Bible Reply Privacy Policy

Last updated: August 28, 2026

1. Introduction

Bible Reply ("we", "our", "us") is committed to protecting your privacy. This Privacy Policy explains how we handle information when you use our mobile application.

2. Information We Collect and Process

We design the app to handle as little data as possible. The daily verse and the home-screen widget work without any account; saving bookmarks and using the AI devotional feature use Sign in with Apple to keep your content under a private account (see below). We do not collect your name, email, phone number, or contact details. Specifically:

Exception — AI Devotional Feature: When you use the AI devotional feature, your text input is transmitted to our server and processed by a third-party AI provider to generate your devotional. The input is never written to any server log; it is stored only as part of your devotional history under your account (up to 50 entries — see Section 3), where you can revisit or delete it. See Section 4 for details.

Operational & Security Data: To verify subscriptions and entitlements and to prevent abuse, our server records a stable, anonymous, app-scoped identifier issued by Sign in with Apple (of the form apple_<sub>, derived from Apple's user identifier for this app; it contains no name or email), your subscription-entitlement binding (an Apple transaction identifier), a per-device public key issued by Apple's App Attest service, and the requesting IP address. These are used solely for entitlement verification, rate limiting, and abuse prevention — they are not linked to your name, email, or any other identity, and are not used for any other purpose. The app identifier, entitlement binding, and device public key are stored in a managed database hosted in the European Union, so these checks survive server restarts; they are removed when you delete your account in the app. The requesting IP address is held only in the server's volatile memory for as long as needed for these checks, is never written to the database, and is cleared whenever the server process restarts; it may also appear in standard operational and security logs retained by our hosting provider (Render) for its standard log retention period — currently about 7 days on our (free) plan, and up to about 30 days if the plan is upgraded.

Error reports: If the app crashes or hits an unexpected error, it may send a technical report to our own server (app platform, app version, error type, error message, and stack trace). These reports contain no account identifier and no devotional content — long passages of your own text that could appear inside an error message are automatically redacted before anything leaves your device. Reports go only into our hosting provider's standard logs (retention as above) and are never stored in a database.

Account identifier stored on your device: For the optional AI devotional feature, Sign in with Apple gives our server a stable, anonymous identifier (never your email or name). A copy of this anonymous identifier is kept in your device's secure keychain so that your session is preserved when you reinstall the app on the same device. Our server also retains this anonymous identifier (together with the entitlement binding and device public key described above) in its EU-hosted database, solely for entitlement verification and abuse prevention. It is not used for tracking and is not shared with advertisers. Signing out clears the local copy; deleting your account from within the app removes both the local copy and the server-side records. The Apple ID credential itself is managed by you under your device's Apple ID settings.

Sign in with Apple (AI feature, optional): To use the AI devotional feature, the app offers Sign in with Apple. We request no scopes, so Apple provides our server only a stable, anonymous user identifier (never your email or name). Our server verifies Apple's cryptographic signature on this identifier and issues its own short-lived session. Your subscription entitlement is verified directly from the Apple-signed StoreKit 2 transaction your device presents — never via a third party — so it is bound to your verified identity and cannot be impersonated. You can use the app fully without signing in except for the AI feature, and you can delete your account at any time in Settings (this clears our cached session and entitlement data; the Apple ID credential itself, and any active subscription, are managed by you under your device's Apple ID settings).

3. Where Your Content Is Stored

The following data is stored only on your device and is never sent to our servers:

You can clear this local data at any time via the app's "Reset App Settings" action or by deleting the app.

Your bookmarks and devotional history (account data, sign-in required): When you are signed in, your bookmarked verses and your recent AI devotionals — including the situation text you entered — are stored on our servers in a managed database hosted in the European Union, so they follow you when you reinstall the app or move to a new device. Each list holds at most 50 entries (nothing is auto-deleted; you manage the list yourself). You can remove individual history entries in the app (long-press a recent entry), and deleting your account in Settings removes all of them. Crisis-help responses are never saved to your history.

4. AI-Generated Devotional Content

When you use the AI devotional feature, the following occurs:

Legal basis for processing (European users): Under the EU General Data Protection Regulation (GDPR), we process your text input for AI devotionals based on Article 9(2)(a) — your explicit consent, given when you read the consent disclosure and start using the app (or, if you skip past it, the first time you tap "Generate"). You may withdraw this consent at any time — see "Withdrawing AI consent" in Section 9. Withdrawal does not affect the lawfulness of processing before withdrawal.

Automated decision-making: The AI devotional is generated entirely by automated means without human review. Under GDPR Article 22, you have the right not to be subject to a decision based solely on automated processing where it produces legal effects or similarly significantly affects you. The devotional content is presented as encouragement only — it does not constitute professional advice (medical, mental-health, legal, or financial) and is not used to make any decision about you as an individual. If you object to receiving AI-generated content without human oversight, please do not use this feature.

Data controller and processor: For purposes of applicable data-protection law, we (the app developer) are the data controller — we decide what data is processed and why. Mistral AI (a French/European company) is the data processor, acting on our instructions to generate the devotional content. Your relationship with Mistral is governed by Mistral's own privacy policy and terms.

Where your input is processed: Our backend servers are located in the European Union (Frankfurt, Germany). When you use the AI devotional feature, your text input is transmitted to these EU-based servers, and our AI provider (Mistral) also processes it in the European Union (EU data residency is Mistral's default). After your devotional is generated, the input lives only in your account's devotional history (see Section 3) — never in any server log.

Data residency and transfers: Your input is processed and stored within the European Union — both our backend (Frankfurt, Germany) and our AI provider (Mistral) operate in the EU. Should any processing ever need to occur outside the EU in the future, we would rely on the Standard Contractual Clauses approved by the European Commission (or an equivalent lawful safeguard). We do not transfer your data to China, or to any jurisdiction lacking an adequate level of data protection.

5. Third-Party Services

Our app uses the following third-party services:

We do not integrate any advertising networks, social media SDKs, or tracking tools.

6. Children's Privacy

The App is not directed to anyone under 18, and we do not knowingly collect personal data from anyone under 18. If we learn we have collected personal data from anyone under 18, we will delete it. If you believe someone under 18 has provided us personal data, contact us at jidutu093@gmail.com.

7. Data Security

We implement appropriate technical measures to protect any data transmitted between your device and our servers, including HTTPS encryption.

8. Changes to This Policy

We may update this Privacy Policy from time to time. Any changes will be reflected on this page with an updated "Last updated" date.

9. Your Regional Privacy Rights

If you are in a region with data-protection laws — such as the CCPA/CPRA (California, United States), the UK-GDPR and EU-GDPR (United Kingdom / European Union), PIPEDA (Canada), the Privacy Act (Australia), or the PDPA (Singapore / Malaysia) — you may have rights over your personal data, including the right to access, correct, or delete it, and to object to or opt out of certain processing. Under these laws, the data described in this policy (such as the anonymous app identifier and IP address in Section 2, and the text you submit to the AI devotional feature in Section 4) may qualify as personal data, so these rights can apply. To exercise any right, or to ask what data we hold about you, contact us at jidutu093@gmail.com and we will respond promptly. Your language and display preferences are stored only on your device, under your sole control; your bookmarks and devotional history are stored under your account on our EU-hosted servers (see Section 3) and are removed when you delete your account.

Response timeline. We respond to verified requests within 30 days; where a request is complex, we may extend this period and will inform you of the extension and the reason.

Right to lodge a complaint (EEA and UK users): If you believe our processing of your personal data infringes data-protection law, you have the right to lodge a complaint with your local data-protection supervisory authority (in particular, in the EU/EEA member state of your habitual residence, place of work, or the place of the alleged infringement). For users in the Netherlands, the supervisory authority is the Autoriteit Persoonsgegevens (autoriteitpersoonsgegevens.nl). We encourage you to contact us first so we can resolve your concern directly.

Limits on deletion: Once your text input has been transmitted to the AI provider to generate a devotional, we cannot access or delete it after the fact — its retention and deletion are governed by the provider's privacy policy. Our server's operational records (Section 2: the anonymous app identifier, the subscription-entitlement binding, and the device public key) are stored in our EU-hosted database; deleting your account from within the app removes them, along with your bookmarks and devotional history (Section 3). One anonymous item is retained after account deletion: a per-day count of AI generations — a number keyed only to the anonymous app identifier, containing no content — kept solely to prevent quota abuse through repeated account deletion. The requesting IP address is held only in volatile memory — never in the database — and may also appear in standard hosting-provider logs retained for a limited operational period. To request deletion of any such log data, contact us.

Withdrawing AI consent: Because your text input is shared with a third-party AI provider (Section 5) to generate devotionals, we obtain your explicit consent first (Section 4). You can withdraw that consent at any time from within the app: open Settings ▸ AI Data Use ▸ Revoke Consent. Once revoked, your input is no longer sent to the AI provider, and you cannot generate AI devotionals until you consent again (the next attempt re-prompts you). The daily verse and bookmarks remain fully available. Note that the separate "Clear All Local Data" action also resets this consent. Withdrawal does not affect the lawfulness of any processing carried out before you withdrew.

10. Contact Us

If you have questions about this Privacy Policy, please contact us at:

Email: jidutu093@gmail.com


圣经有云 隐私政策(简体中文)

最后更新:2026年8月28日

1. 引言

圣经有云("我们")致力于保护您的隐私。本隐私政策说明您使用本移动应用时,我们如何处理信息。

2. 我们收集和处理的信息

本应用在设计上尽可能少地处理数据。每日经文与主屏小组件无需任何账号即可使用;收藏经文与 AI 灵修功能使用 Sign in with Apple(通过 Apple 登录),将您的内容保存在专属账号下(见下文)。我们收集您的姓名、电子邮件、电话号码或联系方式。具体而言:

例外——AI 灵修功能:当您使用 AI 灵修功能时,您的文本输入会传输到我们的服务器,并由第三方 AI 提供商处理以生成灵修内容。输入文本绝不会写入任何服务器日志;它仅作为您账号下的灵修历史的一部分存储(上限 50 条——详见第 3 节),您可随时回看或删除。详见第 4 节。

运营与安全数据:为验证订阅与权益并防止滥用,我们的服务器会记录一个由 Sign in with Apple 签发的稳定的匿名应用级标识符(apple_<sub> 形态,由 Apple 为本应用分配的用户标识派生,不含姓名/邮箱)、您的订阅权益绑定(Apple 交易标识符)、由 Apple App Attest 服务签发的每设备公钥,以及请求 IP 地址。这些信息仅用于权益验证、限流与防滥用——不与您的姓名、邮箱或任何其他身份信息关联,不以其他用途使用。其中,应用标识符、权益绑定与设备公钥保存在一个位于欧盟的托管数据库中,以便这些检查在服务器重启后仍然有效;在应用内删除账号时会一并删除。请求 IP 地址仅保存在服务器的易失性内存中,仅在这些检查所需期间保留,绝不会写入数据库,服务器进程重启时即清除;它也可能出现在托管服务商(Render)按其标准日志保留期——我们当前(免费)套餐约 7 天,升级套餐至多约 30 天——保留的标准运营/安全日志中。

错误上报:当应用崩溃或遇到意外错误时,可能向我们的自有服务器发送一份技术报告(应用平台、应用版本、错误类型、错误消息与堆栈)。这些报告不含账号标识、不含灵修内容——错误消息中若出现您本人输入的大段文字,会在离开设备前被自动打码。报告仅写入托管服务商的标准日志(保留期同上),绝不存入数据库。

存储在您设备上的账号标识:使用可选的 AI 灵修功能时,Sign in with Apple 会向我们的服务器提供一个稳定的匿名标识(绝非您的邮箱或姓名)。该匿名标识的一份副本保存在您设备的安全钥匙串中,以便在同一设备上重装应用后,您的登录会话仍能保留。我们的服务器也会把这个匿名标识(连同上述权益绑定与设备公钥)保存在其位于欧盟的托管数据库中,仅用于权益验证与防滥用。该标识不用于追踪,也不与广告商共享。退出登录会清除本地副本;在应用内删除账号会同时删除本地副本与服务端记录。Apple ID 凭据本身由您在设备的 Apple ID 设置中管理。

Sign in with Apple(AI 功能,可选):使用 AI 灵修功能时,应用提供 Sign in with Apple。我们不申请任何 scope,因此 Apple 仅向我们的服务器提供一个稳定的匿名用户标识(绝非您的邮箱或姓名)。我们的服务器校验 Apple 对该标识的密码学签名后签发自有的短期会话。您的订阅权益直接由您设备呈现的 Apple 签名 StoreKit 2 交易验证——不经任何第三方——因此绑定到经核验的身份、无法被冒充。除 AI 功能外,您无需登录即可使用本应用;您可随时在"设置"中删除账号(将清除我们缓存的会话与权益数据;Apple ID 凭据本身及任何有效订阅由您在设备的 Apple ID 设置中管理)。

3. 您的内容存储在哪里

以下数据仅存储在您的设备上,绝不会发送到我们的服务器:

您可随时通过应用内的「重置应用设置」或卸载应用来清除这些本地数据。

您的收藏与灵修历史(账号数据,需登录):登录后,您收藏的经文与最近生成的 AI 灵修——包括您输入的处境文本——存储在我们位于欧盟的托管数据库中,重装应用或更换设备后登录即可恢复。每个列表最多保存 50 条(不会自动删除,由您自行管理);您可在应用内删除单条历史记录(长按),在「设置」中删除账号则会全部移除。危机求助回应绝不会保存进历史。

4. AI 生成的灵修内容

使用 AI 灵修功能时:

您的输入在何处处理:我们的后端服务器位于欧盟(德国法兰克福)。使用 AI 灵修功能时,您的文本输入会传输到这些位于欧盟的服务器,我们的 AI 提供商(Mistral)也在欧盟(EU 数据驻留为 Mistral 默认设置)处理您的输入。灵修生成后,该输入仅存于您账号的灵修历史中(详见第 3 节)——绝不会出现在任何服务器日志里。

数据驻留与传输:您的输入在欧盟境内处理与存储——我们的后端(德国法兰克福)与 AI 提供商(Mistral)均在欧盟运营。若将来确有必要在欧盟境外处理,我们将依据欧盟委员会批准的标准合同条款(SCC)(或同等有效的合法保障机制)。我们不会将您的数据传输至中国,或任何不具备充分数据保护水平的司法管辖区。

法律依据(欧盟用户):根据 GDPR,我们处理您的文本输入以生成 AI 灵修的合法性基础为 第 9(2)(a) 条——您的明确同意,您在阅读同意说明并开始使用本应用时即视为同意(若您跳过,则在首次点击"生成"时征求)。您可以随时撤回该同意——详见第 9 节"撤回同意"。撤回不影响撤回前基于同意进行的处理的合法性。

自动化决策:AI 灵修完全通过自动化方式生成,未经人工审核。根据 GDPR 第 22 条,您有权不受仅基于自动处理作出的决策的约束,当该决策对您产生法律效力或类似重大影响时。灵修内容仅供鼓励参考,不构成专业建议(医疗、心理健康、法律或财务),也不用于对您个人作出任何决定。若您不希望接收未经人工审核的 AI 生成内容,请勿使用此功能。

数据控制者与处理者:根据适用数据保护法,我们(应用开发者)是数据控制者——决定处理哪些数据及为何处理。Mistral AI(法国/欧洲公司)是数据处理者,按照我们的指示生成灵修内容。您与 Mistral 的关系受 Mistral 自身隐私政策与条款的约束。

5. 第三方服务

本应用使用以下第三方服务:

我们不集成任何广告网络、社交媒体 SDK 或追踪工具。

6. 儿童隐私

本应用不面向 18 岁以下人员,我们不会有意收集 18 岁以下人员的个人数据。若我们得知收集了 18 岁以下人员的个人数据,将予以删除。若您认为有未满 18 岁者向我们提供了个人数据,请联系 jidutu093@gmail.com。

7. 数据安全

我们采取适当的技术措施保护您设备与服务器之间传输的任何数据,包括 HTTPS 加密。

8. 政策变更

我们可能不时更新本隐私政策。任何变更将反映在本页面,并更新"最后更新"日期。

9. 您的地区隐私权利

如果您所在地区有数据保护法律——如美国加州 CCPA/CPRA、英国 UK-GDPR、欧盟 GDPR、加拿大 PIPEDA、澳大利亚隐私法、新加坡/马来西亚 PDPA——您可能对您的个人数据享有权利,包括访问、更正、删除,以及反对或退出某些处理。根据这些法律,本政策所述数据(如第 2 节的匿名应用标识符与 IP 地址,以及第 4 节您提交给 AI 灵修功能的文本)可能构成个人数据,因此这些权利可能适用。如需行使任何权利,或想了解我们持有您的哪些数据,请联系 jidutu093@gmail.com,我们将及时回复。您的语言和显示偏好仅存储在您的设备上,完全由您控制;您的收藏与灵修历史存储在您账号下的欧盟服务器上(详见第 3 节),删除账号时一并移除。

响应时限。我们将在 30 天内回复经验证的请求;若请求复杂,我们可能延长该期限并告知您延期及原因。

向监管机构投诉的权利(EEA 及英国用户):如果您认为我们对您个人数据的处理违反了数据保护法律,您有权向当地数据保护监管机构提出投诉(特别是在您习惯居住地、工作地或涉嫌侵权地的 EU/EEA 成员国)。荷兰用户可联系 Autoriteit Persoonsgegevens(autoriteitpersoonsgegevens.nl)。我们建议您先联系我们,以便我们直接解决您的关切。

删除的局限:您的文本输入一旦传输给 AI 提供商用于生成灵修,我们事后便无法访问或删除,其留存与删除受提供商隐私政策约束。我们服务器的运营记录(第 2 节所述的匿名应用标识符、订阅权益绑定与设备公钥)保存在我们位于欧盟的托管数据库中;在应用内删除账号即可删除这些记录,连同您的收藏与灵修历史(第 3 节)。注销后仍保留一项匿名数据:每日 AI 生成次数计数——一个仅以匿名应用标识为键、不含任何内容的数字——留存的唯一目的是防止通过反复注销刷新用量上限。请求 IP 地址仅保存在易失性内存中——绝不写入数据库——也可能出现在托管服务商为运营期保留的标准日志中。如需删除任何此类日志数据,请联系我们。

撤回同意:由于您的文本输入会共享给第三方 AI 提供商(第 5 节)以生成灵修,我们会事先取得您的明确同意(第 4 节)。您可随时在应用内撤回该同意:进入「设置 ▸ AI 数据使用 ▸ 撤回同意」。撤回后,您的输入不再发送给 AI 提供商,在您重新同意之前将无法生成 AI 灵修(下次尝试时会再次征求同意)。每日经文与收藏不受影响。另请注意,「清除所有本地数据」操作也会重置该同意。撤回不影响撤回前基于同意进行的处理的合法性。

10. 联系我们

如对本隐私政策有任何问题,请联系:

邮箱: jidutu093@gmail.com