Table of Contents
1. Introduction
Joy CareBot ("the App"), developed by Spiritify.ai ("we", "us", "our"), is an AI-powered wellness companion that helps users monitor their health, converse with AI agents, manage calendars, and journal their emotions. This Privacy Policy describes how we collect, use, store, and share your information when you use the App.
By using the App, you agree to the collection and use of information as described in this policy.
2. Information We Collect
2.1 Account Information
When you create an account, we collect:
- Email address
- Password (encrypted, never stored in plaintext)
- Name (first and last, optional)
- Date of birth (optional)
- Gender (optional)
If you sign in using Google or Apple, we receive an authentication token from the provider containing your name and email address. We do not receive or store your Google or Apple password.
2.2 Health and Fitness Data
With your explicit permission, the App reads the following data from Apple HealthKit:
- Heart rate (current, minimum, maximum)
- Heart rate variability (HRV)
- Blood oxygen saturation (SpO2)
- Body temperature
- Step count
- Calories burned
- Walking/running distance
- Active exercise minutes
- Sleep duration and stages (deep, light, REM)
This data is synced to our servers periodically (approximately every 5 minutes while the App is open, and approximately every 15 minutes in the background) to provide personalized wellness insights. Health data is never used for advertising or shared with third parties.
2.3 Voice and Conversation Data
When you use the voice chat feature:
- Microphone audio is captured and streamed in real-time to our servers. Speech is transcribed to text on our infrastructure using our own voice activity detection (VAD) and automatic speech recognition (ASR) pipeline; the raw audio is not shared with third parties for this step
- The transcribed text is sent to OpenAI's API for language-model processing to generate a response. OpenAI acts as a data processor on our behalf under their API data-usage policy and does not use this data to train their models. See OpenAI's API data-usage policies.
- The AI-generated response text is sent to Microsoft Azure Speech Service (Text-to-Speech) to synthesize the audio spoken back to you. Azure processes this text on our behalf under Microsoft's data processing terms and does not use it to train models. See Azure Speech Service data privacy.
- Conversation transcripts (text only, not audio recordings) are stored in your chat history on our servers
- You can view your chat history within the App
2.4 Calendar Data
If you choose to link your calendar, we access event titles, descriptions, dates, and times from Google Calendar, Microsoft Calendar, or Apple Calendar. We use this data to provide reminders and schedule wellness activities. Calendar access requires separate authorization through the respective provider (Google or Microsoft OAuth).
2.5 Device Information
We collect a unique device identifier (generated and stored locally on your device), device platform (iOS or Android), and app version.
2.6 Spiritify Hardware Device
If you use a Spiritify companion device (sold separately), the App displays device status information such as battery level and connectivity status. This data comes from the Spiritify hardware device, not from your personal phone or tablet.
2.7 Caregiver Data
If you add a caregiver, we collect their name, email address, and relationship to you. Caregivers may view your health summaries and activity data.
2.8 Avatar Images
If you upload a custom avatar for your AI agent, the image is stored on our servers.
3. Information We Do NOT Collect
- GPS location or precise coordinates (we only use your device timezone for scheduling)
- Contacts or address book
- Browsing history
- SMS or call logs
- Biometric data (Face ID and fingerprint data remain on your device and are never transmitted to our servers)
- We do not use any third-party analytics, advertising, or tracking services
4. How We Use Your Information
We use your information to:
- Provide and maintain the App's functionality
- Deliver personalized AI wellness conversations
- Display health insights and trends based on your HealthKit data
- Send local notification reminders for upcoming calendar events
- Enable caregiver access to your health summaries (if you choose to link a caregiver)
- Authenticate your identity and secure your account
- Improve and develop our services
5. Data Storage and Security
5.1 Local Storage
Authentication tokens and biometric preferences are stored in your device's secure enclave (iOS Keychain / Android Keystore) using industry-standard encryption. No health data is stored locally in a database; it is read from HealthKit and transmitted to our servers.
5.2 Server Storage
Your account data, health snapshots, conversation history, and calendar events are stored on our servers. All data transmitted between the App and our servers is encrypted using HTTPS (TLS/SSL). Real-time voice communication uses encrypted WebSocket connections (WSS).
5.3 Authentication Security
Passwords are encrypted and never stored in plaintext. Access tokens expire after a limited period; refresh tokens are valid for 30 days. You may enable biometric authentication (Face ID or fingerprint) for additional security.
6. Data Sharing
We do not sell, rent, or trade your personal information. We share data only in the following circumstances:
- Caregivers: If you link a caregiver, they may view your health summaries, activity data, and alerts
- Service Providers: We use secure cloud infrastructure to host our servers; these providers process data on our behalf under strict confidentiality agreements
- AI Service Provider (OpenAI): Transcribed conversation text from the voice chat feature is transmitted to OpenAI's API to generate AI responses. OpenAI acts as a data processor on our behalf, does not use this data to train its models under their API terms, and is bound by OpenAI's API data-usage policies
- Voice Synthesis Provider (Microsoft Azure): AI response text is transmitted to Microsoft Azure Speech Service (Text-to-Speech) to synthesize the spoken audio you hear. Azure acts as a data processor on our behalf under Microsoft's data processing terms and does not use this data to train models
- Authentication Providers: When you sign in with Google or Apple, those providers receive confirmation of your authentication but do not receive your health or conversation data
- Calendar Providers: When you link Google or Microsoft Calendar, those providers facilitate calendar data access per their own privacy policies
- Legal Requirements: We may disclose information if required by law, regulation, or legal process
7. HealthKit Data
In compliance with Apple's HealthKit guidelines:
- Health data accessed through HealthKit is not used for advertising or marketing purposes
- Health data is not sold to third parties, including data brokers or information resellers
- Health data is not shared with third parties for their marketing or advertising purposes
- Health data is used solely to provide the App's health and wellness features to you
- Background health sync runs periodically to keep your wellness insights up to date
8. Children's Privacy
The App is intended for users aged 18 and above. We do not knowingly collect personal information from individuals under 18. If you believe someone under 18 has provided us with personal information, please contact us and we will promptly delete it.
9. Your Rights
You have the right to:
- Access your personal data stored in the App
- Correct inaccurate personal information through the App's profile settings
- Delete your account and associated data by contacting us
- Withdraw consent for HealthKit access at any time through your device's Settings
- Revoke calendar access through your Google or Microsoft account settings
- Disable biometric authentication through the App's settings
10. Data Retention
- Account data is retained as long as your account is active
- Conversation history is retained as long as your account is active
- Health data snapshots are retained as long as your account is active
- Upon account deletion, we will delete your personal data within 30 days, except where retention is required by law
11. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy within the App. Your continued use of the App after such changes constitutes acceptance of the updated policy.
12. Google API Services User Data Policy
Joy CareBot's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
When you choose to link your Google account, Joy CareBot may access the following Google API data:
- Google Sign-In (openid, email, profile) — to authenticate you and create or access your account
- Google Calendar (calendar scope) — to read your upcoming events and, with your permission, create wellness-related events (e.g., medication reminders and scheduled activities) on your behalf
In accordance with the Limited Use requirements, we commit to:
- Use data obtained from Google APIs only to provide or improve user-facing features of Joy CareBot — specifically calendar-based reminders, wellness scheduling, and integration into AI wellness conversations
- Not transfer this data to third parties except as necessary to provide or improve those user-facing features, to comply with applicable law, or as part of a merger, acquisition, or sale of assets with user notice
- Not use this data for serving advertisements, including personalized, retargeting, or interest-based advertising
- Not allow humans to read this data unless we have obtained your affirmative consent to view specific data, doing so is necessary for security purposes such as investigating abuse, to comply with applicable law, or the data has been aggregated and anonymized in a way that cannot be used to identify individuals
13. Contact Us
If you have questions about this Privacy Policy or wish to exercise your data rights, please contact us: