1. Who We Are — Data Controller and Operator
VoxDivina is a digital Bible reading, listening and study platform, available as a web application, Progressive Web App (PWA) and mobile app for iOS and Android. The platform offers Bible reading, narrated audio, reading plans, personal notes, highlights, bookmarks, reading history, AI Chat, and the Guardians (Guardiões) supporter program.
Data Controller
Parmenes Information Technology Services LTDA
CNPJ (Brazilian tax ID): 37.638.493/0001-08
General email: [email protected]
Data Protection Officer (DPO): [email protected]
This Policy applies to all users of the platform regardless of country of access, and covers data processed in compliance with Brazil's General Data Protection Law (LGPD — Law 13,709/2018), the EU General Data Protection Regulation (GDPR — Regulation 2016/679), UK GDPR (UK-retained GDPR), the California Consumer Privacy Act / California Privacy Rights Act (CCPA/CPRA), Canada's Personal Information Protection and Electronic Documents Act (PIPEDA), and other applicable data protection laws.
2. Personal Data We Collect
2.1 Registration Data
- Full name or display name
- Email address (required for platform access)
- Phone number / WhatsApp (optional)
- City and country of residence (optional, self-declared)
- Profile photo or avatar (optional)
- Google account identifier (when logging in via OAuth 2.0)
- Password (stored exclusively as a bcrypt cryptographic hash — never in plain text)
2.2 Technical and Device Data
- IP address (partially anonymized after 90 days for analytics purposes)
- User-Agent: browser type, version, operating system and device model
- Access logs: timestamp, event, result (success / failure)
- Authentication logs: login attempts, token issuance and revocation
- PWA installation identifier (generated locally on the device, when applicable)
- Performance data and error reports (anonymized before storage)
- Cookies, localStorage and session identifiers
2.3 Usage and Behavioral Data
- Preferred language and time zone
- Biblical tradition and preferred version (translation)
- Chapters and books read, with access timestamps
- Platform browsing history
- Bookmarks: saved verses and chapters
- Highlights: verses marked with color and optional note
- Personal notes (Spiritual Notebook): title, content, tags
- Reading plans: active plan, progress and days completed
- Searches performed on the platform (text and voice)
- Accessibility settings: font size, theme
- AI feature interactions: questions sent to AI Chat, sessions created
2.4 Subscription and Payment Data
Complete card and banking data is processed exclusively by payment providers (Stripe and/or Mercado Pago). VoxDivina stores only:
- Customer identifier with the payment processor
- Subscription identifier and active plan
- Billing status (active, pending, cancelled, failed)
- Subscription start, renewal and end dates
- Transaction history: amount, currency, date and status per charge
- Payment method type (card / bank slip / PIX — no full number stored)
We never store full card numbers, CVV codes, complete banking details or PIX keys.
2.5 VoxDivina Guardians Program Data
Users who voluntarily join the Guardians program provide:
- Public name (displayed on the Guardians page)
- Country of origin (optional, displayed publicly when provided)
- Support message (optional, public)
- Financial contribution data (via Stripe / Mercado Pago)
- Date and amount of contribution
Public name and message are shown on the public Guardians page. You can edit or remove this information at any time from your Guardian profile.
2.6 Consent and Legal Audit Data
To comply with regulatory obligations (LGPD Art. 7, II; GDPR Art. 7; CCPA; PIPEDA), at the time of accepting our legal documents we record:
- User identifier (user_id)
- Exact date and time of acceptance (UTC)
- Version of accepted documents (Terms, Privacy, Cookies)
- IP address at time of acceptance
- User-Agent at time of acceptance
- Language displayed at time of acceptance
- Country detected via time zone / browser settings
- Recorded time zone
- Source of acceptance (web, PWA, mobile)
These records are retained for up to 5 years for proof and regulatory compliance, and are not used for any other purpose.
3. Authentication and Credential Protection
VoxDivina offers two authentication methods:
Email and Password Login
The password provided is transformed into a cryptographic hash using bcrypt with an appropriate cost factor before being stored. The original password text is never stored or transmitted. JWT access tokens are issued with limited validity and accompanied by refresh tokens with automatic rotation and logout revocation.
Google OAuth 2.0 Login
When the user chooses to sign in with Google, we receive only the account's unique identifier (sub), display name and associated email address. No Google password is transmitted to VoxDivina. The flow follows the OAuth 2.0 protocol with token verification via Google's Token Verification API.
We maintain authentication logs (timestamp, IP, result) for up to 2 years for security purposes. These logs are not used for personalization or marketing.
4. Artificial Intelligence and Content Processing
VoxDivina uses Artificial Intelligence technologies to provide:
- AI Chat: answers to questions about biblical texts, theology and spirituality
- AI Insights: contextual explanations of biblical passages
- Smart search: finding verses by intent and context
- Guided studies: AI-assisted thematic content (Premium and Elite plans)
Important notice about AI
AI feature interactions may be processed by specialized providers (such as OpenAI). Content submitted — your questions and the biblical text in context — may be transmitted to these providers to generate a response. Do not send sensitive personal information, financial data, passwords or confidential documents to AI Chat or any AI feature.
VoxDivina does not transmit personally identifiable data (name, email, national ID) to third-party AI APIs. Only interaction content is sent. AI providers maintain data processing agreements compatible with GDPR and CCPA. AI-generated responses may contain inaccuracies; VoxDivina does not guarantee the theological or doctrinal accuracy of automatically generated content.
5. Audio Generation and Streaming
VoxDivina offers biblical narration through voice synthesis. The system works as follows:
- Generation: biblical texts are converted to narrated audio by specialized providers (ElevenLabs and/or OpenAI Text-to-Speech)
- Storage: generated audio files are stored in a private cloud repository (Cloudflare R2) with access control via temporary token
- Streaming: audio is delivered via secure streaming with short-lived token authentication; files cannot be accessed without valid authentication
- Cache: frequently accessed audio files may be cached to improve delivery performance, without privacy impact
- Data transmitted to voice provider: only the biblical text to be narrated and voice parameters (voice, language, speed). No personally identifiable data is sent.
Daily audio limits vary by subscription plan. Usage is monitored for limit enforcement only and is not used for other purposes.
6. Payments and Billing
Payments are processed exclusively by PCI-DSS certified providers:
Stripe
Used for international payments via credit and debit card. Stripe processes and stores all complete financial data (PCI-DSS Level 1). VoxDivina receives only customer and subscription identifiers, plus event notifications via secure webhook (payment confirmed, failed, cancelled). Stripe maintains GDPR adequacy and SCCs with sub-processors.
Mercado Pago
Used for payments in Brazil via card, bank slip (boleto) and PIX. Mercado Pago is responsible for storing and processing all financial data. VoxDivina receives only payment confirmations and transaction identifiers via signature-validated secure webhook.
VoxDivina never stores full card numbers, CVV codes, complete banking data or PIX keys. Disputes and refunds are managed by the respective providers per their policies.
7. Communications and Notifications
VoxDivina may send communications through the following channels, according to registered preferences:
Transactional email: account verification, password recovery, subscription confirmation, renewal and expiry notices, security alerts. Legal basis: contract performance — no additional consent required.
Push notifications (browser / PWA): feature alerts and reading reminders. Require explicit browser permission and can be revoked at any time in device settings.
WhatsApp: payment, plan renewal and relevant feature notifications. Require explicit opt-in in account settings. Can be disabled at any time in Settings → Notifications.
SMS (via Sinch): sent for phone number verification, reminders and operational notifications. Require a registered and verified phone number. Can be disabled in account settings.
Critical security communications (e.g., suspicious login attempt) may be sent regardless of preferences, as they are necessary to protect your account.
8. Cookies and Tracking Technologies
We use cookies, localStorage, IndexedDB and similar technologies as detailed in our Cookie Policy. Main categories include: essential (required for operation), preferences, analytics and advertising (applicable to the free plan only).
You can manage your cookie preferences at any time in Settings → Privacy → Cookies or via the consent banner shown on first access.
9. Advertising — Google AdSense
Users of the Path Plan (free) may see advertisements displayed by Google AdSense. These ads are selected by Google based on:
- Content of the accessed page (contextual advertising)
- Browsing history and interest profile, per Google's policies, when the user consents to advertising cookies
You can manage Google ad personalization preferences at adssettings.google.com. Non-personalized ads can be shown even without advertising cookies.
10. Data Sharing with Third Parties
Your personal data is not sold to third parties. We share data only with the following operators and sub-processors, strictly to the extent necessary:
Google LLC
Sub-processorOAuth 2.0 authentication; AdSense advertising (free plan); usage analytics via Google Analytics (when user-enabled)
Privacy policy ↗Stripe, Inc.
Sub-processorInternational payment processing, subscription management and billing webhooks. PCI-DSS Level 1 certified.
Privacy policy ↗Mercado Pago S.A.C.P.
Sub-processorPayment processing in Brazil (card, bank slip, PIX) and local subscription management.
Privacy policy ↗Cloudflare, Inc.
Sub-processorGlobal CDN, DDoS protection, secure audio storage (Cloudflare R2), network proxy and web application security.
Privacy policy ↗OpenAI, L.L.C.
Sub-processorAI response generation for Chat AI and AI Insights; voice synthesis (Text-to-Speech). Only interaction content is transmitted, no personally identifiable data.
Privacy policy ↗ElevenLabs, Inc.
Sub-processorPremium narrated audio synthesis (neural voices for biblical narration). Only biblical text and voice parameters are transmitted.
Privacy policy ↗Sinch AB
Sub-processorSMS delivery for phone number verification, reminders and operational notifications.
Privacy policy ↗Infrastructure providers (hosting, database, transactional email)
Sub-processorsBackend infrastructure operation, database and transactional email delivery. All bound by adequate DPAs.
Competent authorities
Third partyWhen required by law, court order or applicable regulation, strictly to the extent necessary for compliance or protection of legal rights.
In the event of a merger, acquisition or asset sale, data may be transferred to the successor, with prior notice to users and maintenance of this Policy's protections.
11. Data Retention and Deletion
| Data Category | Retention Period |
|---|---|
| Registration and preferences data (active account) | While account is active |
| Registration data (deleted account) | Deleted within 30 calendar days of request, unless legally required |
| Security and authentication logs | Up to 2 years (security and incident investigation) |
| Payment and billing records | 5 to 10 years (applicable tax and accounting obligations) |
| Legal consent records | Up to 5 years (proof and regulatory compliance) |
| Guardian program data (contributions) | Up to 10 years (tax obligations); public name deleted on request |
| Audio access logs | Up to 90 days for operational purposes |
| Analytics data (after irreversible anonymization) | Indefinitely (no longer constitutes personal data) |
| SMS/WhatsApp consent data (opt-in) | Up to 5 years for proof purposes |
To request deletion of your data, email [email protected] with subject “Data Deletion”. We will respond within 15 business days (LGPD) or 30 calendar days (GDPR/UK GDPR).
12. Data Subject Rights
You have the following rights, exercisable under the law applicable to your country of residence:
Access
LGPD Art. 18, II · GDPR Art. 15 · UK GDPR · CCPA · PIPEDA
Obtain confirmation and a copy of the personal data we hold about you, including purposes, legal bases and recipients.
Rectification
LGPD Art. 18, III · GDPR Art. 16 · UK GDPR · PIPEDA
Correct inaccurate, incomplete or outdated data. Basic profile data can be updated directly in settings.
Erasure (Right to be Forgotten)
LGPD Art. 18, VI · GDPR Art. 17 · UK GDPR · CCPA
Request deletion of your personal data, except where retention is required by law (e.g., tax records, security logs, consent records).
Restriction of Processing
LGPD Art. 18, IV · GDPR Art. 18 · UK GDPR
Request temporary suspension of processing in certain circumstances, such as during accuracy contestation or processing objection.
Objection to Processing
LGPD Art. 18, IX · GDPR Art. 21 · UK GDPR
Object to processing based on legitimate interests or for direct marketing purposes. Processing will cease absent compelling legitimate grounds.
Withdrawal of Consent
LGPD Art. 18, IX · GDPR Art. 7(3) · UK GDPR · PIPEDA
Withdraw consent at any time without affecting the lawfulness of processing before withdrawal. Revocation can be done in account settings.
Anonymization
LGPD Art. 18, IV
Request anonymization of unnecessary, excessive or unlawfully processed data.
Information on Sharing
LGPD Art. 18, VII · CCPA · PIPEDA
Know which public and private entities your data is shared with and for what purposes.
Opt-out of Sale / Sharing (CCPA/CPRA)
CCPA § 1798.120 · CPRA
Opt out of having your personal data sold or shared with third parties for commercial purposes. VoxDivina does not sell personal data.
Non-Discrimination (CCPA)
CCPA § 1798.125
You will not be discriminated against for exercising your privacy rights.
Complaint to Supervisory Authority
LGPD Art. 18, § 4 · GDPR Art. 77 · UK GDPR · PIPEDA
File a complaint with the ANPD (Brazil), your EU member state supervisory authority, the ICO (UK), or the OPC (Canada).
To exercise any right: [email protected]
Response times: 15 business days (LGPD) · 30 calendar days (GDPR/UK GDPR) · 45 days (CCPA) · 30 days (PIPEDA)
13. International Data Transfers
Your data may be processed on servers located outside Brazil and/or the European Union, primarily in the United States and Europe. We ensure compliance with applicable laws through the following safeguards:
- Standard Contractual Clauses (SCCs): approved by the European Commission (Decision 2021/914), applied in contracts with sub-processors outside the EEA
- Data Processing Agreements (DPAs): signed with all sub-processors, requiring equivalent protection standards
- Adequacy assessments: analysis of the level of data protection in the destination country before transfer
- UK GDPR: transfers from the UK to third countries via International Data Transfer Agreements (IDTAs) when applicable
- LGPD Art. 33: international transfers based on ANPD adequacy decisions, specific contractual clauses or data subject consent
14. Information Security
We implement appropriate technical and organizational measures to protect your personal data:
- Encrypted transmission: HTTPS/TLS 1.2+ for all communications
- Passwords: stored with bcrypt hash and random per-password salt
- Tokens: JWT with limited validity, automatic refresh token rotation and logout revocation
- Access control (RBAC): role-based permissions for internal staff; principle of least privilege
- Monitoring: access logs, anomaly detection and security alerts
- Encryption at rest: sensitive data encrypted in the database
- API protection: rate limiting, input validation and OWASP Top 10 protection
- Periodic assessments: security testing and infrastructure configuration review
In the event of a security incident involving personal data, we will notify the ANPD pursuant to LGPD Art. 48 and inform affected users when the risk is significant. To report security vulnerabilities: [email protected]
15. Minors
VoxDivina is directed at users aged 13 and over. For users between 13 and 17, we recommend access with parental or legal guardian knowledge and supervision.
- Brazil (LGPD): children under 12 must not use the platform. Data from children under 12 identified will be deleted immediately.
- EU / UK (GDPR/UK GDPR): minors under 16 (or 13 in jurisdictions that adopted the reduced minimum age) require verifiable parental consent for consent-based data processing.
- USA (COPPA): we do not intentionally collect data from children under 13 residing in the US. If such a situation is identified, data will be deleted immediately.
- Canada (PIPEDA): in compliance with applicable provincial laws on minor privacy.
Parents or guardians who identify that a minor has provided data without authorization should contact [email protected] for immediate deletion.
16. Changes to This Policy
We may update this Policy periodically to reflect changes in our practices, legal requirements or the platform. Summary version history:
For significant changes, we will notify by email with at least 15 days' notice and display a highlight in the account dashboard for 30 days. A new acceptance confirmation may be required. Previous versions available on request to [email protected].
17. Contact, DPO and Supervisory Authorities
Parmenes Information Technology Services LTDA
- CNPJ: 37.638.493/0001-08
- General email: [email protected]
- Privacy / DPO: [email protected]
- Security: [email protected]
Supervisory authorities:
- Brazil (LGPD): ANPD — www.gov.br/anpd
- European Union (GDPR): supervisory authority of your EU member state of residence
- United Kingdom (UK GDPR): Information Commissioner's Office — ico.org.uk
- California, USA (CCPA/CPRA): California Privacy Protection Agency — cppa.ca.gov
- Canada (PIPEDA): Office of the Privacy Commissioner — www.priv.gc.ca