Last updated: 2026-07-20. This policy is written in English (the product language).
1. Who we are
Sacra Latina is a service provided by Nilable, a company registered with the Dutch Chamber of Commerce (KvK) under number 78608783.
Sacra Latina is a web application for studying Latin Scripture (the Vulgate with the Douay-Rheims English translation) with per-word grammar, a translation drill, a vocabulary browser, syntax charts, and spaced-repetition flashcards.
For questions about this policy or your data, contact us at support@sacralatina.com.
2. Data we collect
You can read Scripture and use most study tools without an account. We collect the following, depending on how you use the service:
Account data (if you register)
- Email address (for sign-in, verification, and transactional email)
- Password, stored as a bcrypt hash (we never see or store your actual password)
- Email verification status
- Two-factor authentication secret and recovery codes (if you enable 2FA)
- Reading preferences (text size, interlinear gloss, hide English), synced from your browser when you sign in
Study progress (if you register)
- Chapters you mark as read and translation drills you complete
- Your last reading position
- Flashcard scheduling data (which words you study, review dates, and review statistics)
Session data
- IP address and browser user agent, stored per sign-in session for security. You can view and revoke your active sessions from your account settings.
Annotation reports
- If you report an annotation error: the verse reference, the word in question, your note, and your email address (if you provide one, or from your account if signed in). Reports are stored in our database so we can review and fix the content. If you have an account, the report is linked to it; if you delete your account, the report stays but the link to you is removed.
Server logs
- IP address, user agent, and request metadata, kept briefly for security and abuse prevention.
Browser storage (no account needed)
- Reading preferences, practice selections, and tutorial state may be stored in your browser (localStorage). This data stays on your device unless you sign in, in which case preferences are synced to your account.
We do not sell personal data. We do not use your data for advertising. We do not build marketing profiles. Your personal data is not processed by any AI system.
3. How we use your data
- Service delivery: providing your account, saving your study progress, syncing preferences
- Communication: transactional email only (email verification, password reset). We do not send marketing email.
- Security: detecting and preventing unauthorized access and abuse
- Content quality: fixing grammar annotations based on your reports
4. Legal bases (GDPR / AVG)
- Contract: providing your account and the study features you request
- Legitimate interests: security logs, session records, and improving annotation quality from reports
- Consent: Holy Orders grant data (explicit consent under Article 9(2)(a), given by your email request), and anything else that would require it (we currently use no non-essential cookies or analytics)
5. Data storage, security, and transfers
- Your data is stored on DigitalOcean infrastructure.
- All traffic is transmitted over HTTPS/TLS.
- Passwords are stored as bcrypt hashes. Optional two-factor authentication is available on every account.
- Changing your password revokes all other active sessions.
- Some of our providers process data outside the EU/EEA. Where personal data leaves the EEA, transfers are safeguarded by the European Commission's Standard Contractual Clauses (SCCs) and, where applicable, the EU-U.S. Data Privacy Framework.
6. Third-party service providers
We use a small number of providers to operate the service. Each receives only the minimum data needed for its function.
| Service | Purpose | Data shared |
|---|---|---|
| DigitalOcean | Servers and database hosting | All service data |
| Cloudflare | DNS, content delivery, and protection against attacks | IP address and request metadata (as traffic passes through) |
| Postmark | Transactional email delivery | Email address, email content |
| Sentry | Error monitoring | Error reports, configured to exclude personal data where possible |
We use no analytics service and no advertising or tracking scripts. If that changes, this page will be updated first.
Emails we send load two fonts from Google Fonts for styling; if your email client loads remote content, Google receives a standard font request from your device. The web application itself makes no third-party requests.
7. Cookies and browser storage
We use only cookies that are strictly necessary for the service:
- Session cookie: keeps you signed in.
- Cloudflare security cookies: our infrastructure provider may set strictly necessary cookies to protect the site against attacks and bots.
We do not use analytics cookies, advertising cookies, or third-party tracking cookies, so no cookie banner is needed. Preferences and practice state may be kept in your browser's localStorage as described in section 2; you can clear it at any time through your browser.
8. Your rights (GDPR / AVG)
You have the right to:
- Access: request a copy of the personal data we hold about you
- Rectification: correct inaccurate personal data
- Erasure: request deletion of your personal data
- Restriction: ask us to limit how we process your data
- Portability: receive your data in a structured, machine-readable format
- Objection: object to processing based on legitimate interests
- Withdraw consent: at any time, for processing based on consent (such as Holy Orders grant data)
To exercise any of these rights, email support@sacralatina.com. We respond within four weeks. You may also lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) at autoriteitpersoonsgegevens.nl, or with your local supervisory authority.
9. Retention
- Account and study data: kept until your account is deleted.
- Sessions: until you sign out or revoke them; revoked sessions are removed.
- Annotation reports: until resolved, then a short archive for quality trends.
- Holy Orders grant data: deleted together with your account.
- Server logs: typically 30–90 days, unless needed for a security investigation.
10. Account deletion
To delete your account, email support@sacralatina.com from your account address (a self-serve option is planned). When your account is deleted, we permanently remove:
- Your account data (email, password hash, 2FA secret, and recovery codes)
- All sessions
- All study progress (completions, reading positions, and flashcard data)
- Any Holy Orders grant data (vocation, diocese, institution)
11. Children
The service is intended for users aged 16 and older. We do not knowingly collect personal data from children under 16. If you believe a child under 16 has created an account, contact us and we will delete it promptly.
12. Changes
We may update this policy from time to time; the "Last updated" date will change. For material changes affecting account holders, we will notify you by email or with a notice on the site.
13. Contact
Nilable
KvK: 78608783
Email: support@sacralatina.com