Last updated: 7 May 2026

This Privacy Policy explains how Form Ventures Ltd. (“we,” “us,” “our”) collects, uses, stores, and protects your personal data when you use the Pantheon mobile application (the “App”). We are the data controller for the personal data described in this policy.

If you have any questions about this policy or about how we handle your data, contact us at support@pantheon.app.


1. Who we are

  • Company: Form Ventures Ltd.
  • Registered address: Alexander Pushkin Blvd. 15, 1618 Sofia, Bulgaria
  • Country of establishment: Bulgaria (European Union)
  • Contact for privacy matters: support@pantheon.app

We are subject to the EU General Data Protection Regulation (GDPR) and the Bulgarian Personal Data Protection Act.


2. The service

Pantheon is a mobile application that helps you write a memoir or personal book. You record voice answers to AI-generated interview questions; we transcribe those recordings and generate written chapters from them. You can add photos, edit chapters, and order printed copies of the finished book.

The App is intended for users who are at least 18 years old.


3. Data we collect

3.1 Account data

When you create an account we collect:

  • Email address
  • Password (stored only as a salted hash; we cannot read it)
  • Full name
  • Account creation date
  • Email verification status
  • Sign-in session tokens (managed by Supabase Auth)

3.2 Profile and app preferences

  • Language preference
  • Subscription tier (free or Author)
  • Profile photo URL (if you upload one)

3.3 Content you create in the App

  • Book metadata: title, subtitle, theme, description, cover image
  • Chapter content: text you write or that the AI generates from your interview answers
  • Interview questions and your written or transcribed answers
  • Photos you upload
  • Captions and descriptions for photos

This content is personal in nature and may contain sensitive information about your life, family, health, beliefs, or experiences. We treat it accordingly. See sections 4 and 5 below for how we use and share it.

3.4 Voice recordings (biometric data)

When you answer an interview question with your voice:

  • We record your voice on your device.
  • We upload the audio file to our private storage on Supabase.
  • We send the audio file to OpenAI’s Whisper API for transcription into text.
  • We store both the audio file and the resulting transcript.

Voice data is considered biometric data under GDPR Article 9 (“special category data”). We process it only with your explicit consent, which you provide by tapping the “Record” button after reading this Privacy Policy.

You can withdraw your consent at any time by stopping recording new answers and by requesting deletion of your existing audio files (see section 9).

3.5 Subscription and payment data

When you subscribe to the Author plan or buy credit top-ups:

  • We collect a Stripe customer ID, subscription ID, and price ID.
  • We store the date your subscription period ends and whether it is set to cancel.
  • We log credit balance changes and transaction history.

We do not collect, see, or store your full payment card number, CVV, or expiration date. You enter these directly on Stripe’s hosted checkout page; Stripe sends them to your card issuer. We only receive a reference token from Stripe.

3.6 Book orders (when you order printed copies)

If you order a printed copy of your book:

  • Shipping address (name, address line 1, address line 2, city, postal code, country)
  • Number of copies, total price, order status
  • An order ID from our print provider, Lulu Press, Inc. (“Lulu”)

3.7 Technical data

  • Device language
  • App version
  • Crash and error logs sent to our backend (no third-party crash reporting service is used at this time)

We do not use any third-party analytics, tracking, advertising, or attribution SDKs. We do not collect your device identifier (IDFA / Android Advertising ID), location, contacts, calendar, or any other on-device data.


4. Why we use your data and our legal basis (GDPR Article 6)

Purpose Data used Legal basis
Provide and maintain your account Account data Contract (Article 6(1)(b))
Generate questions, transcribe voice, generate chapters Voice recordings, content, profile Contract + explicit consent for voice (Article 6(1)(b) + Article 9(2)(a))
Process payments and grant entitlements Subscription data, credit balances Contract (Article 6(1)(b))
Comply with tax and accounting law Subscription, payment metadata Legal obligation (Article 6(1)(c))
Print and ship physical books Book orders, shipping address Contract (Article 6(1)(b))
Detect abuse, fraud, and security incidents Account activity, error logs Legitimate interests (Article 6(1)(f))
Respond to your support requests Whatever you provide Legitimate interests (Article 6(1)(f))
Send transactional emails (verification, password reset, receipts) Email address Contract (Article 6(1)(b))

We do not use your data for advertising, profiling, automated decision-making with legal effects, or marketing to third parties.


5. Who we share your data with (sub-processors)

We use the following service providers (“sub-processors”) to operate the App. Each receives only the minimum data needed to perform its function:

5.1 Supabase

  • Role: Database, authentication, file storage, backend functions
  • Data shared: All account data, content, voice files, transcripts, photos, subscription metadata
  • Location: EU and US infrastructure
  • Privacy policy: https://supabase.com/privacy

5.2 OpenAI

  • Role: Transcribes voice recordings (Whisper API) and generates interview questions, chapters, and chapter refinements (GPT-4o)
  • Data shared: Audio files (for transcription), book theme, chapter title, your transcribed answers, and other context strings
  • Location: United States
  • Important: OpenAI’s API terms state that data submitted via the API is not used to train their models and is retained for up to 30 days for abuse monitoring before deletion. See OpenAI’s API data policy at https://openai.com/policies/api-data-usage-policies
  • Privacy policy: https://openai.com/policies/privacy-policy

5.3 Stripe

  • Role: Payment processing (subscriptions and one-time top-ups)
  • Data shared: Email address, name, subscription identifiers; you enter your payment card details directly with Stripe
  • Location: Global; Stripe is the data controller for your card details
  • Privacy policy: https://stripe.com/privacy

5.4 Lulu Press, Inc. (“Lulu”)

  • Role: Prints and ships physical copies of your book
  • Data shared: Your shipping address, the PDF of your book, and order details — only when you place a print order
  • Location: United States
  • Privacy policy: https://www.lulu.com/about/privacy

5.5 Apple and Google

  • Role: App distribution via the App Store and Google Play
  • Data shared: Whatever Apple and Google collect under their own policies when you download or update the App; we receive aggregated, anonymous installation analytics from them
  • Privacy policies: https://www.apple.com/legal/privacy/ and https://policies.google.com/privacy

We do not sell your data, and we do not share it with anyone outside the list above except where required by law (court order, regulatory request, etc.).


6. International data transfers

Some of our sub-processors are located in the United States (OpenAI, parts of Stripe and Supabase infrastructure, Lulu). When your data is transferred outside the European Economic Area, we rely on:

  • Standard Contractual Clauses (SCCs) approved by the European Commission, included in our agreements with these providers; and
  • The EU–U.S. Data Privacy Framework where applicable.

You can request a copy of the safeguards in place by emailing support@pantheon.app.


7. How long we keep your data

Category Retention period
Account data (email, name, login info) Until you delete your account
Books, chapters, photos, captions Until you delete the book or your account
Voice recordings (audio files) Until you delete the related book or your account
Transcripts of voice recordings Stored alongside the related chapter; deleted when the chapter or book is deleted
Subscription and credit transaction history Up to 7 years after the transaction, to comply with Bulgarian and EU tax and accounting law
Shipping addresses for book orders Up to 7 years after the order, for the same legal reason
Backups Up to 30 days in our database backup snapshots
Crash and error logs Up to 90 days

After these periods, we delete or anonymize the data.


8. How we protect your data

  • All data in transit is encrypted using HTTPS / TLS.
  • Passwords are salted and hashed by Supabase Auth; we never see your plaintext password.
  • Database access is governed by row-level security policies — you can only see rows linked to your own user ID.
  • Audio and book PDF files are stored in private buckets accessible only via signed URLs to authenticated users.
  • Photos are stored in a bucket configured for public read access via unguessable URLs. While this means a photo URL is technically reachable from the internet without authentication, the URL contains a long random component that is not searchable or guessable. We are evaluating whether to switch this to fully private signed URLs in a future release. Please consider this when uploading photos that contain highly sensitive imagery.
  • We restrict employee access to user data on a need-to-know basis.

No system is perfectly secure. If we ever detect a personal data breach that affects you and is likely to result in a risk to your rights, we will notify you and the Bulgarian Commission for Personal Data Protection within 72 hours, as required by GDPR Article 33–34.


9. Your rights under GDPR

You have the following rights regarding your personal data:

  • Right of access (Article 15) — to know what data we have about you and to receive a copy.
  • Right to rectification (Article 16) — to correct inaccurate or incomplete data.
  • Right to erasure / “right to be forgotten” (Article 17) — to ask us to delete your data.
  • Right to restriction (Article 18) — to ask us to limit how we use your data.
  • Right to data portability (Article 20) — to receive your data in a machine-readable format.
  • Right to object (Article 21) — to object to processing based on legitimate interests.
  • Right to withdraw consent (Article 7) — at any time, where processing is based on consent (such as voice recording).
  • Right not to be subject to automated decision-making (Article 22) — we do not make automated decisions with legal effects about you.
  • Right to lodge a complaint with the Bulgarian Commission for Personal Data Protection (CPDP, www.cpdp.bg) or your local supervisory authority.

How to exercise your rights

Send a request from the email address linked to your account to support@pantheon.app. We respond within 30 days as required by GDPR. We may ask for additional verification if we cannot confirm the request comes from you.

Account deletion

You can delete your account at any time directly from the App: open the Profile tab, scroll to the Danger Zone at the bottom, and tap Delete Account. After confirming with your email address, deletion happens immediately:

  • Your account, books, chapters, transcripts, photos, and audio recordings are removed.
  • Any active subscription is cancelled with Stripe straight away (you will not be billed again).
  • Records that we are legally required to retain (for example, payment metadata for tax purposes) may be kept until the legal retention period expires — see section 7.

If you prefer to delete your account by email instead, write to support@pantheon.app from the address linked to your account, with the subject line “Delete my account.” We respond within 30 days as required by GDPR.


10. Children’s data

The App is intended for users aged 18 and older. We do not knowingly collect personal data directly from anyone under 18 — accounts cannot be created by minors.

If you, as the account holder, choose to record voice contributions from a person under 18 (for example, a child or grandchild whose story is being preserved), you are responsible for that content and for obtaining the consents required by law — see Section 2 of our Terms of Service. We process such voice content on the basis of your consent and your representation that those further consents are in place.

If you become aware that personal data of a minor has been collected without proper consent, please contact us at support@pantheon.app and we will delete it.


11. Cookies and similar technologies

The App is a mobile application and does not use web cookies. We use the local device storage that is necessary to keep you signed in (e.g., session tokens stored by Supabase Auth and language preferences stored by Expo Secure Store). These are essential for the App to function and are not used for advertising or tracking.


12. Changes to this policy

If we make material changes to this Privacy Policy, we will notify you in the App or by email before the changes take effect. The “Last updated” date at the top of this document indicates the most recent revision.


13. Contact and Data Protection Officer

For any questions, requests, or complaints about how we handle your data:

  • Email: support@pantheon.app
  • Postal address: Alexander Pushkin Blvd. 15, 1618 Sofia, Bulgaria

If you are not satisfied with our response, you have the right to file a complaint with the Commission for Personal Data Protection (CPDP) at https://www.cpdp.bg or with the supervisory authority in your country of residence.