How OwLira collects, uses, and protects your data.
Last updated:
OwLira ("we") respects the privacy of readers, guardians, educators, and partners. This policy explains how we process personal data in compliance with the GDPR (EU 2016/679), LGPD (Brazil Law 13.709/2018), and COPPA for children.
OwlyHero app (Bible Heroes)
The OwlyHero app is managed by a responsible adult. The account is created by the adult with name, email, and password — or Google/Apple sign-in.
Child profiles are optional and created by the adult, containing only a first name, age, and an illustrated avatar. We do not collect a child's email, phone, photo, voice, or location.
To personalize the experience, we store reading and listening progress per profile (current chapter, audio position, completion).
Device technical data: a notification token (Firebase Cloud Messaging) for optional alerts and crash reports (Crashlytics) to keep the app stable.
Subscriptions are processed by the store (Google Play / App Store) and RevenueCat; we do not store credit card data.
The app shows no ads and does not perform advertising tracking of children.
The adult can edit or delete profiles and delete the account at any time, in the app or by emailing contact@owlira.com.
OwlyHero account on owlira.com
The portal lets you sign in with the same account as the OwlyHero app, using email and password, Google sign-in, or Sign in with Apple. It is a single account: if you already use the app you sign in with the same credentials, and an account created on the portal also works in the app. The account area is intended for adults.
Account data processed on the portal: the internal account identifier, the email address, and the linked sign-in providers (for example, password, Google, or Apple). Authentication is handled by Firebase Authentication (Google); OwLira never receives or stores your password. With Google sign-in, Google shares basic profile data with Firebase Authentication according to its consent screen, and the portal only uses the email address and the account identifier.
Sign in with Apple: Apple confirms your identity and shares an account identifier with Firebase Authentication and, depending on your choice on Apple's screen, your email address and name. If you choose "Hide My Email", Apple provides a private relay address (ending in @privaterelay.appleid.com) that forwards messages to your real email; in that case this address becomes the account email, and an account created this way is separate from any existing account under your real email. The portal only uses the email address and the account identifier. Apple's processing is governed by Apple's Privacy Policy (https://www.apple.com/legal/privacy/).
Subscription status: the portal reads, and never changes, the status of the subscription purchased in the app (whether it is active, the plan, the expiry date, and the originating store, Google Play or App Store), as reported to the app by the stores and RevenueCat. This status is used to unlock the materials included in the subscription and to show it in the account area. The portal does not sell subscriptions, offers no checkout, and processes no payment data; purchases, cancellations, and refunds happen in the store.
Download history: when you download a supplementary material while signed in, we record on your account the book, the language, the material, how many times it was downloaded, and the dates of the first and last download. The history is shown in the account area so you can find your materials again; it is not used for advertising or shared with third parties.
Session storage: to keep you signed in, Firebase Authentication stores session tokens in your browser's local storage (IndexedDB or localStorage), and the portal sets an "owlira-sessao" flag in localStorage so the sign-in code only loads on public pages for people who have signed in before. A summary of the account (identifier, email address, sign-in providers, subscription status, and recent downloads) is kept in sessionStorage and only reused for up to 5 minutes to avoid repeated requests; it is deleted when you sign out or close the tab. When you tap "Sign out", the session, the flag, and the summary are removed from this browser.
Security and abuse prevention: sign-in and account requests are protected by Firebase App Check with Google reCAPTCHA Enterprise, which evaluates technical signals from the browser, the device, and the interaction (such as IP address and browser characteristics) to tell people from bots and may set Google's own cookies. This processing is also governed by Google's Privacy Policy (https://policies.google.com/privacy). We also apply request limits per IP address and per account.
Legal basis: performance of a contract (GDPR art. 6(1)(b) / LGPD art. 7, V) for sign-in, the subscription check, unlocking materials, and the download history, which are part of the service you request when using the account; legitimate interest (GDPR art. 6(1)(f) / LGPD art. 7, IX) for security, App Check, and request limits. Session and App Check storage is strictly necessary for the service you request and therefore does not depend on the consent banner.
Retention: account data, subscription status, and download history are kept while the account exists and are deleted automatically when the account is deleted. Session storage in the browser lasts until you sign out or clear your browser data.
How to delete: signing out on the portal ends the session in this browser but does not delete the account. To delete the account and all associated data, including the portal download history, use "Delete account" under Profile → Settings in the OwlyHero app or follow the instructions at https://owlira.com/owlyhero/delete-account. Deleting the account does not cancel the store subscription: cancel it first in Google Play or the App Store.
1. Data we collect
We collect only the minimum required to operate the portal and respond to requests:
Email and name when you subscribe to the newsletter, request catechesis samples, or submit a partnership form.
Institutional contact data (school, parish, role, country) in B2B forms.
Technical browsing data via Google Analytics 4 (page view, referrer, country, device and a browser identifier stored in a cookie) when you consent to analytics.
Anonymous error telemetry via Sentry to keep the portal stable.
In the account area (optional): email address, sign-in providers, app subscription status, and material download history, detailed in the "OwlyHero account on owlira.com" section.
2. Processing purposes
Send requested communications (newsletter, samples, form replies).
Process commercial leads for partners, schools, and parishes.
Improve content and experience based on aggregated metrics.
Authenticate your OwlyHero account on the portal, unlock materials according to the subscription status, and keep the download history.
Protect sign-in and the account area against bots, fraud, and abuse.
Comply with legal, regulatory, and contractual obligations.
3. Legal basis (GDPR art. 6 / LGPD art. 7)
Explicit consent for newsletters and marketing.
Contract execution or pre-contract steps for B2B leads you initiated.
Performance of a contract for sign-in, the subscription check, and the download history of the OwlyHero account on the portal.
Legitimate interest for fraud prevention, security (including Firebase App Check with reCAPTCHA Enterprise and request limits), and aggregated analytics without personal identification.
Legal obligation when required by a competent authority.
4. Your rights
You may exercise the following rights under GDPR and LGPD at any time:
Access to the data we hold about you.
Rectification of incomplete or inaccurate data.
Anonymisation, blocking, or deletion of unnecessary data.
Portability of data to another provider.
Withdrawal of consent and deletion of data processed on that basis.
Information about how data is shared and used.
In the portal account area you can check at any time the email address, subscription status, and recent downloads linked to your account.
To exercise any right, email contact@owlira.com. We respond within 15 business days.
5. Data sharing
We do not sell personal data. We only share with essential processors bound by protection agreements:
Resend or Brevo for transactional email.
Google Cloud / Firebase for hosting and storage.
Google (Firebase Authentication, Firebase App Check, and reCAPTCHA Enterprise) for sign-in and abuse protection in the account area.
Apple (Sign in with Apple), only when you choose to sign in with Apple, to confirm your identity.
The subscription status reaches the app from the stores (Google Play / App Store) and RevenueCat; the portal only reads it and sends no data to them.
Sentry for error monitoring.
Google (Google Analytics 4), only with analytics consent, for portal usage metrics.
6. Retention
Newsletter email: until you request unsubscription.
B2B leads: up to 24 months after the last contact unless a contract requires longer.
Technical logs: 6 months, encrypted at rest and in transit.
Generic contact data: 12 months after reply.
OwlyHero account, subscription status, and download history: while the account exists; deleted together with the account.
Sign-in session in the browser: until you sign out or clear your browser data.
7. International transfers
We run on Google Cloud / Firebase. Cloud Functions execute in the southamerica-east1 region (São Paulo, Brazil); sub-systems may process data in EU or US datacenters.
Cross-border transfers follow the GDPR Standard Contractual Clauses and LGPD art. 33 safeguards.
8. Children and COPPA
All portal forms are intended for adult guardians.
In the OwlyHero app, the only child-related data (first name and age) is provided and managed by the responsible adult, with parental consent, and can be deleted at any time. We do not collect a child's contact data, photo, voice, or location.
We do not knowingly collect other personal data from children under 13. If you spot misuse, email contact@owlira.com and we will remove the data within 48 hours.
9. Security
We use TLS on every connection, Firebase Secrets for encrypted credentials, HSTS, CSP, X-Content-Type-Options headers, and least-privilege access in Cloud Functions.
In the account area, every request requires a valid session token verified on the server, and the browser never reads the database directly.