Avila ("we," "us," or "our") is operated by Ryan Sales, 4020 N. MacArthur Blvd Ste 122-112, Irving, TX 75038. We are the data controller for the personal data described in this policy.
Questions or requests may be sent to the contact details in Section 16.
This policy applies to the Avila mobile application ("App") on iOS and Android, our related websites — including the public relationship-reflection tool at take.avila-catholic.app — and any related services. By creating an account, using the App, or submitting your details through our reflection website, you confirm that you have read this policy and consent to the practices described herein. If you do not agree, please do not use the App or the website.
| Category | Examples | Sensitive? |
|---|---|---|
| Account credentials | Email address, password (hashed) | No |
| Communication preferences | Whether you have opted in to "Avila updates" marketing email, and when | No |
| Profile information | First name, last name, birth date (month and day only — birth year is not stored), gender. Your profile also records whether you are Catholic — see "Religious beliefs" below, as that answer is treated as sensitive data. | No |
| Photos | Profile avatar (visible only to your paired partner); optional couple photo (visible only to you and your paired partner) | No |
| Relationship data | Relationship stage (dating, committed, engaged, married) and milestone dates shared with your partner | No |
| Subscription data | Subscription status, product ID, trial/renewal dates, store of purchase — managed by RevenueCat; payment card details are handled entirely by the app store | No |
| Questionnaire responses | Answers to relationship-growth questions | Yes |
| Inventory assessments | Responses and scores from personality and compatibility inventories (e.g. Big Five, Attachment Style, Financial) | Yes |
| Religious beliefs | Avila is a Catholic app. Your profile records whether you are Catholic — an answer you give us directly and can change at any time — and it is used solely to tailor your AI guidance, so that it is not written as though you follow practices that are not yours. In addition, some questionnaire and inventory answers, and the AI guidance built from them, can reveal your faith and religious practice. All of this is a special category of personal data, which we process only with your explicit consent. | Yes |
| AI-generated content | Relationship guidance, roadmap summaries, and inventory feedback generated by AI and stored against your account | Yes |
| Reflection-tool data (website) | Your email address and your answers to the public 10-question relationship reflection at take.avila-catholic.app, which you can take without an App account | Yes |
| Category | Examples |
|---|---|
| Device identifiers | Device type, operating system version, app version, unique device ID |
| Performance data | App start time, screen-render and network-request timing collected by Firebase Performance Monitoring (no personal content) |
| Push notification tokens | FCM registration token for delivering notifications |
| Crash and diagnostics data | Error logs, stack traces (no personal content) |
| Network identifiers | IP address, captured transiently when you attempt to pair with a partner or use the public reflection tool, used only to rate-limit abuse and prevent fraud (raw IP kept at most 7 days for in-app pairing; hashed for the public reflection tool) |
| Purpose | Data Used |
|---|---|
| Create and manage your account | Credentials, profile information |
| Pair you with a partner via a shared code | Profile, pairing codes, pair status |
| Deliver relationship-growth content and questions | Questionnaire responses, pair status |
| Generate AI-powered guidance and relationship roadmaps | Questionnaire responses, inventory scores, couple profile — sent to Anthropic's API to generate content; results stored against your account |
| Provide the public relationship reflection and email it to you | Website reflection answers (scores sent to Anthropic to generate the reflection — no name or contact details), your email address |
| Send you occasional "Avila updates" (product news and announcements) if you opt in — via the Settings toggle in the App, or when you sign up through the reflection website | Your email address (used only if you opt in) and your opt-in choice |
| Send push notifications | FCM token, notification preferences |
| Enforce our Terms of Service and safety policies | Account and usage data |
| Improve the App and fix bugs | Anonymized usage data, crash logs |
| Comply with legal obligations | Any data required by applicable law |
We do not use your data for targeted advertising, and we do not sell your personal data to any third party.
If you are located in the European Economic Area (EEA), United Kingdom, or Switzerland, we process your personal data under the following legal bases:
| Processing Activity | Legal Basis |
|---|---|
| Providing the App's core features | Performance of a contract (Art. 6(1)(b) GDPR) |
| Processing data revealing religious beliefs (the Catholic / other answer you give on your profile; faith-related questionnaire and inventory answers; and the AI guidance built from them) | Explicit consent (Art. 6(1)(a) and Art. 9(2)(a) GDPR) |
| Processing relationship data (relationship stage and milestone dates) | Performance of a contract (Art. 6(1)(b) GDPR) |
| Sending "Avila updates" marketing email to those who opt in | Consent (Art. 6(1)(a) GDPR) |
| Fraud prevention and safety | Legitimate interests (Art. 6(1)(f) GDPR) |
| Complying with legal obligations | Legal obligation (Art. 6(1)(c) GDPR) |
| Improving the App (anonymized data only) | Legitimate interests (Art. 6(1)(f) GDPR) |
You may withdraw consent at any time where we rely on consent. Withdrawal does not affect the lawfulness of prior processing.
Your profile information, photos, inventory results, and questionnaire responses are visible only to the single partner you have paired with via an eight-character pairing code. We never expose your data to other users without your consent.
| Provider | Purpose | Data Shared | Location |
|---|---|---|---|
| Supabase, Inc. | Database, authentication, storage | All stored user data | United States (AWS) |
| Google (Firebase Cloud Messaging) | Push notifications | FCM token only | United States |
| Apple (APNs) | Push notifications (iOS) | APNs token only | United States |
| Apple (Sign in with Apple) | Account creation and sign-in on iOS (optional — email/password and Google are also offered) | Apple-issued identity token verified by our authentication service; optional email (which may be a private Apple relay address) and full name provided only on first sign-in | United States |
| Google (Sign-In) | Account creation and sign-in (optional — email/password and Apple are also offered) | Google-issued identity token verified by our authentication service; email address and Google account name | United States |
| Anthropic, PBC | AI generation of relationship guidance, roadmaps, and inventory feedback | Questionnaire responses, inventory scores, couple profile context, and both partners' first names (no last names, email, or other contact details) | United States |
| RevenueCat, Inc. | Subscription management | User ID, app store purchase receipts (no card numbers) | United States |
| Google (Firebase Crashlytics) | Crash reporting and diagnostics | Device info, stack traces (no personal content) | United States |
| Google (Firebase Performance Monitoring) | App performance monitoring | Anonymized session and network timing data | United States |
| Google (Cloud Vision SafeSearch) | Automated safety screening of profile and couple photos at upload time | Image bytes only, scanned in-flight; Google does not persist the image after the response | United States |
| Resend | Sending email — App account emails (e.g. sign-in confirmation, password reset) and, for the public reflection tool, the confirmation email, the reflection delivery, and the opt-in updates list | Email address; email contents | United States |
| Netlify, Inc. | Hosting of the admin portal, public policy pages, and the public reflection website (take.avila-catholic.app) | Email address and reflection answers entered on the reflection website | United States |
All providers are bound by data processing agreements and may only process your data as instructed by us.
We may disclose your data when required by applicable law, court order, or governmental authority, or to protect the rights, safety, or property of Avila, our users, or the public.
If Avila is involved in a merger, acquisition, or sale of assets, your data may be transferred. We will notify you before your data becomes subject to a different privacy policy.
We do not sell, rent, or trade your personal data to third parties for their own marketing purposes.
| Data Type | Retention Period |
|---|---|
| Active account data | Until you delete your account |
| Questionnaire and inventory responses | Until you delete your account; purged within 30 days of deletion |
| Data associated with archived pairs | Purged 2 years after the pair is archived |
| Push notification tokens | Purged after 6 months of inactivity |
| Pairing attempt logs | Purged weekly; kept at most 7 days |
| Photo moderation audit log | Purged after 180 days; deleted with your account |
| Error and diagnostic event logs | Purged after 90 days |
| Inactive accounts | Warning at 18 months of inactivity; account and data deleted at 24 months |
| Unconfirmed reflection-tool submissions (email never confirmed) | Deleted in our weekly cleanup once more than 30 days old |
| Confirmed reflection-tool data (you confirmed your email) | Kept until you unsubscribe or ask us to delete it |
| Product analytics events (which milestones you reached in the app, such as completing an inventory or pairing) | Deleted after 3 years. If you delete your account, the link to you is removed immediately and only an anonymous record remains. |
| Anonymized analytics data | Up to 3 years |
| Legal/compliance records | As required by applicable law (typically up to 7 years) |
When you delete your account, we will delete or anonymize your personal data within 30 days, except where retention is required by law.
Depending on your location, you may have the following rights regarding your personal data:
To exercise any of these rights, contact us at the address in Section 16 or use the in-app account settings. We will respond within 30 days (or within the timeframe required by applicable law). We may request verification of your identity before processing your request.
If you have an App account and opted in to "Avila updates" emails, you can turn them off at any time from the App's Settings screen, or use the unsubscribe link in any such email.
If you used our public reflection website without an App account, you can stop receiving emails at any time using the unsubscribe link in any email we send, or email us at the address in Section 16 to have your reflection data deleted.
Avila is not intended for persons under the age of 18. We do not knowingly collect personal data from children under 18. If you are a parent or guardian and believe your child has provided us with personal data, please contact us immediately and we will delete that information.
In jurisdictions where a higher age threshold applies (e.g., age 16 under GDPR in certain member states), we apply the higher threshold for residents of those jurisdictions.
We implement industry-standard technical and organizational measures to protect your data, including:
No system is completely secure. If you believe your account has been compromised, contact us immediately at the address in Section 16.
Avila supports two kinds of photo upload: your profile picture and a couple photo visible to your paired partner. Both are subject to automated safety screening:
photo_moderation_events) recording the bucket, path, Vision response, decision, and timestamp. You have the right to access your own entries (see Section 8).Visibility: unlike open social platforms, Avila has no public feed, no discovery, and no matching algorithm. A user's photos are visible only to the single partner they have paired with via an eight-character pairing code exchanged out of band. Pairing is reciprocal and can be ended by either party without the other's consent.
Child sexual abuse material (CSAM) is reported to the U.S. National Center for Missing & Exploited Children (NCMEC) via the CyberTipline as required by 18 U.S.C. § 2258A. Details are in our Child Safety Policy.
Your data is stored and processed in the United States by Supabase (hosted on AWS). If you are located outside the United States, your data will be transferred to and processed in the US, which may not provide the same level of data protection as your home country.
For transfers from the EEA, UK, or Switzerland, we rely on:
You may request a copy of the applicable transfer safeguards by contacting us.
We use Firebase Cloud Messaging (Android) and Apple Push Notification service (iOS) to send you notifications about new questions, partner activity, and app updates. You can disable push notifications at any time in your device's system settings or within the App. Disabling notifications does not delete your account or data.
The App integrates with the following third-party services. Each has its own privacy policy:
We are not responsible for the privacy practices of these third parties beyond our contractual obligations.
If you are a California resident, you have the following additional rights under the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA):
In the past 12 months we have collected: identifiers (name, email, device ID, user ID); profile data (birth month/day, gender, photos); relationship data (pair status, anniversary dates); inventory and questionnaire responses; reflection-tool data submitted on our public website (email address and relationship-reflection answers); subscription data (via RevenueCat); and usage/diagnostics data. See Section 3 for details.
Submit requests by email to the address in Section 16 with subject line "California Privacy Request." We will verify your identity and respond within 45 days (extendable to 90 days with notice).
You may designate an authorized agent to make a request on your behalf; the agent must provide written authorization signed by you.
We may update this Privacy Policy from time to time. We will notify you of material changes by:
Your continued use of the App after the effective date constitutes acceptance of the revised policy. If you do not agree to the revised policy, please delete your account before the effective date.
For privacy questions, requests, or complaints:
Avila – Privacy
Ryan Sales
4020 N. MacArthur Blvd Ste 122-112
Irving, TX 75038
Email: privacy@avila-catholic.app
If you are located in the EEA and we have not satisfactorily resolved your concern, you have the right to lodge a complaint with your local supervisory authority.