1. Summary
Midvash is a daily devotional and Bible study app available on the web, on mobile (iOS, Android), and as a browser extension. We collect only the data needed to run the product, measure how people find it, and keep it working. We do not sell personal data, and the Bible reader shows no ads. This page lists every category of data we handle and every provider that processes it.
2. Who we are
"Midvash" refers to the project published at midvash.com, including the iOS and Android applications and the Chrome extension. The project is operated by an independent developer. For data-related questions, contact contact@midvash.com.
3. What we collect
On the web (midvash.com). Reading does not require an account. Server-side request logs (URL accessed, IP address, user-agent, timestamp) are kept by our hosting provider for a limited period for operational and security purposes. We use Google Analytics and the Meta Pixel, loaded through Cloudflare Zaraz, to measure visits and the performance of our ads (for example, which campaign brought a visitor and whether they started a subscription). These tools may set cookies and receive your IP address, browser information, and the pages you visit.
On the mobile apps (iOS, Android). Reading preferences (default translation, theme, font size) are stored on your device. The apps use Google Analytics for Firebase to understand feature usage and the Meta SDK (App Events) to measure app installs and subscriptions that come from our ads. On iOS we do not collect the advertising identifier (IDFA); ad measurement uses Apple's SKAdNetwork. On Android the Meta SDK may use the Android advertising ID, which you can reset or delete in your device settings. The Android app sends crash reports (device model, OS version, error details) to Sentry so we can fix bugs.
On the Chrome extension. Detection of Bible references happens entirely on your device. No page content leaves your browser. Detailed policy at midvash.com/chrome-extension/privacy.
4. What we do NOT do
We do not sell or rent personal data to anyone. We do not show ads inside the Bible reader or the devotional. We do not offer Facebook Login and do not access your Facebook or Instagram account. We do not send your notes, highlights, prayers, or chat messages to advertising or analytics providers.
5. Account
Creating a Midvash account is required for sync and account features (devotional, notes, highlights, reading plans, AI chat, subscription). When you create an account, we collect:
- Email address: to identify your account and enable sign-in
- Display name: pre-populated from your Apple or Google profile, editable later
- Profile picture: pre-populated from your Apple or Google profile, optional
- Gender and date of birth: optional, used only to personalize content, editable or removable in your profile
- Preferred locale and Bible translation: to sync your reading preferences across devices
- Your personal library and activity: bookmarks, highlights, notes, prayers, reading position, reading plan progress, devotional streak
- AI chat and study conversations: stored so you can return to them
- Subscription status: whether you have Midvash Pro and until when
We do not store passwords. Authentication uses Sign in with Apple, Sign in with Google, or a one-time code or link sent to your email.
6. Authentication providers
You can sign in to Midvash using:
- Sign in with Apple: Apple authenticates you and shares your name and email with Midvash on first sign-in. If you choose Apple's "Hide my email" feature, you'll get a relay address (something like abc123@privaterelay.appleid.com); we'll only ever see that relay. We do not see your Apple ID password or have any further access to your Apple account.
- Sign in with Google: Google authenticates you and shares your name, email, and profile picture with Midvash. We request only basic profile scopes (no access to your Gmail, Drive, contacts, or calendar). We do not see your Google password.
- Email: you enter your email and we send a one-time sign-in code or link valid for 15 minutes. No third party involved.
You can revoke Midvash's access to your Apple or Google account at any time:
7. Providers that process data
We share data only with the providers below, and only for the purpose described:
- Cloudflare: hosting, CDN, security, and database. Stores your account data. Also runs the AI models behind the chat and study features (Cloudflare Workers AI), so your chat messages are processed on Cloudflare's infrastructure and are not used to train models. Sends our transactional email.
- Apple and Google: sign-in (when you choose it) and processing of in-app purchases through the App Store and Google Play.
- RevenueCat: manages subscriptions. Receives an anonymous app user ID, your purchase history, and your country.
- Google Analytics and Google Analytics for Firebase: usage statistics on the website and apps.
- Meta (Facebook and Instagram): measurement of our ads through the Meta Pixel on the website, the Meta SDK in the apps, and subscription events sent from RevenueCat. Meta receives events such as page view, app install, trial start, and purchase, plus technical data (IP address, device and browser information). We do not send your name, notes, or reading content.
- Sentry: crash reports from the Android app.
- Legal requirements: we comply with valid legal requests (subpoenas, court orders) when required by applicable law.
Each provider handles data under its own privacy policy. We do not sell personal data and do not share it with data brokers.
8. Your choices
You can block or delete cookies in your browser settings. You can limit ad tracking on your device (iOS: Settings → Privacy & Security → Tracking; Android: Settings → Privacy → Ads). You can manage how Meta uses data from other apps and websites at Your activity off Meta technologies. Instructions to delete data associated with Meta are at midvash.com/facebook-exclusion.
9. Account deletion
You can delete your account at any time from Settings → Account → Delete account in the app, or by emailing contact@midvash.com.
When you delete your account, we immediately mark it as deleted and revoke all active sessions. Your personal data (profile, bookmarks, notes, reading position) remains in a recoverable state for 30 days. During this grace period you can restore your account by contacting us. After 30 days, all associated data is permanently and irreversibly purged from our servers. Deleting your account does not cancel a subscription bought through the App Store or Google Play; cancel it in your store account.
10. Children
Midvash is suitable for general audiences. We do not knowingly collect personal information from children under 13. Account creation is restricted to users aged 13 and over. If you believe we have inadvertently collected data from a child under 13, contact us and we will delete it.
11. Your rights
Subject to applicable law (LGPD in Brazil, GDPR in the EU, CCPA in California, and similar regulations elsewhere), you have the right to access, correct, export, and delete the personal data we hold about you, and to object to its use for ad measurement. To exercise these rights, write to contact@midvash.com.
12. Security
We use industry-standard practices to protect data in transit (HTTPS) and at rest (encrypted databases). On mobile devices, authentication tokens are stored in the operating system's secure storage (iOS Keychain, Android Keystore), encrypted at rest by the OS. No system is perfectly secure; in the event of a breach affecting personal data, we will notify affected users as required by applicable law.
13. Changes to this policy
If we change this policy materially, we will publish the updated version at the same URL with a new Last updated date. For changes that affect how we handle data, we will notify users through the app or by email when applicable.
14. Contact
For questions, requests, or concerns related to this policy, write to contact@midvash.com.