Privacy Policy
- Effective
- 8 September 2026
- Last updated
- 8 September 2026
In short
We store your account and the things you write (your plans, notes, prayers, journal and routine) because the app cannot show them to you otherwise. Nobody else can see any of it.
There is no analytics, no advertising, no tracking and no push notifications in HolyFit. We do not know which screens you open. Your reminder times never leave your phone. We do not sell or share your information, and we never have.
You can delete your account from inside the app, under Profile. Everything in it goes with it, permanently and immediately.
This summary is here to be understood, not to replace what follows. Where the two differ, the full text below is what applies.
1.Who we are, and what this covers
This policy covers the HolyFit mobile app and this website, and explains what happens to information about you when you use them. “We” and “us” mean the operator of HolyFit.
For readers in the UK and the European Economic Area, we are the data controller for that information. If you would rather not read the whole document, the summary above is accurate and the sections on deletion and your rights are the ones most people want.
2.Information you give us
Your account
Accounts are handled by Clerk, an authentication provider. When you sign up, Clerk records your email address and, if you supply them, your name, username and profile picture. We keep a copy of those four things so the app can greet you and show your account without calling Clerk on every screen.
Your password, if you use one, is held by Clerk and never reaches us. We cannot read it and cannot recover it.
What you create in the app
Everything the app is for is stored so that it survives losing or replacing your phone:
- Reading plans: the title, description, dates and the list of passages you chose.
- Passages and notes: which you have marked as read, and anything you wrote about one.
- Prayers: the requests you write down and whether you have marked them answered.
- Journal entries: your daily reflections, one per day.
- Your routine: how many sittings of each kind you keep, the hour of each, and which ones you kept on which day.
- Settings: your chosen translation and which notices you have already seen.
This is the private, personal material the app exists to hold. It is treated accordingly: see Security.
3.Information created as you use it
Two things are produced by the act of using the service rather than typed in by you.
- A session token, stored in your device’s secure keychain so you are not asked to sign in every time you open the app. It stays on your device. Deleting the app removes it.
- Server logs. Our API and its hosting provider record ordinary request information (the time, the route called, the response status and the originating IP address) for a short period. These are used to keep the service running and to investigate faults and abuse. They are not used to build a picture of you, and they are not combined with what you write.
4.What we do not collect
Stated specifically, because “we value your privacy” is not information. None of the following exists in the app:
- No analytics. There is no analytics or product-measurement SDK of any kind. We do not know which screens you open, how often you open the app, or how long you stay.
- No advertising and no ad identifier. We do not show ads, use an ad network, or read your device’s advertising identifier.
- No cross-app or cross-site tracking. Nothing about you is shared for tracking purposes, so the app never asks for App Tracking Transparency permission.
- No push notification tokens. See Reminders.
- No location, contacts, calendar, photos, microphone, camera or health data. The app does not request access to any of these.
- No cookies on this website beyond what is needed to serve the page. There is no tracking pixel and no third-party script; the fonts are served from this site rather than from Google.
5.How reminders work, and why it matters
When you set a routine, the app schedules a local notification on your phone for each sitting. That scheduling is done entirely by the device, using the hours you chose.
There is no push notification service involved and no push token is ever registered or sent. The practical consequence: no server of ours, and no third party, ever learns what time you pray or read. The hours are stored with the rest of your routine so they survive a new phone, but nothing outside your device acts on them.
6.Why we are allowed to hold it
Under the UK and EU GDPR, the lawful bases we rely on are:
- Performance of a contract: for your account and everything you create. We cannot show you your journal without storing your journal.
- Legitimate interests: for short-lived server logs, used to keep the service available and to prevent abuse. We have considered this against your interests and consider the impact minimal, as the logs are not used to profile anyone.
- Consent: for device notification permission, which you grant to iOS and can withdraw at any time in Settings without losing anything else.
7.What we use it for
Only these things:
- To sign you in and keep you signed in.
- To show you your plans, passages, notes, prayers, journal and routine, and to save changes to them.
- To work out what your day looks like: what you have kept, and what is next.
- To reply to you when you contact support.
- To keep the service running, secure and free of abuse.
- To comply with the law where we are legally required to.
We do not use what you write to train machine-learning models, and we do not read it except where you have explicitly asked us to look at something in a support request, or where the law requires it.
8.Who else processes it
We use a small number of service providers to run HolyFit. They act on our instructions and may not use your information for their own purposes. This is the complete list.
| Provider | What for | What it sees |
|---|---|---|
| ClerkUnited States | Accounts and sign-in | Your email address, name, username and profile picture, and the session that keeps you signed in. |
| SupabaseRegion selected at project creation | Database | Everything you create in the app: plans, passages, notes, prayers, journal entries, your routine and which sittings you kept. |
| RailwayUnited States | Hosting for the HolyFit API | Requests between the app and the database, and short-lived server logs of those requests. |
| API.BibleUnited States | Scripture text | The passage reference being read, for example "1 John 2:1". Never your identity: the request is made by our server with our key, not by your device. |
| AppleUnited States | App distribution | Your download and, during testing, your TestFlight participation. Governed by Apple’s own privacy policy, not ours. |
Beyond these, we disclose information only if we are legally compelled to, or where it is necessary to establish or defend a legal claim. If we are ever compelled, we will tell you unless we are prohibited from doing so.
We do not sell your personal information, and we do not share it for cross-context behavioural advertising, in the specific senses those terms are given by the California Consumer Privacy Act. We never have.
9.Where it is stored
Our providers are based in the United States, and your information is processed there. If you are in the UK or the EEA, that is a transfer outside your home jurisdiction.
Those transfers are covered by the Standard Contractual Clauses (and the UK Addendum where relevant) in our agreements with each provider, which is the safeguard the GDPR provides for this situation. You can ask us for details of the safeguards that apply.
10.How long we keep it
- Your account and everything you create: for as long as your account exists. It is your journal; it is not ours to expire.
- Server logs: a short period, typically no more than 30 days, then discarded.
- Support emails: up to two years, so we can pick up a thread you return to.
- After deletion: removed from the live database immediately, and from encrypted backups within 30 days as those backups age out.
11.Deleting your account and your data
In the app: open Profile → Delete account. You will be asked twice, and then it happens immediately. There is no queue and no cooling-off period during which we still hold it.
By email: if you have lost access to the app, write to privacy@useholyfit.com from the address your account uses. We will confirm and complete it within 30 days, usually much sooner.
Deletion removes the account and everything attached to it: every plan, passage, note, prayer, journal entry, routine and setting, and the sign-in record held by Clerk. It is permanent and there is no way to undo it. So if you want to keep your journal, ask us for a copy first (see your rights) and we will send it before deleting anything.
You can also delete individual items at any time in the app without deleting your account. Deleting the app from your phone does not delete your account, because the point of the account is that your journal survives the phone.
12.Your rights
Wherever you live, you may ask us to:
- Give you a copy of the information we hold about you, in a portable format.
- Correct anything that is wrong.
- Delete your account and its contents.
- Restrict or object to a particular use of it.
Write to privacy@useholyfit.com. We will not charge you, and we will not treat you differently for asking. We may need to confirm you control the email address on the account before acting, which is a protection for you rather than an obstacle.
If you are in the UK or EEA and you think we have handled this badly, you can complain to your national data protection authority: in the UK, the Information Commissioner’s Office. We would rather you told us first, but you do not have to.
13.Security
Traffic between the app and our servers is encrypted in transit, and data is encrypted at rest by our database provider. Your session token is held in your device’s secure keychain, not in ordinary app storage.
The more important measure is structural. Every table is protected by a database-level rule that checks a row belongs to the signed-in reader before it is returned, and our API reaches the database as you, using your own session. It holds no master key that would let it read everyone’s rows. A bug in our code therefore cannot hand your journal to another reader, because the database itself would refuse to produce it.
No system is perfectly secure, and we will not claim otherwise. If we ever discover a breach affecting your information, we will tell you and the relevant regulator as the law requires.
14.Children
HolyFit is not directed to children under 13, and we do not knowingly collect personal information from them. If you believe a child under 13 has created an account, write to privacy@useholyfit.com and we will delete it.
15.Changes to this policy
If this policy changes, the date at the top changes with it. For anything that materially affects how your information is handled, we will tell you in the app before it takes effect rather than relying on you to re-read this page.
16.Contact
Privacy questions and requests: privacy@useholyfit.com
Everything else: support@useholyfit.com
Operator: HolyFit. See also our Terms of Service.
Questions about this document? Write to support@useholyfit.com.