Privacy Notice
Last updated: September 29, 2026
Privacy is at the heart of Confession Compass. This notice explains, in plain language, what happens to what you share, why, and what your rights are. You can also read our Terms & Conditions.
1. Who we are
Confession Compass is run by RankRolo Limited (Reg. 78233372), a Hong Kong company with its registered office at 8/F, China Hong Kong Tower, 8-12 Hennessy Road, Wan Chai, Hong Kong (“we”, “us”). Our team works from our office in the European Union, at Manufakturu g. 20, Vilnius, Lithuania, which is also our contact point in the EU. We decide how and why your data is used, so we are its “controller” under data-protection laws such as the EU's GDPR, Brazil's LGPD and Hong Kong's Personal Data (Privacy) Ordinance.
For anything about your data, write to privacy@confessioncompass.com, or by post to our Vilnius office. This address also reaches our “encarregado”, the person responsible for data protection under Brazil's LGPD, whose name we give on request.
If the Service is ever transferred to another organisation, your data will go with it, and we will tell you in advance.
2. Our promise
Confession Compass is built around one simple promise: what you share here stays yours. Your situations, journeys, good deeds and conversations are private to you — no other user of the app can see them.
We do not sell your data, and we do not share it for advertising. Beyond the service providers that run the app for us (see “Service providers, locations and transfers”) and, if you subscribe, Stripe, which takes your payments (see “Payments”), we share it with no one unless the law requires us to. There are no advertising networks, analytics or trackers in the app.
3. What we collect
Account data: your email address (used for sign-in) and your name, if you give one or your Google account provides it; the date you joined; your interface language; your plan (Free or Premium) and, if you subscribe, the billing details described in “Payments”; and a record of the consents you gave (what you agreed to, which version, and when). Your password is handled by Firebase Authentication; we never see it. If you sign in with Google, Firebase Authentication also keeps the profile-picture link Google provides; we don't use it.
Content you enter: the situations you describe, the journeys and guidance generated from them, the steps you complete, your good deeds, your Companion conversations, your insights and — if you choose to join — your Community nickname, posts and replies, and the reports you file.
What you write may reveal your religious beliefs and other sensitive matters, such as your health, your sex life or things you have done. We process it only with your consent, and only to provide the Service to you, as this notice describes. You don't need to use names or details that identify you or anyone else, and we suggest you don't.
If what you write in a journey or to the Companion suggests you may be in danger, the app shows emergency and crisis lines. For a journey, this is recorded as a mark on the journey, so the lines keep being shown and the journey is never held back by the Free plan's daily limit. The mark stays with the journey, and administrators who open the journey can see it.
Technical data: your device's time zone, sent with each request so that “today” follows your own day, and not stored with your account. Our server logs record technical details such as internal identifiers, the part of the app used, timings and error types — never what you wrote, the prompts or the AI's answers — and are kept for 30 days. To protect accounts, Firebase Authentication records the IP address and browser type used to sign up and sign in, and keeps the IP addresses for a few weeks.
In your browser, the app stores only what it needs: your sign-in session (kept by Firebase Authentication), a note that someone is signed in on this browser (so the public pages know whether to load sign-in), your interface and journey languages, and whether Companion replies are read aloud. These are needed for the Service or remember choices you made, so we don't ask for cookie consent. There is no analytics, advertising or tracking, and no cookies or similar technologies for those purposes. Signing in with Google opens Google's own sign-in window, which runs under Google's terms.
4. Why we use your data, and our legal bases
To create and run your account, send you sign-in and security emails, give you the plan you have — taking your payments through Stripe if you subscribe — and answer your messages: because this is necessary to provide the Service you signed up for (GDPR Art. 6(1)(b); LGPD Art. 7, V).
To prepare your guidance, the Companion's replies, read-aloud, Catechism readings and insights, to show help lines when you may be in danger and, if you join, to show your Community posts to its members: with your consent, because what you write may reveal sensitive matters (GDPR Art. 9(2)(a); LGPD Art. 11, I). You give it when you create your account or sign in, by continuing after the notice on the sign-in page, and you can withdraw it at any time (see “Your rights”). The Service can't work without it, so withdrawing it ends your use of the Service, and we delete your account.
To keep the Service safe and working: fixing problems (including the administrators' logged access described in “Who can see what you share”), preventing abuse and enforcing daily limits, moderating the Community, and keeping our audit log and the records of your consent and of deletions. We do this because we have a legitimate interest in running a safe, reliable service and in being able to show that we handle data correctly (GDPR Art. 6(1)(f); LGPD Art. 7, IX); where it involves sensitive content, your consent covers it. You can object to it (see “Your rights”).
To comply with the law, and to establish, exercise or defend legal claims (GDPR Art. 6(1)(c) and (f) and Art. 9(2)(f); LGPD Art. 7, II and VI, and Art. 11, II, a and d).
You need an email address to have an account; everything else is up to you. Your name is optional, and what you share, and how much, is always your choice.
We make no decisions about you based solely on automated processing that have legal or similarly significant effects. The AI's guidance, the automatic danger check and the Premium insights (which look for recurring patterns across your journeys) are there to help you, and decide nothing about your account. An automatic filter also stops Community posts, replies and nicknames that contain contact details, links or certain harmful phrases, and tells you why so you can reword them.
5. Who can see what you share
Your journeys, good deeds and conversations are protected by access controls on our server: no other user of the app can read or change them.
A small number of authorised administrators may view records — a journey and its Companion conversation, for example — only to fix problems, and every view in our admin tools is logged. Administrators also grant Premium, moderate the Community and carry out account deletions, and each of these actions is logged too. Everyone with this access is bound by confidentiality.
Community posts are different by design: they are visible to Community members, but only under the nickname you choose, and never with your email, your name or your private journeys. If you leave the Community, your Community profile is deleted, but your posts and replies stay, under the nickname they were written with. You can delete your own posts at any time, even after leaving; your replies stay until a moderator removes them, you ask us to remove them at privacy@confessioncompass.com, or your account is deleted.
When you report a post or reply, our moderators see the reason you chose and a short excerpt of what you reported — never who filed the report.
6. How AI processing works
To prepare your guidance, the situation you describe is sent over an encrypted connection to Google's Gemini models on Google Cloud Vertex AI, together with instructions that shape a reverent answer, faithful to Church teaching. The same models write the Companion's replies, the Catechism reading summaries and, with Premium, insights across your journeys.
What you write here is private and confidential. Apart from our own small team, the only company that processes it is Google Cloud, acting as our data processor under a written contract (Google Cloud's Data Processing Addendum). That contract allows Google to use it solely to provide its services to us — including keeping them secure and free of abuse — and requires Google to keep it confidential and protected. (If you use the Companion's microphone, your browser's own speech service is also involved; see below.)
Google processes it to produce your answers and, under Google Cloud's terms, does not use it to train its models; we will never give Google permission to do so, and we do not train any AI models ourselves. Your journeys and conversations are never sold, never used for advertising profiles, and never shared with anyone else unless the law requires it.
Google's Gemini service can keep requests and answers in memory for up to 24 hours to answer faster. We have turned this cache off for Confession Compass, so what you write is not kept in it.
Google also runs automated safety checks on requests to its AI models. If these checks flag a request as a possible breach of Google's AI usage policies, Google may keep the text of that request — what you wrote, together with our instructions — for up to 90 days, in the United States, solely so that authorised Google staff can check whether a breach occurred. Google does not use it to train models. Because people bring difficult matters here, a request can occasionally be flagged even when nothing is wrong.
When you use read-aloud, the text being read — the prayer, a step, a part of your guidance or a Companion reply, never your own words — is sent to Google Cloud Text-to-Speech, which does not keep it. Text-to-Speech is a global Google service, so this text may be processed in any of Google's data centres. The audio is cached in Google Cloud Storage for about 30 days, so it doesn't have to be made again, and is then deleted automatically.
To check Scripture passages, our server looks up only the reference (for example “Luke 15:11-32”) on third-party Bible sites: bible-api.com and thedouayrheims.com. Your words are never sent to them, and no web search is ever made from what you write.
The Companion's microphone uses your browser's own speech recognition, which may send the audio to the browser's maker to turn it into text (Chrome, for example, sends it to Google). This happens under the browser maker's terms, not ours; if you prefer, type your message instead.
AI-generated guidance may contain errors. It is educational support, never a substitute for the Sacrament of Reconciliation, your priest, or professional help.
7. Service providers, locations and transfers
The app runs on Google services, which process your data on our behalf and only on our instructions: Google Cloud (Compute Engine for our servers, Cloud SQL for the database, Vertex AI, Text-to-Speech and Cloud Storage) and Firebase Authentication for sign-in and its emails, under Google Cloud's Data Processing Addendum and Firebase's data processing terms. Emails you send to our addresses are received on our own mail server, which runs on Google Cloud in the United States. Payments are handled by Stripe (see “Payments”).
Our servers, our database, the AI processing and the stored audio are in Google Cloud's us-central1 region, in Iowa, United States, and Firebase Authentication runs only in Google's US data centres. Our team, including the administrators, works from our office in Vilnius, Lithuania. So if you use the app from outside the United States, your data is transferred to the United States and processed there.
These transfers are protected as follows. We are established in the European Union, so the GDPR's transfer rules apply to all the data we send to the United States. Google LLC is certified under the EU–U.S. Data Privacy Framework and its UK and Swiss extensions, which the European Commission, the UK and Switzerland recognise as providing adequate protection; if that framework ever stops applying, Google Cloud's terms fall back on the European Commission's Standard Contractual Clauses and their UK and Swiss equivalents. For data from Brazil, Google Cloud's terms include the standard contractual clauses approved by the ANPD, and you also consent to the transfer — and to our team in Lithuania accessing your data — when you start using the app. Where the law of another country requires your consent to a transfer, you give it at the same step. You can ask us for a copy of these safeguards at privacy@confessioncompass.com.
8. Payments
If you subscribe to Premium, your payments are handled by Stripe: Stripe, Inc. and, in the European Economic Area, Stripe Payments Europe, Limited. You enter your payment details on Stripe's secure pages, which run under Stripe's own terms and privacy policy, cookies included; we never see your card number.
We give Stripe your email address and an internal identifier of your account. On its pages you give Stripe your name, your country (and, where needed, your postal code) and your payment method. From Stripe we keep only what we need to run your subscription: its Stripe identifiers, your plan and period, its status, and when it renews or ends. Stripe never receives what you write in the app.
Stripe processes this data to take your payments for us and, as an independent controller, for its own purposes, such as preventing fraud and meeting its legal duties. Its privacy policy (stripe.com/privacy) explains how, including where it transfers data and with what safeguards.
When your account is deleted, we cancel any subscription and delete your customer record at Stripe. Stripe keeps its records of your payments, which are also our accounting records, for as long as the law requires, for example under tax and anti-money-laundering rules.
9. Retention and deletion
We keep your account and content until you ask us to delete them. If you don't sign in for 24 months, we will email you, and delete your account with everything in it 30 days later unless you sign in again. An account whose owner never gave the consent needed to use the app is deleted after 30 days.
In the app, you can delete your good deeds and your own Community posts at any time. Everything else — your journeys and Companion conversations included — is deleted together with your account.
To delete your account, use “Withdraw my consent and delete my account” in your profile, or write to privacy@confessioncompass.com from the email address of your account. An administrator deletes it within 30 days, with everything in it: your sign-in, journeys, conversations, good deeds, insights, Community profile, posts and replies, the reports you filed, and the audio made for you. Any Premium subscription is cancelled, and your customer record at Stripe deleted (see “Payments”).
We keep the administrators' log entries about your account, including the record of its deletion, and the record of the consents you gave. They hold only internal identifiers, dates, versions and the language shown, never your email or anything you wrote.
Our database backups age out within 7 days, so deleted data is gone from them within 7 days as well. Google then removes deleted data from its own internal systems within the time its terms allow, at most 180 days; this includes Firebase Authentication's backups of your sign-in.
Read-aloud audio is deleted with your account, and in any case about 30 days after it was made.
Other time limits: a request flagged by Google's safety checks is kept for up to 90 days (see “How AI processing works”); our server logs are kept for 30 days; Firebase Authentication keeps sign-in IP addresses for a few weeks. A report you file is deleted with your account. A report about something you wrote, with a short excerpt of it, is kept for our moderators until your account is deleted.
10. Security
All traffic to and from the app is encrypted (TLS), and Google encrypts our database and the stored audio at rest. Access to records is enforced on our server, not only in the app; our database cannot be reached from the internet; and only a few administrators, bound by confidentiality, can view records, with every view in our admin tools logged. No system is perfectly secure, but we protect your data with care.
What you write is not end-to-end encrypted: the app has to read it to guide you, which is also why administrators can view it to fix problems (see “Who can see what you share”). Our logs never contain your words, the prompts or the AI's answers.
If a security breach puts your data at risk, we will tell you and the relevant data-protection authorities as quickly as the law requires.
We never see or store your card or other payment details: you enter them on Stripe's page, and Stripe holds them.
11. Your rights
You have the right to see your data and get a copy of it — also in a portable, machine-readable format — to have it corrected or deleted, to restrict how we use it, and to object to processing based on our legitimate interests. In the app you can see your data and change your name and interface language in your profile. On the Free plan, journeys from earlier days can't be opened in the app, but they are included when you ask for your data. For any request, write to privacy@confessioncompass.com from the email address of your account, so we know it is yours. It is free, and we answer within one month (15 days for requests under Brazilian law); if a request is complex, we may need up to two more months and will tell you why.
You can withdraw your consent at any time, as easily as you gave it: use “Withdraw my consent and delete my account” in your profile, or write to privacy@confessioncompass.com. From then on we stop using your journeys and conversations, and we delete your account within 30 days. Withdrawing doesn't affect what was done before.
If you think we have not handled your data properly, please tell us first at privacy@confessioncompass.com. You also have the right to complain to a data-protection authority. Because our EU office is in Lithuania, our lead authority is Lithuania's State Data Protection Inspectorate (Valstybinė duomenų apsaugos inspekcija, vdai.lrv.lt). You can also complain in the country where you live or work — for example to the AEPD in Spain, the CNPD in Portugal or the CNIL in France — and, outside the EU, to the ANPD in Brazil (gov.br/anpd), the ICO in the UK (ico.org.uk) or the Privacy Commissioner for Personal Data in Hong Kong (pcpd.org.hk).
12. If you live in Brazil, Hong Kong or the United States
If you are in Brazil, we process your data under the LGPD (Lei 13.709/2018). Your sensitive data is processed with your specific, highlighted consent (Art. 11, I), and its transfer abroad with your consent and the ANPD-approved standard clauses. Besides the rights above, you can ask us to confirm whether we process your data; to de-identify, block or delete data that is unnecessary or excessive; for information about the entities we share it with; and about what happens if you don't consent. You can reach our encarregado at privacy@confessioncompass.com; we give the encarregado's name on request. You can also petition the ANPD.
Under Hong Kong's Personal Data (Privacy) Ordinance, you can ask for access to, and correction of, your personal data by writing to privacy@confessioncompass.com or to our registered office in Hong Kong. We answer within 40 days at the latest, free of charge. We do not use your data for direct marketing.
If you are in the United States, we do not sell your personal information or share it for cross-context behavioural advertising, we do not use it to train large language models, and we use sensitive information (such as your religious beliefs or health) only to provide the Service you ask for, with your consent. Wherever you live, you can ask to know, correct, delete or get a copy of your data at privacy@confessioncompass.com. We answer within 45 days; if we decline a request, you can appeal by replying to our answer, and we will answer your appeal within 45 days.
Consumer health data. What you write may include health information, such as your mental or physical health, and the app may infer that you are in danger (see “What we collect”). We collect it only from you, and only to provide the Service you ask for: your guidance, Companion replies, read-aloud and insights, and the help lines. We share it only with Google Cloud, our processor, under contract, and we never sell it. You can see, get a copy of or delete it, or withdraw your consent, as described in “Your rights”, and ask us for a list of any third parties and affiliates with which we have shared it (there are none).
13. Children
Confession Compass is only for adults: you must be 18 or older to use it, and you confirm your age before you start. It is not directed to children, and we do not knowingly collect data from anyone under 18. If we learn that an account belongs to someone under 18, we delete it. If you believe a child has given us data, write to privacy@confessioncompass.com.
14. Changes to this notice
If we make material changes to this notice, we will tell you by email before they take effect, and the date at the top of this page will change. If a change affects how we use the sensitive data you consented to, we will ask for your consent again before it applies.
Questions about privacy can be sent to privacy@confessioncompass.com.