← Davar Church App

Davar Church App Privacy Policy

Last updated: September 12, 2026

Availability: See Version History for current public releases. This policy also describes self-selected affiliations used by branch-specific order notifications in compatible app versions.

This Privacy Policy explains how Davar Church (a church based in the United States, with a branch in Japan; "the Church," "we") handles data in connection with the Davar Church App (the "app") for iPhone, iPad, and Apple TV. Public sections — including Home, general media, memory verses, announcements, links, settings, and published slideshows — are available without sign-in. In Version 1.17, account sign-in is managed centrally in Settings. User access enables Bible AI and uploads; Operator access also enables announcement sending; Administrator access also enables Verse Card and photo/video management.

What we collect

The app itself contains no advertising or analytics SDKs and does not track you. On the server side, we collect only the following:

DataWhenDetails
Chat question textWhen you use the Bible AI chatThe text of the question you submit.
Anonymized question-log identifierWhen you use the Bible AI chatA one-way (irreversible) hash derived from your app sign-in session, stored alongside the question so that questions from the same session can be grouped. It contains no personal information and cannot identify you.
IP address (temporary)During account sign-in attemptsUsed only to rate-limit sign-in attempts and prevent brute-force abuse. Not retained long-term.
Bookmarks / in-app settings other than notification choicesWhile using the appStored locally on your device only; never sent to our servers.
Offline copiesAfter you open supported contentPreviously opened public text, images, weekly bulletin documents and reading text may be stored locally so they can be opened offline. After password authentication, the 2026 SBS room assignment may also be stored in protected local app storage. These files are excluded from device backups. Slideshow video files are not stored for offline use. Offline copies can be removed from Settings; the room-assignment screen also has its own removal control.
Authentication credentialsAfter account sign-inVersion 1.17 receives separate opaque credentials scoped to Bible AI, Verse Cards, media, and—when the role permits—announcements. Credential values are stored only in the device Keychain; the server retains validation records such as one-way hashes and server-defined expiration timestamps. The central app session ends when the earliest required scoped credential expires, so it has no fixed 180-day lifetime. Signing out immediately removes the local credentials and requests server invalidation. Passwords are used for authentication but are not stored in plaintext.
Church photos and videosOnly when you select media and upload itThe complete selected original file, media type, capture date when available, upload state, saved rotation, and a contribution-session ownership reference. Original files may contain embedded metadata supplied by the camera or editing software, including capture location, date, device/camera details, and other EXIF or container metadata. The app does not scan or upload the rest of your photo library and does not request device Location permission.
Self-selected branch affiliationsWhen you save My branches in SettingsStable branch IDs are saved on this device and synchronized with its notification registration when available, solely to route branch-specific order announcements. They do not grant membership or administrative access and are not linked to a member account.
APNs device token and notification choicesOnly when you explicitly enable administrator announcements or daily site updatesAn app-device delivery address and two independent on/off choices used only for optional Church notifications. The token is stored as a lookup hash plus a server-key-encrypted delivery value and is not associated with your name, email address, or an individual member account.
Orders and recovery emailOnly when you submit an order or choose email recoveryThe name and email address you enter, selected items and quantities, optional comment, order status and revision history, and a one-way session ownership reference. A verified email address may be linked to an opt-in recovery identity so orders, Bible AI conversation history, and other supported opted-in app data can be restored on another device. Verification codes and recovery grants expire; the shared Church password alone does not identify an individual.

Except when you choose to place an order or use email recovery, the app does not request your name or email address. It does not request your phone number, contacts, or device Location permission. A photo or video you affirmatively select may nevertheless contain precise location and other metadata embedded in its original file; that metadata is uploaded and retained with the original.

Room-assignment names are supplied by the Church through a password-protected service; the app does not read them from your contacts. A downloaded assignment remains only on that device until the app or its saved offline copy is removed.

The Version 1.17 User, Operator, and Administrator roles are shared Church access roles rather than uniquely identifying personal accounts. Access is limited by the scoped credentials issued for each role. Sign in with Apple is not provided.

How we use it

We do not use this data for advertising, third-party marketing, or user profiling.

Third-party processing (AI)

The Bible AI chat uses Anthropic's Claude API to generate answers. When you use the chat, your question text (and up to the last several turns of the conversation) is sent to Anthropic for processing to generate a response. Anthropic's handling of this data is governed by its commercial terms; under those terms, API inputs are not used to train its models. See Anthropic's privacy policy.

The app's backend (content delivery, media storage, and chat relay) runs on servers operated by the Church. We do not sell or rent your data. New contributions made from an app or web form that displays the immediate-publication consent become Public when upload completes. Public media can appear in iPhone/iPad and Apple TV slideshows without sign-in. The full contribution album and uploads require member, operator, or administrator access; bulk, original-file export, and management controls are limited to administrators. Legacy Private media remains available only to Church administrators and the same authorized uploader session until it is published.

If you enable either notification choice, the app uses Apple Push Notification service (APNs) for delivery. Administrator announcements and site updates are separate choices. At 8:00 AM Los Angeles time, the server may send one daily summary when Home/site content, the weekly bulletin, photos, videos, or Verse Cards changed. The summary identifies updated categories and may include counts, but not page or video titles, destination URLs, filenames, contributor identity, or media content. Compatible apps show published or updated page and YouTube video titles with links in announcement details. The server reads public YouTube information without sending notification device tokens or branch affiliations to YouTube. Administrator-authored pushes use their own audience and require a separate administrator confirmation.

Moderation: Administrators can make Public media Private or delete it. Removal can also be requested through the contact address below. The Church Photos & Videos contribution feature has no comments, direct messaging, public profiles, or follower system. Access can be stopped by expiring or invalidating the central account's scoped credentials. Verse Cards may have a separate public comment supplied with the uploaded card.

Where data is stored & retention

Chat question text, related hashes, and contributed media are stored on Church-operated Linux servers in the United States; part of the AI answer generation runs on Anthropic's servers in the United States. If you use the app from outside the United States (including Japan), your data may be transferred to and processed in the United States. Contributed media is retained while needed as Church-media source material; administrators delete material that is no longer needed. APNs device tokens are retained while at least one notification choice is enabled and deleted after both choices are turned off or when APNs reports them invalid; a network-failed opt-out is retried on a later app refresh. Deleted operational files may remain temporarily in disaster-recovery backups until those backups rotate.

Security

Children

The public content is suitable for general audiences. Bible AI and the media contribution feature are intended for Davar Church members, including families, and younger members may use them under a family member's guidance. Upload only media you are authorized to share, and confirm the permission appropriate for minors, worship or prayer, private conversations, addresses, name badges, and Church-media use.

Your rights & contact

To request deletion of chat question data, contributed-media deletion, removal from Public, or for any privacy-related question, contact [email protected]. Uploaders may delete their own legacy Private items while their contribution session remains valid; administrators can delete media and control publication.

Changes

This Policy may be updated as the app evolves. Material changes will be posted at this URL.