The Bible text, your favorites, notes and colors, your reading progress, your reading plans and streak (from app version 5.1), your Daily Question answers (from app version 5.2), your last reading position, and every app setting are stored on your device. Reading, listening to the text read aloud by your phone's voice, searching, sharing verse images, daily verse notifications, and every other core feature work without an account and without an internet connection (the narrated audio beta streams over the internet, section 15). Your device is the master copy of your data whether or not you ever sign in; the account described below only mirrors it.
When the device is online, the app creates an anonymous identity with Firebase Authentication and stores a copy of the following in Google Firebase (Cloud Firestore), keyed only to that random identity:
Reading plans and your streak are not part of the backup; they stay on the phone. The identity has no name, email address, phone number or profile, and on its own it does not tell us who you are. It is connected to you only by something you choose to do: signing in (section 3), or sending us a feedback mail, whose Backup id (section 13) lets us find your backup — which is how we delete it when you ask. Access rules restrict each backup to the identity that created it.
What the anonymous backup can and cannot do. It is a cloud copy for this installation of the app: the random identity lives only in the app's storage on this phone. When that storage is lost — the app is uninstalled, its storage is cleared, or a new phone is set up without the app's data — the app starts a new identity, and the old anonymous backup cannot be brought back from there. To be able to restore your data after a reinstall or on another phone, sign in (section 3) while you still have the phone — that attaches this backup to an account you can use anywhere. An anonymous backup left behind stays in the cloud until you ask us to delete it (section 7).
Signing in exists from app version 5.1.4. You can sign in with a Google account or, when the app offers it, with an email link (no password — we send a link to your address and tapping it signs you in). The app offers this once after installation and once more about a week later; "Not now" leaves the backup anonymous (section 2), and Profile → Account (and a card at the end of Home) remain the permanent way to sign in later. You can use the app for as long as you like without ever signing in.
Signing in upgrades the anonymous identity of section 2 in place: your existing backup simply becomes the backup of your account — nothing is copied elsewhere and nothing moves. If the account already exists (for example you signed in on a second phone), the data on this phone is merged into it as section 5 describes for a phone's first sign-in to an account, and the phone's old anonymous backup is then deleted.
| Where | What | Why |
|---|---|---|
| Your account record (Firebase Authentication) | Your email address; with Google also your name, the profile-picture link and your Google account identifier; the random account identifier; which sign-in method you used; when the account was created and last signed in. | To recognise you on another device and, for email sign-in, to send you the link. |
| Our database (Cloud Firestore) | Your name as your Google account provides it, or as Apple shares it the first time you sign in with Apple on iPhone (none for email sign-in), the dates the account was created and last signed in, which kind of phone you last signed in on (Android or iPhone, from app version 5.2.0), and your backup: favorites (verse references, colors, notes), chapters marked read, your last position, your quiz answers (from app version 5.2), one copy of the app settings per device (from app version 5.2.0 with which kind of phone it is, Android or iPhone), and small deletion markers, kept for 30 days, that stop a deleted item from coming back from another device that syncs within that time. | Restoring and syncing your data. |
| Invite records (Cloud Firestore), signed in or not, only when an invite code is used (from app version 5.1.6) | If you joined with a friend's invite code: one record under that code holding your random identifier and the time. If friends joined with your code: one such record for each of them. No name, email address or anything else. | Crediting the ad-free days of Invite a friend (section 13). |
| Amen and share records (Cloud Firestore), signed in or not (from app version 5.2.0) | When you say Amen to the verse of the day, or share it: one record under that day's verse holding your random identifier and the time and, for shares, how many times you shared it that day. No name, email address or anything else. The counts on the card include these records. | Showing how many people said Amen and shared, and letting you take an Amen back. Kept until you delete your account (section 7). |
| Not stored in the account | Your purchases (Google Play is the authority and restores them on any device), the text you read or listen to, what you search for, your reading plans and streak, your contacts, your location, and your email address and profile-picture link inside our database — they stay on the account record only. Usage statistics and crash reports (section 10) are kept apart, under an installation identifier, and are never attached to the account. | |
To protect sign-in against abuse, Firebase Authentication also logs the IP address and technical device information of each sign-in attempt and keeps those logs for a few weeks.
When you are signed in on more than one device, the app keeps them in step by merging, never by overwriting:
The backup is written shortly after a change when the device is online. Profile → Account also has Sync now, which runs the same merge on demand and shows when it last completed. Nothing is erased or overwritten unless you ask for it.
When you ask to sign in by email, Google's Firebase Authentication service sends the message on our behalf from a no-reply address (we may move it to our own domain; the message itself does not change). It contains the app name and a single sign-in link, nothing else. The link is meant to be opened on the phone that asked for it, works once, and expires; if it has expired, request a new one. If you receive such an email without having asked for it, ignore it — nobody can sign in with the link alone, because the address it was sent to must match the address entered on the phone that opens it. We use your address only to send that link and to recognise your account; we send no newsletters or marketing.
Profile → Account → Delete account & data (shown once you are signed in). From app version 5.1.5 this is a screen of its own. The screen lists what will be deleted, lets you choose whether to erase this phone too, and asks you to type DELETE. You then sign in once more, whichever way you signed in, to confirm it's you; nothing is deleted before that. The app then deletes, in this order, the cloud copies of your favorites, notes, progress, quiz answers and settings — and, from app version 5.1.8, your invite records (section 13) and, from app version 5.3.0, your Amen and share records (section 4), each taken off that day's count — then the account itself, and finally — only if you chose it — the favorites, notes, progress, reading plans, streak and quiz answers stored on this phone (settings and purchases are never wiped). In 5.1.4, two confirmation dialogs ask whether to go ahead and whether to erase this phone too; the cloud copies are then deleted, and the app asks you to sign in again only if Firebase requires a recent sign-in, after the cloud copies are gone. Afterwards the app keeps working without an account. The app then starts a fresh anonymous backup of whatever is still on the phone, under a new random identifier that has no link to the deleted account.
An anonymous backup (section 2) has no delete button in the app. Email us as described below, or sign in first and then use Delete account & data — signing in attaches the anonymous backup to the account, so both go together.
Our deletion page explains the same steps and the email path: write to [email protected] with the email address you signed in with, or with the "Backup id" printed at the bottom of a feedback mail (Profile → Send feedback), and we delete the backup, the account, any invite records and your Amen and share records within 30 days and confirm by reply. We may ask you to confirm the backup is yours before we delete it. This works for anonymous backups too, and for every version of the app.
Signing out is not deletion: Sign out keeps everything on the phone and leaves the backup in your account until you delete it.
| Data | Kept |
|---|---|
| Everything on your phone | Until you delete it in the app or uninstall the app. |
| Your backup and account | Until you delete them (section 7). Google then removes the remaining copies from its live and backup systems within 180 days. |
| An anonymous backup of a phone that never signed in | Until you ask us to delete it (section 7). Uninstalling the app does not remove it. |
| Invite records | Until you or the friend on the other side of the invite deletes their data (section 7). |
| Sign-in logs (IP address, device information) at Firebase Authentication | A few weeks. |
| Access logs at our website and our narration site (section 15) | A short period, for security and troubleshooting, then deleted. Not used for advertising. |
| Crash reports | 90 days. |
| Usage statistics | Individual events for 2 months; aggregated counts without identifiers are kept indefinitely. |
| Feedback emails | Only as long as needed to answer; deletion requests are kept as the record of the deletion. |
| Purchase records | By Google Play under its terms; the app keeps only a local "owned" flag on your device. |
The free version shows ads served by Google AdMob. To serve and measure ads, Google may collect your device's advertising ID, IP address, general device information and how you interact with ads, and may pass an ad request with that information to other ad companies that bid to fill it (Google's ad technology partners), within the limits of your consent and ad choices. Whether ads are personalized depends on your region and your choices:
Signing in does not change any of this. Your name and email address are never given to the ad system or used to target ads. How Google uses ad data is described at How Google uses information from sites or apps that use its services and in the Google Privacy Policy.
The app collects usage statistics with Google Analytics for Firebase. They record what is done in the app, for example:
These records are keyed to an installation identifier (the Analytics app-instance ID) and to your device's advertising ID, which the Google Analytics SDK collects with them. They are never linked to your name, email address or account, and they never contain the Bible text, your note text, which verses you saved, or your search words. In the EEA and the UK, from app version 5.1.8, usage statistics start only after you answer the consent form, and follow your answer. Everywhere, you can turn them off at any time under Profile → Privacy (the switch reads "Share usage statistics" from app version 5.1.8, and "Share anonymous usage stats" before); while it is off, the app sends no usage statistics.
When the app crashes, or when something it should have done fails — a sign-in, a purchase, saving a favorite or note, a backup, deleting your account, and the like — Firebase Crashlytics sends a crash report containing the technical stack trace, the app version, the device model and operating system version, a few counts about the app's state, such as how many favorites a failed backup held (from app version 5.1; the backup counts from 5.1.5), and an installation identifier. While usage statistics are on, the report also carries the last usage events before the crash, so it can show the book and chapter that were open. Crash reports never contain the Bible text, your notes or your name, and the usage-statistics switch does not turn them off. Statistics and crash reports are keyed to an installation identifier, not to your account, so they are not part of what "Delete account & data" removes; they expire on their own (section 8).
The daily verse notification and the evening devotional reminder (from app version 5.1.5) are scheduled on your device. The verse comes from a list built into the app or from the small verse-of-the-day file the app downloads from our website at most once a day (section 15); the notification itself sends nothing about you. The app also registers with Firebase Cloud Messaging so we can occasionally send every user a short note from the developer or a replacement verse of the day; we do not store your push token ourselves. You can turn the daily verse and the evening reminder off in the app (Profile → Notifications), and any notification, including notes from the developer, in Android settings.
Pro purchases and subscriptions are processed entirely by Google Play. We never see or store your payment details. The app keeps a record on your device of which product you own so it can hide ads and unlock Pro features, and it asks Google Play to confirm ownership when you reinstall. Purchases made in earlier versions of this app are honored automatically. Purchases are tied to your Google Play account, not to the app account, and are never synced through it. Subscriptions renew automatically until cancelled in Google Play › Subscriptions.
If you send feedback from the app, your mail app opens with a draft addressed to us. Its subject names the app and its version. The draft ends with a short footer: the app version and the screen you wrote from, your device model and Android version, and a short "Backup id" (the first characters of your backup identity) so we can find your backup if you ask us to delete it. From app version 5.1.5 the subject also starts with "PRO" if you have Pro, and the footer adds a support code and a short tag that sorts the mail in our inbox.
The support code is a compact, encoded summary of how the app is set up on your phone, so we can answer without asking you questions. It holds: the app version; whether you have Pro, which products you own and where each came from (including purchases carried over from the earlier app); the Backup id; how many days since the app was first opened; your theme, text size, audio choice, and daily-verse notification setting and time; whether data from the earlier app was imported; your current and best streak; how many reading plans are active; how many favorites and notes you have and how many chapters you have marked read (counts only — never which ones or what they say); whether and how you signed in; your Android or iOS version and whether your phone is set to dark mode; whether an ad-free pass is running; how many days since the last backup; and, from app version 5.2.0, for Invite a friend, whether you have shared your invite, how many friends have joined with it, and whether you joined with a friend's invite (counts only — never a code or who they are). It contains no name, email address, note text or verse.
Nothing leaves your phone until you press send, and you can delete any of these lines first. We keep feedback emails only as long as needed to answer them.
Invite a friend exists from app version 5.1.6. Your invite code is the first eight characters of your backup identity (section 2) in lower case — the same characters as the Backup id — so anyone you send an invite to can see it. When someone installs the app through your invite link, Google Play hands the code to their app on its first launch (or they type it in), and their app writes a small record in Cloud Firestore under your code: their own random identifier and the time. Your app reads the records under your code, at most once a day, to add your ad-free days, and keeps a note on your phone of which ones it has already counted. The records contain no name, email address or anything else, and are kept as section 8 says.
From app version 5.2.0, Invite a friend is offered only when the Google Play or App Store account on your phone is in the United States, the European Union, the European Economic Area, the United Kingdom or Switzerland. The app asks the store which country the account belongs to, keeps that answer on your phone only and asks again about once a week. The country itself is never sent to us; the app's usage statistics record only whether the invite is offered on the phone (yes or no).
If you open a share or invite link on an iPhone or on a computer before the iPhone app is available on the App Store, our website offers to tell you when it is. If you leave your email address there, we keep it, with the time and the invite code if the link carried one, only to send that one message, and delete it afterwards. Nothing is kept if you do not leave an address.
| Identifier | Who | Purpose |
|---|---|---|
| Advertising ID | Google AdMob, Google Analytics for Firebase | Serving and measuring ads; usage statistics, including the reading events of section 10. Resettable in device settings. |
| Firebase user ID | Firebase Authentication, Cloud Firestore | Keys your backup and your invite records. Random. Anonymous until you sign in; from then on it is your account identifier. |
| Backup id and invite code | The app: the feedback-mail footer, and the invite links you share | The first eight characters of the Firebase user ID. The Backup id lets us find a backup you ask us to delete; the invite code (the same characters in lower case, from app version 5.1.6) lets a friend's installation credit you (section 13). |
| Google account identifier | Google Sign-In, Firebase Authentication | Recognises your Google account when you sign in with it. Only if you sign in with Google. |
| Firebase installation ID and Analytics app-instance ID | Firebase Analytics, Crashlytics, Cloud Messaging | Distinguish installs for usage statistics (the installation identifier of section 10), crash grouping and notifications. |
| App set ID | Google Play services, for Google AdMob and Google Analytics for Firebase | Analytics and fraud prevention. |
| App-generated device ID | The app (stored in your backup) | Lets a backup hold settings for more than one device. |
We do not collect your contacts, precise location, photos, or the content of other apps. Your name and email address are collected only if you sign in, and only as described in sections 3 and 4.
Google receives data from this app through the services named above: AdMob, Firebase (Authentication — including Google sign-in and email-link sign-in — Cloud Firestore, Hosting for the email sign-in link, Analytics, Crashlytics, Cloud Messaging) and Google Play Billing. Firebase Hosting also serves the app's daily files and a copy of this website to app versions before 5.1.7. Google processes this data on our behalf; its handling is governed by the Google Privacy Policy and the Firebase privacy and security notice, and Firebase may process and store data anywhere Google or its agents maintain facilities, which may be outside your country. For ads, Google may pass an ad request to other ad companies as section 9 describes.
Two websites of ours, hosted by InMotion Hosting and delivered through Cloudflare's network, serve files the app downloads. Neither receives anything from your backup, your account or your usage statistics. Each request carries only what any web request carries: your IP address, the time, the address of the file, and the app's technical request headers (such as its user-agent string). Cloudflare also works out from the IP address which country the request comes from.
Both sites keep standard access logs of these requests (IP address, time, the file requested, user-agent) for a short period, for security and troubleshooting, and then delete them. They are not used for advertising. Cloudflare handles the same connection data under its own privacy policy.
We do not sell personal information for money, and apart from the providers named in this section we do not share it with anyone. Some US state laws count personalized advertising as a "sale" or "sharing" of personal information; section 9 explains how to opt out.
From version 5.0, all data sent by the app travels over encrypted connections (HTTPS/TLS); the earlier app's downloads from our sites use plain HTTP (section 19). Backups are protected by access rules that allow only the identity that owns a backup — anonymous or signed in — to read or change it. We store no passwords: Google handles Google sign-in, and email-link sign-in has no password at all; the sign-in link works once and only together with the address it was sent to. Firebase Authentication adds its own protection against abuse (section 4). No method of transmission or storage is perfectly secure, and we cannot promise absolute security.
The app is intended for general audiences and is not directed at children under 13 (or the age of digital consent in your country). Every feature works without an account; if you are under that age, please use the app without signing in. We do not knowingly create accounts for children or collect personal information from them. If you believe a child has signed in or provided personal information through the app, contact us and we will delete the account and backup.
If you are in the EEA or UK you have the rights of access, rectification, erasure, restriction, portability and objection under data-protection law, and the right to complain to your supervisory authority. Our legal bases are: performing the service you asked for when you sign in (the account, backup and sync), consent for personalized advertising and, from app version 5.1.8, for usage statistics, and our legitimate interest in providing a working, ad-supported free app for the rest. If you are a resident of California or another US state with a privacy law, the same email address serves your access and deletion requests. We do not sell personal information for money; where a state law counts personalized advertising as a "sale" or "sharing", Profile → Ad privacy options is how to opt out, and your device's ad settings work everywhere.
This revision (2026-10-05) describes the Amen and share records of the verse of the day (section 4) and, from app version 5.3.0, their deletion with your account (section 7). The revision of 2026-10-04 offered the website's "tell me when it is out" email to visitors on a computer too (section 13). The revision of 2026-10-03 added that email for iPhone visitors of a share or invite link. The revision of 2026-10-01 recorded, from app version 5.2.0, which kind of phone (Android or iPhone) you last signed in on and each device in a backup is (sections 2 and 4), and adds your iOS version and three Invite a friend facts to the feedback mail's support code (section 13). The revision of 2026-09-28 added sign-in on iPhone, with Apple or Google (section 20, and the name in section 3). The revision of 2026-09-27 added the iPhone app, Faith Perfect on the App Store (section 20). It also described more exactly what usage statistics record (the book, chapter and reading-plan events, keyed to an installation identifier and the advertising ID), names the two websites the app downloads from, spells out the feedback mail's support code and the invite records, and corrects what an anonymous backup can restore. It documents what changes with app version 5.1.8 — a phone's first sign-in to an account and cleared notes (section 5), consent in the EEA and UK applying to usage statistics (sections 9 and 10), and the deletion of invite records (section 7) — and states the 30-day window for deletion markers (sections 4 and 5). The previous revision (2026-09-17) added optional sign-in, syncing between devices, and self-service deletion. This policy covers every version of the app from 5.0 on; where something applies only from a particular version, the section that describes it names that version. When a future version changes what data is handled (for example comments on the daily verse), this page is updated before that version ships, and the effective date above changes.
The app before version 5.0. Some phones still run the earlier app. This paragraph describes version 4.95, the one we checked; version 4.93 was not checked. It has no account, backup, sync or invitations, and it shows ads from Google AdMob with no consent form. It sends usage events to Google's older Universal Analytics service, and these include the words you search for, every chapter you open, play or finish (by book and chapter), and the verse you save as a favorite. Google Analytics for Firebase also collects its automatic app events, with the app-instance ID and the advertising ID. Over plain HTTP, which is not encrypted, it requests three things from b.sonof.me: a small build file each time its daily-verse alarm runs (its check for updates), the narrated chapters you download (each file's address names the book and chapter), and the FAQ page when you open About → FAQ. b.sonof.me keeps access logs as section 15 describes. The rest of this page describes version 5.0 and later; what it says usage statistics never contain does not apply to version 4.95. Updating the app from Google Play brings everything described above.
The app is also on Apple's App Store, for iPhone, under the name Faith Perfect. It is the same app from the same publisher, and this page applies to it, with these differences:
Email [email protected] with any question or request about this policy.