Doxa Privacy & Data Protection Policy

Effective Date: 23 January 2026 | Last updated: 6 February 2026

Plain Language Summary

We collect only what we need to provide Doxa. We never sell your data. We never use it for advertising. Your spiritual content is encrypted and protected. You can export or delete your data at any time. This full policy explains everything in detail.

Key updates (February 2026): See Section 6B for complete transparency about what data is shared with AI providers (Google, Anthropic, ElevenLabs, AssemblyAI), what protections exist, and your choices. We've also added Sentry session replay disclosure, updated payment processor information, and expanded jurisdiction-specific rights.

1. Who We Are

The Doxa Way Ltd ("Company," "we," "us," "our") is the data controller for your personal data.
Company Number: 16744139
Registered Address: 108 Kings Road, New Haw, Addlestone, KT15 3BH, United Kingdom
Email: privacy@doxa.app

"Company Personnel" means the directors (including Garth Hilton Watson in his capacity as director and in his personal capacity), officers, employees, agents, contractors, and affiliates of The Doxa Way Ltd. References to the Company include Company Personnel acting in their official capacity.

POPIA Information Officer: Garth Hilton Watson — privacy@doxa.app

2. Our Commitment to Your Privacy

We built Doxa with privacy at its core. Your spiritual records, prayers, testimonies, and encouragements are deeply personal. We treat this data with the utmost respect and implement robust security measures to protect it.

Our Privacy Principles

  • Minimal collection: We only collect data necessary for the Service
  • No advertising: We never sell your data or use it for advertising
  • Encryption: All data encrypted in transit (TLS 1.3) and at rest (AES-256)
  • Your control: Export or delete your data at any time
  • Transparency: Clear disclosure of all third-party processors

3. What Data We Collect

Account & Profile Information

  • Name, email address (required for account creation)
  • Profile picture, bio, location (optional, user-provided)
  • Authentication credentials (securely hashed, never stored in plain text)
  • Authentication method used (email/password, Apple Sign In, Google Sign In)

Content You Create

  • Prophecies, testimonies, encouragements, prayers, notes
  • Audio recordings (processed for transcription, then optionally stored)
  • Tags, categories, dates, and metadata you assign

Technical & Usage Data

  • Device type, operating system version, app version
  • IP address (for security, rate limiting, and service delivery only)
  • Error logs and crash reports via Sentry (including masked session replays — see below)
  • Basic interaction data (screens viewed, features used) for service improvement
  • Website page views via Google Analytics (website only, not the mobile app — see our Cookie Policy)

Sentry Session Replay

To diagnose bugs and improve reliability, we use Sentry's session replay feature. This records a visual representation of your app session, but with all text, images, input fields, and vector graphics fully masked. What we see is a blurred wireframe of interactions — we cannot read your content.

  • Sampled at 10% of normal sessions and 100% of sessions where an error occurs
  • All text content, images, and user inputs are hidden before transmission
  • Retained for 90 days, then automatically deleted
  • Used exclusively for debugging — never for profiling, analytics, or advertising

Group & Community Data

  • Group memberships, roles, invitations you send or receive
  • Content you choose to share within groups

Voice Chat (Engage) Data

  • Voice audio streamed in real-time (processed by ElevenLabs, not stored by Doxa)
  • Text chat messages during Engage sessions (if you use text mode)
  • Session metadata: duration, topics discussed, Scriptures referenced
  • Your voice preference selections (which AI voice you chose)
  • Conversation summaries generated to improve future sessions

Subscription & Payment Data

  • Subscription tier and status (free trial, active, cancelled)
  • Usage metrics (session counts, duration for subscription management)
  • Payments primarily processed through Apple App Store (iOS) or Google Play (Android) — we do not receive or store your full payment card details for in-app purchases
  • Stripe is used as a secondary processor for certain payment methods

What We Do NOT Collect

  • Precise GPS location or location tracking
  • Contacts, photos, or files from your device (unless you explicitly upload them)
  • Biometric data: We never receive, transmit, store, or process biometric data on our servers. If you use Face ID, Touch ID, or fingerprint authentication, all biometric processing occurs entirely on your device via your operating system. Doxa has no access to your biometric templates, facial geometry, voiceprints, or fingerprint data. This applies regardless of your jurisdiction, including under the Illinois Biometric Information Privacy Act (BIPA), Texas Capture or Use of Biometric Identifier Act (CUBI), and Washington State biometric privacy laws.
  • Any data for advertising, profiling, or sale to third parties

4. How We Use Your Data

We use your data exclusively to:

  • Provide the Service: Account management, content storage, search, sync, notifications
  • AI-Powered Features: Audio transcription, title generation, scripture recommendations, voice chat (all features use AI to assist you)
  • Voice Encouragement (Engage): Process voice input for real-time AI conversations, reference your prophecies and testimonies with your permission, generate contextual Scripture encouragement
  • Subscription Management: Track usage for subscription tier enforcement, process payments, manage billing
  • Improve the Service: Debugging (including session replays), performance optimization, feature development based on aggregated (non-personal) usage patterns
  • Communicate: Service updates, security alerts, support responses (never marketing spam)
  • Ensure Safety: Fraud prevention, abuse detection, AI-assisted content moderation for shared/public content, compliance with legal obligations

What this means

We only use your data to make Doxa work for you. We don't sell it, we don't advertise with it, and we don't share it with anyone except the specific service providers listed in Section 6 below.

5. Legal Basis for Processing

Under data protection laws (including UK GDPR, EU GDPR, and POPIA), we must have a lawful basis to process your personal data. Here's how we justify each type of processing:

Contract Performance (Article 6(1)(b) GDPR)

Processing necessary to perform our contract with you—i.e., to provide the Doxa Service:

  • Account creation and authentication
  • Storing and syncing your content
  • Processing payments and subscriptions
  • Providing voice chat and AI features
  • Customer support

Legitimate Interests (Article 6(1)(f) GDPR)

Processing necessary for our legitimate interests (or those of third parties), balanced against your rights and freedoms:

  • Service security and fraud prevention
  • Performance monitoring and optimization (including masked session replays)
  • Aggregated analytics for service improvement (non-personal)
  • Website analytics via Google Analytics (non-EU visitors)
  • Protecting our legal rights and enforcing our terms
  • Responding to legal requests and preventing harm

We conduct a balancing test for each legitimate interest to ensure your rights are not overridden. You may object to processing based on legitimate interests by contacting us.

Consent (Article 6(1)(a) GDPR)

Where you have freely given specific, informed, and unambiguous consent:

  • Push notifications (you can opt in/out at any time)
  • Optional AI features (transcription, title generation)
  • Error reporting via Sentry (optional)
  • Website analytics for EU/UK visitors (where required by ePrivacy regulations)
  • Marketing communications (if any—currently we send none)

You can withdraw consent at any time. Withdrawal does not affect the lawfulness of processing before withdrawal.

Legal Obligation (Article 6(1)(c) GDPR)

Processing required to comply with legal obligations:

  • Tax and accounting records retention
  • Responding to valid legal requests from authorities
  • Child safety reporting obligations
  • Data breach notification requirements

Vital Interests (Article 6(1)(d) GDPR)

In rare emergency situations, we may process data to protect vital interests of you or another person (e.g., if we become aware of an imminent threat to life and need to contact emergency services).

6. Data Processors (Sub-processors)

We engage trusted third-party service providers ("processors") to help deliver the Service. All processors are bound by data processing agreements with equivalent security and confidentiality obligations. By using the Service, you acknowledge that we may engage, replace, or add processors without prior notice, provided they meet our security standards.

Current Sub-processors

ProcessorPurposeLocationData Processed
Supabase Inc.Database, Auth, Storage, Edge FunctionsUSA (us-east-1)All user data, content, authentication
Apple Inc.App distribution, push delivery (APNs), in-app purchase payment processing, Sign in with AppleUSADevice tokens, payment information (for IAP), authentication credentials, app usage analytics (if enabled)
Google LLCApp distribution (Play Store), in-app purchase payment processing, Google Sign In, website analytics (GA4)USADevice tokens, payment information (for IAP), authentication credentials, website page views (anonymized)
ElevenLabs Inc.Voice chat (Conversational AI), text-to-speechUSAVoice audio (real-time streaming, not stored), text prompts (not retained after session)
AssemblyAI Inc.Audio transcriptionUSAAudio files (temporarily, deleted after processing)
Google LLC (Gemini)Grace Record synthesis, content embeddings, writing quality reviewUSAPublic testimony content only (not private vault data)
Anthropic PBC (Claude)Title generation, content review, Grace Record red team reviewUSAText content (not stored by Anthropic per API terms)
Stripe Inc.Secondary payment processing for certain payment methodsUSAPayment information, billing details, subscription status
Expo (650 Industries)Push notificationsUSADevice tokens, notification content
Functional Software (Sentry)Error monitoring, masked session replays (all text/images/vectors hidden)EU (Frankfurt)Error logs, device info, stack traces, masked session recordings
Vercel Inc.Website hostingGlobal CDNAccess logs, IP addresses (website only)

We do not sell, rent, or trade your personal data. We may disclose data if required by law, court order, or to protect our legal rights.

Disclosure Without Consent

We may disclose your personal data without your consent only where required or permitted by law:

  • To comply with a legal obligation, court order, or regulatory requirement
  • To protect and defend our legal rights, property, or safety
  • To protect the vital interests of you or another person
  • To prevent fraud, crime, or harm to the Service
  • In connection with a merger, acquisition, or sale of assets (with notice to you)

We will notify you of any such disclosure where legally permitted to do so.

6A. Voice & Audio Data — Special Provisions

We handle voice data with particular care. Here's exactly what happens:

  • Real-time streaming only: Voice audio is streamed directly to ElevenLabs' Conversational AI for processing during your conversation—it is NOT recorded or stored by Doxa
  • No permanent audio storage: ElevenLabs processes audio in real-time and does not retain it after your session per our agreement
  • Conversation summaries: Brief summaries may be generated to help improve future sessions; these contain no audio data
  • Text alternative: You can use text-only mode if you prefer not to use voice features
  • Opt-out available: You may choose not to use Engage voice features; this does not affect other Service functionality

6B. AI Data Processing — Full Transparency

Why This Section Exists

We understand that sharing spiritual data with AI providers raises legitimate concerns. This section provides complete transparency about what data goes where, what protections exist, and what choices you have. We believe you should have all the facts to make your own informed decision.

Protecting Your Prayers & Prophecies

Your prayers and prophecies are sacred. We take this responsibility seriously. Here's what you need to know:

  • Your private vault stays private: Your personal prophecies, prayers, and testimonies stored in your vault are ONLY sent to AI providers when YOU actively use a feature that requires it (like voice chat or voice recording). They are never bulk-exported, scraped, or shared.
  • No training on your spiritual content: All our AI providers are contractually prohibited from using API data to train their models. Your prayers will never become part of a future AI's training data.
  • No selling or monetizing: Your spiritual content is never sold, rented, or monetized by us or our AI providers. It exists solely to serve you.
  • No profiling or targeting: We do not build profiles based on your spiritual content. Your prayers are not analyzed to sell you products or influence your beliefs.
  • Public vs Private is clear: The only content that leaves your control is content you explicitly choose to share publicly (like testimonies submitted to The Grace Record). Your private vault remains yours.

What Personal Data Is Sent to AI Providers?

ProviderWhat DataWhenHow Long Retained
ElevenLabsVoice audio stream + compact text context from your vault (max 3 prophecies at 200 chars, 3 vault items at 200 chars, 2 testimonies at 150 chars, 3 scriptures at 150 chars)During Engage voice chat sessions onlyAudio: NOT stored after session. Conversation data deleted after session ends
AssemblyAIAudio file of your voice recordingWhen you record a prophecy or testimony by voiceDeleted immediately after transcription. Transcoded copies: 3 days max
Google (Gemini)Public testimony content for Grace Record synthesis and embeddingsWhen processing public Grace Record content onlyAPI data not used for training per Google's API terms
Anthropic (Claude)Text content for title generation and content reviewWhen generating titles or reviewing Grace Record content7-day API retention, not used for training per Anthropic's API terms

Contractual Undertakings from AI Providers

Each AI provider has made legally binding commitments about how they handle data:

ElevenLabs (Voice Chat Provider)

  • No training on API data: ElevenLabs does not use API data to train models without explicit consent
  • No audio retention: Voice audio is processed in real-time and not stored after the session ends
  • SOC 2 Type 2 certified: Independent audit verification of security controls
  • GDPR compliant: Full compliance with European data protection regulations
  • Enterprise-grade security: Encryption in transit and at rest for all data

AssemblyAI (Transcription Provider)

  • Immediate deletion: "All submitted audio or video data is deleted from their servers as soon as the transcription has completed"
  • No selling or sharing: Data Processing Agreement explicitly prohibits selling or sharing personal data
  • SOC 2 Type 2 + PCI-DSS 4.0: Industry-leading security certifications
  • DELETE endpoint: Immediate removal of all associated data on request

Google (Gemini) — Grace Record Processing

  • No training on API data: Google's Gemini API terms confirm API data is not used for model training
  • Public content only: Only used for public Grace Record testimonies, not your private vault
  • SOC 2 Type 2 + ISO 27001: Industry-leading security certifications
  • Data residency options: Processing can be configured for specific regions

Anthropic (Claude) — Title Generation & Review

  • No training on API data: Anthropic confirms "By default, we will not use your inputs or outputs from commercial products to train our models"
  • 7-day API retention: Minimal retention period for abuse monitoring
  • SOC 2 Type 2 certified: Independent audit verification of security controls
  • Used for: Title generation and Grace Record content review

Technical Safeguards We Implement

  • Data minimisation: Only compact excerpts of relevant records are sent — max 3 prophecies at 200 characters, 3 vault items at 200 characters, 2 testimonies at 150 characters, 3 scriptures at 150 characters — never your full vault
  • Size guard: A 50KB hard limit prevents oversized data from being sent to AI providers; if exceeded, the system falls back to using only the base prompt
  • Direct WebSocket connection: Voice audio streams directly from your device to ElevenLabs — it never passes through or is stored on Doxa servers
  • Encryption in transit: TLS 1.3 for all HTTPS connections, DTLS for WebRTC audio
  • Encryption at rest: AES-256 encryption for all stored data in our database
  • Row-Level Security: Database policies ensure you can only access your own records — enforced at the database level, not just application level
  • No bulk export to AI: Your full vault is never sent to any AI provider

Honest Answers to Common Concerns

"Could AI provider employees read my prayers?"

Technically possible but highly restricted. ElevenLabs, Google, and Anthropic all have internal access controls audited under SOC 2. Data access requires business justification. Your prayers are one of millions of API calls — no one is actively reading them. However, we cannot guarantee what happens inside third-party systems.

"Could my spiritual data train AI models?"

No — contractually prohibited. All our AI providers' API terms explicitly exclude API data from training unless the customer opts in. Doxa has NOT opted in. This is a legally binding commitment. ElevenLabs, Google (Gemini), Anthropic (Claude), and AssemblyAI all confirm this in their terms.

"Could my data be leaked in a breach?"

Risk exists but is mitigated. All three providers have SOC 2 Type 2 certification. Encryption protects data in transit and at rest. Short retention periods limit the exposure window. These companies invest heavily in security as high-value targets. However, no system is 100% secure — this is true of all digital services.

"What if the government subpoenas my data?"

Possible but limited. Our AI providers have stated they fight overly broad requests. Minimal retention periods limit what data exists to be produced. Doxa's data is stored in the USA (Supabase) and is subject to US law. We would notify you of any request where legally permitted.

"Could my prayers be connected to me personally?"

Low risk. We do not send your email, name, or Doxa account ID to AI providers. Your prayers arrive as anonymous text context. AI providers see our Edge Function server IP, not your device IP directly. However, your voice is biometrically unique, and your prophecy content may contain personal details (e.g., names, locations, churches mentioned in the text). While theoretical re-identification through content correlation is possible, it would require deliberate effort, access to multiple data sources, and a specific reason to target you. Such an exercise would be costly — requiring engineering resources, cross-referencing external databases, and violating access policies — with no business justification. This makes it a low-probability scenario for ordinary users. Minimal retention periods further limit any exposure.

"Could AI companies use my content on Doxa for evil?"

This is the heart of the concern, and it deserves a thoughtful answer.

The short answer: We have done everything reasonably possible to prevent this, but we cannot make absolute guarantees about systems we don't control.

What "evil" would look like: Selling your prayers to advertisers. Training AI on your spiritual struggles. Profiling your faith to manipulate you. Targeting you based on your vulnerabilities. Using your content against you.

Why this is unlikely:
No business incentive: AI providers make money selling API access, not harvesting prayer data. Your prayers have no commercial value to them.
Legal liability: Misusing data would violate contracts, data protection laws (GDPR, CCPA), and expose them to lawsuits worth far more than any profit.
Reputational suicide: A single scandal would destroy enterprise trust—their primary revenue source.
Technical barriers: Your data arrives anonymously, in fragments, mixed with millions of other API calls. Targeting you specifically would be like finding one drop in an ocean.
Short retention: Data is deleted within hours to days. There's no archive of your prayers sitting on a server.

What we cannot guarantee: We cannot see inside ElevenLabs, Google, or Anthropic's systems. We cannot prevent a rogue employee. We cannot stop a government with a warrant. We cannot predict future policy changes. These are honest limitations of any cloud service—including email, messaging apps, and every other digital tool you use.

The wisdom: Perfect privacy exists only in your own heart and in prayer spoken to God alone. Every digital tool involves some trust. We have chosen providers carefully, implemented technical safeguards, and secured contractual protections—but ultimately, you must decide if the benefits of AI-assisted encouragement are worth this measured risk. If they are not, Doxa works without AI features. Your spiritual life does not depend on technology.

"What's the difference between my private vault and The Grace Record?"

Private Vault (your prophecies, prayers, notes): Only sent to AI when you use voice chat or voice recording. Never shared publicly. Never bulk-processed. Only you can see it.

The Grace Record (public testimonies): A public archive of historical and user-submitted testimonies. If you submit a testimony to The Grace Record, it becomes public content that others can read. This public content is processed by AI for synthesis, review, and discoverability. Your private vault is never connected to The Grace Record unless you explicitly submit something.

"What if AI companies change their policies in the future?"

Valid concern. If any AI provider materially changes their data practices in a way that weakens protections for your spiritual content, we commit to: (1) notifying you promptly, (2) evaluating alternative providers, and (3) giving you the option to export your data and delete your account before any adverse changes take effect. We chose providers with strong privacy track records, but we remain vigilant and will act in your interest if circumstances change.

Your Choices

You have control over how much data is processed by AI providers:

  • Don't use Engage: Record prophecies and testimonies in text only — no voice data sent to ElevenLabs
  • Type instead of speak: Use text transcription instead of voice recording — no audio sent to AssemblyAI
  • Use Doxa as storage only: Record your content without using AI features at all
  • Delete your data: Request full deletion at any time — we will remove your data from our systems and instruct processors to do the same

The Bottom Line

When you use Engage voice chat, compact excerpts of your vault (max 3 prophecies, 3 vault items, 2 testimonies, 3 scriptures — all truncated) are sent to ElevenLabs to personalise your encouragement. This data is processed in real-time and is not stored after your session ends. Your data is not used for AI training. When you record by voice, your audio goes to AssemblyAI, is transcribed, and immediately deleted. For Grace Record content, Google (Gemini) handles synthesis and Anthropic (Claude) handles title generation and review. We have implemented technical and contractual safeguards, but we cannot control what happens inside third-party systems. We believe in transparency — you should have all the facts to decide what's right for you.

7. International Data Transfers

Your data may be processed in the United States and other countries where our processors operate. For transfers from the UK/EEA, we rely on:

  • Standard Contractual Clauses (SCCs) approved by the European Commission
  • UK International Data Transfer Agreement (IDTA) addendum where applicable
  • Processor certifications and security attestations (SOC 2, ISO 27001 where available)

What this means

Because our service providers are mostly based in the USA, your data travels internationally. We use legal agreements approved by UK and EU regulators to ensure your data receives equivalent protection wherever it's processed.

7A. Your Rights by Region

We respect privacy rights worldwide. Depending on where you live, you may have additional rights:

European Union & United Kingdom (GDPR/UK GDPR)

  • Right to access, rectify, erase, restrict, and port your data
  • Right to object to processing and withdraw consent
  • Right not to be subject to solely automated decisions
  • Right to lodge a complaint with your supervisory authority

South Africa (POPIA)

  • Right to access your personal information and know what we hold
  • Right to request correction or deletion of your information
  • Right to object to processing of your personal information
  • Right to submit a complaint to the Information Regulator
  • Right to be notified of data breaches that affect you

POPIA Transfer Provisions: We transfer data outside South Africa on the basis that our processors are bound by contractual obligations that provide an adequate level of protection as required by Section 72 of POPIA.

United States (State Privacy Laws)

  • California (CCPA/CPRA): Right to know, delete, correct, and opt out of sale/sharing
  • Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana: Similar rights to access, delete, correct, and opt out
  • We do not "sell" or "share" personal information as defined by CCPA/CPRA
  • We do not use personal information for targeted advertising or cross-context behavioral advertising
  • We do not use sensitive personal information for purposes other than providing the Service
  • We do not discriminate against you for exercising your privacy rights

CCPA/CPRA Notice at Collection

Categories of personal information collected: Identifiers (name, email), internet activity (usage data), audio data (voice recordings for transcription), and inferences (AI-generated content). Purpose: To provide and improve the Service as described in Section 4. Retention: As described in Section 8. Right to opt out of sale: We do not sell your personal information. Right to limit use of sensitive information: We only use sensitive information to provide the Service. To exercise any CCPA/CPRA rights, contact privacy@doxa.app or use the in-app data management features.

AI Transparency (EU AI Act & Global)

  • Risk classification: Doxa's AI features are classified as LIMITED RISK under the EU AI Act — they provide assistance and recommendations, not autonomous decisions affecting your rights
  • We clearly label when AI is being used in features like Engage, transcription, and content generation
  • AI-generated content (including images in the Grace Record) is labelled as such
  • You can choose not to use AI-powered features without losing access to core functionality
  • We do not use your data to train AI models without your consent
  • AI-generated spiritual content is assistive only — it does not make decisions on your behalf
  • You have the right to request human review of any AI-generated content that affects you

Children's Privacy by Jurisdiction

  • USA (COPPA): The Service is not directed at children under 13. We do not knowingly collect data from children under 13.
  • UK/EU (GDPR/Age-Appropriate Design Code): Users under 16 require verifiable parental consent (or 13 in some EU member states per local implementation).
  • South Africa (POPIA): Users under 18 require consent from a competent person (parent or guardian).
  • General: If we become aware that we have collected data from a child below the applicable age threshold without proper consent, we will delete that data promptly.

EEA Representative: If you are located in the European Economic Area and need to contact a representative under Article 27 GDPR, please email privacy@doxa.app and we will direct your inquiry appropriately. We are in the process of appointing a formal EEA representative and will update this policy when that appointment is confirmed.

To exercise any of these rights, contact us at privacy@doxa.app. We respond to all requests within the timeframes required by applicable law.

8. Data Retention

  • Active accounts: Data retained as long as your account exists
  • Deleted accounts: Personal data removed within 30 days; encrypted backups purged within 90 days
  • Audio files (transcription): Deleted from processor systems immediately after transcription
  • Voice chat audio: Streamed in real-time, not stored by Doxa or ElevenLabs
  • Voice chat summaries: Session metadata retained with your account; deleted when you delete your account
  • Payment data: Retained by Apple/Google/Stripe per their respective policies; subscription records retained for accounting/legal compliance
  • Error logs & session replays: Retained for 90 days maximum, then automatically deleted
  • Website analytics: 14 months (Google Analytics default with our configuration)
  • Legal/safety data: May be retained longer if required by law or to protect legal rights (up to 7 years for financial records)

9. Your Rights & How to Delete Your Data

You have the right to:

  • Access: Request a copy of your personal data
  • Rectification: Correct inaccurate or incomplete data
  • Erasure: Delete your account and all associated data
  • Restriction: Limit processing of your data in certain circumstances
  • Portability: Export your data in a machine-readable format
  • Object: Opt out of certain processing activities
  • Withdraw Consent: For consent-based processing at any time
  • Automated Decision-Making: Not be subject to solely automated decisions (we don't make such decisions)

How to Delete Your Data

You can request deletion of your data through any of these methods:

Deletion Timeline

  • Account data: Removed within 30 days of confirmed deletion request
  • Encrypted backups: Purged within 90 days
  • Third-party processors: Instructed to delete within 30 days of our request
  • Legal/financial records: Retained up to 7 years where required by law (e.g., tax records)

You will receive a confirmation email when your deletion request has been processed. If you do not receive confirmation within 30 days, please contact us at privacy@doxa.app.

To exercise these rights, contact privacy@doxa.app. We will respond within 30 days (or as required by applicable law).

10. Data Security

We implement industry-standard and beyond security measures:

  • Encryption in transit: TLS 1.3 for all connections
  • Encryption at rest: AES-256 encryption for stored data
  • Authentication: Secure authentication via Supabase Auth with optional biometrics
  • Row-Level Security: Database policies ensure you can only access your own data
  • Rate limiting: Protection against brute-force and abuse
  • Regular audits: Security reviews and penetration testing
  • Incident response: Documented procedures for security incidents
  • Access controls: Strict internal access policies with audit logging
  • Data minimisation: We only collect and retain what is necessary

Data Breach Notification

In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will:

  • Notify the relevant supervisory authority (ICO) within 72 hours of becoming aware of the breach, where required
  • Notify you without undue delay if the breach is likely to result in a high risk to your rights and freedoms
  • Provide clear information about the nature of the breach and recommended protective measures
  • Document the breach, its effects, and remedial actions taken

Your Security Responsibilities

No system is completely secure. You are responsible for:

  • Maintaining the confidentiality of your account credentials
  • Enabling device-level security features (PIN, biometrics)
  • Notifying us immediately of any suspected unauthorized access
  • Logging out from shared devices
  • Using strong, unique passwords

We cannot be held responsible for breaches resulting from your failure to maintain adequate security of your account credentials or devices.

11. Children's Privacy

The Service is not intended for children under 13 years of age (or under the applicable age threshold in your jurisdiction — see Section 7A). We do not knowingly collect personal data from children below the applicable age threshold. If you are a parent or guardian and believe your child has provided us with personal data, please contact us immediately at privacy@doxa.app.

12. Cookies & Tracking

We use minimal cookies and tracking technologies. We do not use advertising or marketing cookies. The mobile app uses no analytics cookies. The website uses Google Analytics for basic traffic metrics. See our Cookie & Tracking Policy for details.

13. Changes to This Policy

We may update this policy from time to time. Material changes will be communicated via the app, email, or this page. The "Last updated" date at the top indicates when this policy was last revised. Your continued use of the Service after changes constitutes acceptance.

14. Contact & Complaints

For privacy inquiries, data requests, or complaints:
Data Protection Contact: privacy@doxa.app
POPIA Information Officer: Garth Hilton Watson — privacy@doxa.app
Address: The Doxa Way Ltd, 108 Kings Road, New Haw, Addlestone, KT15 3BH, United Kingdom

How We Handle Your Requests

  • We will respond to all data subject requests within 30 days (or as required by applicable law)
  • We may need to verify your identity before processing requests
  • Complex requests may take up to 90 days (we will inform you if this is the case)
  • We will not charge for requests unless they are manifestly unfounded or excessive

Supervisory Authorities

You have the right to lodge a complaint with a supervisory authority if you believe we have processed your data unlawfully:

We encourage you to contact us first so we can try to resolve your concern directly.

15. Automated Decision-Making

We do not use your personal data for automated decision-making that produces legal effects concerning you or similarly significant effects. While we use AI to provide features like transcription, title generation, and voice chat, these are assistive tools—not automated decision-making systems that affect your legal rights.

If we ever introduce automated decision-making with significant effects, we will update this policy and provide appropriate safeguards including the right to human review.

16. Sensitive Personal Data

We recognise that Doxa may contain sensitive personal data, including religious or philosophical beliefs (as spiritual content is central to the Service). By using Doxa to record prophecies, testimonies, or other spiritual content, you explicitly consent to the processing of this special category data as necessary to provide the Service.

We apply additional safeguards to sensitive data, including enhanced encryption and stricter access controls. We never share your spiritual content for advertising, profiling, or any purpose unrelated to providing the Service.

17. No Profiling for Advertising

We do not:

  • Build advertising profiles about you
  • Sell your personal data to data brokers
  • Share your data with advertisers or ad networks
  • Use your spiritual content for marketing purposes
  • Track you across websites or apps for advertising
  • Share or sell your data as defined under CCPA/CPRA

This is a core commitment. We believe your spiritual journey should never be commoditised.

18. Disclaimer of Liability for Data Processing

While we take extensive measures to protect your data, you acknowledge that:

  • No data transmission over the internet or electronic storage is completely secure
  • We cannot guarantee the absolute security of your data despite our best efforts
  • You transmit data at your own risk
  • Neither the Company nor any Company Personnel (including Garth Hilton Watson in his capacity as director and in his personal capacity) shall be liable for any unauthorised access, disclosure, or loss of data caused by circumstances beyond our reasonable control

Nothing in this section limits or excludes liability for breach of applicable data protection laws to the extent such limitation is not permitted by law.

18A. No Personal Guarantees

This Policy creates obligations for The Doxa Way Ltd as a corporate entity. Nothing in this Policy shall be construed as a personal guarantee, warranty, or undertaking by any director, officer, employee, or agent of the Company in their personal capacity.

The obligations, liabilities, and commitments set forth in this Policy are those of the Company alone. Company Personnel may enforce the protective provisions of this Policy (including limitation of liability and disclaimer provisions) as express third-party beneficiaries under the Contracts (Rights of Third Parties) Act 1999.

Summary: Your Data, Your Control

  • We collect only what's necessary to provide the Service
  • Your content is encrypted and protected with industry-leading security
  • We never sell your data or use it for advertising—ever
  • You can export or delete your data at any time
  • We are transparent about every third party that touches your data
  • We respond to all data requests within 30 days
  • You can complain to a supervisory authority if we fail you

Questions? Contact us at privacy@doxa.app. We're here to help.