Riwa · Privacy

Your privacy, explained.

This policy explains how Little Human Group Inc. handles information when you use Riwa and this website.

Effective date:

What Riwa processes

Riwa creates an account identifier for connected features, including guest use. If you register, we process your email address and password to provide your account. The server stores a salted password hash, not your original password, and hashed session credentials.

Our service stores conversations, questions, AI answers and verse citations; daily study plans, voluntarily submitted mood states and responses; completion, streak and reward records; question allowances; and purchase, subscription and entitlement records. Language and time zone help deliver the requested experience. Reading settings, local progress, reminders and widget data are also stored on your device.

Questions, reflections and learning activity may reveal religious beliefs or other sensitive information. Share only what you intend to use with the service. We use these records to provide account access, study features, history, purchases, synchronization, security and abuse prevention.

AI processing and your choice

After your explicit permission for OpenAI, Riwa sends your question, requested language, relevant recent conversation context and selected Quran source material through our server to OpenAI to generate an answer. Generated daily reflections send the selected verse, language and study instructions. Our integration does not deliberately add your account email, password, session credential or App Store receipt to the AI request. Information you put into a question may still be included.

The OpenAI Responses API request sets store:false to disable storage of the response as retrievable application state. This does not establish zero retention: OpenAI may retain abuse-monitoring data and other limited operational data under its applicable terms and account settings. OpenAI states that API data is not used to train its models by default. See its data-controls documentation linked below.

You can decline AI permission and avoid submitting AI requests. Stopping use prevents new submissions; it does not erase content already stored. To remove Riwa content, use conversation/account deletion or contact the privacy address below. A change of AI provider requires fresh provider-specific permission.

Voice, notifications and purchases

Where voice is enabled, it requires microphone and speech-recognition permission. Apple speech recognition uses on-device processing when supported; otherwise Apple may process the audio. Riwa sends the resulting text to its API and AI provider as a question, rather than sending raw microphone audio to the Riwa API. Replies are spoken using Apple speech synthesis. Text turns can be retained in conversation history.

You can revoke microphone, speech and notification permissions in iOS Settings. Reading reminders are local notifications. Apple handles App Store payment details; Riwa processes signed transaction information and account-linked entitlements to deliver purchases and prevent repeat redemption. We do not receive your full payment-card details from StoreKit.

Service providers, hosting and website

Riwa uses Alibaba Cloud hosting in Frankfurt, Germany, OpenAI for the AI processing described above, and Apple services for purchases and, when needed, speech recognition. We may also process correspondence you send to our support/privacy contact to respond to your request.

The website uses no analytics scripts, advertising trackers, cookies or external font services. Servers necessarily receive connection information such as IP addresses. The API uses IP addresses in memory for request limits. The supplied web server configuration does not enable access logs, but hosting, security or system services may process operational records.

Operational records may be retained for security, maintenance, troubleshooting and applicable legal obligations. Records held by hosting and other service providers follow their applicable terms and settings. We do not promise that all infrastructure or provider logs are disabled.

Hosting is in Germany. Apple and OpenAI may process data in other countries under their applicable terms and safeguards. Applicable protections and your rights can depend on your location. Contact us for questions about international processing.

Retention and deletion

Account-linked service records remain available while the account exists unless you delete the relevant content. The current service does not automatically delete older accounts or conversations based on age. Deleting a conversation removes its messages and cached answer content from the live database, while non-content identifiers/status remain to prevent replay and duplicate quota credit.

Use Settings → Account → Delete account to delete a guest or registered account. Registered accounts require the current password. This removes the account and its linked service records from the live database. Minimal consumable-purchase records (transaction identifier, a one-way account-owner hash, and benefit category where applicable) remain to prevent repeat redemption; these records currently have no automatic expiry.

Resetting local app data is separate from deleting a server account. Account deletion does not cancel an Apple subscription. Manage subscriptions through Apple separately. Copies held in backups and by service providers follow their applicable retention processes; deleting a live record does not instantly erase every backup.

Backup copies, if created, may remain for recovery needs until their replacement or removal. Their retention depends on recovery needs and applicable legal obligations, rather than a fixed deletion period promised here. A restored backup may contain older records; contact us about any deletion request that needs to be applied to recovered data.

Your requests and policy updates

Contact fxvisiongo@gmail.com for privacy questions, access, correction, deletion or export requests, or to withdraw consent for processing that relies on consent. We may need to verify your identity. Contact fxvisiongo@gmail.com for app support. Do not send passwords or full payment-card information.

Depending on applicable law, you may have rights to access, correct, erase or receive your information, restrict or object to processing, withdraw consent, and complain to the relevant data-protection authority. Requests are assessed under the law that applies to you; withdrawal does not invalidate earlier lawful processing.

Riwa is not designed to collect information from children who cannot consent under applicable law. A parent or guardian who believes a child has provided information can contact us to request its removal. We will update this page when our practices change; the effective date identifies the current policy.

Useful links

OpenAI · Data controls Apple · Privacy