Privacy Policy
How Homeward guards what passes between you and God.
- 1. Our Promise
- 2. No Account
- 3. What We Collect
- 4. What Stays on This Device
- 5. Reflections and the AI
- 6. Usage Data and Crash Reports
- 7. Subscriptions
- 8. Experiments and Remote Configuration
- 9. Who Else Sees Your Data
- 10. Keeping and Deleting Your Data
- 11. Your Choices and Rights
- 12. Where Your Data Lives
- 13. Children
- 14. Changes to This Policy
- 15. Contact Us
1. Our Promise
What you bring to Homeward — your reflections, your questions, your prayers — passes between you and God. Our job is to keep it that way. This policy says, in plain words, what information Homeward touches, what it never touches, and how long anything is kept. Except where a capability is marked as coming, every sentence here describes what the app does today.
Homeward: Bible Reflection is built and run by one person, Ilia Libelman, an individual in Israel, who is responsible for your data under this policy. Our servers run in Amazon Web Services' Oregon region in the United States. The only contact address is support@homewardbible.com.
Using a Bible reflection app says something about your faith, and privacy law treats religious belief as sensitive. We treat everything here that way. Nothing you write trains AI. Nothing is sold. There is no advertising, no advertising identifier, no ad network, no tracking across other apps or websites, and no tracking prompt — there is nothing to ask about.
2. No Account
Homeward has no account, no email, no password. When the app first runs, it creates a pair of keys on this device. The secret key never leaves the device; it stays in the device's secure storage. The other key — we call it your device key — is what our servers see: it travels with every request about your data (reflections, next steps, membership checks, letters, reminder tokens), and it is how our subscription processor knows you. It carries no name and no email, but it does link together everything our servers hold under it for this one copy of the app.
The support code shown in the Sacristy (Settings) is the first eight characters of that key. Quote it when you write to us and we can find what our servers hold under your key.
Because there is no account, there is nothing to sign up for and nothing to recover. Your reflections are never synced between devices. If you delete Homeward data from this device (section 10), the app erases what it keeps here, makes a new key and shows a new support code. Rows our servers hold under the old key stay tied to that key until they expire or you ask us to delete them by quoting the old support code; nothing on this device points to them any more. On iOS, deleting the app alone can leave the old key in the device's keychain, so 'Delete Homeward data from this device' in the Sacristy is the way to start over.
3. What We Collect
Here is what reaches our servers, and for each item whether it is needed for that part of the app to work or is yours to give:
- Your device key — needed for anything about your data. It rides with reflections, next steps, membership checks, letters and reminder tokens; without it those parts of Homeward cannot work.
- The words of a reflection turn — needed. Each time you send a message in Reflect, the last twelve entries of the conversation and any carried note you chose to bring in (section 4) are sent over an encrypted connection so a reply can be prepared. Three short settings ride with them, each a single fixed word, never your text: on the first message of a conversation you entered through a doorway, which doorway it was (grief, forgiveness, gratitude or decision); the church-year tradition setting when it is Catholic or Protestant (Catholic by default, changeable in the Church Year room; the shared year sends none); and whether you asked to reflect or to hear the Church's teaching. They are used only so the reply comes in the right voice and are not kept with it. On the fallback path described in section 5 those three words also pass through our job queue in the clear — your words never do — and sit on the job record only until the turn is processed; a failed turn's record is deleted within 7 days. Usage data, if you turn it on, never carries the doorway or the tradition — at most whether a doorway was used and whether you asked for reflection or an answer (section 6). Without the words there is no reflection; the three settings can each be left unset. Section 5 describes exactly how a turn travels and that nothing readable is kept.
- A two-letter region code — not needed, and sent automatically when your device reports one. If your device's language and region setting reports a region, its code (for example US or GB) rides along with a turn and a Scripture search, and is used only to choose which crisis resources to show. It is a device setting, not your location: Homeward has no switch for it, and the only way to change or withhold it is your device's own region setting. Without it a reflection still works and the general crisis resources are shown.
- Your next step — only if you set one. The step itself is sealed with your key before it leaves the device; its date is kept in the clear so a reminder can be scheduled.
- The weekly conversation meter — when you start a conversation: your key and the start time, so the free allowance can be counted.
- Membership records — only if you subscribe: your plan, price, currency, dates and store, received from our subscription processor. Never a card number.
- A subscription-processor record — from first launch, whether or not you ever subscribe: the app registers your device key with RevenueCat (as its app user id) so a purchase or a Restore can be matched to this install, and RevenueCat notes from that request your platform, app and OS version and the country your connection comes from. It never receives an advertising identifier from us; while usage data is on it also holds the analytics app-instance id (section 7). After Delete Homeward data from this device, the new key is registered the same way; the record under the old key stays with RevenueCat under its terms.
- A push token — only if you allow notifications: the token Expo's push service issues for this device, sent to our servers when you set a next step or write a letter, so a reminder, or a notice that a reply to your letter is waiting, can reach it. Notification text is always generic — never a step, never your words and never the reply itself.
- Letters to the builder — only if you write one: your message in plain text, the reply address if you leave one, your device key (the support code is its first eight characters), your platform and app version. Letters are the one thing the founder reads in your own words. A copy of each letter is also emailed to our support mailbox through Amazon's email service. If we write back, the reply is stored beside your letter on our servers and shown in the app's Letter Box beneath it; it is also emailed to the reply address if you left one, and, if this device has a push token, a notification saying only that a reply is waiting is sent to it. Sending a letter also asks the device for notification permission, if it has not been asked already, so that notice can reach you.
- Scripture searches — your search words and the region code. They are answered and not stored.
- Answer feedback — if you rate an answer drawn from Catholic teaching (the app calls these grounded answers): a reason, the identifiers of the passages it cited, the answer mode, your platform and app version. No key travels with it.
- Service records — fixed error codes in our application log and daily counts of service events, including how many times a day crisis resources were shown. They carry no words; the counts carry no key and measure totals, never who.
- Connection records — like every internet service, our web server writes one line per request: the IP address your connection used, the time, the request itself — which includes your device key when it rides in the address of a request (fetching a reply, your next steps, your membership, your letters) and a verse reference when a passage is fetched from our server rather than from the Bible bundled in the app — the outcome, and the app's software identifier. Your search words and the words of a turn travel in the body of a request and are not written to this log. It is kept 14 days, used only to keep the service running and to investigate abuse, and is never joined to analytics. Your IP address is also used, a minute at a time, to limit how fast requests may arrive; that count is not kept.
- Google's Firebase installation id — needed. Homeward is built with Firebase, Google's toolkit for apps. The first time the app runs, Firebase gives this copy of the app a random id and sends it to Google, together with the code that identifies Homeward to Firebase and the version of the Firebase software inside the app — whatever you later choose about usage data and crash reports. No usage event, no crash report and never your device key rides with it before you choose; section 6 says what leaves after.
- Usage data and crash reports — only if you turn them on. Section 6 lists exactly what they contain.
What we do not collect: no name, no email unless you leave one in a letter, no contacts, no photos, no precise location, no advertising identifier; no audio — dictation is handled by your device's recognizer (section 5). Our servers, and each provider named in section 9, see the internet address your device connects from; we keep it only in the 14-day access log described in section 10. The journal, the Examen, carried notes, candles, the bell and your reading position never leave this device (section 4).
We use what we collect to prepare your reflection and Scripture results, to choose crisis resources, to count the free allowance, to keep reminders and your membership working, to fix and secure the service, to answer letters and act on feedback, and to meet legal obligations — and for nothing else. Improvement uses counts and patterns only, never content.
4. What Stays on This Device
Your journal, the Examen and your written answers in the daily prayer, carried notes and your current reflection are encrypted on this device before they are stored, with a key that lives only in the device's secure storage. The candles you light in the chapel, the evening bell's time and whether it is on, and where you left off reading are stored on this device in plain form; they hold none of your words. None of this is uploaded, and it is never synced between devices. We cannot read the encrypted items, and we cannot recover any of it for you.
Carried notes leave the device only when you choose to bring one into a conversation, and then only as part of that turn (section 5). 'Delete Homeward data from this device' erases all of this along with the keys that unlock it.
5. Reflections and the AI
When you reflect in Homeward you are talking with an AI companion, not a person and not clergy. The room's header names it an AI companion on every visit, the threshold before your first reflection says responses are generated by an AI companion, and 'About this room' says it is not confession to clergy, spiritual direction, therapy or a sacrament. When you press Send, the words you submit — which may reveal your beliefs — are processed only to prepare the reflection, a grounded answer and, if needed, crisis resources. The AI never speaks as God or Jesus, never grants absolution and never diagnoses; it is a companion for reflection, not an authority, and our Terms of Service describe those boundaries in full. If a conversation touches on danger, the app shows crisis resources — please also reach a pastor, a counselor or a crisis line.
Here is how a turn travels. Your words are sent to our servers over an encrypted connection, together with the three settings named in section 3. Two of our processors see the words of a turn, each transiently and only to do its job: Anthropic prepares the reply, and, when a question is answered from Catholic teaching, OpenAI turns the question into a list of numbers that stands for its meaning — not for you — which we use to find the relevant passages in our own library. That list is held in memory only and never stored.
If you tap the microphone to speak a reflection, your device's own speech recognition turns your voice into text that you review before sending. Depending on the device, language and settings, Apple (iPhone) or Google (Android) may process that audio on their servers under their own privacy terms; Homeward never receives, stores or hears audio. You can always type instead.
On the streaming path our servers keep nothing. On the fallback path the words are sealed into an envelope with a managed key, destroyed the moment the reply is ready — and unreadable after 15 minutes in any case, with a sweep every five minutes removing any straggler, and the reply is stored only as ciphertext that this device alone can open. Nothing readable is kept on our servers, and nothing is used to train AI — not by us and not by our processors.
Anthropic keeps the words of a turn for up to 30 days under its standard API terms and does not train on them. OpenAI keeps the question text it receives for up to 30 days for abuse monitoring under its standard API terms and does not train on it.
The Bible verses you see are never generated by the AI. Verse text comes from our own database, and every reference the AI offers is checked against it before it is shown.
6. Usage Data and Crash Reports
Both are off unless you turn them on. The first time you enter the nave (the app's main room) after the welcome, a card asks once, with both switches off. The same two switches live in the Sacristy (Settings) under WHAT LEAVES THIS DEVICE and can be changed at any time, as easily as you set them. Until you turn a switch on, no usage event and no crash report is recorded — nothing is saved up on the device to send later.
Share usage data — when on, Google Analytics for Firebase receives screens opened, features used, and app-start and screen-render times; never words, verses tied to reflections, or search terms, and never an identifier of you that Homeward supplies. Purchase events from our subscription processor also reach the same Google property while this switch is on (section 7). Google identifies the install with an app-instance id it creates, alongside the Firebase installation id described in section 3, and derives an approximate country from your IP address; precise location is never collected. Google keeps this event data for 14 months.
Send crash reports — when on, Firebase Crashlytics receives a report when the app crashes, and also each time something fails while the app keeps running (a request that failed or timed out, a note that could not be decrypted, a membership record that could not be written, a room that failed to render). Each report carries the device model, OS version, app version, memory, free disk space, orientation and whether the device is jailbroken or rooted at that moment, a title that is a fixed failure code and, for errors in our own code, only which files of our own code were running when it failed — when the app process itself crashes, the report carries the usual technical stack of the app and the operating system, never your words — plus five fixed labels: whether this is a test build or a store build, the room you were in, your membership status, whether in-app purchases are set up in this build, and which version of the membership offer the app was given (a short label such as 'default', never anything about you). Never a message, never your words, never an identifier of you that Homeward supplies. Google also processes a Crashlytics installation id, the Firebase installation id and session timing metadata, and keeps crash reports for about 90 days.
Turning either switch off removes no feature. 'Delete Homeward data from this device' turns both switches back off, clears any unsent crash report and label on this device, resets the app-instance id and, when the device is online, deletes the Firebase installation id (otherwise a fresh id simply replaces it at the next launch); if usage data was on, the app first records one final 'wipe completed' usage event under the old app-instance id (best effort — it may not arrive). Google removes data tied to a deleted installation id within 180 days. Event data already at Google is not erased by Homeward — it expires there on Google's schedule above.
7. Subscriptions
Homeward Plus is sold through Apple's App Store and Google Play. Apple or Google hold the payment; we never see a card number. Our subscription processor, RevenueCat, knows this install from first launch under an app user id that is your device key (section 9); if you buy, it records the purchase under that id and tells our servers your plan, price, currency, dates, store and store country, the offering you were shown, the renewal count, and whether a trial converted or a membership was cancelled or expired, and why. Each of these notices arrives as one whole event — including RevenueCat's own ids for your purchase and transaction and the attributes it holds for you — and is kept as delivered for 90 days (section 10). What a membership unlocks is always decided on our servers — what the app shows is a reflection of that verdict, never the verdict itself.
Restore purchases moves your membership to the key this device holds now, for instance after 'Delete Homeward data from this device'. If usage data is on, RevenueCat also passes purchase events — plan, price, currency, never a card number — into our Google Analytics property, tied to the same app-instance id. While usage data is on, that app-instance id is among the attributes RevenueCat includes in each event it sends our servers, so for up to 90 days after the last event our own database holds it beside your device key — the one place the two meet; we do not use it, and it is erased with the event (section 10). When usage data is off, RevenueCat sends no more purchase events to Google and drops the app-instance id from your purchase record; events already at Google stay until Google's retention period ends.
Deleting Homeward data from this device does not cancel a subscription. Cancel in your App Store account or Google Play account settings; refunds follow Apple's and Google's policies.
8. Experiments and Remote Configuration
No experiment runs today. When one does, it may vary only two versions of a screen, its wording or layout, or the timing and shape of the membership offer — never safety guidance, this policy, any consent, prayers, the Examen, the guided paths that open a reflection, Scripture, teaching, the candle chapel (which stays free), deletion, any guilt or urgency framing, or your own words. Who is a member is always decided on our servers and is never part of an experiment.
A server-assigned experiment would pick your version from a scrambled form of your device key that cannot be reversed and is never logged. A crash report might then carry the version name as one more fixed label beside the five in section 6; no such label exists today, and this document would change first. A remote switch that could pause Reflect for everyone at once is a coming capability through Google's Firebase Remote Config; today the app fetches no remote settings. Any of this appears in this document in the present tense only once it ships.
9. Who Else Sees Your Data
A small number of service providers process data for us, each only for the job named here:
- Google — Firebase Analytics and Performance Monitoring only while usage data is on, Crashlytics only while crash reports are on, the Installations service from first launch, and Remote Config as an unused coming capability; on Android, Firebase Cloud Messaging also carries reminders and letter-reply notices to the device. Separately from Firebase, Google Workspace hosts our support mailbox, where the emailed copy of each letter is kept.
- RevenueCat — knows this install from first launch under an app user id that is your device key, whether or not you ever subscribe: it receives that id when the app starts, the request for the offerings and prices to show you, the store's answer on whether you are eligible for an introductory offer, a note each time the membership screen is shown, and, if you buy, your purchases and membership status. Its software also reports your platform, OS and app version, language setting and software-library version, and RevenueCat derives an approximate country from the connection. Never a card number.
- Anthropic — the words of a turn, transiently, to prepare the reply.
- OpenAI — the text of a question, transiently, to turn it into the list of numbers used to find passages for a grounded answer.
- Amazon Web Services, Oregon (us-west-2) — our servers and database, the managed keys that seal envelopes, and the email service that copies a letter to our support mailbox and sends any reply to the address you left. We keep no database backups today (section 10).
- Expo's push service — relays reminders and letter-reply notices to the token it issued for this device, through Apple's or Google's notification service.
- Typesense, on our own server — Scripture and teaching search; the query is never stored.
- Apple and Google — distribute the app, process payments and deliver notifications to the device under their own terms.
- Apple or Google — speech recognition when you dictate, through the device's own recognizer under their own terms; Homeward never receives audio.
No advertising identifiers, no cross-app tracking, no tracking prompt, no ad networks. We do not sell personal information and we do not disclose it for advertising or cross-app tracking; our providers receive it only for the services described here, under their own legal obligations — never advertisers, never data brokers, and never a faith organization.
Our website carries no analytics today; if a consent tag is ever added, it loads only after you allow it, with every advertising signal denied and no form contents or query strings.
If we receive a legal demand for information, we will not provide more than the law requires, and we will notify you where the law allows and where we have a way to reach you. Our servers hold no readable reflection to hand over. If responsibility for Homeward ever changed hands, what our servers hold would stay under this policy and the law, and any change would be disclosed in a new version of this document first.
10. Keeping and Deleting Your Data
Our servers delete on the schedule below. The envelope period is enforced every five minutes, the server-log period by daily rotation, the push-token period by Expo's reports, the mailbox copy by hand, and the Google periods by Google; every other period is enforced by one nightly routine on our servers. Each period appears here only because it is enforced:
- The sealed envelope of a turn — destroyed the moment the reply is ready. If anything goes wrong it can no longer be opened after 15 minutes and is swept from the database within five minutes after that.
- The sealed reply your device fetches — 7 days.
- The weekly conversation meter — 30 days after a conversation starts.
- A next step you completed or released — 90 days after its date. An open step stays until you complete or release it; when you delete Homeward data from this device while online, the app first releases every open step under the old key, so no reminder rings for a key you left behind. If the device was offline at that moment, the old key's open steps remain and its reminders can still reach this device until they pass; email support@homewardbible.com with the old support code and we will release them.
- The whole purchase event from our subscription processor — RevenueCat's ids and, if usage data was on, the analytics app-instance id (section 7) — 90 days after the last event; the plan, price, currency, dates, store, store country, offering and the trial, renewal, cancellation and expiration facts stay as billing evidence for as long as the membership record exists, and no fixed end has yet been set for that record.
- Letters, and any reply beside them — 24 months on our servers. The emailed copy of each letter in the support mailbox is kept until the founder deletes it.
- Answer feedback and daily counts — 24 months.
- A push token — until Expo reports the device no longer accepts it; deleting Homeward data from this device moves the token to your new key when the device is online (offline, it moves the next time you set a next step or write a letter).
- Database backups — we keep no database backups today; when we add them they will be kept 30 days, and this document will say so. Server logs — 14 days, rotated daily. The application log carries fixed error codes, never your words; the web server's connection log carries IP addresses and request lines, including your device key where it rides in the address (section 3).
- At Google, if you turned the switches on — event data 14 months, crash reports about 90 days, and data tied to a deleted installation id within 180 days of deletion.
'Delete Homeward data from this device' in the Sacristy erases everything Homeward keeps here: reflections, journal, carried notes, candles, the bell, and the keys that unlock them. It also turns both switches off, clears any unsent crash report and resets the app-instance id. Then it gives the device a new key and a new support code; a membership is not lost — Restore purchases brings it to the new key, and the old membership record stays under its rule above. Four steps need the network and are attempted for four seconds each: releasing the old key's open steps, deleting the Firebase installation id, unlinking this install's analytics id from its purchase record at RevenueCat (a copy of that id already inside a stored purchase event leaves our database on the 90-day rule above), and moving the push token to the new key. If the device is offline, deletion still completes without them — a fresh installation id simply replaces the old one at the next launch — and only the open-step release matters afterwards; see the next-step line above. It does not erase what our servers hold under the old key: those rows expire on the schedule above, or sooner if you email support@homewardbible.com quoting the support code shown before you deleted. Once the key has changed, only that old code, if you kept it, can point us to those rows.
Deleting the app itself takes your journal, the Examen, carried notes, candles, the bell and your reading position with it. On iOS it can leave the old device key in the device's keychain, so a reinstall may come back with the old support code and the old identity to our servers; for a clean start, use 'Delete Homeward data from this device' first. Deleting the app does not touch what our servers hold under your key, and does not cancel a subscription (section 7).
Anthropic and OpenAI delete the transient text on their own schedule, described in section 5.
11. Your Choices and Rights
The two switches in the Sacristy decide whether usage data and crash reports leave this device; both are off until you choose, and either can be withdrawn at any time, as easily as it was given. 'Delete Homeward data from this device' erases what the app keeps here and gives this device a new identity.
For the server rows that can be found through your support code — a next step, the meter, a sealed reply, a membership record, a push token, a letter and its copy in our support mailbox — email support@homewardbible.com quoting the code and we will show you what there is, correct it or delete it, after reasonable steps to verify the request. The one exception is the billing evidence of a membership — plan, price, currency, dates and store — which stays for as long as section 10 says, because it proves what was bought and is what keeps a membership working; the raw purchase event behind it still expires after 90 days. Daily counts are totals only, and answer feedback carries no key, so neither can be found by your support code and they fall outside what we can show, correct or delete for you. We respond within the time the law that applies to you sets, and as soon as we can; you may appeal a decision by writing again, and we never treat you differently for asking. Quote the code before you delete Homeward data from this device: afterwards it changes, and only the old code can point us to the old rows.
You are under no legal duty to give Homeward any information; everything here is provided by your own choice. Usage data, crash reports, letters, reminders and a membership are all optional, and refusing any of them removes no other part of the app; the region code follows your device's region setting, Homeward offers no switch for it, and without one the general crisis resources are shown. What is needed is needed only for that feature to work: a reflection needs the words you send and your device key; the free allowance needs the conversation meter; a letter needs a message; a reminder needs a push token; paid features need a membership; the Firebase installation id is created, and your device key registered with RevenueCat, at first launch whatever you choose; and, like any internet service, our web server sees the IP address of every request.
No export feature exists. Your journal, Examen, carried notes and candles live only on this device, and our servers hold no readable reflection to copy. If you live somewhere that gives you a right to complain to a data protection authority, you may do so; we would rather hear from you first.
12. Where Your Data Lives
Homeward is run by an individual in Israel, who reads letters and answers requests from there. Our servers are in the United States, in Amazon's Oregon region, and Google, RevenueCat, Anthropic, OpenAI and Expo process what they receive under their own terms, principally in the United States. When you use Homeward from anywhere else, your information travels to and is processed there.
13. Children
Homeward is for people 13 and older. It is not directed to children under 13, and we do not knowingly collect personal information from anyone under 13. If we learn that we have, we will delete it. Parents and guardians can write to support@homewardbible.com with any concern.
14. Changes to This Policy
This document carries a version number and a date, shown at the top. A material change to what leaves the device raises the version and ships only in a new build of the app, so the version and date you see here are the ones this build was made with. A build is allowed to send usage or crash data only if it was made after the version it carries was approved; an older build keeps the disclosure it shipped with until you update the app. The text this build carries is always in the Archive inside the app. The current version is also published at https://homewardbible.com/privacy.
We will never quietly weaken a promise. Prior versions remain available on request.
15. Contact Us
Questions, requests or concerns: email support@homewardbible.com. Homeward is built and run by Ilia Libelman, an individual in Israel, who is responsible for your data under this policy. We read everything and aim to respond within a few days — always within the timelines the law sets.