PRIVACY POLICY

Last updated: February 28, 2026


WHAT IS THIS POLICY?

This privacy policy explains, clearly and in detail, how the Bible & Stories application collects, stores, and protects user information. The goal is to offer complete transparency regarding data processing and ensure that using the application is safe and understandable for anyone, even without technical knowledge.

The application is developed and maintained in the European Union and complies with applicable data protection regulations, including the General Data Protection Regulation (GDPR). To use it, you must accept this policy and the Terms and Conditions.

Login is performed through the "Sign in with Apple" feature, which allows anonymizing the user's identity. By doing so, an anonymous account is created that enables the use of the application's features without exposing the user's real identity.


1. DATA CONTROLLER

Controller: The Bible & Stories application

Contact for questions or requests: bible.apsd@gmail.com

Location: European Union

The application only uses data necessary for the proper functioning of the service. The only identifier stored on the application's servers is a cryptographic hash (SHA256) derived from the Apple ID, which is mathematically impossible to reverse to identify the user. No email addresses, names, or any other personally identifiable data are stored on the application's servers.


2. INFORMATION COLLECTED

a) Authentication data:

- Apple ID: Managed exclusively by Firebase Authentication (Google). The application never stores the associated email address.

- Hash identifier (SHA256): Derived from the Apple ID through an irreversible cryptographic function. This is the only identifier stored on the application's servers and does not allow personal identification of the user.

- Session tokens: Temporary digital keys managed by Firebase to maintain the active session.


b) Service usage data (stored on server):

- Account status: Available free credits, premium subscription status, and expiration date.

- Usage control: Counter of requests to the artificial intelligence service to apply fair use limits.

- Timestamps: Account creation date, last activity, and other internal control dates.


c) Technical and analytical data (processed by external services):

- Firebase Analytics: Application usage events, screens visited, session time (anonymously).

- Firebase Crashlytics: Technical error logs and application crashes for service improvement.

- RevenueCat: Premium subscription status management.


d) Data stored locally on the user's device:

- iCloud (Apple): Personal notes, bookmarks, favorites, and preferences. This data is encrypted and only accessible with the user's Apple ID. The application cannot access this data outside the user's device.


3. PURPOSE OF PROCESSING

The processing of the hash identifier and other data has the following purposes:

- Authentication and access control: Verify the user's identity securely without knowing their real identity.

- Free credits management: Assign and control the use of 15 free credits per user to access the artificial intelligence assistant.

- Premium subscription management: Verify active subscription status and apply corresponding benefits (assistant usage).

- Abuse prevention: Detect and block fraudulent behavior, mass account creation, or improper use of the service.

- Fair use control: Apply reasonable request limits for premium users and prevent service saturation.

- Service improvement: Analyze technical errors, optimize performance, and improve user experience through anonymous data.

- Personal storage in iCloud: Allow the user to save their notes, bookmarks, and preferences privately and encrypted in their iCloud account.


IMPORTANT:

- The hash identifier is permanently retained even after account deletion, exclusively for security reasons and to prevent abuse.

- The Bible AI & Stories application does not sell user data or use it for advertising purposes. It also does not perform cross-application tracking or user profiling.

- However, integrated external services (Firebase, OpenAI, RevenueCat, Unsplash) operate under their own privacy policies and may process data according to their terms. 

We only share data with third-party providers that maintain industry-standard security and data protection practices. OpenAI processes data in accordance with their Data Usage Policy, which does not use API inputs for model training.


It is recommended to review the privacy policies of each provider:

- Firebase/Google: https://policies.google.com/privacy

- OpenAI: https://openai.com/privacy

- RevenueCat: https://www.revenuecat.com/privacy

- Unsplash: https://unsplash.com/privacy


4. TECHNOLOGIES AND SERVICES USED

Account control and fraud protection:

When signing in with Apple for the first time, a technical identifier is automatically generated using the SHA256 cryptographic function applied to a unique identifier provided by Apple. This process is irreversible: it is not mathematically possible to recover the original identifier from the hash.

The hash identifier is used to:


Permanent retention of the identifier:

The hash identifier is retained indefinitely in the database, even after the user deletes their Firebase account. This measure is necessary to:


Account blocking:

If fraudulent activity, service manipulation, violation of terms of use, or abuse of the free credits system is detected, the account may be blocked temporarily or permanently. In these cases:


Account deletion from the application:

The user can delete their Firebase account at any time from the application settings. When doing so:

- Data deleted: Email and credentials stored in Firebase (managed by Google). Restricted access to some application features (both free and premium).

- Data NOT automatically deleted: Notes, bookmarks, and preferences stored in iCloud: remain in the user's iCloud account and must be manually deleted by the user from their iCloud settings if desired.

- Hash identifier stored on the server: permanently retained for security and fraud prevention reasons, as explained in this policy.

- Important: If you sign in again with the same Apple ID after deleting the account, the system will recognize you with the same identifier and previous credit status. If the account was blocked for fraud, the block will remain active.


Cookies and third-party technologies:

The application does not use its own cookies or IDFA. However, some integrated third-party services (Firebase, OpenAI, Unsplash, RevenueCat, Apple iCloud) may use technical identifiers equivalent to cookies for security, authentication, or performance analysis purposes. These identifiers are managed directly by external providers. The application does not access or control these technologies and assumes no responsibility for their use to the extent permitted by law.


Integrated external services:

The application integrates the following external services necessary for its operation:


1. OpenAI 🤖

- Purpose: Provide the conversational assistant service based on artificial intelligence.

- Data processed: Messages sent by the user to the assistant, user's hash identifier.

- Location: OpenAI servers (United States).

- Important: Conversations are not permanently stored in the application. OpenAI may retain data temporarily according to its own privacy policies.

When you use the AI assistant feature in Bible AI & Stories, the content of your messages (conversation history within the chat session) is transmitted to OpenAI, L.L.C. (San Francisco, CA, USA) to generate responses.


What data is sent to OpenAI:

- The text of your messages during the chat session.

- The conversation context (previous messages in the same session).


What is NOT sent to OpenAI:

- Your name or email address.

- Your Apple ID or any personal identifier.

- Your Bible notes, bookmarks, or annotations.

- Any payment or subscription information.


Purpose:

To generate AI-powered responses to your Bible study questions.


Data Policy:

OpenAI processes this data according to their Privacy Policy (openai.com/privacy) and API Data Usage Policies. OpenAI does not use API data to train its models by default.


2. Firebase Authentication (Google)

- Purpose: Manage Sign in with Apple.

- Data processed: User's email address (real or hidden as chosen by the user), Apple sub (Apple identifier).

- Location: Google servers (with GDPR protection measures).

- Control: The user can delete their Firebase account from the application settings.


3. Firebase App Check (Google)

- Purpose: Verify that requests to the server come from the official application and not from fraudulent sources.

- Data processed: Device verification tokens (not personally identifiable).

- Location: Google servers.


4. Firebase Analytics (Google)

- Purpose: Collect anonymous application usage statistics.

- Data processed: Navigation events, screens visited, session time (associated with an anonymous identifier, not email).

- Location: Google servers.


5. Firebase Crashlytics (Google)

- Purpose: Detect and log technical errors to improve application stability.

- Data processed: Crash logs, device information (model, operating system, app version).

- Location: Google servers.


6. RevenueCat

- Purpose: Manage premium subscriptions and synchronize payment status between the App Store and the application server.

- Data processed: User's hash identifier (SHA256), subscription status, expiration date.

- Location: RevenueCat servers (United States, with GDPR protection through Standard Contractual Clauses).


7. Unsplash

- Purpose: Provide illustrative background images for the application.

- Data processed: No personal data. Only requests for public images.

- Location: Unsplash servers.


8. iCloud (Apple)

- Purpose: Store personal notes, bookmarks, and user preferences privately and encrypted.

- Data processed: Content created by the user within the application.

- Location: iCloud servers controlled by Apple.

- Control: Only accessible with the user's Apple ID. The application cannot access this data outside the user's device.

- Deletion: iCloud data remains in the user's account even when logging out or uninstalling the application. The user must manually delete them from their iCloud settings if desired.


5. LEGAL BASIS

Data processing is based on the following legal grounds according to GDPR:

1. Contract performance (Art. 6.1.b GDPR): Processing of the hash identifier is necessary to provide the service requested by the user (access to AI assistant, credit and subscription management).

2. Legitimate interest (Art. 6.1.f GDPR): Fraud and service abuse prevention. Protection of the business model based on limited free credits. Security of the application and other users.

3. Informed consent (Art. 6.1.a GDPR): Acceptance of this Privacy Policy and Terms and Conditions when using the application.

4. Regulatory compliance: Application of the principle of data minimization (only the hash identifier is processed, no additional personal data). Application of the principle of purpose limitation (data is used exclusively for the described purposes).


6. INTERNATIONAL TRANSFERS

Some external services (for example, Firebase, OpenAI, and RevenueCat) process information on servers located outside the European Economic Area. These providers apply recognized legal mechanisms, such as Standard Contractual Clauses (SCC) or equivalent, to ensure data protection in accordance with GDPR. Compliance with these measures is the responsibility of each provider.


7. SECURITY

Security measures are applied to protect data:

- HTTPS encryption in communications.

- Encryption applied to sensitive data in iCloud.

- Security rules against unauthorized access.

- Error logging and control.

- Verification through Firebase App Check to prevent fraudulent access.

- Protection to prevent attacks.

- Important: Not all information is encrypted at rest in all systems, but reasonable and proportionate measures to risk are applied.


8. USER RIGHTS

Users have the following rights under GDPR:

Rights over Firebase data (email):

- Access: Check what data Firebase stores (through Google).

- Rectification: Modify the email associated with the Apple ID (managed by Apple).

- Deletion: Delete the Firebase account from the application settings, which immediately deletes the email.

- Portability: Request a copy of data stored in Firebase.


Rights over the hash identifier (stored on server):

IMPORTANT: The hash identifier (SHA256) is anonymized data that does not allow personal identification. Therefore:

- The GDPR rights of access, rectification, deletion, and portability do not apply to this data, in accordance with Recital 26 of GDPR.

- The identifier is retained indefinitely for legitimate security reasons, even after Firebase account deletion.

- The user cannot request deletion of the hash identifier from the database.


Rights over iCloud data:

- Data stored in iCloud (notes, bookmarks, preferences) is controlled exclusively by the user.

- This data remains in iCloud even when logging out or uninstalling the application.

- The user must manually delete this data from their iCloud account if they wish to remove it.

- Apple is responsible for processing this data according to its privacy policies.


9. USE BY MINORS

The application is suitable for minors and does not collect sensitive personal data. It is recommended that parents or guardians supervise its use by minors.


10. POLICY CHANGES

The policy may be updated for technical, legal, or functional reasons. Users must periodically review the Settings section and the last update date indicated in this document.


11. GLOSSARY

- RevenueCat: Subscription management service.

- Apple ID: Apple identification system.

- GDPR: European data protection regulation.

- Anonymized/pseudonymized data: Information modified to not directly identify the user.

- SHA256: Cryptographic function that transforms any data into a 64-character hexadecimal string.

- Hash identifier: Result of applying SHA256 to an identifier. It is the only identifier the application stores on its servers.

- Firebase: Google services for authentication, analytics, and errors.

- OpenAI: Artificial intelligence engine provider.

- Unsplash: Provider of free background images.

- HTTPS: Encrypted communication protocol.

- SCC: Standard Contractual Clauses for international transfers.


12. CONTACT

For any questions or requests related to privacy, users can write to:

📧 bible.apsd@gmail.com


13. EXTERNAL PROVIDERS AND DISCLAIMER

The application integrates third-party services strictly necessary for its operation. Each provider operates with its own infrastructure and policies. The application does not control the internal operation or technical decisions of these services. The use of cookies or equivalent identifiers by third parties is outside the direct responsibility of the application. To the extent permitted by law, the application assumes no responsibility for the actions of such third parties.


Bible & Stories protects your privacy seriously and transparently.

Continued use of the application implies full and conscious acceptance of these Policies.