Privacy Policy
Effective Date: February 12, 2026
Our Commitment to Your Privacy
At GoVivid, we design technology specifically for blind and visually impaired individuals. Privacy isn't an afterthought—it's built into everything we create.
Our Core Principles:
Transparency First: We explain exactly what we collect and why
Minimal Data: We only collect what's necessary to serve you
Your Control: You decide what to share and when
No Selling: We never sell your personal information
Security by Design: We protect your data with industry-leading safeguards
This policy covers:
GV Discover mobile app (iOS & Android)
DirectMe Platform (Pending FDA registration)
Our website (www.govividco.com)
Quick Summary (Full details below)
What We Collect
Why We Collect It
Your Control
Account info (name, email)
To create your account
Edit anytime in Settings
Camera images (real-time)
To describe scenes & read text
Processed immediately, not stored*
Voice commands
To understand your requests
Processed & discarded
Device sensors (DirectMe)
To provide spatial awareness
Hardware-based, minimal transmission
Analytics, crash reporting
Firebase
Device info, anonymized usage patterns
App distribution, push notifications
Apple / Google
Device tokens, app version
Until you delete them
Saved scans
User-controlled storage
90 days
Crash logs
Debugging and stability analysis
Enable/disable anytime
Location (optional)
For navigation features
Opt out in Privacy settings
Usage patterns
To improve the app
*Unless you explicitly save a scan
1. What Information We Collect
1.1 Information You Give Us Directly
Account Setup:
Name and email address (required)
Date of birth (for age verification)
Password (encrypted, never stored in plain text)
Phone number (optional, for account recovery)
Profile Customization:
AI companion name (e.g., "Maya", "Sam")
Voice gender and accent preferences
Speech rate and verbosity level (brief/standard/detailed)
Visual impairment type (optional, helps us personalize)
Orientation & Mobility training status (DirectMe users only)
Payment Information:
Billing name and address
Payment card details (processed by Stripe, we never see full card numbers)
Subscription plan and renewal preferences
When You Contact Us:
Support tickets and email conversations
Feedback surveys and user research responses
Bug reports and feature requests
1.2 Information Collected Automatically
Device & App Data:
Device Information:
Device model (e.g., iPhone 14, Samsung Galaxy S23)
Operating system version (e.g., iOS 17.2, Android 14)
App version (e.g., GV Discover 1.0.5)
Screen reader status (VoiceOver/TalkBack enabled)
Language and region settings
Technical Data:
IP address (for security and approximate location)
Device identifiers (anonymized, for analytics only)
Network type (WiFi, cellular)
Battery level (to optimize performance)
Available storage space
Usage Analytics:
Features used (Look, View, Read, Find modes)
Session duration and frequency
Voice command success/failure rates
Error logs and crash reports
Time spent in each feature
Navigation patterns (which buttons/gestures you use)
Note: We collect these analytics to understand how people actually use our app and identify areas for improvement.
1.3 Camera & Visual Data (GV Discover)
What We Capture:
Real-time camera frames for scene analysis
Photos for detailed object recognition
Text images for OCR reading
Video streams during "Look" mode
How We Handle It:
Processing: Sent to Google's Gemini Vision API via encrypted connection
Storage: Images are immediately discarded after analysis (typically <2 seconds)
Exceptions: If you tap "Save this scan", we store it locally on your device until you delete it
Training: Images are NOT used to train AI models unless you explicitly opt in (see Section 3.4)
Why This Matters: Unlike social media apps that store every photo, we designed GV Discover so visual data exists only for the moment you need it. Think of it like a phone call—the connection happens, then it's gone.
1.4 Sensor Data (DirectMe Hardware)
From the Seymour Handheld Device:
Laser range finder measurements (obstacle distances)
IMU orientation data (which way you're pointing)
Camera images (processed same as GV Discover)
Button press patterns
Battery status
From the Iris Head Tracker:
Head orientation (for 3D audio positioning)
Movement patterns (for spatial audio accuracy)
Transmission:
Sensor data is transmitted to your iPhone via WiFi/Bluetooth
Processed locally on your phone when possible
Only summarized data sent to cloud (e.g., "obstacle detected at 3 feet")
Full sensor logs are NOT uploaded unless you report a bug
Storage:
DirectMe devices store minimal operational data (settings, calibration)
No personal information stored on the hardware itself
Resetting the device wipes all stored data
1.5 Audio Data
Voice Interactions:
Voice commands to AI companion ("Find my keys", "What's ahead?")
Questions during Look/View modes
Text-to-speech preferences
How We Process Audio:
Your voice is captured by device microphone
Converted to text using on-device speech recognition (iOS/Android native)
Text is sent to Gemini Live API for understanding
Response is generated and spoken back
Audio recording is immediately deleted
We Do NOT:
Store voice recordings
Create voiceprints or voice identification profiles
Use your voice for any purpose beyond immediate command processing
1.6 Location Data (Optional)
When We Use Location:
"Find Nearby" feature (coffee shops, restrooms, etc.)
Navigation assistance (if you enable this feature)
Weather-based context (future feature)
Precision Level:
Coarse location (city-level) for weather and general context
Precise location (GPS coordinates) only when you use navigation features
Your Control:
Location is OFF by default
You can enable/disable at the iOS/Android system level
You can also toggle "Find Nearby" in app settings independently
Data Handling:
Location is NEVER shared with third parties except Google Maps (when you use navigation)
We don't create location history profiles
Location data is not stored after your session ends
1.7 Information from Third Parties
Google Services:
Google Maps data (POI information, routes)
Gemini Vision/Live API responses
Firebase analytics data
Apple/Google Account Login:
Name and email from your Apple ID or Google account (if you sign in via SSO)
Account verification status
Payment Processors:
Payment confirmation from Stripe
Subscription status updates
Research Partners (With Your Consent):
Anonymized benchmark data from accessibility research institutions
De-identified usage patterns from BVI community studies
2. How We Use Your Information
2.1 Core Service Delivery
To Make the App Work:
Process scene descriptions in real-time
Recognize and locate objects you search for
Read text aloud with natural voices
Enable voice-controlled AI companion
Synchronize settings across devices
Provide spatial audio feedback (DirectMe)
Example: When you say "Find my keys", we use your camera feed + AI object detection + spatial audio to guide you to them.
2.2 Personalization
To Tailor Your Experience:
Remember your AI companion's name and voice
Adjust verbosity (brief vs. detailed descriptions) based on your preference
Learn which features you use most
Adapt to your interaction patterns (gesture vs. voice)
Example: If you consistently ask for "brief descriptions", we'll make that your default.
Important: Personalization happens on your device or via encrypted cloud processing. We don't build advertising profiles.
2.3 Service Improvement
To Make GV Discover Better:
Identify which features are most/least useful
Fix bugs and crashes
Optimize battery usage and performance
Understand how people navigate the app
Prioritize new feature development
Example: If analytics show most users struggle with Find mode, we'll improve the tutorial.
Anonymized Data: We analyze aggregated patterns like "80% of users prefer detailed scene descriptions" without identifying individuals.
2.4 AI Model Improvement (Opt-In Only)
With Your Explicit Consent:
Use anonymized images to train better object recognition for the BVI community
Improve scene description accuracy for diverse environments
Enhance text reading for challenging fonts/handwriting
Safeguards:
All identifying information is stripped (faces blurred, text redacted)
Images are reviewed by humans to ensure no personal data remains
You can opt out anytime, and past contributions are removed from training sets
Only shared with approved research partners under strict data agreements
Why This Matters: AI models work better when trained on diverse real-world data. By contributing, you help future users have a better experience—but it's 100% optional.
2.5 Communication
Service Updates:
Critical bug fixes and security patches
New feature announcements
Changes to privacy policy or terms
Support & Feedback:
Respond to your questions and issues
Request feedback on beta features
Conduct user research interviews (with separate consent)
Marketing (Opt-In):
New product launches (e.g., DirectMe availability)
Tips and tricks for getting more from GV Discover
Community spotlight stories
Your Control: Unsubscribe from marketing emails anytime. Service updates are essential and cannot be disabled.
2.6 Safety, Security & Legal Compliance
Detect and prevent fraud (e.g., unauthorized account access)
Investigate reported misuse or violations of Terms of Service
Comply with legal obligations (court orders, regulatory requirements)
Protect our intellectual property and business interests
FDA compliance and post-market surveillance (DirectMe)
3. How We Share Your Information
3.1 We DO NOT Sell Your Data
Never. Period.
We do not and will never sell, rent, or trade your personal information to data brokers, advertisers, or marketing companies.
3.2 Service Providers (With Strict Contracts)
We work with trusted companies to help deliver our Services:
What They Access
Provider
What They Do
Camera images (temporary), usage data
Google Cloud
AI processing, cloud storage
Billing info (we never see full card numbers)
Stripe
Payment processing
Camera images, voice text, contextual queries
Gemini / Vertex AI
Computer vision, natural language
Contractual Protections:
Data Processing Agreements (DPAs) limit how providers can use data
Providers cannot use your data for their own purposes
Regular audits ensure compliance
Immediate notification if a breach occurs
3.3 Legal Requirements
We may disclose information when legally required:
Court orders or subpoenas
Government investigations (with warrant)
FDA inspections (DirectMe compliance)
To protect safety (e.g., imminent threat of harm)
Transparency Promise: If legally permitted, we will notify you before disclosing your information and challenge overbroad requests.
3.4 Research Partners (With Your Consent)
If You Opt Into AI Training:
Anonymized visual data may be shared with:
Academic institutions studying assistive technology
Non-profits developing AI for accessibility
Approved industry partners (e.g., Microsoft, Google) under strict data agreements
Safeguards:
All personally identifiable information removed
Data cannot be traced back to your account
Shared under Data Use Agreements that prohibit re-identification
You can withdraw consent and request deletion of contributed data
3.5 Business Transfers
If GoVivid is acquired, merges, or sells assets:
Your information may be transferred to the new entity
We will notify you 30 days in advance
The new owner must honor this privacy policy
You can delete your account before the transfer completes
3.6 Aggregated/Anonymous Data
We may publicly share anonymized statistics:
"GV Discover has been used for 1 million scans"
"Most common use case is reading labels"
"Average session duration is 8 minutes"
This data cannot identify you individually and helps demonstrate impact to funders and partners.
FERPA-Covered Educational Data: For data derived from accounts at educational institutions (K-12 schools, districts, colleges), GoVivid's use of anonymized and aggregated data is limited to: (a) product improvement, AI model training, safety research, and internal analytics; and (b) investor materials and regulatory submissions. GoVivid will not use student-derived anonymized data for commercial licensing, industry benchmarking, or marketing purposes.
4. Your Privacy Rights & Controls
4.1 Access & Correction
What You Can Do:
View your profile information in Settings → Account
Update name, email, preferences anytime
Download a copy of your data (see 4.3 below)
How to Exercise:
Most changes can be made in-app
For comprehensive data access, email hello@govivid.ai
4.2 Data Deletion
Delete Your Account:
Go to Settings → Account → Delete My Account
Or email hello@govivid.ai with subject "Account Deletion Request"
We'll confirm your identity and delete within 30 days
What Gets Deleted:
Profile information
Saved scans
Usage history
Voice preference settings
What We Retain (Legal Requirements):
Transaction records (7 years for tax/accounting)
Anonymized data already used in research
Aggregated analytics (not linked to your identity)
Records necessary for legal disputes
4.3 Data Portability
Get Your Data: Request a machine-readable copy of:
Account information
Saved scans
Usage statistics
Preference settings
Format: JSON or CSV file
Timeline: Delivered within 30 days
How: Email hello@govivid.ai
4.4 Opt-Out Options
Marketing Communications:
Click "Unsubscribe" in any marketing email
Or toggle off in Settings → Notifications → Marketing
AI Model Training:
Settings → Privacy → Contribute to AI Improvement (toggle OFF)
Analytics:
Settings → Privacy → Share Usage Data (toggle OFF)
Note: This may limit our ability to provide personalized support
Location Services:
Disable at iOS/Android system level
Or toggle off Settings → Privacy → Location Access
4.5 California Residents (CCPA/CPRA)
Your Additional Rights:
Right to Know: What personal information we collect, use, disclose
Right to Delete: Request deletion of your data (with legal exceptions)
Right to Opt-Out: We don't "sell" data, but you can opt out of sharing for analytics
Right to Correct: Update inaccurate information
Right to Non-Discrimination: We won't penalize you for exercising these rights
How to Exercise:
Email hello@govivid.ai with subject "California Privacy Rights"
We'll verify your identity and respond within 45 days
Authorized Agents: You may designate someone to make requests on your behalf (provide written authorization).
4.6 European Users (GDPR)
Your Additional Rights:
Right to Access: Confirm what data we process
Right to Rectification: Correct inaccurate data
Right to Erasure ("Right to be Forgotten")
Right to Restrict Processing: Limit how we use your data
Right to Object: Object to processing based on legitimate interests
Right to Data Portability: Receive data in structured format
Right to Withdraw Consent: Revoke consent for optional processing
Legal Bases for Processing:
Consent: AI training, marketing, optional features
Contract Performance: To provide GV Discover/DirectMe services
Legitimate Interests: Service improvement, fraud prevention
Legal Obligation: Tax compliance, FDA requirements
Age Requirements for EU Users:
EU users must be 16 or older to use GoVivid Services, or have verifiable
parental or legal guardian consent. If your country of residence sets a
higher minimum age for digital consent, that local requirement applies.
Data Protection Officer: Contact legal@govivid.ai for GDPR-specific inquiries
Supervisory Authority: You have the right to lodge a complaint with your national data protection authority if you believe we've violated GDPR.
4.7 Other Jurisdictions
UK (UK GDPR): Same rights as EU/GDPR above
Brazil (LGPD): Contact hello@govivid.ai for data subject requests
Other Regions: We respect all local privacy laws; contact us for specific rights
5. Data Security
5.1 How We Protect Your Data
Encryption:
In Transit: All data transmitted via TLS 1.3+ encryption
At Rest: Database encryption with AES-256
Backups: Encrypted and stored in separate secure locations
Access Controls:
Multi-factor authentication for employee access
Role-based permissions (engineers cannot access user data without approval)
Regular access reviews and immediate revocation for terminated staff
Technical Safeguards:
Automated security scanning and vulnerability testing
Intrusion detection systems
DDoS protection
Regular penetration testing by third-party security firms
Organizational Safeguards:
Employee privacy training (annual)
Confidentiality agreements with all staff and contractors
Incident response plan with 72-hour breach notification commitment
Privacy-by-design methodology in product development
5.2 DirectMe Hardware Security
Device-Level Protection:
Encrypted firmware with secure boot
No personal data stored on Seymour/Iris devices
Factory reset wipes all configuration data
Battery protections prevent tampering
Manufacturing Security:
ISO 13485 certified facilities
Tamper-evident packaging
Secure supply chain with component traceability
5.3 What We Cannot Guarantee
Important: While we use industry best practices, no system is 100% secure. Risks include:
Phishing attacks targeting your credentials
Device theft (if auto-login is enabled)
Zero-day vulnerabilities in third-party software
Advanced persistent threats from nation-state actors
Your Responsibility:
Use strong, unique passwords
Enable device lock screens
Don't share your account credentials
Report suspicious activity immediately
6. Data Retention
6.1 How Long We Keep Data
2 years from collection
Usage analytics
Trend analysis, long-term product improvement
Reason
Data Type
Retention Period
Service continuity, potential reactivation
Account info
Active account + 1 Year after deletion
Privacy-by-design principle
Camera / audio data
Processed in real-time, not stored*
Quality assurance, dispute resolution
Support tickets
3 years from last contact
Tax and accounting regulations
Payment records
7 years
Cannot be re-linked to individuals
Research data (anonymized)
Indefinitely
*Unless explicitly saved by user
6.2 Deletion Process
Automated Deletion:
Temporary data (camera frames, audio) auto-deletes after processing
Session data expires after 90 days of inactivity
Failed login attempts purged after 7 days
Manual Deletion:
Account deletion requests processed within 30 days
Backups containing your data are overwritten within 90 days
You receive confirmation email when deletion is complete
7. Children's Privacy
7.1 Age Requirements
Ages 13 to 17: Parental or legal guardian consent is required. We may verify consent via signed form, credit card, video verification, or email/phone confirmation.
Institutional customers must collect Parental Consent Forms per www.govividco.com/legal/Consent_Form before granting access to users in this age range.
Under 13 Not permitted. GoVivid does not provide services to children under 13.
International Users: If you are located in the European Union, you must be 16 or older to use the Services, or have verifiable parental or legal guardian consent. If your country of residence sets a higher minimum age for digital consent than stated above, that local requirement applies to you.
7.2 Teen Users (13-17)
Additional Protections:
Marketing emails require explicit opt-in (not pre-checked)
Social features (if any) include bullying/harassment reporting
Account deletion can be requested by teen or parent
Educational Institutions: Schools/programs using GV Discover for students must provide:
Signed consent from parents/guardians
Compliance with FERPA (Family Educational Rights and Privacy Act)
Designated supervising teacher/O&M specialist
7.3 Regulatory Compliance Framework
GoVivid is committed to compliance with all applicable data protection and privacy laws, including:
Children's Online Privacy Protection Act (COPPA): GoVivid does not provide services to children under 13. For users ages 13-17, we require verifiable parental consent as described in Section 7.1.
Family Educational Rights and Privacy Act (FERPA): For educational institutions, GoVivid acts as a "school official" with "legitimate educational interest" under 20 U.S.C. § 1232g and 34 CFR Part 99 solely to provide the Services.
California Consumer Privacy Act (CCPA/CPRA): California users have additional rights described in Section 4.5.
General Data Protection Regulation (GDPR): EU and UK users have additional rights described in Section 4.6. EU users must be 16 or older (or have parental consent).
Additional Regional Laws: We comply with LGPD (Brazil), PIPEDA (Canada), and other applicable regional privacy laws. Contact hello@govivid.ai for jurisdiction-specific questions.
8. International Data Transfers
8.1 Where We Store Data
Primary Data Centers:
Google Cloud Platform (US regions: us-central1, us-east1)
Firebase (US)
Stripe (US, with global compliance)
If You're Outside the US: Your data will be transferred to and processed in the United States.
8.2 Safeguards for International Transfers
For EU/UK Users:
Standard Contractual Clauses (SCCs) approved by EU Commission
Additional safeguards as required by Schrems II decision
Encryption and anonymization where possible
For Other Regions:
Data Processing Agreements with cross-border data transfer provisions
Compliance with local data localization laws (where applicable)
Your Consent: By using GoVivid Services, you consent to this transfer. You can withdraw consent and delete your account if you object.
9. Third-Party Services & Integrations
9.1 Services We Integrate With
Google Services:
Google Maps (navigation, POI search)
Gemini Vision/Live API (AI processing)
Firebase (analytics, crash reporting)
Privacy Policy: policies.google.com/privacy
Apple/Google SSO:
Sign-in authentication
Privacy Policies:
Apple: apple.com/legal/privacy
Google: policies.google.com/privacy
Stripe (Payments):
Payment processing
Privacy Policy: stripe.com/privacy
9.2 Third-Party Links
Our website and app may contain links to third-party sites:
Envision (integration partnerships)
User community forums
Research institutions
We Are Not Responsible For:
Content or privacy practices of external sites
Data collected by third parties after you leave our Services
Recommendation: Review the privacy policy of any site you visit.
10. Cookies & Tracking Technologies
10.1 Website Cookies
What We Use:
Essential Cookies: Required for site functionality (login, preferences)
Analytics Cookies: Understand how visitors use our site (Google Analytics)
Marketing Cookies (Opt-In): Measure ad campaign effectiveness
Your Control:
Manage cookies via browser settings
Or use our Cookie Preferences banner (on first visit)
Do Not Track: We do not currently respond to DNT signals, but we don't track you across third-party sites.
10.2 Mobile App Tracking
What We Use:
Analytics SDK: Firebase Analytics (anonymized)
Crash Reporting: Firebase Crashlytics (diagnostic data only)
No Advertising IDs: We don't use IDFA (iOS) or AAID (Android) for ad tracking
Your Control:
iOS: Settings → Privacy → Tracking → Disable for GV Discover
Android: Settings → Google → Ads → Opt out of personalization
In-App: Settings → Privacy → Share Usage Data (toggle off)
11. Updates to This Privacy Policy
11.1 How We Notify You
For Material Changes:
Email to all registered users (30 days before effective date)
Prominent in-app banner
Push notification (if enabled)
Updated "Effective Date" at top of this policy
For Minor Changes:
Updated policy posted at govividco.com/privacy
"Last Updated" date reflects change
11.2 Your Options After Changes
If You Disagree:
Stop using the Services before the effective date
Delete your account (see Section 4.2)
Continued Use = Acceptance: Using GoVivid Services after the effective date means you accept the updated policy.
12. Accessibility of This Policy
We've Designed This Policy To Be:
✅ Fully compatible with screen readers (VoiceOver, TalkBack, JAWS)
✅ Structured with semantic headings for easy navigation
✅ Written in plain language (Flesch-Kincaid Grade 8-10)
✅ Available in high-contrast format
✅ Printable in large text (18pt+)
Alternative Formats:
Audio version: Available at govividco.com/legal
Large print PDF: Email hello@govivid.ai
Braille (upon request): Contact hello@govivid.ai with your preferred format
Translation: Currently available in English. Additional languages coming soon (Spanish, French, German).
13. Contact Us
General Privacy Questions
GoVivid Co.
1120 S. Freeway, Suite 215
Fort Worth, Texas 76104
United States
Email: hello@govivid.ai
Phone: (870) 468-4843 (870-GoVivid)
Website: www.govividco.com/contact
Privacy-Specific Inquiries: legal@govivid.ai
Exercising Your Rights
Data Subject Requests: legal@govivid.ai
Response Timeline:
Initial acknowledgment: 5 business days
Full response: 30-45 days (depending on complexity)
Parental Rights & Minor Users (Ages 13-17)
Email: hello@govivid.ai
Phone: (870) 468-4843
Parents and legal guardians may:
Review information about their child
Request corrections to their child's data
Request deletion of their child's account
Withdraw parental consent at any time
Report a Security Issue
Security Vulnerability Reporting: security@govivid.ai
(Please do not report security issues via public channels)
Bug Bounty Program: Coming Q2 2026
14. Legal Information
Governing Law: This Privacy Policy is governed by the laws of the State of Texas, United States, without regard to conflict of law principles.
Dispute Resolution: Any disputes will be resolved via binding arbitration in Fort Worth, Texas, as specified in our Terms of Service.
Severability: If any provision is found invalid, the remaining provisions remain in effect.
Document History:
v1.0 (July 24, 2024): Initial policy
v2.0 (February 9, 2026): Comprehensive update reflecting GV Discover launch, DirectMe development, AI transparency enhancements, and expanded privacy rights
Your Consent
By using GoVivid's Services, you acknowledge that you have read, understood, and agree to this Privacy Policy.
Last Reviewed: February 9, 2026