Skip to content
Vella
FeaturesHow it worksJournalSupport
EN⌄
English✓PortuguêsEspañolFrançaisDeutschItalianoРусскийPolski
Get Vella
FeaturesHow it worksJournalSupportGet Vella

Trust & legal

Vella Privacy Policy

Vella is operated by Madai Tecnologia LTDA. This Privacy Policy explains what information Vella processes, why we process it, how it is protected, and the choices available to you. It applies to the Vella mobile app, website, and related services.

Last updated: August 25, 2026

Vella

Last updated: August 25, 2026

1. Information you provide

You may provide account details such as your email address, profile name, social handle, bio, language, onboarding preferences, goals, reminder choices, and support messages.

When you use Vella, we store the private Prayer Space entries you create, including intentions, prayers you write, prayer check-in dates and counts, answered status, and optional gratitude notes. You may also create private notes and favorites, journey progress, group activity, and public Faith Feed content such as posts, comments, images, likes, follows, mentions, reports, and blocks.

2. Information processed automatically

We process limited technical and service information needed to operate Vella, such as a device identifier for guest features, app version, language, request and error information, notification tokens, and basic interaction records.

Apple and Google process payments. Vella receives subscription status, product identifiers, transaction references, and receipt data needed to validate access, but does not receive your full card number.

To measure product reliability and growth without placing devotional content in analytics, Vella uses first-party analytics with a random pseudonymous installation identifier in the app and a random pseudonymous session identifier on the website. We record only mechanical events such as first open, onboarding steps and completion, paywall views, plan selection, checkout start, purchase-validation results and verified trial or subscription starts, meaningful-session completion, notification permission results and opens, and store-button clicks.

Analytics properties deliberately exclude prayers, searches, Scripture or verse text, notes, posts, profile content, email addresses, names, notification tokens, purchase receipts, religious preferences, and other user-created or devotional content.

Raw analytics events are kept for no more than 90 days and are then deleted or retained only as longer-lived aggregate statistics. We suppress small cohorts in reports to reduce re-identification risk. We do not sell this analytics data or use it to create or upload audiences for targeted advertising.

To measure which Vella campaign led to an installation, Vella processes coarse first-party install attribution alongside the random pseudonymous installation identifier. On Android, the app parses Google Play Install Referrer data, sends only allowlisted source, medium, campaign, and creative codes, and discards the raw referrer on the device. On iOS, a transient Apple AdServices attribution token is sent to Vella's API and exchanged directly with Apple; after validating only coarse, bounded campaign fields, Vella discards both the token and Apple's raw response. After sign-in and creation or hydration of the Vella profile, the installation may be linked to that Vella profile to measure subscription outcomes; creating a shared Supabase Auth account in another app does not count as a Vella acquisition. Vella does not use IDFA, Google Advertising ID (AAID), ATT, device fingerprinting, or cross-app tracking.

Separately from Vella's first-party analytics, the app uses a separate Google Analytics for Firebase SDK stream. The SDK automatically sends an app-instance identifier; device model, platform, operating-system and app versions, and language; approximate location inferred from a masked IP address; and lifecycle, session, engagement, and app-update events.

Automatic client-side in-app purchase events may include subscription product, value, and currency fields, and the SDK may send SDK transport diagnostics needed to deliver and troubleshoot analytics events.

Vella also sends this SDK a closed list of exactly ten custom marketing events: onboarding_begin, onboarding_complete, first_experience_begin, first_experience_complete, vella_profile_initialized, paywall_view, plan_select, begin_checkout, verified_trial_start, and verified_subscription_start. Their properties exclude devotional or other user content, identity, receipts or purchase tokens, notification tokens, localized prices, and raw errors.

In this implementation, Vella does not set a Firebase account user ID or user properties and does not collect an advertising ID through this stream. Ad storage, ad user data, and ad personalization are disabled.

Separately, Firebase Crashlytics automatically receives native crash and ANR reports, stack traces, and coarse app, build, operating-system, and device context needed to diagnose reliability. Vella does not set a Vella account user ID in Crashlytics or attach private devotional content, profile fields, receipts, purchase or notification tokens, or raw JavaScript error messages.

Automatic client-side purchase events are never authoritative subscription validation. Only the custom server-verified verified_trial_start and verified_subscription_start outcomes may be used as verified conversions.

Google's retention and processing for this separate SDK stream follow the configured Google Analytics retention settings and applicable Google terms; Vella's 90-day raw-event retention promise applies only to Vella's first-party analytics and not to Google's SDK stream.

3. How we use information

We use information only for legitimate product and safety purposes, including to:

  • provide authentication, synchronization, daily verses, search, Prayer Space, notes, journeys, groups, and community features;
  • personalize your starting journey and language experience;
  • validate subscriptions and restore purchases;
  • deliver notifications you request;
  • moderate public content, investigate reports, prevent abuse, and secure the service;
  • respond to support requests and improve reliability.

4. AI and service providers

OpenAI processes the text you submit in a natural-language Scripture search to expand it into useful search terms. OpenAI may also help draft reflection prompts and, before publication, process the text of public Faith Feed posts and comments and images you select for a Feed post or profile photo to support safety moderation. We send only the information reasonably needed for each task. Vella does not intentionally save search text as an in-app search history, although limited security or provider logs may be retained under the applicable agreements and policies. AI-drafted commentary or reflection may be inaccurate. Displayed Scripture always comes from an approved edition stored in Vella’s corpus and is never written or translated by AI; available editions may vary by language. Prayer Space text is never included in notification content. If you choose voice transcription, the recording is securely sent to OpenAI only to create an editable draft. Vella does not store the audio; only the text you confirm is saved as prayer content.

When you tap Listen on approved Scripture or narrated Gathering content, Vella may send only the approved public Scripture text or reviewed Vella editorial content and its language to OpenAI to produce an AI-generated voice, not a human recording. Vella stores the returned audio in a private shared server cache and on your device to reduce repeat processing and never sends your prayers, notes, profile, private responses, or other private content for narration.

Our principal processors are Supabase for authentication, database, and file storage; Vercel for website and API hosting; OpenAI for the AI processing described above; Expo for app updates, push-notification infrastructure, and related installation or service diagnostics; and Apple and Google for app distribution, store billing, and notification delivery, including Apple Push Notification service and Firebase Cloud Messaging. They process data needed to provide their services under our agreements, configurations, and their applicable legal terms. We do not sell personal information or use private devotional content for targeted advertising.

5. Sharing, retention, and security

We share information with service providers, app stores, authorities when legally required, or as part of a business transaction subject to appropriate safeguards. Public Faith Feed content is visible to other users according to the feature design.

Retention depends on the purpose of the data, whether your account remains active, legal and financial recordkeeping duties, dispute and fraud-prevention needs, security requirements, and backup cycles. Account, profile, private devotional, journey, and community data is generally kept while your account is active and the data is needed to provide Vella. Prayer Space entries and other content you delete, as well as data removed with account deletion, are deleted from active systems, subject to limited billing, transaction, audit, fraud-prevention, security, legal, and backup records that may remain only as required or permitted. Backup copies persist only until they are overwritten or isolated through scheduled backup rotation. Processors may retain limited copies under our instructions, agreements, and applicable law.

We use technical and organizational safeguards, but no online system can guarantee absolute security.

6. Your choices and rights

You can update preferences, disable notifications, manage or delete individual Prayer Space entries, manage private notes and favorites, block users, cancel a subscription through your store, and delete your account in the app. Depending on where you live, you may also have rights to access, correct, export, restrict, object to, or delete personal information.

To make a privacy request, email privacy@vella.one. We may verify your identity before completing a request. You may also have the right to contact your local data-protection authority.

7. Age eligibility, international use, and changes

Vella is intended only for users who are at least 18 years old, or the legal age of majority where they live if that age is higher. We do not knowingly offer accounts to anyone who does not meet this requirement. If you believe an underage person has provided personal information, contact privacy@vella.one so we can investigate and delete it as appropriate.

Information may be processed in countries other than yours with appropriate safeguards where required. We may update this policy as Vella evolves; material changes will be communicated through the service or another reasonable channel.

8. Contact

For privacy questions or requests, contact privacy@vella.one. For general product support, contact support@vella.one.

Vella

A calmer daily rhythm for Scripture, prayer, and life with God.

Product

HomeFeaturesJournalSupport

Vella

Our approachGet Vellahello@vella.one

Trust & legal

PrivacyTermsCommunity guidelinesDelete your Vella account
EnglishPortuguêsEspañolFrançaisDeutschItalianoРусскийPolski

© 2026 Madai Tecnologia LTDA. All rights reserved.

Made with care for quieter, truer moments.