Scripture First
Privacy Policy
Last updated · August 1, 2026
This Privacy Policy describes how Scripture First (“we,” “us,” or “our”) handles information when you use the Scripture First mobile application for iOS (the “App”) and the related website at downloadscripturefirst.com (the “Site”). It reflects how the App and Site are built as of the date above. The App is intended for users 13 years of age or older. This policy is not legal advice; if you need advice for your situation, consult a qualified attorney.
Information We Collect and Generate
You can use most of the App without creating an account. Core reading progress, app-blocking settings, highlights, notes, and streaks are stored on your device. If you choose to create an optional account, join the waitlist on the Site, purchase a subscription, use AI study features, or grant tracking permission, we (or our service providers) process the additional information described below.
- Subscription and purchase activity: Purchases are processed by Apple. We do not receive your full payment card number. The App may record which subscription product identifiers are active on your device for feature access, and may coordinate subscription status through Superwall.
- Device and app interaction (analytics and measurement): The App includes the Meta (Facebook) Software Development Kit, which can collect device and usage-related data and send events to Meta for app analytics and advertising measurement. When Apple’s App Tracking Transparency framework grants tracking authorization, the App aligns Meta settings so that advertiser identifier collection may be enabled; if you do not grant tracking, advertiser identifier collection is disabled while other SDK features may still operate per Meta’s defaults.
- Purchase-related app events (Meta): When you complete certain App Store purchases or start trials inside the App, the App may send standard Meta app events (for example, trial start or purchase events with product and currency information) for advertising measurement and analytics.
- Paywall presentation: The App uses Superwall to show subscription paywalls. Superwall may collect identifiers and usage data according to its own privacy policy when you interact with paywalls.
- Waitlist and Site use: If you join the waitlist on the Site, we collect the email address you submit. We use Cloudflare Turnstile to help prevent bots; that check may process a verification token and related technical signals. We may temporarily process your IP address for rate limiting (currently limited submissions per hour per IP). Waitlist contacts are stored with Resend and tagged so we can send launch and product emails related to Scripture First.
Optional Account
The App offers an optional account in Settings (presented as a sync / account card). If you create an account, you may sign in with an email address using a one-tap magic link, or with an email and password. While you are signed in:
- Your email address (and password credentials, if you choose password sign-in) are processed by our authentication provider so we can recognize you, send sign-in or password-reset emails, and manage your account.
- We store account metadata that identifies the account as associated with Scripture First (for example, an app or source label).
- As of the date of this policy, the optional account is used for authentication and account identity. Most of your reading progress, app-blocking configuration, highlights, notes, and streaks remain stored on your device. If we later enable full cross-device sync of that content, we will update this Privacy Policy and the in-app experience to describe what is uploaded.
Account services are provided by Supabase, our authentication and database processor, on hosting infrastructure located in the United States. Supabase processes this data on our behalf under their privacy policy.
You can sign out or delete the account at any time. In Settings you can sign out (which leaves data on this device and leaves the account available when you sign back in) or use Delete account, which permanently removes your auth identity from our cloud. Deleting the account does not erase reading progress, notes, highlights, streaks, or blocking settings already saved on this device — those remain on this device unless you remove them or delete the App.
Data Stored on Your Device
Whether or not you create an account, the App keeps information locally on your device (including in Apple’s app group container shared with the App’s extensions). Examples include:
- Family Controls / app-blocking configuration: the apps, categories, and web domains you choose to block; schedule settings; always-allowed lists; unlock and completion timestamps; and related shield state. This information is used on-device to enforce the blocker you configured and is not uploaded by us as part of the optional account feature described above.
- Reading activity: today’s reading progress, plan selection and completion flags, Bible time tracking, and streaks
- Personal study content: highlights, bookmarks, verse notes, and custom reading plans you create
- App preferences: theme, font size, preferred Bible translation, and onboarding completion state
- Subscription access flags mirrored locally so extensions and the main App can honor paid features
Deleting the App or clearing app data may erase this local information unless you have a separate device backup that restores it.
Information Sent to Third-Party Services
When you use certain features, the App or Site sends data over encrypted HTTPS connections to service providers so those features can work:
- OpenAI: The App uses OpenAI’s APIs for AI-assisted verse study features (for example, explain easier, original language, deep study, and related verses). Prompts can include the verse text and reference you are studying, along with instructional text required to produce a safe, on-topic response.
- API.Bible (American Bible Society): To download Bible chapter text for supported online translations (currently NKJV and NLT), the App calls API.Bible with identifiers such as translation, book, and chapter. Responses may be cached on-device to reduce repeat network requests. The King James Version is bundled offline on your device and does not require this call.
- Apple: In-App Purchases, StoreKit subscription state, offer/promo code redemption, App Tracking Transparency, Family Controls / Screen Time frameworks, and App Store services.
- Meta Platforms, Inc.: As described above, through the Facebook SDK and related app events.
- Superwall: Paywall presentation, subscription status coordination, and related analytics as described in Superwall’s documentation and privacy policy.
- Supabase: If you create an optional account, your email address, sign-in events (magic link or password), and account metadata are processed in our Supabase project. Supabase may also deliver authentication emails on our behalf.
- Resend: If you join the waitlist on the Site, your email and related contact properties are stored with Resend so we can send product emails. Confirmation emails are sent from our Scripture First sending domain.
- Cloudflare: Turnstile bot protection on the waitlist form.
Each provider processes data under its own terms. Please review their policies:
How We Use Information
- Provide Bible reading, app blocking via Family Controls, reading plans, streaks, and related tools
- Provide AI-assisted verse study when you use those features
- Process and validate subscriptions, trials, offer codes, and paywall access
- Authenticate you and manage optional accounts
- Operate the waitlist and send related product emails
- Measure advertising and subscription performance through Meta’s SDK where enabled
- Improve reliability and understand aggregate usage patterns through vendors’ analytics where applicable
- Comply with law and protect rights and safety
Data Sharing
We do not sell or share personal information as those terms are defined under the California Consumer Privacy Act. We instruct service providers as part of operating the App and Site (listed above). We may disclose information if required by law, legal process, or to protect users and the public.
Data Retention
We retain information for as long as it is needed to provide the App and Site and the features you use. Specifically:
- Account data. If you create an optional account, we retain your email address and related auth records for as long as your account is active. When you use Delete account in Settings, your auth identity is promptly removed from our cloud.
- Waitlist contacts. Emails submitted on the Site are retained until you unsubscribe or ask us to delete them, or until we no longer need them for the waitlist and related product communications.
- On-device data. Data stored locally on your device is retained on your device until you delete it inside the App or remove the App.
- Third-party services. Data processed by service providers (such as Apple, Meta, Superwall, OpenAI, API.Bible, Supabase, Resend, and Cloudflare) is retained per each provider’s own retention policies.
App Tracking Transparency and Your Controls
iOS may prompt you to allow or deny cross-app tracking. You can change your choice later in Settings > Privacy & Security > Tracking. You can also limit ad personalization through device and Meta account settings as described in Meta’s help documentation.
Family Controls Permission
Scripture First uses Apple’s Family Controls, Managed Settings, and Device Activity frameworks so you can block apps you choose until you complete Bible reading. Granting this permission allows the App to apply the restrictions you configure on your device. Selected apps and blocking rules remain under your control and are stored on-device as described above. You can revoke Family Controls authorization in iOS Settings, which will disable the blocker features that depend on it.
Local Notifications
The App may schedule notifications on your device using Apple’s local notification APIs (for example, shield interactions or confirmation prompts). These are not marketing push notifications sent from our servers.
Security
- Network requests to third parties use HTTPS.
- We rely on Apple’s platform security for device-level protection, including for Family Controls and app group data.
- Authentication credentials for optional accounts are handled by Supabase using industry-standard auth flows.
No method of storage or transmission is perfectly secure.
Your Choices and Rights
Depending on where you live, privacy laws may give you rights to access, correct, delete, or restrict certain processing of personal information, or to opt out of certain sharing for advertising. Because most reading and blocking content stays on your device, you can often delete it directly inside the App or by removing the App. For subscription billing history or refunds, use Apple’s account tools.
If you created an optional account, you can permanently delete your account from inside the App (Settings > account / sync card > Delete account). This removes your auth identity from our cloud. On-device data is not automatically wiped by account deletion.
To unsubscribe from waitlist emails, use the unsubscribe link in those emails or contact us. To exercise rights that apply to information we hold as a business, contact us using the information below. We may need to verify your request as permitted by law.
European Economic Area, United Kingdom, and Switzerland
If you are located in the European Economic Area, the United Kingdom, or Switzerland, we process your personal information based on the following legal grounds: your consent (for example, when you join the waitlist, create an account, or grant App Tracking Transparency authorization); the performance of our agreement with you (to provide the App and the features you use); our legitimate interests in operating, securing, and improving the App and Site and measuring advertising performance, where those interests are not overridden by your rights; and compliance with legal obligations.
Subject to applicable law, you may have the right to access, correct, delete, restrict, or object to our processing of your personal information, the right to data portability, and the right to withdraw consent at any time without affecting the lawfulness of processing based on consent before its withdrawal. You also have the right to lodge a complaint with your local data protection authority. To exercise these rights, contact us using the information below.
Personal information processed for the App or Site may be transferred to and stored in the United States or other countries where our service providers operate. Where required, we rely on appropriate safeguards for such transfers, including the standard contractual clauses published by relevant authorities.
Children's Privacy
The App and Site are intended for users 13 years of age or older. We do not knowingly collect personal information from children under 13. If you believe a child has provided personal information to us, contact us using the information below and we will take appropriate steps to delete it.
International Users
If you use the App or Site from outside the United States, your information may be processed in the United States or other countries where service providers operate. Those countries may have different data protection laws than your country.
Changes to This Policy
We may update this Privacy Policy from time to time. We will post the updated policy and revise the “Last updated” date. If changes are material, we may provide additional notice as required by law or through the App or Site.
For the rules that govern your use of the App, see our Terms of Use.
Contact Us
If you have any questions about this Privacy Policy, please contact us:
Email: scripturefirstapp@gmail.com
Developer: Scripture First