Bible Scroll – Privacy Policy

Last updated: 13 September 2026

Hapiga Vietnam Company Limited, also known as Hapiga Studio (“Hapiga,” “we,” “us,” or “our”), provides Bible Scroll. This policy covers the Android app and the online services we provide for it. We are responsible for deciding how personal information is used for these services, including as data controller where that term applies.

You can read bundled Scripture without creating an email account. Your notes and reading activity are stored locally. Purchases, secure online sessions, AI studies, app updates, and support involve additional information as described below. An installation identifier is not your name, but it can link activity to one installation and is treated as personal information where the law requires.

1. Reading data on your device

The app stores data needed for your reading experience, including:

  • Notes, favorites, liked verses, generated study history, and studies you mark as saved.
  • Reading position, plans, completed readings, streaks, and related history.
  • Display preferences, onboarding choices, reminder settings, and a locally stored ministry-vote choice.
  • Cached subscription status and technical settings needed to operate the app.

Bible Scroll does not provide cloud syncing of these notes, plans, or reading histories. Reading the bundled King James Version does not require a chapter request to an external Bible service.

Android or your device manufacturer may back up and restore the app’s reading database according to your device settings. We configure Android backup rules to exclude the app’s secure identity and authentication stores. A backup can therefore restore reading data without restoring the credentials for online features. Device backups are separate from a Bible Scroll account-sync service.

2. Installation identity and secure sessions

The app creates a random installation identifier. RevenueCat uses this identifier to associate purchase status with the installation. When an online feature needs a secure session, the app also uses Google Firebase Authentication and App Check with Google Play Integrity.

These services process an installation identifier, authentication and integrity tokens, and technical information needed to verify requests. This can include IP address, app and device information, and integrity-check results. A secret stored in secure device storage is sent to our session service to establish the installation’s identity. Our session handler does not save that secret or its request body. Authentication tokens and the device secret are not sent to the AI provider.

Our database stores installation status, session request counts and time periods, and daily AI request counts linked to a transformed installation identifier. These records help us enforce usage limits and prevent unauthorized access and abuse. They are not a copy of your personal notes or reading history.

3. Optional AI studies

When you use an available online AI study feature, the app sends the selected verse text, its reference, the translation, and the type of study to our server. The request includes a session token so we can check access and usage limits.

Our server sends the verse information and study instructions through OpenRouter to an AI model provider. The current default model is Google’s Gemini 2.5 Flash. The provider or model may change as the service develops. We do not send your installation identifier, authentication tokens, personal notes, saved history, or payment details to OpenRouter as part of the study request.

OpenRouter and the selected model provider process the request and response under their own applicable terms and data practices. Retention and use for model improvement can vary by provider. We do not promise that every provider deletes requests immediately or excludes them from training. See OpenRouter’s Privacy Policy and its provider data practices.

Our study handler does not save the request body or AI answer to a study-history database on our server. Generated results are stored in the app’s local study history, and you can mark a study as saved. Network infrastructure and AI providers may still process request metadata and retain information under their applicable policies.

Your choice of Scripture can reveal religious interests or beliefs. Use AI studies only if you are comfortable sending the selected passage for this processing. You can use the local reader without requesting an AI study. Do not send sensitive personal information about yourself or others in support messages unless it is needed for your request.

4. Purchases

Google Play processes subscriptions through your Google account. RevenueCat receives the app’s installation identifier, product and transaction information, purchase tokens or receipts, subscription status, and technical app or device data needed for purchase verification and service operation. We use this information to provide premium access, check renewal or trial status, restore eligible purchases, and address billing issues.

We do not receive your full payment card details. Deleting local app data does not delete purchase records held by Google Play or RevenueCat and does not cancel your subscription.

5. Updates and technical records

Bible Scroll uses Expo’s update service to check for and download app updates. The service can receive technical information such as IP address, platform, app or runtime version, update identifiers, and update-related error or crash metadata. We use update services to distribute fixes and keep the app working.

Our online hosting providers also process network information, such as request time, IP address, HTTP information, response status, and errors. These records help operate and secure the services. Our app server handlers do not deliberately log request bodies, installation secrets, or AI prompts and answers.

The current app has no advertising, advertising attribution, general product analytics, or session-replay SDK. It does not send your reading activity to an advertising network. This does not mean that purchase providers, update services, or hosting systems collect no technical data.

6. Reminders, sharing, and device permissions

Reading and trial reminders are scheduled locally on your device when you enable them. You can turn them off in the app or through Android notification settings. The app does not register a remote push-notification token for a marketing campaign.

When you choose to copy a verse, the app writes the selected text to the clipboard. When you share or export a verse image, the app creates the image and passes it to the destination you choose. Temporary image files are used for this process. Saving an image to Photos requests permission to add it where needed; the feature does not read your photo library. Copies saved to Photos or another app remain there until removed using that service’s controls.

External ministry links open third-party sites. Those sites receive the normal network information associated with your visit and follow their own privacy policies. The current app does not send Community votes to an online voting service.

7. Support

If you email us, we receive your email address, your message, and any attachments or other information you choose to provide. We use them to respond, investigate the issue, and keep a record of the request where needed. Include only information relevant to the issue. Do not send passwords, authentication tokens, or full payment card details.

8. Service providers and other disclosures

The providers involved in the app include:

ProviderPurposeFurther information
Google Firebase and Google CloudAuthentication, app-integrity checks, hosting, security records, and usage limitsFirebase privacy information
Google PlayBilling, purchase management, and app integrityGoogle Privacy Policy
RevenueCatPurchase verification and premium accessRevenueCat Privacy Policy
OpenRouter and the model providers it usesGenerate optional AI studiesOpenRouter Privacy Policy
ExpoApp updates and related technical operationsExpo Privacy Policy

Providers receive information for the purposes described above. Their roles and independent obligations depend on the service and applicable law. We may also disclose relevant information to comply with a legal obligation, respond to a valid legal request, protect against fraud or security threats, or handle a business transfer subject to applicable privacy requirements.

We do not sell personal information for money or provide it to advertising networks for targeted advertising in the current app. AI provider processing is described separately in Section 3.

9. Reasons for processing

We process information to provide the features you request, manage subscriptions, maintain secure sessions, prevent abuse, deliver updates, answer support requests, and meet legal obligations.

Where European, UK, or similar laws require a legal basis, the basis depends on the purpose: performing our agreement with you for requested services; our legitimate interests in security, reliable operation, and support, subject to your rights; complying with law; or consent where required. Device permission prompts do not replace any separate consent that applicable law requires. Where processing relies on consent, you may withdraw it without affecting processing that was lawful before withdrawal.

10. Retention and security

Local reading data stays on the device until you remove it or clear the app’s storage, subject to system backups. Copies you export and backups maintained by your device provider have separate controls.

Authentication records, installation-status records, and daily usage counters are kept in our service systems; they are not automatically removed when you uninstall the app or when a usage period ends. Retention depends on the need to operate the service, prevent abuse, resolve a request or dispute, and comply with legal obligations. We have not set an automatic expiry for these records. You can contact us about records linked to your installation.

Support, purchase, hosting, and AI-provider records have retention requirements that depend on their purpose, applicable law, and provider practices. We do not promise a single deletion period for all providers or systems.

We use measures such as encrypted connections, secure device storage for credentials, and checks on access to online features. No storage or network system can guarantee complete security.

11. International processing

Hapiga is based in Vietnam. Information may be processed in Vietnam, the United States, or other countries where our providers operate. Protections can differ from those in your country. Where required, transfers must use an applicable legal mechanism and safeguards. Contact us for information about the arrangements that apply to your data.

12. Your choices and rights

Our Data Policy gives further instructions for local data, backups, and requests to access, correct, or delete server records.

  • Use the bundled reader without requesting AI studies.
  • Edit or remove saved items using the controls available in the app. To remove the app’s local data, use Android app-storage controls. Check device backups separately because a later restore may bring reading data back.
  • Control reminders and Photos permissions in device settings.
  • Manage or cancel subscriptions through Google Play.
  • Contact us about access, correction, deletion, or other privacy requests. There is no in-app cloud-account deletion button in the current app.

Depending on the law that applies, you may have rights to receive a copy of information, correct it, delete it, restrict or object to processing, withdraw consent, and complain to a data protection authority. Where applicable, you may use an authorized agent and exercise your rights without unlawful discrimination.

Where the right to data portability applies, you may receive qualifying personal data you provided to us in a structured, commonly used, machine-readable format and transfer it to another provider. You may also request a direct transfer where technically feasible. This right is subject to the conditions and limits of applicable law, including the rights of others.

Send requests to support@hapiga.com and identify Bible Scroll. We may need enough information to locate and verify the relevant installation or purchase. We do not use an email account to identify every reader, so an email address alone may not identify app records. Do not send your device secret or session tokens. We will explain any verification needed and any legal reason that limits a request. Removing server records does not cancel a Google Play subscription or remove copies held independently by other services.

13. Children and guardians

Bible Scroll is designed for a general audience aged 13 or older. It is not directed to children under 13. We do not ask for a date of birth in the app and do not knowingly collect personal information from children under 13. Use by a minor must also meet the requirements of applicable law and the eligibility rules in our Terms.

A parent or guardian who believes that a child has provided personal information contrary to these requirements can contact us. We will assess the request and take the steps required by law, including deletion where required. A store age rating is not, by itself, consent for online processing of a child’s information.

14. Changes and contact

We may update this policy as the app or our practices change. We will show the effective date and provide notice of significant changes, or request consent, where required. This policy covers Bible Scroll; websites and external services you visit can have separate policies.

Hapiga Vietnam Company Limited
34/521 Nguyen Trai, Thanh Xuan District, Hanoi, Vietnam
Email: support@hapiga.com
Website: hapiga.com