App Privacy Policy
Privacy policy for the Rebuilding Faith Journal App
Our Privacy Promise
Rebuilding Faith LLC ('Rebuilding Faith', 'we', 'our', or 'us') exists to help you engage Scripture without trading away your privacy. This policy explains what we collect, why we collect it, and the choices available to you under laws like the GDPR, CCPA/CPRA, and similar global regulations.
In plain terms:
- We don't read your content. No one at Rebuilding Faith looks at your journals, notes, or highlights.
- We keep a simple record of the skills you've learned in the app—you can clear it anytime. It's for you first: to help your faith journey. In aggregate, anonymized form it also helps us improve the app for everyone.
- Your content stays in our own storage. It only goes to a third party when you explicitly ask—for example, sending an image or audio clip for AI transcription.
Using the Service means you agree to this policy. If you ever have questions or concerns, reach out—we want to make the experience safe and transparent.
Information We Collect
- Account details such as your name, email address, and authentication data provided by you or your identity provider.
- Content you create or upload—journal entries, posts, highlights, and chat messages.
- Usage diagnostics (crash reports, performance metrics, and basic device information) via Sentry—these are opt-in and off by default; we collect them only if you turn on crash/performance reporting in Privacy Preferences. They never capture the text or media from your journal.
- Up to sixty days of activity history—chapters you read, Strong's views you open, books and audiobooks you access, and notes you view or edit—so you can continue seamlessly across multiple devices. We also track which features you've used so we can recommend other features that may help your journey. This short-term log is private, secure, stays inside Rebuilding Faith, is never shared with other people or outside services, and is never sold or used for advertising.
- When you use voice dictation, your device's built-in speech recognition (provided by Apple, Google, or your browser) processes the audio. We receive only the text transcript, not the audio itself.
- Anonymous onboarding events—reaching the sign-in screen, starting and completing sign-in, and getting into the app for the first time (plus taps on a few key prompts, like the launch-mode banner). These are tied only to a random device identifier (never your name or email), are sent to our own first-party servers, are never shared with or sold to anyone, and are used only to find and fix where people get stuck getting started.
How We Use Your Information
We tie each kind of data to a specific purpose—nothing is collected 'just in case':
- Account details (name, email, sign-in) — to sign you in, keep your account secure, and send essential notices.
- Your content (journal entries, notes, highlights) — it's yours. We store, sync, search, and show it back to you across your devices. We never analyze it, and no one reads it. It lives only in our own storage—run for us under contract by the storage providers listed under 'When We Share'—and is never shared with anyone else, except when you explicitly run AI transcription on an image or audio clip, where that file is sent to a third-party AI provider to create your transcript (see 'Third-Party AI' below). Chat messages are delivered to the people you send them to. We never sell your content.
- Diagnostics via Sentry (opt-in, off by default) — to find and fix crashes and performance problems; these never include your journal text or media.
- Which features and skills you've used — a lightweight record (just the feature, not your content) so we can recommend other features that may help your journey and improve the app.
- Anonymous onboarding signals — to see where people get stuck getting started (reaching sign-in, signing in, first use), so we can smooth out onboarding. These are aggregate only and never tied to you.
- Voice-dictation audio — processed on your device; we receive only the text transcript you create.
We may also contact you about security notices, important updates, or product tips—you can opt out of non-essential messages anytime.
We never sell or rent your personal data, and we do not run advertising or third-party behavioral tracking.
Scripture Usage Tracking (FUMS)
To show you Bible text, we use API.Bible, operated by the American Bible Society. The publishers who license those translations require a Fair Use Management System (FUMS): we report anonymous Bible usage—essentially which passages are accessed—so publishers can understand how their translation is used and confirm fair use.
FUMS receives only anonymous identifiers (a per-device identifier, a per-session identifier, and an obfuscated user identifier)—never your name, email, journals, notes, or highlights. Only which passages were viewed is reported.
This reporting is a condition of licensing copyrighted translations. See the in-app Credits page for the versions we use and their copyright details.
Photos and Location Metadata
Photos you take can carry hidden metadata called EXIF, which often includes the exact GPS location where the photo was taken as well as device details.
When you upload a photo, we automatically remove this EXIF metadata on your device before the image is sent to our servers, so the location and device data never leave your phone or computer.
If a photo you're attaching to a note contains GPS coordinates, we'll ask whether you'd like to add that location to your note's map. This is opt-in: if you decline, the coordinates are discarded. If you accept, only the latitude and longitude are saved as part of your note's content, never the original EXIF metadata.
Content Safety & How We Scan Images
The short version: We don't read your private journals, and we don't look at your private photos. To help protect children, we generate a 'fingerprint' for every image you upload—a value derived from the image that is not the image itself and can't be turned back into it. That fingerprint, never your actual photo, is what we check against a list of images already confirmed to be illegal—so known illegal images are caught quickly without your photos ever leaving Rebuilding Faith's systems. If a fingerprint isn't a match, nothing else happens. If it matches confirmed child sexual abuse material, we lock the image so no one can see it and report it to the authorities, because U.S. law requires us to.
What a 'fingerprint' is. A fingerprint (technically, a 'hash') is a short string of numbers generated from what an image looks like. It is one-way: it can't be turned back into the picture, it can't be used to view or recreate the picture, and it carries none of the photo's details—no location, no faces, nothing that identifies you. (We already remove location and camera metadata from your photos on your device before they're uploaded—see 'Photos and Location Metadata' above.) The same picture always produces the same fingerprint; a different picture produces a different one.
How the scan works. Every image is fingerprinted on our own servers. For child-safety scanning, only that fingerprint—never your image, and nothing that resembles it—is sent to Microsoft PhotoDNA. PhotoDNA compares the fingerprint against a database of fingerprints of child sexual abuse material that has already been identified and confirmed by child-protection authorities. It does not look at, classify, or form a judgment about your photo; it only checks whether your fingerprint matches one already on that list.
What this means for your images:
- Your private images. If an image is only yours—not shared to a group—the automated fingerprint check is the only thing that ever happens to it. No one reviews your private images: not other members, not group moderators, not our staff.
- Images you share to a group. When you post an image to a group, the people in that group can see it, and that group's moderators can review and act on it if it's reported. They can also escalate it to us. The same automated fingerprint check still applies.
- If a fingerprint matches known illegal material. The image is immediately locked so that no one can view it—not you, not group moderators, not our staff—and, as the law requires, we report it to the National Center for Missing & Exploited Children (NCMEC). Because PhotoDNA only matches against material that authorities have already confirmed is illegal, this is not someone's opinion about your photo.
What we report, and what we keep. When the law requires us to file a report, we share the image and an account identifier with NCMEC, which works with law enforcement, and we may preserve and disclose related account information as the law requires. We may be legally prohibited from notifying you when this happens. Content that is reported, flagged, or removed for safety reasons may be kept—along with related records—for as long as needed to enforce our policies and meet our legal obligations (at least 90 days for content reported to NCMEC), even after you delete it from your account.
When We Share Information
We use secure third-party software to operate the Service. These services are bound by contract to protect your data and use it only to provide the agreed services:
• MongoDB Atlas — database hosting (United States)
• Sentry — crash diagnostics and performance monitoring
• Firebase Cloud Messaging (Google) — push notification delivery
• Tigris — file and media storage (images, audio, note history)
• Capgo — over-the-air app updates for mobile devices
• Stripe — payment processing for subscriptions
• RevenueCat — subscription management and entitlement tracking
• Mailgun — transactional email delivery (security notices, updates)
• Grafana on Fly.io — application logging and monitoring
• OpenAI Whisper — audio transcription when you explicitly request it (see 'Third-Party AI' section below)
• Stripe — payment processing for subscriptions and sponsorships. Stripe collects payment details (card number, billing address) directly; we never see or store your full card number.
• American Bible Society (API.Bible) — Scripture delivery and anonymous Fair Use (FUMS) usage reporting (see 'Scripture Usage Tracking' below).
• Microsoft PhotoDNA — checks a fingerprint (hash) of each uploaded image against a list of known child sexual abuse material; only the fingerprint is shared, never the image (see 'Content Safety & How We Scan Images' above).
• National Center for Missing & Exploited Children (NCMEC) — when the law requires it, we report confirmed child sexual abuse material; the image and an account identifier are shared (see 'Content Safety & How We Scan Images' above).
We do not sell, rent, or share your information with advertisers, data brokers, or anyone else. We may disclose data only if required by law or to respond to valid legal requests.
Third-Party AI & Machine Learning Services
When you use the audio transcription feature, selected audio ranges are sent to OpenAI's Whisper API to generate a text transcript. This feature is opt-in and clearly marked in the app. OpenAI does not use API-submitted audio to train its models. Your journal entries and other content are never sent to OpenAI.
When you transcribe text from an image, that image is sent to Google Cloud Vision to extract the text. Like audio transcription, this is opt-in and clearly marked; we receive only the extracted text, and only the image you choose is sent—never your journals or other content.
Voice dictation uses your device's built-in speech recognition (provided by Apple, Google, or your browser) and does not send audio to any third-party service.
AI-powered features are always clearly marked with an [AI] badge in the app so you know when a third-party AI service is involved.
If we ever introduce additional AI features, we will clearly disclose what data is shared, obtain your explicit consent, and provide full control to opt in or opt out at any time.
Cookies, Local Storage & Similar Tech
We rely on cookies, secure storage, and service workers to keep you signed in, remember your preferences, and enable offline experiences.
We do not use third-party advertising trackers. Our own analytics is first-party and cookieless—a random device identifier, not advertising cookies—and it's lightweight: a record of which features you use (to recommend features that may help your journey and to improve the app), plus anonymous onboarding signals (to smooth out getting started). You can clear cookies or use private browsing, but doing so may sign you out or limit certain functionality.
Data Storage, Security & Retention
Your text content (journal entries, notes, highlights) lives in our own database on MongoDB Atlas (United States), and your files (images, audio) in our object storage (Tigris)—both encrypted at rest. Your content is never copied elsewhere or shared with third parties, except the image or audio you explicitly send for AI transcription. Diagnostics are processed in Sentry, with your content filtered out.
All network traffic uses HTTPS/TLS (so your data is encrypted in transit as well). Access to production systems is limited to a small number of administrators, protected by multi-factor authentication, and audited.
We keep your content while your account is active. If you delete entries or close your account, we remove them from active systems and purge related backups on their normal rotation (typically within 30–45 days), unless a longer period is required by law.
Your Rights & Choices
Access and manage your information anytime: export your journals, update profile details, and configure privacy preferences. You can delete your account from Account Settings in the app. When you request deletion, your account is deactivated immediately and permanently removed—along with all associated data—after a 30-day grace period. During this window you can contact us to cancel the deletion. You may also email support@rebuildingfaith.org to request deletion.
Depending on where you live, you may also have rights to request access, correction, deletion, portability, or to object to certain processing. Contact us and we will respond within 30 days (or the timeframe required by law).
You can control analytics consent, sharing options, and notifications under Privacy Preferences in your profile.
International Users
Rebuilding Faith is operated from the United States. By using the Service, you understand that your information will be stored and processed in the U.S. and may be accessed by our trusted providers there.
Where required, we rely on safeguards such as contractual data protection clauses to support lawful cross-border transfers.
Children's Privacy
The Service is not directed to children under 16 (or the minimum age required in your country). We do not knowingly collect personal information from children under 16.
If we learn that a child has provided us data without appropriate consent, we will delete it promptly. Please contact us if you believe this has happened.
Recent Changes to This Policy
We believe you should be able to see what changed and when, so we keep a short, plain-language record here—newest first. If a change significantly affects your rights, we'll also let you know in the app.
- June 17, 2026 — Added 'Content Safety & How We Scan Images': how we fingerprint and check uploaded images for known child sexual abuse material using Microsoft PhotoDNA, how group moderation and escalation work, and how we report confirmed illegal content to NCMEC. Added Microsoft PhotoDNA and NCMEC to the list of services we share data with.
- May 29, 2026 — Initial version.
Changes & Contact
We'll update this policy when practices change, post the new version in the app, and update the effective date below. Significant updates may also trigger in-app or email notices.
Effective Date: June 17, 2026
Have a question, privacy request, or accessibility concern? Email support@rebuildingfaith.org and we will help as quickly as possible.
The data controller for the information described here is Rebuilding Faith LLC, 2112 Broadway St NE, Ste 225 #316, Minneapolis, MN 55413, USA.