Privacy Policy
Last updated:
In short
This privacy policy explains, clearly and in detail, how the Bible 365 application collects, stores and protects user information. The goal is to offer complete transparency regarding data processing and to make using the application safe and understandable for anyone, even without technical knowledge.
The application is developed and maintained in the European Union and complies with applicable data protection regulations, including the General Data Protection Regulation (GDPR). To use it, you must accept this policy and the Terms of Use.
Login is performed through Sign in with Apple, so the application never learns your name and never has to. You can also choose to hide your email address, and Apple will give a relay address instead.
Who processes your data
The Bible 365 application, developed by ApSD-Studio, an independent studio based in the European Union. For questions or requests: [email protected].
What data is processed
The application only uses data necessary for the proper functioning of the service. The only identifier stored on the application’s own servers is a cryptographic hash (SHA256) derived from the identifier Apple provides, which cannot be reversed to recover your Apple ID. No email addresses, names or any other directly identifying data are stored on those servers.
That hash recognises an access without identifying a person. The application cannot work out who you are from it, and the database holds no link between it and any Apple ID or email address. It is not anonymous data either, since the same Apple ID always produces the same hash: it is pseudonymised, and the GDPR still covers it. What that means for your rights, including why the hash is not deleted, is set out further down.
a) Authentication data. Managed exclusively by Firebase Authentication (Google). The application never stores the associated email address.
- Hash identifier (SHA256). Derived from the identifier Apple provides, through a one-way cryptographic function. It is the only identifier stored on the application’s own servers. It does not reveal who you are, but it does single you out, which is why it is treated as pseudonymised personal data.
- Session tokens. Temporary digital keys managed by Firebase to maintain the active session.
b) Service usage data, stored on the server.
- Available free credits, premium subscription status and expiration date.
- Counter of requests to the artificial intelligence service, to apply fair use limits.
- Account creation date, last activity and other internal control dates.
c) Technical and analytical data, processed by external services.
- Application usage events, screens visited and session time, reported in aggregate and never tied to your email address or to your hash.
- Technical error logs and application crashes, for service improvement.
- Premium subscription status management.
d) Data stored locally on your device. Personal notes, bookmarks, favourites and preferences. This data is encrypted and only accessible with your Apple ID. The application cannot access it outside your device.
What the data is used for
- Authentication and access control. Verify your identity securely without knowing who you are.
- Free credits management. Assign and control the use of the free credits that give access to the artificial intelligence assistant.
- Premium subscription management. Verify active subscription status and apply the corresponding benefits.
- Fraud prevention. Detect and block fraudulent behaviour, mass account creation or improper use of the service.
- Fair use. Apply reasonable request limits and prevent service saturation.
- Service improvement. Analyse technical errors and optimise performance using aggregated usage data.
- Personal storage in iCloud. Allow you to save your notes, bookmarks and preferences privately and encrypted in your own iCloud account.
What is never done with your data
Bible 365 does not sell user data and does not use it for advertising purposes. It does not perform cross-application tracking or user profiling.
Integrated external services (Firebase, OpenAI, RevenueCat, Unsplash) operate under their own privacy policies and may process data according to their terms. You are encouraged to review each provider’s policy:
The hash identifier
When you sign in with Apple for the first time, a technical identifier is generated by applying the SHA256 cryptographic function to a unique identifier provided by Apple. The function is one-way: the original identifier cannot be recovered from the hash, and neither can your name or your email address.
The hash is used to verify authorised access without knowing who you are, to assign and manage free credits and premium subscriptions, and to detect and prevent fraud, abuse or violations of the Terms of Use.
Recognisable, not identifiable. The application cannot tell who you are from the hash and has no way of finding out: it holds no name, no email address and nothing that points back to one. What it can do is recognise the same access when it returns, because the same Apple ID always produces the same hash. That is the whole purpose.
That distinction matters for your rights, so this policy is precise about it rather than convenient. The hash is not anonymous data — anonymous would mean nobody could ever connect it to a person, and Apple can connect the identifier it derives from. It is pseudonymised: it singles out an access without naming anyone. In legal terms it therefore counts as personal data, while in practical terms the application is not in a position to identify you from it, and Article 11 of the GDPR is written for exactly that situation. The section on your rights explains what follows.
The hash is not deleted. It stays in the database after you delete your account, and deleting it is not offered. It exists so that an access blocked for fraud or abuse cannot come back by starting over, and so that a service giving a limited number of free credits per person is not drained by an endless supply of new accounts. That is a legitimate interest and it is the ground relied on. It is removed only if the application itself needs to for technical reasons.
Nothing is kept alongside it: no email address, no name, no record of what you read. The row is a hash, a credit count, a subscription status and a few internal dates.
Blocking. If fraudulent activity, service manipulation, violation of the terms of use or abuse of the free credits system is found, the account may be blocked temporarily or permanently. In these cases you will not be able to access the application’s features, no refunds will be processed for active subscriptions, and the identifier will remain blocked.
That decision is taken by a person, one case at a time. Nothing blocks an account automatically: no rule, no threshold and no score. Someone looks at what happened and decides. If you believe a block is a mistake, write to [email protected] and it will be looked at again by the same person who made the decision.
Deleting your account
You can delete your Firebase account at any time from the application settings. When you do:
Deleted immediately — the email and credentials stored in Firebase, managed by Google, and access to the application’s features, both free and premium.
Not deleted automatically
- Notes, bookmarks and preferences stored in iCloud. They remain in your iCloud account and must be deleted manually from your iCloud settings if you want them gone.
- The hash identifier stored on the application’s servers. Kept on the legal ground of legitimate interest, to prevent fraud and abuse, for as long as that purpose stands. You can ask for it to be erased and you can object to it being kept; see the section on your rights.
Because the hash is derived from your Apple ID, signing in again produces the same one: the service will recognise you, with the free credit count you had when you deleted the account. If the account had been blocked for fraud or abuse, the block is still in place.
Cookies and third-party technologies
The application does not use its own cookies or IDFA. However, some integrated third-party services (Firebase, OpenAI, Unsplash, RevenueCat, Apple iCloud) may use technical identifiers equivalent to cookies for security, authentication or performance analysis purposes. These identifiers are managed directly by the external providers. The application does not access or control these technologies and assumes no responsibility for their use, to the extent permitted by law.
Where the application’s own service runs
The service the application talks to —the one holding the hash, the free credit count and the subscription status— runs on rented infrastructure from a hosting provider, on servers located in the United States.
The illustrated stories and their images are held encrypted with a storage provider. The application asks its own service for a temporary link and a decryption key, and then downloads the file from that provider directly, which means the provider sees the network address of your device, as any provider serving a file does. The files themselves carry nothing about you.
Both act as processors: they run infrastructure on the application’s behalf, under contract, and do not use the data for their own purposes. Because both are in the United States, the section on international transfers below applies to them.
If you want to know which providers these are, ask at [email protected] and you will be told. They are not named here because naming the machines that hold the data is of no use to you and of some use to whoever might want to attack them.
External services used
1. OpenAI. Provides the conversational assistant based on artificial intelligence. When you use the AI assistant, the content of your messages —the conversation history within the chat session— is transmitted to OpenAI, L.L.C. (San Francisco, CA, USA) to generate responses.
- What is sent: the text of your messages during the chat session and the conversation context, meaning previous messages in the same session.
- What is NOT sent: your name or email address, your Apple ID or any personal identifier, your Bible notes, bookmarks or annotations, and any payment or subscription information.
Conversations are not permanently stored in the application. OpenAI may retain data temporarily according to its own privacy policies, processes it according to its Privacy Policy and API data usage policies, and does not use API data to train its models by default.
2. Firebase Authentication (Google). Manages Sign in with Apple. Processes your email address —real or hidden, as you choose— and the Apple sub identifier, on Google servers with GDPR protection measures. You can delete your Firebase account from the application settings.
3. Firebase App Check (Google). Verifies that requests to the server come from the official application and not from fraudulent sources, using device verification tokens that are not personally identifiable.
4. Firebase Analytics (Google). Collects usage statistics: navigation events, screens visited and session time. Google attaches them to an installation identifier of its own, not to your email address and not to the hash, so what reaches the application is aggregate figures rather than anything traceable to a person. Advertising identifiers are not collected: the framework Google uses to attribute advertising campaigns is removed from the application at build time.
5. Firebase Crashlytics (Google). Detects and logs technical errors to improve stability: crash logs and device information such as model, operating system and app version.
6. RevenueCat. Manages premium subscriptions and synchronises payment status between the App Store and the application server, processing the hash identifier, subscription status and expiration date on servers in the United States, with GDPR protection through Standard Contractual Clauses.
7. Unsplash. Provides illustrative background images. No personal data is involved: only requests for public images.
8. Google Gemini. Used to generate the illustrations that accompany the stories. This happens while the application’s content is being prepared, not while you use it: no data of yours is ever sent to it. It is listed here for completeness, and the Terms of Use explain how that visual content is produced.
9. Apple iCloud. Stores personal notes, bookmarks and preferences privately and encrypted, on iCloud servers controlled by Apple. Only accessible with your Apple ID; the application cannot access this data outside your device. iCloud data remains in your account even when you log out or uninstall the application, and you must delete it manually from your iCloud settings if you wish.
Legal grounds
Data processing rests on two legal grounds under the GDPR, and only two:
- Contract performance (Art. 6.1.b). Processing the hash is necessary to provide the service you asked for: signing in, access to the AI assistant, and management of free credits and subscriptions. Without it there is no way to give you what you installed the application for.
- Legitimate interest (Art. 6.1.f). Preventing fraud and abuse, protecting a service that gives a limited number of free credits per person, and the security of the application and of everyone else using it. This is the ground for keeping the hash after an account is deleted, and you can object to it — the section on your rights explains how.
Accepting this policy is not used as a legal ground. Consent under the GDPR has to be freely given, specific and withdrawable, and agreeing to a document in order to use an application is none of those things. Where genuine consent is required for something — notifications, for instance — it is asked for separately and can be withdrawn in the system settings.
The principle of data minimisation is applied —only the hash is processed on the application’s own servers, with no additional personal data— as is the principle of purpose limitation: data is used exclusively for the purposes described here.
International transfers
The application’s own service and the storage of its content are in the United States, as described above. Several of the external services also process information outside the European Economic Area: Firebase, OpenAI and RevenueCat among them.
All of them rely on recognised legal mechanisms for those transfers, principally the European Commission’s Standard Contractual Clauses. Each provider is responsible for keeping to them, and their own privacy policies, linked above, state which mechanism they use.
What this means for you in plain terms: the small amount of data described in this policy —your hash, your credit count, your subscription status— is stored in the United States, and the messages you send to the assistant are processed there as well.
Security
The following measures are applied to protect data: HTTPS encryption in communications, encryption applied to sensitive data in iCloud, security rules against unauthorised access, error logging and control, verification through Firebase App Check to prevent fraudulent access, and protection against attacks.
Not all information is encrypted at rest in all systems, but measures reasonable and proportionate to the risk are applied.
Your rights
Over the data held in Firebase (email)
- Access. Check what data Firebase stores, through Google.
- Rectification. Modify the email associated with your Apple ID, managed by Apple.
- Deletion. Delete the Firebase account from the application settings, which immediately deletes the email.
- Portability. Request a copy of the data stored in Firebase.
Over the hash identifier stored on the application’s servers. Here the answer is shaped by the design rather than by preference.
The application is not in a position to identify you from the hash. Given an email address or a name it cannot find the matching row, because no such link exists anywhere in the database. Article 11 of the GDPR covers precisely this case: where a controller cannot identify the data subject, the rights of access, rectification, erasure and portability do not apply, since there is no way to know whose data is whose. That is the situation here, and it is a consequence of how the identifier is built, not a way of avoiding the obligation.
Those rights become exercisable the moment you supply what is missing, which in practice means signing in with the same Apple ID from inside the application: that reproduces the hash and locates your row. From there:
- Access and portability. You can be told, or given a copy of, everything held against it. It is a short list: the hash, your free credit count, your subscription status and expiry, and a few internal dates such as when the account was created and when it was last active.
- Rectification. There is nothing to rectify. The hash is derived from your Apple ID, and nothing descriptive of you is stored beside it.
- Erasure. The hash itself is not deleted, and this policy does not pretend otherwise. Its only purpose is to stop an access that was blocked for fraud or abuse from returning, and to keep a limited-free-credits service from being drained by new accounts. That legitimate interest overrides the request, which the GDPR allows. Everything that does identify you is deleted: your account, your email address and your credentials, from the application settings, at any time and immediately.
- Objection. You can object to the hash being kept, and the objection will be answered with reasons rather than ignored. If you disagree with those reasons you can complain to your national data protection authority; if you are in Spain, that is the Agencia Española de Protección de Datos.
For anything else, write to [email protected].
Over the data stored in iCloud. Notes, bookmarks and preferences are controlled exclusively by you. This data remains in iCloud even when you log out or uninstall the application, and you must delete it manually from your iCloud account if you wish to remove it. Apple is responsible for processing this data according to its own privacy policies.
Minors
The application collects no sensitive personal data and its content is written to be suitable for a general audience, minors included.
One part of it deserves a specific warning. The application includes an assistant that answers in your own words using artificial intelligence, and those answers are generated automatically: they are not written or reviewed by a person beforehand, and they can be wrong. The Terms of Use go into this. For that reason, parents or guardians are encouraged to supervise a minor’s use of the assistant in particular, rather than the application in general.
The application is not directed at children under 13. Where the law of your country requires a parent or guardian to authorise the processing of a minor’s data —in the European Union that threshold sits between 13 and 16 depending on the member state— that authorisation must be given before the minor uses the application. If you believe a minor has used it without that authorisation, write to [email protected] and the account will be deleted.
Changes to this policy
The policy may be updated for technical, legal or functional reasons. You are encouraged to review the Settings section periodically, along with the last update date shown at the top of this document.
Glossary
- Hash identifier. Result of applying SHA256 to an identifier. The only identifier the application stores on its servers.
- SHA256. Cryptographic function that transforms any data into a 64-character hexadecimal string.
- Apple ID. Apple’s identification system.
- Firebase. Google services for authentication, analytics and error reporting.
- OpenAI. Artificial intelligence engine provider.
- RevenueCat. Subscription management service.
- Unsplash. Provider of free background images.
- HTTPS. Encrypted communication protocol.
- SCC. Standard Contractual Clauses for international transfers.
- GDPR. European data protection regulation.
- Pseudonymised data. Data that no longer names a person directly, but that still singles them out, so that the same person can be recognised again. It remains personal data and the GDPR still applies to it. The hash identifier is of this kind.
- Anonymised data. Data from which a person can no longer be identified by anyone, by any means. The GDPR no longer applies to it. Nothing in this policy is claimed to be anonymised except the aggregate usage statistics.
External providers and disclaimer
The application integrates third-party services strictly necessary for its operation. Each provider operates with its own infrastructure and policies. The application does not control the internal operation or technical decisions of these services. The use of cookies or equivalent identifiers by third parties is outside the direct responsibility of the application. To the extent permitted by law, the application assumes no responsibility for the actions of such third parties.
Contact
Continued use of the application implies full and conscious acceptance of this policy.