Privacy Policy
Plain English first: CoptAra does not sell personal data, show ads, or use cross-site advertising trackers. An account is optional and is not needed for Kids or Luna. Divine history may sync when you sign in. Luna history stays on your device, and Luna does not keep a server transcript. You can delete your account and its associated content from your account page.
1. Who We Are
CoptAra is a Coptic Orthodox digital platform based in Texas, USA. Our website is coptara.org. “CoptAra,” “we,” “us,” and “our” mean the team operating that service.
2. Data We Collect
- Newsletter data: your email when you subscribe, plus the country and city derived from your IP at signup. The raw IP used for that lookup is not retained in the subscriber record.
- Account data: email, language, password hash, verification/reset records, sessions, and—if chosen—Google identity information. We never store your plaintext password.
- Divine chat data: messages, a random session identifier, and retrieved source passages needed to generate and contextualize a reply. The AI provider processes message content.
- Luna questions: the current question and up to six recent turns supplied by the child’s device are processed only to create the reply. CoptAra does not write Luna message content to a server transcript. Common direct identifiers are blocked from AI processing where our automated filter detects them.
- Synced Divine history: signed-in users may store conversations and messages so they can continue across devices. Luna does not use account sync.
- Device storage: the browser may save theme, language, font size, Bible bookmarks/progress, and local chat history using localStorage or IndexedDB. This remains on that device unless a signed-in adult deliberately imports eligible Divine history.
- Operational data: server/security logs may include IP address, browser type, requested page, time, and error information. Luna rate limiting temporarily stores an IP-based security key, not message content.
- Payment and subscription data: Creem, PayPal, or Ko-fi may provide name, email, amount, transaction/subscription identifiers, status, paid-through dates, refunds, reversals, and disputes. We store the expected offer, consent version, provider status, and payment facts needed to grant access and reconcile billing. We do not receive card or bank credentials.
We use only functional cookies: a secure sign-in session, a CSRF security token, a short-lived OAuth verifier during Google sign-in, a two-day local-date cookie so “today” follows your device calendar, and a random chat-quota cookie for up to 30 days after the chat counter is opened or a prompt is sent. The quota cookie contains an opaque signed value, not chat content or account details; the server stores only its one-way hash and daily counts. If you sign in, that day’s browser count is linked to the account count so the same allowance cannot be used twice. We do not use advertising or cross-site tracking cookies.
3. How We Use Data
- Provide AI replies, source evidence, and local or opted-in synced history
- Create, secure, and support adult accounts
- Send requested newsletter, account-security, and subscription-lifecycle email
- Operate, debug, protect, and improve the service
- Process support contributions and paid subscriptions, prevent duplicate charges, reconcile cancellations/refunds, and meet legal obligations
We do not sell personal data or use chat content for advertising. AI responses are automated service output, not decisions about employment, credit, housing, insurance, or legal rights.
4. Service Providers
- Cloudflare: DNS, delivery, DDoS protection, and transport security. Privacy policy
- OpenRouter and its selected model provider: AI inference for Divine and Luna. Luna requests require OpenRouter zero-data-retention routing and deny providers that collect prompts for training or other use. OpenRouter may retain request metadata such as model, token counts, and timestamps. Zero-data-retention documentation
- Google: optional Google account sign-in. Privacy policy
- InMotion Hosting: hosted SMTP delivery for newsletter and account-security email. Privacy policy
- ip-api.com: approximate country/city lookup at newsletter signup. Legal/privacy information
- Creem, PayPal, and Ko-fi: Creem is merchant of record for optional Individual subscriptions. PayPal and Ko-fi process optional support payments. Creem · PayPal · Ko-fi
Zelle support is bank-to-bank. The identifying information visible in the banking transaction may be available to us for reconciliation. We disclose data when legally required or necessary to protect users, CoptAra, or others.
5. Retention and Deletion
- Anonymous Divine context: deleted after 14 days without activity by a daily cleanup process.
- Luna content: no persistent server transcript is created. Processing copies exist only as needed to complete the request. Recent context and the finished reply remain on the device until cleared.
- Device history: remains until you clear it in CoptAra or your browser.
- Signed-in Divine history: retained until you delete the conversation or account.
- Account content: retained while the account is active. Account deletion removes email, credentials, identities, conversations, and account-associated content. A non-identifying shell may remain solely to preserve legally required financial record relationships.
- Security records: IP-based rate-limit records are pruned after 24 hours; expired OAuth and one-time tokens after one day; expired or revoked sessions after 30 days.
- Chat quota records: pseudonymous daily counts and request-idempotency records are retained for at least the 30-day cookie life and pruned after 31 days. They contain no prompt or answer text. Account deletion removes account counters and unlinks browser counters.
- Server logs: retained for up to 90 days for security and operations.
- Newsletter: retained until unsubscribe or deletion request.
- Payment records: offer/consent, transaction, cancellation, refund/reversal, and audit records are retained as required for accounting, tax, fraud, access reconciliation, and dispute handling. Account deletion removes direct account identifiers but may retain a non-identifying financial relationship shell.
- Payment-provider event payloads: a full signed Creem or PayPal event is held only while verification and reconciliation are pending, then scrubbed while its event ID, type, time, and cryptographic hash remain for audit. A failed event may be held for troubleshooting for up to 30 days after it becomes a dead letter, then its payload is scrubbed.
6. Your Choices and Rights
You may access, correct, export, object to processing of, or request deletion of personal data, subject to applicable law. To request a copy of server-held data linked to your account and verified email, email [email protected]; there is no self-service account download. We may verify your identity before releasing data. Allow up to 90 days for completion, unless applicable law requires an earlier response or notice. You can delete an account and associated content at Account deletion, delete individual synced conversations in Divine, clear device storage through CoptAra/browser controls, and unsubscribe through any newsletter email.
EU/EEA: depending on the activity, our bases are consent, performance of the service you request, legitimate interests in security and improvement, and legal obligations. You may also complain to your supervisory authority. California: we do not sell or share personal information for cross-context behavioral advertising.
7. Children and Luna
The Kids and Luna area offers child-friendly faith content without an account, advertising, account promotion, or account sync. Luna history is saved only on the device. Each question and up to six recent device-stored turns are sent through our server to the AI provider to create a reply, using zero-data-retention provider routing. We record aggregate token usage without message content, retain an IP-based rate-limit key for up to 24 hours for security, and keep the pseudonymous daily usage counter for the period described above.
Automated filters are designed to stop common direct identifiers before AI processing, but no filter is perfect. Children should not enter a name, email, phone number, social handle, school, street address, precise location, photograph, or other identifying detail. A parent can erase Luna history using “New conversation” or browser storage controls.
Accounts are for users age 13 or older. We do not knowingly create an account for a child under 13. Because Luna does not keep a server transcript, we ordinarily have no Luna conversation to retrieve or delete. A parent or guardian may still contact [email protected] with a privacy concern, and we will review and delete child information we hold when required.
8. Security and International Processing
We use reasonable technical and organizational safeguards, including hashed passwords/tokens, encrypted transport, access controls, and isolated data stores. No system is completely secure. Providers may process data in the United States or other locations under their own safeguards.
9. Changes
We may update this policy as features or law change. We will change the effective date and provide additional notice when appropriate.
10. Contact
Email privacy questions or requests to [email protected].