Last updated 7 September 2026
Bible Stars is a Bible reading and study app published by ShuiTech (“we”, “us”). This policy explains what the app collects, why, who else sees it, and how to get it back or get rid of it. It covers the Bible Stars mobile app on iOS and Android and the services behind it. It is written to be read, not survived — if anything here is unclear, email us and we will explain it.
The short version. We collect the account you create, what you read, and what you write in the app. We run no analytics, no advertising and no tracking of any kind, and we never sell your data. Your journal entries and reading history reveal your religious interests, so we treat them as sensitive. Deleting your account erases all of it, immediately.
ShuiTech is the data controller for the information described here.
Email: shuifamily0710@gmail.com
We aim to respond within 1–2 business days, and to formal data requests within 30 days.
Your email address and password. Accounts are created with email and password only — Bible Stars has no social sign-in, so we never receive anything from Google, Facebook, Apple ID or any other identity provider. Passwords are stored as salted hashes by our authentication provider and are never visible to us.
Display name, username, a short bio, a country, and a profile picture. All of these are optional, and all of them are visible to other users. See section 6.
If you use them: friend relationships, group memberships, card listings and trade offers, and the in-app notifications those activities generate.
Purchases are processed entirely by Apple or Google. We never see your card number, billing address, or any payment credential. Our subscription provider tells us only which products you own and whether a subscription is active, trialling, or expired.
If you allow notifications, we store a push token for each of your devices so we can deliver them. It identifies the device, not you personally, and it is deleted with your account.
Our hosting provider records standard server logs — IP address, timestamp and the request made — for security, abuse prevention and debugging. These are short-lived operational logs, not a behavioural profile.
This list is exhaustive, and we intend to keep it that way:
We do not sell personal information, and we do not share it for cross-context behavioural advertising, as those terms are defined under California law. We never have, and we have no mechanism to.
We would rather be straightforward about this than hide it behind a checkbox.
Bible Stars is a Christian scripture app. Using it at all suggests an interest in the Bible, and your journal entries may contain personal reflections on faith, doubt, prayer, or your own life. Under the UK and EU GDPR, information revealing religious or philosophical beliefs is a special category of personal data, and it counts as sensitive personal information under California law too.
So:
Bible Stars includes an optional AI assistant that answers questions about the verse you are reading. It does nothing unless you use it.
If you are in crisis, please contact your local emergency services or a helpline at findahelpline.com. Bible Stars is not an emergency service and cannot get help to you.
Visible to other users: your display name, username, bio, country, profile picture, star total, streak, leaderboard rank, and your card collection and trade listings.
Never visible to other users: your email address, your journal entries, your highlights, your reading history, and your purchases.
Profile pictures are public files. Profile pictures are kept in a public storage bucket so they load quickly throughout the app. Each one is given a long, randomly generated web address that is listed nowhere and cannot be guessed or browsed — but anyone holding that address can open the image without signing in. Please do not use a photo you would mind being seen outside the app. Replacing or removing your picture deletes the underlying file.
We use a small number of service providers. They act on our instructions and may not use your data for their own purposes.
| Provider | What it does | What it receives |
|---|---|---|
| Supabase | Database, authentication, file storage and server functions, hosted in the United States | Everything in section 2 apart from payment data |
| Anthropic | Runs the AI study assistant | Verse text and your questions, only when you use the assistant. No account identifiers. |
| RevenueCat | Manages subscriptions and purchase entitlements | Your account identifier and purchase status. No payment details. |
| Apple and Google | App distribution, payment processing, push delivery | Payment information, which they hold under their own privacy policies |
| Expo | Delivers push notifications and app updates | Device push tokens and notification contents |
| helloao.org | Supplies Bible text and commentary | Your device requests chapters from it directly. We send it no identity; it sees the request and the network it came from. |
We may also disclose information where the law genuinely requires it, to protect someone’s safety, or as part of a merger or acquisition — in which case you would be told before your data moved to a new controller.
Bible Stars is intended for users aged 13 and over. If you are in the European Economic Area or the United Kingdom, you must be at least 16, or have a parent or guardian’s consent.
The app is not directed at children under 13 and we do not knowingly collect their information. If you believe a child under the applicable age has an account, email us and we will delete the account and its data promptly and without argument.
We keep your data for as long as your account exists. There is no separate retention schedule and no archive — we do not keep copies for later.
You can delete your account from Profile → Delete Account inside the app. It is immediate and permanent. Deleting removes:
What we cannot delete. Purchases and subscriptions live with Apple or Google. Deleting your account neither cancels a subscription nor produces a refund — cancel first (section 10). Backups of our database are overwritten on a rolling basis and any residue clears within 30 days. Server logs containing IP addresses expire on their own short schedule.
Cancelling is as easy as subscribing. Open Profile → Manage subscription, or the “Cancel anytime” link on the subscription screen, and the app takes you straight to the store’s cancellation page. You can also cancel from Settings → your name → Subscriptions on iOS, or the Play Store → Payments and subscriptions on Android. Cancelling stops the next charge; access continues to the end of the period you have paid for.
If you start a free trial, your device schedules a reminder two days before it turns into a charge, so a first bill is never a surprise. That reminder is generated on your phone and nothing about it is sent to us.
Wherever you live, you can ask us to:
Most of these you can exercise directly: edit your profile, delete individual journal entries and highlights, or delete the whole account. For anything else, email us.
In the EEA and UK, our legal bases are performance of our contract with you (running the app and your account), explicit consent (the sensitive information in section 4, and push notifications), and legitimate interests (security, abuse prevention, and keeping the service working). You have the right to data portability and the right to complain to your national data protection authority.
In California, you have the rights to know, delete, correct, and to limit the use of sensitive personal information. We neither sell nor share personal information, so there is nothing to opt out of, and we will never discriminate against you for exercising a right.
We do not charge for these requests, and we will not make you create anything extra in order to file one.
Our servers are in the United States. If you use the app from elsewhere, your information is transferred there. Where the law requires a transfer mechanism, we rely on the European Commission’s Standard Contractual Clauses, and the UK Addendum, in our agreements with our providers.
Traffic between the app and our servers is encrypted in transit, and data is encrypted at rest by our hosting provider. Database access is governed by row-level security policies, so one account cannot read another’s private data. The AI assistant’s API keys are held server-side and never ship inside the app.
No system is perfectly secure and we will not pretend otherwise. If a breach affects your data, we will notify you and the relevant regulator as the law requires.
If we change this policy we will update the date at the top, and for anything material we will tell you in the app before the change takes effect. The current version always lives at this address.
Questions, requests or complaints: shuifamily0710@gmail.com
See also our Support page.
© 2026 ShuiTech. All rights reserved.