Cinematic dark mode background asset representing a private digital third space

Vairi Privacy Policy

Full legal text at vairi.app/privacy-policy. Data Controller: Vairi, 8 Devonshire Square, London, EC2M 4YJ, United Kingdom. Privacy contact: hello@vairi.app.

1. Who We Are (Data Controller)

Vairi is a web-based application (Progressive Web App) accessible at vairi.app. We do not currently distribute a native mobile app on the Apple App Store or Google Play.

2. Information We Collect

Collected data falls into three categories, each with its own legal basis, retention period and sharing rules: Core Matching & Profiling Data (used exclusively for matching and our AI engine, on a performance-of-contract and explicit-consent basis), Technical, Analytics & Marketing Data (account security, and only with consent, product analytics or advertising measurement), and Account & Authentication Data (email address, hashed one-time passwords, and Google OAuth details if you sign in that way).

3. What We Actually Share With Meta & Google

With marketing consent, only a SHA-256 hashed email and internal user ID, Meta's own click/browser ID cookies, browser user-agent, and event name/page URL are sent to Meta for ad measurement. Google Analytics 4 receives standard pageview and route-change events under the same consent gate, using Google Consent Mode v2. SHA-256 hashing is pseudonymisation, not anonymisation, under UK/EU GDPR.

4. What We Never Share With Advertisers

Regardless of consent given, message contents, behavioural quiz answers and derived psychological scores, date of birth, precise location, post-reveal identity, match details, and Vairi Concierge conversation data never leave Vairi's database for advertising purposes.

5. Subprocessors & International Transfers

Sub-processors include Supabase/AWS (database, EU-Frankfurt), OpenAI (AI concierge, USA, SCCs), Resend (email, USA, SCCs), Stripe (payments, USA/Ireland, SCCs), Daily.co (optional video calls, USA, SCCs), Cloudflare (CDN, global), Meta and Google (consent-gated, USA/Ireland, SCCs), and Microsoft Clarity (consent-gated session analytics, USA, SCCs). Transfers outside the UK/EEA are protected by Standard Contractual Clauses and the UK International Data Transfer Addendum.

6. How Long We Keep Your Data

Chat messages are retained for 90 days after a match closes, then automatically purged. Match metadata is kept while the account is active. Analytics/funnel events are retained up to 24 months aggregated, consent logs for 5 years, payment records for 7 years (UK tax law), and encrypted backups for a rolling 30 days after deletion.

7. Automated Decision-Making & AI Profiling (Art. 22 GDPR)

Vairi's matching engine derives a psychological profile from quiz answers to suggest compatible matches, which is automated profiling under Art. 22 GDPR. You can request human review, contest a result, or opt out of profiling entirely (which means matching cannot be offered). Matching decisions do not affect access to essential services, healthcare, employment, or credit.

7a. Chat Insights & Vairi in Your Conversations (opt-in)

Two AI features inside conversations are off by default: Chat Insights (analyses only your own messages if you opt in, saving short interest notes you can view and delete) and Summoning Vairi Concierge into a chat (public suggestions visible to both people; private questions answered only to the asker and not stored).

8. Your Rights Under UK & EU GDPR

You have the right to access, rectify, erase, restrict or object to processing, port your data in a machine-readable format, and withdraw consent at any time without affecting prior lawful processing.

9. Account & Data Deletion (Right to Erasure)

Delete in-app via Personal Space > settings > Delete account (immediate, cascades through 20+ tables) or by emailing hello@vairi.app with subject "Data Deletion Request" (actioned within 30 days). This section also satisfies Meta and Google Developer Data Deletion requirements for OAuth users.

10. Cookies & Similar Technologies

Strictly necessary cookies (auth session, CSRF token, consent record) are always on. Analytics (Google Analytics 4, Microsoft Clarity) and advertising (Meta Pixel) cookies require consent. Choices can be changed anytime by clearing the vairi_cookie_consent entry in local storage.

11. Children

Vairi is not intended for users under 18 and we do not knowingly collect data from anyone under 18.

12. Security

TLS 1.2+ in transit and AES-256 encryption at rest, Row Level Security on every database table, isolated edge functions for sensitive workloads, and segregated payment processing via Stripe.

13. Changes to This Policy

Changes are posted on this page with an updated "Last updated" date. Material changes, such as a new sub-processor, are notified by email at least 14 days before taking effect.

14. Contact Us

Questions or requests: hello@vairi.app, or by post to the address in Section 1. Replies aim for 5 working days and always within the 30-day GDPR limit.

Proudly listed on Launchpadly Startup Directory