← Back
Privacy Policy
Last updated: May 21, 2026
Altar ("we", "our", "the app") is a Christian discipline app that intercepts distracting app use with Scripture, reflection, and prayer. This policy explains what information Altar collects, why, and your choices.
The short version
- Altar is local-first. Your core data stays on your device.
- We do not sell your data. We do not track you across apps or the web. We do not run ads.
- The free tier does not require your name, email, phone number, or any contact information.
- Your Screen Time app selections never leave your device.
- The Bible Assistant is part of Altar Pro and requires Sign in with Apple. Apple gives us an opaque per-app identifier (a random UUID) — we never see your real name, email, or Apple ID. We use it to verify your subscription and apply rate limits.
- Altar Circles is an optional, opt-in community feature. Sign in with Apple is required. Free members can host one small Circle (up to 2 members) and join any Circle they're invited to; Altar Pro expands seat counts and lets you host more Circles. If you create or join a Circle, the check-ins, reactions, and photos you post are visible to invited members of that Circle.
What we collect
On-device only (never leaves your phone)
- Your selected blocked apps (Screen Time / Family Controls data).
- Your reflections, prayer notes, and intervention history.
- Cached Bible text and reading plan content bundled with the app.
- Reading-plan progress, settings, streaks, and unlock history.
- OCR'd passage text from Scan to Unlock.
Sign in with Apple identifier
The Bible Assistant and Altar Circles require Sign in with Apple. When you sign in, Apple gives us an opaque user identifier (a random UUID specific to this app and your Apple ID), and — at your choice — your name and a relay email address. We use these only to:
- Verify your active Altar Pro subscription where required (Bible Assistant, expanded Altar Circles seats and hosting), and enforce the free-tier limits in Altar Circles (one hosted Circle with up to two members) without requiring payment.
- Apply per-user rate limits to the Bible Assistant so the feature stays affordable.
- Identify you to other members of any Circle you join (display name only).
- Maintain your authenticated session.
- Honor Apple Guideline 5.1.1(v) account deletion (Settings → Delete Account).
We never see your Apple ID, your Apple ID password, or any contact information beyond the relay email you choose to share. Email addresses are never shown to other members and are never used for marketing.
Anonymous baseline session
Before you've signed in with Apple, the app may create an anonymous Supabase session for connectivity. The anonymous session does not store identifying information and cannot be used to access the Bible Assistant or Altar Circles — those features explicitly require Sign in with Apple. If you reinstall the app, any prior anonymous session is unrecoverable.
Purchase records
If you buy a subscription, Apple processes the transaction. Altar receives only an anonymous entitlement status (premium on/off) from Apple's StoreKit — we never see your payment details.
Bible Assistant and Scan-to-Unlock (AI features)
The Bible Assistant and the Scan-to-Unlock devotional generator are Altar Pro features. They require Sign in with Apple and an active Altar Pro subscription to use.
Your explicit consent is required before any AI request leaves the device. The first time you tap a Bible Assistant button (or trigger the Scan-to-Unlock devotional), a primer sheet describes what will be sent and to whom and asks you to allow AI assistance. Per Apple App Review guideline 5.1.2(i), this consent is opt-in and revocable: you can turn AI assistance off any time in Settings → Cloud & AI → AI assistance. While AI assistance is off, these features fall back to local offline responses and nothing is transmitted to OpenAI.
When AI assistance is on and you use these features, your prompt or the OCR'd Scripture reference is sent to our Supabase Edge Function over HTTPS. The Edge Function uses your Apple-issued opaque identifier to verify your active Pro entitlement and apply per-user rate limits. It records the timestamp of the request (so we can rate-limit abuse); the prompt text itself is not stored server-side. The prompt and passage are forwarded to OpenAI's API to generate a response. OpenAI does not see any identifying information about you. Under OpenAI's standard API data-usage policy, prompts sent via the API are not used to train OpenAI's models. If the Edge Function is unavailable, the Bible Assistant falls back to offline responses that never leave your device.
Altar Circles (optional community feature)
Altar Circles is an opt-in feature for invite-only accountability groups. It is off until you choose to use it. If you create or join a Circle, the following applies:
- Sign in with Apple is required. When you sign in, Apple shares an opaque user identifier with us, and — at your choice — your name and a relay email address. We use these only to identify you to other members of Circles you join (display name only), to maintain your authenticated session, and to honor Apple Guideline 5.1.1(v) account deletion ("Delete Account" in Settings).
- Email addresses are never shown to other members and are not used for marketing.
- What members of your Circle see: your display name, any check-in text or Scripture passage you post, any photo you attach, and your reactions ("Praying," "Amen," "Encouraged," "Keep Going") on their check-ins.
- What members do not see: your email, your Apple ID, your Screen Time selections, your other Circles, or any of your private reflections from the rest of the app.
- Reports and blocks: if you report a check-in, only Altar (the app, via automated rules and the Circle's RLS policies) sees the report — the author is not notified. Two distinct reports auto-hide a check-in pending review. If you block another user, neither of you can see the other's check-ins, reactions, or profile in any shared Circle. The blocked user is not notified.
- Retention: you can delete any check-in you authored at any time; this also removes the photo from storage. Leaving a Circle hides your historical content from that Circle. Disbanding a Circle (owner only) cascade-deletes every member's check-ins, reactions, and reports for that Circle. Deleting your account through Settings removes all of your check-ins, reactions, reports, profile row, and block list.
- No third-party sharing. Circle content stays on Altar's Supabase backend. It is not shared with OpenAI or any other third party.
What we do NOT collect
- Your real name, email address, phone number, or contact information unless you sign in with Apple to use Altar Circles.
- Your Apple ID password or any sign-in token beyond the short-lived session Apple gives us during Sign in with Apple.
- Which specific apps you have blocked.
- Photos or camera content from outside Altar Circles. (Camera frames captured by Scan to Unlock are processed in-memory and not retained.)
- Location.
- Any cross-device sync or cloud backup of your private spiritual data unless you opt in to Cloud Sync.
How we use your information
- To run the app's core features (interventions, streaks, reading plans).
- To verify your Altar Pro subscription before granting access to Pro features (Bible Assistant, expanded Altar Circles seats and hosting), and to enforce the free-tier limits (one hosted Circle with up to two members) without requiring payment.
- To rate-limit the AI Bible Assistant fairly across paying users (per-Apple-identifier and per-IP).
- To improve the app's reliability by aggregating anonymous crash and error data (iOS system-level only — we do not run third-party analytics SDKs).
Optional product analytics (opt-in)
In Settings → Cloud & AI → "Help improve Altar" you can choose to share pseudonymous product-usage events — for example: a paywall was viewed, an intervention was completed, an exit-survey reason was selected — with our own Supabase backend. This is off by default and only takes effect once you have signed in with Apple; anonymous sessions never send these events.
- We never send the text of your reflections, prayers, scans, journal entries, or Circle posts through this channel.
- Events are stored against your Apple-issued opaque identifier (the same UUID we already use for entitlements), not your name or email.
- Events older than 90 days are purged.
- You can turn this off at any time. Turning it off stops new events immediately. To remove your previously-recorded events, use Settings → Account → Delete Account, which cascades to every server-side row tied to your identifier.
How we protect your information
- All network traffic uses HTTPS/TLS.
- The Apple-issued user identifier we use for backend auth is opaque and does not contain your name or email.
- Per-IP and per-user rate limits prevent abuse of the AI backend.
- On-device data is stored via Apple's SwiftData framework, encrypted by iOS at rest.
Data transfer when you upgrade your phone
When you transfer to a new iPhone via Quick Start, iCloud Backup, or an encrypted local backup, Altar's on-device data (history, reflections, settings, reading-plan progress) is included in the standard iOS migration and carries over automatically. If you set up your new phone "as new" without restoring a backup, that data does not transfer because Altar does not sync to the cloud.
Your choices
- Reset all app data in Settings → Account → About → Reset All App Data. This erases every reflection, scan, and setting on this device.
- Revoke Screen Time access in iOS Settings → Screen Time → Family Controls. Altar will continue to work with a limited feature set.
- Revoke camera access in iOS Settings → Privacy → Camera. Scan to Unlock will be unavailable.
- Leave or disband a Circle — leaving hides your content from that Circle; disbanding (owner only) deletes the Circle and all its content for everyone.
- Block another member in any Circle from the check-in card menu, or manage your block list in Settings → Circles → Blocked Members.
- Delete your account in Settings → Account → Delete Account. This permanently removes your Circles content, profile, block list, and authenticated session, then signs you out.
- Delete the app to remove all on-device data. If you have used Altar Circles, also use Delete Account first so your Circles content is removed from the server.
Children
Altar is not directed at children under 13 and does not knowingly collect information from them.
Third parties
- Supabase (backend): hosts our Edge Functions (Bible Assistant, entitlement verification, push fan-out for Circles) and stores Altar Circles content (check-ins, reactions, reports, photos) for users who opt in. Receives your Apple-issued opaque user identifier and request timestamps whenever you use an Altar Pro server feature. For Circles, additionally receives your chosen display name and the content you post. See supabase.com/privacy.
- OpenAI (via our Edge Function): processes Bible Assistant and Scan-to-Unlock devotional prompts when those features are used. Receives only the prompt content, not your identity. See openai.com/policies/privacy-policy.
- RevenueCat (subscription state): receives your Apple-issued opaque user identifier so we can verify your active Altar Pro subscription on the backend. Does not see your name, email, or Apple ID password. See revenuecat.com/privacy.
- Apple (Sign in with Apple, StoreKit): handles authentication for Altar Pro features (Bible Assistant, Circles) and processes purchases. We receive only the opaque Apple user identifier and, if you choose to share them, a relay email and your chosen name.
Changes
We will update this policy as the app evolves. The "Last updated" date at the top reflects the most recent version.
Contact
Questions? Email thealtarapp@gmail.com.