Skip to the policy
Zap do Jesus
Home PT

Transparency first

Privacy Policy

What stays on your device, what must be processed for the app to work, and which choices remain yours.

Effective and last updated: August 11, 2026

In this policy
Plain-language summary Controller Data on your device Data you send Service providers Purposes Retention Your rights International transfers Children Security Contact
Plain-language summary: conversation history, voice recordings, your preferred name, bookmarks, highlights, and preferences stay on your device. When you send a message, a limited window of recent conversation is transmitted to generate the reply. Our backend does not maintain a conversation history, but infrastructure and AI providers may process and retain data as explained below.

1. Who is responsible

Zap do Jesus is provided by C.M. Leal LTDA, operating under the Great Apps brand (“we,” “us,” or “our”). For privacy questions or requests concerning your data, email [email protected].

This policy covers the Zap do Jesus application for iOS and Android and the website at zapdojesus.com. It describes the current implementation of the product, which remains in development. If practices change before or after public release, we will update this page before applying those changes to users.

2. Data kept on your device

The app stores the following locally without creating a user account:

  • an optional preferred name;
  • message history and displayed transcripts;
  • voice-message files recorded in the app;
  • language, visual theme, and notification preferences;
  • Bible bookmarks, highlights, and recent passages;
  • a random installation identifier and local usage-limit information.

This data remains on the device until you delete it in the app, remove the app, or the operating system deletes it. “Clear conversation” removes the messages and associated audio files from that device. The app does not send Bible bookmarks, highlights, or your complete Bible-reading history to our server.

3. Data sent when you talk

When you send a text message, the app transmits the following over an encrypted connection:

  • the current message and a limited window of up to 20 recent messages to preserve context;
  • your preferred name, if you chose to provide one;
  • language, IANA timezone, and identifiers of recently shown Bible passages;
  • a random installation identifier used for message limits, security, and future subscription verification.

When you send a voice message, the M4A file is also transmitted for transcription. The audio is processed in memory by our service and is not written to Firestore or Cloud Storage. After transcription, the transcript follows the same processing path as a typed message.

Sensitive content: a conversation may reveal religious beliefs, health information, emotions, relationships, or other sensitive personal information. Send only what you are comfortable having processed. The app does not require your real name and should not be used to share another person's information without permission.

4. Service providers and what they process

Provider Purpose and data Relevant storage
Google Cloud
Cloud Run and Firestore, United States region
Runs our API, forwards requests to OpenAI, and keeps usage-limit metadata: installation identifier, first-use date, quota date, usage count, last access, and any future subscription state. Conversation content and audio are not written to Firestore or Cloud Storage. The infrastructure may keep technical logs such as time, status, IP address, and security information.
OpenAI
Replies and audio transcription
Processes recent context, the current message, optional name, and transcript to generate the reply. The audio file is sent to the transcription endpoint. We make response requests with store: false. Even so, OpenAI documentation states that abuse-monitoring logs may contain prompts and responses for up to 30 days by default. The audio-transcription endpoint is listed with no retention; the text transcript becomes part of the response request and follows the rule that applies to text.
Cloudflare
Hosting for this website
Delivers pages and images, protects the domain, and may process IP address, headers, request time, and security signals. This site uses no cookies, forms, advertising, or analytics scripts. Operational network logs follow Cloudflare's policy.

See provider policies and information: Google Cloud, OpenAI data controls, and Cloudflare.

OpenAI states that data sent to its API is not used to train or improve models unless the API account holder explicitly opts in to share that data. Provider rules may change; the current version appears at the link above.

5. Why we use this data

We process information only to:

  • generate replies, transcribe voice messages, and select verified Bible passages;
  • preserve enough context during the current conversation;
  • apply free-usage limits and, in the future, verify subscription entitlements;
  • protect the service against fraud, abuse, failures, and security risks;
  • comply with law and respond to valid requests.

Depending on applicable law, our legal bases may include performing the service you request, legitimate interests in security and abuse prevention, legal compliance, and your consent or affirmative action for optional features such as microphone and notifications. We do not sell personal data, use conversations for behavioral advertising, or turn private messages into marketing content.

6. How long data is kept

  • On your device: until you delete the data or remove the app.
  • On our backend: messages, replies, and audio files are not persisted as conversation history. They remain only while a request is being processed.
  • At OpenAI: prompts and responses may appear in abuse-monitoring logs for up to 30 days by default, unless longer storage is legally required or reasonably necessary to prevent harm. The provider lists audio transcription with no retention, but the text transcript follows the text-processing path.
  • Quota metadata: remains in Firestore while needed to operate limits, security, and access rights. A final production retention period will be defined and published before public release.
  • Technical logs: follow provider operating cycles and may be preserved longer when required by law or to investigate abuse and incidents.

7. Your choices and rights

You may decline to provide a name, avoid the microphone, leave notifications disabled, clear local conversation history, and uninstall the app. Depending on where you live, you may also request confirmation of processing, access, correction, information about sharing, anonymization, restriction, portability, or deletion, and withdraw consent where consent is the applicable legal basis.

Send requests to [email protected]. To locate technical metadata, we may need your installation identifier and enough information to avoid deleting somebody else's data. We may retain the minimum required for legal obligations, fraud prevention, or legal claims.

8. International processing

The current backend runs on Google Cloud infrastructure in the United States and uses OpenAI for replies and transcription. Data sent during a conversation may therefore be processed outside Brazil and your country of residence. We use encrypted connections, provider contracts, and other safeguards required by applicable law.

9. Children's privacy

Zap do Jesus is not designed for independent use by children under 13, and we do not knowingly seek their personal data. Guardians should supervise use by minors. If you believe a child submitted personal information without appropriate authorization, contact us so we can assess and delete identifiable information available to us.

10. Security and limits

We use encryption in transit, server-side secrets, request validation, and separation between local history and quota metadata. No system is invulnerable. Do not send passwords, complete financial information, identity documents, or third-party information that is unnecessary for a reply.

Zap do Jesus is not a medical, psychological, legal, financial, emergency, or crisis service. If you or someone else is in immediate danger, contact local emergency services and a person you trust.

11. This website

The website at zapdojesus.com is static. It uses no cookies, advertising pixels, forms, or analytics tools. Cloudflare may still process technical data needed to deliver and protect the site, as described in the provider table.

12. Changes and contact

We may update this policy to reflect changes in the app, law, or service providers. The date at the top shows the current version. When required, we will communicate material changes in the app or through another appropriate channel before they take effect.

C.M. Leal LTDA · Great Apps
[email protected]
zapdojesus.com

© 2026 C.M. Leal LTDA · Great Apps. All rights reserved.

Home Contact Português