Privacy Policy
Effective Date: February 27, 2026
Last Updated: April 7, 2026
Welcome to Viv
At Viv ("we," "us," or "our"), we are committed to protecting your privacy and being transparent about how we collect, use, and share your information. This Privacy Policy explains our practices when you use our AI-powered travel companion service, including our website at heyviv.ai, our mobile application (package name: ai.heyviv.app), and all related services (collectively, the "Service").
By using Viv, you agree to the collection and use of information in accordance with this policy. If you do not agree with this policy, please do not use our Service.
1. Information We Collect
Information You Provide
We collect information you provide directly to us, including:
- Name, email address, and account credentials
- Travel preferences, interests, and behavioral data
- Messages, prompts, and conversations with our AI travel assistant
- Trip plans, itineraries, and saved destinations
- Profile information and display preferences
- Feedback, reviews, and support communications
Information Collected Automatically
When you use our Service, we automatically collect:
- Device information (type, operating system, unique device identifiers)
- Usage data (features accessed, interaction patterns, session duration)
- Log data (IP address, browser type, access times, referring URLs)
- Location information (with your explicit permission via device settings)
- Push notification tokens (for delivery of service notifications)
Guest Session Data
If you use Viv without creating an account (via our "Try Before You Sign Up" feature), we collect limited session data including a temporary session identifier, conversation history, and any trip previews generated. This data is associated with a temporary guest token and is automatically deleted after 30 days of inactivity. If you later create an account, your guest session data may be converted and associated with your new account.
2. How We Use Your Information
We use your information to:
- Personalize Your Experience: Our AI learns your preferences to create tailored travel recommendations and itineraries
- Provide Core Services: Enable features such as AI-powered trip planning, destination discovery, itinerary management, and booking assistance
- Connect You with Ambassadors: Match you with verified local experts who can enhance your travel experience with insider knowledge
- Process AI Conversations: Your messages are processed by our AI system to generate relevant travel recommendations and responses
- Improve Our Service: Analyze anonymized usage patterns to enhance our AI models, develop new features, and improve performance
- Communicate with You: Send service updates, travel recommendations, account notifications, and respond to your inquiries
- Ensure Safety and Security: Protect against fraud, abuse, unauthorized access, and security threats
3. AI and Data Processing
Viv uses artificial intelligence to provide personalized travel recommendations. When you interact with our AI assistant:
- Your messages and conversation context are processed by third-party AI providers (currently Together AI) to generate responses
- We implement prompt sanitization and input validation to protect against misuse of our AI systems
- Conversation data may be used in anonymized, aggregated form to improve our AI models and service quality
- AI-generated recommendations are based on your stated preferences, location context, and general travel knowledge — not on tracking your behavior across other websites or services
- You can request deletion of your conversation history at any time through your account settings or by contacting us
4. Information Sharing
We do not sell your personal information. We may share your information in the following limited circumstances:
With Your Consent
We share information when you explicitly agree, such as connecting you with local Ambassadors or sharing your itinerary with travel companions.
Service Providers
We work with trusted third-party providers who assist in operating our Service. These include:
- Together AI — AI model hosting and inference
- Render — Cloud infrastructure and hosting
- Resend — Transactional email delivery
- Google Maps / Places — Location and mapping services
- Firebase — Push notifications and analytics
- Sentry — Error monitoring and performance tracking
- Vercel — Website hosting
All service providers are bound by confidentiality agreements and process data only as instructed by us.
Legal Requirements
We may disclose information when required by law, to comply with legal process, to protect our rights, to prevent fraud, or to ensure user safety.
5. Data Security
We implement industry-standard security measures to protect your information, including:
- HTTPS/TLS encryption for all data in transit
- Encrypted database storage for sensitive information
- JWT-based authentication with token blacklisting for session management
- Input sanitization and prompt injection protection on AI endpoints
- Regular security audits and vulnerability assessments
- Role-based access controls for administrative functions
While we strive to protect your information, no method of transmission over the internet is 100% secure. We encourage you to use strong, unique passwords and keep your account credentials confidential.
6. Data Retention
We retain your personal information for as long as your account is active or as needed to provide our Service. Specific retention periods include:
- Account data: Retained while your account is active and for up to 30 days after deletion approval
- Conversation history: Retained while your account is active; deletable on request
- Guest session data: Automatically deleted after 30 days of inactivity
- Log and analytics data: Retained in anonymized form for up to 12 months
- Legal compliance data: Retained as required by applicable law
7. Account Deletion
You may request deletion of your account and all associated personal data at any time. Our deletion process works as follows:
- Submit a deletion request through the app (Profile → Account Settings → Delete Account) or by emailing support@heyviv.ai
- Your request enters a 14-day review period during which your account remains accessible and you may cancel the request
- After the review period, an administrator processes the request. You will receive an email notification when your request is approved or if additional information is needed
- Upon approval, your personal data — including profile information, conversation history, trip data, and saved preferences — is permanently deleted from our active systems
- Anonymized, aggregated data that cannot be linked back to you may be retained for analytical purposes
- Backup copies are purged within 30 days of deletion approval
8. Your Rights and Choices
Depending on your jurisdiction, you may have the following rights regarding your personal data:
- Access: Request a copy of the personal information we hold about you
- Correction: Request correction of inaccurate or incomplete personal information
- Deletion: Request deletion of your personal information (see Account Deletion above)
- Portability: Request your data in a structured, machine-readable format
- Restriction: Request that we limit processing of your personal information in certain circumstances
- Objection: Object to processing of your personal information for direct marketing or based on legitimate interests
- Withdraw Consent: Where processing is based on consent, you may withdraw consent at any time without affecting the lawfulness of prior processing
- Opt-out of Communications: Unsubscribe from marketing emails via the link in each email or through account settings
- Location Services: Control location sharing through your device settings at any time
To exercise any of these rights, contact us at support@heyviv.ai. We will respond within 30 days.
9. Cookies and Local Storage
Our Service uses:
- Essential cookies: Required for authentication, session management, and security (e.g., JWT tokens)
- Local storage: Used to store user preferences, guest session identifiers, and onboarding progress for a seamless experience
- Analytics cookies: Help us understand how visitors use our website to improve our Service (e.g., Vercel Analytics)
You can control cookies through your browser settings. Disabling essential cookies may affect the functionality of our Service.
10. International Data Transfers
Viv operates from the United States, and our servers are hosted in the US (Virginia region via Render and Vercel). Your information may be transferred to and processed in the United States or other countries where our service providers operate. By using our Service, you consent to such transfers. We ensure appropriate safeguards are in place — including contractual data protection clauses with all third-party providers — to protect your information in accordance with applicable data protection laws, including the GDPR for European users.
11. Children's Privacy
Our Service is not intended for children under 13 years of age (or 16 in the European Economic Area). We do not knowingly collect personal information from children. If you are a parent or guardian and believe your child has provided us with personal information, please contact us at support@heyviv.ai and we will promptly delete such information.
12. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or legal requirements. We will notify you of material changes by posting the updated policy on this page, updating the "Last Updated" date, and — for significant changes — sending a notification to your registered email address. We encourage you to review this Privacy Policy periodically.
13. Contact Us
If you have any questions about this Privacy Policy, our data practices, or wish to exercise your rights, please contact us:
Email: support@heyviv.ai
Website: heyviv.ai
We will respond to all privacy-related inquiries within 30 days.