Privacy

Română · English

Last updated: 20 September 2026
Data controller: IMPERICORP X SRL, with its registered office at Str. Valea Lui Mihai nr. 3, Bl. TD14, Et. 10, Ap. 64, Sector 6, București, postal code 061751 — contact email: contact@impericorp.com

This policy explains what personal data the Neva Bible application (the “App”) collects, why, where it is stored and what rights you have as a user. The policy complies with the General Data Protection Regulation (Regulation (EU) 2016/679, the “GDPR”) and applicable Romanian legislation.


1. What data we collect

1.1 Account data (mandatory)

  • Email address: for authentication, password recovery and, if you buy a subscription, the purchase confirmation email (§1.3).
  • Password (stored encrypted): never in plain text — Supabase uses bcrypt hashing.
  • Display name (optional): only if you choose to fill it in when creating your account.
  • The data received from Google (when you sign in with “Continue with Google”): the unique identifier of your Google account, your email address, your name and the address (URL) of your profile photo. Google sends them at sign-in, and Supabase saves them automatically in your account record (see §3.5). The App does not display or use the profile photo.
  • Date of birth: requested when you create your account, in order to verify the minimum age of 16 (see §7). We keep it in your account exclusively for that purpose.
  • Proof of consent for religious data: we keep proof of your consent: the moment, the version of the text you accepted, the language it was shown to you in and a few technical details of the request (the device type and a code derived from the IP address); the details are in §2.1. Consent is not asked for when you create your account, but the first time you use a feature that needs it (§2.1); if you withdraw it, we also keep proof of the withdrawal (§2.1).
  • Sign-in sessions: for each device on which you are signed in, the authentication service keeps the IP address, the application/device type (user agent) and the times of sign-in; sign-ins, sign-outs and password changes are also entered in an audit log (see §3.1).
  • Accounts whose registration was not completed: an account whose registration was not completed — no date of birth was ever saved — is deleted automatically, together with all its data, 7 days after it was created. This happens, for example, if you sign in with “Continue with Google” and do not get past the “One more step” screen, where we ask for your date of birth, including if registration was stopped there because you are not yet 16 (§4, §7): your account is created at the moment you sign in with Google, before that screen, with the data received from Google (§3.5). An account whose registration was completed (the date of birth is saved) is not deleted because you have not given your consent for religious data (§2.1). Nor is an account deleted automatically if a Google Play purchase, a subscription record or a consent record is linked to it.
  • Email sign-ups that were never confirmed: if you create your account with an email address and a password and do not confirm the address (you do not enter the code received by email), the account is deleted automatically, together with all its data, 7 days after it was created or, if a new code was sent to you in the meantime, 7 days after the last code was sent (§4). You can then register again with the same address. This does not delete accounts linked to Google, accounts that have ever been signed in to, or accounts to which a Google Play purchase or a subscription record is linked.

1.2 Usage data

  • AI conversations: the conversation with the assistant, including the 5 free questions a day, works only after you give your consent for religious data (§2.1); until then the chat input is disabled. Your questions are sent to our servers, processed by OpenAI models (see §3), and the answers are displayed to you. So that the assistant understands a question that follows on from the discussion, together with each question we also send at most the last 3 exchanges (question and answer) of the current conversation, from the last 6 hours, shortened (§3.3). A message in which the App recognises signs of a crisis (for example, suicidal thoughts) receives a fixed reply with the emergency numbers. The text of a message recognised as a sign of crisis is not sent to OpenAI, either then or in the history of later questions; the server only tells the assistant that such a message existed in the conversation. The conversation history is stored locally on your phone (AsyncStorage) and can be deleted at any time from the chat interface. We do not keep a copy of your conversations in our database — with a single exception, the one below.
  • The answers you choose to report: every assistant answer can be reported (long-press the answer → “Report this answer”), a mechanism required by Google Play’s policy on AI-generated content. Reporting works only with your consent for religious data (§2.1). When you send a report, we upload to our Supabase database your question and the answer you received, in full, together with the reason you selected, the free-text note you write (if you write one), the conversation mode and your user identifier. If you do not report anything, nothing from the conversation goes there. Reports are read by the operator in order to correct the assistant’s behaviour.
  • The daily reflections you choose to report (Pro): the daily reflection — a short meditation on the day’s verse, which our server generates with OpenAI models (§3.3) — can be reported through the same mechanism (the “Report this reflection” link under the reflection). When you send a report, we upload to the same table of our Supabase database (chat_reports, with the mode reflection) the reference and text of the verse of the day and the text of the reflection, in full, together with the reason you selected, the day and verse the reflection belongs to, and your user identifier. Reports about the reflection are read by the operator in order to correct the instructions the reflection is written with, and are kept in the same way as reports about answers (§4).
  • Narration (Pro): when you tap “Listen” on a prayer, on the synaxarion of the day or on an answer from the assistant, the text is sent to our server and converted to audio by OpenAI (§3.3). Narration works only with your consent for religious data (§2.1). The audio of prayers and of the synaxarion — public texts of the Church, the same for every user — is kept in a shared cache so that it starts instantly. The audio of an assistant’s answer is never stored on our servers: it reaches only your phone, as a temporary file that the App deletes automatically as soon as playback ends or fails (while playback is paused, the file is kept so that you can resume it). A file left behind because the App was closed before then is deleted the next time the App starts, or earlier if you sign out or delete your account. Narration has a limit of 30,000 characters of narrated text per day.
  • Usage counters: in order to enforce the limit of 5 free questions per day (or 200 for Pro subscribers), we record, for each day, how many questions you asked — only the number, not the content. The limit resets daily at midnight (Romanian time); the records of past days remain in your account until your account is deleted. For the daily narration limit and for the daily reflection we keep separate counters (the number of narrated characters and of generated reflections), which are deleted automatically after 35 days.

1.3 Subscription data

  • Subscription status: tier (Free / Pro monthly / Pro annual), expiry date, renewal status.
  • Purchase data from Google Play: the purchase token, the plan, the status and the expiry date of the subscription — to validate purchases, restore them on another device and apply refunds. We receive no card details (§3.2, §4).
  • The purchase confirmation email: after you buy a subscription, we send a confirmation email to the email address of your Neva Bible account (§3.6) and keep a record that it was sent (§4).

1.4 Data generated in the App (on your phone and, for Pro subscribers, in the cloud)

As you use the App, it generates:

  • Bookmarks on Bible verses
  • Favourite prayers
  • Prayer lists (pomelnice) — lists of the names of the living and of those who have fallen asleep (see §1.6)
  • AI conversation history
  • Reading plan progress and progress on your personal prayer rule
  • Name days you follow — the people for whom you receive name-day notifications (see §1.6)
  • Device preferences: notifications (time, type, on/off), theme, text size, interface language

All of these are written first to your phone (AsyncStorage), and the App works offline on the basis of them.

Cloud synchronisation (Pro subscribers only). If you have an active Pro subscription, three of the categories above are also copied automatically to your account in our Supabase database (Frankfurt — see §3.1), so that you find them again after a reinstall or on another phone:

What is synchronised Exactly what it contains When
Verse bookmarks the book, the chapter, the verse, the Bible version (Anania or World English Bible), the date saved on every addition or deletion and on every sign-in
Favourite prayers the prayer identifier, the date saved on every addition or deletion and on every sign-in
Prayer lists (pomelnice) the title, the type (for the living / for the departed), the list of names, the creation and modification dates on every creation, change or deletion and on every sign-in

Synchronisation is not a separate switch that you turn on or off: it works automatically while you have an active Pro subscription and your consent for religious data (§2.1), and it stops automatically when the subscription is no longer active, when you sign out or when you do not have (or no longer have) that consent — you resume it by giving your consent when the App asks for it (for example, in the conversation with the assistant, §2.1). When you delete an item on your phone, we delete it from the cloud as well. Data uploaded while the subscription was active remains in your account until you delete it yourself, until you withdraw your consent for religious data — withdrawal deletes it from our server, and it stays on your phone (§2.1) — or until you delete your account (§5.3).

What is NEVER synchronised — it stays exclusively on your phone: your AI conversation history (except for the answers you yourself report — see §1.2), reading plan progress, the personal prayer rule, the name days you follow and device preferences. If you uninstall the App, these are lost permanently. The App does not let Android copy this data into your Google account backup, so reinstalling the App does not bring it back.

If you are on the Free plan, nothing in §1.4 leaves your phone.

1.5 Data we do NOT collect

  • We do not collect your phone’s location (GPS or precise location), and the App does not ask for the location permission. The only location-type information is the approximate country and city that Sentry may derive from the IP address an error or performance report comes from (§3.7).
  • We do not collect contacts.
  • We do not collect photos or other files from your phone.
  • We do not use tracking cookies, advertising identifiers or similar technologies to track you. The App uses only technical identifiers: the random installation identifier sent to Expo when it checks for updates (§3.8), and the identifiers in error reports (§3.7).
  • We do not use Google Analytics, Facebook Pixel or other behavioural analytics services. (We use Sentry only for reporting technical errors and performance problems — see §3.7 — not for behavioural analysis.)
  • We do not sell personal data to any third party.

1.6 Data about other people (prayer lists and name days)

Two features of the App let you write down the names of other people — people who do not use Neva Bible, have no account with us and have not accepted this policy:

  • Prayer lists (pomelnice): lists of the names of the living and of those who have fallen asleep, which you prepare for commemoration at church. Each list has a title you choose, a type (for the living / for the departed) and the list of names.
  • Name days: the people you follow so as to be reminded on their name day — a display name you choose, the associated saint and date and, optionally, the family relationship (“mother”, “godfather”, etc.).

What you need to know about this data:

  • You enter it, manually. The App has no access to your phone’s address book and never imports contacts (see §1.5). Nothing reaches these lists unless you write it there.
  • It is personal data of those people, not yours. In a context of liturgical commemoration, a name can reveal the religious affiliation of the person named, and therefore falls under Art. 9 GDPR (see §2.1); a name in a prayer list “for those who have fallen asleep” additionally shows that the person has died.
  • Where it goes. Name days always stay only on your phone. Prayer lists stay on the phone if you are on the Free plan; if you have a Pro subscription, they are synchronised to your account in Supabase together with the names they contain (§1.4). Row-level security policies (§6) mean that only your account can read them.
  • We do not use it for any other purpose. We do not analyse it, we do not build profiles from it, we do not correlate it between users, we do not send it to OpenAI and we do not sell it.
  • Personal use and your responsibility. You enter these names on your own initiative, for strictly personal use (prayer and commemoration). Write only what is of use to you — as a rule, the given name. If a person mentioned in one of your prayer lists asks us to delete their data, they may write to the contact address and we will examine the request; in practice, the fastest deletion is the one you carry out yourself, directly in the App, and deleting your account removes them all (§5.3).
  • Name-day notifications display the person’s name on your phone’s screen. When you sign out, the App cancels these notifications. The lists stay on the phone and are shown again only when you sign back in with the same account. If a different account signs in on that phone, the App first deletes your lists from the device, so that person does not see the names of your relatives.

2. Why we collect this data (legal basis)

Data category Purpose Legal basis (Art. 6 GDPR)
Account (email, password, name) Authentication and account security Performance of the contract (art. 6.1.b)
AI conversations and narration (§1.2) Providing the answers and the audio you request Performance of the contract (art. 6.1.b)
Usage counters (§1.2) Enforcing the contractual usage limits Performance of the contract (art. 6.1.b)
Subscription status Granting access to Pro features Performance of the contract (art. 6.1.b)
The purchase confirmation email and the record that it was sent (§1.3) Confirming the contract on a durable medium, with the information on the right of withdrawal Legal obligation (art. 6.1.c)
Data generated in the App (§1.4: bookmarks, favourites, prayer lists, reading plans, name days) App functionality and, for Pro subscribers, synchronisation between devices Performance of the contract (art. 6.1.b)
Reports about AI answers and about the daily reflection (§1.2) Safety of the service and compliance with Google Play’s policy on AI-generated content Legitimate interest (art. 6.1.f)
Records of refunded or replaced purchases, refund and notification logs (§4) Preventing a refunded or replaced subscription from being activated again; applying refunds correctly Legitimate interest (art. 6.1.f)
Date of birth (§1.1) Verification of the minimum age of 16 (§7) Legal obligation (art. 6.1.c)
Proof of consent and of its withdrawal (§1.1) Demonstrating the consent given for religious data and its withdrawal Legal obligation (art. 6.1.c, read together with art. 7(1))
Sign-in sessions, the authentication audit log and the Supabase server logs (§3.1); limiting the number of requests at Cloudflare (§3.4) Security of the account and of the service, debugging, abuse diagnostics Legitimate interest (art. 6.1.f)
Error reports and performance data (Sentry, §3.7) Finding and fixing errors Legitimate interest (art. 6.1.f)
Update checks (Expo, §3.8) Delivering fixes and security updates to the App Legitimate interest (art. 6.1.f)

2.1 Special categories of data — religious data (Art. 9 GDPR)

Neva Bible is a religious application. By its very nature, part of the data we process reveals your religious beliefs and therefore falls within the special categories of data provided for by Art. 9 GDPR:

  • the questions you put to the AI assistant and the answers you receive (including those you choose to report, §1.2);
  • the prayers marked as favourites, your personal prayer rule and your reading plan progress;
  • your bookmarks on Bible verses;
  • your prayer lists (pomelnice) and the names entered in them — which also concern the beliefs of other people (§1.6);
  • the name days you follow;
  • the details about your health that you choose to write in questions (health is also a special category of data, Art. 9 GDPR).

While they stay only on your phone, favourite prayers, the prayer rule, reading plan progress, bookmarks, prayer lists and name days do not reach us (§1.4); they reach our server only through Pro synchronisation, which works only with your consent.

The legal basis for this data is your explicit consent, within the meaning of Art. 9(2)(a) GDPR, which is additional to the contractual basis in the table above.

When we ask for your consent. Not when you create your account. Once you are signed in and we have checked your date of birth (§7), the Bible, prayers and calendar work without consent. We ask for it the first time you open one of the features that need it: the conversation with the assistant (including the 5 free questions a day), prayers read aloud (narration, §1.2), cloud synchronisation (Pro, §1.4) and reporting an answer or the daily reflection (§1.2). If you gave your consent to an earlier version of the text — for example, when you created your account, in an older version of the App — we ask for it again, with the text below, the next time you use one of these features; until then, for Pro subscribers, synchronisation is paused (§1.4). Consent is given by ticking a dedicated box, separate from acceptance of the Terms and Conditions. The text of the box is:

“I agree that Neva Bible may process what I write.”

Next to the box, the “Details” link opens the text below, which shows what the consent covers — the categories of data (religious beliefs and, if you choose to write them, health details), the purposes and the recipients:

What your consent covers:

• What you write in questions goes to our server and to OpenAI so you can get an answer. It can reveal your religious beliefs and, if you choose to write them, details about your health.

• Messages that look like a sign of crisis are not sent to OpenAI; you get the helpline numbers straight away.

• With your consent you can also use: prayers read aloud, syncing bookmarks, favourite prayers and prayer lists (Pro), and reporting an answer.

• The Bible, prayers and calendar work without consent.

• You can withdraw your consent at any time by writing to contact@impericorp.com. Synced data is deleted from our server and stays on your phone. Your subscription is not cancelled automatically.

All the details are in the Privacy Policy.

Each consent is recorded in a consent register (§1.1), so that we can prove when and for what you gave your agreement.

If you do not give your consent, the features above do not start, and the rest of the App works as before. The chat input stays disabled.

You may withdraw your consent at any time, by email, without deleting your account: write to contact@impericorp.com from the email address of your Neva Bible account (this is how we confirm that you are the account holder; if you no longer have access to it, write to us from another address and mention the account address, and we will contact you to check that you are the account holder). After we receive your email, without undue delay and within one month at most (§5.7), we record the withdrawal in the consent register, delete the cloud-synchronised copies from our server and stop the features that need the consent, then reply to you by email. Withdrawal does not affect the lawfulness of the processing carried out up to that moment. You can give your consent again at any time, in the App, when it asks for it (for example, in the conversation with the assistant). When you withdraw your consent:

  • the conversation with the assistant, narration, reporting answers and the daily reflection, and cloud synchronisation stop; the Bible, prayers and calendar keep working;
  • the cloud copies of your synchronised bookmarks, favourite prayers and prayer lists (§1.4) are deleted from our server; they stay on your phone;
  • what you have already sent to OpenAI is deleted there after at most 30 days, with the exceptions in §3.3;
  • the reports you have already sent us (§1.2) remain until your account is deleted (§4), because each one shows a concrete problem with the assistant that we must be able to check and correct (§2); if you want us to delete them sooner, write to us (§5.7) or delete your account (§5.3);
  • the proof of consent remains in the consent register until your account is deleted (§4), together with the withdrawal, which is recorded in the same way as a consent, so that we can show when you gave your agreement and when you withdrew it (Art. 7(1) GDPR);
  • the Google Play subscription is not cancelled automatically: if you no longer want to pay, cancel it in Google Play → Payments and subscriptions → Subscriptions → Neva Bible → Cancel subscription. The right of withdrawal from the Pro contract and refunds remain as described in Neva Bible’s Terms and Conditions.

This data is not analysed, profiled, correlated between users or used for any purpose other than providing the features described here. We do not ask you for health data or other special categories of data (political opinions, sexual orientation, biometric data, etc.). If you nevertheless choose to write such information in a question (for example, about an illness), your consent covers it and it is processed like the rest of the question, including by OpenAI (§3.3), except for messages recognised as a sign of crisis (§1.2).

How we keep proof of your consent. The proof is kept in two places. In your account: the date and time at which you gave your consent, according to your phone’s clock, the version of the text you accepted and the language it was shown to you in (Romanian or English); if you withdraw it, the date and time at which we recorded the withdrawal. In the consent register, filled in by our server: the type (consent or withdrawal) and the version — for a consent, the version also shows the language the text was shown to you in (for example, “2026-09-19.en” for the English text) —, the date and time at which the server received the record from the App, a pseudonymised code (SHA-256) derived from the IP address that request came from and your account identifier — the IP address can be reconstructed from it, so we treat it as personal data — and the application/device type (user agent) sent with the request. The App sends the record of a consent at the moment you give it; if the server does not receive it (for example, because the phone has no internet connection), the consent is not treated as given, and the features stay off until you try again and it succeeds. We record a withdrawal received by email in the register ourselves, with the date and time of recording, without a code derived from an IP address and with a note that it was received by email. These are kept as proof of the consent and of its withdrawal, as required by Art. 7(1) GDPR.


3. Where the data is stored (third parties)

3.1 Supabase (auth + database)

  • Location: Frankfurt, Germany (eu-central-1 region).
  • Data stored: the account (email, encrypted password, display name, date of birth and, if you signed in with Google, the data received from Google — §3.5), subscription status and the records of your Google Play purchases (§1.3), the records of the purchase confirmation emails sent (§1.3, §4), the daily usage counter, the consent register (§1.1), the reports you send about AI answers and about the daily reflection (§1.2) and — for Pro subscribers only — verse bookmarks, favourite prayers and prayer lists (§1.4). Also stored there, without any link to an account: records of refunded or replaced purchases and the refund and notification logs (§4), and an audio cache of the narrated prayers and synaxarion, which contains no user data (§1.2).
  • Sign-in sessions: for each session (each device on which you are signed in), Supabase Auth keeps the IP address and the application/device type (user agent) from which you signed in, the times at which the session was created and last refreshed, and the refresh token. A session’s record is deleted when you sign out of the App while connected to the internet and, in any case, when your account is deleted.
  • Authentication audit log: Supabase Auth enters authentication events in a log — account creation, sign-ins, sign-outs, session refreshes, password reset requests and password changes, account deletion — with the time, the IP address, the application/device type, the account identifier and the account’s email address. Entries older than 90 days are deleted automatically.
  • Server logs: Supabase automatically records the requests the App sends directly to Supabase (sign-in, reading your profile, Pro synchronisation) in technical logs that may contain the IP address, the application/device type, the time, the response code and the address of the request (which may include, for example, the reference of a synchronised bookmark), without the content of the data sent. These logs are kept by Supabase for a maximum of 7 days, then deleted automatically.
  • Backups: our Supabase project is on the free plan (Free), which, according to Supabase’s documentation, does not include automatic database backups — these are offered only on the paid plans. There are therefore no backups that we can access and from which deleted data could be restored. Supabase’s documentation does not describe any other copies that Supabase might keep internally on the free plan; if any exist, we cannot access them. If we move to a paid plan, deleted data will be able to remain in its daily backups for at most 7 days, and this policy will be updated before that.
  • Site: https://supabase.com/privacy
  • Data Processing Agreement (DPA): concluded in accordance with Art. 28 GDPR.

3.2 Google Play (subscription management and payments)

  • Location: Google’s global infrastructure, including the United States (with standard contractual clauses for international transfers, in accordance with Art. 46 GDPR).
  • Data sent: your unique Supabase identifier (transmitted as obfuscatedAccountId at the moment of purchase, so that the subscription can be linked to your account), the purchase token, subscription transaction history, renewal status and refund status.
  • Payment: Google Play is the merchant of record. Your card details are collected and processed directly by Google — the App never sees or stores them.
  • Site: https://policies.google.com/privacy

3.3 OpenAI (processing AI questions)

  • Provider: OpenAI Ireland Ltd, Dublin, Ireland, which processes this data on our behalf under OpenAI’s data processing addendum (DPA). Our OpenAI API account belongs to IMPERICORP X SRL, which has its registered office in Romania, and for customers in the European Economic Area OpenAI’s services agreement and DPA are concluded with OpenAI Ireland Ltd.
  • Transfer outside the European Economic Area: under the DPA, OpenAI Ireland Ltd may transfer the data to other OpenAI group companies and to sub-processors outside the European Economic Area, on the basis of the European Commission’s standard contractual clauses (art. 46 GDPR). OpenAI’s sub-processor list names the group companies that support the API, among them OpenAI OpCo, LLC and OpenAI, LLC, in the United States, and states that the standard contractual clauses are used between them. The data sent to OpenAI may therefore also be processed in the United States.
  • Data sent: the text of your question (also used to search for the relevant verses), the relevant verses retrieved from the App’s biblical corpus (the Anania Bible for Romanian, the World English Bible for English) and, so that the assistant understands a question that follows on from the discussion, at most the last 3 exchanges (question and answer) of the current conversation, from the last 6 hours, shortened: at most 500 characters of a question, 1,200 of an answer and 5,000 in total. A message recognised as a sign of crisis receives a fixed reply, without OpenAI (§1.2). The text of a message recognised as a sign of crisis is not sent to OpenAI, either then or in the history of later questions; the server only tells the assistant that such a message existed in the conversation. If you use narration (Pro), we also send the text you asked to hear — a prayer, the synaxarion of the day or an answer from the assistant. We do NOT send your email address, your ID or other information that directly identifies you; the text you write, however, reaches OpenAI as you wrote it, including any information about yourself that you choose to include.
  • Retention: in accordance with OpenAI’s API policies: data sent through the API is NOT used to train the models; it is kept for a maximum of 30 days in abuse-monitoring logs, then deleted, unless the law requires it to be kept longer or keeping it is reasonably necessary to protect OpenAI’s services or other people from harm. We do not use the API features that store conversations at OpenAI.
  • Site: https://openai.com/policies/privacy-policy; data processing addendum: https://openai.com/policies/data-processing-addendum; sub-processor list: https://openai.com/policies/sub-processor-list

3.4 Cloudflare (backend server)

  • Provider: Cloudflare, Inc., United States, which processes the data described below on our behalf, as a processor (except for the processing for its own purposes at the end of this section).
  • Location: the Cloudflare global network. Each request is processed in the Cloudflare location that receives it — usually the one nearest to you, but not necessarily in the EU.
  • Transfer outside the EU: Cloudflare’s data processing addendum, part of the terms of our Cloudflare account, includes the European Commission’s standard contractual clauses (art. 46 GDPR).
  • EU-U.S. Data Privacy Framework: Cloudflare, Inc. appears on the official list of active participants in the EU-U.S. Data Privacy Framework (https://www.dataprivacyframework.gov/participant/5666, checked on 19 September 2026), so the transfer to Cloudflare, Inc. in the United States can also rely on the European Commission’s adequacy decision (art. 45 GDPR); for the other locations outside the EU the standard contractual clauses above apply.
  • Data processed: our server’s code runs on the Cloudflare network. Each request the App sends to the server — with its content (for example, a question for the assistant), your phone’s IP address, the application/device type (user agent) and the other technical data of the request — is processed by Cloudflare while it is transmitted and handled, so that it reaches the server and the service is protected against abuse.
  • Limiting the number of requests: to stop excessive repeated requests, the server counts requests over one-minute intervals. The key of the counter is your account identifier and, for the sign-in verifications the server asks Supabase to carry out, the IP address the request comes from. The counters are kept by Cloudflare, in the network location that received the request. A counter covers only the current one-minute window and contains nothing of the content of the request; Cloudflare does not publish how long it keeps these counters internally.
  • Data stored: our server stores no request logs. Cloudflare’s logs for the server (Workers Logs) are switched off, so Cloudflare keeps no logs of your requests or of your IP address for us. Apart from the counters above, the server saves no data about you at Cloudflare: what has to be kept goes to the Supabase database (§3.1), and the server’s error reports go to Sentry (§3.7). Cloudflare shows us only aggregate statistics about how the server is running (for example, the number of requests and errors and the processing time), which do not identify users. When we investigate a problem, we can follow in real time the requests reaching the server and its technical messages, which may include the IP address; this live view saves nothing.
  • Processing by Cloudflare for its own purposes: for the security of its network, Cloudflare, Inc. processes information about traffic (for example, IP addresses) as an independent controller, under its own privacy policy (link below), in order to identify and block malicious activity on its network.
  • Site: https://www.cloudflare.com/privacypolicy

3.5 Google (optional sign-in)

  • If you sign in with “Continue with Google”, Google sends us the basic information of your Google profile: the identifier of your Google account, your email address, your name and the address (URL) of your profile photo. Supabase saves them in your account record (§3.1), where they remain until your account is deleted. The App does not display or use the profile photo. We never receive your Google password.
  • Google’s policy: https://policies.google.com/privacy

3.6 Resend (account confirmation, password reset and purchase confirmation emails)

  • Provider: Plus Five Five, Inc. (“Resend”), United States, which processes this data on our behalf.
  • Purpose: sending the account confirmation and password reset emails, which the Supabase authentication service (§3.1) sends through Resend, and the purchase confirmation emails, which our server sends (§3.4).
  • Data transmitted: your email address and the content of the email.
  • The purchase confirmation email: after you buy a Pro subscription, our server sends you, through Resend, to the email address of your Neva Bible account, an email containing the Google Play order number, the plan, the purchase date and the renewal price, if Google Play gives them to us, our contact details, the information on automatic renewal and on the right of withdrawal and the model withdrawal form from the Neva Bible Terms of Service (sections 5.3, 5.4 and 5.4.1 of the Terms), and the links to the Terms and to this policy. The email can be sent only if the account has a valid email address. The record that it was sent, without the email address and without the content of the email, is kept in our database (§3.1, §4).
  • Location and retention: the emails and their delivery logs are stored in the United States and are deleted after 30 days; they disappear from Resend’s backups within at most a further 7 days.
  • Transfer to the United States: on the basis of the European Commission’s standard contractual clauses included in Resend’s data processing addendum (art. 46 GDPR).
  • EU-U.S. Data Privacy Framework: Plus Five Five, Inc. (Resend) appears on the official list of active participants in the EU-U.S. Data Privacy Framework (https://www.dataprivacyframework.gov/participant/8907, checked on 19 September 2026), so the transfer can also rely on the European Commission’s adequacy decision (art. 45 GDPR).
  • Site: https://resend.com/legal/privacy-policy

3.7 Sentry (error reporting and diagnostics)

  • Provider: Functional Software, Inc. (“Sentry”), United States, which processes this data on our behalf.
  • Location: European Union (the de.sentry.io region — Frankfurt).
  • EU-U.S. Data Privacy Framework: the data is stored in the EU; to the extent that Sentry accesses it from the United States, Functional Software, Inc. appears on the official list of active participants in the EU-U.S. Data Privacy Framework (https://www.dataprivacyframework.gov/participant/5869, checked on 19 September 2026), so the transfer can rely on the European Commission’s adequacy decision (art. 45 GDPR).
  • Purpose: when the App or our server encounters an error, or the App closes unexpectedly, a technical report is sent automatically so that we can fix the problem. The App also sends stability and performance data: for each use of the App, a session (its start, its duration and whether it ended normally or with an error); for about 5% of operations — and for all chat, subscription and sign-in operations — measurements of how long they took; and for about 10% of the measured operations, a technical profile of the code’s execution.
  • Data collected: the device model and operating system, the App version, technical data about the device and the App (for example available memory, language and time zone), your user identifier (UUID — not the email address), a random technical installation identifier, the technical stack trace of the error and the last technical steps before it: the screens opened, technical messages from the App and the addresses of the network requests made by the App, without the part after the “?” (the request parameters), so the verse references of bookmarks do not reach Sentry. For server errors: the address of the request, also without parameters, the application/device type (user agent) and Cloudflare’s technical identifier of the request.
  • IP address: not stored. Neither the App nor our server includes it in reports, and our Sentry project is set not to store the IP address a report comes from. On receiving a report, Sentry may derive from that address the approximate country and city, which remain in the report.
  • Screen recording (“Session Replay”): not used in the published version of the App.
  • What does NOT reach Sentry: the content of your AI conversations, passwords, the text of prayers and the names in prayer lists and name days.
  • Retention: we use Sentry’s Developer plan, on which error reports, performance measurements and profiles are deleted automatically after 30 days. Sentry regularly makes backups of the data and deletes each backup 90 days after it was created, so a report that has already been deleted may remain in a Sentry backup until 90 days after that backup was created.
  • Site: https://sentry.io/privacy/

3.8 Expo (App updates — EAS Update)

  • Provider: 650 Industries, Inc. (“Expo”), United States, which processes this data on our behalf.
  • Purpose: every time it starts, the App asks Expo’s update server whether there is a new version of its code (for example, a fix) and, if there is, downloads it. This lets us fix errors without you waiting for an update from Google Play.
  • Data Expo receives on every check: the phone’s IP address; a random installation identifier (EAS Client ID), generated on the phone the first time it is needed — it is not derived from the phone’s hardware or from your account, stays the same across launches and updates, and changes only if you reinstall the App or clear its data; the platform (Android), the App’s technical version, the update channel and the identifiers of the updates already installed; the technical values that Expo’s server sent to the App earlier and asks it to send back (for example, for the gradual rollout of an update); and, only if the previous launch of the App failed, a short technical message about that error. We do not send Expo your email address, your account identifier or your content.
  • Legal basis: our legitimate interest in delivering fixes and security updates promptly (art. 6(1)(f) GDPR).
  • Transfer to the United States: 650 Industries, Inc. (Expo) appears on the official list of active participants in the EU-U.S. Data Privacy Framework (https://www.dataprivacyframework.gov/participant/5606, checked on 19 September 2026), so the transfer relies on the European Commission’s adequacy decision (art. 45 GDPR), and Expo’s terms include the European Commission’s standard contractual clauses for transfers to a processor (art. 46 GDPR).
  • Retention: in accordance with Expo’s privacy policy.
  • Site: https://expo.dev/privacy

4. How long we keep the data

Data Retention period
Active account For the entire duration of your use of the App
Account after deletion Deleted immediately from our database (automatic cascade); for backups, see the next row; the other data that remains after deletion, and for how long, is listed in §5.3
Database backups (Supabase, §3.1) The Supabase plan we use (Free) does not include automatic backups, so deleted data does not remain in any backups that we can access; if we move to a paid plan, it will be able to remain in the daily backups for at most 7 days (§3.1)
Account whose registration was not completed — no date of birth saved, for example a Google sign-in stopped at the “One more step” screen (§1.1) Deleted automatically, together with all its data, 7 days after it was created. An account whose registration was completed is not deleted for not having given the consent for religious data
Account created with an email address that was never confirmed (§1.1) Deleted automatically, together with all its data, 7 days after it was created or after the last confirmation code was sent, if that is more recent
Accounts and their data, if we discontinue Neva Bible (§4.1) Deleted 90 days after the discontinuation date
The data received from Google at sign-in (§3.5) Until your account is deleted
Sign-in sessions (IP address, application/device type, times of sign-in — §3.1) Until you sign out on that device or until your account is deleted
Authentication audit log (§3.1) Entries older than 90 days are deleted automatically; those about a deleted account remain until the 90 days have passed
Supabase server logs (§3.1) A maximum of 7 days
Daily question counter (§1.2) Until your account is deleted
Daily counters for narration and reflection (§1.2) Deleted automatically after 35 days
Subscription payment transactions Kept by Google Play, which is the seller (merchant of record), under Google’s own policies. Our servers keep no record of your payments
Your Google Play purchase records (§1.3) Until your account is deleted — deleted in cascade together with it
Records of the purchase confirmation emails (the number of the subscription’s first Google Play order, the account identifier, the plan bought, the language of the email, the sending status and the number of attempts, the times of the attempt and of sending, the message identifier at Resend and a short error code — without the email address and without the content of the email; §1.3, §3.6) Until your account is deleted — deleted in cascade together with it
Tokens of refunded or replaced Google Play purchases — without any link to your account No fixed term: they are kept so that a refunded or replaced subscription cannot be activated again, including from a new account. They contain no email address, name or user identifier
Log of processed refunds (order number, purchase token, refund date, reason and source codes) — without any link to your account Deleted automatically 90 days after processing
Log of Google Play notifications (notification identifier, type, purchase token) — without any link to your account Deleted automatically after 90 days
AI conversations and narrated texts, at OpenAI A maximum of 30 days at OpenAI, then deleted automatically, with the exceptions in §3.3 (legal obligations, protection against abuse)
Audio of prayers and of the synaxarion Kept in a shared cache with no fixed term; it contains no user data
Audio of an assistant’s answer Not stored on our servers; the temporary file on your phone is deleted automatically when playback ends or, at the latest, the next time the App starts (§1.2)
Synchronised bookmarks, favourite prayers and prayer lists (Pro) Until you delete them yourself in the App, until you withdraw your consent for religious data (§2.1) — they stay on your phone — or until your account is deleted
Reports about AI answers and about the daily reflection (§1.2) Until your account is deleted — they are deleted in cascade together with it; they also remain after you withdraw your consent (§2.1)
Consent register (§1.1) Until your account is deleted — it is deleted in cascade together with it; it also keeps the withdrawals of consent (§2.1)
Error reports (Sentry, §3.7) Deleted automatically after 30 days (Sentry’s Developer plan); from Sentry’s backups, 90 days after the backup was created
Performance measurements and profiles (Sentry, §3.7) Deleted automatically after 30 days (Sentry’s Developer plan); from Sentry’s backups, 90 days after the backup was created
Request logs at Cloudflare (§3.4) Not stored: Cloudflare’s logs for our server are switched off
Rate-limit counters at Cloudflare (§3.4) A counter covers only the current one-minute window and contains nothing of the content of the request; Cloudflare does not publish how long it keeps these counters internally
Account confirmation, password reset and purchase confirmation emails and their delivery logs, at Resend (§3.6) Deleted after 30 days; from Resend’s backups, within at most a further 7 days
The data Expo receives when checking for updates (§3.8) In accordance with Expo’s policy

4.1 Data after Neva Bible is discontinued

If we permanently stop providing Neva Bible, accounts and all the data linked to them are deleted 90 days after the discontinuation date — the same data that is deleted when you delete your account yourself (§5.3). Until the discontinuation date you can delete your account in the App at any time (§5.3), and during the 90 days that follow you can still exercise your rights by writing to us (§5.7). During these 90 days the data is only stored, so that we can answer your requests (§5) and complete refunds; we no longer use it for any other purpose.

The copies on your phone (§1.4) are not on our servers, so we cannot delete them remotely; they are deleted when you uninstall the App.

After the 90 days, only the following may remain:

  • At Google Play: the payment transaction data — Google Play is the seller — kept under Google’s policies (§3.2).
  • With us: the records the law requires us to keep (for example, accounting records), only for as long as and to the extent that the law requires.
  • At OpenAI: conversations and narrated texts, only in the exceptional cases in §3.3.
  • At Sentry: the error reports and performance data already sent, until they are deleted automatically, after 30 days, and from Sentry’s backups, 90 days after the backup was created (§3.7).
  • At Resend: the emails already sent and their delivery logs, until they are deleted, after 30 days (§3.6).
  • At Expo: the data received when checking for updates, in accordance with Expo’s policy (§3.8).
  • Records not linked to any account (§4), for example the tokens of refunded or replaced purchases, for the periods set out in §4.

5. Your rights (GDPR)

You have the following rights in relation to your personal data:

5.1 Right of access (Art. 15)

You may request a copy of all the data we hold about you. We respond within one month at most (§5.7).

5.2 Right to rectification (Art. 16)

The App has no screen for editing account data: your email address, display name and date of birth stay as entered when you created your account (Settings → ACCOUNT only displays your email address and name). To correct any of them, write to us and we will make the correction within one month at most (§5.7). You can change your password yourself from the sign-in screen → “Forgot your password?”. You can change or delete the content you create — prayer lists, bookmarks, favourite prayers, name days — directly in the App.

5.3 Right to erasure (the “right to be forgotten” — Art. 17)

You may delete your account directly from the app: Settings → DELETE ACCOUNT → “Delete account”. This triggers the immediate and complete deletion of the account (including the data received from Google and the sign-in sessions), profile, subscription and the records of your Google Play purchases, usage counters, bookmarks, favourite prayers and synchronised prayer lists, of the reports you have sent about AI answers and about the daily reflection, and of your consent register. At the same time, the App deletes the local copies from your phone as well (conversation history, bookmarks, favourite prayers, prayer lists, name days, reading plan progress, the prayer rule and any temporary audio file of a narrated answer) and cancels the name-day notifications. What remains after deletion:

  • At Google Play: the payment transaction data — Google Play is the seller — kept under Google’s policies, together with the account identifier attached to the purchase (§3.2).
  • In our database, only records that are not linked to your account: the tokens of refunded or replaced purchases, with no fixed term, and the refund and notification logs, which are deleted after 90 days (§4).
  • In the authentication audit log (Supabase): the entries about your account — including its deletion — with your email address and IP address, until they reach 90 days and are deleted automatically (§3.1).
  • In the Supabase server logs: recent requests, with the IP address, for a maximum of 7 days (§3.1).
  • In the database backups (Supabase): the Supabase plan we use does not include automatic backups, so no backups that we can access remain (§3.1, §4).
  • At Sentry: the error reports and performance data already sent, which contain your user identifier (not the IP address), until they are deleted automatically after 30 days, and from Sentry’s backups, 90 days after the backup was created (§3.7).
  • At Cloudflare: no log of your requests, because our server stores no logs (§3.4).
  • At OpenAI: your AI conversations and the texts you asked to hear, for a maximum of 30 days, with the exceptions in §3.3.
  • At Resend: the account confirmation, password reset or purchase confirmation emails already sent and their delivery logs, until they are deleted, after 30 days, and from Resend’s backups within at most a further 7 days (§3.6).
  • At Expo: the data received when checking for updates — the IP address and the random installation identifier, which are not linked to your account — in accordance with Expo’s policy (§3.8).

Deleting your account does not cancel a Google Play subscription — cancel it in Google Play first.

5.4 Right to restriction of processing (Art. 18)

You may request that we stop processing your data in a particular context (for example, during a dispute).

5.5 Right to data portability (Art. 20)

You may receive a copy of your data in a structured format (JSON) in order to use it elsewhere.

5.6 Right to object (Art. 21)

You may object to the processing of your data — although, for the basic operation of the account, objecting means ceasing to use the App. The consent for religious data is not part of this right: you withdraw it separately, without giving up the App (§5.9).

5.7 How to exercise your rights

Send an email to contact@impericorp.com. We respond without undue delay and within one month at most of receiving your request. For complex or numerous requests this period may be extended by up to two further months; in that case we tell you within the first month and explain why. To delete your account, use the option in the App directly — it is faster. You also withdraw your consent for religious data by email (§5.9).

5.8 Right to lodge a complaint

If you consider that your rights have been infringed, you may lodge a complaint with the National Supervisory Authority for Personal Data Processing (ANSPDCP), https://www.dataprotection.ro/.

5.9 Right to withdraw your consent (Art. 7(3))

You may withdraw your consent for religious data at any time, without deleting your account, by writing to contact@impericorp.com. We record the withdrawal, delete the synced copies from our server and stop the features that need the consent within one month at most of receiving your email (§5.7). You can give it again in the App. What stops, what is deleted from our server, what we keep and why is described in §2.1. Withdrawal does not cancel a Google Play subscription — cancel it in Google Play if you no longer want to pay.


6. Security

  • Passwords are encrypted (bcrypt) — never stored in plain text.
  • All communication between the App and our servers uses HTTPS / TLS 1.2+.
  • API keys and server secrets are stored encrypted and are accessible only to our code, not to users.
  • Our backend verifies every request by means of signed JWT tokens, so that no one can access another user’s data.
  • Row-Level Security (RLS) policies at the database level ensure that each user sees only their own data.

No system is perfect. If you suspect a security breach, let us know immediately.


7. Minors

Neva Bible is intended for users aged 16 and over. When you create your account we ask for your date of birth and we block registration if you have not turned 16; the date of birth is kept in your account exclusively in order to verify this limit (§1.1). An account already created when signing in with Google, whose registration was not completed (no date of birth was saved — including when registration was stopped because you are not yet 16), is deleted automatically 7 days after it was created, and an account created with an email address that was never confirmed, after 7 days (§1.1, §4).

The threshold is 16 and not 13 because the App processes data concerning religious beliefs on the basis of explicit consent (§2.1), and in Romania the age at which a minor may give consent on their own in relation to information society services is 16 (Art. 8 GDPR). Below that age, the verifiable consent of the legal guardian would be required, which we cannot reliably obtain within a mobile application — which is why we prefer a firm limit instead of a parental consent procedure.

If we are informed that we have collected data from a minor under 16, we delete the account and the associated data immediately. Parents or legal guardians may request this deletion by writing to the contact address.


8. Changes to this policy

We may update this policy as the App evolves. We tell you by email about significant changes before they come into force. If a change would extend the purposes for which you gave your consent for religious data, we will not process that data for the new purpose without a new consent.

The current version is always available at https://impericorp.com/neva/privacy and in Settings → About → Privacy policy.


9. Contact

For any question relating to this policy or to the processing of your data:

  • Email: contact@impericorp.com
  • Postal address: IMPERICORP X SRL, Str. Valea Lui Mihai nr. 3, Bl. TD14, Et. 10, Ap. 64, Sector 6, București, postal code 061751

We respond within one month at most (§5.7).


This document was drafted in order to comply with the GDPR and Romanian legislation. For specific legal clarifications, consult a lawyer specialising in data protection.

This document is the English version of Neva Bible’s privacy policy. The Romanian version is available at https://impericorp.com/neva/confidentialitate.