Privacy Policy
Last updated September 20, 2026 · Applies to Holdfast, including the iOS app and the Android app currently available through private beta testing (the “app”), published by Fremdly.
The short version. What you practice and how you practice it is between you and God, not us. Your recall attempts, mistakes, notes, and private recordings you choose to keep stay on your device, except for content you deliberately include in a feedback message or screenshot. If you use an account, Firebase Authentication stores the identity information needed for sign-in, and Cloud Firestore stores your saved passages and review schedule for account backup and restore. Continuous multi-device sync while you study is a Pro feature. We never sell data, we show no ads, and the app-authored analytics events and crash diagnostics do not contain Scripture text or anything you typed or said.
What stays on your device
The following stays on your device during normal use. It is not included in automatic analytics or crash reports. You can separately choose to share visible content in a feedback screenshot:
- Your typed recall attempts and the words you miss during practice.
- Your raw practice and mistake history.
- Recite/Say It microphone input and speech transcripts are transient inputs for on-device recall scoring. Speech recognition runs on-device only — the app refuses to use cloud speech recognition — and the attempt audio and transcript are discarded after scoring. This is separate from any private recording you explicitly keep.
- Private recordings you choose to keep, where the feature is available, stay on this device until you delete or replace them. They are not synced and are not sent to analytics or crash reports.
- Personal reflections, notes, and visual memory aids.
Account and sync (optional)
You can use the app without an account. If you sign in through a Firebase Authentication provider available in your beta build, the account backup and restore path stores the following in your private space in Google Firebase (Cloud Firestore), readable by no other user. Continuous multi-device sync after the initial restore is available with Pro. Available sign-in providers vary by platform and beta build; a provider can be configured in Firebase before its app flow is implemented:
- Your saved passages: the Scripture reference, the passage text for translations whose license permits storage, the translation credit, and collection/status metadata.
- A summary of your review schedule (due dates, intervals, progress) — never your raw attempt or mistake history.
Firebase Authentication handles sign-in and Cloud Firestore stores the account records above. Firebase Cloud Messaging is used only where the current beta build enables it and only after you opt in to a remote-push category, such as study reminders or announcements. The app may also schedule reminders locally; local notification permission is separate. Delivery behavior varies by platform and beta build. When enabled, Firebase Analytics and Crashlytics process the coarse events and diagnostics described below.
Where enabled by the current beta build, Android uses Firebase App Check with Google Play Integrity and iOS uses Firebase App Check with Apple App Attest for protected backend requests. These services provide app/device integrity signals to Firebase without including practice content.
You can permanently delete your account from inside the app on both iOS and Android. The flow requires fresh provider authentication, removes and verifies the app-owned account data covered by its current deletion sweep, and clears account-scoped local copies. Matching account quota records for the deleted account are removed by asynchronous cleanup and may finish after the in-app flow; unrelated records are untouched. It does not promise complete erasure of every provider, service, log, backup, or separately configured backend record. The app blocks normal content until recovery completes if local cleanup is interrupted.
Delete your Holdfast account — see the public deletion steps, data details, and retention information.
The deletion flow intentionally retains a server-side account-deletion fence keyed by the Firebase account identifier in its document path. It contains no Scripture, notes, or practice history and remains to prevent stale signed-in devices from writing records again. This server-side key is distinct from the one-way SHA-256 Firebase-user-ID digests retained locally for ownership and recovery. On iOS, the local deletion workflow also keeps a phase marker; after the local reset completes, sync metadata retains a content-free completed-deletion digest for account-isolation checks. Local markers contain no raw user ID or practice content.
After account deletion, Android retains a content-free device security marker: a one-way SHA-256 digest of the first account's Firebase user ID, or an unknown-ownership marker. This prevents a later account's cleanup from erasing another person's preserved data. It stays only in local app data, has no timed expiry, and survives sign-out, account switching, deletion, and recovery resets. The app excludes its local data from Android cloud backup and device transfer. See the deletion page for details.
Telemetry and notifications
- No ads, no ad tracking, no sale or rental of personal data — ever.
- App-authored events and nonfatal reports sent to Google Firebase Analytics and Crashlytics use only coarse, predefined event names and bucketed numbers. The app does not add Scripture text, your selected passages, recall attempts, transcripts, notes, or your email or user ID to them.
- Separately, Firebase SDKs and infrastructure may automatically process device/app identifiers (including a Firebase Installation ID or push-token identifier), IP address, device/app metadata, and technical diagnostics needed to provide these services. This is distinct from the app-authored event payload above and is handled by Google under its terms.
- Remote notifications are optional. Where the current beta build uses Firebase Messaging, installation registration begins only after you opt in to at least one remote-push category, such as Daily study reminders or Announcements and news. Local notifications may also be used. Opted-in practice reminders may include a passage reference and limited due or streak counts, but never passage text, notes, recall answers, transcripts, or audio. Delivery availability varies by platform and beta build.
Optional widgets, Shortcuts, and Android launcher shortcuts are provided by the operating systems. If you add or invoke one, it may show the reference and practice status already selected for that surface according to your device's home-screen or lock-screen settings. These integrations do not export recall answers, notes, audio, or transcripts; the operating system controls where an enabled widget or shortcut is visible.
Feedback you choose to send
Send Feedback in Settings, or shake the app while it is open, to prepare a bug report, issue, or idea. Shake to Send Feedback starts on and can be turned off in Settings. Shaking never sends a report automatically. You review the message and any screenshot before tapping Send.
A screenshot may show private content visible on your screen, including Scripture or notes. You can remove it before sending. Include Diagnostics starts off. If you enable it, the report contains up to 40 predefined app event names from the last 15 minutes, relative timing and optional numeric error codes. These diagnostics contain no raw logs, note text, prayer content, recall answers, passage references, account identifiers or authentication tokens. The short event list exists only in app memory; it is separate from optional automatic analytics.
Reports include your category and message, app version/build, operating-system version, hardware model, a random report ID, and the attachments you choose. A Cloudflare Worker verifies app integrity, limits submissions and saves the report in a private Google Cloud Firestore inbox. You do not need to sign in. We do not attach your Firebase account ID or email address. Infrastructure providers may process network addresses and integrity identifiers to deliver and protect the service; we do not save your IP address with the report.
Authorized maintainers, including authorized AI-assisted review tools, may review reports to diagnose bugs, respond to issues and consider improvements. Reports are not public. Report contents are not sent as Analytics events or Crashlytics logs; a separate coarse submission outcome may be recorded when telemetry is enabled. We do not use feedback for advertising.
Daily housekeeping removes screenshots after 14 days and reports after 90 days; removal can take until the next successful daily run. Unsaved drafts and screenshots are discarded when you cancel or close the app. Account deletion does not automatically identify these reports, because they are not linked to your account. To request earlier deletion or follow up, email the contact below with the report ID shown after submission. Avoid including information you do not want maintainers to see.
Performance and experiments
Features and connected services vary by platform and beta build. Where a build includes Firebase Performance, Remote Config, or related experiments, its telemetry choice controls app-initiated requests as described in that build. The app remains usable when you decline where the build offers that choice.
Firebase may process performance measurements, device and app metadata, an installation identifier, and IP-derived geography. Remote Config may use Analytics properties or first-open timing to assign configuration; A/B Testing uses Analytics for experiment membership and measurement. No experiment or optional service is promised to be active in every build. Our custom performance measurement uses a fixed name and duration, with no Scripture, notes, prayers, account identifiers, or URLs added.
Turning telemetry off stops new requests and measurements initiated by these app adapters. It cannot recall data already sent or automatically erase SDK caches and experiment assignments. Other enabled Firebase services may continue using their shared installation identifier.
Purchases
Subscriptions and purchases are processed by Apple's App Store or Google Play and managed through RevenueCat. RevenueCat receives your purchase state and the app-user identifier used to associate entitlements. That identifier can be anonymous before sign-in; signing in lets the app associate entitlements for restore across devices. We never see or store your payment details.
AI coaching (as this feature rolls out)
The app includes an optional coaching feature that suggests what to practice next and how. It is designed so that artificial intelligence can help without your data leaving the boundary above:
- The core recommendations are computed on your device by deterministic rules and work with AI disabled or offline.
- When cloud AI assists, the app sends a small, strictly structured request to our service running on Cloudflare containing only non-identifying practice signals — for example, coded reason categories, accuracy ranges, and candidate passage references. It never contains Scripture text, your recall attempts, missed words, notes, transcripts, your name, email, or account ID.
- Cloudflare processes these requests as our service provider and states that customer content on its AI platform is not used to train models. We do not store the AI requests or responses.
- On supported devices, some coaching runs entirely on-device (Apple Intelligence on iOS; Google's Gemini Nano via ML Kit on Android). On Android, Google's ML Kit reports technical performance metrics (not your content) to Google to operate the service.
- AI-assisted suggestions are memorization coaching, clearly labeled — never Bible text, commentary, or theological guidance.
Scripture text
Bible text in the app comes from public-domain or licensed sources with attribution shown where the text appears (for example, the World English Bible, public domain, via eBible.org). Licensed texts are handled per their licenses, including limits on storage and audio.
Children
The app is not directed at children under 13, and we do not knowingly collect personal information from them.
Changes
If this policy changes, we will update this page and the “last updated” date, and note material changes in the app.
Contact
Questions or deletion requests: email [email protected].