Privacy Policy
DaVal Co., Ltd. (주식회사 데벨, the "Company") has established and publishes this Privacy Policy in accordance with the Personal Information Protection Act of Korea and other applicable laws, to protect users' personal information and to handle users' concerns about personal information quickly and smoothly. This policy applies to the mobile application "Vibe Bible" (the "Service") provided by the Company.
- Purposes of processing
- Personal information we process and how we collect it
- Sensitive information
- Retention and destruction
- Processors
- International transfers
- Provision to third parties
- Your rights and how to exercise them
- Security measures
- Automatic collection
- Children under 14
- Privacy officer
- Remedies for infringement
- Changes to this policy
1. Purposes of Processing Personal Information
The Company processes personal information for the following purposes. If a purpose changes, the Company will take the steps required by applicable law, such as obtaining separate consent.
- Member management: identifying and authenticating members through Apple and Google sign-in, applying the one-account-one-device policy, preventing misuse, processing account deletion, delivering notices and responding to inquiries.
- Today's Verse recommendations: choosing one verse each day. For users who are subscribed and have completed their profile, the Company's server uses artificial intelligence (the processor described in Section 5) to choose a week of verses and short reflections in advance, based on the profile. For all other users, this is worked out on the user's device.
- Providing counsel: finding Bible passages based on the concern the user writes, generating and verifying an interpretation and returning it, and showing the user their counsel history again. For users who have entered a profile, answers take the profile into account. When the Service is used in English, the user's region is also used, only while the answer is being prepared, to show crisis resources for the place where the user is (see Section 3).
- Providing Paid Services: confirming Store payments, managing subscription status, restoring subscriptions, and handling payment-related disputes.
- Service safety and quality: reviewing counsel in which signs of crisis were detected or output that failed verification, analyzing errors, and limiting requests to prevent abuse.
2. Personal Information We Process and How We Collect It
| Category | Items | How it is collected |
|---|---|---|
| Member identification (required) | Sign-in provider (Apple or Google), the user identifier issued by the provider, and email address (the relay address if Apple's "Hide My Email" is used) | Passed on by the provider when you sign in with Apple or Google |
| Profile (optional) | The name you'd like to be called, birth year, gender, occupation, life stage, marital status, faith stage and concerns | Entered by the user during onboarding or in My Page. Every item can be skipped. Items other than the name can be entered only while subscribed |
| Counsel (created while using the Service) | The concern the user writes, the Counsel Output generated (quoted verses, interpretation, risk-level assessment and any crisis contacts shown), the time of the request, and the language used | When the user requests counsel |
| Subscription (created while using the Service) | Subscription status, period, payment platform, the Store's transaction identifier (Apple originalTransactionId or Google purchase token), and Store environment (production/test) | After a Store payment, the app sends the receipt to the Company's server and the Company verifies it with the Store |
| Progress display (iOS, optional and temporary) | A Live Activity push token used to show counsel progress on the Lock Screen | Issued by the device when counsel is requested; no longer needed once the counsel ends |
| Collected automatically | IP address, request time and path, response status, app version and error records | Generated automatically in the hosting provider's logs while server requests are processed |
3. Sensitive Information
- The "faith stage" and "concerns" items in the profile relate to religion and may be sensitive information under the Personal Information Protection Act of Korea. The Company does not require these items, and processes them for Today's Verse recommendations and counsel only if the user chooses to enter them. The input screen explains this, and by entering them the user is deemed to consent to this processing. They can be deleted at any time in My Page.
- The concerns written for counsel may include sensitive matters such as the user's health, state of mind, faith or family relationships. The Company processes this text only to create Counsel Output and does not use it for any other purpose (advertising, profiling or model training). By requesting counsel, the user consents to this processing. We recommend not writing other people's real names, contact details and the like.
- The Service automatically assesses counsel text for signs of crisis such as self-harm or suicide. This assessment is made so that the Service can show the user contacts for urgent help. The result (risk level) is kept with the counsel record and is not provided to third parties. When the Service is used in English, the region set on the device and the country inferred from the IP address of the connection are used only while an English response is being prepared, to choose which crisis contacts to show; those contacts come from a fixed list the Company has checked against official sources. The region and the country are not stored: they are erased when that counsel finishes, whether or not it succeeds. Only the crisis contacts chosen for that counsel are saved, with the counsel record, as part of the Counsel Output. When the Service is used in Korean, the app does not send the device region.
4. Retention and Destruction
| Information | Retention period | Basis |
|---|---|---|
| Member identification, profile | Deleted immediately when the account is deleted | User consent |
| Counsel text and output | Deleted immediately when the account is deleted | User consent |
| Device region and connection country (English counsel only) | Used only while that counsel is being prepared and erased when it finishes; not kept with the counsel record | To choose crisis contacts (Section 3) |
| Subscribers' personalized Today's Verse plans | Deleted immediately when the account is deleted | User consent |
| Live Activity push token | Kept with the counsel record after the counsel ends; deleted when the account is deleted | User consent |
| Subscription status, Store transaction identifiers | When the account is deleted, the link to the account is removed; records of the payment and period are kept for 5 years | Act on the Consumer Protection in Electronic Commerce (records of contracts and payments) |
| Sign-in sessions and revocation records | Deleted on sign-out or account deletion; sessions ended by signing in on another device are kept for 30 days | To tell the user why the session ended |
| Access records (IP, request time and path) | 3 months | Protection of Communications Secrets Act |
| Records of consumer complaints and disputes | 3 years | Act on the Consumer Protection in Electronic Commerce |
- When an account is deleted, the Company replaces the name and email with values that cannot identify anyone, and deletes the profile, counsel records, subscribers' personalized Today's Verse plans (which are stored on the Company's server) and sign-in connection information without delay. For Sign in with Apple accounts, the Company notifies Apple to disconnect the account.
- Personal information whose retention period has ended, or whose purpose has been fulfilled, is destroyed without delay. Electronic files are deleted in a way that cannot be recovered. Information kept because the law requires it is stored separately from other personal information and is not used for any purpose other than the reason it is kept.
5. Processors
The Company entrusts the following processing of personal information to processors in order to provide the Service. When entering into these agreements, the Company manages and supervises the processors, as required by applicable law, so that they handle personal information safely.
| Processor | Work entrusted | Retention and use period |
|---|---|---|
| Vercel Inc. | Server (API) hosting and storage of access logs | Until the agreement ends or the log retention period expires |
| Neon Inc. | Database hosting (storing member, profile, counsel and subscription information) | Until the agreement ends or the user asks for deletion |
| Anthropic PBC | Artificial intelligence processing of counsel text (choosing passages, generating the interpretation, verification), and Today's Verse recommendations based on subscribers' profiles (choosing verses, generating reflections) | Up to 30 days after processing (for the processor's abuse monitoring); never used for model training |
| Apple Inc. | Sign in with Apple, App Store payments and subscription management, TestFlight, delivery of push notifications (Live Activity) | According to Apple's policies |
| Google LLC | Google sign-in, Google Play payments and subscription management | According to Google's policies |
6. International Transfers of Personal Information
All of the processors above are located in the United States, and the Company transfers personal information outside Korea as follows. Users may refuse the international transfer, but in that case they cannot use all or part of the Service (sign-in and counsel).
| Recipient | Country | Items transferred | When and how | Purpose | Retention and use period |
|---|---|---|---|---|---|
| Vercel Inc. (privacy@vercel.com) | United States | All items in Section 2, and the region described in Section 3 (passing through the server) | Over the network (TLS) while the Service is used | Server operation | The periods in Section 4 |
| Neon Inc. (privacy@neon.tech) | United States | Member identification, profile, counsel records, Today's Verse plans and subscription information (and, until an English counsel finishes, the region described in Section 3) | Stored over the network (TLS) while the Service is used | Database storage | The periods in Section 4 |
| Anthropic PBC (privacy@anthropic.com) | United States | Counsel text, and the profile items needed for recommendations (age range calculated from birth year, gender, occupation, life stage, marital status, faith stage and concerns). Email and name are not sent | Over the network (TLS) when counsel is requested and when a subscriber's Today's Verse is chosen | Generating Counsel Output and Today's Verse recommendations | Up to 30 days |
| Apple Inc. | United States | Apple account identifier, payment transaction identifiers and Live Activity push token | At sign-in, payment and counsel progress display | Authentication, payment confirmation and notification delivery | According to Apple's policies |
| Google LLC | United States | Google account identifier and payment purchase token | At sign-in and payment | Authentication and payment confirmation | According to Google's policies |
7. Provision of Personal Information to Third Parties
The Company does not provide users' personal information to third parties beyond the purposes in Section 1. The exceptions are when the user has separately consented, or when an investigative agency, court or similar body requests it through lawful procedures based on the law.
8. Your Rights and How to Exercise Them
- You may at any time access, correct or delete your personal information, or ask the Company to stop processing it. You can edit or delete your profile yourself in My Page › Edit Profile, and you can delete your whole account immediately with My Page › Delete Account.
- For requests that can't be made in the app (for example, access to log records), write to business@daval.ai. The Company will handle the request within 10 days after verifying your identity.
- You may also exercise your rights through a legal representative or a person you have authorized. In that case, a power of attorney as required by applicable law must be submitted.
- Personal information deleted at your request cannot be recovered. Information kept because the law requires it may be excluded from a deletion request; in that case, the Company will tell you why.
9. Security Measures
- Encryption in transit: all communication between the app and the server, and between the server and processors, is encrypted with TLS.
- No stored credentials: the Company does not create or store passwords, and stores sign-in session tokens only as hash values. A leaked database alone cannot be used to take over a session.
- Minimal collection and transfer: email and name are left out of what is sent to the artificial intelligence model provider for counsel.
- Access control: administrative access to the database and servers is given only to the smallest necessary number of people, and service credentials are kept outside the code repository.
- Logging and review: security-related events, such as failed payment verification or authentication, are logged, and the payment and authentication code paths go through independent code review.
- Safe deletion: personal information is deleted immediately when an account is deleted, and information kept because the law requires it is separated from identifying information.
10. Automatic Collection
The Service is provided as a mobile app and does not use cookies. It does not use advertising identifiers or analytics SDKs either. If you use widgets or Live Activities, your device's operating system issues the tokens needed for that purpose, and the Company uses them only for that feature.
11. Personal Information of Children Under 14
The Company does not collect personal information from children under the age of 14, and children under 14 cannot sign up as members. If the Company learns that it has collected personal information from a child under 14, it deletes that information without delay.
12. Privacy Officer
The Company has designated a privacy officer who oversees the processing of personal information and handles users' complaints and requests for remedy.
| Privacy officer | Seungmin Park (CEO) |
|---|---|
| business@daval.ai | |
| Phone | 1555-0629 (from within Korea). From outside Korea, please contact us by email. |
You can send any privacy-related question, complaint or request for remedy that arises while using the Service to the contact above, and the Company will answer and handle it without delay.
13. Remedies for Infringement
If you need to report a privacy infringement or get advice about one, you can contact the following organizations in Korea.
- Personal Information Infringement Report Center (Korea Internet & Security Agency): 118 (from within Korea, no area code) / privacy.kisa.or.kr
- Personal Information Dispute Mediation Committee: 1833-6972 (from within Korea) / www.kopico.go.kr
- Cyber Investigation Division, Supreme Prosecutors' Office: 1301 (from within Korea, no area code) / www.spo.go.kr
- Cyber Investigation Bureau, Korean National Police Agency: 182 (from within Korea, no area code) / ecrm.police.go.kr
14. Changes to This Privacy Policy
- This policy applies from its effective date, and it may be added to, removed from or modified as laws, policies or the Service change. Changes are announced on this page and in the app starting 7 days before they take effect. Changes that are important to your rights (such as changes to the items collected, the purposes, provision to third parties or international transfers) are announced 30 days in advance, and consent is obtained again where necessary.
- Matters not set out in this policy are governed by the Terms of Use and applicable laws.
Addendum
This policy takes effect on September 23, 2026.