Privacy Policy
Last updated: 4 September 2026
Simply Scripture is a local-first Bible reading app. Most personal reading data begins on your device, and the app does not require a Simply Scripture account. This policy explains the limited information handled when you use optional sync, account, analytics, and Session Replay features, the crash diagnostics used to keep the app reliable, and the performance data handled by this website.
1. Who we are
“Simply Scripture” (“we”, “us”, “our”) provides the Simply Scripture iOS application and the website at simplyscripture.app. If you have any questions about this policy or your privacy, you can reach us at info@simplyscripture.app.
2. The short version
- You can read and use personal Scripture tools without a Simply Scripture account.
- Your reading preferences, saved passages, highlights, notes, and collections are stored on your device first.
- Before sign-in, supported personal records may sync through your private iCloud database when iCloud is available.
- If you choose an account, your personal library can sync through our Supabase-backed service after the first merge you approve. This account sync is not end-to-end encrypted from the service operator.
- Sentry crash and performance diagnostics stay off unless you choose to share them; turning them on takes effect on the next app launch, while turning them off takes effect immediately.
- Amplitude usage analytics and Session Replay are separate choices. Both are off by default, and Replay also requires analytics to be enabled.
- We do not sell your information or use advertising, data brokers, or cross-site tracking.
3. On-device data and private iCloud sync
Your reading position, preferences, saved passages, highlights, notes, and collections are stored on your device first. Downloaded Bible and study content is also read from your device. Reading and personal Scripture tools do not require a Simply Scripture account or a network connection once the required content is available locally.
While you are not signed into a Simply Scripture account, supported personal records may be mirrored through your private CloudKit database when iCloud is available. Apple operates that service under your Apple Account. We do not receive your Apple Account password, and we do not use your iCloud identity for analytics. Bible text and downloaded Bible files are not copied into CloudKit by Simply Scripture.
4. Optional Simply Scripture accounts and account sync
If you choose to create or connect a Simply Scripture account, we process the information needed to operate it, such as your email address, profile name, account identifier, authentication provider, and security and session records. Supabase provides the authentication and account service.
Supabase authentication, security, and service logs can include your account identifier, IP address, IP-derived approximate location, device or browser context, authentication provider, and request metadata. We use these records only to authenticate accounts, prevent abuse, protect the service, and diagnose reliability issues.
After you approve the first-account merge, the current local library can sync through your Simply Scripture account using our Supabase-backed service. This can include saved-passage and highlight references, notes, collections, collection membership, timestamps, deletion markers, and sync metadata. Account sync becomes the primary sync path while you are signed in. It is protected in transit and by authenticated, account-scoped access controls, but it is not end-to-end encrypted from the service operator.
Saved passages, highlights, notes, and collections concern Scripture and devotional activity and may reveal religious or philosophical beliefs. We therefore treat this account-synced content as sensitive information.
Signing out preserves the on-device library and the account-held copy; private iCloud sync can resume when available. Deleting an account removes the active account and account-held library from our active service, subject to limited copies that may need to remain temporarily for security, legal, or disaster-recovery purposes. It does not automatically erase the library stored on your device or in iCloud.
5. Bible and study content
Bible translations, study resources, and related content are provided by Simply Scripture and the applicable licensors or rights holders. Some content is bundled with the app; other editions may be browsed or downloaded from Simply Scripture’s catalogue and distribution service. When your device requests hosted content, that service necessarily receives the requested resource and ordinary network information needed to deliver it. Rights and attribution notices for a particular edition are shown with that content where required.
6. Crash and performance diagnostics
If you choose to share crash diagnostics, the production app can send information about crashes, hangs, watchdog terminations, and performance problems to Sentry so we can identify and fix them. Crash diagnostics stay off until you choose them in Privacy & Analytics settings. Turning them on takes effect on the next app launch; turning them off takes effect immediately.
Diagnostic records may include app version and build, operating-system and device context, stack traces, performance timings, sampled performance profiles, and a small allowlisted set of content-free feature and operation categories. We configure Sentry not to receive default personal information, screenshots, view hierarchies, raw network traffic, Scripture or study text, searches, note content, collection content, account credentials, personal-library payloads, or sync payloads.
7. Optional usage analytics
You can separately choose to share content-free product-usage analytics with Amplitude. Analytics is off by default. If you enable it, the app sends a random app-installation identifier, session and app-lifecycle events, and a limited set of typed interactions such as the app surface or semantic control zone used and whether an operation succeeded. We use this information to understand reading navigation, Collections, highlights, saves, downloads, reliability, and feature adoption.
Analytics does not include Scripture text or references, search text, copied or shared text, note bodies, collection names or contents, exact saved or highlighted passages, email addresses, account identifiers, CloudKit identifiers, sync payloads, URLs, raw errors, or stack traces. We do not send raw tap coordinates or use analytics to infer your devotional interests.
8. Optional Session Replay
If analytics is enabled, you can make a second, separate choice to share privacy-masked Session Replays with Amplitude. Replay is also off by default. We initially select no more than 1% of eligible production sessions. The replay system captures changes in the app’s interface so we can understand navigation and interface friction; it does not receive permission to inspect private devotional content.
We use conservative masking for text, block or exclude Scripture and personal-content surfaces, stop recording on sensitive account and editing flows, and do not capture web views. Images inside blocked areas are replaced; non-sensitive interface imagery outside those protected areas may appear in a Replay. Disabling analytics also disables Replay.
9. Information this website handles
This website is a set of static pages. It does not use advertising or technology intended to follow you across other companies’ sites. It does use Vercel Speed Insights to measure page performance. Vercel reports technical data points such as the page route and URL, Web Vitals, network speed, browser, device type, operating system, country, performance attribution, SDK version, and event time. Vercel states that Speed Insights data is not associated with an individual visitor or IP address and cannot reconstruct a browsing session across pages. See Vercel’s Speed Insights privacy documentation.
Google Fonts provides the Site’s typefaces. When your browser requests its stylesheet and font files, Google receives ordinary network-request information, such as your IP address and browser context, needed to return the appropriate files. The provider serving the website may also process ordinary request and security-log information, including IP address and browser information, to deliver and protect the Site. We do not combine website performance data with app analytics or use it for advertising profiles.
10. Service providers and the App Store
Depending on the features and choices you use, Simply Scripture relies on Apple for private iCloud sync and App Store distribution, Supabase for hosted Bible distribution, optional accounts, and account sync, Sentry for crash and performance diagnostics, Amplitude for optional analytics and Session Replay, Vercel for website performance measurement and hosting, and Google Fonts for website typography. These providers process information under their own privacy and security terms and may do so in the UK, European Economic Area, United States, or other locations subject to applicable safeguards.
We require service providers that process information for Simply Scripture to protect it to the same or an equivalent standard described in this policy and required by applicable App Store rules.
When you download the app, Apple handles that transaction under Apple’s Privacy Policy. We do not receive a list from Apple identifying everyone who downloaded the app.
11. Why we use information
We process optional account and sync information to provide the service you request and perform our agreement with you. We use website delivery, typography, and performance information for our legitimate interests in presenting the Site and keeping Simply Scripture secure, reliable, and usable. We use Sentry diagnostics, Amplitude analytics, and Session Replay only when you choose to enable each feature. We may also process information where necessary to comply with law or protect legal rights.
12. Your choices, retention, and deletion
You can change analytics and Session Replay choices at any time in Privacy & Analytics settings. Disabling a choice stops future collection from that installation; disabling analytics also disables Replay. You can switch off crash diagnostics there immediately; turning them on takes effect on the next app launch.
On-device data remains until you delete it, remove the app’s data, or uninstall the app. Private iCloud copies follow the controls and retention of your Apple Account. Optional account information and the account-synced personal library remain while the account is active and are removed from the active service when you delete the account, subject to limited security, legal, and disaster-recovery retention. Deleting an account does not delete the separate on-device or iCloud copies.
Sentry diagnostics, Amplitude analytics, and Session Replays are retained under the provider and project settings in effect at the time. We do not promise a fixed telemetry retention period in this policy; you can contact us for the current setting. The app does not currently offer self-service deletion of telemetry tied only to one random installation. Disabling telemetry does not erase records already received. You may contact us to request access or deletion where a record can be associated with information you provide, although the deliberately pseudonymous design may mean that we cannot reliably identify a particular installation’s records.
13. Your data-protection rights
Depending on where you live and the circumstances, you may have rights to access, correct, erase, restrict, or receive personal data, to object to certain processing, and to withdraw consent without affecting earlier lawful processing. To make a request, email info@simplyscripture.app. We may need information to verify your identity and locate the relevant record. If UK data-protection law applies, you may also complain to the UK Information Commissioner’s Office.
14. Children’s privacy
Simply Scripture is designed for a broad audience, but we do not knowingly collect personal information from a child under 13, or the equivalent minimum age in their country, without appropriate authorization. A Simply Scripture account is optional, and analytics and Session Replay are off by default. If you believe a child has provided personal information without appropriate authorization, please contact us.
15. Data security
We use platform security, encrypted network transport, authenticated access controls, privacy filtering, and data minimisation. No system is completely secure, so we limit telemetry at the source and prohibit private devotional content from analytics and diagnostics.
16. Changes to this policy
We may update this policy when Simply Scripture or its data practices change. We will update the “last updated” date above and provide any additional notice required by law. We will ask for a new choice before materially expanding optional analytics or Session Replay beyond the purposes described here.
17. Contact
Questions about this Privacy Policy can be sent to info@simplyscripture.app.