Privacy Policy

Last updated: August 2, 2026

The Short Version: Gospel Grasp is a Bible study app. We collect the minimum data needed to make it work. We do not sell your data. We do not use your data for advertising. We do not share it with anyone except the services that help us run the app (listed below).

Who We Are

Gospel Grasp is operated by ApeWare. If you have any questions about this policy, contact us at: privacy@gospelgrasp.com

What We Collect and Why

Account Information

  • What: Email address and password (stored as a secure hash — we never see your actual password).
  • Why: To create and manage your account, allow you to sign in, and sync your data across devices.
  • Stored: On our servers (hosted by Vercel and Turso).

Your Consent

  • What: Creating a Gospel Grasp account requires your affirmative consent to our processing of your study data — notes, highlights, reading activity, and sermon content — which may reflect your religious beliefs. We ask for this with an explicit checkbox at signup; we do not infer or assume consent.
  • Why: Study activity in a Bible app can reveal religious beliefs, which privacy law (including GDPR Article 9) treats as a special category of data requiring your explicit consent before we may process it.
  • Withdrawing consent: You can withdraw consent at any time by deleting your account (Account → Delete Account). See Data Retention below for what happens to your data once you do.
  • Under 13: Account creation requires confirming you are 13 or older. We do not knowingly collect personal information from children under 13 — see Children below.

Reading Data

  • What: Your current book and chapter position, Bible version preference, theme preference.
  • Why: To restore your place when you return to the app.
  • Stored: On your device and synced to our servers.

Highlights and Notes

  • What: Verses you have highlighted (with colors and categories) and any notes you have written.
  • Why: To save and display your personal study work.
  • Stored: On your device first (offline-first), synced to our servers when online.
  • Note text is end-to-end encrypted: the text of your notes is encrypted on your device before it is synced. Our servers store only the encrypted form, and the keys needed to read it exist only on your devices — so we cannot read your notes, even if we wanted to or were asked to. Note details we can see are limited to metadata: which verse a note is attached to, its tags, and when it was created or edited.

Usage Analytics

  • What: Usage activity — which books, chapters, and verses you read, highlight, or write notes against, the highlight category used, and how long/often you study. For AI studies, we record the study passage, translation, account tier, how access was granted, where it was opened, and when it was viewed. This is metadata about your activity, not its contents.
  • Account association: Some operational usage records, including AI-study views and saved-study credits, are linked to your account so we can enforce access accurately, prevent duplicate charges, restore saved studies, and include them in account export and deletion.
  • What we do NOT collect: the text of your notes. Note text is end-to-end encrypted on every plan, free and paid alike — we cannot read or analyze the words you write, because we do not hold the keys. We only count that a note exists and which verse it is attached to.
  • Why: To understand how the app is used so we can decide which features to build. Aggregated across users, this tells us (for example) which passages are most studied.
  • How: Recorded on your device and sent to our servers when you are online. Applies to all accounts, including free. We also use Mixpanel for product analytics.

4F Program Data (Opt-In Only)

  • What: Daily reading session timestamps and duration — specifically how many days per week you read and for how long.
  • Why: To verify eligibility for the Free for Faithful Followers (4F) program, which grants Pro features to users who maintain a consistent Bible study habit.
  • How: Engagement signals (session, idle, scroll, and app-visibility timing — never mouse movements or note contents) are processed on your device using a cryptographic integrity chain. Raw events stay on your device and are deleted after 48 hours. Only a compact daily summary (date, minutes studied, sessions count, verification score) is synced to our servers for eligibility verification.
  • Important: This tracking is entirely opt-in. If you do not enroll in 4F, none of this data is collected. You can leave the 4F program at any time in Settings; your server-side 4F study data is deleted within 7 days of withdrawal.

Sermon Recordings (Pro and 4F)

  • What: Audio recordings you make within the app.
  • Why: To generate AI-powered transcriptions and summaries of your sermons.
  • How: On supported devices, transcription happens entirely on your device using Apple's speech frameworks, and the transcript is uploaded to your account. Otherwise, audio is temporarily uploaded to our storage (Cloudflare R2) and sent to OpenAI for transcription (via OpenAI's Whisper API), and the resulting transcript and summary are stored in your account. The raw audio is deleted from our servers after processing.
  • Third party: When cloud transcription is used, OpenAI processes your audio under their own privacy policy (openai.com/privacy). We use the API, which means your audio is not used to train OpenAI's models. On-device transcription never sends your audio to OpenAI.

AI Features (Pro and 4F)

  • What: Bible passages or sermon transcripts processed by AI-powered features (e.g., sermon summaries, AI study context).
  • Why: To generate AI responses relevant to your study.
  • How: Your input is sent to OpenAI's or Anthropic's API for processing, depending on the feature. Responses are returned and stored in your account. Neither provider trains their models on API data.

Device Information

  • What: A unique device identifier (generated on first launch, stored in your device's secure keychain).
  • Why: To associate your offline data with your account during sync, and for basic account security.
  • Not: This is not your device's IDFA or advertising identifier. It cannot be used to track you across apps.

Note Encryption Keys, Passkeys, and Device Linking

  • What: Encrypted ("wrapped") copies of your note key, and — if you use a passkey — the passkey's public key, its credential ID, a signature counter, and which transports it supports.
  • Why: So your notes can be unlocked on each of your own devices without us ever holding the key that decrypts them.
  • What we never receive: your fingerprint, face, or any other biometric data — those stay in your device's own secure hardware and are never sent to us. We also never receive your note key, your recovery code, or the secret your passkey derives.
  • Linking a new browser: when you use the QR code to unlock notes in a browser, we briefly relay a temporary public key and an encrypted key package between that browser and your phone, along with the browser's user-agent string so you can see what you are approving. These records are single-use and expire shortly after they are created.

Analytics (Mixpanel)

We use Mixpanel to understand how the app is used — for example, which features are most popular. Our analytics events do not include your search queries, note contents, or any other personally identifiable content, and we do not use analytics data for advertising. See Mixpanel's privacy policy at mixpanel.com/legal/privacy-policy.

Crash Reporting & Diagnostics (Sentry)

We use Sentry to detect crashes and errors so we can fix problems quickly. When the app encounters a problem, we may receive a technical crash report and a session replay showing how the app was being used when it happened. When you are signed in, a report may include your Gospel Grasp account ID and email address so support can identify the affected account and contact you about the problem. Your personal study content is redacted on your device before anything is sent: the text of your notes, your photos, your password and other authentication secrets, and AI study conversations never appear in diagnostics. See Sentry's privacy policy at sentry.io/privacy.

What We Do NOT Collect

  • We do not collect your name (unless you choose to add it to your profile).
  • We do not collect your location.
  • We do not access your contacts, camera, or microphone except when you explicitly use the sermon recording feature.
  • We do not collect advertising identifiers.
  • We do not track you across other apps or websites.

How We Use Your Data

  1. Provide, operate, and improve the Gospel Grasp app
  2. Sync your highlights, notes, and reading position across your devices
  3. Verify 4F eligibility (opt-in only)
  4. Power AI features you explicitly invoke
  5. Send you account-related emails (password resets, subscription receipts)

Today we only send account-related transactional email (password resets, receipts). If we ever introduce product-update or marketing email, every such email will include a one-click unsubscribe link.

Who We Share Your Data With

We share your data only with the following service providers, and only to the extent necessary to run the app:

ProviderPurposePrivacy Policy
VercelApp hosting and backend APIvercel.com/legal/privacy-policy
Turso (ChiselStrike)Database storageturso.tech/privacy
Cloudflare R2File storage (temporary sermon audio, map data)cloudflare.com/privacypolicy
OpenAISermon transcription and AI featuresopenai.com/privacy
AnthropicAI study features (e.g. study summaries)anthropic.com/legal/privacy
MixpanelProduct analytics (no personal content in events)mixpanel.com/legal/privacy-policy
SentryCrash reporting and diagnostics (signed-in account ID and email included; personal study content redacted)sentry.io/privacy
ResendTransactional email (password resets, receipts)resend.com/legal/privacy-policy

We do not sell your data. Ever. We do not share your data with advertisers, data brokers, or marketing companies.

Data Retention

  • Active account: Your data is retained as long as your account is active.
  • Deleted account: When you delete your account, it is immediately deactivated (you are signed out everywhere and can no longer sign in), and all of your data (including highlights, notes, reading history, AI-study view and credit records, 4F records, sermon recordings, and transcripts) is permanently deleted from our servers within 30 days. That includes the encrypted note key material and any passkey public keys registered to your account — nothing that could be used to identify or unlock your notes outlives the account. If you deleted your account by mistake, contact us within those 30 days and we can restore it.
  • Sermon audio: Raw audio is deleted from our servers immediately after transcription is complete (typically within minutes).
  • Device data: Deleting the app removes all locally stored data from your device.
  • Device-linking records: The temporary records created when you unlock notes in a new browser (the QR handoff) are single-use and expire automatically a short time after they are created, whether or not they are used.

Your Rights

You have the right to:

  • Access & export your data — use Account → Export My Data in the app to download a complete copy (JSON) of the data associated with your account at any time. Because we cannot read your notes, the export is assembled on your device: your notes are decrypted there and written into the file as readable text, which also means anyone who opens that file can read them. Exporting from a device that does not hold your note key still gives you everything else, with the notes included in encrypted form. You can also email us at the address below.
  • Delete your account and all associated data — Account → Delete Account in the app.
  • Opt out of 4F tracking at any time by withdrawing from the 4F program in the app.
  • Contact us with any privacy questions at the email above.

If you are in the European Union, you have additional rights under GDPR. Contact us to exercise them.

Children

Gospel Grasp is not directed at children under 13. We do not knowingly collect personal information from children under 13. If you believe a child has provided us with personal information, please contact us and we will delete it promptly.

AI and Your Data

We want to be transparent about AI. When you use Gospel Grasp's AI features:

  • Your input (Bible text, sermon audio, questions) is sent to OpenAI's API (transcription and some AI features) or Anthropic's API (some AI study features).
  • The provider processes it and returns a response.
  • Neither OpenAI nor Anthropic uses API inputs to train their models (per each provider's API data usage policy as of the date of this policy).
  • We do not use your data to train any AI models.

Security

We use industry-standard security practices:

  • Passwords are hashed (never stored in plain text)
  • Data in transit is encrypted (HTTPS/TLS)
  • The 4F event chain uses SHA-256 cryptographic hashing for tamper resistance
  • Device identifiers are stored in the iOS Keychain
  • Notes are end-to-end encrypted (AES-256): note text is encrypted on your device before syncing, and decryption keys never leave your devices. Keys are kept in your device's secure keychain and, on Apple devices, synced between your own devices via iCloud Keychain. On the web, your passkey unlocks your notes.

Because we do not hold your note keys, we also cannot recover your note text for you. If you lose access to all of your devices, your iCloud Keychain, and your optional recovery code, your encrypted notes cannot be recovered — by design. Your account, highlights, and reading history are unaffected.

No system is perfectly secure. If you discover a security issue, please contact us directly before disclosing it publicly.

Changes to This Policy

If we make material changes to this policy, we will notify you via the app or by email before the changes take effect. The "last updated" date at the top of this page will always reflect the most recent version.

Contact

Questions? Concerns? Email us:

privacy@gospelgrasp.com

We will respond within 5 business days.