Bible Club

Privacy Policy

This describes exactly what Bible Club stores, why, and how you get rid of it. It is written against what the app actually does, not against a template.

Last updated {{EFFECTIVE_DATE}}

Who is responsible

The controller for the purposes of the GDPR is {{COMPANY_LEGAL_NAME}}, {{COMPANY_ADDRESS}}. You can reach us at {{SUPPORT_EMAIL}} about anything on this page.

The short version

What we collect, and why

DataWhyLegal basis (GDPR)
Email address, and an authentication identifier from Apple or Google if you sign in that wayTo create and secure your accountPerformance of a contract (Art. 6(1)(b))
Username, display name, profile photo, short bio, chosen interestsSo other people can recognise you in a discussionPerformance of a contract
Reflections, questions and replies you post, and which verse and translation they are attached toThey are the productPerformance of a contract
Direct messages and club chat messagesTo deliver themPerformance of a contract
Clubs you belong to, who else is in them, and what the club is readingTo show you the clubPerformance of a contract
Highlights, verse notes and saved versesThey are yours; they sync to your devicesPerformance of a contract
Follows, blocks and reports you makeTo keep the social graph and the moderation queue workingPerformance of a contract; legitimate interest in a safe service (Art. 6(1)(f))
A hash of your own phone number, only if you choose to connect contactsSo contacts who already have your number can find youConsent (Art. 6(1)(a)) — you opt in, and can disconnect at any time
Push notification device token, and your notification and daily-digest preferencesTo send the notifications you asked forConsent
Product events: which screens were opened, that a reflection was posted, that a digest was tapped — a name, a few non-identifying properties, and your user idTo understand whether the app works, and where people get stuckLegitimate interest in improving the service — switch it off in Settings → Privacy
Crash reportsTo fix crashesLegitimate interest in a working service — switch it off in Settings → Privacy

What we deliberately do not collect

Contacts, in detail

Finding friends by phone number is optional, off by default, and works like this:

  1. Your device reads your address book. The address book never leaves your phone.
  2. Each phone number is converted to a hash — a fixed-length string — on your device.
  3. Only those hashes are sent, and only to be compared against the hashes of people who have chosen to be findable. They are not stored.
  4. If you added your own number, its hash is stored, so that your contacts can find you. Disconnecting in Settings deletes it immediately.

To be straight with you about the limits of that: a phone number is drawn from a small enough set of possibilities that a hash of one is not, on its own, a strong protection. It keeps plaintext numbers out of the database and off the network — which is worth doing — but it should not be read as making a number unrecoverable. If that trade-off is not one you want to make, do not connect contacts; every other part of the app works without it.

Photos and the camera

Used only when you choose a profile picture, or save a verse card to your photo library. Nothing is uploaded except the profile picture you pick.

Who else processes your data

We use a small number of processors, each under a data processing agreement, and none of them receive your data for their own purposes:

ProcessorWhat forWhere
SupabaseDatabase, authentication, file storage, push fan-out{{SUPABASE_REGION}}
SentryCrash and error reportingEuropean Union
{{ALERT_SERVICE}}Receives moderation alerts when someone reports content, so reports can be acted on quickly. Carries the reported text and the author's username — never the reporter's identity.{{ALERT_SERVICE_REGION}}
Expo (Expo Application Services)Relays push notifications to Apple and GoogleUnited States
Apple Push Notification service / Google Firebase Cloud MessagingDelivers push notifications to your deviceUnited States
Apple / GoogleSign in with Apple, Google Sign-In — only if you use themUnited States

Where a processor is outside the EEA, the transfer relies on the European Commission's Standard Contractual Clauses. Push notifications carry only what is needed to show the notification.

Crash reports

You can turn crash reports off entirely in Settings → Privacy. When they are on, they contain the technical state of the app at the moment it failed, plus your user id so a recurring crash can be recognised as one person's. Before a report leaves your device we strip the query strings from network requests and drop console output, because those would otherwise reveal which profiles you looked at and which verses you read. Crash reports never contain message or comment text.

How long we keep things

Your rights

Under the GDPR you have the right to access your data, correct it, delete it, restrict or object to how it is processed, and receive a copy in a portable format. You may also withdraw consent — for contacts or notifications — at any time in the app, without affecting anything done before you withdrew it.

Most of this is immediate and self-service in the app: edit your profile, disconnect contacts, turn notifications off, turn off usage analytics or crash reports under Settings → Privacy, delete your account. For anything else, write to {{SUPPORT_EMAIL}} and we will respond within 30 days.

You also have the right to complain to a supervisory authority — in Germany the data protection authority of your federal state, in Croatia the Agencija za zaštitu osobnih podataka (AZOP).

Children

Bible Club is not for children under 13, and not for anyone under 16 where local law sets that as the minimum age for using a service like this — which includes Germany and Croatia. See our child safety standards. If you believe a child is using the app, tell us at {{SUPPORT_EMAIL}} and we will remove the account.

Security

Traffic is encrypted in transit. Your session is stored in your device's Keychain or Keystore. Access to your rows is enforced by the database itself, not only by the app: a club's discussion is unreadable to anyone who is not in that club, and your direct messages are unreadable to anyone who is not in the conversation.

Changes

If this policy changes in a way that matters, we will say so in the app before the change takes effect.