Privacy Policy for Steeple
Last updated: 13 August 2026
The operator and the governing jurisdiction were resolved on 28 July 2026 to Billionweb, Singapore, and are stated at the foot of this page. If you later change what the app does, change this page in the same commit.
Steeple is built so that there is very little to collect. There is no account, no login and no profile. This page explains exactly what happens to information when you use the app, including the parts that are not zero.
The short version
- Steeple does not require an account and never asks for your name, email address or phone number.
- Your streak, your saved verses, your reminder time and your translation choice are stored only on your device.
- Steeple contains no advertising, no ad networks and no attribution software. It does not read your device's advertising identifier, and it will never ask permission to track you, because it does not track you.
- Steeple does collect anonymous usage statistics and crash reports, so that faults can be found and the app improved. These are tied to a random number generated at install, not to you. Details below.
- The one feature that sends anything you have written is Ask. Your question goes to our AI provider so it can be answered. Nothing identifying you goes with it.
- Steeple does not sell your information and does not share it with data brokers.
What is stored on your device
The following stays on your iPhone and is never transmitted to us or anyone else:
- Your current and longest streak, and the dates you have read
- Verses you have saved
- Your daily reminder setting and time
- Your translation choice
- Whether you have an active subscription
This data lives in the app's own storage and in a shared container the widget reads. There is no sync and no cloud backup of it on our side. Deleting the app deletes all of it. We have no copy and cannot recover it, which is also why a streak does not follow you to a new phone unless you restored that phone from an iPhone backup.
Anonymous usage statistics
Steeple uses Google Firebase Analytics to count how the app is used in aggregate. We use it to answer questions like how many people added the widget, and how many keep a streak past a week. Those two numbers decide what gets built next.
What it collects:
- A random app instance ID, generated when you install the app. It is not your name, your Apple ID, your phone number or your device's advertising identifier. It is reset if you delete and reinstall the app.
- Your device model, operating system version, app version, and the country or region your connection appears to come from.
- Seventeen events, and no others: finishing a step of first time setup, finishing setup and how many seconds it took, viewing a verse, viewing an explanation, adding the widget, answering the reminder permission question either way, opening a reminder, reaching a streak day and its number, using Ask, hitting the free Ask limit, saving a verse, seeing the paywall and which of five places opened it, tapping the trial button, starting a trial, subscribing, tapping share, and tapping the rate button.
- Six general facts about your copy of the app, so the counts above can be read in groups: whether you subscribe, whether reminders are on, whether the widget is installed, roughly how long your streak is as one of four bands rather than the exact number, which translation you read, and which of the app's preset verse text sizes you read at.
What it does not collect: which verses you read or save, what you type into Ask, the content of anything, or any identifier that points back to you as a person.
That last point is built into the app rather than promised. An event can carry a small number of extra details, and they are all listed above: a count, a number of seconds, a yes or no, which setup step, or which of the five places the paywall opened from. Every one of them is chosen from a fixed list written into the app, not assembled while it runs.
There is no way for a verse, a reference, a saved item or a word you typed to be attached to an event, because the app provides no means of attaching such text to one. The part of the app that sends these events accepts only whole numbers and values picked from those fixed lists, and nothing you type can become one. It is not that we choose not to send it. There is no route.
Firebase Analytics is built here in its version without the advertising identifier. The library that reads Apple's IDFA is deliberately not included in the app, and an automated check fails the build if it ever gets added back. This data is not used for advertising, is not linked to an advertising profile, and is not used to track you across other companies' apps or websites.
Crash reports
Steeple uses Google Firebase Crashlytics. If the app crashes, it sends a report so the fault can be fixed.
A crash report contains the technical stack trace of what the app was doing when it failed, plus your device model and operating system version. It does not contain your saved verses, your questions, or anything you have written.
Ask
Ask is the only feature that sends anything you have typed. When you ask a question about a verse, we send exactly three things to our AI provider:
- The verse reference, for example
Matthew 6:34 - The text of that verse
- The question you typed
We do not send your name, email, device identifier, advertising identifier, location, subscription status, streak, or any history of your previous questions. Each question is handled on its own, with no memory of any earlier one.
We keep a cache of questions and their answers, so that a question already answered does not have to be sent to the AI provider again. You should know how that works:
- The cache stores the verse reference, a simplified version of the question, and the answer. It does not store who asked, when you asked, or anything about your device.
- It is keyed on the verse and the wording of the question, never on you, which means the cache is shared. Two people asking the same thing about the same verse are served the same entry. There is no way to group entries back into one person's questions, because nothing in the request says which questions came from the same phone.
- Cached entries are kept indefinitely and are not deleted on a schedule. They are ordinary reference material at that point, not a record of anyone.
Our own server logs record the verse reference, whether the answer came from the cache, and how long the request took. They never record the question text, on any code path, including when a question is stopped by the crisis check.
To confirm the app really is the app, and to stop other people running up our bill, each request carries an Apple issued attestation through Firebase App Check. It says "this is a genuine copy of Steeple on a genuine device". It is not an account, it does not identify you, and it is not stored.
Please do not type sensitive personal information into Ask. The app shows this reminder on screen every time, and the reason is the cache described above.
Purchases
Subscriptions are processed by Apple. We never see and never receive your card number, billing address or Apple ID.
We use RevenueCat to check whether a valid subscription exists. It receives the purchase receipt Apple issues and an anonymous purchase ID that it generates. It does not receive your name or your Apple ID. To manage or cancel, use Profile inside the app or your Apple subscription settings.
Children
Steeple is rated 4+, which means its content is suitable for all ages. It is written for adults and is not directed at children, and it is not published in the App Store Kids Category.
Steeple has no account, no sign up, no messaging, no user profiles, no advertising and no links to user generated content, so there is no way for a child to give us personal information or to be contacted through the app. The anonymous usage and crash data described above is not personal information about any individual, child or adult, and is never used for advertising or to build a profile.
We do not knowingly collect personal information from children under 13. If you believe a child has somehow provided personal information through the app, write to the address below and we will delete it.
Your rights
We hold almost nothing that could identify you, so in most cases there is nothing for us to look up, correct or delete.
Depending on where you live you may have rights under the GDPR, the UK GDPR, or the CCPA, including the right to access, correct, delete, or object to processing. We honour all of them. We do not sell personal information as defined by the CCPA, and we have never done so.
If you want the anonymous usage data associated with your installation to stop being collected, deleting the app stops it, and reinstalling generates a new random ID unconnected to the old one.
For requests about anything on this page, write to the address below.
Who processes data for us
| service | what it receives | why |
|---|---|---|
| Google Firebase Analytics | anonymous app instance ID, device and app version, coarse region, the seventeen events and six general facts above | to see which features are used |
| Google Firebase Crashlytics | crash stack traces, device model and OS version | to fix crashes |
| RevenueCat | Apple purchase receipt, anonymous purchase ID | to check subscription status |
| Our AI provider | verse reference, verse text, your typed question | to answer Ask |
| Google Firebase App Check | a device attestation proving the app is genuine | to stop abuse of the Ask endpoint |
| Google Cloud Firestore | the cached question and answer described above | so a question is not sent twice |
| Apple | your purchase, entirely between you and Apple | to take payment |
Changes to this policy
If the app starts doing something new with information, this page changes first and the date at the top changes with it. Material changes will also be described in the app's release notes.
Contact
Questions about privacy, or anything else:
arshpreet@billionweb.co
Steeple is operated by Billionweb, Singapore.