Privacy Policy
Last updated: 27 August 2026
1. Controller
Vajra-Team — Jamie Stein & Markus Stein
Himmelsbörnchen 17, 51588 Nümbrecht, Germany
Email: vajra@etik.com
Phone: +49 152 07654601
This policy covers the Sila app. A separate policy applies to the website vajra-team.eu.
2. What data we process
- Account data: email address and display name, optionally a profile picture
- Journal and practice entries: text, timestamps, virtue and vow assignments, focus, lists and favourites that you enter yourself
- App settings: time slots, reminders, theme, language
- Subscription and purchase status including start and expiry date
- Bug reports: title, description, category and an optional screenshot that you select yourself
- Technical data: platform (iOS or Android), app and runtime version, device type, IP address when our servers are contacted
- Push token, if you enable reminders
3. Account and use of the app
To use the app you create an account with an email address and a password. We process your account data and your entries in order to provide the app, to sync your entries across your devices and to preserve your settings.
The legal basis is Art. 6(1)(b) GDPR (performance of the user agreement).
4. Data on your device
The app is built to work without an internet connection. Your entries, settings and subscription status are therefore first stored locally on your device (the app's database and key store) and then synchronised with your account. This local data leaves your device only for that synchronisation. If you delete the app, the local data is removed with it; the data in your account is unaffected.
5. Hosting and storage location
Account, journal and settings data is stored with Supabase. The server location is Frankfurt am Main, Germany (AWS region eu-central-1) — your data therefore stays inside the European Union. The contracting party and processor is Supabase Pte. Ltd, 65 Chulia Street #38-02/03, OCBC Centre, Singapore 049513. A data processing agreement under Art. 28 GDPR is in place with the provider; as it is established outside the EU, we additionally rely on the European Commission's standard contractual clauses (Art. 46(2)(c) GDPR). More information: supabase.com/privacy
Our website is operated by Infomaniak Network SA, Rue Eugène-Marziano 25, 1227 Les Acacias (Geneva), Switzerland. The server location is Switzerland, for which an adequacy decision of the European Commission exists (Art. 45 GDPR). A data processing agreement is in place here as well.
6. Subscription and payment
We use RevenueCat (RevenueCat, Inc., 1 Letterman Drive, San Francisco, CA 94129, USA) to manage the "Sila Pro" subscription.
The following is transmitted to RevenueCat:
- your user ID in our system (a random string, not your email address),
- purchase and subscription status including start and expiry date,
- the purchase receipts issued by the app store,
- technical device data (device type, operating system and app version, IP address).
The purpose is to check whether your subscription is active and to restore earlier purchases on a new device. The legal basis is Art. 6(1)(b) GDPR (performance of the subscription contract).
We never receive payment details. Payment is handled exclusively by the store you obtained the app from — Apple Distribution International Ltd., Hollyhill Industrial Estate, Hollyhill, Cork, Ireland, or Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. We only learn whether a subscription exists, not which payment method you used. Apple and Google are independent controllers for your payment data; their privacy notices apply.
Transfers to the USA are based on the European Commission's standard contractual clauses (Art. 46(2)(c) GDPR) and, where the provider is certified under the EU-U.S. Data Privacy Framework, additionally on the Commission's adequacy decision (Art. 45 GDPR).
7. Push notifications
When you enable reminders, your device generates a push token. That token is issued by Expo (650 Industries, Inc., 1 Post Street, San Francisco, CA 94104, USA) and stored in our database so that we can deliver reminders and messages to you. Delivery itself runs through your operating system's push service — Apple Push Notification service (Apple) or Firebase Cloud Messaging (Google).
A push token identifies a device, not you as a person. We transmit the content of the notification to Expo, not your journal data.
The legal basis is your consent under Art. 6(1)(a) GDPR, given in the system dialog. You can withdraw it at any time by turning notifications off in your device settings or in the app settings. Withdrawal takes effect for the future.
8. App updates
On start-up the app checks whether a newer version of the program files is available. That check is directed at a server operated by Expo (650 Industries, Inc., USA). It transmits your IP address, device type and operating system version as well as the installed app and runtime version. No journal or account data is transmitted.
The legal basis is Art. 6(1)(f) GDPR — our legitimate interest in providing you with a current, bug-fixed app. Section 6 above applies to transfers to the USA.
9. Profile picture
You may optionally set a profile picture. To do so we request access to your photo library; only the single image you select yourself is transferred. We do not search your photo library and do not read any other images.
The image is stored in our file storage at Supabase under your user ID. The legal basis is Art. 6(1)(a) GDPR (consent given by uploading) or Art. 6(1)(b) GDPR. You can replace the image in the app at any time; it is deleted when you delete your account.
10. Unlocking by a teacher
Certain content in the app only becomes visible once a teacher has unlocked it. If you want content unlocked, you give that person your email address. They can then look you up in the app and see:
- your display name,
- your email address,
- which areas are unlocked for you and since when.
Your journal and practice entries are not visible to teachers. Other users cannot see your entries either.
The legal basis is Art. 6(1)(b) GDPR, as unlocking is part of the service you requested. If you no longer want the unlock, contact us or the person who granted it.
11. In-app messages
We may deliver messages inside the app, for example about maintenance, new features or content notes. We record which message was delivered to you and whether you have already read it. The purpose is to avoid showing you the same message twice.
The legal basis is Art. 6(1)(f) GDPR — our legitimate interest in communicating about the service. We only send promotional messages with your explicit consent under Art. 6(1)(a) GDPR.
12. Bug reports and feedback
When you send feedback via "Report a problem" in the app, we transmit:
- your display name (or your email address instead),
- your email address,
- the category you chose plus the title and description of your report,
- an optional screenshot that you select from your photo library yourself,
- the app version and the platform (iOS or Android).
The transfer runs through a server function at Supabase which automatically creates an entry in our private repository at GitHub. The recipient is therefore GitHub, Inc., 88 Colin P. Kelly Jr. Street, San Francisco, CA 94107, USA. The legal basis is Art. 6(1)(f) GDPR — our legitimate interest in being able to trace and fix errors — and Art. 6(1)(b) GDPR insofar as the report serves the performance of our contract with you.
The entry remains until the reported problem has been dealt with and the entry has been closed and archived. On request we will delete your report earlier — write to vajra@etik.com.
13. No tracking, no advertising
We use no ad networks, no analytics tools for user tracking and no advertising identifiers. We therefore do not ask for permission to track you across apps. There is no automated decision-making, including profiling, within the meaning of Art. 22 GDPR.
14. Minimum age
The app is intended for people aged 16 and over. Anyone younger may only use it with the consent of a parent or guardian. We do not knowingly collect data from children. If you become aware that we hold data of a minor without the required consent, write to vajra@etik.com and we will delete it.
15. How long we keep your data
| Data | Retention |
|---|---|
| Account (email, display name) | until you delete your account |
| Journal and practice entries, focus, lists, favourites | until you delete them, at the latest when the account is deleted |
| Profile picture | until you replace or delete it, at the latest when the account is deleted |
| Push token | until withdrawal, uninstallation or account deletion |
| Subscription and purchase status at RevenueCat | for the term of the subscription and beyond, as long as statutory retention periods apply |
| Bug reports in the GitHub repository | until the entry has been resolved and archived, earlier on request |
| Website server logs | held by the host, available there for at least 7 days according to the provider; we do not evaluate them |
| Purchase records relevant for tax | 10 years under § 147 AO, § 257 HGB |
16. Deleting your account and data
You can delete your account yourself at any time: in the app under "Profile" → "Delete account". This irreversibly removes your access and all data attached to it — entries, settings, profile picture, push token.
Important: this does not cancel a running subscription. Subscriptions are managed exclusively in the store you obtained the app from (iOS: Settings → Apple Account → Subscriptions; Android: Play Store → Payments and subscriptions). Cancel there before you delete your account.
17. Your rights
You have the right of access (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and the right to object to processing based on legitimate interests (Art. 21 GDPR). You can withdraw consent you have given at any time with effect for the future (Art. 7(3) GDPR).
Please write to vajra@etik.com.
You may also lodge a complaint with a data protection supervisory authority. The authority responsible for us is:
Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen
Kavalleriestraße 2–4, 40213 Düsseldorf, Germany
poststelle@ldi.nrw.de
18. Changes to this privacy policy
We reserve the right to update this privacy policy where necessary. The current version is always available at this address.