Privacy Policy

How Coptic Compass collects, uses, protects, and retains personal data.

1. Information We Collect

We collect the information needed to provide the feature you use. This may include your account name, email address, profile picture, learning data, contact-form name, inquiry and message, chosen mailing topics and locale, consent and withdrawal history, and technical email-delivery events such as acceptance, delay, bounce, unsubscribe, or complaint status.

2. Purposes and Legal Bases

We process account and learning data to provide and secure the service; contact messages to answer your request; and essential transactional email to complete actions you request. Where applicable, these activities rely on performing a contract or requested pre-contractual steps, our legitimate interests in operating and protecting the service, or legal obligations. We send optional lesson, publication, and project marketing updates only after your explicit consent.

3. Mailing Consent and Preferences

Contact-form mailing choices are optional, separate from sending a message, and unchecked by default. We use double opt-in: opening the emailed link only displays the requested topics, while pressing the confirmation button records consent. You can change or stop topics without an account by requesting a short-lived private link from the email-preferences page. Authenticated users can also use dashboard settings.

4. Service Providers and International Processing

Supabase provides database and authentication infrastructure, Resend provides email delivery and audience tooling, and Vercel hosts the application and may provide disclosed performance analytics. They process data for Coptic Compass under their service terms and safeguards. Data may be processed outside your country where these providers operate, subject to applicable transfer protections.

5. Delivery Events and Suppression

We process provider delivery events to diagnose failures, prevent repeated sends to invalid addresses, honor unsubscribes, and suppress marketing after hard bounces or spam complaints. We prefer delivery, bounce, complaint, and unsubscribe observability over open-rate optimization, and we do not use email open or click engagement data to silently expand consent or audience membership. Suppression records override ordinary topic settings and are kept as needed to respect the request and protect sending integrity.

6. Retention

Contact messages are normally retained for up to 24 months after the last relevant interaction unless a longer period is needed for an ongoing matter or legal obligation. Active mailing preferences are retained while used; consent and withdrawal evidence may be retained for up to five years after the last change to demonstrate compliance. Detailed delivery-event payloads are normally retained for up to 90 days, while minimal suppression records may be retained longer so we do not resume unwanted mail. Account data is retained until deletion, subject to required legal or security records.

7. Security and Data Sharing

We apply access controls, row-level database policies, hashed action tokens, rate limits, and encrypted transport. No system is completely risk-free. We do not sell or rent personal data and do not share it with external advertisers.

8. Your Choices and Rights

Depending on applicable law, you may request access, correction, deletion, restriction, portability, or object to processing, and you may complain to your data-protection authority. You may withdraw mailing consent at any time through the no-account email-preferences flow or by contacting Coptic Compass; withdrawal does not affect earlier lawful processing. You may also request account deletion through the contact page.

9. Cookies and Contact

Cookies and local browser storage are described in our Cookie Policy. For privacy questions or requests, contact Coptic Compass through the contact page.