Homeward

Privacy Policy

How Homeward guards what passes between you and God.

Last updated · SEPTEMBER 13, 2026 · Version 2
  1. 1. Our Promise
  2. 2. No Account
  3. 3. What We Collect
  4. 4. What Stays on This Device
  5. 5. Reflections and the AI
  6. 6. Usage Data and Crash Reports
  7. 7. Subscriptions
  8. 8. Experiments and Remote Configuration
  9. 9. Who Else Sees Your Data
  10. 10. Keeping and Deleting Your Data
  11. 11. Your Choices and Rights
  12. 12. Where Your Data Lives
  13. 13. Children
  14. 14. Changes to This Policy
  15. 15. Contact Us

1. Our Promise

What you bring to Homeward — your reflections, your questions, your prayers — passes between you and God. Our job is to keep it that way. This policy says, in plain words, what information Homeward touches, what it never touches, and how long anything is kept. Except where a capability is marked as coming, every sentence here describes what the app does today.

Homeward: Bible Reflection is built and run by one person, Ilia Libelman, an individual in Israel, who is responsible for your data under this policy. Our servers run in Amazon Web Services' Oregon region in the United States. The only contact address is support@homewardbible.com.

Using a Bible reflection app says something about your faith, and privacy law treats religious belief as sensitive. We treat everything here that way. Nothing you write trains AI. Nothing is sold. There is no advertising, no advertising identifier, no ad network, no tracking across other apps or websites, and no tracking prompt — there is nothing to ask about.

2. No Account

Homeward has no account, no email, no password. When the app first runs, it creates a pair of keys on this device. The secret key never leaves the device; it stays in the device's secure storage. The other key — we call it your device key — is what our servers see: it travels with every request about your data (reflections, next steps, membership checks, letters, reminder tokens), and it is how our subscription processor knows you. It carries no name and no email, but it does link together everything our servers hold under it for this one copy of the app.

The support code shown in the Sacristy (Settings) is the first eight characters of that key. Quote it when you write to us and we can find what our servers hold under your key.

Because there is no account, there is nothing to sign up for and nothing to recover. Your reflections are never synced between devices. If you delete Homeward data from this device (section 10), the app erases what it keeps here, makes a new key and shows a new support code. Rows our servers hold under the old key stay tied to that key until they expire or you ask us to delete them by quoting the old support code; nothing on this device points to them any more. On iOS, deleting the app alone can leave the old key in the device's keychain, so 'Delete Homeward data from this device' in the Sacristy is the way to start over.

3. What We Collect

Here is what reaches our servers, and for each item whether it is needed for that part of the app to work or is yours to give:

What we do not collect: no name, no email unless you leave one in a letter, no contacts, no photos, no precise location, no advertising identifier; no audio — dictation is handled by your device's recognizer (section 5). Our servers, and each provider named in section 9, see the internet address your device connects from; we keep it only in the 14-day access log described in section 10. The journal, the Examen, carried notes, candles, the bell and your reading position never leave this device (section 4).

We use what we collect to prepare your reflection and Scripture results, to choose crisis resources, to count the free allowance, to keep reminders and your membership working, to fix and secure the service, to answer letters and act on feedback, and to meet legal obligations — and for nothing else. Improvement uses counts and patterns only, never content.

4. What Stays on This Device

Your journal, the Examen and your written answers in the daily prayer, carried notes and your current reflection are encrypted on this device before they are stored, with a key that lives only in the device's secure storage. The candles you light in the chapel, the evening bell's time and whether it is on, and where you left off reading are stored on this device in plain form; they hold none of your words. None of this is uploaded, and it is never synced between devices. We cannot read the encrypted items, and we cannot recover any of it for you.

Carried notes leave the device only when you choose to bring one into a conversation, and then only as part of that turn (section 5). 'Delete Homeward data from this device' erases all of this along with the keys that unlock it.

5. Reflections and the AI

When you reflect in Homeward you are talking with an AI companion, not a person and not clergy. The room's header names it an AI companion on every visit, the threshold before your first reflection says responses are generated by an AI companion, and 'About this room' says it is not confession to clergy, spiritual direction, therapy or a sacrament. When you press Send, the words you submit — which may reveal your beliefs — are processed only to prepare the reflection, a grounded answer and, if needed, crisis resources. The AI never speaks as God or Jesus, never grants absolution and never diagnoses; it is a companion for reflection, not an authority, and our Terms of Service describe those boundaries in full. If a conversation touches on danger, the app shows crisis resources — please also reach a pastor, a counselor or a crisis line.

Here is how a turn travels. Your words are sent to our servers over an encrypted connection, together with the three settings named in section 3. Two of our processors see the words of a turn, each transiently and only to do its job: Anthropic prepares the reply, and, when a question is answered from Catholic teaching, OpenAI turns the question into a list of numbers that stands for its meaning — not for you — which we use to find the relevant passages in our own library. That list is held in memory only and never stored.

If you tap the microphone to speak a reflection, your device's own speech recognition turns your voice into text that you review before sending. Depending on the device, language and settings, Apple (iPhone) or Google (Android) may process that audio on their servers under their own privacy terms; Homeward never receives, stores or hears audio. You can always type instead.

On the streaming path our servers keep nothing. On the fallback path the words are sealed into an envelope with a managed key, destroyed the moment the reply is ready — and unreadable after 15 minutes in any case, with a sweep every five minutes removing any straggler, and the reply is stored only as ciphertext that this device alone can open. Nothing readable is kept on our servers, and nothing is used to train AI — not by us and not by our processors.

Anthropic keeps the words of a turn for up to 30 days under its standard API terms and does not train on them. OpenAI keeps the question text it receives for up to 30 days for abuse monitoring under its standard API terms and does not train on it.

The Bible verses you see are never generated by the AI. Verse text comes from our own database, and every reference the AI offers is checked against it before it is shown.

6. Usage Data and Crash Reports

Both are off unless you turn them on. The first time you enter the nave (the app's main room) after the welcome, a card asks once, with both switches off. The same two switches live in the Sacristy (Settings) under WHAT LEAVES THIS DEVICE and can be changed at any time, as easily as you set them. Until you turn a switch on, no usage event and no crash report is recorded — nothing is saved up on the device to send later.

Share usage data — when on, Google Analytics for Firebase receives screens opened, features used, and app-start and screen-render times; never words, verses tied to reflections, or search terms, and never an identifier of you that Homeward supplies. Purchase events from our subscription processor also reach the same Google property while this switch is on (section 7). Google identifies the install with an app-instance id it creates, alongside the Firebase installation id described in section 3, and derives an approximate country from your IP address; precise location is never collected. Google keeps this event data for 14 months.

Send crash reports — when on, Firebase Crashlytics receives a report when the app crashes, and also each time something fails while the app keeps running (a request that failed or timed out, a note that could not be decrypted, a membership record that could not be written, a room that failed to render). Each report carries the device model, OS version, app version, memory, free disk space, orientation and whether the device is jailbroken or rooted at that moment, a title that is a fixed failure code and, for errors in our own code, only which files of our own code were running when it failed — when the app process itself crashes, the report carries the usual technical stack of the app and the operating system, never your words — plus five fixed labels: whether this is a test build or a store build, the room you were in, your membership status, whether in-app purchases are set up in this build, and which version of the membership offer the app was given (a short label such as 'default', never anything about you). Never a message, never your words, never an identifier of you that Homeward supplies. Google also processes a Crashlytics installation id, the Firebase installation id and session timing metadata, and keeps crash reports for about 90 days.

Turning either switch off removes no feature. 'Delete Homeward data from this device' turns both switches back off, clears any unsent crash report and label on this device, resets the app-instance id and, when the device is online, deletes the Firebase installation id (otherwise a fresh id simply replaces it at the next launch); if usage data was on, the app first records one final 'wipe completed' usage event under the old app-instance id (best effort — it may not arrive). Google removes data tied to a deleted installation id within 180 days. Event data already at Google is not erased by Homeward — it expires there on Google's schedule above.

7. Subscriptions

Homeward Plus is sold through Apple's App Store and Google Play. Apple or Google hold the payment; we never see a card number. Our subscription processor, RevenueCat, knows this install from first launch under an app user id that is your device key (section 9); if you buy, it records the purchase under that id and tells our servers your plan, price, currency, dates, store and store country, the offering you were shown, the renewal count, and whether a trial converted or a membership was cancelled or expired, and why. Each of these notices arrives as one whole event — including RevenueCat's own ids for your purchase and transaction and the attributes it holds for you — and is kept as delivered for 90 days (section 10). What a membership unlocks is always decided on our servers — what the app shows is a reflection of that verdict, never the verdict itself.

Restore purchases moves your membership to the key this device holds now, for instance after 'Delete Homeward data from this device'. If usage data is on, RevenueCat also passes purchase events — plan, price, currency, never a card number — into our Google Analytics property, tied to the same app-instance id. While usage data is on, that app-instance id is among the attributes RevenueCat includes in each event it sends our servers, so for up to 90 days after the last event our own database holds it beside your device key — the one place the two meet; we do not use it, and it is erased with the event (section 10). When usage data is off, RevenueCat sends no more purchase events to Google and drops the app-instance id from your purchase record; events already at Google stay until Google's retention period ends.

Deleting Homeward data from this device does not cancel a subscription. Cancel in your App Store account or Google Play account settings; refunds follow Apple's and Google's policies.

8. Experiments and Remote Configuration

No experiment runs today. When one does, it may vary only two versions of a screen, its wording or layout, or the timing and shape of the membership offer — never safety guidance, this policy, any consent, prayers, the Examen, the guided paths that open a reflection, Scripture, teaching, the candle chapel (which stays free), deletion, any guilt or urgency framing, or your own words. Who is a member is always decided on our servers and is never part of an experiment.

A server-assigned experiment would pick your version from a scrambled form of your device key that cannot be reversed and is never logged. A crash report might then carry the version name as one more fixed label beside the five in section 6; no such label exists today, and this document would change first. A remote switch that could pause Reflect for everyone at once is a coming capability through Google's Firebase Remote Config; today the app fetches no remote settings. Any of this appears in this document in the present tense only once it ships.

9. Who Else Sees Your Data

A small number of service providers process data for us, each only for the job named here:

No advertising identifiers, no cross-app tracking, no tracking prompt, no ad networks. We do not sell personal information and we do not disclose it for advertising or cross-app tracking; our providers receive it only for the services described here, under their own legal obligations — never advertisers, never data brokers, and never a faith organization.

Our website carries no analytics today; if a consent tag is ever added, it loads only after you allow it, with every advertising signal denied and no form contents or query strings.

If we receive a legal demand for information, we will not provide more than the law requires, and we will notify you where the law allows and where we have a way to reach you. Our servers hold no readable reflection to hand over. If responsibility for Homeward ever changed hands, what our servers hold would stay under this policy and the law, and any change would be disclosed in a new version of this document first.

10. Keeping and Deleting Your Data

Our servers delete on the schedule below. The envelope period is enforced every five minutes, the server-log period by daily rotation, the push-token period by Expo's reports, the mailbox copy by hand, and the Google periods by Google; every other period is enforced by one nightly routine on our servers. Each period appears here only because it is enforced:

'Delete Homeward data from this device' in the Sacristy erases everything Homeward keeps here: reflections, journal, carried notes, candles, the bell, and the keys that unlock them. It also turns both switches off, clears any unsent crash report and resets the app-instance id. Then it gives the device a new key and a new support code; a membership is not lost — Restore purchases brings it to the new key, and the old membership record stays under its rule above. Four steps need the network and are attempted for four seconds each: releasing the old key's open steps, deleting the Firebase installation id, unlinking this install's analytics id from its purchase record at RevenueCat (a copy of that id already inside a stored purchase event leaves our database on the 90-day rule above), and moving the push token to the new key. If the device is offline, deletion still completes without them — a fresh installation id simply replaces the old one at the next launch — and only the open-step release matters afterwards; see the next-step line above. It does not erase what our servers hold under the old key: those rows expire on the schedule above, or sooner if you email support@homewardbible.com quoting the support code shown before you deleted. Once the key has changed, only that old code, if you kept it, can point us to those rows.

Deleting the app itself takes your journal, the Examen, carried notes, candles, the bell and your reading position with it. On iOS it can leave the old device key in the device's keychain, so a reinstall may come back with the old support code and the old identity to our servers; for a clean start, use 'Delete Homeward data from this device' first. Deleting the app does not touch what our servers hold under your key, and does not cancel a subscription (section 7).

Anthropic and OpenAI delete the transient text on their own schedule, described in section 5.

11. Your Choices and Rights

The two switches in the Sacristy decide whether usage data and crash reports leave this device; both are off until you choose, and either can be withdrawn at any time, as easily as it was given. 'Delete Homeward data from this device' erases what the app keeps here and gives this device a new identity.

For the server rows that can be found through your support code — a next step, the meter, a sealed reply, a membership record, a push token, a letter and its copy in our support mailbox — email support@homewardbible.com quoting the code and we will show you what there is, correct it or delete it, after reasonable steps to verify the request. The one exception is the billing evidence of a membership — plan, price, currency, dates and store — which stays for as long as section 10 says, because it proves what was bought and is what keeps a membership working; the raw purchase event behind it still expires after 90 days. Daily counts are totals only, and answer feedback carries no key, so neither can be found by your support code and they fall outside what we can show, correct or delete for you. We respond within the time the law that applies to you sets, and as soon as we can; you may appeal a decision by writing again, and we never treat you differently for asking. Quote the code before you delete Homeward data from this device: afterwards it changes, and only the old code can point us to the old rows.

You are under no legal duty to give Homeward any information; everything here is provided by your own choice. Usage data, crash reports, letters, reminders and a membership are all optional, and refusing any of them removes no other part of the app; the region code follows your device's region setting, Homeward offers no switch for it, and without one the general crisis resources are shown. What is needed is needed only for that feature to work: a reflection needs the words you send and your device key; the free allowance needs the conversation meter; a letter needs a message; a reminder needs a push token; paid features need a membership; the Firebase installation id is created, and your device key registered with RevenueCat, at first launch whatever you choose; and, like any internet service, our web server sees the IP address of every request.

No export feature exists. Your journal, Examen, carried notes and candles live only on this device, and our servers hold no readable reflection to copy. If you live somewhere that gives you a right to complain to a data protection authority, you may do so; we would rather hear from you first.

12. Where Your Data Lives

Homeward is run by an individual in Israel, who reads letters and answers requests from there. Our servers are in the United States, in Amazon's Oregon region, and Google, RevenueCat, Anthropic, OpenAI and Expo process what they receive under their own terms, principally in the United States. When you use Homeward from anywhere else, your information travels to and is processed there.

13. Children

Homeward is for people 13 and older. It is not directed to children under 13, and we do not knowingly collect personal information from anyone under 13. If we learn that we have, we will delete it. Parents and guardians can write to support@homewardbible.com with any concern.

14. Changes to This Policy

This document carries a version number and a date, shown at the top. A material change to what leaves the device raises the version and ships only in a new build of the app, so the version and date you see here are the ones this build was made with. A build is allowed to send usage or crash data only if it was made after the version it carries was approved; an older build keeps the disclosure it shipped with until you update the app. The text this build carries is always in the Archive inside the app. The current version is also published at https://homewardbible.com/privacy.

We will never quietly weaken a promise. Prior versions remain available on request.

15. Contact Us

Questions, requests or concerns: email support@homewardbible.com. Homeward is built and run by Ilia Libelman, an individual in Israel, who is responsible for your data under this policy. We read everything and aim to respond within a few days — always within the timelines the law sets.