JCBSNThe JCBSN Brand
Back

Scripture First

Privacy Policy

Last updated · May 9, 2026

This Privacy Policy describes how JCBSN Brand (“we,” “us,” or “our”) handles information when you use the Scripture First mobile application for iOS (the “App”). It reflects how the App is built as of the date above. The App is intended for users 13 years of age or older, and may also be installed on a child’s device with a parent or guardian configuring it. This policy is not legal advice; if you need advice for your situation, consult a qualified attorney.

Apple Family Controls and Screen Time

Scripture First is built on Apple’s Family Controls, Managed Settings, and Device Activity frameworks. These are the same system frameworks Apple provides for Screen Time. To use the App, you (or, for a child Apple ID, a parent or guardian using their Screen Time passcode) must grant Family Controls authorization.

  • App selections stay opaque to us: When you pick the apps, app categories, or web domains you want to lock, iOS returns those selections to the App as encrypted, opaque tokens. Apple intentionally designs these tokens so developers cannot read the bundle identifiers, app names, or URLsyou selected. We pass those tokens back to Apple’s frameworks to apply shields and to schedule monitoring. We do not see, log, or transmit the names or identifiers of the apps you chose to lock.
  • Restrictions are applied on-device: The actual blocking (shielding apps, categories, or web domains and unlocking them once you meet your reading goal) is performed by iOS on your device using the tokens above. No server we operate decides what to block.
  • Child accounts (parental setup):If the App is used by a minor under a Family Sharing child Apple ID, Family Controls authorization must be approved by the parent or guardian through Apple’s Screen Time passcode flow. The same on-device, opaque-token handling applies.

Information We Collect and Generate

You can use most of the App without creating an account. If you choose to enable cross-device sync inside Settings, we collect the additional information described under “Optional Account and Cross-Device Sync” below. Subscription status is determined through Apple and, where applicable, third-party paywall tooling described below.

  • Subscription and purchase activity: Purchases are processed by Apple. We do not receive your full payment card number. The App may record which subscription product identifiers are active on your device for feature access.
  • Device and app interaction (analytics and measurement): The App includes the Meta (Facebook) Software Development Kit, which can collect device and usage-related data and send events to Meta for app analytics and advertising measurement. When Apple’s App Tracking Transparencyframework grants tracking authorization, the App aligns Meta settings so that advertiser identifier collection may be enabled; if you do not grant tracking, advertiser identifier collection is disabled while other SDK features may still operate per Meta’s defaults.
  • Purchase-related app events (Meta): When you complete certain App Store purchases inside the App (including auto-renewable subscriptions and any optional one-time purchases such as charitable donations offered in the Support experience), the App may send standard Meta app events (for example, trial start or purchase events with product and currency information) for advertising measurement and analytics.
  • Paywall presentation: The App uses Superwall to show subscription paywalls. Superwall may collect identifiers and usage data according to its own privacy policy when you interact with paywalls.
  • Feedback you choose to send: If you submit in-app feedback, the App transmits the text you enter, an optional email address if you provide one, a category label, an app name label, and a timestamp to an HTTPS endpoint we control (hosted through an automation service) so we can read and respond to feedback.
  • Optional Support tab actions: If you participate in in-app voting or similar interactions offered on the Support tab, the App may send a non-personal identifier for the choice (for example, an organization code), a month label, an app name label, and a timestamp to the same kind of HTTPS automation endpoint for tallying results. If you complete an optional charitable donation through the Support experience, the purchase is processed by Apple as described above.

Optional Account and Cross-Device Sync

The App offers an optional“Sync across devices” feature in Settings. If you turn it on, you create an account by entering your email address; we send you a one-tap magic-link sign-in email and we do not collect or store passwords. While you are signed in:

  • Your email address is stored on our auth provider so we can recognize you and send sign-in links.
  • The App uploads a copy of your saved Scripture First activity to our cloud database so it can be downloaded on your other devices when you sign in there. The synced data includes your daily reading goal and plan selection, your reading progress and unlock state, saved and highlighted verses, personal notes, recent search history, your streak, app theme and translation preferences, and your selected favorite verse for widgets.
  • Sync uploads run automatically a couple of seconds after you make a change while signed in, and downloads run when you open the App. We also keep a small per-user record of when each device last synced.
  • Family Controls selections are not synced. The opaque, encrypted tokens for the apps, categories, or web domains you chose to lock stay on the device that selected them. Each device using Scripture First sets up its own lock list locally.

Cross-device sync is provided by Supabase, our cloud-database and authentication processor, on hosting infrastructure located in the United States (Amazon Web Services, US-West region). Supabase processes this data on our behalf under their privacy policy. Each user’s data is segregated by user identifier and protected with row-level access rules so that a signed-in user can only read or write their own data.

Cross-property accounts. The same email-based account can be reused across other apps and websites we operate (Bible Word Study, Scroll the Bible, Scripture First, and JCBSN). Signing into one of these properties with your email creates or reuses a single underlying account so you do not have to manage separate logins. Each property only stores its own activity (for example, only Scripture First reads or writes the Scripture First sync data described above).

You can stop syncing or delete the account at any time. In Settings > Sync across devices you can sign out (which leaves your data on this device and in your account, available again when you sign back in) or tap Delete account, which permanently removes your auth identity and all of your synced data from our cloud and from any other devices that sign in afterwards. Deleting the account does not erase the reading progress, notes, and saved verses already on this device, and it does not revoke Family Controls authorization. Those remain on this device unless you choose to remove them.

Data Stored on Your Device

Whether or not sync is turned on, the App keeps a copy of your study activity locally on your device. Examples include:

  • Family Controls selection tokens for the apps, categories, or web domains you chose to lock (opaque tokens as described above)
  • Daily reading goal and plan (such as a verse a day, a chapter, a proverb a day, or a longer plan), and your progress and unlock state for each day
  • Saved and highlighted verses, personal notes, and recent search history
  • App preferences (such as theme and translation selection)
  • Streak and notification scheduling metadata used for local reminders
  • Widget-related verse selectionsshared with the App’s widgets through Apple’s app group container on your device
  • Technical data used for App functionality, such as timestamps used to limit repeated feedback submissions

Deleting the App or clearing app data may erase this local information unless you have a separate device backup that restores it. Removing the App also releases the Family Controls restrictions it was applying. If sync is turned on, your synced data is also stored in our cloud as described above.

Information Sent to Third-Party Services

When you use certain features, the App sends data over encrypted HTTPS connections to service providers so those features can work:

  • OpenAI:The App uses OpenAI’s APIs for AI-assisted features (such as verse explanations, short studies, and related guided experiences). The prompts can include the text you are studying or asking about (for example, a verse reference and verse text needed for context), along with instructional text required to produce a safe, on-topic response. If you enter your own OpenAI API key in the App, requests are authenticated with your key and processed under your relationship with OpenAI.
  • API.Bible (American Bible Society): The King James Version (KJV) text is loaded from data bundled with the App. For certain other Bible translations, the App calls API.Bible with identifiers such as translation, book, and chapter. Responses may be cached on-device to reduce repeat network requests.
  • Apple: In-App Purchases, StoreKit subscription state, App Store services, and the Family Controls / Managed Settings / Device Activity frameworks described above.
  • Meta Platforms, Inc.: As described above, through the Facebook SDK and related app events.
  • Superwall:Paywall presentation, subscription status coordination, and related analytics as described in Superwall’s documentation and privacy policy.
  • Supabase:If you enable cross-device sync, your email address, magic-link sign-in events, and the synced study data described above are stored in our Supabase project (hosted on Amazon Web Services in the United States). Supabase also delivers magic-link sign-in emails on our behalf. See “Optional Account and Cross-Device Sync” above for details.

Each provider processes data under its own terms. Please review their policies:

How We Use Information

  • Operate the core Scripture First experience: applying and releasing on-device app restrictions through Apple’s Family Controls frameworks based on your reading progress
  • Provide Bible text, AI-assisted explanations, and related study tools
  • Process and validate subscriptions and paywall access
  • Process optional charitable donations made through the Support experience
  • Authenticate you, deliver magic-link sign-in emails, and synchronize your study data across devices when you enable cross-device sync
  • Measure advertising and subscription performance through Meta’s SDK where enabled
  • Improve reliability and understand aggregate usage patterns through vendors’ analytics where applicable
  • Respond to feedback you send us
  • Comply with law and protect rights and safety

Data Sharing

We do not sell or share personal information as those terms are defined under the California Consumer Privacy Act. We instruct service providers as part of operating the App (listed above). We may disclose information if required by law, legal process, or to protect users and the public.

Data Retention

We retain information for as long as it is needed to provide the App and the features you use. Specifically:

  • Synced account data. If you enable cross-device sync, we retain your email address and synced study data for as long as your account is active. When you tap Delete account in Settings, your auth identity and all synced study data are promptly removed from our cloud.
  • Feedback. Messages you submit through the in-app feedback form are retained for as long as reasonably necessary to respond to and act on the feedback.
  • On-device data. Data stored locally on your device (including Family Controls selection tokens) is retained on your device until you delete it inside the App or remove the App.
  • Third-party services.Data processed by service providers (such as Apple, Meta, Superwall, OpenAI, API.Bible, and Supabase) is retained per each provider’s own retention policies.

App Tracking Transparency and Your Controls

iOS may prompt you to allow or deny cross-app tracking. You can change your choice later in Settings > Privacy & Security > Tracking. You can also limit ad personalization through device and Meta account settings as described in Meta’s help documentation.

You can revoke Family Controls authorization at any time in Settings > Screen Time. Doing so will release any shields the App was applying.

Local Notifications

Reading reminders are scheduled on your device using Apple’s local notification APIs. They are not push notifications sent from our servers.

Security

  • Network requests to third parties use HTTPS.
  • API keys stored for your OpenAI and API.Bible access are stored in the iOS Keychain with device-only accessibility settings intended to keep them off unencrypted backups.
  • We rely on Apple’s platform security for device-level protection, including the protections built into Family Controls.

No method of storage or transmission is perfectly secure.

Your Choices and Rights

Depending on where you live, privacy laws may give you rights to access, correct, delete, or restrict certain processing of personal information, or to opt out of certain sharing for advertising. Because most study content stays on your device, you can often delete it directly inside the App or by removing the App. For subscription billing history or refunds, use Apple’s account tools.

If you enabled cross-device sync, you can permanently delete your account and all of the synced data we hold about you at any time from inside the App: open Settings > Sync across devices and tap Delete account. This wipes your auth identity and your synced study data from our cloud and from any other devices that sign in afterwards.

To exercise rights that apply to information we hold as a business (for example, feedback you emailed through the App), contact us using the information below. We may need to verify your request as permitted by law.

European Economic Area, United Kingdom, and Switzerland

If you are located in the European Economic Area, the United Kingdom, or Switzerland, we process your personal information based on the following legal grounds: your consent (for example, when you choose to enable cross-device sync or grant App Tracking Transparency authorization); the performance of our agreement with you (to provide the App and the features you use); our legitimate interests in operating, securing, and improving the App and measuring advertising performance, where those interests are not overridden by your rights; and compliance with legal obligations.

Subject to applicable law, you may have the right to access, correct, delete, restrict, or object to our processing of your personal information, the right to data portability, and the right to withdraw consent at any time without affecting the lawfulness of processing based on consent before its withdrawal. You also have the right to lodge a complaint with your local data protection authority. To exercise these rights, contact us using the information below.

Personal information processed for the App may be transferred to and stored in the United States or other countries where our service providers operate. Where required, we rely on appropriate safeguards for such transfers, including the standard contractual clauses published by relevant authorities.

Children's Privacy and Parental Use

Scripture First is suitable for general audiences and may also be installed on a child’s device with a parent or guardian configuring it. When the App is used under a child Apple ID, Family Controls authorization is granted through Apple’s Screen Time passcode flow controlled by the parent or guardian. The opaque-token handling described above applies in the same way.

The App is intended for users 13 years of age or older. We do not knowingly collect personal information from children under 13 through the App beyond what the operating system and integrated SDKs may collect in the ordinary course. If you believe a child has provided personal information to us through feedback or another channel, contact us using the information below and we will take appropriate steps to delete it.

International Users

If you use the App from outside the United States, your information may be processed in the United States or other countries where service providers operate. Those countries may have different data protection laws than your country.

Changes to This Policy

We may update this Privacy Policy from time to time. We will post the updated policy and revise the “Last updated” date. If changes are material, we may provide additional notice as required by law or through the App.

Contact Us

If you have any questions about this Privacy Policy, please contact us:

Email: founder@thejcbsnbrand.com

Developer: JCBSN Brand