Privacy Policy

Effective [launch date] · Last updated 4 October 2026

Draft for legal review. Replace every [bracketed] item and have a Philippine data-privacy lawyer review this before launch.

The short version
  • Your prayer intentions, journal and notes are private unless you share them with a group.
  • Your examination of conscience never leaves your phone.
  • The apps you choose for Prayer Lock, and how you use them, stay on your phone. We never receive that list.
  • No ads, ever. We don't sell or rent your data, and we don't use advertising trackers.
  • You can download or delete your data at any time.

1. Who we are

Gracio ("we", "us") is operated by [Company legal name], [registered address], Philippines. We are the personal information controller for the Gracio apps on iOS and Android and for gracio.app. Our Data Protection Officer can be reached at [email protected].

This policy follows the Data Privacy Act of 2012 (Republic Act No. 10173), its Implementing Rules and Regulations, and issuances of the National Privacy Commission (NPC). Where they apply, we also respect the EU/UK GDPR and US state privacy laws for users abroad.

2. What we collect and why

InformationExamplesWhy we use it
AccountName (optional), mobile number or email, Sign in with Apple/Google identifier, profile photo (optional), language, time zoneCreate your account, sign you in, sync across devices, show the right local times
Prayer information (sensitive)Routines, prayer intentions, answered-prayer notes, Bible highlights, bookmarks and notes, novena and reading-plan progress, prayer sessions (date, length)Run the features you use and show your own history. Religious information is sensitive personal information under the Data Privacy Act; we process it only with your consent
Group contentMessages, 🙏 reactions, photos, PDFs, songs, events, RSVPs, live prayer participationDeliver group features to the members of that group
Prayer LockYour schedule, session length, number of apps locked, lock and unlock eventsBack up your settings and show your prayer history. The list of apps and your app-usage data are processed only on your device (Android Usage Access / iOS Screen Time) and never sent to us
Device & diagnosticsPush token, app version, OS version, crash reports, pseudonymous feature-usage eventsSend notifications you asked for, fix bugs, improve the app. You can turn analytics off in Me → Settings → Privacy
PurchasesSubscription product, status, trial and renewal datesGive you Gracio Plus. Payment details (card, GCash, Maya) are handled by Apple or Google; we never see them
SupportEmails and attachments you send usAnswer you

What we don't collect: contacts, precise location, advertising identifiers, or the content of other apps. An event's address is only what an organizer types in.

The examination of conscience is stored only on your device, is cleared after 24 hours or when you tap "Clear all", and is excluded from backups, analytics and crash reports.

3. Legal bases

4. Who we share it with

We don't sell or rent personal information. We share it only with:

Some providers process data outside the Philippines (for example in Singapore, the United States or the EU). We use contractual safeguards so your information keeps the protection the Data Privacy Act requires.

5. How long we keep it

6. Your rights

Under the Data Privacy Act you have the right to be informed, to access, to object, to erasure or blocking, to rectification, to data portability, to damages, and to file a complaint with the National Privacy Commission. In the app:

7. Children

You must be at least 13 to create a Gracio account (or older if your country requires it). Children can pray along on a parent's device, for example during a family Rosary. If you believe a child under 13 has an account, contact us and we will delete it.

8. Security

Data is encrypted in transit (TLS) and at rest. Access is limited by row-level security, so group content is readable only by its members. Staff access is restricted and logged. If a breach affects your information, we will notify you and the NPC as the law requires.

9. Changes

If we change this policy in a meaningful way, we'll tell you in the app before the change takes effect.

10. Contact

Data Protection Officer, [Company legal name], [address] · [email protected]