Privacy Policy

Effective Date: 2 June 2026 · Last Updated: 2 June 2026

This Privacy Policy explains how Codedu Software Technologies, having its registered office at COCO Group, Mukkadan Complex, Infopark Smart City Short Road, Edachira, Kakkanad, Kochi, Kerala 682030, India ("GospelVox", "we", "us", "our"), collects, uses, shares, retains, and protects information about you when you use the GospelVox mobile application, websites, and related services (collectively, the "Platform").

We are the Data Fiduciary under the Digital Personal Data Protection Act, 2023 ("DPDP Act") for personal data we process about Users in India, and the Controller under the UK GDPR and EU GDPR for data of users in those jurisdictions. For California residents we are the "Business" under the California Consumer Privacy Act, 2018 ("CCPA").

By using the Platform you confirm you have read this Policy. Where your jurisdiction requires consent, you give that consent by proceeding to use the Platform.


1. Quick Summary

2. Information We Collect

2.1 Information you provide

Account and profile (all users):

Speaker (priest) registration data:

Session content:

Payment information (Users):

Communications:

2.2 Information collected automatically

We do not use third-party trackers for advertising, and we do not deploy Apple's App Tracking Transparency (ATT) tracking. Where the SDKs we use (Crashlytics, Firebase Cloud Messaging) collect device identifiers, they are used for diagnostics and notification delivery only.

2.3 Information from third parties

2.4 Permissions the app requests

PermissionWhy we ask
MicrophoneTo capture your voice during voice Sessions (Agora).
CameraTo take a profile photo and to capture document images during Speaker registration.
Photos / mediaTo pick a profile photo or document image from your gallery.
NotificationsTo deliver incoming-Session alerts, message notifications, and important account updates via FCM.
BluetoothTo route call audio to headsets / car systems during voice Sessions.
Network stateTo detect connectivity and choose between Wi-Fi and cellular for Sessions.
Foreground service (microphone)To keep a voice Session alive when you lock your screen or background the app.

You can revoke any of these permissions through your device settings. Some features will not work without the relevant permission.

3. How We Use Your Information

  1. Provide the Platform — create and maintain your account, verify Speakers, enable discovery, run Sessions, process Coin purchases, credit Speaker earnings, and process withdrawals.
  2. Communicate with you — send Session and account notifications, transactional messages, security alerts, and (where you've opted in) updates about new features.
  3. Safety, integrity, and fraud prevention — detect, prevent, and respond to fraud, abuse, harassment, and policy violations, including by reviewing reported Content within 24 hours.
  4. Comply with law — meet our obligations under the Information Technology Act, 2000, the DPDP Act, payment regulations, tax laws (including TDS where applicable), and other applicable law.
  5. Improve the Platform — analyse aggregated usage, fix crashes (Crashlytics), measure feature adoption, and improve reliability.
  6. Enforce our Terms — investigate suspected breaches and take appropriate action.

Legal bases (UK GDPR / EU GDPR users)

PurposeLegal basis
Provide the Platform (account, Sessions, payments)Performance of a contract (Art. 6(1)(b))
Speaker KYC / identity / bank verificationLegal obligation (Art. 6(1)(c)); legitimate interests (Art. 6(1)(f))
Fraud prevention, security, abuse handlingLegitimate interests (Art. 6(1)(f))
Promotional emails / push (if any)Consent (Art. 6(1)(a)) — withdrawable any time
Crash and performance diagnosticsLegitimate interests (Art. 6(1)(f))

For DPDP Act purposes (India users), we process your personal data based on your consent (given by using the Platform) and for "certain legitimate uses" listed under the Act (including for the performance of a contract, fraud prevention, compliance with law, and responding to a medical emergency).

4. Sharing of Information — Data Processors and Sub-processors

We share your information only with the parties listed below, only for the purposes described, and under contractual data-protection obligations.

RecipientPurposeData sharedCountry
Google LLC / Google India Pvt Ltd — Firebase AuthenticationSign-in, session tokensEmail, identity-provider ID, auth tokensUS / India
Google LLC — Cloud FirestoreStoring app data (user profile, Speaker profile, chat messages, transactions)All structured app dataIndia (asia-south1, Mumbai)
Google LLC — Firebase StorageStoring profile photos, ID proofs, certificates, message mediaUploaded filesIndia (asia-south1)
Google LLC — Cloud FunctionsServer-side logic (payment verification, withdrawals, Session billing)Request payload + caller identityIndia (asia-south1)
Google LLC — Firebase CrashlyticsCrash and stability diagnosticsDevice model, OS, app version, stack traces, non-personal install IDUS
Google LLC — Firebase Cloud Messaging (FCM)Push notification deliveryFCM token, notification payloadUS
Google LLC — Google Sign-InAuthenticationEmail, name, profile picture URL, Google IDUS
Apple Inc. — Sign in with AppleAuthentication (iOS)Email (or relay), name, Apple IDUS
Google LLC — Google Play Billing (Android)In-app purchase processing and server-side verificationGoogle Play order ID, purchase token, product (SKU) ID, purchase status, amountUS / global
Apple Inc. — Apple In-App Purchase (iOS)In-app purchase processing and server-side verificationApp Store transaction ID, product (SKU) ID, purchase status, environmentUS / global
Agora Lab, Inc.Real-time voice infrastructure for voice SessionsChannel name, ephemeral user IDs, audio packets in transit (not retained by us)US / global edge

We do not sell or rent your personal data to advertisers, data brokers, or any other third party for marketing. We do not share identified personal data for cross-context behavioural advertising.

We may disclose information to courts, regulators, or law-enforcement authorities where required by law, in response to a valid legal process, or to protect the rights, property, or safety of GospelVox, our users, or the public.

We may transfer your information as part of a merger, acquisition, financing, reorganisation, or sale of all or part of our business, subject to standard confidentiality protections.

5. International Transfers

Our primary data store is Mumbai, India (asia-south1). Some sub-processors (Crashlytics, Agora, Apple, Google Play Billing) process data in the United States and other regions. Where personal data of EU/UK users is transferred outside the EEA/UK, we rely on:

A copy of the relevant transfer mechanism is available from us on request at support@gospelvox.com.

6. Retention

We keep your personal data only as long as we need it for the purposes described in this Policy, or as required by applicable law.

CategoryRetention
User account & profileWhile your account is active. Deleted within 30 days of account deletion or our termination of your account.
Speaker profile, ID proof, certificate, bank detailsWhile the Speaker account is active, plus the period required by Indian tax / KYC / anti-money-laundering law (typically 5–8 years).
Chat messagesWhile both participants' accounts are active and for 12 months thereafter, unless deletion is requested earlier.
Voice Session audioNot retained (voice is transmitted in real time and is not recorded).
Wallet / payment / withdrawal transaction records8 years from the financial year of the transaction, in line with Indian tax and bookkeeping law.
Crash and diagnostic logsUp to 90 days.
Support and grievance correspondence3 years from closure of the matter.

After the applicable retention period we will delete or irreversibly anonymise the data. We may retain anonymised, non-identifying aggregates indefinitely for analytics and Platform improvement.

7. Security

We use a combination of technical and organisational measures to protect your personal data, including:

No system is perfectly secure. If we become aware of a personal-data breach that is likely to result in a high risk to your rights and freedoms, we will notify you and the relevant regulator(s) as required by applicable law (e.g., within the timelines prescribed by the DPDP Act and GDPR).

8. Your Rights

8.1 All users

8.2 California residents (CCPA)

To exercise any of these rights, email support@gospelvox.com from the email address linked to your account, or use the in-app controls described in Section 10. We will respond within the timelines required by applicable law (typically 30 days under GDPR; 45 days under CCPA; the DPDP-Act timeline once notified).

9. Children's Privacy

The Platform is intended for users 18 years and above. We do not knowingly collect personal data from children. If you believe a child has provided personal data to us, please contact support@gospelvox.com and we will delete the data and the associated account.

10. How to Delete Your Account

You may delete your account at any time:

  1. In-app: Settings → Account → Delete Account. Confirm the deletion when prompted.
  2. By email: write to support@gospelvox.com from the email associated with your account, with the subject line "Account Deletion Request".

See the dedicated Account Deletion page for the full process, what gets deleted, and what records are retained under law.

11. Cookies and Similar Technologies

The GospelVox mobile app does not use browser cookies. The SDKs we use (Firebase, Agora) and your app store's billing flow may store small amounts of data locally on your device for session continuity, crash reporting, and notification delivery. You can clear this storage by clearing the app's data through your device settings.

12. Grievance Officer (India)

In accordance with the Information Technology Act, 2000 and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, and consistent with the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, the Grievance Officer for the Platform is:

The Grievance Officer will:

13. Data Protection Officer (where required)

If we become a "Significant Data Fiduciary" under the DPDP Act, or where required by GDPR, we will appoint a Data Protection Officer and update this Policy with their contact details.

14. Changes to This Policy

We may update this Policy from time to time. The "Last Updated" date will reflect the latest version. We will notify you in the app or by email about material changes. Your continued use of the Platform after the changes take effect constitutes acceptance of the updated Policy.

15. Contact Us