BeBible · Tappedin Apps LLC
Privacy Policy
Last updated: September 6, 2026
BeBible is operated by Tappedin Apps LLC ("we", "our"). BeBible ("the app") is a Christian discipline app: it guards the apps you choose behind Scripture, and gives you one shared daily quiet time with a small private group of friends. This policy explains what information BeBible collects, why, and your choices.
BeBible was previously called Altar. The app is now operated by Tappedin Apps LLC following an App Store account transfer.
The short version
- BeBible is local-first. Your core data stays on your device.
- We do not sell your data. We do not track you across apps or the web. We do not run ads.
- The free tier does not require your name, email, phone number, or any contact information.
- Your Screen Time app selections never leave your device.
- The Bible Assistant is part of a BeBible subscription and requires Sign in with Apple. Apple authenticates your sign-in, and Supabase assigns an account UUID that we use to verify your subscription and apply rate limits. Apple may also share your name and your chosen real or relay email address during sign-in.
- Groups are an optional, opt-in community feature. Sign in with Apple is required. Free accounts may create or join one Group, while Premium accounts may belong to up to ten Groups. A free Group holds four people, and a Group whose owner has Premium may hold up to fifty people. If you create or join a Group, the posts, comments, and photos you share are visible to its invited members.
What we collect
Information stored on your device
- Your selected blocked apps (Screen Time / Family Controls data).
- Your reflections and intervention history.
- Cached Bible text bundled with the app.
- Settings, streaks, and unlock history.
- OCR'd passage text from Scan to Unlock, except when you choose remote AI identification or share a passage with a Group.
- Your onboarding answers, including your age. During setup we ask how old you are, how often you read, what pulls you away, and how long you want to spend each morning. These shape the plan we suggest and are stored on your device. Your age is not uploaded. If you enable and use AI assistance, a selected struggle may be included as context for your question, as described below.
The name you type may also be shared, only if you choose to sign in with Apple. It is then used as the default display name your Group members see, so that people who know each other can recognise each other. You can change it at any time in your profile → your name. If you never sign in, your name never leaves your phone either.
Sign in with Apple and your account
The Bible Assistant and Groups require Sign in with Apple. When you sign in, Apple provides an opaque sign-in identifier and may share your name and a real or private relay email address, depending on your choices. Supabase links this identity to its own account UUID. We use account information to:
- Verify your active BeBible subscription before granting access to Pro features.
- Apply per-user rate limits to the Bible Assistant so the feature stays affordable.
- Identify you to other members of any Group you join (display name only).
- Maintain your authenticated session.
- Honor Apple Guideline 5.1.1(v) account deletion (your profile → Account → Delete account).
We do not receive your Apple Account password. We may receive the name and real or relay email address you choose to share. Email addresses are never shown to other members and are never used for marketing.
Anonymous baseline session
Before you've signed in with Apple, the app may create an anonymous Supabase session for connectivity. This session has a Supabase account UUID and session credentials. It cannot be used to access the Bible Assistant or Groups — those features explicitly require Sign in with Apple. Do not rely on an anonymous session as a way to recover an account after reinstalling.
Purchase records
If you buy a subscription, Apple processes the transaction. BeBible uses RevenueCat to manage purchase and subscription status. RevenueCat processes app user identifiers and purchase information, including products, transactions, subscription dates, and entitlement status. Before account linking, RevenueCat can use its own anonymous app user ID; after sign-in, BeBible links RevenueCat to your Supabase account UUID. Our backend also keeps subscription entitlement information to authorize paid features. We do not receive your payment card details.
Bible Assistant and Scan-to-Unlock AI assistance
The Bible Assistant is a subscription feature that requires Sign in with Apple and an active BeBible subscription. Scan to Unlock is free and normally identifies passages on your device. If on-device identification is uncertain, a signed-in user who has enabled AI assistance may ask our backend to identify the passage; this does not require a subscription.
Your explicit consent is required before any AI request leaves the device. The first time you tap a Bible Assistant button or request remote Scan-to-Unlock passage identification, a primer sheet describes what will be sent and to whom and asks you to allow AI assistance. Per Apple App Review guideline 5.1.2(i), this consent is opt-in and revocable: you can turn AI assistance off at any time in your profile → Account → Privacy → AI assistance. While AI assistance is off, the Bible Assistant falls back to local offline responses and Scan to Unlock stays on-device with manual reference entry available; nothing is transmitted to OpenAI.
When AI assistance is on and you use these features, your question, relevant passage context, selected struggle when supplied, or OCR'd passage text is sent to our Supabase Edge Function over HTTPS. The Edge Function validates your Supabase session and uses your Supabase account UUID to authenticate the request and apply per-user rate limits. It verifies an active Pro entitlement for Bible Assistant chat, but not for Scan-to-Unlock passage identification. It records the timestamp of the request (so we can rate-limit abuse); the prompt text itself is not stored server-side. The prompt is forwarded to OpenAI's API to answer a Bible Assistant question or identify a Scripture passage. We do not attach your account identifier to the prompt sent to OpenAI. Any personal information you include in your question is part of that prompt. Under OpenAI's standard API data-usage policy, prompts sent via the API are not used to train OpenAI's models. If the Edge Function is unavailable, the Bible Assistant falls back to offline responses and Scan to Unlock retains on-device and manual identification.
AI-Generated Content (disclaimer)
Responses from the Bible Assistant are produced by a generative AI model and may be inaccurate, incomplete, or theologically imprecise. Remote Scan-to-Unlock passage identification may also identify a reference incorrectly. AI output is not professional spiritual, medical, legal, or financial advice. Always verify Scripture references against a trusted Bible translation and consult your pastor or a qualified mentor for important decisions. BeBible surfaces a similar in-app reminder near the assistant interface.
We do not attach your account identifiers or photos to OpenAI requests. Requests contain your question, relevant Scripture context, OCR'd passage text for identification, and a selected struggle when supplied. Avoid including personal information you do not want processed in your questions. OpenAI processes those prompts under their standard API policy (https://openai.com/policies/api-data-usage-policies); they do not train on inputs sent through their API.
Groups (optional community feature)
Groups is an opt-in feature for invite-only accountability groups. It is off until you choose to use it. If you create or join a Group, the following applies:
- Sign in with Apple is required. When you sign in, Apple provides a sign-in identity that Supabase links to your account UUID, and may share your name and your chosen real or relay email address. We use these only to:
- Identify you to other members of Groups you join (display name only).
- Maintain your authenticated session.
- Honor Apple Guideline 5.1.1(v) account deletion ("Delete account" in your profile → Settings).
- Email addresses are never shown to other members and are not used for marketing.
- What members of your Group see: your display name, any post text or Scripture passage you share, your photos, and the comments and one-level replies you add to Group posts. Comments and replies cannot be edited after posting, but their authors can delete them.
- What members do not see: your email, your Apple ID, your Screen Time selections, your other Groups, or any of your private reflections from the rest of the app.
- Photo storage: When you choose to post a captured photo pair, BeBible stages it in the app's private storage for upload and local Memories. If you grant Photos access, BeBible can also place a recovery copy in a named BeBible album. Photos shared to a Group are uploaded to private Cloudflare R2 storage for temporary feed delivery and are available only through short-lived links issued to authorized Group members.
- Reports and blocks: if you report a post, comment, or reply, the author is not notified. Your first report hides that content from you; reports from two distinct members hide it from the Group pending review. If you block another user, neither of you can see the other's posts, comments, replies, or profile content in shared Groups. Because blocking does not remove either person from a Group, factual membership remains visible in its roster and owners retain the ability to remove members. The blocked user is not notified.
- Retention and deletion: while you remain a member of a Group, you can delete posts, comments, or replies you authored. Deleting a top-level comment also deletes its replies. Post deletion removes server rows and requests cleanup of temporary feed photos, app-private files, and matching assets in the BeBible Photos album. These are separate operations: a failed cleanup can leave an R2 object, local file, or Photos copy after a post disappears. A post leaving the daily feed or a signed link expiring does not itself delete its stored photo bytes; R2 deletion and storage lifecycle cleanup are separate. Leaving a Group revokes your access but does not delete content you shared. Account deletion removes account-related database records, including your profile, content, and block list; it does not guarantee simultaneous deletion of every stored media copy. Limited report records may remain as moderation evidence, containing the report reason and optional details rather than deleted content. Account deletion does not delete recovery copies already saved to Apple Photos. You can remove those separately in Photos; contact us if you need help with remaining server media.
- Service providers: Group rows are stored in Supabase and temporary feed photos are stored in Cloudflare R2. Group content is not sent to OpenAI or used for advertising.
Notifications and support
If you allow notifications and sign in, BeBible stores your APNs device token, app identifier, platform, and notification environment against your account in Supabase so it can deliver Group notifications through Apple. Notification payloads can include Group activity and comment previews. You can manage notification permissions and previews in iOS Settings.
If you contact support, we receive your email address and the information you choose to include so we can respond. Please avoid sending passwords, sign-in codes, or private Group content.
What we do NOT collect
- Your phone number or contacts. Names and email addresses may be provided through sign-in, your profile, or a support request.
- Your Apple Account password. Authentication does use Apple identity tokens and Supabase session credentials.
- Which specific apps you have blocked.
- Unrelated photos or camera content outside Groups. Camera frames captured by Scan to Unlock are processed in-memory and not retained. If you grant Photos access for Group recovery copies, BeBible limits its Photos work to creating, finding, writing, and deleting identified assets in the named BeBible album; it does not scan your other albums.
- Location.
- Private spiritual data for general cross-device cloud sync. This version does not enable that feature; standard iOS backups are separate.
How we use your information
- To run the app's core features (interventions, streaks, reading plans).
- To verify your subscription before granting paid Group creation or capacity options and the Bible Assistant, and to apply the Group access rules shown in the app.
- To rate-limit the AI Bible Assistant fairly across paying users (per-Supabase-account and per-IP).
- To improve the app's reliability by aggregating anonymous crash and error data (iOS system-level only — we do not run third-party analytics SDKs).
Product analytics (opt-out)
To help us see where the onboarding or paywall trips people up, BeBible sends pseudonymous product-interaction events (for example: which onboarding step you reached, that a paywall was viewed, an intervention was completed, an exit-survey reason was selected) to our own Supabase backend. This is on by default and can be turned off at any time in your profile → Account → Privacy → "Help improve BeBible." The mirror is first-party — the same Supabase backend that powers Groups. We do not use PostHog, Mixpanel, Amplitude, or any other third-party analytics SDK.
- We never send the text of your reflections, prayers, scans, journal entries, or Group posts through this channel.
- Events are grouped by a random UUID we generate on first launch and store on-device (the "install identifier"). Events also carry the Supabase account UUID for the current session, including an anonymous session. These identifiers do not themselves contain your name or email.
- Once you sign in with Apple, events can be associated with your authenticated Supabase account UUID, which is also used for entitlements.
- Events older than 90 days are purged.
- Turning it off stops new events immediately. To remove your previously-recorded events, use Settings → Account → Delete Account, which removes analytics rows tied to the deleted account. Events associated with an earlier anonymous account may remain until the retention cleanup.
How we protect your information
- All network traffic uses HTTPS/TLS.
- The Supabase account UUID used for backend authorization does not itself contain your name or email.
- Per-IP and per-user rate limits prevent abuse of the AI backend.
- On-device data is stored via Apple's SwiftData framework, encrypted by iOS at rest.
Data transfer when you upgrade your phone
When you transfer to a new iPhone via Quick Start, iCloud Backup, or an encrypted local backup, eligible on-device data can be carried over through Apple's migration or backup mechanisms, depending on your device and backup settings. If you set up your new phone "as new" without restoring a backup, that data does not transfer because BeBible does not sync to the cloud.
Your choices
- Reset all app data in Settings → Account → About → Reset All App Data. This resets local app data. It does not automatically delete server content or copies saved to Apple Photos.
- Revoke Screen Time access in iOS Settings → Screen Time → Family Controls. BeBible will continue to work with a limited feature set.
- Revoke camera access in iOS Settings → Privacy → Camera. Scan to Unlock will be unavailable.
- Leave or disband a Group — leaving revokes your access but does not delete your content from the Group; disbanding (owner only) deletes the Group and all its content for everyone.
- Block another member in any Group from the post menu, or manage your block list in Settings → Groups → Blocked Members.
- Delete your account in Settings → Account → Delete Account. This permanently removes your Groups content, profile, block list, and authenticated session, then signs you out. Limited report records may remain as moderation evidence as described above.
- Delete the app to remove its local app container. Copies in Apple Photos and device backups are separate. If you have used Groups, also use Delete Account first so your Groups content is removed from the server.
Children
BeBible is not directed at children under 13 and does not knowingly collect information from them.
During onboarding we ask your age so we can suggest a realistic daily plan. That answer stays on your device — it is not uploaded, not stored on our servers, and not used to build a profile of you. We do not use it to target advertising, because BeBible contains no advertising of any kind.
Third parties
- Supabase (backend): hosts our Edge Functions and stores Group rows (profiles, memberships, posts, comments, reports, and blocks) for users who opt in. It receives your Supabase account UUID, authentication information, and request timestamps when you use a BeBible server feature. For Groups, it also receives your chosen display name and the content you post. See supabase.com/privacy.
- Cloudflare R2 (temporary photo storage): stores Group feed photos for short-lived delivery to authorized members. See cloudflare.com/privacypolicy.
- OpenAI (via our Edge Function): processes Bible Assistant prompts and optional Scan-to-Unlock passage-identification prompts when those features are used. Receives prompt content and context, without an attached account identifier; personal information you type may be included. See openai.com/policies/privacy-policy.
- RevenueCat (subscription state): processes anonymous or linked app user IDs, purchase records, and entitlement information so we can manage and verify your subscription. BeBible uses your Supabase account UUID when linking your account. We do not send your Apple Account password. See revenuecat.com/privacy.
- Apple (Sign in with Apple, StoreKit): handles authentication for subscription features (Bible Assistant, Groups) and processes purchases. Apple provides a sign-in identifier and, depending on your choices, your name and a real or relay email address. StoreKit provides transaction information.
Changes
We will update this policy as the app evolves. The "Last updated" date at the top reflects the most recent version.
Contact
Questions about BeBible or this policy? Contact Tappedin Apps LLC at kyle@tappedinapps.com or visit https://www.tappedinapps.com/support.