Privacy Policy
Last updated on August 9, 2026
This document is a draft, still under legal review. We publish it marked as such rather than presenting it as final — the date above shows the last revision.
This is a translation. The Portuguese version is the one that governs, since the platform and its data-protection obligations are Brazilian.
This policy explains how Alicerçar handles personal data on the platform — both of the people who use the system and of the people a church records in it.
Those are two different relationships, and the difference matters more than anything else in this document. For the congregation's data, the church decides. For your sign-in account, we do.
Who decides what
The church is the controller of the congregation's data. It decides what it records about its members and why. Alicerçar is the operator: we process that data on the church's instructions and never for purposes of our own.
Alicerçar is the controller of your sign-in account — your name, e-mail, password, sessions and preferences. That information exists so you can get into the system, and its purposes are ours.
Both relationships live in one product. If you are a member of a church and want to know what is recorded about you, your church answers; if the question is about your account, we do.
What the church records
The church chooses what to fill in. The platform offers fields for:
- name, date of birth and gender;
- e-mail, phone and home address;
- which building the person attends, and family relationships;
- membership of groups and ministries, and the position served;
- attendance at gatherings — who came, or simply how many.
None of it is required beyond a name. A church that records only names uses the platform perfectly well.
The platform also holds people a church knows without their being members — a visitor to a cell, a volunteer. Those records are deliberately thin.
What we hold about your account
Your name, e-mail, a hashed version of your password, the devices you have signed in on, and your language and theme preferences.
We never store your password in readable form, and we never send it by e-mail under any circumstances.
If you sign in with a Google account, we receive from Google only what identifies you — we have no access to your Google password or to anything else in that account.
Giving
The platform does not record giving yet. When it does, a rule already decided applies from the outset: how much a person gave is confidential, visible only to whoever the church designated as treasurer, and to the person themselves.
That holds against the church's own leadership. Neither an administrator, nor a pastor, nor the person who created the account sees what someone gave — and the fact that someone gives nothing is exactly as confidential as an amount.
What we use it for
To run the platform: keeping the church's records, authenticating who signs in, sending invitations and system messages, and keeping the service working.
We do not sell data, do not advertise with it, and do not train artificial-intelligence models on any congregation's records. Aggregate metrics about the product are ours; a congregation's data is not raw material.
We count each church's active members for billing. It is the only aggregate we derive for a purpose of our own, and it identifies nobody.
Who we share it with
With providers acting on our behalf, only as far as the service requires:
- Brevo — sending system e-mail (invitations, password resets);
- Google Places — suggesting addresses as someone types one, so the address is recorded consistently.
Where the platform is hosted, and where the data physically rests, is not yet settled in our infrastructure documentation. We would rather say so than publish a provider that may not be the right one — this is the document in which a guess is least acceptable. It will be corrected once decided.
Beyond that, we share only under legal order or at the church's own request.
Your rights
Brazilian data-protection law gives you the right to confirm that processing exists, to access your data, to correct it, to ask for anonymisation or deletion, to withdraw consent, and to obtain portability.
If you are a member of a church, exercise those rights with your church. It is the controller of those records and the party that can change them. Our duty is to give it the means to answer — and we do: any church can export its records at any time.
If the question is about your sign-in account, write to privacidade@alicercar.com.br. If you come to us about a congregational record, we will point you to your church rather than unilaterally change something we do not control.
How long we keep it
For as long as the church keeps its account. Billing never deletes records: stopping payment, cancelling, or exceeding a limit does not erase, hide or lock what a church has recorded.
We delete a church's records when the church asks, after a grace period that guards against accidental loss. The exact length of that grace period has not been fixed — it is an open decision, and we will not publish a number nobody has decided.
You can close your sign-in account at any time. That removes your access; it does not remove the records the church keeps about you as a member, which are the church's.
Children
The platform records children when a church records them — in families and in children's ministries. Those records are created and kept by the church, under its responsibility, and we do not give system access to minors.
Security
Encrypted traffic, hashed passwords, sessions revocable at any moment, and role-based access within each church — a cell leader does not see the whole congregation.
No system is immune to incidents. We do not yet have a formal breach-notification process with a defined timeline, and we record that here rather than imply an assurance we cannot evidence.
Changes to this policy
When something material changes we update the date at the top and tell churches with active accounts before the change takes effect.