← Back
Privacy Policy — Altar for Android
Last updated: June 8, 2026
Altar is a Christian app that helps you replace digital impulses with Scripture-grounded moments. We built it with a single principle: your spiritual practice is yours, and we collect only what's needed to make the app work.
This page applies to the Altar Android app (com.altarapp.android). For the iOS app, see the main Altar privacy policy.
Who runs Altar
Altar is built and operated by an individual developer. For questions about this policy, email thealtarapp@gmail.com.
What we collect and why
Account data
- Anonymous user ID — when you first open Altar, we create an anonymous account (a random ID, with no email) so the app can securely reach our backend for features like the Bible Assistant and subscription checks. This anonymous account is specific to this device; your in-app settings and progress are kept on your device and do not sync across devices. You don't need to provide an email to use the app.
- Email + display name — only if you choose to Sign in with Google to use Altar Circles (small-group features). We use your email solely to authenticate you and to scope what content belongs to you. We never email you marketing.
Stored only on your device
The following is kept in the app's local database (Room / Android DataStore) on your device. It is not uploaded to our servers and does not sync across devices:
- Scan records — when you use Scan-to-Unlock, the Bible passage you scanned and the reflection you wrote are stored on your device so you can revisit them and so streaks/stats work. Scanned page images are processed on-device by Google ML Kit and are not uploaded.
- Intervention records — each time the Shield screen appears (because you tried to open a guarded app), the timestamp and the verse shown are recorded on your device. This powers your streak count and Home stats.
- Reading-plan progress — which devotionals you've completed.
- Reflections — the text you write during intervention prompts or Quiet Time is stored on your device so the app can show it back to you.
- Your guarded-apps list — which apps trigger the Altar Shield is stored locally and is never uploaded.
- Your Accessibility Service permission state — the OS owns this; Altar never reads, transmits, or stores screen contents or any data from other apps.
Stored on our servers
- Circle activity — if you join an Altar Circle (which requires signing in with Google), your check-ins, reactions, and messages are stored on our servers so the Circle can function and are visible to the other members of that Circle.
- Circle photos (QT Moments) — if you choose to capture a "QT Moment" in an Altar Circle, the photo you take is uploaded and stored so it can be shared with the other members of that Circle. Photos are kept in a private storage bucket (Supabase Storage); they are never public and are never shared with any third party. Your Circle members can view a QT Moment only through a short-lived (15-minute) signed link. This is the only feature that uploads a photo, it happens only when you explicitly capture and post a QT Moment, and ordinary text check-ins never attach or upload a photo. You can remove a photo at any time by deleting the check-in, or remove all of your photos by deleting your account (Settings → Account → Delete my account).
- Subscription status — your Altar Pro entitlement is managed by RevenueCat. We store the entitlement state (free or pro), not your payment details.
Device & technical data
- FCM push token — a device-specific token from Firebase Cloud Messaging. It is stored against your account only if you sign in with Google (so we can deliver Altar Circle notifications such as when the Altar window opens or a member checks in). We do not store a push token for anonymous (signed-out) users. Daily prayer/reminder notifications are scheduled locally on your device and do not use this token. The token is rotated by the OS.
- Crash diagnostics — if the app crashes, we may receive an anonymous crash report (no personal content). It contains no Scripture, reflection, or Circle content.
How we use Accessibility Service
Android requires us to disclose this clearly.
Altar's Accessibility Service is used for one purpose only: to detect when an app you have chosen to guard comes to the foreground, so Altar can show the Shield screen with Scripture and a reflection prompt.
We do not:
- Read screen contents of any app
- Capture, transmit, or store text from any app
- Perform automated UI actions in other apps
- Use Accessibility data for any analytics, advertising, or profiling
The Accessibility permission can be revoked at any time via Android Settings → Accessibility. When revoked, the Shield will simply stop appearing.
Who we share data with
We do not sell your data. We share it only with the service providers required to run the app:
| Provider | What they receive | Why |
| Supabase (PostgreSQL + private file storage, hosting) | Anonymous user ID; if you sign in with Google: your email + display name, your Circle check-ins/reactions/messages, and Circle QT Moment photos (private bucket); subscription entitlement state. Scan, intervention, reflection, and reading-plan data stays on your device and is not sent to Supabase. | Stores your account state and Circle content. Hosted in the US. |
| Firebase Cloud Messaging (Google) | Your FCM device token (only after you sign in with Google) and the notification payload (verse text + Circle activity copy) | Delivers Circle push notifications. |
| RevenueCat | Your anonymous user ID, your Google Play subscription entitlement state | Manages your Altar Pro subscription. |
| Google Play Billing | Your Google account + payment info (handled by Google, not us) | Processes subscription purchases. |
| OpenAI (Bible Assistant only) | The text of your question to the Bible Assistant, if you use that feature. We do not send your account ID. | Powers the AI Bible Assistant responses. |
We do not use third-party advertising, analytics SDKs (other than Firebase Crashlytics-style crash reporting), or social media trackers.
Your rights
- Delete your account — Settings → Account → Delete my account. This permanently removes your account, your Circle membership, check-ins, reactions, and any Circle QT Moment photos you uploaded from our database and storage. Your on-device data (scan history, intervention records, reflections, reading-plan progress, and guarded-apps list) is wiped from this device on next launch.
- Export your data — email thealtarapp@gmail.com with the request and we'll provide a JSON export within 30 days.
- Revoke specific permissions at any time via Android Settings (Notifications, Camera, Accessibility, etc.).
Children
Altar is not directed at children under 13. We do not knowingly collect personal data from children under 13. If you believe a child has provided data, please email us and we will delete it.
Changes
If we materially change this policy, we will update the "Last updated" date and surface a notice in the app on next launch.
Contact
thealtarapp@gmail.com