Privacy Policy
Last updated: March 5, 2026
1. Introduction
This Privacy Policy describes how BIBLIC AI LTDA. (“BiblicAI”), enrolled under CNPJ/MF No. 63.250.009/0001-70, headquartered at Rua do Rocio, No. 350, Conj 71, Vila Olímpia, São Paulo - SP, 04552-000, Brazil, collects, uses, stores, shares, and protects the personal data of users of the BiblicAI application.
Prepared in accordance with the LGPD (Brazilian General Data Protection Law No. 13.709/2018), the Brazilian Civil Rights Framework for the Internet (Law No. 12.965/2014), and the Consumer Protection Code (Law No. 8.078/1990).
By creating an account, you declare that you have read and understood this Policy and consent to the processing of your data as described herein.
2. Data Controller
Controller: BiblicAI Tecnologia Ltda. For privacy matters, contact the Data Protection Officer (DPO): privacy@biblic.ai.
3. Children and Adolescents
Minimum age: 12 years. We do not knowingly collect data from children under 12. Users between 12 and 18 years old must have authorization from their legal guardian.
4. Legal Bases for Processing
| Legal Basis | Ground (LGPD) | Application |
|---|---|---|
| Consent | Art. 7, I and Art. 11, I | Sensitive data (religious conviction), optional communications |
| Performance of a contract | Art. 7, V | Account, provision of the Service, subscriptions |
| Legitimate interest | Art. 7, IX | Security, fraud prevention, Service improvement |
| Legal obligation | Art. 7, II | Tax and regulatory obligations |
5. Data We Collect
5.1. Account and Registration Data
| Data | Required? | Details |
|---|---|---|
| Yes | Collected in all login methods. | |
| Name | Yes | Provided at registration or extracted from Google/Apple Sign-In. |
| Profile photo | No | Optional. Stored in Firebase Storage. |
| Login identifiers | Automatic | Firebase UID, Google ID, or Apple ID. |
5.2. Usage Data and Preferences
- Preferences: theme, font size, Bible version, language, notifications.
- Progress: study plans, check-ins, streaks, points, and level.
- Favorites and notes: favorite verses, highlights, study notes.
- Usage counters: daily/monthly usage to control free-plan limits. Automatically renewed; previous values overwritten.
5.3. Content Sent to the AI (Chat)
All messages sent to the AI assistant are stored in Google Cloud Firestore (Firebase) for history access. Data per message: content, role (user/assistant), date/time, and technical metadata.
Smart Memory (Premium): On the free plan, each conversation is independent and the AI does not retain context between conversations. On the Premium plan, the Smart Memory feature allows the AI to store relevant information voluntarily provided by you (such as name, birthday, study preferences) and use it to personalize your experience across different conversations and features of the App. This data is stored in a structured way, linked to your profile, and can be viewed, edited, or deleted at any time.
Sensitive data: Messages may contain data on religious conviction, classified as sensitive under the LGPD (Art. 5, II). Processing is based on your specific consent.
5.4. Subscription and Purchase Data
- Subscription status: current plan (free/monthly/annual) and premium status.
- Plan type and dates: managed by RevenueCat.
- Transaction identifiers: RevenueCat identifier linked to the profile.
BiblicAI does not receive, store, or process credit card data. Transactions are processed by Apple and Google.
5.5. Technical Data
- IP address: not actively collected. Infrastructure services may log IPs.
- Identifiers: Firebase UID, OneSignal Player ID, RevenueCat App User ID.
- Device: we do not actively collect IDFA, IDFV, or device ID. The RevenueCat SDK may collect IDFV automatically.
5.6. Data We Do Not Collect
BiblicAI does not use attribution/marketing SDKs, does not have Firebase Analytics enabled, does not perform cross-app tracking, does not collect location (GPS), nor contact-list data or other device sensors.
6. How We Collect Data
- Directly from you: when creating an account, setting preferences, sending messages, saving favorites.
- Automatically: authentication identifiers, usage counters.
- From third parties: authentication data from Google and Apple; subscription data via RevenueCat; notification data from OneSignal.
7. How We Use Data
| Purpose | Data Used |
|---|---|
| Create and manage account | Email, name, login identifiers |
| Provide the Service (chat, search, studies) | Messages, preferences, progress |
| Personalize experience and Smart Memory | Preferences, voluntarily shared data |
| Process subscriptions | Status, RevenueCat identifiers |
| Send notifications | OneSignal Player ID, settings |
| Control free-plan limits | Usage counters |
| Security and abuse prevention | Access data, usage patterns |
| Comply with legal obligations | Data required by law |
8. Artificial Intelligence and Sensitive Data
8.1. AI Processing
BiblicAI uses AI provided by the Microsoft Azure OpenAI Service (GPT-4.1 model), with servers located in Brazil (Brazil South region). Azure Cognitive Services is used for audio transcription, also on servers in Brazil.
When you send a message, the content is transmitted to Microsoft Azure servers in Brazil via an encrypted connection (HTTPS/TLS).
8.2. AI Use of Data
Conversation content is not used to train or improve artificial intelligence models. Under the terms of the Azure OpenAI Service, data sent via API is not used by Microsoft for training. Messages are processed exclusively to generate real-time responses.
8.3. Storage and Smart Memory
Conversation history is stored in Google Cloud Firestore (Firebase), separately from AI processing. You can delete conversations individually or request complete deletion via account deletion.
On the Premium plan, Smart Memory stores, in a structured way, personal information you voluntarily share during conversations. This data is saved as variables linked to your profile, accessible by the AI across different conversations and features, enabling continuous personalization. It can be viewed, edited, or deleted in the App settings.
8.4. Sensitive Data
Interactions with the App may involve data on religious conviction (sensitive data, LGPD Art. 5, II). Processing is based on your specific consent (Art. 11, I of the LGPD).
8.5. Protection Measures
- Encrypted communications (HTTPS/TLS);
- Data at rest protected by AES-256 (Google Cloud and Azure);
- Content access restricted to the account holder.
9. Data Sharing
BiblicAI does not sell, rent, or trade personal data. Data may be shared in the event of a legal obligation or court order.
| Provider | Purpose | Data | Country |
|---|---|---|---|
| Google Firebase | Hosting, database, authentication | Profile, conversations, preferences | Brazil / USA |
| Microsoft Azure (OpenAI) | AI processing | Chat messages | Brazil |
| Microsoft Azure (Cognitive) | Audio transcription | Audio sent | Brazil |
| RevenueCat | Subscription management | Firebase UID, status | USA |
| OneSignal | Push notifications | Firebase UID, email, Player ID | USA / EU |
| Apple (App Store) | Payments | Transaction data | USA |
| Google (Play Store) | Payments | Transaction data | USA |
10. International Data Transfers
Some data may be transferred and processed in the United States (RevenueCat, OneSignal, Apple, Google) and in the European Union (OneSignal). AI services (Azure OpenAI and Cognitive Services) and Firebase use servers in Brazil when available.
International transfers are carried out based on standard contractual clauses and safeguards provided for in the LGPD (Art. 33), including data processing terms and security certifications (SOC 2, ISO 27001) of the providers.
11. Data Retention and Deletion
| Data Type | Retention | Note |
|---|---|---|
| Account data | Until deleted by the user | Accounts inactive for 2+ years may be deleted |
| Conversations (all) | Until deleted by the user | No persistent context between chats on the free plan |
| Smart Memory | Until deleted by the user | Manageable in settings (Premium only) |
| Local audio cache | 7 days | Automatic cleanup on the device |
| Subscription data | Per RevenueCat/stores | Tax data: 5 years (Brazilian legislation) |
| Infrastructure logs | Per Google Cloud/Azure | Managed by the providers |
| Usage counters | Transient data | Automatically renewed and overwritten |
12. Account and Data Deletion
Delete your account in Settings > Account > “Delete my account”. The process requires double confirmation. The following will be permanently removed:
- Profile and account data;
- Chat conversations and messages;
- Favorites, notes, and conversation folders;
- Smart Memory data;
- Journey, progress, and preference data;
- Profile photo;
- Authentication records.
Deletion is irreversible. Tax data will be retained for the legal period. You may also request deletion by email: privacy@biblic.ai.
13. Information Security
- Encryption in transit: HTTPS/TLS in all communications.
- Encryption at rest: AES-256 managed by Google Cloud and Azure.
- Access control: Firebase Auth with UID-based access.
- Backups: automatically managed by Firebase.
No system is completely secure. We strive to protect your information but cannot guarantee absolute security.
14. Your Rights (LGPD)
You have the following rights:
- Confirmation and access: confirm the existence of processing and access your data;
- Correction: request correction of incomplete or inaccurate data;
- Anonymization, blocking, or deletion: of unnecessary or excessive data;
- Portability: request portability to another provider;
- Deletion: of data processed based on consent;
- Information about sharing: know with whom we share your data;
- Withdrawal of consent: withdraw at any time;
- Objection: object to processing in cases that do not depend on consent.
Contact: privacy@biblic.ai. Response time: 15 days (LGPD).
15. Communications and Notifications
- Push: via OneSignal. Permission requested on first access, manageable on the device.
- Local: devotional reminders configurable by the user.
- Emails: transactional only (account verification, password recovery). No marketing.
16. Changes to this Policy
We may update this Policy periodically. Substantial changes will be communicated by notification in the App or by email. Continued use after the communication constitutes acceptance.
17. Contact
For questions about privacy:
- Privacy (DPO): privacy@biblic.ai
- Support: support@biblic.ai
- Website: https://biblic.ai
You may file a complaint with the ANPD (Brazilian National Data Protection Authority): www.gov.br/anpd.