PentecostalGPT

Privacy Policy

Last updated: 8/5/2026

Introduction

PentecostalGPT ("we", "our" or "the Service") is committed to protecting your privacy. This policy describes how we collect, use, and protect your personal data.

Data We Collect

Account Information

  • Name and email address
  • Profile picture (if you sign in with Google)
  • Account preferences (doctrine, family mode)

Usage Data

  • Conversations with the AI assistant
  • Usage statistics (number of messages, sessions)
  • Technical data (browser, device, IP address)

Payment Data

Payments are processed by our payment providers. We do not store full card details — only transaction references needed to manage your subscription.

How We Use Your Data

  • Provide and improve the service
  • Personalize experience based on your preferences
  • Manage your account and subscriptions
  • Communicate important service updates
  • Prevent abuse and ensure security

Data Sharing

We do not sell your personal data. We share data only with:

  • OpenAI: to process your AI requests
  • Payment providers: to handle card payments
  • Hosting providers: to host the service

Conversation Storage

Your conversations are stored to allow you to access your history. You can delete individual conversations or request complete deletion of your data by contacting us.

Data Retention Periods

We keep personal data only for as long as necessary for the purposes described above, in line with GDPR Art. 5(1)(e). Concretely:

  • Account data (email, name, locale, doctrine and minister preferences): kept for the entire life of the account, then deleted within 30 days after you close the account or after 24 months of complete inactivity (no sign-in, no API call).
  • Conversation history and AI message metadata: kept for the entire life of the account so you can resume past conversations. Deleted with the account, or sooner on your individual deletion requests.
  • Generated images and exported PDFs: kept while the account is active. You can delete them individually at any time.
  • Subscription and payment metadata (transaction IDs, last 4 digits of the card, plan history, refunds, invoices): kept for 10 years after the last transaction, as required by EU/Panamanian accounting and tax law. We never store full PAN, CVV or expiry — those stay with our payment processor.
  • Server access logs, error logs and security/audit logs: kept up to 12 months and then automatically rotated.
  • Inbound and outbound transactional emails (support exchanges, billing notices): kept up to 24 months for support traceability.
  • Encrypted database backups: kept for up to 30 days, after which the backup itself is deleted; data already deleted from the live database disappears from backups within this window.
  • Anonymous, aggregated analytics (Umami): retained indefinitely as it cannot be traced back to an individual.

After the retention period a record is either fully deleted or irreversibly anonymised. You can request earlier deletion at any time using the rights described in the next section.

Security

We implement industry-standard security measures to protect your data, including:

  • Encryption of data in transit (HTTPS/TLS)
  • Limited database access
  • Secure authentication
  • Access monitoring

Your Rights (GDPR)

You have the right to:

  • Access your personal data
  • Correct inaccurate data
  • Request deletion of your data
  • Export your data
  • Object to certain processing

To exercise these rights, contact us at legal@pentecostalgpt.com

US State Privacy Rights (CCPA/CPRA and similar)

If you are a resident of California or another US state with a similar law (Colorado, Connecticut, Virginia, etc.), you have additional rights:

  • Right to know what personal information we have and how it is used
  • Right to delete personal information we hold
  • Right to correct inaccurate personal information
  • Right to opt out of the "sale" or "sharing" of personal information for cross-context behavioral advertising (this includes our use of the Meta Pixel for retargeting)
  • Right not to receive discriminatory treatment for exercising any of these rights

Use the "Do Not Sell or Share My Personal Information" link in the footer (or turn off Marketing cookies in the cookie banner) to exercise the opt-out. We also honor the Global Privacy Control (Sec-GPC) browser signal as a binding opt-out. For other rights, contact legal@pentecostalgpt.com.

Children's Privacy

Our service is not directed to children under 13 (or the equivalent age in your jurisdiction). We do not knowingly collect personal information from minors and we do not knowingly build advertising audiences from minors' data. If you believe a minor has provided us with personal information, contact us and we will delete it.

Cookies and Tracking

We use essential cookies for site functionality, optional analytics (Umami), and optional advertising cookies (Meta Pixel + Conversions API for retargeting). The consent model varies by region — EU/EEA/UK visitors must opt in; US and other visitors can opt out at any time. Full details (categories, what we send, region-specific behavior, GPC) are in our Cookie Policy.

Cookie Policy

Changes to Privacy Policy

We may update this policy periodically. We will notify you of significant changes via email or site notice.

Data Controller & Contact

Data controller: RASCA STUDIOS CORP., RUC 155752294-2-2024 (DV 41), Calle 50, Torre Credicorp, Piso 31, Ciudad de Panamá, Panamá. For privacy questions, deletion or data export requests: legal@pentecostalgpt.com.