CMCodex

Privacy Policy

This policy explains what data the Codex Mythologia website collects, why, who it is shared with and how you exercise your rights under the Brazilian LGPD and the GDPR.

Last updated: September 16, 2026

1. Controller

Pryvion Studio — data protection contact: pryvionstudio@gmail.com.

2. Data we collect

Anonymous browsing: you can browse and read the open content of the site without an account. In that case we only collect aggregated technical data (page views, country, device type) to measure audience.

Account: when you sign in with Google we receive your email, name and account identifier. We use these to identify your subscription and preferences.

Subscription: we store plan, start date, validity and the payment identifier. Card and Pix data are processed directly by Mercado Pago or Stripe — they never pass through or get stored on our servers.

Scribe (AI): the text you send is transmitted to the model provider solely to generate the answer to that conversation. Limited use, and you should know exactly what that means: what you write is not used to train AI models, is not sold or sent to advertisers, and no identifier of yours (name, email, account) travels with the text. Do not send sensitive personal data to the Scribe.

Scribe memory: so the conversation picks up where you left off, signed-in PRO subscribers have the history of each deity stored in their account. You can erase it whenever you want with the "New conversation" button on the Scribe screen, and conversations idle for more than 12 months are deleted by us.

Reading log: Oracle and Rune results are kept in your browser; for signed-in PRO subscribers, also in your account, so they follow you to another device. The log's "Clear" button erases both copies.

Daily limit: to prevent automated scraping of the Codex sections, we store a day's count against your account identifier or, when you are not signed in, against a code derived from your IP (a non-reversible hash). It is used only for that limit and is dropped when the day turns.

Favorites: stored in your own browser (localStorage). If you are a signed-in PRO subscriber, the list is also kept in your account so it syncs across devices — it is never shared with third parties.

3. Legal bases

Performance of a contract (subscription and PRO content delivery), legitimate interest (audience measurement and abuse prevention) and consent (non-essential cookies, where applicable).

4. Who we share with

Only providers strictly necessary to run the service: Vercel (hosting), Google Firebase (login and database), Cloudflare R2 (images and audio), Mercado Pago and Stripe (payments) and the AI model provider behind the Scribe.

We do not sell personal data and we do not share your reading list with third parties.

5. Cookies and advertising (Google AdSense)

We use local storage for preferences (language, favorites) and session cookies to keep you signed in. Audience metrics are collected in aggregate form.

Advertising & third-party partners: this website displays advertisements served by Google (Google AdSense, publisher ID ca-pub-4720172954033263). Third-party vendors, including Google, use cookies to serve ads based on a user’s prior visits to this website or other websites on the internet.

User opt-out & choices: users may opt out of personalized advertising at any time by visiting Google Ads Settings (https://adssettings.google.com) or by visiting www.aboutads.info/choices. To learn more about how Google processes information across partner websites, please visit policies.google.com/technologies/partner-sites.

6. Retention

Account and subscription data are kept while the account exists and for the legal period applicable to tax records. You may request deletion at any time.

Scribe conversations stored in your account (PRO) are erased instantly by the "New conversation" button and discarded by us after 12 months of inactivity. The daily limit count is dropped when the day turns, and technical anti-abuse records are kept for up to 30 days.

7. Your rights

Confirmation of processing, access, correction, anonymisation, portability, erasure and withdrawal of consent. To exercise them write to pryvionstudio@gmail.com — we reply within 15 days.

8. Children

The site is not directed to children under 13 and does not knowingly collect data from that age group.

9. Security

HTTPS connections, payment credentials kept off our servers, restricted administrative access and per-IP rate limits on sensitive routes.

10. Mobile app integration (cross-platform subscription)

Codex Mythologia also exists as an Android app on Google Play. Signing in with a Google account unifies your PRO access across both the website and the app. Profile data (name, email, and Firebase Authentication UID) is used to authenticate and grant PRO features on both platforms.

For purchases made inside the app, the Play Store receipt is validated with the Google Play Developer API to link the subscription to your account. No credit card data is stored by us.

Account and data deletion: you may request permanent deletion at any time at /en/delete-account or directly within the Android app (About tab → "Account and data deletion"). Deletion permanently removes your Firebase Authentication profile and all associated data across the website and the app.

11. Changes

Material changes will be announced on this page with a new update date.