Privacy Policy

Effective date: [Effective date — to be set at release]. Last updated: October 2, 2026. This policy is issued by Westeresch B.V. and covers the Sacred Feed app for iPhone and the website sacredfeed.com.

The short version

  • There is no account and no sign-in. We never ask for your name, email or password to use the app.
  • Your reading history, bookmarks, likes, notes, streaks, reminder time and the faith tradition you choose stay on your iPhone. We do not receive them. Your tradition is sent to our usage statistics only if you switch on “Share my tradition in analytics” in Settings, and never to advertising or attribution partners.
  • The app works fully offline. It sends a small amount of technical data to a few service providers: subscription status, anonymous usage statistics, crash reports and, only if you tap Allow in the iOS tracking prompt, an advertising identifier used to see which ads bring new readers.
  • We do not sell or share your personal information. No personal data is ever sent to any artificial-intelligence system.
  • You can export or delete all app data in the app's Settings at any time. To delete data held by our service providers, email app@sacredfeed.com.
  • The website sets no cookies.

1. Who we are

Sacred Feed is made by Westeresch B.V., a private limited company registered in the Netherlands, [registered address, Netherlands], Chamber of Commerce (KVK) number [Chamber of Commerce (KVK) number]. Under the EU General Data Protection Regulation (GDPR) we are the controller of the personal data described in this policy. We have not appointed a data protection officer because the law does not require one for a company of our size and activity. For any question about privacy, write to app@sacredfeed.com.

Sacred Feed is marketed in the United States first. Because we are established in the European Union, the GDPR applies to everything we do with your data, wherever you live. If you live in the United States, the state-law rights in section 12 also apply to you.

2. No account

You do not create an account to use Sacred Feed. We do not collect your name, email address, phone number, contacts, photos, precise location or payment card details through the app. Because there is no account, there is nothing to log in to and no password that could leak. The only time you give us contact details is when you choose to email us or use the support form on this website.

3. What stays on your device

Everything personal about how you read stays on your iPhone and is never transmitted to us or to anyone else:

  • your reading history and current position;
  • bookmarks, likes and saved verses;
  • notes you write;
  • streaks and reading-plan progress;
  • your reminder time and notification settings;
  • the faith tradition and Bible translation you choose.

Our commitment about your faith tradition. The tradition you pick during setup reveals your religious beliefs. That is sensitive information under the GDPR (Article 9) and US state privacy laws, and we treat it that way. It is used on your device to choose a default translation and the order of the books. By default it is never sent anywhere. If you switch on Share my tradition in analytics in the app’s Settings, you give us your explicit consent to receive it as a single property in our product analytics (Amplitude) so we can see which traditions use the app and what they read. We never send it to advertising or attribution partners, never use it to target you, and never sell it. Switch the setting off at any time: the property is deleted from analytics and nothing further is sent.

If you use the app's export feature, the file is created on your device and goes only where you send it. If you delete the app, this data is deleted with it.

4. What we collect

4.1 Through the app

The app sends a limited set of technical data to the service providers listed in section 6. In the category wording used by California law, this is:

CategoryWhat exactlyWho receives it
IdentifiersApple's identifier for vendors (IDFV), a random app-user ID created by our subscription provider, a random device ID created by our analytics provider, a Crashlytics installation ID, and the advertising identifier (IDFA) only if you tap Allow in the iOS tracking promptAdapty, Amplitude, AppsFlyer, Google Firebase Crashlytics
Commercial informationApp Store transaction and receipt data: which subscription you have, when a trial or subscription started, renewed or ended. We never see card numbersAdapty, Apple, AppsFlyer (trial start and purchase events)
Internet or other electronic network activityProduct events such as screens viewed, number of verses read, features opened; app version, iOS version, device model and language; crash reports with stack traces and app state at the time of the crashAmplitude, AppsFlyer, Google Firebase Crashlytics
Geolocation data (coarse only)Country, and for attribution the city, derived from your IP address at the time of the request. The IP address itself is not kept by us; precise location is never collectedAmplitude (country), AppsFlyer (city)
Sensitive personal informationYour faith tradition, only if you switch on “Share my tradition in analytics” (explicit consent, off by default). Reading history, notes and bookmarks never leave your deviceAmplitude
InferencesNone. We do not build profiles about you—

We do not collect your contacts, photos, microphone, camera, health, financial or precise location data, and the app does not ask for permission to.

4.2 Through the website

  • Server logs. Our host, Netlify, records the IP address, requested page, time and browser of each request for security and troubleshooting. Logs are kept for 30 days.
  • Visitor statistics. We use Cloudflare Web Analytics, which does not use cookies or local storage and does not fingerprint your browser. It records the page URL, referrer, browser type and country.
  • Support form. If you write to us through the form on /support/, Netlify Forms stores your email address and message so we can answer you.
  • Cookies. This website sets no cookies, first-party or third-party.

5. Why we use this data and on what legal basis

The GDPR requires us to name a legal basis for each purpose. Here they are.

PurposeData usedLegal basis (GDPR Art. 6)
Unlocking Premium, restoring purchases, keeping your subscription in syncTransaction data, IDFV, app-user IDPerformance of a contract, Art. 6(1)(b)
Keeping accounting and tax records of salesTransaction dataLegal obligation, Art. 6(1)(c)
Understanding which features help people keep reading, so we can improve the appAnonymous usage events, device and app version, countryOur legitimate interest in improving the app, Art. 6(1)(f). Where the law where you live requires consent for this, we ask first. You can object at any time (section 9)
Finding and fixing crashesCrash reports, device model, OS, app stateLegitimate interest in a working app, Art. 6(1)(f)
Measuring which advertising brings new readers (attribution)IDFV, install and purchase events, IP-derived city; IDFA only with your permissionConsent, Art. 6(1)(a), given through the iOS tracking prompt for the IDFA; otherwise legitimate interest, Art. 6(1)(f), limited to counting installs
Answering your questions and fixing reported mistakesYour email address and messageLegitimate interest in helping you, Art. 6(1)(f); contract where it concerns your subscription
Keeping the website secureServer logsLegitimate interest in security, Art. 6(1)(f)
Complying with the law, including age-range signals from Apple (section 14)Only what the law requiresLegal obligation, Art. 6(1)(c)

We do not make any decision about you by automated means that has a legal or similarly significant effect on you. There is no profiling.

6. Who receives your data

We do not sell personal information. We do not share personal information for cross-context behavioral advertising. We work with a small number of service providers (processors) that act only on our instructions and under written contracts. Each is bound to protect your data at least as well as this policy and Apple's App Store guidelines require.

ProviderRoleData it receivesRetentionPrivacy page
AdaptySubscription infrastructureApp Store receipt and transaction data, purchase history, IDFV, a random app-user ID, device type and localeFor the life of the subscription, then 7 years for accountingadapty.io
AmplitudeProduct analyticsRandom device ID, events such as screens viewed and verses-read count, app version, iOS version, coarse country from IP24 months, then deleted automaticallyamplitude.com
AppsFlyerInstall attributionIDFV, IP-derived city, install and in-app events such as trial start and purchase; IDFA only if you tap Allow in the iOS tracking promptRaw user-level data 90 days; aggregated data 25 monthsappsflyer.com
Google Firebase CrashlyticsCrash reportingStack traces, device model, iOS version, app state at the crash, Crashlytics installation ID90 daysfirebase.google.com
AppleApp Store billing and distributionYour purchase, handled entirely by Apple under Apple's own privacy policy. We receive transaction records, never card numbersPer Apple's policyapple.com
NetlifyWebsite hosting and support formServer logs with IP address; support-form messages and emailLogs 30 days; form messages until answered, deleted within 12 monthsnetlify.com
CloudflareDNS and cookieless web analyticsPage URL, referrer, browser type, countryAggregated statistics onlycloudflare.com

We may also disclose data if the law requires it, to protect our rights or someone's safety, or to a buyer if our company is sold, in which case this policy continues to apply.

7. No data is sent to AI

Deep Study notes in the app are written in advance, checked, and shipped inside the app. The app never sends your prompts, your reading, your notes or any personal data to any artificial-intelligence service, ours or anyone else's. Read how our studies are made.

8. International transfers

Our service providers are based in, or process data in, the United States. When personal data leaves the European Economic Area we rely on the EU–US Data Privacy Framework for providers certified under it, and otherwise on the European Commission's Standard Contractual Clauses, with supplementary measures where needed. You can ask us for a copy of the relevant safeguards at app@sacredfeed.com.

9. Tracking and your choices

App Tracking Transparency

Soon after you start the app, iOS asks whether Sacred Feed may track you across other companies' apps and websites. If you tap Allow, the app shares Apple's advertising identifier (IDFA) with AppsFlyer so we can learn which ad brought you here. If you tap Ask App Not to Track, no IDFA is shared and attribution is limited to counting installs. Nothing in the app depends on your answer. You can change it at any time in iOS Settings › Privacy & Security › Tracking.

Analytics

Usage statistics are anonymous and never include your reading history or notes; your tradition is included only if you switched on “Share my tradition in analytics”. If you want us to delete the statistics tied to your device ID, email us with the Support ID shown in the app under Settings › Privacy, or use Delete my data in Settings, which also resets the identifiers on your device.

Reminders and notifications

Reminders are optional, scheduled on your device, and controlled in the app's Settings or in iOS Settings › Notifications. No feature requires notifications.

Do Not Track and Global Privacy Control

Our website does not track you across other sites, sets no cookies and uses no third-party advertising. There is therefore nothing to opt out of, and we do not change our behavior in response to a browser's Do Not Track signal. We nevertheless treat a Global Privacy Control signal as a valid request not to sell or share personal information, which we never do in any case.

10. How long we keep data

DataKept for
Everything on your device (reading, notes, tradition, settings)Until you delete it or delete the app
Subscription and transaction records (Adapty)Life of the subscription, then 7 years for accounting and tax law
Analytics events (Amplitude)24 months, then deleted automatically
Attribution data (AppsFlyer)Raw data 90 days; aggregated data 25 months
Crash reports (Crashlytics)90 days
Website server logs (Netlify)30 days
Support messages and emailsUntil answered, then deleted within 12 months unless we need them for an open issue or a legal reason
Aggregated statistics with no personal dataIndefinitely

11. Your rights

Under the GDPR you have the right to:

  • access the personal data we hold about you and get a copy;
  • correct inaccurate data;
  • erase your data ("right to be forgotten");
  • restrict processing or object to it, including to processing based on legitimate interest;
  • port your data in a machine-readable format;
  • withdraw consent at any time, for example by turning off tracking in iOS Settings. This does not affect processing that happened before you withdrew it.

How to exercise them. Email app@sacredfeed.com. Because we hold no account, the only way we can find data about you with our providers is the Support ID shown in the app under Settings › Privacy; please include it. We will answer within 30 days. We may ask a question to confirm that the request really comes from the device owner. We never charge for a request unless it is clearly excessive.

Much of your data you can handle yourself, instantly: Settings › Export my data gives you a copy of everything stored on your device, and Settings › Delete my data erases it and resets analytics identifiers. See Privacy Choices for step-by-step instructions.

Complaints. If you believe we have handled your data unlawfully, you can lodge a complaint with the Dutch data protection authority, the Autoriteit Persoonsgegevens (autoriteitpersoonsgegevens.nl), or with the supervisory authority where you live or work. We would appreciate the chance to resolve it first.

12. Your US state privacy rights

If you live in California, Colorado, Connecticut, Virginia, Oregon, Texas or another US state with a comprehensive privacy law, you have the right to know what personal information we collect and how we use it; to access it; to delete it; to correct it; to opt out of its sale, sharing or use for targeted advertising; to limit the use of sensitive personal information; and not to be discriminated against for exercising these rights.

  • We do not sell or share personal information as those terms are defined in the California Consumer Privacy Act, and we do not use it for targeted advertising. We have no reason to believe we sell or share the personal information of anyone under 16.
  • Sensitive personal information. Your faith tradition leaves your device only with your explicit consent (the “Share my tradition in analytics” switch, off by default). You can withdraw consent at any time by switching it off, and you may ask us to limit the use of sensitive personal information by email.
  • Categories collected in the last 12 months are listed in section 4; sources are you and your device; purposes are in section 5; the service providers that receive them are in section 6.
  • How to make a request. Email app@sacredfeed.com or use the form on /support/ with the topic "Privacy request". Include the Support ID from Settings › Privacy. We confirm receipt within 10 business days and answer within 45 days, extendable once by a further 45 days with notice. An authorized agent may act for you if they show written permission.
  • Appeal. If we decline your request, we will tell you why. You may appeal by replying to our decision within 60 days; a different person will review it and answer within 45 days. If you remain unsatisfied, you may contact your state attorney general.
  • California "Shine the Light" (Civil Code §1798.83). We do not disclose personal information to third parties for their direct marketing.
  • Global Privacy Control. We honor it as an opt-out of sale and sharing (section 9).

13. Children

Sacred Feed is a general-audience app for people aged 13 and over. We do not knowingly collect personal information from children under 13. If we learn that we have, we delete it. If you believe a child under 13 has used the app with analytics enabled, email app@sacredfeed.com and we will delete the associated data.

14. Age-range signals from Apple

Where the law requires it (for example the Texas App Store Accountability Act), Apple may tell the app the age range of the account holder. We use that signal only to comply with the law, for example by disabling analytics and attribution for younger users, and we do not store it beyond what is needed to do so.

15. Security

All data sent by the app and the website travels over encrypted connections (TLS). We hold no account database and no payment details, so there is very little to steal. Our providers maintain independent security audits (such as SOC 2). No system is perfectly secure; if we ever learn of a breach affecting you, we will inform you and the authorities as the law requires. To report a security problem, email app@sacredfeed.com.

16. Changes to this policy

When we change this policy we update the "Last updated" date at the top. If a change is material, we will tell you inside the app before it takes effect and keep the previous version available on request. We review this policy at least once a year.

17. Contact

Westeresch B.V.
[registered address, Netherlands]
KVK [Chamber of Commerce (KVK) number]
app@sacredfeed.com

See also: Privacy Choices, Terms of Use (EULA), Support, How our studies are made.