Conversa

Privacy Policy

Conversa LLC

Effective Date: May 1, 2026 | Last Updated: July 29, 2026

Our Commitment to Your Privacy

Conversa is built on a simple promise: We Secure The Sacred. Your prayers are deeply personal — between you and God — and we treat them that way. We will never sell your prayer data, share it with advertisers, or use it to train AI models. This Privacy Policy explains clearly what we collect, why we collect it, and how we protect it.

Conversa LLC ("Conversa," "we," "us," or "our") is a Massachusetts limited liability company. This Privacy Policy governs your use of the Conversa mobile application (the "App") and our website at getconversa.app (the "Site"). Conversa is currently available to users in the United States only; international availability is planned for a future release.

1. Information We Collect

1.1 Account Information

When you create an account, we collect:

1.2 Prayer Content and Derived Data

When you record a prayer, here is exactly what happens:

1.3 Usage Analytics

We collect anonymized usage data to understand how people use the App and improve it. This includes:

This data does not include the content of your prayers and is never linked to your prayer transcriptions.

1.4 Payment Information

If you subscribe to Conversa Premium through the App, your payment is processed by Apple through your App Store account. We never receive or store your payment card details. Apple provides us only with your subscription status and a transaction identifier so we can grant and maintain your Premium access.

If you subscribe through our website, payment is processed through Stripe. We do not store your credit card number, billing address, or any financial credentials. Stripe's privacy policy governs the handling of your payment information and can be found at stripe.com/privacy.

1.5 Device and Technical Information

We may collect basic technical information necessary to operate the App, including operating system version and crash or error logs. We do not collect precise location data, contacts, or other sensitive device information.

2. How We Use Your Information

We use the information we collect solely to operate and improve Conversa:

We do NOT use your information to:

3. How We Share Your Information

We do not sell your personal information. We share information only with the service providers necessary to operate Conversa, and only to the extent required:

We may also disclose information if required by law, court order, or to protect the rights and safety of Conversa, our users, or others.

4. Data Security

We take the security of your prayer data seriously. Below is an honest and precise account of our security posture.

4.1 Encryption at Rest

The body text of your prayers is encrypted at rest in our database using Supabase Vault, a managed server-side key vault. This encryption is fully in place across all prayers, including those created before it was introduced. AI-generated titles, summary bullets, and category tags are stored separately from the encrypted prayer body and are not yet encrypted at rest; encryption of these derived surfaces is on our roadmap.

4.2 Server-Side Decryption and Audit Logging

Our servers hold the encryption keys and can decrypt your prayer body text when needed to provide the product. Decryption paths are purpose-tagged and audit-logged: each decryption event records which user, which content, which feature triggered the decryption, and when. The decryption paths cover features you actively use: viewing your prayers, generating titles and summaries when you save a prayer, generating weekly summaries if enabled, and grounding Ask Conversa responses against your prayer history.

4.3 What We Are Not

Conversa is not end-to-end encrypted and is not zero-knowledge. We do not offer client-side encryption or client-held keys. Our servers can decrypt your prayer body content when needed for product features. We believe this honest framing is more trustworthy than overstating our security posture.

4.4 Embeddings

Derived embeddings used for search and Ask Conversa are stored in queryable form and are not encrypted at rest. They are not your original prayer text, but they can reflect the meaning of what you prayed. We treat them as sensitive and conducted an adversarial extraction probe before launch. This is a stated trade-off we accept in order to deliver search and AI retrieval functionality.

4.5 Operational Audit Metadata

Internal audit metadata — such as timestamps, purpose tags, feature names, and success or failure outcomes — remains queryable so we can investigate safety and reliability issues without reading your prayer content by default. This is operational metadata, not user content.

4.6 Transport Security

All data in transit between the iOS app, Conversa edge functions, and Supabase is encrypted using TLS 1.2 or higher.

4.7 Additional Safeguards

No method of transmission or storage is 100% secure. If we experience a security breach that affects your data, we will notify you as required by applicable law.

5. Data Retention

Encrypted prayer content is retained while your account is active.

You may delete your account at any time from within the App under Settings. Deleting your account permanently removes your account and all associated prayer data, including transcriptions, AI-generated titles and summaries, categories, and embeddings. All such data is removed from our systems within 30 days of deletion.

Individual prayers that you delete are removed from the database at the time of deletion.

You may also contact us at support@getconversa.app with any data deletion or privacy request.

6. Your Rights and Choices

6.1 Access and Correction

You may access and update your account information at any time within the App under Settings.

6.2 Account Deletion

You may delete your account at any time from within the App under Settings. Deletion permanently removes your account and all associated prayer data, and that data is removed from our systems within 30 days. If you prefer, you may also request deletion by contacting us at support@getconversa.app.

6.3 Communications Opt-Out

You may opt out of non-essential email communications at any time by clicking "Unsubscribe" in any email or by contacting us at support@getconversa.app. You will still receive essential service communications (e.g., receipts, security notices).

6.4 California Residents (CCPA)

If you are a California resident, you have the right to: (1) know what personal information we collect and how it is used; (2) request deletion of your personal information; (3) opt out of the sale of your personal information (we do not sell personal information); and (4) not be discriminated against for exercising these rights. To exercise your rights, contact us at support@getconversa.app. You may exercise your deletion right directly in the App under Settings, or by contacting us at the address above.

7. Children's Privacy

Conversa is not directed to children under the age of 13. We do not knowingly collect personal information from children under 13. If you are a parent or guardian and believe your child has provided us with personal information, please contact us at support@getconversa.app and we will promptly delete it.

8. Third-Party Links

The App may contain links to third-party websites or services. We are not responsible for the privacy practices of those third parties. We encourage you to review the privacy policies of any third-party services you access.

9. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. If we make material changes, we will notify you by email and by displaying a prominent notice in the App before the changes take effect. Your continued use of Conversa after changes become effective constitutes your acceptance of the updated policy.

10. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy, please contact us:

Conversa LLC

Email: support@getconversa.app

Website: getconversa.app

State of Formation: Massachusetts

We take privacy concerns seriously and will respond within 5 business days.


This Privacy Policy was last updated on July 29, 2026.