Privacy Policy
Last updated: 2026-06-08
1. About Gratia Plena
Gratia Plena is a free platform for Catholic biblical and magisterial study. This policy describes, in plain language, what data we handle when you use the service and with whom it is shared.
2. What we collect
Gratia Plena does not currently offer user accounts and does not ask for any personal information to browse. There is no sign-up, no email collection, no document upload.
What exists is only standard technical web traffic:
- Server logs kept by our hosting provider (Vercel): IP address, browser user-agent, route accessed, and timestamp. These logs are used to detect abuse and diagnose technical failures. They are not associated with you as an identifiable individual.
- Aggregate usage analytics via Vercel Analytics and Vercel Speed Insights: pageviews per route, performance metrics (Core Web Vitals), approximate country, and device type. No cookies, no persistent identifier — visitors are counted via a daily hash of IP+user-agent that is discarded within 24h. No cross-session profile.
- Search query content: when you use semantic search (not text search), your query is sent to the OpenAI API to generate an embedding vector. The query exists transiently during that call and is not stored by us.
We do not set our own cookies. The interface language is controlled by the URL prefix (/pt-BR/ or /en/), not by a cookie. Analytics is cookieless too.
3. Who we share data with
Three third parties receive technical data in the normal course of the service:
- Vercel — hosts the site and processes aggregate analytics (Vercel Analytics + Speed Insights). Sees all HTTP traffic (IP, user-agent, routes) and performance metrics. Their policy: vercel.com/legal/privacy-policy.
- Supabase — stores the PostgreSQL database with the public content (Bible, Catechism, Vatican II, etc.). Stores nothing about you as a user. Their policy: supabase.com/privacy.
- OpenAI — receives the text of your query when you use semantic search, turns it into a numeric vector, returns the vector. Their policy: openai.com/policies/privacy-policy.
We do not sell, rent, or trade data with third parties for marketing purposes. No advertising vendors are integrated today.
4. Retention
Vercel logs are kept for the provider's standard retention period (typically 30 days). We have no user database, so there are no personal records to delete.
5. Your rights (LGPD, GDPR, CCPA)
Because we do not currently process identifiable personal data about you, there are no individual records to access, correct, or delete. If this changes in the future (for instance, with the introduction of user accounts), we will update this policy and provide the appropriate mechanisms for exercising rights under LGPD (Brazil), GDPR (EU), and CCPA (California).
6. Changes to this policy
This policy may be updated as the service evolves (for example, when adding analytics, advertising, or user accounts). The last-updated date at the top of this page reflects the most recent substantive change.
7. Contact
For questions about this policy, write to contato@gratiaplena.app.