Privacy Policy — B.AI (Bíblia IA)
Last updated: August 24, 2026
Version: 2.1
1. Who we are
- Data controller: MR ROCCO INTERNET LTDA.
- Brazilian tax ID (CNPJ): 19.675.774/0001-40
- Headquarters: Av. Doutor Martin Luther King, nº 630, sala 51, Umuarama, Osasco/SP, Brazil — ZIP 06.030-003
- Data Protection Officer (DPO): Marcel Ricardo Rocco — dpo@bibliaai.app.br
This policy transparently explains what data the B.AI (Bíblia IA) app collects, why we collect it, whom we share it with and your rights as a data subject under Brazil's General Data Protection Law (LGPD — Law 13.709/2018) and, where applicable, the EU General Data Protection Regulation (GDPR — Reg. EU 2016/679).
If you do not agree with this policy, do not create an account or continue using the app.
2. One-line summary
To use the app you create an account (anonymous or with email / Google / Apple). What you chat with the AI, your Bible highlights, your notes and your progress are stored in your account so they sync across devices. We rely on Google services (infrastructure and the Gemini AI) to serve the experience. You can delete everything at any time by emailing the DPO above.
Your data is not used to train AI models — neither by us nor by the providers that process the content on our behalf (see section 5.3).
3. Data we collect
3.1 Account and authentication data
We create an anonymous account the first time you open the app (using Google's authentication service) so you can try the app without signing up. When you tap "Sign up" or "Sign in", you can link:
| Sign-in provider | Data received |
|---|---|
| Email + password | Email (required); password hashed by the authentication provider (never stored in plain text) |
| Display name, email, profile photo URL | |
| Apple | Name (optional), email (real or Apple's private relay) |
We also store a unique account identifier generated automatically.
3.2 Profile and preference data (onboarding)
During onboarding we ask you to pick:
- Age range (e.g. 25–34)
- Gender (male / female)
- Religious denomination (Catholic, Protestant, Non-Denominational, etc.)
- Preferred Bible version (NIV, NVI, KJV, etc.)
- Spiritual goals (e.g. study the Bible, share your faith)
- Content preferences (transformative devotional, divine inspiration, etc.)
- A free-text field about what is on your heart (optional)
These data are used solely to personalize the content the AI serves you (verses, devotionals, prayers).
Sensitive personal data (religious belief). Your denomination and preferred Bible version reveal religious belief and are therefore sensitive personal data (LGPD, Art. 5, II). We process them on the basis of your specific, highlighted consent (LGPD, Art. 11, I), given when you enter them during onboarding, and only to guide the AI toward content that is appropriate and respectful of your faith. They are never shared with Google AdMob or any ad network, and are not used for targeted advertising. You may withdraw this consent at any time (section 10); without it the app keeps working with non-personalized content.
3.3 Personal content you create
The app stores in your account:
- Conversations with the AI (messages sent and received in chat)
- Bible notes you write
- Favorite verses and highlights
- Journal answers (when you answer the reflective question in the daily plan)
- Daily mood score (0–100)
- History of AI-generated devotional plans
- Notes from sermons, talks and studies and the notes the AI produces from them (see section 5.4)
This content is tied to your account identifier and is not readable by other users.
3.4 Usage and analytics data
We collect, in a pseudonymized way (via Google Analytics):
- Usage events: screens visited, Bible reading (book, chapter), chat messages sent (count, not content), days completed in the plan, streak, interactions with AI assistants
- Session duration and open count
- Consent signals for analytics and advertising (Google Consent Mode)
The identifier used is an internal account pseudonym. We do not send your name, email, phone number or message content to Google.
3.5 Technical diagnostic data
Via Google's crash-reporting tool:
- Device information (model, OS, app version)
- Error reports (stack trace) when the app crashes
- Device identifier to associate the report with the user
3.6 Payment data
When you subscribe to VIP or purchase Talentos packs, the transaction is processed by RevenueCat (which brokers Apple App Store and Google Play). We only receive:
- Transaction ID
- Purchased product (e.g.
vip_annual,talentos_200) - Amount and currency
- Subscription status (active, expired, cancelled)
We do not receive, store or process credit card data. The entire financial flow is handled by the platforms (Apple or Google) and RevenueCat.
3.7 Advertising identifiers
If you are not a VIP subscriber, we show ads via Google Mobile Ads (AdMob). In that case we may collect:
- IDFA (iOS) — only if you allow it via *Settings → Privacy → Tracking* or on the App Tracking Transparency prompt inside the app. Without authorization, AdMob serves only non-personalized ads.
- Android Advertising ID (Android) — can be removed at *Settings → Google → Ads → Delete advertising ID*.
- SKAdNetwork (iOS) — Apple's protocol that delivers ad attribution without identifying the user.
3.8 Push notifications
We store your device's notification token to send daily devotional reminders (when you enable the feature in *Account → Daily reminder*). You can disable it at any time.
3.9 LGPD consent
We record in your profile: the date/time when you checked the consent box during onboarding and the version of the text shown to you.
4. How we use the data
| Purpose | Legal basis (LGPD Art. 7) |
|---|---|
| Create and maintain your account | Contract performance |
| Personalize devotionals, verses and AI answers | Consent |
| Sync your progress across devices | Contract performance |
| Process subscriptions and purchases | Contract performance |
| Send reminders you enabled | Consent |
| Analyze app usage (aggregated / pseudonymous) | Legitimate interest |
| Prevent fraud and abuse (app integrity check) | Legitimate interest |
| Show ads (non-subscribers only) | Consent (ATT) / Legitimate interest |
| Comply with legal or regulatory obligations | Legal obligation |
5. AI-generated content
The app uses Google AI models to deliver the personalized devotional experience. We want to be transparent about this:
5.1 What is sent to the AI providers
All AI processing happens on Google Cloud infrastructure, with the Gemini models:
- Chat with Bible assistants — processed on our servers with the Gemini model. When you send a message, the text is stored in your account and forwarded to Gemini to produce the answer. We do not send your name, email or account identifier to Gemini.
- 7-day devotional plans — generated on our servers with the Gemini model. We send your religious profile (denomination, Bible version, goals), age range and gender — no data that personally identifies you.
We may switch to a different Gemini model at any time for availability, cost or quality reasons, always within Google Cloud and under the same terms described in section 5.3.
- Google speech synthesis — the text of verses, devotionals and prayers is sent to Google Cloud to generate the spoken audio you hear in the app.
5.2 Model limitations
AI models can produce inaccurate, outdated or contextually inappropriate answers, especially on sensitive theological topics. Their answers are not a substitute for pastoral guidance by a human nor for professional advice (medical, legal, psychological).
5.3 Training usage
Under the Google Cloud terms for AI services, as of our last review on 2026-04-18, data sent to Gemini through these APIs is not used to train Google's models. This may change — the provider's policy in force on the date of the request will always apply.
5.4 Notes from sermons, talks and studies
The Notes feature turns a sermon, talk or Bible study into structured notes. There are four ways to create one, and what leaves your device differs in each:
- YouTube video — we send Gemini only the URL of the public video you picked; Google is the one that accesses the video to produce the notes. We neither download nor store the video. Video search inside the app uses Google's YouTube Data API.
- Live recording — speech is transcribed on your own device, by the operating system's speech recognition (Android/iOS). The audio is never sent to our servers: only the transcribed text leaves the device, so the AI can organise it. How the operating system handles the audio is governed by Apple's or Google's privacy policy, depending on your device.
- Audio file upload — the file is uploaded to Google Cloud storage, into an area restricted to your account, and processed by Gemini to produce the notes. The audio is deleted right after processing. If processing fails, the file stays temporarily so you can retry, and is deleted when you delete the note.
- Typed text — sent to Gemini only to organise and format the notes.
The resulting notes are stored in your account like the rest of your personal content (section 3.3), and are deleted when you delete the note or request account deletion.
Other people's content. A recording of a service or talk may contain other people's voices — the preacher, the speaker or people present — who are not users of the app. You are responsible for recording only where you are allowed to and for respecting the venue's rules and applicable law. We use that material for nothing beyond producing your notes: it is not used to train models (section 5.3), is not shared with other users and does not feed advertising.
6. Third-party sharing
We share data, pursuant to LGPD Art. 7, with:
| Third party | Purpose | Data shared | Location |
|---|---|---|---|
| Google LLC (Firebase / Google Cloud) | Authentication, database, analytics, crash reporting, notifications, integrity check, audio generation | Account identifier, email, account content, usage events, notification tokens, text for audio | USA |
| Google Cloud (Gemini AI) | Chat answers and devotional plan generation | Chat messages; religious, demographic profile and goals (no PII) | USA |
| YouTube Data API (Google LLC) | Sermon video search inside the Notes feature | Search term (no data identifying you) | USA |
| RevenueCat, Inc. | Subscription and purchase brokering | account identifier, transactions, subscription status | USA |
| Apple Inc. | Apple Sign-In and App Store authentication (IAP) | Name (optional), email/relay, purchase data | USA |
| Google Mobile Ads (AdMob) | Ad display to non-subscribers | Advertising identifiers (with ATT/consent), contextual data | USA |
We never sell personal data to third parties. Your sensitive data (denomination and Bible version) stays within Google Cloud, where the content is generated — it does not go to AdMob, RevenueCat or any other third party in the table above.
7. International data transfer
Your data is processed on Google Cloud servers in the United States. The transfer is covered by approved Standard Contractual Clauses and by the providers' adherence to recognized international frameworks (including the EU–U.S. Data Privacy Framework, where applicable).
8. Retention and deletion
| Data type | Retention period |
|---|---|
| Account and user content | For as long as the account exists |
| Crash reports | 90 days (default) |
| Analytics events (Google Analytics) | 14 months (default) |
| Purchase tax records | 5 years (Brazilian legal obligation) |
| Data after account deletion | Deleted or anonymized within 30 days |
You can delete your account inside the app, under *Account → Personal Information → Delete account*, without contacting us. If you prefer, or no longer have access to the app, email dpo@bibliaai.app.br. Either way, all your data will be removed from our databases and aggregated services, except what is required to meet legal obligations.
9. Security
We adopt technical and administrative measures to protect data:
- Encryption in transit (TLS 1.2+)
- Encryption at rest on Google Cloud servers
- App integrity verification that blocks requests from tampered builds
- Access rules restricting each user to their own data
- User identity validated on every server-side operation
- Internal access to data limited to the DPO and vendors under NDA
10. Your rights (LGPD Art. 18)
You can, at any time:
1. Confirm the existence of processing of your data 2. Access the data we hold about you 3. Correct incomplete, inaccurate or outdated data 4. Anonymize, block or delete unnecessary data or data processed non-compliantly 5. Port your data to another provider 6. Delete data processed on the basis of your consent 7. Know whom we share data with (section 6 of this document) 8. Be informed about the possibility of not consenting and its consequences 9. Withdraw consent at any time
How to exercise: email dpo@bibliaai.app.br with "Data Subject" in the subject line. We reply within 15 days.
11. Cookies and similar technologies
The app itself does not use cookies (it is a native app). It does, however, use device identifiers and advertising identifiers (IDFA / IDFV / AAID), which work similarly and are described in section 3.7.
12. Children and teens
The app is intended for users 13 years or older. We do not intentionally collect data from children below that age. If you identify that a child has provided data, please request deletion via the DPO email.
During onboarding we collect age range (optional — the lowest range offered is 13–17) and when that range is picked we adapt the tone of the content.
13. Changes to this policy
Changes take effect on the date of the next app update or via in-app notice when they are material. The "Last updated" date at the top of this page always reflects the version in force.
If changes require new consent (e.g. inclusion of a new purpose or sharing), we will ask for your acceptance before applying them.
14. Contact and complaints
- DPO: Marcel Ricardo Rocco
- Email: dpo@bibliaai.app.br
- Brazilian Data Protection Authority (ANPD): https://www.gov.br/anpd