Privacy Policy
Last updated — 13 July 2026
Welcome to Pathly, a faith and emotional wellness app designed to help you navigate life's challenges through spiritual reflection and scripture-based guidance (the "Service"). The Service is owned and operated by Pathly ("Company", "we", "us", "our").
This Privacy & AI Disclosures Policy (the "Policy") explains the privacy practices for our Service and its use of Artificial Intelligence. It also describes the rights and options available to you with respect to your information.
This Policy is incorporated into the Service's Terms of Use and constitutes an integral part of them.
We comply with applicable privacy laws including the General Data Protection Regulation (GDPR) for users in the European Economic Area (EEA), the California Consumer Privacy Act (CCPA) and other US state privacy laws, and we follow the requirements of Apple's App Store Review Guidelines (sections 5.1.1 and 5.1.2) regarding data collection, use, and sharing.
1. What Data We Collect
1.1 Data You Give Us
Information you actively provide to us:
- Registration: email address, name, username, and authentication credentials when you create an account. If you sign in with Google, we receive your name and email address from your Google account.
- Onboarding preferences (special category / sensitive data): your preferred scripture library (e.g. Bible) and the areas of life where you seek improvement (e.g. family, relationships, work, mental wellbeing).
- Session inputs: the first message you send describing your concern, the structured choices you make during a session, and any free-text messages you write to the AI.
- Support requests: your contact details and the content of your request when you reach out to us.
1.2 Data the Service Creates
Information generated as a result of you using the Service, stored against your account:
- The area of life selected during each check-in
- Your emotional state at the time of check-in
- The verses you have been shown, including a rolling 30-day history (used to avoid repeats and improve future recommendations)
- Your response to "Did this verse help you?"
As described in Section 4 below, portions of this data are transmitted to OpenAI to generate AI responses. We do not retain full conversation transcripts on Pathly's own servers.
1.3 Data Collected Automatically
Information collected through standard technical means as you use the Service:
- Diagnostics: crash reports and error logs, including device model, operating system version, app version, a technical description of the error, and your app user identifier. We use this only to detect and fix stability problems. We do not collect general product-analytics data such as which screens you visit or how long your sessions last.
- Technical information: device type, operating system version, app version, and performance diagnostics.
- Cookies and similar technologies: limited to authentication, session management, and basic app security. Not used for advertising or cross-site tracking.
You are not legally required to provide us with your information. However, if you do not provide the necessary information, we will not be able to allow you to sign up, personalise the Service, or provide you with its features.
2. How We Use Your Data
- To operate the Service, verify your identity, and prevent fraud
- To provide the core AI-powered functionality (which involves sharing data with OpenAI as described in Section 4)
- To personalise scripture recommendations based on your faith preference and emotional state
- To improve verse recommendation accuracy based on your feedback
- To detect, diagnose and fix crashes and errors so the app stays stable
- To manage your subscription
- To send transactional emails (password changes, account notifications)
- To send marketing communications where you have consented
- To detect crisis indicators and surface support resources
- To comply with legal obligations
We do not sell your personal data.
3. When and How We Share Personal Data With Others
We will not share your information with third parties except in the events listed below or with your explicit consent. We do not sell personal information. Sharing of data with our third-party AI service provider is described in detail in Section 4 below.
Equal protection commitment.
We require all third parties with whom we share user data — including analytics providers, AI services, advertising networks, and third-party SDKs, as well as any parent, subsidiary, or related entities — to provide the same or equivalent level of protection of your personal data as stated in this Privacy Policy and as required by applicable law.
Service providers we share data with.
We may use service providers and infrastructure partners to support the functionality, security, and performance of the App. These providers are authorised to use your personal information only as necessary to provide services to us and not for their own promotional purposes. The categories of providers we work with include:
- Third-party AI service (OpenAI) — used to process your inputs and generate AI responses. Described in detail in Section 4. openai.com/privacy
- Embedding provider (Nomic Atlas) — used to deliver relevant content based on inputs from the check-in flow. No personal identifiers are sent. Transfers to the United States are governed by Standard Contractual Clauses and Nomic's executed Data Processing Agreement.
- Email and push notification providers — used to deliver transactional service communications (e.g. password changes, account notifications) and, where you have consented, marketing messages. Marketing messages may be personalised based on your in-app interactions (such as check-in topics and verse feedback) to keep them relevant. We do not share your data with third-party advertising networks. You can unsubscribe from marketing communications at any time using the link in any marketing email or by contacting support@mypathly.io.
- Crash and error diagnostics (Sentry) — used to record crash reports and error logs so we can detect and fix stability problems. Sentry processes this data in the European Union. sentry.io/privacy
Sharing where legally required or to defend Pathly.
We will share your information with relevant authorities if obligated to do so by law, and with relevant authorities or legal advisors if necessary to defend Pathly from legal claims or if you have breached our Terms of Use or this Policy.
Sharing in the event of business reorganisation.
In the event of a merger, acquisition, or similar reorganisation, provided that the receiving entity agrees to be bound by this Policy.
4. Sharing of Data with Third-Party AI Services
Important: To provide core conversational features, Pathly securely shares specific, non-identifying inputs with our AI service provider, OpenAI, L.L.C. We do not transmit your name, email address, account credentials, location data, payment information, or any other identifying personal data to the AI service.
What We Share
- Your selected check-in category (e.g. family, work, relationships)
- Your selected emotional state and scripture preference
- Free-text messages and structured choices you make during a session
What We Never Share
We strip away all personal identifiers before network transmission. The following are never shared with OpenAI:
- Your user ID
- Your email address
- Your name
- Your authentication tokens (including Supabase auth tokens)
- Your device identifier
- Your payment information
- Your location data
Your Control & Permissions
In-App Opt-In. Pathly requires your explicit consent via an in-app prompt before processing your first AI request. If you decline, you can still use all non-AI features of the app.
Revoking Consent. You can withdraw consent at any time by contacting support@mypathly.io or deleting your account.
Data Retention. Under OpenAI's API policies, data sent from Pathly is used solely for abuse monitoring, is retained for a maximum of 30 days, and is never used to train OpenAI models or serve advertisements.
5. Use of Artificial Intelligence
Limitations and capabilities of Pathly's AI component.
Not a Substitute for Professional Services. The AI-powered guidance in Pathly is not a replacement for professional mental health counselling, therapy, medical advice, or religious counsel from a qualified authority.
Not a Religious Authority. Pathly's scripture recommendations are intended for personal reflection only and do not represent the views of any religious institution or authority.
Lack of True Understanding. Pathly's AI operates based on patterns in data and may not grasp the nuances or full complexity of your situation.
Not for Crisis Situations. If you are experiencing a crisis, please contact emergency services or a crisis helpline immediately.
Risks involved in using our AI-driven Service.
Potential for Inaccurate Responses. Our AI may generate responses that are factually incorrect, inconsistent, or not sufficiently tailored to your circumstances.
Data Safeguards. Your inputs are processed by OpenAI as described in Section 4. You should avoid sharing highly sensitive information you would not want processed by a third-party AI service.
Dependency Risk. Over-reliance on AI-driven wellness guidance may delay seeking necessary professional help.
6. Crisis Detection & Safety
Pathly includes automated detection for messages that may indicate self-harm, suicidal thoughts, violence, or abuse. If such indicators are detected, the App will display a compassionate support message and provide contact details for international crisis helplines.
Pathly does not automatically contact emergency services on your behalf. If you or someone you know is in immediate danger, please contact your local emergency services directly.
7. International Data Transfer
Your data is primarily stored in the EU (Supabase and Sentry). When we transfer data to processors outside the EEA, we make sure appropriate safeguards are in place:
- Standard Contractual Clauses (SCCs) approved by the European Commission;
- The EU-U.S. Data Privacy Framework, where the recipient is certified; or
- Other transfer mechanisms recognised under GDPR Chapter V.
You can request a copy of the relevant safeguards by emailing support@mypathly.io.
8. Security & Data Retention
- Account information is retained for as long as your account is active
- Session Data and Onboarding Information are retained to enable personalisation
- Following account deletion, personal data will be deleted or anonymised within 30 days, unless retention is required by law
- Support communications may be retained for up to 7 years for legal and compliance purposes
- Crash and error diagnostic data is retained for up to 90 days and then automatically deleted
- Aggregated or de-identified analytics data may be retained indefinitely
We implement appropriate technical and organisational measures including encryption in transit, encryption at rest, and access controls.
9. Revoking Consent & Requesting Deletion
You may revoke your consent or request deletion of your data at any time:
- AI consent: see Section 4.
- Marketing communications: unsubscribe link in any marketing email.
- Account deletion: Settings > Account > Delete Account, or contact support@mypathly.io.
- General privacy requests: contact support@mypathly.io.
Upon receiving a deletion request, we will delete or anonymise your personal data within 30 days, subject to any legal retention obligations.
10. Additional Information for Users in the EU and EEA
- Business name: Pathly
- Email: support@mypathly.io
Legal basis for processing under GDPR.
- Registration & Session Data — performance of contract (Article 6(1)(b))
- Sharing data with OpenAI — explicit consent (Article 6(1)(a)) obtained via in-app consent screen
- Faith tradition and emotional state data — explicit consent under Article 9(2)(a) GDPR, obtained during onboarding
- Diagnostics (crash and error reporting) — legitimate interest (Article 6(1)(f))
- Crisis intervention — vital interests (Article 6(1)(d))
- Legal compliance — legal obligation (Article 6(1)(c))
Your GDPR rights.
You have the right to Access, Rectify, Erasure, Restriction, Data Portability, Objection, and Withdraw Consent. To exercise any right, contact support@mypathly.io. We respond within 30 days.
You may lodge a complaint with your local data protection authority.
11. Additional Information for US Users (CCPA & State Laws)
The Service is operated by Pathly, contactable at support@mypathly.io.
US users may have the right to access, delete, correct, port, and limit use of personal information; opt out of sale (we do not sell); and receive equal service without discrimination. To submit a request, contact support@mypathly.io.
12. Minors
Pathly is not intended for users under the age of 12. If you are between 12 and 18, please use the Service with parental awareness.
If you believe a child under 12 has provided us with personal data, please contact us at support@mypathly.io and we will delete such information promptly.
13. Wellness & Faith Disclaimer
Pathly is an AI-powered faith and emotional wellness app. It is not a licensed mental health provider, therapist, physician, or religious authority. Content provided by Pathly — including scripture recommendations and AI responses — is for personal reflection only.
14. Changes to This Policy
We may update this Policy from time to time. We will notify you through the App or via email. The latest version will always be accessible through the Service.
15. Contact Us
For any questions, concerns, or privacy requests relating to this Policy or your personal data, please contact us:
- Business name: Pathly
- Email: support@mypathly.io