Pular para o conteúdo
Legal document

Privacy Policy

Sanctuo is about faith — and faith requires trust. This policy explains, without unnecessary legalese, exactly what data we collect, why we collect it, who we share it with and how you stay in control of all of it.

Last updated: LGPD (Brazil) and GDPR (EU)Applies to the app and to this website

This policy is also available in Portuguese and Spanish.

1 Who we are and who this policy applies to

Sanctuo is an app that helps you find churches near you, read the Bible offline and keep up with the life of your faith community.

The controller of your personal data — the party that decides how and why it is processed — is Sanctuo App Desenvolvimento de Software Customizável LTDA, a Brazilian company registered under CNPJ no. 68.480.807/0001-02, with its registered office at Rua Pais Leme, 215, Conj. 1713 — Pinheiros, São Paulo/SP, CEP 05424-150, Brazil.

This policy applies to:

  • the Sanctuo app for iPhone (iOS) and Android;
  • the sanctuo.com.br website and its subpages;
  • the support we provide by e-mail to users and churches.

By creating an account or using Sanctuo, you state that you have read and understood this policy. If you do not agree with it, please do not use the app.

2 30-second summary

The full document is right below, but this is what matters most:

  • We do not sell your data. Ever. To anyone.
  • There is no advertising in the app. We do not use ad SDKs, social media pixels or advertising identifiers. We use Google Analytics for Firebase to measure how the app is used — which screens are opened, what is ignored —, always read in aggregate and without your name or e-mail. See section 3.2.
  • Your precise location is not stored on our servers. It is used on your device, at the moment of the search, to sort churches by distance.
  • The Bible works 100% offline. The text lives inside the app; what you read is not sent anywhere.
  • You can delete everything. Account deletion is available inside the app itself and removes your data permanently.
  • Your faith choices are treated as sensitive data — with the extra care that the LGPD (and, in Europe, the GDPR) requires. See section 6.

3 What data we collect

We collect only what is needed for the app to work. We have organized it by source: what you give us, what is generated by use and what stays only on your device.

3.1 Data you provide

DataWhen it is collected
E-mail and passwordWhen you create an account by e-mail. The password is stored only as a cryptographic hash — not even we can read it.
Google or Apple identifierWhen you sign in with Google or with Apple. We receive your e-mail and, when available, your name. If you use Apple’s “Hide My Email”, we receive only the anonymous relay address.
First-use answers, without an accountWhen you open the app for the first time, before any sign-up, we ask for your age range, your city and the denomination you identify with. You can skip the city and the denomination. The answers are stored under a random code that does not point to you: this record has no name, e-mail or phone number. It exists so we know who we are talking to and where we need to reach — never to identify anyone. If you later create an account, these answers become part of your profile and the anonymous record is no longer counted separately, so you are not asked twice.
Favorite churchesWhen you tap the heart on a church.
Bible markingsFavorited and highlighted verses (book, chapter, verse and color), to sync between devices.
Reading plan progressThe plan you chose, the days completed and your reading streak.
Church claim requestIf you are a leader and want to take over your church’s profile: your name, role, e-mail, phone number and proof of your connection to the church. Used only for moderation.
Church profile contentIf you manage a church: photo, description, service times, social media, phone number, website, streaming link and events.
Photos from your galleryOnly the images you explicitly select for a church’s profile photo. We do not scan your gallery.
Waiting list for your cityIf Sanctuo does not yet have churches listed where you are, the app shows a notice and asks whether you want to be told when we get there — and the same request can be made at sanctuo.com.br/minha-cidade, without installing anything. We keep the city (and the approximate region) to know where the demand is — and, only if you fill it in, your e-mail, for the notice. The e-mail is optional: without it, the city still counts as a request. Along with it goes a code derived from your IP address — never the IP itself —, which serves only to prevent automated mass submissions.
Support messagesWhat you write through the form at sanctuo.com.br/suporte or by e-mail: name, e-mail, subject and the text of the message. Along with it go the browser used and a code derived from your IP address — never the IP itself —, which serves only to prevent automated mass submissions.

3.2 Data generated by using the app

DataDetails
Precise location (GPS)Requested with your permission and used only while the app is open, to sort churches by distance and center the map. The coordinates are used in the query and discarded — we do not record your location history. We never access your position in the background.
Approximate regionCity, state and country derived from your position. This is saved, so we can understand in which regions Sanctuo needs more churches mapped and to let you know about news in your city. It is kept in your profile when you have an account and, when you do not, in the anonymous first-use record described in section 3.1 — moving to your profile if you sign up. It is always the municipality, never the coordinates.
Last accessDate and time you last used the app, to measure active users.
Church viewsWe record that a church was opened, to know which ones are popular. This record is read only in aggregate and is never exposed per user.
Notification tokenAn identifier of your device generated by Expo’s push service, plus the platform (iOS or Android). It is only created if you allow notifications.
Subscription statusIf you subscribe to Sanctuo Pro: status (trial, active, canceled), the product purchased, the store it came from and the start/renewal dates. See section 13.
App usage (Google Analytics)Which screens you open and when, plus usage events from the app itself. Along with them go an identifier of the app on this device generated by Firebase, the device model, the system version and the country — never your name, your e-mail or the content of what you read. It helps us know what is used and what is not. No advertising identifier is sent: see section 4.
Minimal technical dataApp version, operating system and IP address, recorded automatically by our infrastructure providers in security and diagnostic logs.

3.3 Data that stays only on your device

This data never reaches our servers — it lives in your phone’s local storage and disappears when you uninstall the app:

  • the full text of the Bible (Bíblia Livre, public domain), built into the app;
  • your preferences: light/dark theme, preferred denomination, your home church and service reminders;
  • the list of recently viewed churches;
  • the cache of images and search results;
  • your session token, which keeps you signed in.

4 What we do not collect

Saying what we collect is as important as saying what we left out:

  • Your credit card details. Every payment happens inside the App Store or Google Play; we never see card numbers.
  • Your contacts, text messages, calls or files. The app does not ask for these permissions.
  • Your location in the background. Never. When the app is closed, we do not know where you are.
  • Your photos in general. Only the images you choose, one by one.
  • What you read or search for in the Bible. Reading is offline and not tracked.
  • Advertising identifiers (IDFA / GAID), device fingerprinting or any ad network SDK. On Android, the AD_ID permission is removed from the app at build time, on purpose — even if a library asks for it.

5 What we use it for and on what legal basis

Brazil’s General Data Protection Law (LGPD) requires every processing of data to have a legitimate purpose and a legal basis that authorizes it. Here is ours, item by item. The equivalent bases under the GDPR, for people in Europe, are in section 21.

PurposeData usedLegal basis (LGPD)
Create and maintain your account, sync favorites and markings between devicesE-mail, social sign-in identifier, favorites, markings, reading plansPerformance of a contract — art. 7, V
Show the nearest churches and center the mapPrecise locationConsent — art. 7, I (you grant it in the system permission)
Recommend churches by denomination and save your favoritesPreferred denomination, favoritesSpecific consent for sensitive data — art. 11, I (see section 6)
Send the verse of the day, service reminders and notices from your churchNotification token, preferencesConsent — art. 7, I
Moderate claims, preventing fraud and inappropriate contentForm data, author identifierPerformance of a contract and legitimate interest — art. 7, V and IX
Understand where the app is used and which regions need more churchesApproximate region, last access, aggregated viewsLegitimate interest — art. 7, IX
Measure how the app is used — most opened screens, ignored features, where people give upUsage events and the app identifier on the device (Google Analytics)Legitimate interest — art. 7, IX
Let you know when Sanctuo starts covering your cityCity, approximate region and e-mail (when you provide it)Consent — art. 7, I (you tick the option; it is not pre-ticked)
Unlock Sanctuo Pro features for subscribersSubscription statusPerformance of a contract — art. 7, V
Ensure security, prevent abuse and diagnose failuresTechnical data, logs, IPLegitimate interest — art. 7, IX
Comply with legal obligations and respond to competent authoritiesWhatever is legally requiredLegal obligation — art. 7, II
About legitimate interest

When we rely on legitimate interest, we always use the smallest possible amount of data, in aggregate. You can object to this processing at any time by writing to contato@sanctuo.com.br.

6 Religious belief: sensitive data

The LGPD classifies religious belief as sensitive personal data (art. 5, II) — and so does the GDPR, as a special category of data (Art. 9). It is only honest to acknowledge it: when you use Sanctuo, some of your actions may reveal your faith — favoriting a church, choosing a denomination or marking verses.

We take this on with the care the law requires:

  • we process this data on the basis of your specific and highlighted consent (LGPD art. 11, I; GDPR Art. 9(2)(a), explicit consent), given at the moment you take each of these actions;
  • we do not share this data with third parties for commercial, advertising or profiling purposes — under any circumstances;
  • our administrators see only aggregated numbers (for example, “so many churches favorited in São Paulo”), never the list of favorites of an identified person;
  • you can withdraw this consent at any time by removing your favorites and markings, or by deleting your account.
A word of caution

If you live in a context where exposing your faith could put you at risk, think carefully before making contact details public on the profile of a church you manage. You can use Sanctuo to search for churches and read the Bible without creating any account.

7 Content that is public in the app

Not everything you send is private — and it is important that the difference is clear. The following is visible to any user of Sanctuo:

  • the profile of a church you manage: description, service times, photos, social media, phone number, website and events.

Publish in these fields only information you want to make public. We would rather you use a contact phone number and e-mail belonging to the ministry, not your personal ones.

What is private and never appears to other users: your favorites, your Bible markings, your reading progress, your sign-up e-mail, your location and the status of your subscription.

8 Data about churches in the catalog

Sanctuo’s church catalog is built from publicly available information about establishments — name, address, business phone number, coordinates, opening hours, public rating and photos of the building. This is data about legal entities and places of worship, not personal data of individuals.

If you are responsible for a listed church and want to correct, add to or request the removal of the information, there are two ways:

  • claim the profile inside the app and edit the data yourself;
  • write to contato@sanctuo.com.br — we reply within 15 days.

9 Who we share data with

We do not sell, rent or hand over your personal data. We share it only with the service providers (processors) that make the app possible, and only to the extent each one needs to do its job:

PartnerWhat forWhat it receives
SupabaseDatabase, authentication and image storagePractically all the account and content data described in section 3
ExpoSending notifications and app updatesNotification token, platform and app version
GoogleSign in with Google, maps on Android, measuring usage of the app and the website (Google Analytics) and distribution through the Play StoreAccount identifier (if you use Google sign-in), map usage data and the usage events described in sections 3.2 and 19 — without name or e-mail
AppleSign in with Apple, maps on iOS and distribution through the App StoreAccount identifier (if you use Apple sign-in) and map usage data
RevenueCatManaging Sanctuo Pro subscriptionsYour user identifier and subscription status — no payment data
VercelHosting this websiteTechnical website access data (IP, browser), in short-lived logs

In addition, we may disclose data when:

  • there is a court order or a request from a competent authority;
  • it is necessary to defend our rights or the safety of users;
  • there is a merger, acquisition or sale of the business — in which case you will be notified in advance and this policy will remain in force until it is formally replaced.

10 International transfers

The partners listed above operate servers outside Brazil, mainly in the United States and the European Union. This means your data may be stored and processed in those countries.

These transfers are carried out under art. 33 of the LGPD and supported by standard contractual clauses and protection commitments equivalent to those required by Brazilian law, entered into with each provider.

For people in the European Economic Area and the United Kingdom, see also section 21.

11 Device permissions

Every permission is optional and can be revoked at any time in your phone’s settings. The app keeps working without them — just with fewer features:

PermissionWhat forIf you decline
Location (only while the app is open)Sort churches by distance and center the mapChurches are listed by highest rating, and you search by city or neighborhood
NotificationsVerse of the day, service reminders and notices from your churchNothing is sent; you still see the notices inside the app
PhotosChoose the image for a church’s profileThe church keeps the default image

To revoke: on iPhone, in Settings → Sanctuo; on Android, in Settings → Apps → Sanctuo → Permissions.

12 Notifications

We send only two kinds of notification, and you control both:

  • Reminders you schedule yourself — verse of the day and service times. They are generated on your own device and can be turned off in the Profile tab.
  • Community notices — announcements from a church you follow and the outcome of the moderation of your claims.

We do not send third-party advertising notifications. To stop receiving everything at once, just turn off Sanctuo notifications in your system settings — your device’s token is no longer used.

13 Payments and subscriptions

Sanctuo Pro is billed exclusively through the App Store or Google Play, depending on the store you downloaded the app from. Billing is processed entirely by Apple or Google.

  • We never see, receive or store card details, bank account or billing address.
  • We receive only confirmation that the subscription is active, in trial, canceled or expired, with the corresponding dates.
  • Cancellations, refunds and plan changes are made directly in the store, following its rules.

14 How long we keep data

DataRetention period
Account, favorites, markings and reading plansFor as long as your account exists
Inactive accounts (no access at all)Up to 24 months; after that we notify you by e-mail before removing them
Published church profilesWhile they are active or until you remove them
Notification tokenUntil you revoke the permission, change devices or delete your account
Church view recordsAnonymized when the account is deleted and kept only as aggregate statistics
Technical and security logsUp to 12 months
Subscription statusDeleted along with the account. The tax record of the purchase stays with Apple or Google, which are the sellers, for each one’s legal period
Support messagesUp to 24 months after the request is closed
E-mail on a city’s waiting listUntil the notice is sent, or up to 18 months — whichever comes first. You can ask for removal before that. The city, without the e-mail, remains as a demand statistic

15 How we protect your data

  • Encryption in transit (TLS/HTTPS) for all communication between the app and our servers, and encryption at rest in the database.
  • Per-user isolation in the database itself: we use Row Level Security, a lock at the database level that technically prevents one user from reading another’s data — even if the app had a bug.
  • Passwords never in plain text: they are stored as a salted, irreversible hash.
  • Administrative access restricted to a minimal number of people, only for moderation and support.
  • No sensitive data is kept in the app in a way that other apps on the device could read.

No system is 100% invulnerable. If a security incident occurs that poses a relevant risk to your rights, we will notify you and the ANPD (Brazil’s National Data Protection Authority) within a reasonable time, as required by art. 48 of the LGPD.

16 Your rights

Art. 18 of the LGPD grants you a set of rights over your data. All of them apply here, free of charge:

  • Confirmation and access — to know whether we process your data and receive a copy of it.
  • Correction — to update incomplete, inaccurate or outdated data.
  • Anonymization, blocking or deletion — of data that is unnecessary, excessive or processed in breach of the law.
  • Portability — to receive your data in a structured, machine-readable format.
  • Information about sharing — to know which entities we share your data with.
  • Withdrawal of consent — at any time, without affecting the lawfulness of what was done before.
  • Objection — to object to processing based on legitimate interest.
  • Account deletion — to erase everything, as described in section 17.

To exercise any of them, write to contato@sanctuo.com.br. We reply within 15 days. We may ask you to confirm your identity before acting on a request — it protects you against fraudulent requests made in your name.

If you are not satisfied with our response, you have the right to complain to Brazil’s National Data Protection Authority (ANPD), at gov.br/anpd. If you are in the European Economic Area or the United Kingdom, your rights under the GDPR and the authority you can turn to are in section 21.

17 How to delete your account

You can delete your account and your data yourself, right in the app, without having to talk to anyone:

  • open Sanctuo and go to the Profile tab;
  • scroll to the Privacy and account section;
  • tap Delete my account and confirm.

If you prefer, write to contato@sanctuo.com.br from the e-mail address you signed up with — we complete the deletion within 15 days. The full step-by-step guide, with what is deleted and what remains, is at sanctuo.com.br/excluir-conta (in Portuguese).

What is deleted immediately

  • your login account and the e-mail you signed up with;
  • favorites, Bible markings and reading plan progress;
  • your profile and approximate region;
  • the first-use answers — age range, city and denomination, described in section 3.1 —, including the ones you gave before creating the account;
  • notification tokens for all your devices;
  • claim requests and the church profiles you managed;
  • the images you uploaded;
  • your e-mail on any city waiting list.

What remains — and why

  • Aggregated and anonymized statistics — the record that a church was visited still exists, but unlinked from you, becoming just a number;
  • the tax record of your purchase, if you subscribed to Pro — it stays with Apple or Google, which are the ones who sell and bill, not with us;
  • data we need to keep due to a legal obligation or for the exercise of rights in legal proceedings.
Deletion is permanent

There is no way to undo it or recover the content afterwards. If you subscribe to Sanctuo Pro, cancel the subscription in the App Store or Google Play before deleting your account — deleting the account here does not automatically cancel the billing made by the store.

18 Children and teenagers

Sanctuo is intended for people aged 18 and over: when you first open the app, the youngest age range available is 18 to 20, and there is no option for anyone younger. We do not knowingly collect data from children or teenagers.

If you are a parent or guardian and have found that a child created an account without your authorization, write to contato@sanctuo.com.br: we promptly remove the account and all associated data.

19 This website (cookies and similar)

The sanctuo.com.br website is a promotional page, and what it does from a privacy point of view fits in a few lines:

  • it shows no advertising and has no Facebook or TikTok pixel, nor that of any ad network;
  • it requires no sign-up to browse — no page on the site asks you to log in;
  • it uses Google Analytics to measure its audience: how many people visit, which pages they land on and where they come from. To do this, it stores the _ga and _ga_<identifier> cookies in your browser, which are used to tell one visit from another. We do not use this data for advertising and we do not cross-reference it with your account in the app;
  • it uses Vercel Speed Insights to measure the speed of pages in your browser — how long it took for the page to appear and become usable. It stores no cookies at all and does not identify you: what is sent is the page address, the measured times and the connection type. It helps us find out which page is slow, not who opened it;
  • the numbers and churches shown are written into the page when it is published — the page does not query our database while you browse;
  • in the book catalog, we count how many times each listing was opened and how many times the buy button was clicked. It is an aggregate count, of the book — not of you: what leaves your browser is the book’s identifier and nothing else. So as not to count the same person twice in the same tab, we keep a temporary marker in your browser (sessionStorage) that disappears when you close the tab and is never sent anywhere;
  • also in the catalog, what you type in the search is recorded, together with how many results appeared — with nothing that identifies you. It serves one purpose only: finding out which books people look for and do not find, to decide what to add to the collection.

Where the site receives your data is in the forms — support, my city, church claim and the church plans form. What each one collects is described in section 3.1, and they only send something when you fill them in and submit them.

The legal basis for both measurements — audience and speed — is legitimate interest (LGPD art. 7, IX): they tell us what to improve on the site, not who you are. You can object to this processing by writing to contato@sanctuo.com.br, and you can also block Google Analytics cookies in your browser settings or turn on Do Not Track — the site keeps working fully without them.

About the buy button in the book catalog: it takes you to Amazon, which is a third-party site with its own privacy and cookie policies — from the click onwards, Amazon is the one processing your data. We are participants in the Amazon Associates Program and earn a commission on qualifying purchases made through these links, at no extra cost to you. We do not send any of your data to Amazon: the link is an ordinary link, and what it carries is the identification of our associate account, not yours.

One last note for transparency: Vercel, which hosts the site, records technical access data (IP and browser) in short-lived logs. The fonts are served from our own domain — your browser makes no request to Google Fonts.

20 Changes to this policy

Sanctuo keeps evolving, and this policy will keep up. Whenever there is a change, we will update the “Last updated” date at the top of this page.

If the change is significant — such as a new purpose of use or a new partner that receives your data —, we will give prominent notice inside the app and, where appropriate, by e-mail, before the change takes effect. Previous versions can be requested through our contact channel.

21 People in the EEA and the UK (GDPR)

If you are in the European Economic Area (EEA) or the United Kingdom, the processing of your data is also governed by the General Data Protection Regulation (GDPR) — and, in the UK, by the UK GDPR. Everything in the previous sections still applies; this section adds what the GDPR requires to be stated. The controller is the Brazilian company identified in section 1.

21.1 Legal basis for each purpose

PurposeLegal basis (GDPR)
Create and maintain your account, sync favorites and markings between devicesPerformance of a contract — Art. 6(1)(b)
Show the nearest churches and center the mapConsent — Art. 6(1)(a) (you grant it in the system permission)
Recommend churches by denomination and save your favoritesExplicit consent — Art. 6(1)(a) and Art. 9(2)(a), since it may reveal religious belief (see section 6)
Send the verse of the day, service reminders and notices from your churchConsent — Art. 6(1)(a)
Moderate claims, preventing fraud and inappropriate contentPerformance of a contract and legitimate interest — Art. 6(1)(b) and (f)
Understand where the app is used and which regions need more churchesLegitimate interest — Art. 6(1)(f)
Measure how the app is used (Google Analytics)Legitimate interest — Art. 6(1)(f)
Let you know when Sanctuo starts covering your cityConsent — Art. 6(1)(a)
Unlock Sanctuo Pro features for subscribersPerformance of a contract — Art. 6(1)(b)
Ensure security, prevent abuse and diagnose failuresLegitimate interest — Art. 6(1)(f)
Measure the website’s audience and speed (section 19)Legitimate interest — Art. 6(1)(f)
Comply with legal obligations and respond to competent authoritiesLegal obligation — Art. 6(1)(c)

Where we rely on consent, you can withdraw it at any time, as easily as you gave it — by turning off the permission in your device settings, removing favorites and markings, or writing to us. Withdrawal does not affect the lawfulness of processing carried out before it.

21.2 Your rights under the GDPR

  • Access — to obtain confirmation of whether we process your data and a copy of it (Art. 15).
  • Rectification — to have inaccurate or incomplete data corrected (Art. 16).
  • Erasure — to have your data deleted (Art. 17); the simplest way is the in-app deletion described in section 17.
  • Restriction — to ask us to limit the processing of your data in the cases provided for in Art. 18.
  • Portability — to receive the data you provided to us in a structured, commonly used, machine-readable format, and to have it transmitted to another controller (Art. 20).
  • Objection — to object at any time to processing based on legitimate interest (Art. 21).
  • Withdrawal of consent — at any time, without affecting the lawfulness of earlier processing (Art. 7(3)).

To exercise any of them, write to contato@sanctuo.com.br. We respond within one month of receiving your request, as required by Art. 12(3) of the GDPR; that period may be extended by two further months where necessary, taking into account the complexity and number of requests, in which case we will tell you why within the first month.

21.3 Right to lodge a complaint

You have the right to lodge a complaint with a data protection supervisory authority, in particular in the country where you live, where you work or where the alleged infringement took place. For example:

  • Portugal — Comissão Nacional de Proteção de Dados (CNPD), cnpd.pt;
  • Spain — Agencia Española de Protección de Datos (AEPD), aepd.es;
  • United Kingdom — Information Commissioner’s Office (ICO), ico.org.uk.

21.4 International transfers

Sanctuo’s database is hosted by Supabase in the United States (Amazon Web Services, us-east-2 region), and the other partners listed in section 9 also process data mainly in the United States and the European Union, as described in section 10. When you use Sanctuo from the EEA or the UK, your data is therefore transferred outside those regions.

These transfers rely on the safeguards offered by our providers, such as the Standard Contractual Clauses approved by the European Commission (and their UK equivalents). You can ask us for more information about these safeguards by writing to contato@sanctuo.com.br.

22 People in the United States and Canada

When you first open the app, Sanctuo asks for your age range, and the youngest option available is 18 to 20 — there is no option for anyone younger. The service is not directed to children under 13, and we do not knowingly collect personal information from them, including for the purposes of the U.S. Children’s Online Privacy Protection Act (COPPA). If you believe a child has given us personal information, write to contato@sanctuo.com.br and we will delete it promptly.

23 Contact us

Questions, deletion requests, corrections to your church’s data or any privacy matter: we talk to you by e-mail, and a human being replies.

Data Protection Officer

Our official channel for exercising the rights provided for in the LGPD and the GDPR. Response time: up to 15 days.

contato@sanctuo.com.br

Controller: Sanctuo App Desenvolvimento de Software Customizável LTDA — CNPJ 68.480.807/0001-02 — Rua Pais Leme, 215, Conj. 1713 — Pinheiros, São Paulo/SP, CEP 05424-150, Brazil.
This policy is governed by the laws of the Federative Republic of Brazil, in particular Law No. 13,709/2018 (LGPD) and Law No. 12,965/2014 (Brazilian Internet Civil Framework), without prejudice to the mandatory data protection rules of the country where you live, such as the GDPR. The courts of the user’s place of residence shall have jurisdiction to settle any disputes.