Skip to content
LiturgyFlow
Home Sign in Contact
Privacy Policy Terms of Service Cookie Policy Refund Policy Copyright & IP Accessibility

Privacy Policy

Effective: 6 September 2026 · Controller: LiturgyFlow · Contact: privacy@liturgyflow.com

This Policy explains how LiturgyFlow (“we”, “us”) collects and uses personal data when you visit https://liturgyflow.com, create an account, request access, contact us, or use Mass media tools. It is designed to align with the Philippines Data Privacy Act of 2012 (RA 10173) and, where applicable, the EU/UK GDPR.

1. Who we are

LiturgyFlow operates LiturgyFlow, a parish Mass media generator (PowerPoint decks, posters, song planning helpers, and related tools). Our primary operating jurisdiction is the Republic of the Philippines.

2. Data we collect

Account & membership

  • Name, email address, password (hashed by our auth provider), parish/community name, role, membership status.
  • Optional profile image / parish logo you upload.
  • Invite tokens and team membership metadata.

Service usage

  • Mass dates, celebrant names, song selections, custom lyrics you enter, generation history, and practice-share metadata.
  • Support messages, access requests, and related correspondence.
  • Technical logs needed for security (IP address truncated/keyed for rate limits, user agent, timestamps, error logs).

Cookies & device storage

  • Necessary cookies/storage for sign-in, security, and practice-share unlock.
  • Optional preference and media-embed consent (see Cookie Policy).

Payment

If paid plans are offered, payment processors (not us) handle card data under their own policies. We receive limited billing status metadata only.

3. Legal bases (GDPR / DPA)

  • Contract — creating your account and providing the service you requested.
  • Legitimate interests — securing the service, preventing abuse, product improvement (balanced against your rights).
  • Consent — optional cookies/embeds, marketing emails (if any), and non-essential processing you opt into.
  • Legal obligation — responding to lawful requests and retaining records where required.

4. How we use data

  • Authenticate users and manage parish membership / invites.
  • Generate Mass media, choir practice links, and related outputs.
  • Respond to contact / access / privacy / copyright requests.
  • Enforce rate limits, detect abuse, and maintain platform integrity.
  • Send transactional emails (invites, password resets, membership notices).

We do not sell personal data.

5. Processors & third parties

We use reputable processors under contractual terms, which may include:

  • Supabase — authentication, database, file storage.
  • Render / hosting & Redis — application hosting, caching, rate limiting.
  • Email delivery (e.g. Brevo) — transactional messages.
  • AI image providers (OpenAI / Google Gemini when enabled) — prompts and generated images for posters you request.
  • Openverse / Creative Commons sources — optional Gospel background images with attribution.
  • YouTube / radio stream hosts — only when you play embeds and have consented to media cookies.
  • hCaptcha — bot protection on authentication where enabled.

These parties process data under their own privacy notices. International transfers may occur; we rely on appropriate safeguards (e.g. standard contractual clauses / provider terms).

6. Retention

  • Account data — while your account is active, then deleted or anonymized within a reasonable period after closure (unless longer retention is required).
  • Generated media — ephemeral on server disks; durable copies (if any) follow your storage settings and account lifecycle.
  • Practice shares — until expiry or revocation.
  • Security / rate-limit logs — short windows (days to weeks).
  • Contact messages — as needed to resolve requests, then archived or deleted.

7. Your rights

Subject to applicable law, you may request:

  • Access, correction, deletion, or portability of your personal data.
  • Restriction or objection to certain processing.
  • Withdrawal of consent (cookie settings or email preferences) without affecting prior lawful processing.
  • Complaint to your supervisory authority (e.g. Philippines National Privacy Commission, or an EU/UK DPA if GDPR applies).

Email privacy@liturgyflow.com with subject “Privacy request”. We may need to verify your identity.

8. Children

LiturgyFlow is intended for adult parish staff and volunteers. We do not knowingly collect personal data from children under 16 (or the digital-consent age in your country). Contact us to delete any such data.

9. Security

We use industry-standard measures (HTTPS, hashed passwords via our auth provider, access controls, rate limiting). No method of transmission or storage is 100% secure.

10. Changes

We may update this Policy. The “Effective” date above will change when we do. Material changes will be highlighted in-product or by email when appropriate.

Privacy Policy Terms of Service Cookie Policy Refund Policy Copyright & IP Accessibility

© 2026 LiturgyFlow. These pages are provided for transparency; they do not create a lawyer–client relationship. For advice specific to your parish or diocese, consult counsel.