Privacy Policy
Last updated: 1 October 2026
S.C. Editura Viaţă şi Sănătate S.R.L., headquartered in Pantelimon, Cernica Street, no. 101, Ilfov, Romania, registered with the Trade Register under no. J23/3442/2012, having the unique registration code RO6710635, hereinafter referred to as the “Controller”, respects the right to privacy and the protection of personal data of users of the platform www.mybible.eu and the MyBible application.
This Privacy Policy explains what personal data we collect, how we use it, who we share it with, how long we keep it, and what rights you have regarding your personal data.
MyBible is a free Bible reading and study application. It is not a shop: we sell nothing through it, we take no orders and no payments, and we issue no invoices to users.
1. Legal framework
As of May 25, 2018, Regulation (EU) 2016/679 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (“GDPR”) is applicable.
2. Personal data we process
2.1. Data you give us when you create an account
If you create an account with an e-mail address and a password, on www.mybible.eu or in the mobile application, we collect:
- the name you choose to be shown by (a display name, not necessarily your legal name);
- your e-mail address;
- the password you choose, which we never store in readable form — see section 8.
2.2. Data we receive when you sign in with Google or with Apple
If you choose “Sign in with Google” or “Sign in with Apple”, we do not receive and do not store a password. After you authorise it, we receive from the provider and store:
- the stable identifier that the provider assigns to your account — a technical string; in Apple’s case it is specific to our application;
- your e-mail address. If you use Apple’s “Hide My Email”, this is a private relay address and we never see your real one;
- your name, when the provider supplies it. Apple sends it only the first time you authorise the application; when we do not receive a name, we use the part of the e-mail address before the “@” as your display name.
When you sign in with Apple we also receive and store, in encrypted form, a token that lets us act on the authorisation you gave. We keep it for a single purpose: so that we can revoke Apple’s authorisation on your behalf when you delete your account, as Apple requires.
Signing in this way also means that Google or Apple learns that you are signing in to MyBible. On the two pages of the website that offer Google sign-in — the sign-in page and the account settings page — Google’s sign-in script runs in your browser, so your IP address, your browser identification and any Google cookies already stored in your browser are available to Google on those pages, whether or not you then use the button. It is the only third-party script the website loads, but it is not the only thing the website loads from a third party: every page, this one included, fetches the typeface it is set in from an outside font provider, as described in section 6. Google and Apple act as independent controllers for their own sign-in services, and their own privacy policies apply to what they do with that data.
2.3. Content you create in the application
What you save while using MyBible is stored under your account:
- Bible notes, and the text they contain;
- favourite verses, the optional note attached to them, and the categories you organise them into;
- saved devotionals, saved hymns, and saved Sabbath School lessons;
- answers you write to Sabbath School questions, and the passages you highlight in lessons;
- reading plans you subscribe to and your day-by-day progress through them;
- your Bible reading progress — which chapters you have read, per version and book;
- Bible Olympiad attempts, including the answer you chose for each question and your score;
- your profile picture, if you upload one. The image is stored with our object-storage provider and served from a public address, so anyone who knows that address can view the image.
2.4. Data recorded automatically when you use the application
To understand how the application is used and what content is worth producing, we record an event for each significant action: a Bible chapter or passage opened, a devotional, a Sabbath School lesson, an educational resource or a book chapter opened or downloaded, a news item, a hymn, a commentary, the verse of the day, a scanned QR code, a sign-in, a search you ran, and the moments when you subscribe to, complete or abandon a reading plan.
Each event records: the type of action, what it referred to, the date and time, the interface language, the platform (iOS, Android or web — derived from your browser identification, which we do not store), the application version and, for searches, the text you typed (converted to lower case and shortened if it is very long).
These events are linked to you. When you are signed in, the event is stored together with your account identifier. Independently of that, an event sent by the mobile application also carries an identifier supplied by your device, which stays the same across sessions — it is recorded in addition to your account identifier, not instead of it, so an event generated in the application while you are signed in carries both. The website sends no device identifier, so an event generated there while you are signed out carries neither. A device identifier is pseudonymous data, but it is still data about you. From these events we also build aggregate statistics — how many times a chapter was read on a given day, how many accounts and how many devices were active each day.
Search terms can be read by our staff in an internal usage dashboard. Please do not type personal information into the search box.
We do not do any advertising or cross-site tracking. The application contains no advertising identifier, no advertising network, no third-party analytics tool and no social-network pixel; we do not follow you across other websites or applications, we build no advertising profiles, and we neither sell nor share personal data for advertising. The statistics described above are our own and are produced on our own systems.
We do not store IP addresses and we do not store your browser identification. Your IP address is used only transiently, in memory, to limit the number of requests from the same source and so prevent abuse.
2.5. Messages you send us
- Through the contact form: the name, the e-mail address and the message you write. These are not stored in our database; they are delivered by e-mail to the colleagues who answer.
- Through the form for reporting a mistake in a commentary text: your description, the passage it concerns, and — if you are signed in — your account identifier. A report sent from the mobile application also carries the identifier of the device it was sent from; a report sent from the website never does, so a report written on the website while signed out carries nothing that identifies you beyond what you typed. These reports are stored so that the correction is not lost.
2.6. Data we do not collect
We do not ask for and do not store: telephone number, postal address, date of birth, gender, bank or card details, orders or invoices (the application sells nothing), location data, your contacts, or any photograph other than the profile picture you choose to upload.
3. How we collect your data
- directly from you, through the account creation form and the other forms in the application;
- from Google or Apple, when you choose to sign in through them;
- automatically, as you use the website or the mobile applications — the events in section 2.4 and the cookies in section 5;
- from the mobile applications, which send the same data to our server through the application programming interface.
4. Purposes of processing and legal bases
- creating and running your account, signing you in, and keeping your notes, favourites and progress in step across your devices — processing necessary for the performance of the agreement between us, Art. 6(1)(b) GDPR;
- answering your messages and correcting the errors you report — our legitimate interest in responding to users and in keeping the published text accurate, Art. 6(1)(f) GDPR;
- keeping the service secure: preventing abuse, limiting automated requests, and detecting technical faults — our legitimate interest in a secure, functioning service, Art. 6(1)(f) GDPR;
- understanding how the application is used, so that we can improve it and decide what content to produce (the events in section 2.4) — our legitimate interest in developing the service, Art. 6(1)(f) GDPR. You may object to this processing at any time, as shown in section 11;
- complying with our legal obligations, where they apply — Art. 6(1)(c) GDPR.
We do not rely on your consent for any of the processing described above. An earlier version of this policy stated that we did; that did not match how the application actually works. If a future feature requires consent, we will ask for it separately and you will be free to refuse.
Processing is largely automated, but it is not exclusively so, and there is no automated decision-making that produces legal effects for you or similarly significantly affects you. Some text you write is read by people: search terms in the internal usage dashboard, reports of errors in commentary texts, and messages sent through the contact form.
5. Cookies
The website uses only its own cookies, all of them necessary for it to work or for your own comfort:
- the session cookie, which keeps you signed in during a visit, and the “remember me” cookie if you ask for it;
- a security cookie that protects the forms against cross-site request forgery;
locale— the interface language, kept for 365 days;theme— light or dark appearance, kept for 365 days;last_passage,reader_versionandreader_position— the passage you were last reading and where you had got to, kept for 365 days.
We set no advertising cookies and no tracking cookies, and we place no third-party cookies. Google’s sign-in script may read cookies Google has already placed in your browser, as explained in section 2.2.
6. Who receives your data
We do not sell personal data and we make it available to no one for their own advertising or marketing purposes. Data is disclosed only to:
- our hosting, managed database and object-storage provider, whose servers are located in Frankfurt, Germany (European Union). It runs the application, the database, the cache and the queues, and stores profile pictures and the other media files, which it also serves through its content delivery network — so your IP address reaches it when such a file is displayed;
- our e-mail delivery provider, which carries password-reset e-mails and the messages relayed from the contact form;
- our web-font provider, from which every page of the website — this one included — loads the stylesheet and the font files for the typeface it is set in. Your browser fetches them directly from that provider, so your IP address and your browser identification reach it on every page you open, whether or not you have an account and whether or not you are signed in. We send it nothing else about you, and its own privacy policy applies to what it does with what it receives;
- our error-monitoring provider, which receives a technical report when the application fails. Before that report leaves our server we filter it field by field — in the data submitted with the request, in its parameters and in the address of the page alike: the password, the sign-in and identity tokens, the e-mail address, the search term and the free text of a note, an answer, a contact message or a mistake report are each replaced with a placeholder, and a body we cannot read field by field is removed whole. The cookies and your IP address are removed in every case, and your name and your e-mail address are not attached to the report. What does still reach the provider is the technical description of the failure, the address of the page with those parameters filtered out, the harmless fields that make the failure reproducible (the book, the chapter, the Bible version, the page number), your browser identification, the identifier of your device when the report comes from the mobile application, and — if you were signed in — the numeric identifier of your account, which we keep so that we can see how many people a fault affects;
- Google and Apple, when you use their sign-in, as described in section 2.2;
- the colleagues who answer messages sent through the contact form;
- public authorities, where we are required by law to disclose data.
Two clarifications, so that the list above is not misread. The search engine behind Bible search runs on our own infrastructure and contains only Bible text, no personal data. The artificial-intelligence service our editors use to correct and translate texts receives only the material we ourselves publish — never your notes, your messages or any other data about you.
7. Transfers outside the European Economic Area
The application, the database and the stored files are hosted in the European Union. Some of the recipients named in section 6 — in particular the sign-in providers, the web-font provider and the error-monitoring provider — may process data outside the European Economic Area. Such transfers take place under the safeguards required by Chapter V of the GDPR, namely an adequacy decision of the European Commission or standard contractual clauses, as provided in those providers’ terms.
8. How we protect your data
- all traffic between your device and our servers travels over an encrypted connection (HTTPS), and the application’s own connection to the database is likewise encrypted;
- the database is not reachable from the public internet: access to it is restricted by firewall to our own servers;
- your password is never stored in readable form, only as an irreversible cryptographic hash. We cannot read it and cannot tell you what it is — we can only help you set a new one;
- the token received from Apple is stored encrypted;
- access to the administration area is limited to authorised staff.
For accuracy: the remaining data — name, e-mail address, the content you create, the usage events — is stored as ordinary text in the database, protected by the access restrictions and the network measures described above rather than by encryption of each field. An earlier version of this policy stated that all data was stored in encrypted form; that was not accurate.
9. How long we keep your data
- your account and the content you create: for as long as the account exists. After you delete the account, see section 10;
- notes, favourites and highlights that you delete inside the application: they stop being shown to you immediately, but a record of the deletion is kept so that it reaches your other devices too; that record is erased together with the account;
- the usage events in section 2.4: we keep them without a fixed term, because they are the basis of our long-term statistics. When your account is erased, the link between those events and your account is removed and what remains is an anonymous data point;
- the sign-in tokens issued to the mobile application: 14 days;
- the password-reset link: 60 minutes;
- the web session: 120 minutes of inactivity; the cookies in section 5: at most 365 days;
- messages sent through the contact form: they are not stored in our database; they remain, as e-mail, in the mailboxes of the colleagues who received them;
- technical logs, which record what the system did rather than who used it, archived with our storage provider;
- longer, where the law requires us to keep certain data for a longer period.
10. Deleting your account
You can delete your account from the MyBible mobile application. For your own protection we first ask you to prove the account is yours — with your password, or with a fresh sign-in through Google or Apple, whichever you use. The website does not currently offer this option, and our administration area cannot reach a reader’s account either: the single delete button it holds is reserved to a super-administrator and acts only on our own staff accounts — those carrying an administrator role — and not even on all of those, since it refuses the administrator’s own account and the last remaining super-administrator. If you use only the website, write to us at the address in section 11, from the e-mail address the account uses. A member of our staff will then carry the deletion out by hand. Because a person handles it rather than the application, it is not instantaneous: we act within the one-month period section 11 provides, and we confirm it to you by e-mail once it is done.
From the moment the deletion is made — the moment you confirm it in the application, or the moment we carry out a written request — the account can no longer be used: all sessions on all devices are ended and no one can sign in to it, neither with a password nor through Google or Apple. If the account was linked to Apple, we revoke that authorisation with Apple straight away. The deletion cannot be undone.
After 30 days, everything is erased permanently: the account itself (name, e-mail address, password, the link to Google and to Apple), your notes, favourites and the categories you grouped them in, your saved devotionals, hymns and lessons, your Sabbath School answers and highlights, your reading plans and your progress through them, your reading progress, your Bible Olympiad attempts, and your profile picture. The erasure is carried out by an automated job that runs every night, and never before that period has elapsed. Once erased, the data cannot be recovered, by you or by us.
A few records are kept. None of them holds your name, your e-mail address or anything else from your profile, but what is removed from each one differs, so they are set out here one by one:
- the download records for books and resources, so that the totals stay correct: the reference to your account is removed. A download made from the mobile application was also recorded with the identifier of the device it came from, and that identifier stays;
- the usage events of section 2.4: the reference to your account, the device identifier, and anything you had typed into the search box are all removed from them in the same step;
- the mistake reports you filed about commentary texts, so that the correction is not lost: the reference to your account is removed and the wording of the report is kept. A report sent from the mobile application also carries the device identifier described in section 2.5, and that identifier stays;
- our internal operational records of content imports and of the use of the artificial-intelligence service, if your account ever triggered any: the reference to your account is removed;
- the daily active-user counts, which contain only a date and a number which, after the erasure, corresponds to no account.
Your e-mail address, and your Google or Apple account, become free again the moment the deletion is made. You may register again with them, but the result is a new, empty account: it recovers nothing from the old one.
If you delete your Apple ID, or withdraw MyBible’s access from your Apple account, Apple tells us. In the first case we delete your account, exactly as above. In the second we remove the Apple link and end all your sessions, but the account itself remains — if it also has a password or a Google link, you can still use it.
A dedicated page sets this out in full: www.mybible.eu/en/account-deletion.
11. Your rights
Under GDPR, you have the following rights:
- right to be informed;
- right of access to your data;
- right to rectification;
- right to erasure (“right to be forgotten”);
- right to restriction of processing;
- right to object — including to the processing carried out for statistical purposes under section 2.4;
- right to data portability;
- right to lodge a complaint with a supervisory authority — in Romania, the National Supervisory Authority for Personal Data Processing (ANSPDCP);
- right to withdraw consent, where processing is based on consent.
You may exercise these rights by submitting a written request to: dpo@viatasisanatate.ro. We answer within one month of receiving the request, as provided by the GDPR.
12. Changes to this policy
We update this policy whenever the application changes in a way that affects the data we process. The date shown at the top of the page is the date of the last update.