Last updated: 23 August 2026
Scriptuary is a Bible reading app. For privacy questions or to exercise any of the rights below, contact us at [email protected].
Account: your email address, and optionally a display name. If you sign in with Google or Apple, we receive and store your provider ID, email, and (for Google) the name you've set with that provider — we do not store your Google profile photo. Magic-link sign-in requests are also logged with the requesting IP address, for security/abuse prevention.
Reading activity: your daily reading progress, streaks, and plan/pace preferences.
Content you create: personal notes on chapters, highlighted verses, and — if you use the Prayer Diary — the text of your prayers. If you participate in a group, this can also include discussion posts, leader notes, and sermon entries you author, which other group members can see.
Some of the above (prayer content, personal notes, and your stated theological tradition, if set) is sensitive religious-belief data, and we treat it as such throughout this policy.
Selah is powered by OpenAI. Generating a response always sends the relevant chapter reference to OpenAI. Two additional data sources are off by default and only used if you turn them on in Settings: your personal notes and your prayer diary content. If enabled, that content (or a summary of it) is sent to OpenAI to personalise the response. You can review and change these settings any time in Selah preferences.
We do not control how long OpenAI itself retains data sent to its API.
We use Sentry for error monitoring — this runs by default, as it's how we keep the service reliable, and does not include a visual recording of your session unless you separately consent to Session Replay (see below).
We use PostHog for product analytics, and Sentry Session Replay (a recording of on-screen activity, with all text and media masked/blocked by default) for deeper debugging — both are optional and only start after you accept analytics cookies via the banner shown on your first visit. You can change this choice at any time by clearing your browser's local storage for this site, or contact us to have it reset. Analytics events do not include your notes, prayers, or reading content — only usage counts and navigation.
We use Stripe for billing (paid plans only), Resend for transactional email (sign-in links, invites, notifications), and API.Bible for some licensed Bible translations (only the book/chapter/version you request is sent — no personal data). Our database and hosting run on MongoDB/Railway infrastructure.
Signing in sets one essential, httpOnly authentication cookie — it's required for the app to work and isn't part of the analytics consent choice. Your browser's local storage also holds some functional data (a cached copy of your profile for faster loading, your theme preference, and offline actions waiting to sync) and, if you've accepted analytics, a local cache of recent AI responses. None of this is shared with third parties beyond what's described above.
You can export a copy of your data (profile, notes, prayers, highlights, reading history, group memberships, authored discussions/sermons, and referral activity) at any time from Settings. You can delete your account at any time, also from Settings — this removes your private content entirely. Content you shared inside a group (discussion posts, leader notes, sermons) is anonymized rather than deleted, so the rest of the group isn't left with broken conversations or a missing sermon library — your name and account link are removed from it, but the content itself stays for the group.
Magic sign-in links expire and are removed after 15 minutes. Some AI response caches and generated summaries expire automatically after a set period (typically 7–90 days). Content you create (notes, prayers, highlights, reading history) is kept until you delete it or your account, whichever comes first.
Scriptuary is not directed at children. We don't currently have an age-verification step at sign-up — see our Terms of Service for eligibility.