Privacy policy
Last updated: 29 September 2026
Who is responsible
Rafael is responsible for Appentecost and for handling privacy requests at r.ji@outlook.com. Appentecost is a free, voluntary, independent project. It does not represent, and is not institutionally affiliated with, the Seventh-day Adventist Church (IASD).
This policy covers the Appentecost website and its Android and iOS apps. The mobile apps are intended for listeners; administration and broadcasting are intended for the web browser.
Listening and connection records
You can listen without an account. The listener experience does not request access to your microphone, camera, contacts or device location. Receiving translated audio does not send your voice to us.
When you join a broadcast, we use a randomly generated browser identifier in a cookie called appentecostes_listener. It is valid for 365 days from creation and helps prevent duplicate connections and manage available places. It is not your name or email, but it is a persistent, pseudonymous identifier.
We store participation records that include this identifier, the selected church and language, the broadcast and connection identifiers, connection status and timestamps. These records support access control, capacity management and reliable delivery. Choosing a church is not a statement of your religious beliefs.
Optional feedback
If you rate a translation, we store your rating from 1 to 5, any optional comment of up to 500 characters, the broadcast, language, a derived listener identifier and submission dates. Authorized operators of that church can read the feedback to review translation quality and suggestions.
Feedback is pseudonymous, not guaranteed to be anonymous: it can be related to participation records. Please avoid including sensitive information about yourself or other people in comments.
Providers and technical data
Vercel hosts the website and APIs. Google Firebase stores application records and provides authentication for administrators. LiveKit delivers translated audio, captions and connection information. These services process the data needed to provide their functions and may keep technical or security logs, including network and device information.
Cloudflare Turnstile helps distinguish people from automated traffic. The verification uses a challenge token and your IP address; Cloudflare also processes browser and connection signals. Its policy describes processing both to protect this service and to improve bot detection.
Provider processing, storage locations and retention depend on the service and its configuration. Data may be processed outside your country. The provider policies linked below explain their practices; we do not promise that all provider data is immediately deleted when a connection ends.
Administrators and the source audio
The separate browser administration uses Google sign-in. It processes the administrator’s account identifier, verified email, name and profile-photo URL when available, church roles, invitations and access dates. An application session cookie lasts up to seven days. Resend is used to deliver administrative invitation emails when configured.
When an operator starts translation, the source audio is sent to OpenAI for processing. The translated audio and captions are distributed through LiveKit. OpenAI also receives an operational safety identifier associated with the operator, church and language. This is the operator’s audio source, not the listener’s microphone. The broadcasting community is responsible for the content and the authorization to transmit it.
An operator may use YouTube as a source in the web browser, where YouTube’s privacy practices apply. The listener experience receives translated audio and captions and does not display an embedded YouTube player.
Retention and your choices
The 365-day listener cookie and seven-day administrative session are local validity periods. They are not deletion schedules for server records. Participation, feedback and administrative records currently have no automatic deletion deadline configured by Appentecost. Provider logs and backups follow the providers’ applicable retention practices.
You may ask Rafael for access, correction or deletion of your data by emailing r.ji@outlook.com. Requests are reviewed manually. Tell us which feature you used and, if relevant, the church, language and approximate date. We may need additional information to locate the records and confirm that they relate to you; please do not send passwords or access tokens.
We will explain any limitation that prevents us from identifying or deleting a record, including information that must be retained. Clearing cookies, signing out or uninstalling the app does not automatically delete information already stored on servers. You may also exercise the privacy rights available under the law applicable to you and contact the relevant data-protection authority.
Contact and changes
For privacy questions or a data request, contact Rafael at r.ji@outlook.com. The support page also explains how to report technical or content problems. We will update this page and its date when this policy changes.
