Last updated: March 2026
This English version is provided for your convenience. The legally binding version is the German Datenschutzerklärung.
The controller within the meaning of the General Data Protection Regulation (GDPR) is:
Digital App Group GmbH
Ferdinand-Koch-Str. 31
26133 Oldenburg
Germany
Email: digitalappgroupde@gmail.com
Phone: +49 441 3793132
This privacy policy explains which personal data we collect, process and use when you use our mobile app "Lisora" (the "App") and the associated website lisora.app, including the chat experience available directly on the website.
Lisora is a platform for spiritual guidance. Users can chat with AI-powered and human advisors specialising in astrology, life coaching and other spiritual topics. Chats are billed through a credit system.
We process personal data on the following legal bases:
Where we process special categories of personal data (for example birth data for astrological purposes), we do so on the basis of your explicit consent under Art. 9(2)(a) GDPR.
You can register using the following methods:
Authentication is handled by our hosting provider Supabase (see section 11). Passwords are stored exclusively as cryptographic hashes and are never visible to us.
Only a display name is required to use the App.
For personalised guidance you can optionally provide:
Your zodiac sign is calculated from your date of birth. This data is used exclusively to create horoscopes and natal charts. Birth data can also be asked for and stored during a conversation with an AI advisor.
You can upload a profile picture (JPEG, max. 500 KB). It is stored in our cloud storage and is not publicly visible to other users.
When you chat with an advisor, your messages are stored on our servers. Each message contains the content, the sender type (user, AI or human advisor), the status and the timestamp.
With AI advisors, your message is processed as follows:
To improve the quality of guidance we store one context text per user. It contains summaries of earlier conversations and allows the AI advisor to refer back to previous topics. In addition, memories (for example important life events you mentioned) are stored per advisor to enable more personal guidance.
You can send images in the chat (max. 5 MB, JPEG/PNG/WebP). They are stored in our cloud storage and analysed by the AI advisor to give a context-aware response.
To generate AI responses we use OpenRouter (OpenRouter, Inc., USA), which routes requests to the following AI models:
The following data is transmitted to the AI providers:
The AI providers process your data exclusively to generate the response. The AI models are not trained on your personal data, as we use API access. The providers may temporarily log requests in accordance with their own privacy policies. Standard Contractual Clauses (SCC) apply to transfers to third countries.
To create natal charts and transit calculations we use an external astrology API. Your date of birth, time of birth and place of birth (transmitted as geographic coordinates) are sent to the service. Results are cached server-side (per date and location) to avoid unnecessary repeat requests.
Horoscopes are created based on your zodiac sign and pre-calculated transit data. Daily affirmations are generated automatically and can be delivered as push notifications.
In addition to AI advisors we also offer chats with human advisors (human takeover). In this case a human advisor can take over an ongoing chat. The human advisor has access to the previous message history of that chat session to ensure a seamless experience. Human advisors are bound to confidentiality.
Payments for credit purchases made in the App are processed by the respective app stores (Apple App Store / Google Play Store). Purchases made on our website are processed by Stripe (Stripe Payments Europe, Ltd., Ireland / Stripe, Inc., USA). In both cases we never receive your credit card or bank details. In-app purchases and credit balances are managed via RevenueCat (RevenueCat, Inc., USA).
During a chat your credit balance is charged per minute. The cost per minute varies by advisor. The billing data (start time, duration, credits used) is stored with us.
We keep a transaction ledger of all credit movements (purchases, deductions, refunds, bonuses). This data is retained for tax and commercial-law purposes for the statutory retention periods.
Under certain conditions we grant bonus credits (for example a welcome bonus on first registration, a referral bonus, a comeback bonus). Grants are logged.
Lisora offers a referral programme. If you share a referral link and another person registers through it, both parties receive bonus credits. For this we store the association between referrer and referred user as well as the respective bonus amounts.
We use Supabase (Supabase, Inc., USA) as our backend platform. Supabase provides:
Our Supabase project is hosted in the EU region (eu-central-1, Frankfurt). Your data is primarily stored within the EU.
All database access is protected by Row Level Security (RLS). Every user can only access their own data. Server-side functions use privileged credentials that are available only in the secure server environment.
In the App we use the following services from Google Firebase (Google Ireland Ltd., Ireland / Google LLC, USA):
To analyse App usage we collect anonymised usage statistics (app opens, screen views, basic interactions). No clear-text names or message contents are transmitted to Firebase Analytics. This is based on our legitimate interest in improving our services.
We use Crashlytics to detect and fix app crashes. In the event of an error, technical information is transmitted (device type, operating system, app version, error message and stack trace). A pseudonymised user ID is used to correlate crash reports. This association is removed when your account is deleted.
We use Firebase Cloud Messaging to deliver push notifications. A device-specific token is stored for this purpose (see section 17). The token is deleted when you sign out.
We use Remote Config to control app configuration parameters server-side. No personal data is transmitted to Remote Config.
We use AppStack as a marketing attribution tool. AppStack records events such as registrations, sign-ins and purchases to measure the effectiveness of our marketing campaigns.
Data processed by AppStack:
On iOS devices, AppStack tracking is only activated with your explicit consent via the App Tracking Transparency framework (ATT).
We use Google Mobile Ads (Google LLC, USA) to display advertisements within the App, together with Google Consent Mode: before any personalised advertising data is collected, your consent is requested via a consent form (UMP, User Messaging Platform). Without consent, no personalised ads are shown.
For the place search when entering your place of birth we use the Google Places API (Google LLC, USA). Your search input is transmitted to Google to display place suggestions. The selected place is stored as a name and geographic coordinates. There is no GPS-based location tracking: the location data comes exclusively from your manual input.
On our website lisora.app we use the following services. Each of them is loaded only after you have given your consent via the cookie banner (Art. 6(1)(a) GDPR); without consent, none of these tools are active. You can withdraw your consent at any time by clearing your cookies for lisora.app.
With your consent we send you push notifications. A device-specific token (FCM token) is stored for this purpose. We distinguish the following types:
On iOS, permission is requested via the system dialog. On Android, the operating system's standard permissions apply. The FCM token is updated automatically when you change devices and deleted when you sign out or delete your account.
Profile pictures are stored as JPEG files (max. 500 KB) in our cloud storage. Access is restricted to authenticated users. You can change or delete your profile picture at any time.
Images sent in the chat (max. 5 MB, JPEG/PNG/WebP) are stored in a separate storage area. These images are deleted together with all other data when your account is deleted.
To upload images, the App needs access to your camera or photo library. This permission is requested via the operating system and can be revoked at any time in your device settings.
The App stores the following data locally on your device:
All locally stored data is deleted when you sign out or delete your account.
We apply the following security measures:
Some of our service providers are based in the USA. Transfers of personal data to the USA take place on the basis of the following safeguards:
| Data category | Storage period |
|---|---|
| User account & profile | Until account deletion |
| Chat messages | Until account deletion |
| Context memory & memories | Until account deletion |
| Birth data & zodiac sign | Until account deletion or withdrawal of consent |
| Profile and chat images | Until account deletion |
| Credit transactions | 10 years (German commercial/tax law, Sec. 257 HGB, Sec. 147 AO) |
| Billing data | 10 years (commercial/tax law) |
| Push tokens | Until sign-out or account deletion |
| Crashlytics data | 90 days (Firebase default) |
| Analytics data | 14 months (Firebase default) |
| Referral data | Until both accounts are deleted |
| Feedback ratings | Until account deletion |
Deleted accounts are first marked as deleted and then permanently removed from the database by an automated process.
Under the GDPR you have the following rights:
To exercise your rights, please contact digitalappgroupde@gmail.com.
You can export your data directly in the App (Settings, then Data Export). The export includes your profile data, chat histories, transaction history, billing data and feedback ratings in JSON format.
You can delete your account directly in the App (Settings, then Delete Account). Account deletion performs the following steps:
Note: transaction data subject to statutory retention periods is anonymised and retained for the required period. Purchases already made through the app stores cannot be reversed by us; please contact Apple or Google for those.
| Provider | Purpose | Location | Transfer basis |
|---|---|---|---|
| Supabase, Inc. | Backend, database, auth, storage | USA (servers: EU) | SCC |
| OpenRouter, Inc. | AI request routing | USA | SCC |
| Google LLC | AI model, Analytics, Crashlytics, FCM, Ads, Places, Play Integrity | USA | DPF |
| Anthropic, PBC | AI model | USA | DPF |
| RevenueCat, Inc. | In-app purchases, credit management | USA | SCC |
| Stripe Payments Europe, Ltd. | Payment processing (website purchases) | Ireland / USA | DPF |
| Apple Inc. | App Store, Sign in with Apple, payment processing | USA | DPF |
| Meta Platforms Ireland Ltd. | Ad measurement on the website (Meta Pixel, consent-based) | Ireland / USA | DPF |
| Microsoft Corporation | Session analytics on the website (Clarity, consent-based) | USA | DPF |
| DataFast | Website visitor and revenue analytics (consent-based) | see provider's site | SCC / DPF |
| AppStack | Marketing attribution (App) | see provider's site | SCC / DPF |
| Astrology API | Natal charts, transit calculations | see provider's site | SCC |
You have the right to lodge a complaint with a data protection supervisory authority. The authority responsible for us is:
Die Landesbeauftragte für den Datenschutz Niedersachsen
(State Commissioner for Data Protection of Lower Saxony)
Prinzenstraße 5
30159 Hannover, Germany
Phone: +49 511 120-4500
Email: poststelle@lfd.niedersachsen.de
Website: lfd.niedersachsen.de
We reserve the right to adapt this privacy policy as needed to reflect changes in the law, in our technology or in our features. The current version is always available at lisora.app/privacy. In the event of significant changes we will inform you via an in-app notification or push message.
Questions about privacy? Contact us any time at digitalappgroupde@gmail.com or by phone at +49 441 3793132.