This policy explains what BIBLESCROLL collects, why it collects it, who processes it on our behalf, and how you can see, correct or delete it. It is written to be read, not to be survived.
Política de Privacidad
Esta política explica qué recoge BIBLESCROLL, por qué lo recoge, quién lo procesa en nuestro nombre y cómo podés verlo, corregirlo o eliminarlo. Está escrita para leerse, no para sobrevivirla.
Effective8 August 2026Version1.0Applies tobiblescroll.app · BIBLESCROLL for iOS
Privacy at a glance
You can read the entire Bible without an account. No email, no sign-up wall, nothing sent anywhere.
Your notes and favourites stay on your phone until you choose to sign in and sync them.
We never sell or rent your personal data. Not to advertisers, not to data brokers, not to anyone.
Analytics never carry what you wrote. Note text, verse text and search queries are stripped before an event leaves the device.
Ad tracking is off unless you allow it in the iOS permission prompt. Saying no changes nothing about the app.
You can delete your account and all of its data from inside the app, in two taps.
01Who we are
BIBLESCROLL is a Bible reading app for iPhone, published by [LEGAL ENTITY NAME], registered at [REGISTERED ADDRESS] (“we”, “us”, “BIBLESCROLL”). We are the data controller for the personal data described in this policy.
This policy covers the BIBLESCROLL mobile app and the website at biblescroll.app. It does not cover the App Store itself, or any third-party site we link to.
BIBLESCROLL is built local-first. The complete Berean Standard Bible ships inside the app, so reading, searching, favouriting and note-taking all work with the network switched off, and without an account.
Personal data only enters the picture when you actively do one of four things: sign in, turn on notifications, subscribe, or ask for an AI study of a verse. Everything else — crash reports and product analytics — is limited, stripped of anything you wrote, and switchable.
03What stays on your device
Until you sign in, the following never leaves your phone. It is stored in the app’s private storage and is removed when you delete the app:
The verse you are currently reading, and which chapters you have finished
Your favourites and the full text of your notes
Your reading streak and the dates you opened the app
Your active reading plan and its progress
Preferences: font size, playback mode and speed, word highlighting, reduced motion
Cached study results, so a verse you already studied opens instantly and offline
Worth knowing
Deleting the app deletes this local data permanently. If you have never signed in, we hold no copy of it and cannot restore it.
04What we collect
Data you give us
Data
When
Why
Email address
Only if you sign in with an email link, Apple or Google
To authenticate you and to attach your library to an account
Display name
Only if you set one
To personalise the profile screen
Your notes, favourites, read chapters, streak, plan progress and preferences
Only after you sign in, so they can sync
To restore your library on a new device and keep it backed up
Support messages
When you email us or use the contact form
To answer you. Includes app version, iOS version and device model when sent from the app
Data collected automatically
Data
Collected by
Can you turn it off?
Product interaction events — such as opening the app, finishing a chapter, starting a plan, requesting a study, opening the paywall
Amplitude
Yes. Analytics consent in Profile. Off means no events are sent
Crash and error reports — stack traces, app version, device model, OS version
Sentry
Sampled at 5% for performance traces. Personal details are removed before sending
Device identifiers for attribution — including the advertising identifier
AppStack
Yes. Only collected if you allow tracking in the iOS prompt
Purchase history — which subscription you hold and when it renews
RevenueCat, via Apple
No, this is required to give you what you paid for
Push subscription — a device token
OneSignal
Yes. Only created if you turn notifications on
Technical logs — IP address and timestamps when the app streams narration audio or requests a study
Our hosting providers
No, this is inherent to any network request
What we deliberately do not collect
Analytics events are filtered on the device before they are sent. Any property whose name looks like personal or scriptural content — note, text, query, email, name, verse, reference, faith or denomination — is removed. So we can see that a study was requested, or that a search happened; we cannot see the verse you studied or the words you searched for.
The same applies to crash reports: the note body, verse text and search query are explicitly deleted before an error leaves your phone, and the user record attached to a crash is reduced to an opaque account ID.
We do not collect your contacts, photos, location, calendar, microphone or health data. The app never asks for them.
05Why we are allowed to
If you are in the European Economic Area or the United Kingdom, we rely on these legal bases under the GDPR:
Performance of a contract — running your account, syncing your library, and delivering a subscription you bought.
Consent — product analytics, push notifications and advertising attribution. You give it explicitly, and you can withdraw it at any time in Profile or in iOS Settings, without losing access to the app.
Legitimate interests — keeping the app stable and secure through crash reporting, and preventing abuse of the study service. We limit what is collected so this stays proportionate.
Legal obligation — keeping transaction records where tax or consumer law requires it.
06Who processes it
We use a small number of providers, each for one job. They act on our instructions and may not use your data for their own purposes.
Provider
What it does
What it receives
Supabase
Accounts, database, server functions
Email, account ID, and the library you chose to sync
Apple
App distribution, Sign in with Apple, payments
Purchase and subscription data; an email or private relay address if you use Sign in with Apple
Google
Sign in with Google, if you choose it
Email address and basic profile
RevenueCat
Subscription state
Account ID, purchase receipts, subscription status
Amplitude
Product analytics
Filtered interaction events and an account ID — only with your consent
Sentry
Crash and error reporting
Stack traces, device and app version, an account ID
OneSignal
Push notifications
Device push token and an account ID — only if you enable notifications
AppStack
Marketing attribution
Device identifiers — only if you allow tracking
OpenAI
Generating study material on request
The verse reference, the verse text and which study mode you picked. No account identifiers
We will update this list before adding a provider that changes what is collected.
07The AI study feature
When you tap the mark in the middle of the reader and choose Explain Easier, Deeper Study or Related Verses, the app asks our server for study material. That request contains the verse reference, the verse text from the public-domain Berean Standard Bible, and which of the three modes you picked. Our server forwards it to OpenAI, checks the response is well-formed, and sends it back.
The request is not tied to your account, your notes, or anything else you have read.
No AI credential is ever embedded in the app; the key lives only on our server.
If the network fails or the model is unavailable, the app falls back to study guides bundled inside the app, and labels the result OFFLINE GUIDE instead of AI STUDY.
Results are cached on your device so the same verse opens instantly next time, offline.
A limit worth stating
AI study material is supplemental and can be wrong. It is meant to make a verse clearer, never to replace pastoral, scholarly, medical, legal or financial guidance.
08Tracking and advertising
On first launch iOS asks whether BIBLESCROLL may track you across apps and websites owned by other companies. If you say no — or if you never answer — no advertising identifier is collected and no attribution data is sent. Nothing in the app is withheld, degraded or nagged about as a result.
If you say yes, our attribution provider receives device identifiers so we can tell which advertisement led you to install the app. You can change your mind at any time in iOS Settings → Privacy & Security → Tracking.
We do not show advertisements inside BIBLESCROLL, and we do not sell or share personal information for cross-context behavioural advertising as those terms are defined under California law.
09Notifications
Push notifications are off until you turn them on. Consent is requested before our notification provider is allowed to collect anything, so declining means no device token is ever created. Turning them off later, either in Profile or in iOS Settings, opts the device out.
10How long we keep it
Account and synced library — until you delete your account, then removed from our live systems immediately and from backups within 30 days.
Analytics events — retained in aggregate; identifiers are removed after 25 months.
Crash reports — 90 days.
Support correspondence — 24 months, so we can follow up on a recurring problem.
Purchase records — as long as tax and consumer-protection law requires, usually up to 10 years.
11International transfers
Our providers operate in the United States and the European Union, so your data may be processed outside your country. Where data leaves the EEA or the UK, transfers are covered by the European Commission’s Standard Contractual Clauses, the UK Addendum, or an adequacy decision, together with technical measures such as encryption in transit and at rest.
12Your rights
Wherever you live, you can ask us to give you a copy of your data, correct it, delete it, restrict how we use it, or object to a particular use. In the EEA and UK these are GDPR rights; in California they are rights under the CCPA/CPRA; several other jurisdictions grant equivalents.
The fastest routes:
Delete everything — Profile → Delete account, then type DELETE to confirm. This removes your account and all synced data. There is also a web form if you have already removed the app.
Withdraw analytics or notification consent — Profile, at any time.
Get a copy, correct something, or anything else — email support@biblescroll.app. We answer within 30 days and never charge for a reasonable request.
We will never treat you differently for exercising a right. If you think we have handled your data badly, please tell us first — but you are entitled to complain directly to your local data protection authority.
13Children
BIBLESCROLL is not directed at children under 13, and we do not knowingly collect personal data from them. In the EEA, creating an account requires you to be at least 16, or to have permission from a parent or guardian. Reading the Bible in the app requires no account at all and collects nothing. If you believe a child has given us personal data, write to us and we will delete it.
14Security
Data is encrypted in transit with TLS and at rest by our providers. Database access is restricted per user through row-level security, so one account cannot read another’s library. The app holds no third-party API secrets: anything requiring a credential runs on our server instead. We keep the number of people with production access small.
No system is perfect. If we discover a breach affecting your personal data, we will notify the relevant supervisory authority within 72 hours and tell you directly where the law requires it.
15Changes to this policy
When we change this policy we update the effective date above and raise the version number. For changes that materially affect your rights or expand what we collect, we will tell you in the app before the change takes effect, and ask for fresh consent where consent is the basis we rely on.
Postal address: [LEGAL ENTITY NAME, REGISTERED ADDRESS].
La privacidad de un vistazo
Se puede leer la Biblia entera sin cuenta. Sin correo, sin muro de registro, sin enviar nada a ningún lado.
Tus notas y favoritos quedan en tu teléfono hasta que decidas iniciar sesión y sincronizarlos.
Nunca vendemos ni alquilamos tus datos personales. Ni a anunciantes, ni a intermediarios de datos, ni a nadie.
La analítica nunca lleva lo que escribiste. El texto de las notas, el de los versículos y las búsquedas se eliminan antes de que el evento salga del dispositivo.
El seguimiento publicitario está apagado salvo que lo permitas en el aviso de iOS. Decir que no no cambia nada de la app.
Podés eliminar tu cuenta y todos sus datos desde la app, en dos toques.
01Quiénes somos
BIBLESCROLL es una app de lectura bíblica para iPhone, publicada por [NOMBRE DE LA ENTIDAD LEGAL], con domicilio en [DOMICILIO REGISTRADO] («nosotros», «BIBLESCROLL»). Somos el responsable del tratamiento de los datos personales descritos en esta política.
Esta política cubre la app móvil BIBLESCROLL y el sitio biblescroll.app. No cubre la App Store en sí, ni ningún sitio de terceros al que enlacemos.
BIBLESCROLL está construida priorizando lo local. La Berean Standard Bible completa viaja dentro de la app, así que leer, buscar, guardar favoritos y escribir notas funciona con la red apagada y sin cuenta.
Los datos personales entran en juego solo cuando hacés activamente una de cuatro cosas: iniciar sesión, activar las notificaciones, suscribirte o pedir un estudio con IA de un versículo. Todo lo demás —reportes de fallos y analítica de producto— es limitado, está despojado de todo lo que escribiste y se puede apagar.
03Qué se queda en tu dispositivo
Hasta que inicies sesión, lo siguiente nunca sale de tu teléfono. Se guarda en el almacenamiento privado de la app y desaparece cuando la eliminás:
El versículo que estás leyendo y qué capítulos terminaste
Tus favoritos y el texto completo de tus notas
Tu racha de lectura y los días que abriste la app
Tu plan de lectura activo y su progreso
Preferencias: tamaño de letra, modo y velocidad de reproducción, resaltado de palabras, movimiento reducido
Resultados de estudio en caché, para que un versículo ya estudiado abra al instante y sin conexión
Conviene saberlo
Eliminar la app borra estos datos locales de forma permanente. Si nunca iniciaste sesión, no tenemos ninguna copia y no podemos restaurarlos.
04Qué recogemos
Datos que nos das
Dato
Cuándo
Para qué
Dirección de correo
Solo si iniciás sesión con enlace por correo, Apple o Google
Para autenticarte y vincular tu biblioteca a una cuenta
Nombre visible
Solo si configurás uno
Para personalizar la pantalla de perfil
Tus notas, favoritos, capítulos leídos, racha, progreso de planes y preferencias
Solo después de iniciar sesión, para que se sincronicen
Para restaurar tu biblioteca en otro dispositivo y mantenerla respaldada
Mensajes de soporte
Cuando nos escribís o usás el formulario
Para responderte. Incluye versión de la app, versión de iOS y modelo de dispositivo si se envía desde la app
Datos recogidos automáticamente
Dato
Recogido por
¿Se puede apagar?
Eventos de interacción — abrir la app, terminar un capítulo, empezar un plan, pedir un estudio, abrir el paywall
Amplitude
Sí. Consentimiento de analítica en Perfil. Apagado significa que no se envía ningún evento
Reportes de fallos y errores — trazas, versión de la app, modelo de dispositivo, versión del sistema
Sentry
Muestreo del 5% para trazas de rendimiento. Los datos personales se eliminan antes de enviarse
Identificadores de dispositivo para atribución — incluido el identificador publicitario
AppStack
Sí. Solo se recoge si permitís el seguimiento en el aviso de iOS
Historial de compras — qué suscripción tenés y cuándo se renueva
RevenueCat, vía Apple
No: es necesario para darte lo que pagaste
Suscripción push — un token de dispositivo
OneSignal
Sí. Solo se crea si activás las notificaciones
Registros técnicos — dirección IP y marcas de tiempo cuando la app transmite el audio o pide un estudio
Nuestros proveedores de alojamiento
No: es inherente a cualquier petición de red
Lo que deliberadamente no recogemos
Los eventos de analítica se filtran en el dispositivo antes de enviarse. Se elimina cualquier propiedad cuyo nombre parezca contenido personal o bíblico: nota, texto, consulta, correo, nombre, versículo, referencia, fe o denominación. Podemos ver que se pidió un estudio, o que hubo una búsqueda; no podemos ver qué versículo estudiaste ni qué palabras buscaste.
Lo mismo vale para los reportes de fallos: el cuerpo de la nota, el texto del versículo y la consulta de búsqueda se eliminan explícitamente antes de que un error salga de tu teléfono, y el registro de usuario adjunto se reduce a un identificador opaco de cuenta.
No recogemos tus contactos, fotos, ubicación, calendario, micrófono ni datos de salud. La app nunca los pide.
05Por qué podemos hacerlo
Si estás en el Espacio Económico Europeo o el Reino Unido, nos basamos en estas bases legales del RGPD:
Ejecución de un contrato — mantener tu cuenta, sincronizar tu biblioteca y entregar la suscripción que compraste.
Consentimiento — analítica de producto, notificaciones push y atribución publicitaria. Lo das de forma explícita y podés retirarlo cuando quieras desde Perfil o los Ajustes de iOS, sin perder acceso a la app.
Interés legítimo — mantener la app estable y segura mediante reportes de fallos, y evitar el abuso del servicio de estudio. Limitamos lo que se recoge para que siga siendo proporcionado.
Obligación legal — conservar registros de transacciones cuando lo exige la normativa fiscal o de consumo.
06Quién lo procesa
Usamos un número reducido de proveedores, cada uno para una sola tarea. Actúan siguiendo nuestras instrucciones y no pueden usar tus datos para fines propios.
Proveedor
Qué hace
Qué recibe
Supabase
Cuentas, base de datos, funciones de servidor
Correo, identificador de cuenta y la biblioteca que elegiste sincronizar
Apple
Distribución de la app, Iniciar sesión con Apple, pagos
Datos de compra y suscripción; un correo o dirección de retransmisión privada si usás Iniciar sesión con Apple
Google
Iniciar sesión con Google, si lo elegís
Dirección de correo y perfil básico
RevenueCat
Estado de la suscripción
Identificador de cuenta, recibos de compra, estado de suscripción
Amplitude
Analítica de producto
Eventos de interacción filtrados y un identificador de cuenta, solo con tu consentimiento
Sentry
Reportes de fallos y errores
Trazas, versión de dispositivo y app, un identificador de cuenta
OneSignal
Notificaciones push
Token push del dispositivo y un identificador de cuenta, solo si activás las notificaciones
AppStack
Atribución de marketing
Identificadores de dispositivo, solo si permitís el seguimiento
OpenAI
Generar material de estudio a pedido
La referencia del versículo, su texto y el modo de estudio elegido. Ningún identificador de cuenta
Actualizaremos esta lista antes de incorporar un proveedor que cambie lo que se recoge.
07La función de estudio con IA
Cuando tocás la marca del centro del lector y elegís Explicar más fácil, Estudio profundo o Versículos relacionados, la app le pide a nuestro servidor el material de estudio. Esa petición contiene la referencia del versículo, su texto según la Berean Standard Bible de dominio público y cuál de los tres modos elegiste. Nuestro servidor la reenvía a OpenAI, verifica que la respuesta esté bien formada y la devuelve.
La petición no está vinculada a tu cuenta, tus notas ni nada más que hayas leído.
Ninguna credencial de IA viaja dentro de la app: la clave vive solo en nuestro servidor.
Si falla la red o el modelo no está disponible, la app recurre a las guías incluidas en la app y etiqueta el resultado como OFFLINE GUIDE en lugar de AI STUDY.
Los resultados quedan en caché en tu dispositivo, así el mismo versículo abre al instante la próxima vez, sin conexión.
Un límite que conviene decir
El material de estudio con IA es complementario y puede equivocarse. Busca aclarar un versículo, nunca reemplazar la guía pastoral, académica, médica, legal o financiera.
08Seguimiento y publicidad
En el primer inicio, iOS pregunta si BIBLESCROLL puede seguirte a través de apps y sitios de otras empresas. Si decís que no —o si nunca respondés— no se recoge ningún identificador publicitario ni se envía dato de atribución alguno. Nada de la app se retiene, se degrada ni se te vuelve a insistir por eso.
Si decís que sí, nuestro proveedor de atribución recibe identificadores de dispositivo para saber qué anuncio llevó a la instalación. Podés cambiar de opinión cuando quieras en Ajustes de iOS → Privacidad y seguridad → Seguimiento.
No mostramos publicidad dentro de BIBLESCROLL, y no vendemos ni compartimos información personal para publicidad conductual entre contextos, según se definen esos términos en la legislación de California.
09Notificaciones
Las notificaciones push están apagadas hasta que las activás. El consentimiento se solicita antes de que nuestro proveedor pueda recoger nada, así que rechazarlas significa que nunca se crea un token de dispositivo. Apagarlas más tarde, desde Perfil o desde los Ajustes de iOS, da de baja al dispositivo.
10Cuánto tiempo lo conservamos
Cuenta y biblioteca sincronizada — hasta que elimines tu cuenta; entonces se borra de los sistemas activos de inmediato y de las copias de seguridad en un plazo de 30 días.
Eventos de analítica — se conservan de forma agregada; los identificadores se eliminan a los 25 meses.
Reportes de fallos — 90 días.
Correspondencia de soporte — 24 meses, para poder dar seguimiento a un problema recurrente.
Registros de compra — mientras lo exija la normativa fiscal y de protección al consumidor, habitualmente hasta 10 años.
11Transferencias internacionales
Nuestros proveedores operan en Estados Unidos y la Unión Europea, así que tus datos pueden procesarse fuera de tu país. Cuando los datos salen del EEE o del Reino Unido, las transferencias se amparan en las Cláusulas Contractuales Tipo de la Comisión Europea, el Addendum del Reino Unido o una decisión de adecuación, junto con medidas técnicas como el cifrado en tránsito y en reposo.
12Tus derechos
Vivas donde vivas, podés pedirnos una copia de tus datos, su corrección, su eliminación, la limitación de su uso, o oponerte a un uso concreto. En el EEE y el Reino Unido son derechos del RGPD; en California, derechos de la CCPA/CPRA; varias otras jurisdicciones reconocen equivalentes.
Las vías más rápidas:
Eliminar todo — Perfil → Eliminar cuenta, y escribir DELETE para confirmar. Esto borra tu cuenta y todos los datos sincronizados. También hay un formulario web si ya desinstalaste la app.
Retirar el consentimiento de analítica o notificaciones — en Perfil, cuando quieras.
Obtener una copia, corregir algo o cualquier otra cosa — escribí a support@biblescroll.app. Respondemos en un plazo de 30 días y nunca cobramos por una solicitud razonable.
Nunca te trataremos distinto por ejercer un derecho. Si creés que gestionamos mal tus datos, decínoslo primero, pero tenés derecho a reclamar directamente ante tu autoridad de protección de datos.
13Menores
BIBLESCROLL no está dirigida a menores de 13 años y no recogemos deliberadamente datos personales de ellos. En el EEE, crear una cuenta exige tener al menos 16 años o contar con permiso de un padre, madre o tutor. Leer la Biblia en la app no requiere cuenta alguna y no recoge nada. Si creés que un menor nos dio datos personales, escribinos y los eliminaremos.
14Seguridad
Los datos se cifran en tránsito con TLS y en reposo por parte de nuestros proveedores. El acceso a la base de datos está restringido por usuario mediante seguridad a nivel de fila, de modo que una cuenta no puede leer la biblioteca de otra. La app no contiene secretos de API de terceros: todo lo que requiere una credencial se ejecuta en nuestro servidor. Mantenemos reducido el número de personas con acceso a producción.
Ningún sistema es perfecto. Si detectamos una brecha que afecte a tus datos personales, lo notificaremos a la autoridad de control competente en un plazo de 72 horas y te lo comunicaremos directamente cuando la ley lo exija.
15Cambios en esta política
Cuando cambiemos esta política actualizaremos la fecha de vigencia de arriba y subiremos el número de versión. Para cambios que afecten materialmente a tus derechos o amplíen lo que recogemos, te avisaremos dentro de la app antes de que entren en vigor y pediremos un consentimiento nuevo cuando sea esa la base en la que nos apoyamos.