Effective Date: March 17, 2026
Account Data: Email address, display name, and profile photo (if provided via Google OAuth).
Usage Data: Pilgrimage records, prayer history, stamps collected, candle counts, streak data, and friend connections.
Payment Data: Subscription and payment information is processed by Paddle. We do not store credit card details.
Device Data: GPS location (only when you explicitly verify a cathedral visit), browser language preference.
Your data is stored securely using Supabase (PostgreSQL database with row-level security). Authentication is handled by Supabase Auth.
We do not sell, trade, or rent your personal data to third parties. Data is shared only with:
We use localStorage to save your language preference and authentication session. We do not use tracking cookies.
Your data is retained as long as your account is active. You may request account deletion by contacting us, which will permanently remove all associated data.
Sancta is not intended for children under 13 years of age. We do not knowingly collect personal data from children under 13.
You have the right to access, correct, or delete your personal data. You may also withdraw consent for data processing at any time by deleting your account.
We may update this Privacy Policy from time to time. Changes will be posted on this page with an updated effective date.
For questions about this Privacy Policy, please contact us at: support@sancta.app