Privacy Policy
Last updated: August 18, 2026
This Privacy Policy explains how Loreto Media LLC, doing business as Apologia Catholic (“Loreto,” “we,” “us,” or “our”), collects, uses, shares, and protects information when you visit or use www.apologiacatholic.com, its public articles and resources, its contact form, or its private editorial features (together, the “Site”). Loreto Media LLC’s mailing address is 501 S Midvale Blvd, Madison, WI 53711, United States. Loreto decides why and how it uses information for the Site. This Policy does not govern the privacy practices of third-party websites or services linked from the Site.
1. Information we collect
Information you provide
Depending on how you use the Site, you may provide:
- Contact information and messages: your name, email address, subject, and message when you use the contact form. We send the message to the configured team inboxes through our email provider and may send a confirmation to the email address you provide.
- Access requests: your name, email address, and reason when you request private editorial access.
- Admin and invitation information: your Google account email, display name, Firebase account identifier, role, invitation details, and sign-in or access status when you are invited to or use the private editorial area. An invitation link is a bearer link; someone who receives a usable link may see the invited email address until the invitation is accepted, revoked, or expires.
- Editorial material: articles, revisions, notes, images, and map or topic changes that authorized editors add to the private editorial system. Those records can include the editor’s email, account identifier, role, file metadata, and change history. Limited editor attribution may appear in public revision history.
The Site is currently free and does not offer subscriptions or process payments. Do not send payment-card data, passwords, health information, sacramental information, or other sensitive personal information through the contact form. We do not need those details to answer ordinary questions about the Site.
Information collected through use of the Site
Our hosting, security, authentication, email, and analytics providers may receive technical information such as IP address, browser and device type, operating system, referring page, requested URL, timestamps, and error or security data. The contact form uses the request IP in an in-memory rate limiter to reduce abuse; the app does not write that IP to its Firestore collections.
Vercel Web Analytics loads from the root layout across the Site, including routes that do not require an account. It may process page paths, referrers, approximate location, browser, operating system, device, and request-time information for page-view and visitor reporting. If Firebase Analytics is enabled by the deployment configuration, its SDK may receive page-view events, including the page path, query string, and page title, and other usage or technical data collected by Firebase and Google Analytics. We do not put contact-form messages, access-request reasons, or admin content into analytics events. We do not currently provide an in-site analytics opt-out or consent banner.
Cookies, local storage, and similar technologies
The private admin area uses an essential, HTTP-only session cookie named __session to keep an authorized editor signed in. The cookie is set for a five-day session period and is not used for advertising. Google and Firebase sign-in may also use storage or cookies needed to complete authentication.
The public Site stores your theme choice and optional formation-map progress in your browser’s local storage. The app does not send that browser-only data to us. You can clear it through your browser settings. Vercel Web Analytics is designed to measure visitors without third-party cookies. Apologia Catholic does not currently display a cookie-consent banner and does not use advertising or retargeting cookies. Blocking storage or scripts may affect sign-in, preferences, analytics, or parts of the Site.
2. How we use information
We use information to:
- Operate, maintain, secure, and improve the Site;
- Answer contact messages and correction requests;
- Review and respond to requests for private editorial access;
- Authenticate and authorize invited editors and manage invitations;
- Store, review, publish, and restore authorized editorial work;
- Send contact confirmations and private-team invitation emails;
- Measure Site use and improve articles, navigation, and performance;
- Detect abuse, enforce our Terms, and protect people and systems; and
- Meet legal, accounting, security, and other valid obligations.
We do not sell personal information or use it for ads based on activity across different sites.
3. When we share information
We share information only as needed for the purposes in this Policy, including with:
- Firebase and Google Cloud: authentication, private Firestore records, editorial files, related server operations, and any enabled Firebase Analytics.
- Google: sign-in services when an invited editor chooses Google authentication.
- Twilio SendGrid: delivery of contact-form notifications, contact confirmations, and private-team invitations. SendGrid receives the email data needed to deliver those messages.
- Vercel: hosting and Web Analytics for the Site.
- Media and storage providers: some pages automatically request images from Wikimedia, YouTube thumbnail servers, or Firebase Storage. Those services may receive your IP address, referrer, browser, device, and request time under their own policies.
- Other providers: your browser may connect to outside sites, media hosts, image sources, and reference services that you choose to open from a link or image on the Site. Their own policies govern their handling of those connections.
- Authorities and a new owner: courts, regulators, law enforcement, or advisers when required or allowed by law, and a new owner if the Site or its assets are transferred, subject to applicable law.
4. Retention
We do not currently delete contact messages, access requests, invitations, audit records, article revisions, or uploaded images on a fixed schedule. We keep each type of information only as long as needed for its stated purpose, security, legal, dispute, audit, backup, and operational records. Revoking an invitation or removing a member changes access status but does not by itself delete related records.
- Contact messages and access requests remain while we handle them and afterward as needed for support, abuse prevention, and business records.
- Admin accounts, editorial history, invitations, and audit records remain while needed to operate and secure the private editorial system, even after access ends.
- Uploaded images and related public files remain while they are used for the Site or are needed for security, backup, legal, or dispute records.
- Backups may retain copies of records until the backup is overwritten or expires under the applicable backup process.
- Browser-only preferences and formation progress remain until you clear them or your browser removes them.
When information is no longer needed, we may delete it or remove details that identify you, subject to legal, security, backup, and records needs. Analytics providers may apply their own retention settings.
5. Your choices and privacy rights
Depending on where you live and which laws apply, you may have the right to ask for access to, correction of, deletion of, or a copy of personal information; to object to or limit some processing; to opt out of a sale or sharing that the law covers; and to receive equal treatment for exercising those rights. We do not sell personal information or use it for ads based on activity across different sites.
To make a privacy request, use the contact form or email support@loretosites.com, and put “Privacy request” in the subject line. Tell us which information and action you seek. We may verify your identity before responding. An authorized agent may make a request with proof of authority. We may keep information that we must retain for security, legal, audit, or other permitted reasons. We will handle a valid request within the time required by applicable law, explain any denial, and provide the appeal path that the law requires.
You can also control browser storage and block analytics or other optional scripts through your browser, device, or network settings. Those controls may affect site features.
6. Security
We use reasonable administrative, technical, and organizational measures for the information handled through the Site. These include access controls for private data, server-side authorization checks, protected session cookies, input validation, and service-provider security controls. No transmission or storage method is completely secure, so we cannot promise absolute security.
7. Children
The Site is a general educational resource and is not directed to children under 13. Do not use the contact or access-request forms if you are under 13. We do not knowingly collect personal information from a child under 13. If we learn that a child sent us personal information, a parent or guardian may contact support@loretosites.com. We will delete the information from active systems where the law allows and will ask our service providers to do the same.
8. International users
The Site and its service providers may process information in the United States and other locations where those providers operate. If you use the Site from another country, your information may be transferred to a location with different privacy rules. We will use safeguards required by applicable law for those transfers when the law requires them.
9. Changes to this Policy
We may update this Privacy Policy when our practices or legal duties change. The revised Policy takes effect when posted unless it states a later date. For a material change, we will give additional notice when appropriate. The “Last updated” date at the top of this page shows when we last revised it. Continued use of the Site after the effective date means you acknowledge the revised Policy.
10. Contact
For privacy questions or requests, use the contact form, put “Privacy request” in the subject line, or email support@loretosites.com. You may also write to Loreto Media LLC, 501 S Midvale Blvd, Madison, WI 53711, United States, or call (608) 285-2027. You may review our Terms of Use. Do not include passwords, payment-card data, or other sensitive information in a request unless we ask for it through a secure channel. If applicable law gives you an appeal right, you may ask us to reconsider a denied request through the same contact channel. Privacy Policy version: 2026-08-18.