Home

Gracelio

Privacy Policy

Last updated: July 8, 2026

Gracelio ("we," "us," or "our") is a Christian daily companion app operated at gracelio.com and available as mobile applications on iOS and Android. Your prayers and journal are sacred. This policy explains, in plain language, what we collect, why, and the choices you have.

Information we collect

Account information. When you create an account we collect your email address, display name, and (optionally) profile picture. Authentication is handled by Supabase Auth.

Content you create. Prayer requests, journal entries, gratitude notes, habit check-ins, reading plan progress, reflections, and any content you write or record inside the app.

Church membership (optional). If you join a church community, we store your church affiliation to enable that feature.

Subscription information. Purchases are processed by Apple, Google, or RevenueCat. We receive entitlement status (active plan, trial end date, renewal date). We never see or store your card number.

Device & usage data. App version, device model, operating system, language, time zone, and anonymized product analytics (which screens you view, which features you use) to improve the experience.

Push notification identifiers. If you enable push notifications, OneSignal assigns a device identifier we associate with your account so we can send reminders you asked for.

Diagnostic data. If the app crashes, Sentry receives a technical stack trace, device model, and OS version so we can fix the bug. We strip personal content from these reports.

How we use your information

  • Provide the core Gracelio experience and sync across devices.
  • Deliver notifications you've opted into (morning walk, evening reflection, prayer reminders, etc.).
  • Process and manage your subscription and entitlements.
  • Generate AI reflections and study aids when you request them.
  • Improve the app through aggregated, anonymized analytics.
  • Prevent abuse, secure accounts, and comply with law.

Service providers we use

We rely on carefully chosen providers who process data on our behalf, under contract, and only for the purposes below:

  • Supabase — authentication, database, and secure storage of your account and content.
  • Cloudflare — website hosting, delivery, and DDoS protection.
  • RevenueCat — subscription management, entitlement state, and receipt validation with Apple and Google.
  • Apple App Store & Google Play — process in-app purchases and auto-renewing subscriptions.
  • OneSignal — delivery of push notifications you've enabled.
  • Sentry — crash and error reporting so we can fix bugs quickly.
  • OpenAI / Google (via Lovable AI Gateway) — generation of AI reflections, summaries, and coaching responses you request. Prompts are transmitted for real-time generation and are not used by these providers to train their public models.

AI-generated content

Some Gracelio features (reflections, coaching, summaries) use large language models. When you use these features, the prompt you submit is sent to our AI provider to generate a response. We do not use your prayers or journal entries for model training, and we contract for the same restriction with our providers.

AI responses are provided for spiritual encouragement only. They are not a substitute for pastoral counseling, medical care, legal advice, or professional mental-health support.

Prayers, journal entries, and sensitive content

Your journal and prayers are private to your account. Gracelio staff do not read them, and we do not share them with any third party except the infrastructure providers listed above (who store the data on our behalf and cannot use it for any other purpose). We never sell your content.

Analytics

We collect aggregated, anonymized product analytics (screen views, feature usage, retention). We do not use advertising SDKs and we do not sell analytics data.

Notifications

Push and email notifications are optional. You can enable or disable them at any time from Profile → Notification Preferences, or from your device's system settings.

Data retention

We keep your account and content for as long as your account is active. When you delete your account, we permanently remove your personal data from our production systems immediately (deletion requests sent by email are completed within 7 business days). Backup copies are purged on the ordinary backup rotation (up to 60 days). Anonymized, aggregated statistics that cannot identify you may be retained.

How to delete your account

You can permanently delete your account and associated data at any time from Profile → Delete Account inside the app, or by following the instructions on our account deletion page. You can also request deletion by emailing hello@gracelio.com.

Your rights

Depending on where you live, you may have the right to access, correct, export, or delete your personal information, and to object to or restrict certain processing. You can exercise these rights by using the in-app controls (Export Data, Delete Account) or by emailing us. We will not discriminate against you for exercising your rights.

Children's privacy

Gracelio is intended for users aged 13 and older (16+ in the EEA and UK). We do not knowingly collect personal information from children under these ages. If you believe a child has provided us information, contact us and we will delete it.

International transfers

Our providers may process data in the United States and other countries. Where required, we use appropriate safeguards such as Standard Contractual Clauses.

Security

Data is transmitted over HTTPS, stored encrypted at rest, and access is protected by row-level security policies. No system is perfectly secure — please use a strong, unique password.

Changes to this policy

We may update this policy from time to time. Material changes will be announced in-app or by email at least 14 days before they take effect.

Contact us

Questions or requests? Email hello@gracelio.com.