Privacy Policy
Almost nothing leaves your phone.
1. The short version
With Him has no advertising or tracking. Reading, alarms, shielding, and writing or saving your own sermon notes work without an account. Library content is stored on your device and may sync through your private Apple iCloud account. If you choose AI sermon processing, an authenticated service sends your selected sermon recording, written notes and metadata to Microsoft Azure to prepare a draft for your review. Feedback and optional Sign in with Apple identity also reach our services when you choose those features.
The rest of this page is the same statement said precisely enough to be relied on.
2. Your voice
Verse-reading audio stays on your device and is not recorded or retained. Apple's on-device speech recogniser checks the reading. Sermon recording is a separate, optional feature with its own recording and processing controls.
What the app keeps from a spoken reading is the outcome, not the sound: that a verse was completed, when, and by which method (spoken or typed). That record is stored on the device and is what the reading history and the alarm's own logic are built from.
The microphone is used for verse reading or when you start a sermon recording. iOS displays its microphone indicator while capture is active. Sermon capture pauses when the app leaves the foreground; it does not add background recording. Obtain permission to record when required by the speaker, venue or applicable rules. Declining microphone access does not prevent manual note taking.
Choosing AI processing sends your manual writing, optional sermon metadata and recording through encrypted transport to our authenticated Supabase backend and Microsoft Azure. Azure transcribes the recording and prepares a note, with your writing treated as the primary source. You can edit the result and must confirm it before it becomes a completed sermon note. We do not log recordings, transcripts, note bodies or prompts containing your content.
3. What stays on the device
The following is held in the app's own storage. Supported library content can also sync to your private iCloud account; your Apple settings control that service. Sermon content is sent to our AI processing service only when you choose that action:
- Highlights, notes, bookmarks and reading positions.
- Reading history and which passages have been completed. If you sign in, a summary of completed verse readings is also kept on our backend — see What we do collect.
- Alarms, their schedules, and the record of which ones were answered.
- Focus Shield configuration and the apps you selected for it.
- Reading preferences: theme, text size, translation, language.
- The Bible text itself, which ships inside the app and needs no network at all.
Some of this is shared between the app and its extensions through a private App Group container on the device, which is what lets the shield and the alarm agree with the app about what has been read. That container is local; it is not a sync service.
4. Screen Time data
The Focus Shield uses Apple's Screen Time (Family Controls) framework. When you choose which apps to shield, iOS hands the app opaque tokens rather than the identities of the apps — by Apple's design we cannot see which apps you picked, and the selection cannot leave the device. Usage figures shown in the app are rendered by a sandboxed Apple extension that is not permitted to return data to us either.
5. What we do collect
The following content reaches our services only through the corresponding feature you choose.
Feedback you type
Settings → Send feedback turns what you write into an issue in our development tracker. No identifier is attached, so it is not linked to you or to your device. Do not put anything in that box you would not want stored — including your email address, unless you want a reply and are content for it to be recorded.
Identity, if you sign in
Signing in is optional for local features and required for AI sermon processing. Sign in with Apple provides an Apple user identifier, an email address — Apple's private relay address unless you share your real one — and the name Apple supplies on first authorisation. Processing jobs are linked to that account to restrict access to their owner. Ordinary highlights, bookmarks, alarms and reading positions are not sent to the AI service.
Verse readings and how a verse landed, if you sign in
When you finish a verse reading that opens an alarm or lifts the Focus Shield, the app records that reading so it can tell you how many times you have now read that passage. Each reading is one record: which passage it was, whether it came from an alarm or the shield, whether you read it aloud or traced it, and when. If you answer the optional question about how much the verse touched you, that answer — a position on a scale, with no number shown to you — is stored on the same record. The text you read is not sent anywhere; it already ships inside the app.
If you are signed in, these records are stored in our Supabase backend and are linked to your account, so the count follows you to a new phone. Row-level security restricts every record to the account that created it; the app holds only your own short-lived access token and has no credential that could reach anyone else's readings.
If you are not signed in, or you are offline, nothing is sent. The reading is recorded on your device, the count you are shown is your device's own, and the mission completes normally — an account is never required to finish a reading, stop an alarm, or lift the shield. Readings taken before you ever sign in are attributed to the first account you sign in with on that device, and are then sent. Readings belonging to one account are never sent or counted under another account on the same device.
Notes you attach when you keep a passage as a highlight stay in your own library, on the device and in your private iCloud account, exactly as any other note does. They are not part of this backend record.
Sermon content you choose to process
We process the selected audio, your written note, optional title, church, speaker, service, date and Scripture references, the resulting transcript, and the generated draft solely to provide the sermon-note feature. This content can include personal reflections or religious information that you choose to write or record. Do not include material you do not want processed by these services.
6. Purchases
Payment is processed entirely by Apple. We never see, receive or store your card details, billing address, or any other payment instrument.
To know whether a subscription is active, the app uses RevenueCat, a subscription-infrastructure provider. RevenueCat receives the App Store purchase record and an anonymous identifier it generates for the installation, and returns whether the subscription is entitled. That identifier is not linked to your name or email unless you have signed in and we associate it.
7. Tracking and advertising
There is none. No advertising identifier is read, no cross-app or cross-site tracking is performed, no data is sold or shared with data brokers, and no third-party analytics SDK is embedded in the app. The App Tracking Transparency prompt does not appear because there is nothing to ask for. The app's privacy manifest, which Apple publishes on the App Store listing, says the same thing in Apple's own format.
8. Who else is involved
These service providers have specific roles:
- Apple — the App Store, payment, Sign in with Apple, on-device speech recognition, alarms and Screen Time, under Apple's own privacy policy.
- RevenueCat — subscription status only, as described above.
- Supabase — authentication, your verse-reading history if you are signed in, and temporary private sermon uploads and processing jobs.
- Microsoft Azure — sermon transcription and AI note preparation, under Microsoft's applicable Azure AI data privacy terms.
Nothing is sold, rented or shared for anyone's marketing purposes.
9. How long anything is kept
Your original writing and saved sermon note remain until you delete them. Local recordings are excluded from device backup and kept while a draft is active or needs retry; confirming or deleting the note removes its local audio. Draft audio unused for 30 days is removed on a subsequent library cleanup, while written notes remain. An abrupt app termination may leave the current recording incomplete, without removing your saved writing.
Backend audio is deleted after a durable transcript is available. Abandoned uploads expire after 24 hours; failed processing artifacts and unacknowledged transcripts or drafts have a maximum seven-day retention window. Cleanup runs on a schedule and retries provider failures. Azure Speech jobs request a 48-hour expiry and are deleted after their results are copied. Confirming the note acknowledges the processing result so temporary backend content can be removed sooner. Provider-operated safety or abuse monitoring is governed separately by Microsoft's applicable terms.
Verse-reading records are kept for as long as the account exists, because their whole purpose is to say how many times you have read a passage over the years. They are small and they do not contain Scripture text. Deleting your account deletes every one of them immediately and permanently, along with any answers you gave about how a verse landed.
Deleting your account cancels its processing jobs, deletes your verse-reading history, and schedules removal of temporary sermon content. It does not delete your local or private iCloud library; delete individual notes in the app to remove those records. Feedback is kept while the issue it created remains useful.
After temporary content is erased, we retain minimal operation identifiers and a one-way input digest until account deletion to prevent an old request from triggering another paid processing job. Cleanup identifiers may remain longer during a service outage until erasure can be verified; they do not include the erased note or transcript.
말씀 읽기 기록 개인정보 안내
알람을 끄거나 집중 보호막을 해제하는 말씀 읽기를 마치면, 그 구절을 지금까지 몇 번 읽었는지 알려 드리기 위해 읽기 기록이 저장됩니다. 한 번의 읽기가 한 개의 기록이며, 어떤 구절이었는지, 알람과 보호막 중 무엇이었는지, 소리 내어 읽었는지 따라 썼는지, 그리고 언제였는지가 담깁니다. 그 말씀이 마음에 얼마나 와닿았는지 묻는 선택 질문에 답하시면, 숫자로 표시되지 않는 그 답도 같은 기록에 함께 저장됩니다. 성경 본문 자체는 앱 안에 들어 있으므로 어디로도 전송되지 않습니다.
로그인한 상태라면 이 기록은 인증된 Supabase 서버에 계정과 연결되어 저장되며, 기기를 바꾸어도 읽은 횟수가 그대로 이어집니다. 행 수준 보안(RLS)으로 각 기록은 그것을 만든 계정만 열람할 수 있고, 앱은 본인의 단기 접근 토큰 외에 다른 사람의 기록에 닿을 수 있는 자격 증명을 갖고 있지 않습니다.
로그인하지 않았거나 오프라인이면 아무것도 전송되지 않습니다. 읽기는 기기에만 기록되고, 화면에 보이는 횟수는 이 기기의 기록이며, 미션은 평소대로 완료됩니다. 말씀 읽기를 마치는 일, 알람을 끄는 일, 보호막을 해제하는 일에는 계정이 필요하지 않습니다. 로그인 전에 쌓인 기록은 그 기기에서 처음 로그인한 계정의 기록이 되어 전송되며, 한 계정의 기록이 같은 기기의 다른 계정으로 넘어가거나 합산되는 일은 없습니다.
읽기 기록은 계정이 유지되는 동안 보관됩니다. 오랜 시간에 걸쳐 한 구절을 몇 번 읽었는지 알려 드리는 것이 그 목적이기 때문입니다. 계정을 삭제하면 모든 읽기 기록과 마음에 와닿은 정도에 대한 답변이 함께 즉시 영구 삭제됩니다.
설교 노트 개인정보 안내
설교 노트 작성과 원본 저장은 로그인이나 녹음 없이 이용할 수 있습니다. 녹음을 시작하기 전에 필요한 허락을 받아 주세요. 앱을 벗어나거나 화면을 잠그면 녹음은 일시 정지됩니다. AI 정리를 선택하고 전송에 동의할 때만 작성한 메모, 선택한 설교 정보와 녹음이 인증된 Supabase 서버와 Microsoft Azure로 전송됩니다. AI는 직접 쓴 메모를 우선하며, 결과는 검토하고 확인 후 저장해야 완성된 노트가 됩니다.
원본 메모와 저장한 노트는 직접 삭제할 때까지 기기와 지원되는 개인 iCloud 보관함에 남습니다. 기기의 녹음은 노트 확인 저장 또는 삭제 시 지워집니다. 30일 동안 사용하지 않은 초안의 녹음도 다음 정리 시 삭제되지만, 작성한 메모는 유지됩니다. 앱이 갑자기 종료되면 진행 중이던 녹음 파일은 복구되지 않을 수 있습니다.
서버의 녹음은 대화 내용이 안전하게 저장되면 삭제합니다. 완료되지 않은 업로드는 24시간 후, 실패한 처리 자료와 확인되지 않은 결과는 최초 처리 후 최대 7일 이내에 정리 대상으로 전환됩니다. Azure 음성 작업에는 완료 후 48시간 만료를 설정하고 결과를 가져온 뒤 삭제를 요청합니다. 서비스 장애 시 실제 삭제가 늦어질 수 있어 재시도하며, Microsoft 자체 보안 및 오용 감시는 해당 약관을 따릅니다. 계정 삭제는 처리 작업과 임시 서버 자료를 정리하며, 기기나 개인 iCloud의 노트는 노트 화면에서 별도로 삭제할 수 있습니다.
10. Your rights
Depending on where you live, you may have rights to access, correct, export or erase personal data we hold, to object to or restrict processing, and to complain to a supervisory authority. Settings → Account → Delete account removes the account and starts cleanup of its temporary processing content. You can edit or delete sermon notes in the Notes library. For a copy of data or help with a request, contact us.
We do not sell personal information and do not share it for cross-context behavioural advertising, as those terms are defined under California law.
11. Children
The app is not directed at children under 13 and we do not knowingly collect personal information from them. If you believe a child has created an account, write to us and it will be deleted.
12. Changes
If this policy changes, the date at the top changes with it. A change that widens what is collected will be announced in the app before it takes effect — not left in a document nobody re-reads.
13. Contact
Write to kipackjeong@devitall.co, or use Settings → Send feedback inside the app.