Policy
Privacy Policy
What personal data Gianna collects, why, how it's used, and the choices you have.
Updated 2026-09-01 · View resource
Last updated: 1 September 2026
This Privacy Policy explains what personal data Gianna collects, why, how we use it, and the choices you have. Gianna is a Catholic household assistant reached over Telegram and a web app at gianna.chat. By using the Service you agree to the handling of data described here.
We take a data-minimal approach: we collect what we need to run the assistant for your household, and nothing whose only purpose is to profile you.
1. Data we collect
Account data. Your email address and a securely hashed password. We never store your password in plain text.
Household data you give us. While using Gianna you may provide: your display name and the names of household members, your timezone, your schedule preferences (e.g. when the morning message is sent), your faith profile (such as which liturgical calendar you follow), parish details, intentions, and the tasks and reminders you ask Gianna to remember.
Messages. The content of your conversations with Gianna, including anything you choose to share in those messages, and the assistant's replies. Gianna's memory feature extracts and stores facts and entities from your messages so it can recall them later. These remembered facts are pooled into a single memory shared across your household, so Gianna may recall for one member something another member provided. This memory is not shared with other households.
Telegram identifier. If you use Gianna over Telegram, your chat id, which identifies your household.
Billing data. Subscription and trial status. Card payments are handled by our payment processor (Stripe); we do not store full card numbers.
Usage and analytics. Limited product-event data, such as account and trial events, which part of the app was opened, which controls were used, whether a message or scheduled note was sent, whether a tool succeeded, and the duration and cost of an assistant turn. These events contain identifiers, categories, counts, timings, and status values. They do not contain conversation text, tool arguments or results, contact details, or prayer intentions. In-app browser analytics run only if you agree. Browser autocapture, browser exception capture, and session recording are disabled. IP-based geolocation is disabled, and Gianna does not add IP addresses to analytics events. The public home page sends ephemeral, cookieless view and link events without creating a person profile or persistent browser identifier. Server analytics do not include household shape, number of children, religious calendar, routine type, tool names, or action names. Basic technical logs are also generated while running the Service. If the home page Feedback box is available and you choose to use it, the text you submit is sent to PostHog as a survey response.
You can allow or withdraw consent for signed-in browser analytics at any time under Settings → Data. Withdrawing consent stops that browser collection and clears PostHog's identifier and local storage from that browser. Limited, pseudonymous server events continue for service reliability, cost control, and product measurement; you may object to that processing by contacting us.
Source links. A printed QR code, sticker, or referral link may carry a short source label. We count visits to that link and, if you create an account, attach the first source label to your household so we can measure sign-ups, trials, and paid subscriptions from that source. This reporting does not store your IP address, a browser identifier, or conversation content.
Parish invitation conversations. Opening a parish invitation creates a pseudonymous account and records the invitation used, messages sent, and project outcomes such as a resource recommendation, sign-up, feedback response, or contact request. The visitor's IP address is used for a one-hour rate-limit window and held only in process memory. It is not written to the database or added to the project report.
Contact requests. Before asking for approval, Gianna stores a proposal with the chosen recipient and the exact details that would be shared. If you approve that proposal in a later message, Gianna records the time of consent and whether delivery succeeded. The stored proposal prevents the recipient or details from changing after you approve them. We do not include your conversation in the request.
2. Sensitive data and faith information
Information about your religious beliefs and practice is, by its nature, a special category of personal data. You provide it to us so that Gianna can serve its purpose as a Catholic household assistant. We process it on the basis of your explicit consent and use it only to deliver the features you have asked for. You can withdraw consent by deleting the relevant data or your account.
3. How we use your data
We use your data to:
- Operate the assistant — capture and recall tasks, send the morning message and weekly review, surface liturgical feasts, and answer your questions.
- Authenticate you and keep your account secure.
- Process your subscription, trial, and payments.
- Understand product usage and improve and maintain the Service.
- Communicate with you about the Service and respond to support requests.
- Send a contact request to the specific organisation contact you approve.
- Send occasional letters about Gianna — new features and seasons of the year — to existing customers, a few times a year at most. You can decline at signup, in your settings, or via the unsubscribe link in any letter; we keep a record of your choice and honour it immediately.
Signed-in browser analytics rely on your consent. We process the limited, pseudonymous server events described above for our legitimate interests in keeping Gianna reliable, controlling service costs, understanding whether the product works, and improving it. We keep those events narrow so that these interests do not override your privacy rights. You may object to this processing by contacting us.
We do not sell your personal data, and we do not use your private messages to train third-party models for purposes unrelated to serving you.
4. Third parties we share data with
We share data only with the service providers needed to run Gianna:
- OpenRouter — your messages and relevant context are sent to the configured model so the assistant can generate replies and features. Voice notes, if you send them, are sent to the configured speech-to-text provider.
- Telegram — to deliver and receive messages if you use that channel.
- Stripe — to process payments.
- Resend — to deliver email we send you (e.g. account emails).
- PostHog — for product analytics (hosted in the EU).
- Google — if you sign in with Google, Google handles that sign-in and we receive your email address.
- YouTube — if you choose to play a YouTube video inside Gianna, the standard YouTube player loads after a one-time notice. YouTube may use that viewing activity to personalise videos and advertising. You can withdraw this choice under Settings → Data. Opening a video directly on YouTube is governed by Google's own settings and policies.
- The Holy See's website (vatican.va) — when Gianna quotes the Catechism or another Church document, the passage is fetched directly from vatican.va. Only the page request is sent — never your message.
- A web-search provider (currently Exa) — when Gianna searches the web on your behalf, your search query is sent to retrieve results. Pages you ask Gianna to read are fetched directly from their hosts.
- An organisation contact you choose — if you explicitly approve a contact request, that person receives only the name, email address, phone number, and message fields you approved. They do not receive your conversation.
Each provider processes data under its own terms; we share only what is necessary for that provider's function.
5. Where your data is stored
Gianna's database and application are hosted on a server in the European Union. Some third-party providers listed above may process data in other regions under appropriate safeguards.
6. Retention
We keep your data for as long as your account is active. If your subscription lapses, your data is preserved so you can reactivate. Deleting your account removes that sign-in immediately. If another account remains in the household, the shared household data remains available to those account holders. Deleting the last account deletes the household's conversations, tasks, household details, and remembered facts from the live service immediately. Encrypted backup snapshots are retained for disaster recovery for up to twelve months and are not restored selectively into the live service. We retain billing records held by Stripe for as long as tax and accounting law requires, and server logs for no more than 30 days. Pseudonymous product analytics currently have no fixed automatic expiry in PostHog and may remain after account deletion. You can ask us to erase the analytics associated with your household. Contacting us before deleting your account allows us to identify them without PostHog receiving your email address.
If you start a conversation from a parish invitation card without creating an account, that pseudonymous invitation conversation (and anything Gianna remembered from it) is deleted after 90 days of inactivity. Creating an account keeps it. The organisation running the project receives activity totals and breakdowns by date and invitation. Its members cannot read the conversation or see the pseudonymous account identifier. Contact details are shared only through the contact request described above.
7. Your rights
Depending on where you live, you may have the right to access, correct, export, or delete your personal data, to object to or restrict certain processing, and to withdraw consent. To exercise any of these rights, contact us at the address below. You also have the right to complain to your local data protection authority.
8. Security
We protect your data with measures appropriate to its sensitivity, including hashed passwords (argon2), authenticated access (JWT), transport encryption (TLS), and sender-verified channel identities. No system is perfectly secure, but we work to keep your data safe and to limit what we collect in the first place.
9. Children
Gianna is intended for adults (18+) and is not directed at children; children cannot hold accounts or talk to Gianna. Parents may mention their children in conversation (names, birthdays, school runs) — that information is provided by and under the control of the parent, who can ask us to delete it at any time. We do not knowingly collect data from children directly. If you believe a child has provided us data, contact us and we will delete it.
9a. If something goes wrong
If a security incident affects your personal data, we will tell you without undue delay — what happened, what data was involved, and what we are doing about it — and we will notify the relevant supervisory authority within the timelines the law requires (72 hours under GDPR).
10. Changes to this policy
We may update this Privacy Policy from time to time. When we make material changes we will update the "Last updated" date and, where appropriate, notify you.
11. Contact
For privacy questions or to exercise your rights, contact hello@gianna.chat.