Draft — have an attorney review before launch.

Privacy Policy

Last updated: 2026-08-16 · This policy explains what BibleLabs LLC ("Scriptura AI," "we") collects at biblelabs.ai, why, and what we do with it. The short version: we collect only what the study tools need, we don't run ads or analytics, we don't sell data, and we don't keep your AI conversations on our servers.

1. What we collect

2. What we don't do

3. Third-party processors

We share data with a small set of processors, each only for the purpose listed:

ProcessorPurposeWhat they receive
Anthropic (Claude)AI processing when you use AI featuresYour chat messages and the passage/study context needed to answer them. Not stored by us.
Google (Gemini)AI processing when you select Gemini or use image transcriptionYour chat messages, passage context, and any image you submit for OCR.
StripeSubscription paymentsPayment and card details go directly to Stripe — card data never touches our servers. We keep only your Stripe customer reference and plan status.
ResendTransactional email (e.g. password resets)Your email address and the message being sent. No marketing email.
Google OAuth"Sign in with Google"Google tells us your verified email address; we request nothing else.

Each processor handles data under its own privacy terms. If you bring your own AI-provider key, your requests to that provider are governed by your agreement with them.

4. How long we keep data

Account and study data are kept while your account exists. Session cookies expire after 30 days of inactivity. AI usage counters are kept as monthly aggregates for billing and allowance enforcement. AI conversation content is not retained server-side at all.

5. Your data: export & deletion

6. Security

Passwords are scrypt-hashed with per-user salts and compared in constant time; session tokens are stored only as hashes; stored API keys are encrypted at rest with AES-256-GCM; session cookies are HttpOnly and, in production, marked Secure and sent only over HTTPS. No system is perfectly secure, but we design so that a copy of our database alone does not expose your password or your API keys. If we learn of a breach affecting your data, we will notify you as required by law.

7. Children

The service is not directed to children under 13 (or the equivalent minimum age in your jurisdiction), and we do not knowingly collect personal information from them.

8. Changes to this policy

If we change this policy in a material way, we will notify you by email or a prominent in-app notice before the change takes effect. The "Last updated" date above reflects the current version.

9. Contact

Privacy questions or requests: biblelabsai@proton.me · BibleLabs LLC, ⟦mailing address — not configured⟧.