AYLUVI

This policy explains what personal data AYLUVI processes, why, on which basis, with whom it is shared and how long it is kept. It describes the app as currently implemented.

Effective date: 31 July 2026

Controller and contact details

Sebahatin Siourous
Karl-Köglspergerstr. 23
80939 München
Germany

Email: helloayluvi@hotmail.com

Provider information is also available on the imprint page.

Scope of this policy

This policy applies to the AYLUVI mobile app, the AYLUVI website at ayluvi.com and the AYLUVI backend services used by them. It does not apply to third-party apps or platforms you share your creations to, which are governed by their own policies.

This text is provided for transparency. It is not individualized legal advice and does not constitute a guarantee of compliance in every jurisdiction.

Minimum age

AYLUVI is intended for users aged 16 and older. It is not directed at younger children.

Account creation and authentication

You can create an account with an email address and a password. Authentication is processed through Supabase Auth. Passwords are handled by that authentication service; AYLUVI does not have access to readable passwords.

Each account is identified by a user identifier (UUID) which is stored alongside your content and settings. Session tokens issued after sign-in are stored locally on your device and sent with requests to AYLUVI's backend so it can recognise you.

Guest use and guest-session identifiers

You can use AYLUVI without an account. In guest mode the app generates a random guest-session identifier, stores it on your device and sends it with requests so your creations, limits and saved items stay associated with your device. It does not contain your name or email address, but it is a pseudonymous identifier.

If you later create an account, guest content created on that device can be transferred to your account.

Manifest personalization information

If you complete the Manifest setup, the answers you provide (such as life stage, work and relationship context, what you want to focus on, current challenges and preferred tone) are stored in AYLUVI's database and used to personalise generated Manifest content. This setup is optional and can be edited or skipped.

Moments, Manifest and Ritual content

Content you create — chosen category, vibe, drink, goal, your own written intentions and the resulting texts — is stored in AYLUVI's database together with your user identifier or guest-session identifier, plus timestamps and status flags such as whether an item was claimed, saved or prepared for sharing.

Photos and transient AI processing

When you select or take a photo for a Moment or a Ritual, the app prepares an optimised copy and transmits it to the AI service so the generated text can fit your actual scene. The photo therefore leaves your device.

According to the current implementation, photos are not persistently stored in AYLUVI's own database or file storage. Any further handling of the transmitted image by the AI service is subject to that provider's terms.

AI-generated content

Texts in Moments, Manifest and Rituals are produced by an AI model through the Lovable AI Gateway. AYLUVI sends the selected category, vibe, goal, language, any personalization answers relevant to the request and — for Moments and Rituals — the photo. Generated output is stored with your creation so you can revisit it.

AI-generated content may be inaccurate and is intended for creative and reflective use only. It is not advice.

Library and saved content

When you save a creation to your library, AYLUVI records that it was saved and when, so it can be listed and reopened. The underlying content stays in the tables described above.

Usage counters and first-party interaction events

AYLUVI counts how many AI creations you make per feature and month in order to apply Free and Pro limits fairly. It also records first-party interaction events such as which screen was opened, which template was chosen and whether a share was started, together with your user or guest identifier and a timestamp.

These events are stored in AYLUVI's own database and are used to operate and improve the product. No third-party analytics or advertising SDK is used, and no advertising identifier is collected.

AYLUVI Waitlist

On the AYLUVI website you can voluntarily join the launch waitlist. The email address you enter is used to send you a confirmation email and, afterwards, AYLUVI launch-related updates. Registration uses double opt-in: until you click the confirmation link, the signup stays pending and you receive no launch updates.

Data stored for a waitlist signup:

  • Email address
  • Waitlist status (pending, confirmed or unsubscribed)
  • Signup and confirmation timestamps
  • Signup source (for example, the welcome page)
  • Version of the consent wording you agreed to

No IP address, device fingerprint or browser identifier is intentionally collected for the waitlist. The confirmation link contains only a random one-time token; only a hash of that token is stored.

The legal basis is your consent, given by ticking the consent box before submitting the form. Email delivery is provided through Resend.

You can withdraw your consent at any time. Until a technical unsubscribe link is included in every email, withdrawal is also possible by contacting helloayluvi@hotmail.com. Waitlist data is deleted when it is no longer required for the waitlist purpose or after withdrawal, subject to any legally required proof or retention needs.

Subscriptions and purchases

AYLUVI Pro is sold through the app store on your device. Payment is processed by the store operator; AYLUVI never receives your payment card details.

AYLUVI stores your plan status, entitlement source, subscription status, the current period end and the subscription identifier supplied by the subscription provider so that Pro features can be unlocked on your account.

RevenueCat and Google Play

Subscription entitlements are managed with RevenueCat. Your AYLUVI user identifier is used as the RevenueCat customer identifier, and purchase information is exchanged between the store, RevenueCat and AYLUVI's backend to verify whether Pro is active.

On Android, purchases are handled by Google Play Billing. Google and RevenueCat process purchase and transaction records under their own terms and retention obligations.

Local storage and session information

The app stores the following on your device:

  • the authentication session issued after sign-in
  • the guest-session identifier
  • your Manifest streak counter
  • a flag recording that onboarding has been completed

These are functional and are not used for advertising or cross-site tracking. AYLUVI does not use advertising or third-party analytics cookies, which is why no cookie banner is shown. Clearing the app's data or your browser storage removes these local values.

Service providers

  • Supabase (via Lovable Cloud) — authentication, database and account emails
  • Lovable — hosting of the website and backend endpoints, and the AI Gateway used for text generation
  • The AI model provider reached through that gateway — transient processing of your prompt inputs and, for Moments and Rituals, the photo
  • RevenueCat — subscription entitlement management
  • Google (Google Play Billing / Google Payments) — purchase and payment processing on Android

These providers process data on AYLUVI's behalf or, in the case of store payment processing, under their own responsibility.

International data transfers

Some of these service providers, or their sub-processors, may process data outside the EU/EEA. Where that happens, such transfers are intended to rely on the safeguards applicable under Chapter V of the GDPR, such as the European Commission's standard contractual clauses or an adequacy decision. You can request further information using the contact address above.

Purposes and legal bases

  • Providing accounts, generation features, the library and subscription entitlements — performance of a contract (Art. 6(1)(b) GDPR) where applicable.
  • Service security, prevention of misuse, enforcement of usage limits and first-party improvement of the product — legitimate interests (Art. 6(1)(f) GDPR) where applicable.
  • Retention of records that must be kept, for example in connection with taxation or store transactions — compliance with a legal obligation (Art. 6(1)(c) GDPR) where applicable.
  • Consent (Art. 6(1)(a) GDPR) is only relied upon where the app actually asks you for it, for example device permissions for camera or photo access requested by the operating system.

Retention and deletion criteria

Data is kept for as long as it is needed for the purpose it was collected for. In practice:

  • account data, creations, saved library items and personalization answers are kept while the account exists and until deletion is completed
  • guest data is kept while it remains associated with the guest-session identifier on the device
  • usage counters are kept for the period they apply to and for a limited follow-up period needed to operate limits correctly
  • subscription and entitlement records are kept while the entitlement is relevant and for as long as required for accounting or legal purposes
  • technical logs generated by hosting and infrastructure providers are kept according to those providers' configurations

Where an exact period is not technically or contractually fixed, retention is determined by these criteria rather than a set number of days.

Account and data deletion

You can delete your account directly in the app under You → Delete account. The deletion requires your password, is carried out immediately, and removes your AYLUVI account together with the data stored with it, including the customer record held for your account by RevenueCat.

If you cannot use the in-app option, you can also request deletion by email.

See the account and data deletion page for what deletion covers and what it does not cover.

Deleting your AYLUVI account does not cancel a Google Play or Apple subscription; those must be cancelled separately in the relevant store.

Exported or shared content

Images you export or share leave AYLUVI's control. Copies already saved to your device or posted to other platforms cannot be recalled or deleted by AYLUVI.

Security

Traffic between the app and AYLUVI's backend is encrypted in transit. Access to stored data is restricted by authentication and server-side authorisation checks, and requests are scoped to the account or guest session they belong to. No system can be guaranteed to be completely secure.

Your rights

Under the GDPR you have the right to:

  • access the personal data held about you
  • have inaccurate data corrected
  • have your data erased
  • have processing restricted
  • receive your data in a portable format
  • object to processing based on legitimate interests
  • withdraw consent where processing is based on consent, without affecting prior processing

To exercise these rights, contact helloayluvi@hotmail.com. Identity verification may be required before a request is carried out.

Complaints to a supervisory authority

You may lodge a complaint with a data protection supervisory authority. The authority responsible for the controller is:

Bayerisches Landesamt für Datenschutzaufsicht (BayLDA)
Promenade 18
91522 Ansbach
Germany

You may also contact another competent supervisory authority, for example in the EU member state of your residence or workplace.

Changes to this policy

This policy may be updated as AYLUVI develops. The current version is always available at ayluvi.com/privacy, and the effective date below indicates when it last changed.

Effective date

31 July 2026