The short version: We collect only what the app needs to work. Your journals and saved verses are encrypted on our servers and on your device. We never sell your data. Analytics are off unless you opt in. You can delete your account — and everything in it — at any time from inside the app.
1. Who We Are
Goodness Bible App ("Goodness", "the app", "we", "us", "our") is operated by Cosvire and available at goodnessbible.com and on Google Play. This policy covers the Android app and the website. For any privacy question, email contact@goodnessbible.com.
2. Information You Provide
- Account: your email address. We sign you in with a one-time passcode (OTP) sent to that email — the app does not use passwords.
- Profile: first and last name, a unique username, and optionally a profile photo and short bio.
- Your content: journal entries, saved (favourite) verses, prayer requests, and community posts (text, and images or video you choose to attach).
- Custom card backgrounds: if you set your own image behind the Verse of the Day card while signed in, that image is stored with your account so it appears on your other devices. As a signed-out guest, the image stays only on your device.
- Contact messages: anything you send us through the in-app or website contact form (stored so we can reply).
3. Information Created As You Use the App
- Reading position & preferences: your last-read chapter, chosen app language, primary/secondary Bible versions, and theme are saved to your account so your setup follows you across devices.
- Reading streak & audio settings: your daily reading streak and text-to-speech options are stored locally on your device only.
- Engagement on shared content: likes and prayer counts you add to community and prayer posts.
4. Information Collected Automatically
- Analytics & crash reports (opt-in): when you leave "help improve the app" usage reporting enabled, we collect anonymised usage statistics and crash diagnostics via Google Firebase Analytics and Crashlytics. This is off until you consent, and you can turn it off any time in Settings. No journal, prayer, or message content is ever included.
- Device integrity signal: the app asks Google's Play Integrity API for a signed verdict that it is the genuine, unmodified app running on a genuine device. We use this only to block fraud and abuse. It does not identify you personally.
- IP address: seen transiently by our server for rate-limiting and abuse prevention. It is not used to build a profile of you and is not retained long-term.
- Advertising ID: the app does not serve ads and does not use the device advertising identifier for advertising.
5. Device Permissions
- Photos / gallery: requested only when you pick an image for your profile, a card background, or a community post. We access only the image you select.
- Notifications: requested only if you choose to receive reminders and updates. You can revoke it in your device settings at any time.
- Internet: used to sync your account, fetch verses in other translations, and load community content. The bundled Bible itself works fully offline.
6. How We Use Your Information
- To create and secure your account and sign you in with one-time passcodes.
- To provide app features — Bible reading, journals, favourites, prayer wall, community, devotions, events, and audio.
- To sync your content, preferences, and reading position across your devices.
- To send transactional emails (your sign-in code) and, if you opt in, notifications you have chosen.
- To keep the service safe (rate limiting, integrity checks, abuse prevention).
- To understand and improve the app — only with anonymised, opt-in analytics.
7. How We Protect Your Data
In transit
All traffic uses HTTPS/TLS. The Android app additionally pins our server certificate and its network configuration blocks unencrypted (cleartext) connections, which helps prevent interception on untrusted networks.
At rest — on our servers
- Sensitive content is encrypted at rest with AES-256-GCM. This includes your journal entries (title, body, the referenced verse and its citation) and your saved verses (verse text and its book/chapter/verse reference).
- Saved-verse references are additionally indexed using a keyed HMAC so the app can find and de-duplicate them without exposing the underlying reference.
- One-time passcodes are stored only as a hash, are single-use, and expire shortly after being issued.
- Where a password is ever used (e.g. the website portal), it is stored as a bcrypt hash — never in plain text.
At rest — on your device
The app's local database (including the offline Bible and your cached content) is encrypted using SQLCipher, and your session token is held in the platform's encrypted secure storage (Android Keystore-backed).
Application integrity & web
Requests to our API are verified with the Play Integrity attestation described above and signed session tokens. Website sessions use HttpOnly, SameSite=Strict cookies over HTTPS, and web forms are protected by Google reCAPTCHA. No system is perfectly secure, but we take these measures to protect your data.
8. Notifications
Notifications are opt-in. Reminders you schedule are generated on your device, and announcement-style notifications are fetched from our own server — we do not use a third-party push-advertising network. You can disable them at any time in the app or your device settings.
9. Payments
Optional in-app purchases (such as contributions/donations and shop items) are processed entirely by Google Play Billing. Google handles the payment; we never receive or store your card or bank details. Google's privacy policy governs that transaction.
10. User-Generated Content & Moderation
Prayer requests and community posts are visible to other users once approved by moderation. Journal entries are private to you. You can edit or delete your posts, prayer requests, journals, and favourites at any time from within the app or the web portal.
11. Data Sharing
We do not sell, rent, or trade your personal data. We share data only with:
- Google — Firebase (opt-in analytics & crash reporting), Play Integrity (app attestation), and Play Billing (purchases). Google's privacy policy applies to these services.
- Legal obligations — where required by law, or to protect the rights, safety, and security of our users and service.
12. International Transfers
Our providers (such as Google) may process data on servers located in other countries. Where data is transferred internationally, it remains subject to appropriate safeguards and this policy.
13. Data Retention
We keep your data while your account is active. When you delete your account, your associated personal data is removed within 30 days, except where we must retain limited records to meet legal obligations. Opt-in analytics data is retained by Google per its own retention settings.
14. Your Rights & Choices
- Access, correct, export, or delete your personal data.
- Delete your account and all associated content directly from within the app.
- Turn analytics on or off at any time via the usage-reporting toggle in Settings.
- Manage notifications and permissions from the app or your device settings.
To exercise any right, email contact@goodnessbible.com. Depending on where you live, you may have additional rights under laws such as the GDPR or CCPA.
15. Children's Privacy
Goodness is not directed at children under 13. We do not knowingly collect data from children under 13. If you believe a child has provided us data, contact us and we will delete it promptly.
16. Changes to This Policy
We may update this policy from time to time. Significant changes will be notified via the app or email, and the "last updated" date above will change. Continued use after an update constitutes acceptance.
17. Contact
Questions or requests? Email contact@goodnessbible.com. See also our Terms of Service and Disclaimer.