Written specifically for SynchedWord, but not legal advice. Complete every [bracketed] field and have it reviewed. One point in particular needs a lawyer's eye: this app necessarily handles religious belief, which several state laws classify as sensitive data requiring opt-in consent. See Sensitive information.
Privacy Policy
Last updated: [EFFECTIVE DATE] · Version 1
At a glance
Four commitments the rest of this document has to keep:
- We do not sell your information, and we do not share it for advertising. There are no ads and no ad networks in SynchedWord.
- Your private notes are yours. The presenter cannot read them. Nobody else in the congregation can read them.
- You can follow a service without an account at all — no name, no email, no sign-up.
- You can download or delete everything from Settings, at any time, without asking us.
Who we are
SynchedWord is operated by [LEGAL ENTITY NAME], a [STATE] limited liability company based in [CITY, STATE, USA]. The service lets a presenter lead a congregation through a sermon outline, and lets each person follow along, read the passages, and keep their own notes.
Privacy questions and requests: [PRIVACY EMAIL].
SynchedWord is intended for use in the United States. It is not directed at the EU or UK, and we do not currently offer it there.
Sensitive information — please read this one
This is the section that matters most in an app like this, and we would rather be blunt than reassuring.
Using SynchedWord reveals something about your religious life. If you join a service while signed in, we necessarily hold a record that you joined a named church's service on a given date. Your notes are about sermons. Taken together, that is information about religious beliefs and affiliation.
Joining is not attendance, and we cannot tell the difference. Many churches stream their services, so someone joining may be sitting in the building, watching from home, following from another country, or simply curious about a code they were given. We record only that a device joined — never where you are. Nothing in SynchedWord places you anywhere, and no record here should be read as proof that you were physically present anywhere.
Several state privacy laws, including Virginia's Consumer Data Protection Act, California's CPRA, and the laws of Colorado, Connecticut and others, treat religious belief as a sensitive category that gets stronger protection than ordinary personal information.
So the following rules apply to everything in SynchedWord, because effectively all of it falls in that category:
- We collect it only to run the service you asked for — showing you the service you joined, keeping your notes, and letting you find them again later.
- We never sell it, never share it for advertising, and never use it to build a profile of you.
- We count totals, never people. To see how SynchedWord is doing we count things like how many services ran this week, how many notes were written, and how many churches use it in each state (from the city and state a presenter gives for their church), and how many people have opened each sermon, which its presenter can see (each device counts itself once; we store only the number). A total never names or describes anyone, we read no one's notes to make it, and no outside analytics company is involved.
- We do not disclose your participation to anyone outside your church, except where the law compels us (see When we may have to disclose).
- You can delete it, and deletion means deletion — see Retention.
- Creating an account is your opt-in. Signing up, and joining a service, is how you consent to us holding this. If you would rather not, you can follow anonymously, and you can stop at any time.
If you are ever uncomfortable with a record existing, follow without an account. Then we keep nothing at all — no record that your device joined, and no identifier for it.
What we collect
The categories below are intended to cover everything. If something is not here, we are not collecting it.
If you follow a service without an account
- Nothing, on our side. We do not record that your device joined, which service it followed, or when.
- A random device identifier, kept only in your browser. It is not your name, your phone number, or your device's serial number — it is a random string, so that if you later sign in on this device it can be linked to your account. Until then it never leaves your device in any form we keep. You can clear it by clearing site data.
If you create an account
- Your name and email address.
- Your password, stored only as a salted hash using scrypt. We cannot read it, and neither can anyone who obtains our database.
- If you add a passkey: its public key (which can check a sign-in but never make one), an identifier for it, the name it is shown under in Settings, and when it was added and last used. Your face, fingerprint and PIN never leave your device — we never receive them. The passkey itself is kept by your device or the password manager you choose (for example iCloud Keychain or Google Password Manager), under your agreement with them, not ours. Removing a passkey in Settings, or deleting your account, deletes what we hold about it.
- If you turn on two-factor login: the secret your authenticator app shares with us, stored encrypted with a key kept apart from the database, and your recovery codes, stored only as hashes we cannot read back. Both are deleted when you turn it off or delete your account. We email you whenever it is turned on or off, new recovery codes are made, or a recovery code is used. Nothing is shared with the maker of your authenticator app — the codes are worked out on your phone.
- Your preferred Bible translation, if you set one.
- Your notes, and which passage each belongs to.
- Which services you have joined, so your library works.
- Sermons you record yourself, if you use that — the title, church name and date you type, the passages you add and your notes on them. Only you can see them, and they are deleted with your account.
- Which devices you have linked, so notes taken on your phone appear on your laptop.
- Your sign-ins: for each place you are signed in, the kind of device and browser (for example "iPhone · Safari" — a few words, not your browser's full details, and not your internet address), when you signed in and when it was last used. You see the list in Settings → Login & security → Your devices and can sign any of them out. We keep only a scrambled fingerprint of each sign-in, never the sign-in itself, so a copy of our database could not be used to sign in as you. At most 20 at once; a new one signs out the least recently used.
If you are a presenter
- Your church's name and location, which are shown to anyone who joins your service.
- Your presenter code prefix — the permanent four characters at the start of your service codes.
- Your sermon outlines: titles, Scripture references, and your own notes on each passage, including the ones you mark private.
If you support the app
- A record that a payment was made, its amount, and whether it repeats — so receipts can be sent and a cancellation honoured. This record is kept by our payment processor; we see it in their dashboard and do not copy it into our own database.
- Your email address, for receipts, the confirmation of your monthly support, and the yearly reminder that it is still running.
- Your name and the billing details you type (such as country and postal code) on the payment page, which the processor needs to take the payment.
- Never your card number. It goes directly to our payment processor and never passes through SynchedWord.
Supporting the app is not linked to your church or your notes, and gets you nothing extra in the product. There is no supporter status to store.
Technical information
- Your IP address, used to rate-limit abuse (repeated failed sign-ins, guessing at service codes) and kept in the server's memory only — never written to the database — for at most 7 days (most for an hour or less; the longest is the record that stops one address sending repeated reports about the same service). The one exception: when you ask for a password reset, the address the request came from is stored with that reset, to investigate misuse, and deleted with it — within a day after the link is used or expires. We do not build a location profile from it.
- Ordinary server logs — the request, the time, the response. These are operational records, not a behavioural profile.
We do not collect: your precise location or GPS, your contacts, your photos, your microphone or camera (except that your camera is used on your device to scan a QR code — the image never leaves your phone), advertising identifiers, or anything from other apps or websites.
Who can see what
People consistently assume the pastor can read their notes. They cannot. Here is the full picture:
- Your private notes: only you, on your devices, or signed into your account. Not the presenter. Not your church. Not anyone else following along.
- That you joined: the presenter sees a count of how many people are connected — not who, and not where. If you are signed in, your name is kept with your own record of that service; the presenter never sees it.
- The presenter's notes: shown to the congregation, except passages the presenter marks private, which stay with them.
- Anyone with the service code: a service code is the key to that service. Anyone who has it can see the outline and the passages revealed so far. Codes are meant to be shared — printed, shown on screen, posted online — so treat what you put in a sermon outline as public.
How we use your age
You must be 13 or older to create an account. Following a service needs no account, no birth year and no age.
Every use of your birth year: checking that minimum at sign-up, and nothing else.
Every non-use: we do not use it for advertising (there is none), for pricing, for profiling, for content selection, or in any statistic we share with anyone. We ask for the year only, check it, and do not keep it — it is not stored anywhere.
If we learn that an account belongs to someone under 13, we will delete it and its notes.
A note for churches: children in a congregation may follow a service anonymously on a shared or family device — in the building or at home, since a service code works from anywhere. In that case we hold nothing about that device — no identifier, no record that it joined, no name, email or age. Churches running youth services should be aware of this and may wish to tell parents. If a child does end up with an account, see Children for how to have it removed.
Who we share with
We use a small number of service providers. Each one is listed below with exactly what it receives and what it never receives. They act on our instructions and may not use your information for their own purposes. We do not sell personal information, and we do not share it for advertising of any kind.
This list is meant to be complete. If we add a provider that handles anything about you, we will add it here and treat it as a material change — see Changes to this policy.
Running the app
- Render (servers in Virginia, USA) — runs the servers.
Receives: everything, in transit, because the app runs on their machines. - Supabase (database in the US East region) — stores the database.
Receives: accounts, notes, sermons and join records. Encrypted at rest and in transit. - Cloudflare — routes traffic and email to us.
Receives: the network requests that reach us, and any email you send to our published addresses.
Never receives: anything from inside your account. It sees traffic, not contents of notes.
- Resend — sends our email: password resets; notices about your account's security (password, two-factor login, passkeys, deletion); to presenters, notice of a takedown and of a restored sermon, with the sermon's title and code and the removed note's opening words; to supporters, the monthly-support confirmation and yearly reminder; and to us, report alerts (with what the reporter wrote and the details they gave) and a weekly email of totals.
Receives: the recipient's email address and the message itself.
Never receives: your own notes or the list of services you follow. - [MAILBOX PROVIDER — e.g. Google Workspace] — holds the mailbox behind our published addresses, so that anything you write to us about privacy, support or a child's account is stored there.
Receives: whatever you choose to put in an email to us.
Never receives: anything we did not ask you for. Please do not send us documents, ID or a date of birth — see Children.
Security and payments
- Have I Been Pwned — checks, when you choose a password (at sign-up, on a reset or a change), whether it has appeared in a public breach.
Receives: the first five characters of your password's SHA-1 hash, which is not enough to identify it. Your password itself is never sent, and the comparison happens on our side. - [PAYMENT PROCESSOR — e.g. Stripe] — handles support payments, if you choose to make one.
Receives: your payment details and email address, directly from you on their own page. Your card number never reaches us and we never store it.
Never receives: your notes, your join records, or which church you follow. If you never support the app, they receive nothing about you at all.
Bible text
- bible-api.com and API.Bible (scripture.api.bible, api.bible) — supply verse text for translations we do not store ourselves.
Receives: the Scripture reference being looked up — for example "John 3:16" — sent from our server, not from your device.
Never receives: your identity, your notes, or which service you are in. Nothing from them is loaded into your browser, and your device never contacts them.
Why a Bible app needs an outside provider at all. Translations like the KJV and the World English Bible are in the public domain, and we store those ourselves — reading them involves nobody but us. Modern translations such as the NIV, NLT and ESV are copyrighted, and the only lawful way for an app this size to show them is through a provider licensed by their publishers. API.Bible is that provider. Which translations are actually available in this app is listed on the Bible Copyright page.
Usage reporting, if and when we offer a copyrighted translation. Publishers license their text on the condition that they can see how much of it is read. Where we show a copyrighted translation, our server sends API.Bible a one-off token meaning "this passage was read". We send no device identifier, no session identifier and no user identifier — their system accepts all three and we deliberately send none of them — so what a publisher learns is how often a passage was read and never by whom. Public-domain translations are not reported at all, and no reporting of any kind happens in your browser.
Nobody else
There is no advertising network, no analytics company, no data broker, no AI provider and no social platform in this list, because we use none of them. SynchedWord contains no advertising and no AI features.
We may also disclose information to professional advisers, or to a buyer if the service is ever sold or merged — in which case this policy travels with it and we will tell you before anything changes.
When we may have to disclose
We will disclose information where we are legally required to: a valid subpoena, court order or other lawful demand, or where necessary to protect someone's life or safety, or to investigate fraud or an attack on the service.
Given what this data reveals about religious participation, our practice is to require valid legal process rather than responding to informal requests, to disclose the narrowest set of records that answers the demand, and to notify you unless we are legally prohibited from doing so.
Bible text and copyright
Public-domain translations (World English Bible, King James, American Standard) are stored on our servers. Copyrighted translations are supplied by a licensed provider; a passage once fetched is kept on our server for up to 14 days, as the provider's terms allow, and is never included in our backups. See Bible copyright.
Cookies and local storage
SynchedWord uses no advertising cookies, no tracking pixels, and no third-party analytics tags. No code is loaded into your browser from any other company's servers on any page of this app — everything comes from SynchedWord itself (including one small open-source library, for reading QR codes, which we serve ourselves) — and we do not track you across sites or apps. The one report we are contractually required to make — Bible publishers' usage reporting for copyrighted translations — is sent by our server and carries no identifier for you; see Who we share with. What we store on your device:
- Your sign-in token — keeps you signed in. Required; clearing it signs you out.
- Your device identifier — a random string. Signed in, it links your notes on this device to your account; signed out, it is used for nothing we keep. A new one is made when you sign out or delete your account.
- Your display preferences — text size, light or dark, contrast and red letters (only if you change them), last Bible position, last service code. Kept on this device, not on our servers.
- Unsaved note text, briefly, so a dropped connection does not lose what you were writing.
All of it is first-party and all of it is cleared by clearing site data for this site — which also signs you out. The full list, and your choice about the optional preferences, is on the Cookie & storage policy.
If you report a service
A report holds what you write, and your name and email if you give them (a copyright report requires both, as the law requires of a copyright notice). We use it only to review and act on the report. If we remove anything because of a report, we tell the presenter what was removed and why, but not who reported it — except that a copyright report may be passed to the presenter concerned so they can respond, as copyright law expects. People following that sermon see only that something was removed and the kind of report, and keep their own notes. Reports are kept as a record of how each was handled. Nobody else can read them back through the app — only we can, when handling them, and you can see your own reports (sent while signed in) in Settings → Your data → Download my data.
Where your information is kept
SynchedWord is offered in the United States, and everything we hold is stored and processed in the United States, by the providers named under Who we share with. If you use SynchedWord from elsewhere, your information is transferred to the US, where privacy laws may differ from yours.
No artificial intelligence reads your notes. We do not use your notes, sermons or anything else you write to train or run AI models, and we do not send them to any AI provider.
Your rights
We extend these to everyone, in every state, rather than only where a law requires them:
- Know and access what we hold about you, and take a copy — Settings → Your data → Download my data gives you all of it in one file, in a standard format (JSON) other apps can read. Each sermon's notes can also be exported on their own from History.
- Correct it.
- Delete it — all of it, or just part, without closing your account: remove one service and your notes on it (open it from History → Remove from my library), or clear all your notes and history (Settings → Your data). Or delete your account and everything attached (Settings → Your data → Delete account).
- Sign out other devices, from Settings → Login & security.
- Opt out of sale, sharing, targeted advertising and profiling — none of which we do, so there is nothing to opt out of. We honour Global Privacy Control signals regardless.
Under Virginia's Consumer Data Protection Act, California's CCPA/CPRA, and comparable laws in Colorado, Connecticut, Utah, Texas, Oregon, Montana and other states, you also have the right to appeal a refused request. To exercise any right, use Settings or write to [PRIVACY EMAIL]. We respond within 45 days and may extend once, with notice. We never charge for this and never treat you differently for asking.
How long we keep things
- Your account and notes — until you delete them.
- Sermons and join records — kept while the presenter's account exists, because a service code is permanent and a congregant may return to it years later. A sermon someone saved stays in their library if the presenter deletes it from their own list (as it was). If the presenter deletes their account, it stays without the presenter's details — see below.
- Sign-in sessions — and the device description and last-used time kept with each — expire after 30 days and are deleted automatically, or sooner when you sign out.
- Rate-limiting records — held in the server's memory for at most 7 days (most for an hour or less), never written to the database, and gone whenever the server restarts.
- A deleted account — removed from our live database immediately, and from backups within [30/90] days as backups roll over.
- Server logs — [RETENTION PERIOD].
If you follow services and delete your account, your notes, your library and your account are deleted. The services you followed stay as they are for their presenter and everyone else.
If you present and delete your account, we delete your account, your church's name and location, and every sermon nobody saved. Where someone saved one of your sermons to their library, we keep only its title, date and Scripture references, alongside their notes — which are their information, not yours — and delete your notes, headings and every link to you and your church. Your code prefix is released, so it is no longer tied to you. The exact terms are in Terms of Service, section 6.
Everywhere, not just the main records: deleting an account also removes your sign-ins on every device, your passkeys, your two-factor settings and recovery codes, any password-reset links, the sermons you recorded yourself, and the link between your devices and your account. On the device you delete from, the app also forgets your notes still waiting to be sent and gives that device a new random identifier.
What deleting does not reach: reports you sent us (kept as a record of how each was handled — see If you report a service); payment records our payment processor must keep by law; emails you have sent us; our backups, for up to 30 days; and anything still stored in the browser on your other devices (they are signed out automatically, and clearing the site's data there removes the rest). Monthly support is not tied to your account, so deleting your account does not stop it — cancel it here.
Deleting an account does not retract anything you shared with others outside the app.
Security
Passwords are stored as salted scrypt hashes and are never recoverable, including by us. All traffic is encrypted in transit. The database enforces access rules at the database level, so a mistake in application code cannot expose one church's data to another. Password strength is checked against known breaches at sign-up. Sign-in attempts are rate-limited.
No system is perfectly secure. If a breach affects your information we will notify you and the relevant regulators as the law requires.
Children
Accounts require you to be 13 or older. We ask the year you were born before an account is created, and we do not knowingly collect personal information from anyone under 13.
Following a service needs no account, and is open to any age. When someone follows without an account we keep no record of that device at all — no identifier, no list of services followed, nothing. So a child using SynchedWord this way leaves nothing for us to hold, delete, or disclose.
If a child under 13 has an account — how to tell us
Write to [PRIVACY EMAIL] with the subject “Child account”. You do not need to be the parent to report it, and you do not need an account yourself.
Please include, if you can: the email address on the account, and your relationship to the child. That is all we need. Do not send us the child's date of birth, a photograph, a government ID or any document — we do not want that information and we will not keep it.
What we do:
- We acknowledge your message within 3 business days.
- We suspend the account immediately on receipt, before any checking, so nothing further is collected while we look.
- We delete the account and everything attached to it within 7 days — notes, join records, sessions and the email address itself. Deletion is permanent and we cannot undo it.
- We write back to confirm when it is done.
- We keep a note that a deletion happened, and its date. We do not keep the child's information in order to prove we deleted it.
If you are a parent and would rather the account simply be closed than have us verify anything, say so — closing and deleting are the same action here, so we will just do it. We would rather delete an account that turns out to belong to an adult than keep one that belongs to a child. An adult whose account is deleted in error can create a new one.
Teenagers, 13 to 17
An account holder aged 13 or over is treated the same as any other account holder, with one thing worth stating plainly, because it is what most laws protecting teenagers actually regulate: we do not sell personal information, share it for advertising, serve targeted advertising, or build profiles for automated decisions — for anyone, of any age. There is no advertising in SynchedWord at all. If that ever changes we will treat it as a material change to this policy and give notice first.
International
SynchedWord is operated in the United States and intended for use there. Your information is stored and processed in the United States. We do not currently offer the service in the EU or UK and have not implemented GDPR transfer mechanisms.
Changes to this policy
We will post changes here and update the date and version above. A change is material if it adds a category of information we collect, adds a third party we share with, or reduces your rights. For material changes we will give notice in the app, and by email to account holders, at least 30 days before they take effect.
Contact
Privacy questions and requests: [PRIVACY EMAIL] · [MAILING ADDRESS]
Terms of Service · Cookies · Bible copyright · Accessibility · Return to SynchedWord