Privacy Policy
1. Who We Are
Hagio (“we”, “us”, “our”) provides a spiritual guidance chat application grounded in the Catechism of the Catholic Church. This Privacy Policy explains how we collect, use, store, and protect your personal data when you use our website, mobile applications, and related services (collectively, the “Service”).
We are committed to protecting your privacy and processing your data in accordance with the General Data Protection Regulation (GDPR) and applicable data protection laws.
2. Data We Collect
Account data
When you create an account, we collect:
- Email address — for authentication and transactional communications
- Given name — for personalisation within the app
- Password — stored only as a cryptographic hash; we never store or see your plaintext password
- Language preference — to display the app in your chosen language
Conversation data
When you use the Service, we collect:
- Conversation content — messages you send and AI-generated responses, encrypted at rest (see Section 4)
- Usage data — token counts, credit balance, and usage counters (never conversation content)
Automatically collected data
- Error reports — via Sentry, to diagnose and fix issues
- Performance metrics — via Grafana Cloud, to monitor service reliability
- Analytics — via PostHog (EU), only with your consent and never including conversation content
Data we do not collect
We do not collect special category data under GDPR Article 9. We do not use analytics on conversation content. We do not log message plaintext at any stage of processing.
3. How We Use Your Data
| Purpose | Legal basis (GDPR Art. 6) |
|---|---|
| Providing the chat service and AI responses | Performance of contract — Art. 6(1)(b) |
| Account authentication and security | Performance of contract — Art. 6(1)(b) |
| Sending transactional emails (e.g. password reset) | Performance of contract — Art. 6(1)(b) |
| Error monitoring and debugging | Legitimate interest — Art. 6(1)(f) |
| Analytics (only with consent) | Consent — Art. 6(1)(a) |
| Legal compliance | Legal obligation — Art. 6(1)(c) |
4. Encryption & Security
Your conversations are encrypted at rest using AES-256-GCM with a unique encryption key generated for each user. Hagio manages that key so we can provide AI responses, search, and account recovery. We will never sell your conversations or use them for advertising, and we do not read them — with one exception that you control: content you explicitly choose to share with us through in-app feedback (see “Feedback you choose to share” below).
- Each message is encrypted with a fresh random nonce and includes a 128-bit authentication tag for integrity.
- Your personal Data Encryption Key (DEK) is wrapped by a Key Encryption Key (KEK) held in AWS Key Management Service (KMS). The plaintext DEK exists only transiently in server memory during your authenticated request — it is never cached, written to disk, or logged.
- All data in transit is protected by TLS 1.3. Mobile clients use certificate pinning.
- Database access is enforced by Row Level Security (RLS) — your data is only accessible to your authenticated session.
Important: Hagio is not end-to-end encrypted and is not zero-knowledge. Because your messages must be sent to an AI provider for inference, plaintext leaves your device. We are transparent about this tradeoff — see Section 5 below.
Feedback you choose to share
When you rate an assistant reply (👍 / 👎), we ask whether you want to share the conversation so our team can review it. If you opt in, we store the content you consent to disclose — either only the message you rated together with the message you sent just before it, or the entire conversation, exactly as you select — as plaintext alongside your rating, so a person on our team can read it to improve the Service. This is a deliberate, opt-in exception to the at-rest encryption described above: it applies only to the scope you pick, only when you submit feedback, and nothing is shared until you confirm. If you never submit chat feedback, your conversations remain encrypted and unread. Feedback you submit is deleted when you delete your account.
5. AI Provider Disclosure
Your messages are sent to our AI provider so it can generate responses. They are not used to train their models. This is covered by a Data Processing Agreement (DPA) with a documented no-training policy.
The AI provider keeps a copy of your messages for a short abuse-review period (typically about 30 days) and then deletes them. The concrete retention window is verified against the provider’s current DPA before each deployment.
6. Cookies & Similar Technologies
Essential (always active)
These are required for the Service to function and cannot be disabled:
- Session / authentication cookies — to keep you signed in
- Locale cookie (
NEXT_LOCALE) — to remember your language preference - Theme preference — stored in browser
localStorage, device-local only
Optional (consent required)
These are set only after you give consent:
- PostHog analytics (EU-hosted) — anonymous usage analytics to improve the Service
We do not set non-essential cookies before you consent. You can change your cookie preferences at any time from the Settings page.
7. Data Storage & Retention
Your data is stored in the European Union (Supabase EU region).
| Data category | Retention period |
|---|---|
| Conversation content | Until you delete the conversation or your account |
| Account data | Until you delete your account |
| Application logs | 30 days |
| Security events | 90 days |
| KMS audit logs | 1 year |
| Database backups (PITR) | 7 days |
8. Anonymous Users
Anonymous web storage is local and device-bound. If you use the Service without an account, your conversation history is stored only in your browser’s local storage and is never sent to our servers. Messages are still sent to the AI provider (covered by the same DPA) but leave no persistent trace in Hagio’s backend.
9. Sub-processors
We use the following sub-processors to deliver the Service:
| Sub-processor | Purpose | Location |
|---|---|---|
| Supabase | Hosting, database, auth, storage | EU |
| Fly.io | Backend compute | EU |
| Cloudflare | CDN, DNS | Global |
| AWS KMS | Encryption key management | EU |
| AI provider | AI inference (DPA, no-training) | Per DPA |
| Resend | Transactional email | US (EU DPA) |
| Sentry | Error tracking | US (EU DPA) |
| Grafana Cloud | Logs, metrics, traces | EU |
| PostHog | Analytics (consent-based) | EU |
10. Your Rights Under the GDPR
Under the GDPR, you have the right to:
- Access — request a copy of your personal data
- Rectification — correct inaccurate data
- Erasure — delete your data (“right to be forgotten”)
- Data portability — receive your data in a machine-readable format
- Objection — object to processing based on legitimate interest
- Withdraw consent — for optional processing (e.g. analytics), at any time
- Lodge a complaint — with your local data protection authority
Account deletion is available directly in the app under Settings → Delete account. This removes all your data, conversation history, encryption keys, and sessions permanently and atomically.
To exercise any other right, contact us at privacy@hagio.chat.
11. Children's Privacy
Hagio is not intended for children under 13. We require age confirmation at registration. If we learn that we have collected personal data from a child under 13, we will promptly delete the account and all associated data.
12. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes through the app or by email. The “Last updated” date at the top of this page reflects the most recent revision.
13. Contact
For privacy inquiries: privacy@hagio.chat
For security issues: security@hagio.chat
General enquiries: luis@hagio.chat