Privacy Policy

Vix – Your Manifestation Coach

Effective date: 9 July 2025

This Privacy Policy explains how Monday Labs Inc. ("Company", "we", "our", or "us") collects, uses, shares, and protects your information when you use Vix – Your Manifestation Coach mobile application, websites, and related services (collectively, the "Services"). It also describes your privacy rights and how you can exercise them.

By downloading, installing, registering for, accessing, or using the Services, you agree to this Privacy Policy and our Terms of Service.

1. Information We Collect

Account & Authentication

Data: Email address, name, avatar URL, Apple ID or Google ID tokens, Supabase session JWT

Source: You via Apple Sign‑In / Google Sign‑In / guest flow

Purpose: Create & secure your account

Legal Basis: Contract (Art. 6 (1)(b))

Demographic (voluntary)

Data: Gender / pronouns, age range, zodiac sign

Source: You during onboarding

Purpose: Personalise content & voice

Legal Basis: Consent (Art. 6 (1)(a))

User‑generated content

Data: Manifestation goals, desires, journal entries, mood logs

Source: You in‑app

Purpose: Provide AI content & tracking

Legal Basis: Contract / Consent

Device & Technical

Data: Device model, OS, IP address, Expo push token, network status, app version, internal UUID

Source: Automatically from your device

Purpose: App security, diagnostics, push notifications

Legal Basis: Legitimate interest (Art. 6 (1)(f))

Usage & Progress

Data: App‑open timestamps, streak counts, listening stats, achievements

Source: Automatically in‑app

Purpose: Feature analytics, habit tracking

Legal Basis: Legitimate interest

Subscription / Purchase

Data: Original purchase date, renewal & expiry dates, product ID, platform, RevenueCat event log, entitlement status

Source: RevenueCat webhook

Purpose: Fulfil premium features & bookkeeping

Legal Basis: Contract / Legal obligation (Art. 6 (1)(c))

Sensitive Data Flags (optional)

Data: Mental‑health intentions (e.g., anxiety, stress)

Source: You during onboarding

Purpose: Tailor affirmations

Legal Basis: Explicit Consent (Art. 9 (2)(a))

Audio Recordings

Data: Microphone input (voice prompts)

Source: You in‑app

Purpose: Transcribed to generate AI content (audio deleted immediately; transcript stored)

Legal Basis: Contract

Children's Data. The Services are not directed to anyone under 16 and we do not knowingly collect personal data from children under 16. If we discover such data, we will delete it.

2. How We Use Your Information

We use your information to:

  1. Provide & operate the Services (create affirmations, generate audio, save journals).
  2. Personalise content, voice, and notifications to your stated goals and mood.
  3. Maintain security (authenticate users, detect fraud, secure infrastructure).
  4. Measure & improve features, performance, and user engagement.
  5. Process payments & subscriptions and comply with tax / bookkeeping laws.
  6. Communicate with you, including service messages, push notifications, and marketing (you can opt out of marketing at any time).
  7. Comply with legal obligations and enforce our Terms of Service.

We do not use your data to train public AI models. Enterprise APIs (e.g., OpenAI, ElevenLabs) process prompts/transcripts only to return results and cannot retain or reuse them for their model training.

3. Sharing & Disclosure

We share your information only as necessary to operate the Services:

Supabase

Service: Cloud database & auth

Data Shared: All stored data

Safeguard: DPA & SCCs in place

OpenAI (Enterprise API)

Service: Language generation

Data Shared: Prompt text / context

Safeguard: No training / 30‑day retention cap

ElevenLabs (Enterprise API)

Service: Voice synthesis

Data Shared: Text prompts

Safeguard: No training

RevenueCat

Service: Subscription management

Data Shared: Purchase & entitlement data

Safeguard: DPA

Expo Services

Service: Push notifications, device constants

Data Shared: Device ID & token

Safeguard: DPA

Apple & Google

Service: Sign‑in & payments

Data Shared: Auth & transaction data

Safeguard: Platform terms

We do not sell your personal information.

4. International Data Transfers

Supabase and several processors store data in the United States. When we transfer data from the EU/UK/EEA, we rely on Standard Contractual Clauses or other approved safeguards under GDPR.

5. Retention & Deletion

Account profile & UGC

Until you delete the account or request erasure

Subscription & purchase records

7 years (tax & accounting)

Logs & diagnostics

12 months, unless needed for security investigations

Audio recordings

Deleted immediately after transcription

Local device cache (AsyncStorage)

Cleared on sign‑out or app uninstall

When you delete your account, we soft‑delete your profile, scramble personal identifiers, and queue associated content for permanent deletion within 30 days (unless retention is required by law).

6. Your Rights & Choices

Depending on your jurisdiction, you may have rights to:

  • Access a copy of your personal data.
  • Correct inaccurate data.
  • Delete your data ("right to be forgotten").
  • Port your data to another service.
  • Restrict or object to certain processing.
  • Withdraw consent at any time (does not affect prior lawful processing).
  • Opt out of marketing emails and push notifications.

You can exercise these rights via in‑app settings or by emailing privacy@vixapp.ai. We may verify your identity before responding. EU/UK users may lodge a complaint with their local data‑protection authority.

7. Security

We implement technical and organisational measures to protect your data, including:

  • TLS encryption in transit
  • Encryption‑at‑rest by Supabase (AWS KMS)
  • Role‑based access controls & MFA for staff
  • Regular security reviews & penetration testing
  • Responsible‑disclosure programme (security@vixapp.ai)

Despite these measures, no system is 100% secure; you use the Services at your own risk.

8. Cookies & Similar Technologies

The mobile App uses local storage and push‑notification tokens to operate. Our websites (if any) may use first‑party cookies for session management and analytics. We do not use third‑party advertising cookies.

9. Automated Decision‑Making & Profiling

Vix uses AI to generate personalised content based on your inputs and mood history. This profiling is non‑consequential—it affects only the wording and tone of affirmations—and has no legal or similarly significant effect on you.

10. Changes to This Policy

We may update this Privacy Policy from time to time. If we make material changes, we will notify you via the App or by email at least 7 days before the new policy takes effect. Continued use of the Services after the effective date constitutes acceptance of the updated Policy.

11. Contact Us

If you have questions or concerns about this Privacy Policy or our data practices, contact us at:

Monday Labs Inc.

123 Queen St W, Suite 456

Toronto, ON M5H 2N2, Canada

privacy@vixapp.ai