Skip to content

VIVIDiary Privacy Policy

Note: This Privacy Policy reflects compliance with Swiss Federal Act on Data Protection (FADP), European Union General Data Protection Regulation (GDPR), and California Consumer Privacy Act (CCPA) / California Privacy Rights Act (CPRA).

The Data User is committed to protecting the privacy and personal data of Data Subjects in accordance with applicable data protection laws.

This Privacy Policy sets out the Data User's practices regarding the collection, use, retention, disclosure, and security of personal data obtained through the "VIVIDiary" application.

1. Scope and Definitions

Definitions

For the purposes of this Privacy Policy:

  • Data Subject: Any living individual who is the subject of personal data held by the Data User.
  • Data User/Controller: "Clayee Co., Ltd." and any of its subsidiaries, affiliates, or related companies that collect, hold, process, or use personal data.
  • Personal Data: Any data relating to a living individual from which it is practicable for the identity of the individual to be directly or indirectly ascertained.
  • Processing or Use: Any operation performed on personal data, including collection, recording, holding, storage, retrieval, alteration, consultation, disclosure, erasure, or destruction.
  • Third Party: Any person, company, or organization other than the Data User or Data Subject.
  • Consent: Voluntary agreement given by a Data Subject for the collection, use, or disclosure of their personal data for specified purposes.
  • Sensitive Personal Data: Personal data consisting of information relating to the physical or mental health, sexual life, commission or alleged commission of offences, or other particularly sensitive matters.
  • Cross-border Transfer: The transfer of personal data to a place outside Switzerland or the European Economic Area (EEA).
  • Cookies: Small text files placed on a device to collect standard internet log information and visitor behavior data.
  • Services: The products, services, websites, applications, or platforms provided by the Data User.
  • EEA: European Economic Area, comprising EU Member States plus Iceland, Liechtenstein, and Norway.

2. Data We Collect

The Data User collects Personal Data directly from Data Subjects through various means including but not limited to registration forms, account creation, service applications, surveys, communications, and interactions with the Data User's platforms and Services.

The Data User may collect Personal Data indirectly from Third Parties including business partners, service providers, publicly available sources, and other legitimate sources where Data Subjects have provided appropriate Consent or where permitted by law.

2.1 Account & Profile

  • Data: Email, password (hashed), nickname/avatar, date of birth, language/region
  • Purpose: Sign-up & authentication, cross-device sync, customer support

2.2 Content & Sync

  • Data: Diary/notes text, versioning & conflict-resolution metadata
  • Purpose: Cross-device synchronization, backup/restore

2.3 Device/Logs/Diagnostics

  • Data: App/browser version, OS & device model, server logs (IP, request path, timestamps), performance & usage events, crash/ANR logs
  • Purpose: Security, incident investigation, quality & performance improvement

2.4 Payments/Subscriptions

  • Data: Product IDs, transaction/receipt identifiers, subscription start/renewal/expiration, free trial/intro offers, price/currency
  • Purpose: Subscription provisioning, receipt validation, refunds/support, fraud prevention

2.5 Voice & Speech-to-Text

  • Data: Microphone input (audio samples/recordings), derived text transcripts, language/locale, timestamps, and limited diagnostic metadata (e.g., recognition errors)
  • Purpose: Provide voice input features (dictation/commands) and generate transcripts. Diagnostics may be processed to stabilize recognition quality

2.6 Health & Fitness Data

  • Data: Step count and sleep duration/sessions, read from Apple Health (HealthKit) on iOS and from Health Connect on Android, only after you grant permission. The app reads this data; it does not write to Apple Health or Health Connect.
  • Purpose: To pre-fill your daily check-in and to show activity and sleep patterns alongside your mood.
  • Handling: This is health data (special category data under GDPR Article 9, and "sensitive personal information" under applicable U.S. state laws), processed only on the basis of your explicit consent. It is never used for advertising or marketing, is never sold, and is never shared with advertising networks, data brokers, or analytics/advertising SDKs. You may revoke access at any time in your device's Health settings.

2.7 Period & Menstrual Data

  • Data: Menstrual/period entries that you choose to log in the app.
  • Purpose: To provide period tracking within your diary.
  • Handling: This is health/special-category data and sensitive personal information, processed only on the basis of your explicit consent. It is never used for advertising or marketing, is never sold, and is never shared with third parties for those purposes.

2.8 Photos & Images

  • Data: Photos or images you attach to your diary entries.
  • Purpose: To enrich your diary entries.
  • Handling: We do not perform facial recognition or biometric identification on your photos. If a photo reveals health information, it is treated under the same protections as the health data described above.

2.9 AI and Conversation Data Usage

Important Statement on Conversation Data:

We will never use or disclose the content of your diary entries for marketing or advertising purposes.

AI Training and Service Improvement: Your diary entries may be used to improve AI interactions and service quality in anonymized form. However, this usage is limited to service improvement purposes only and does not include marketing activities.

3. Purpose, Use, and Legal Basis

3.1 Primary Processing Purposes

The Data User collects and processes Personal Data for the following purposes:

  • To provide, maintain, and improve the Services offered by the Data User
  • To process transactions, fulfill orders, and manage customer accounts
  • To communicate with Data Subjects regarding the Services, including customer support and service notifications
  • To comply with legal and regulatory obligations under applicable laws

3.2 Secondary Processing Purposes

The Data User may Use Personal Data for secondary purposes including:

  • To conduct market research, surveys, and analysis to improve business operations
  • To develop new products and Services or enhance existing offerings
  • To detect, prevent, and investigate fraud, security breaches, or other illegal activities
  • To maintain records for audit, accounting, and business administration purposes

3.3 Legal Basis for Processing (GDPR)

For users in the European Economic Area (EEA) and United Kingdom, we process your personal data based on the following legal grounds:

Processing ActivityLegal BasisExplanation
Account creation and authenticationPerformance of Contract (GDPR Art. 6(1)(b))Necessary to provide the core service you signed up for
Diary data storage and synchronizationPerformance of Contract (GDPR Art. 6(1)(b))Essential functionality of the VIVIDiary service
Service quality improvement and bug fixesLegitimate Interest (GDPR Art. 6(1)(f))We have a legitimate interest in improving user experience and service stability
Subscription management and payment processingPerformance of Contract (GDPR Art. 6(1)(b))Required to deliver paid services
Marketing communicationsConsent (GDPR Art. 6(1)(a))You can withdraw consent at any time
Legal compliance (tax, financial reporting)Legal Obligation (GDPR Art. 6(1)(c))Required by tax laws, financial regulations
Security and fraud preventionLegitimate Interest (GDPR Art. 6(1)(f))Protecting our services and users from security threats

When we rely on legitimate interests, we have assessed that our interests do not override your fundamental rights and freedoms. You have the right to object to processing based on legitimate interests.

3.4 Marketing and Communication Purposes

The Data User may Use Personal Data to send promotional materials, newsletters, and marketing communications where Consent has been obtained or as otherwise permitted under applicable law.

Data Subjects may withdraw Consent for marketing communications at any time through the methods specified in such communications or by contacting us at support@vividiary.live.

3.5 Limitations on Data Usage

The Data User will not Use Personal Data for purposes other than those specified in this Privacy Policy without obtaining appropriate Consent from Data Subjects, except as required or permitted by law.

Any Processing of Sensitive Personal Data will only be conducted with explicit Consent from Data Subjects or as otherwise permitted under applicable data protection laws.

Health and sensitive data are never used for advertising. Health and fitness data (steps, sleep), menstrual/period data, and photos are never used for advertising or marketing, are never sold, and are not shared with advertising networks, data brokers, or analytics/advertising SDKs.

4. Third Party Services

The Data User uses third-party service providers to help us with various operations, such as payment processing, email automation, website and app diagnostics, analytics, and others. These third parties have access to your information only to perform these tasks on our behalf and are obligated not to disclose or use it for any other purpose.

Payment Processing

The Data User utilizes Apple and Google to process all financial transactions:

  • Apple Store In-App Payments
  • Google Play In-App Payments
  • RevenueCat: In-app subscription management, receipt validation, and webhook notifications of subscription events. Subscriber Attributes must not contain sensitive or security-critical data.

Data Infrastructure

The Data User uses third-party service providers to manage our core data infrastructure and user authentication:

  • Supabase: Authentication, database (Postgres), storage, logs/telemetry. The Data User enforces Row Level Security (RLS) so that each user can access only their own records. Private storage buckets are accessed via signed URLs or appropriate authorization.

Speech Processing

The Data User uses third-party service providers to process speech input for real-time conversion into text:

  • Speech-to-Text Processor(s): Real-time conversion of voice input to text on our servers. Unless you opt in to audio retention or improvement programs, raw audio is processed transiently and not retained by the processor.

5. Data Sharing, Disclosure, and International Transfers

5.1 Categories of Recipients

The Data User may share or disclose Personal Data to Third Parties only in accordance with the purposes for which it was collected or as otherwise permitted under applicable law.

The Data User may share Personal Data with the following categories of Third Parties:

  • Service providers and contractors who assist in delivering Services or conducting business operations on behalf of the Data User
  • Professional advisors including legal counsel, auditors, and consultants who require access to Personal Data in the course of providing professional services
  • Business partners and affiliates for legitimate business purposes related to the provision of Services
  • Financial institutions and payment processors for transaction processing and fraud prevention purposes

5.2 Legal Disclosure Requirements

The Data User may disclose Personal Data where required or permitted by law, including:

  • Compliance with court orders, legal processes, or regulatory requirements
  • Cooperation with law enforcement agencies or government authorities in accordance with applicable laws
  • Protection of the Data User's legal rights, property, or safety, or that of Data Subjects or the public

5.3 No Sale of Personal Data

Personal Data will not be sold, rented, or otherwise commercially disclosed to Third Parties for their independent marketing purposes without the explicit Consent of the Data Subject.

5.4 International Data Transfers

VIVIDiary uses service providers such as Supabase (United States) and RevenueCat (United States) that may be located outside the EEA. When we transfer personal data outside the EEA, we ensure appropriate safeguards are in place.

Transfer Mechanisms:

  • Standard Contractual Clauses (SCCs): We use European Commission-approved Standard Contractual Clauses with our service providers to ensure your data receives adequate protection when transferred outside the EEA.
  • Adequacy Decisions: Where applicable, we rely on European Commission adequacy decisions that recognize certain countries as providing adequate data protection.

Additional Safeguards:

  • Encryption in transit (TLS 1.3)
  • Encryption at rest (AES-256)
  • Role-based access controls limiting who can access your data
  • Regular security assessments and audits

Your Rights: You may request a copy of the Standard Contractual Clauses by contacting support@vividiary.live.

Data Localization: We do not currently offer EEA-based data centers, but may consider this option based on user demand in the future.

5.5 Third-Party Obligations

The Data User shall ensure that Third Parties receiving Personal Data are contractually bound to implement appropriate security measures and use the Personal Data only for the specified purposes.

6. Data Retention

The Data User shall retain Personal Data only for as long as necessary to fulfill the purposes for which it was collected or as required by applicable law.

Personal Data collected for different purposes may be subject to different retention periods as follows:

Data CategoryRetention PeriodPurpose
Account information (email, password)Account active period + 90 daysAccount recovery, legal compliance
Diary content (text, voice)Until user deletionService provision
Backup dataUp to 90 days after deletionDisaster recovery
Subscription and payment information7 years from last transactionTax compliance, refund processing
Service operation logs (IP, timestamps)12 months from collectionSecurity, troubleshooting
Marketing consent dataUntil consent withdrawalMarketing communications
Customer support tickets3 years from resolutionService quality improvement

Early Deletion: Personal Data may be deleted earlier than the periods stated above if the retention purpose is achieved or there is no legal obligation to retain it.

Inactive Accounts: Accounts with no login activity for 2 years may be deleted after prior notice and a 30-day grace period.

Upon expiry of the applicable retention period, Personal Data shall be securely disposed of or anonymized unless:

  • The Data User is required by law to retain such data for a longer period; or
  • The Data Subject has provided specific Consent for extended retention

Data Subjects may request information about the retention periods applicable to their Personal Data and may request early disposal where legally permissible.

7. Data Security

7.1 Technical Security Measures

The Data User implements appropriate technical and organizational security measures to protect Personal Data against unauthorized access, processing, erasure, loss or use, or accidental loss, destruction or damage.

Technical Security Measures include but are not limited to:

  • Encryption in transit: TLS 1.3 protocol for all data transmission
  • Encryption at rest: AES-256 encryption for stored data
  • Implementation of firewalls, intrusion detection systems, and anti-virus software to protect against cyber threats
  • Regular software updates and security patches to maintain system integrity
  • Secure backup procedures and disaster recovery protocols
  • Role-based access controls: Limiting data access based on job function
  • Strong authentication: Password requirements and two-factor authentication where available
  • Endpoint security: Protection of devices accessing our systems
  • Regular security audits: Annual compliance audits and penetration testing

7.2 Organizational Security Measures

Access Controls ensure that:

  • Access to Personal Data is limited to authorized personnel on a need-to-know basis
  • User authentication and authorization protocols are implemented for all systems Processing Personal Data
  • Regular reviews of user access rights are conducted and access is promptly revoked upon termination of employment or change of role
  • All employees and contractors with access to Personal Data are bound by confidentiality obligations and receive appropriate data protection training

7.3 Security Limitations

While we implement industry-standard security measures, no method of electronic transmission or data storage is completely secure. We cannot guarantee absolute security of your personal data.

7.4 Data Breach Response

In the event of a data breach or suspected security incident involving personal data, the Data User will:

Immediate Response:

  • Take immediate steps to contain the breach and mitigate potential harm
  • Conduct an investigation to determine the cause, scope, and impact of the incident

Supervisory Authority Notification:

  • Notify the relevant supervisory authority (e.g., EEA data protection authorities) within 72 hours of becoming aware of a breach, unless the breach is unlikely to result in a risk to the rights and freedoms of individuals
  • Provide information about the nature of the breach, affected data subjects, likely consequences, and measures taken

Data Subject Notification:

  • Notify affected Data Subjects without undue delay when the breach is likely to result in a high risk to their rights and freedoms
  • Notifications will be sent via email or in-app notification in clear and plain language
  • Include information about: the nature of the breach, measures taken to address it, and recommended protective actions

Notification Exemptions:

Data Subject notification may be exempted when:

  • Appropriate technical protection measures (e.g., encryption) were applied, making the data unintelligible to unauthorized persons
  • Subsequent measures have been taken to ensure the high risk is no longer likely to materialize
  • Notification would require disproportionate effort (in which case a public communication will be made instead)

Remedial Measures:

  • Implement corrective actions to prevent similar incidents from occurring in the future
  • Document all breaches and responses for regulatory compliance

8. Your Rights

8.1 Universal Data Subject Rights

You have the following rights regarding your personal data:

  • 1. Right of Access: Request information about the personal data we hold about you and how it is processed.
  • 2. Right to Rectification: Request correction of inaccurate or incomplete personal information.
  • 3. Right to Erasure: Request deletion of your personal information in certain circumstances, subject to legal and contractual obligations.
  • 4. Right to Data Portability: Receive your personal information in a structured, commonly used format where technically feasible.
  • 5. Right to Object to Marketing: Object to direct marketing communications at any time.
  • 6. Right to Withdraw Consent: Where processing is based on consent, you may withdraw your consent at any time.

8.2 How to Exercise Your Rights

Contact Methods:

  • Email: support@vividiary.live

Identity Verification: For your security, we may request additional information to verify your identity before processing your request (e.g., email address, account information).

Response Timeline: We aim to respond to your requests within a reasonable timeframe, typically within 30 days of receipt. Complex requests may require additional time, and we will notify you if an extension is necessary.

8.3 Limitations on Rights

Your request may be denied or limited in the following circumstances:

  • 1. Legal Obligations: When law requires us to retain the personal data (e.g., tax law, financial regulations)
  • 2. Legal Claims: When necessary for the establishment, exercise, or defense of legal claims
  • 3. Contractual Necessity: When essential to fulfilling our contract with you (e.g., managing an active subscription)
  • 4. Public Interest: When required for important public health or other public interest reasons
  • 5. Manifestly Unfounded or Excessive Requests: Particularly repetitive requests may be refused or subject to a reasonable administrative fee
  • 6. Technical Limitations: Immediate deletion from backup systems may not be technically feasible (up to 90 days)
  • 7. Third-Party Rights: When fulfilling your request would infringe on the rights and freedoms of others

Fees for Excessive Requests: For manifestly unfounded or excessive requests, especially repetitive ones, we may charge a reasonable administrative fee or refuse the request.

Refusal Notification: If we refuse your request, we will inform you of the reasons and your right to lodge a complaint with a supervisory authority.

8.4 Right to Lodge a Complaint

You have the right to lodge a complaint with a data protection supervisory authority:

EEA/UK Residents: You may lodge a complaint with the data protection authority in your country of residence, place of work, or where an alleged infringement occurred.

Swiss Residents: Federal Data Protection and Information Commissioner (FDPIC) (contact details in Section 11).

9. Cookies and Tracking

The Data User uses Cookies and similar tracking technologies on its websites, mobile applications, and digital platforms to collect information about Data Subjects' interactions with the Services.

Types of Cookies Used

  • Essential Cookies: Necessary for the basic functionality of the Services and cannot be disabled
  • Functional Cookies: Enhance user experience and remember Data Subjects' preferences and settings
  • Analytics Cookies: Collect information about how Data Subjects use the Services for statistical analysis and service improvement
  • Marketing Cookies: Track Data Subjects' browsing behavior for targeted advertising and promotional purposes

Cookie Consent

The Data User will obtain Consent from Data Subjects before placing non-essential Cookies, except where exempted under applicable law.

Data Subjects may withdraw their Consent at any time through cookie preference settings or browser controls.

Cookie Management

Data Subjects can manage Cookie preferences through:

  • The Data User's cookie banner or privacy preference center
  • Browser settings (though this may affect the functionality of the Services)

The Data User will retain Cookie data in accordance with the data retention periods specified in Section 6 of this Privacy Policy.

10. Children's Privacy

Our Service does not address anyone under the age of 13. We do not knowingly collect Personal Data from children under 13. If You are a parent or guardian and believe Your child has provided Personal Data, please contact support@vividiary.live. We will investigate any notification and, if appropriate, delete the Personal Data from our systems.

11. Contact Information

General Inquiries

Data Subjects may contact the Data User regarding any privacy-related inquiries, complaints, or requests to exercise their rights:

  • Email: support@vividiary.live
  • Postal Address: 460 Yeongtong-ro, Yeongtong-gu, Suwon-si, Gyeonggi-do, Republic of Korea

All data access requests, correction requests, and other inquiries relating to Personal Data should be directed to the designated data protection contact.

Identity Verification: When contacting the Data User, Data Subjects should provide sufficient information to enable identity verification and location of the relevant Personal Data.

Federal Data Protection and Information Commissioner (Switzerland)

Data Subjects may lodge complaints regarding the Data User's handling of Personal Data directly with the Federal Data Protection and Information Commissioner (FDPIC), Switzerland:

  • Website: https://www.edoeb.admin.ch
  • Address: Feldeggweg 1, 3003 Bern, Switzerland
  • Telephone: +41 58 462 43 95

12. Additional Information for EEA and UK Users (GDPR)

This section provides additional information for users in the European Economic Area (EEA) and United Kingdom.

12.1 Data Controller

Clayee Co., Ltd. acts as the data controller for the processing of your personal data. This means we determine the purposes and means of processing your personal data. Contact: support@vividiary.live

12.2 Contact for Data Protection Inquiries

For all data protection inquiries and to exercise your GDPR rights, EEA and UK residents may contact us directly at:

Email: support@vividiary.live

We are committed to responding to all requests in a timely manner in accordance with GDPR requirements.

You also retain the right to lodge complaints with your local supervisory authority (see Section 12.3).

12.3 Supervisory Authority

You have the right to lodge a complaint with a supervisory authority, in particular in the EU Member State of your habitual residence, place of work, or place of alleged infringement.

  • List of EU Supervisory Authorities: https://edpb.europa.eu/about-edpb/board/members_en
  • UK Supervisory Authority - Information Commissioner's Office (ICO): Website: https://ico.org.uk | Telephone: 0303 123 1113

12.4 Legal Basis for Processing

Please refer to Section 3.3 for detailed information about the legal basis for each processing activity under GDPR Article 6.

12.5 Your GDPR Rights

In addition to the rights outlined in Section 8, EEA and UK users have specific GDPR-protected rights, including:

  • Right to lodge a complaint with your local supervisory authority
  • Right to an effective judicial remedy against the supervisory authority or against the controller
  • Right to withdraw consent at any time (where processing is based on consent)

12.6 Data Retention

Please refer to Section 6 for information about how long we retain your personal data.

12.7 International Transfers

Please refer to Section 5.4 for information about how we protect your data when it is transferred outside the EEA.

13. Additional Information for California Residents (CCPA/CPRA)

This section applies to California residents and supplements the information in this Privacy Policy with disclosures required by the California Consumer Privacy Act ("CCPA") and the California Privacy Rights Act ("CPRA").

13.1 Sale and Sharing of Personal Information

No Sale: We do NOT sell your personal information for monetary consideration.

No Sharing for Cross-Context Behavioral Advertising: We do NOT currently share personal information for cross-context behavioral advertising purposes.

13.2 Your California Privacy Rights

California residents have the following rights under CCPA/CPRA:

  • Right to Know: Request information about personal information collected in the last 12 months
  • Right to Delete: Request deletion of personal information, subject to certain legal exceptions
  • Right to Correct: Request correction of inaccurate personal information
  • Right to Non-Discrimination: Not receive discriminatory treatment for exercising CCPA rights

Contact Methods:

  • Email: support@vividiary.live

Response Timeline: We will respond within 45 days of receipt. If more time is needed, we may extend by an additional 45 days with prior notice.

14. Policy Updates

The Data User reserves the right to update, modify, or replace this Privacy Policy at any time to reflect changes in business practices, legal requirements, or operational needs.

14.1 Notification of Changes

Material Changes: For material changes that significantly affect the processing of Personal Data or the rights of Data Subjects:

  • We will provide at least 30 days' advance notice
  • Notice will be sent via email to registered users (where contact information is available)
  • Notice will be posted on our website and in-app
  • The effective date of changes will be clearly indicated

Non-Material Changes: For non-material changes (e.g., contact information updates, clarity improvements, typo corrections):

  • Website posting is sufficient
  • No separate notification will be sent

14.2 Implied Consent

Continued use of the Services after the effective date constitutes acceptance of the updated Privacy Policy.

14.3 If You Disagree

If you do not agree to the changes:

  • You must discontinue use of the Services before the effective date
  • You may request deletion of your Personal Data in accordance with Section 8
  • Your rights under the previous version of the Privacy Policy will apply until you stop using the Services

15. Governing Law and Jurisdiction

15.1 Governing Law

This Privacy Policy is governed by and interpreted in accordance with the laws of Switzerland. Consumer Protection Override: If the laws of your jurisdiction provide stronger consumer protections or data protection rights, those laws will apply and take precedence.

15.2 Dispute Resolution

Disputes related to this Privacy Policy will be resolved in the following order:

  • 1. Negotiation: Written notice to us followed by a 30-day negotiation period
  • 2. Arbitration: If negotiation fails, disputes will be resolved through arbitration under the Swiss Chambers' Arbitration Institution rules
  • 3. Litigation: If arbitration is not possible, parties consent to the exclusive jurisdiction of the courts of Zurich, Switzerland (subject to mandatory consumer protection jurisdictions)

15.3 EEA/UK Resident Exceptions

EEA and UK residents have the right to:

  • Bring legal proceedings in the courts of their country of residence
  • Have GDPR and local data protection laws apply with priority over this governing law clause

15.4 California Resident Exceptions

California residents have the right to:

  • Bring legal proceedings in California courts
  • Have CCPA and California consumer protection laws apply with priority

16. Acknowledgment and Consent

By using the VIVIDiary Services, you acknowledge that:

  • You have read and understood this Privacy Policy
  • You consent to the collection, use, and disclosure of your personal data as described in this Privacy Policy
  • You understand your rights and how to exercise them
  • You understand how to contact us with privacy-related inquiries or complaints

Company: Clayee Co., Ltd. · Address: 460 Yeongtong-ro, Yeongtong-gu, Suwon-si, Gyeonggi-do, Republic of Korea
Application: VIVIDiary · Website: vividiary.live · Contact: support@vividiary.live
Last updated: June 12, 2026