Privacy Policy
This describes exactly what Bible Club stores, why, and how you get rid of it. It is written against what the app actually does, not against a template.
Last updated {{EFFECTIVE_DATE}}
Who is responsible
The controller for the purposes of the GDPR is {{COMPANY_LEGAL_NAME}}, {{COMPANY_ADDRESS}}. You can reach us at {{SUPPORT_EMAIL}} about anything on this page.
The short version
- We do not sell your data, and we do not use it for advertising.
- We do not store your contacts' phone numbers, and we never see your address book.
- You can delete your account and everything in it from inside the app, in two taps, or from this website.
- What you write in a club stays in that club. What you write publicly is public.
What we collect, and why
| Data | Why | Legal basis (GDPR) |
|---|---|---|
| Email address, and an authentication identifier from Apple or Google if you sign in that way | To create and secure your account | Performance of a contract (Art. 6(1)(b)) |
| Username, display name, profile photo, short bio, chosen interests | So other people can recognise you in a discussion | Performance of a contract |
| Reflections, questions and replies you post, and which verse and translation they are attached to | They are the product | Performance of a contract |
| Direct messages and club chat messages | To deliver them | Performance of a contract |
| Clubs you belong to, who else is in them, and what the club is reading | To show you the club | Performance of a contract |
| Highlights, verse notes and saved verses | They are yours; they sync to your devices | Performance of a contract |
| Follows, blocks and reports you make | To keep the social graph and the moderation queue working | Performance of a contract; legitimate interest in a safe service (Art. 6(1)(f)) |
| A hash of your own phone number, only if you choose to connect contacts | So contacts who already have your number can find you | Consent (Art. 6(1)(a)) — you opt in, and can disconnect at any time |
| Push notification device token, and your notification and daily-digest preferences | To send the notifications you asked for | Consent |
| Product events: which screens were opened, that a reflection was posted, that a digest was tapped — a name, a few non-identifying properties, and your user id | To understand whether the app works, and where people get stuck | Legitimate interest in improving the service — switch it off in Settings → Privacy |
| Crash reports | To fix crashes | Legitimate interest in a working service — switch it off in Settings → Privacy |
What we deliberately do not collect
- No advertising identifiers, no ad networks, no tracking across other apps or sites.
- No location. The app never asks for it.
- No reading analytics tied to a passage. We record that a reading session started, not what you read in it.
- No payment data. The app does not take payments.
Contacts, in detail
Finding friends by phone number is optional, off by default, and works like this:
- Your device reads your address book. The address book never leaves your phone.
- Each phone number is converted to a hash — a fixed-length string — on your device.
- Only those hashes are sent, and only to be compared against the hashes of people who have chosen to be findable. They are not stored.
- If you added your own number, its hash is stored, so that your contacts can find you. Disconnecting in Settings deletes it immediately.
To be straight with you about the limits of that: a phone number is drawn from a small enough set of possibilities that a hash of one is not, on its own, a strong protection. It keeps plaintext numbers out of the database and off the network — which is worth doing — but it should not be read as making a number unrecoverable. If that trade-off is not one you want to make, do not connect contacts; every other part of the app works without it.
Photos and the camera
Used only when you choose a profile picture, or save a verse card to your photo library. Nothing is uploaded except the profile picture you pick.
Who else processes your data
We use a small number of processors, each under a data processing agreement, and none of them receive your data for their own purposes:
| Processor | What for | Where |
|---|---|---|
| Supabase | Database, authentication, file storage, push fan-out | {{SUPABASE_REGION}} |
| Sentry | Crash and error reporting | European Union |
| {{ALERT_SERVICE}} | Receives moderation alerts when someone reports content, so reports can be acted on quickly. Carries the reported text and the author's username — never the reporter's identity. | {{ALERT_SERVICE_REGION}} |
| Expo (Expo Application Services) | Relays push notifications to Apple and Google | United States |
| Apple Push Notification service / Google Firebase Cloud Messaging | Delivers push notifications to your device | United States |
| Apple / Google | Sign in with Apple, Google Sign-In — only if you use them | United States |
Where a processor is outside the EEA, the transfer relies on the European Commission's Standard Contractual Clauses. Push notifications carry only what is needed to show the notification.
Crash reports
You can turn crash reports off entirely in Settings → Privacy. When they are on, they contain the technical state of the app at the moment it failed, plus your user id so a recurring crash can be recognised as one person's. Before a report leaves your device we strip the query strings from network requests and drop console output, because those would otherwise reveal which profiles you looked at and which verses you read. Crash reports never contain message or comment text.
How long we keep things
- Your account and its content: until you delete it.
- Deleted account: removed immediately and irreversibly, including your posts, messages, marks, memberships, contact hash and profile photo. Backups roll off within 30 days.
- Reports you file about someone: kept while the report is being handled and for up to 12 months afterwards, so a pattern of behaviour can be recognised.
- Product events: disconnected from your account when you delete it, and kept only as anonymous counts. Turning usage analytics off in Settings deletes the events already collected for your account outright.
- Crash reports: 90 days.
Your rights
Under the GDPR you have the right to access your data, correct it, delete it, restrict or object to how it is processed, and receive a copy in a portable format. You may also withdraw consent — for contacts or notifications — at any time in the app, without affecting anything done before you withdrew it.
Most of this is immediate and self-service in the app: edit your profile, disconnect contacts, turn notifications off, turn off usage analytics or crash reports under Settings → Privacy, delete your account. For anything else, write to {{SUPPORT_EMAIL}} and we will respond within 30 days.
You also have the right to complain to a supervisory authority — in Germany the data protection authority of your federal state, in Croatia the Agencija za zaštitu osobnih podataka (AZOP).
Children
Bible Club is not for children under 13, and not for anyone under 16 where local law sets that as the minimum age for using a service like this — which includes Germany and Croatia. See our child safety standards. If you believe a child is using the app, tell us at {{SUPPORT_EMAIL}} and we will remove the account.
Security
Traffic is encrypted in transit. Your session is stored in your device's Keychain or Keystore. Access to your rows is enforced by the database itself, not only by the app: a club's discussion is unreadable to anyone who is not in that club, and your direct messages are unreadable to anyone who is not in the conversation.
Changes
If this policy changes in a way that matters, we will say so in the app before the change takes effect.