Essential cookies
These keep the site, secure sign-in and your cookie choice working properly.
This page explains which data we process on the website and in the mobile app, why we process it and how we protect it.
Sveta Misa processes only the minimum data needed to run the website and mobile app, handle forms, provide support and review editing or new church requests. That includes the data you actively submit, basic server logs needed for security and the cookie preference needed so we remember your privacy choices.
Analytics on this website are first-party only. We do not rely on Google Analytics for public traffic reporting. When you explicitly allow analytics cookies, the website stores a pseudonymous visitor identifier on your device and sends pageview events to our own backend so administrators can see daily and monthly traffic trends. The identifier is hashed before storage in our database and routes are stored without search query parameters.
If you reject analytics cookies, the website continues to work with essential cookies only. Authentication cookies may still be required when you sign in to the administration area, because they are necessary for a secure session. If you send an email or form request, we process the details you provide in order to respond, review the request and maintain the public directory.
For questions about privacy, cookies or data corrections, contact info@sveta-misa.org.
When you contact support through the mobile app, all active Sveta Misa superadmins can see the shared conversation together with the name and email address on your account, your favorite churches and the churches you administer. We show this information only so the support team can understand the request and help you.
Message bodies are protected at rest with AES-256-GCM encryption and in transit with TLS. The support chat is not end-to-end encrypted because every active superadmin must be able to read and answer conversations from the shared support inbox. Email and push notifications never contain the message body.
When realtime support-chat updates are enabled, Firebase Realtime Database is used only to send a minimal invalidation signal telling the app that encrypted conversation data should be refreshed from our backend. Google/Firebase receives only an opaque HMAC-derived channel path, a random signal identifier, the time the signal changed and standard technical connection metadata. Firebase never receives an event type, conversation or message identifier, message body, email address, name, favorite churches or the churches you administer.
Our SQL backend remains the source of truth for every support conversation, and message bodies remain protected there with AES-256-GCM encryption. If Firebase is unavailable or realtime updates are disabled, the app falls back to periodically checking our backend for new messages.
Closed support conversations are deleted after 12 months. Your support history is included in your personal data export and is removed together with your account when the account is finally deleted.
The public website works with essential cookies by default. Analytics stay off until you allow them.
Traffic reporting is handled in our own backend with a pseudonymous visitor ID and route-level aggregates.
When you contact us or submit a request, we use the data you provide only to process it, provide support and maintain the directory.
If you help your parish with schedules or notices, install the mobile app and request access to maintain its information.
Find the nearest church, check Mass times and follow parish notices wherever you are. Download the app from the store you use.