Privacy Policy
Your data is sacred
Sin Guard exists to help you find freedom, not to harvest your secrets. You are trusting us with some of the most private parts of your life — what you struggle with, where you are in your walk, the days you win and the days you don't. We take that seriously.
So here is the short version, in plain English:
- We collect as little as possible — only what the app needs to work for you.
- We never sell your data. Ever. Not to advertisers, not to data brokers, not to anyone.
- We don't run ads and we don't track you across other apps or websites.
- Your journal is end-to-end encrypted — we cannot read it. It is encrypted on your phone with a key only you hold. If you turn on Cloud Backup, we store it as ciphertext we have no way to open.
- Your streaks and progress are backed up to our servers, and we can read those. That includes the struggle category you picked. We do this so your progress survives a new phone — but we'd rather tell you plainly than let you assume otherwise.
- You can delete everything, including your account, from inside the app, at any time.
The rest of this document explains exactly how that works, who we share data with to keep the app running, and the rights you have. We've written it to be readable. Where the law requires specific language, we've kept it as clear as we can.
1. Who we are
Sin Guard is operated by BeBetter Software LLC, a Nevada limited liability company ("BeBetter Software," "we," "us," or "our"). For the purposes of data protection law, BeBetter Software is the data controller for the personal information described in this policy.
You can reach us about privacy at:
- Privacy contact: info@singuard.org
- Support: info@singuard.org
- Mailing address: 732 S 6th St Ste R, Las Vegas, NV 89101, USA
2. How Sin Guard handles your data (the important part first)
Not everything in Sin Guard is protected the same way, and the difference matters. There are three tiers. The honest question to ask about any piece of your data is "can BeBetter Software read this?" — so that is how we've sorted it.
Tier 1 — End-to-end encrypted. We cannot read it.
Your journal entries (including any photos you attach) and your onboarding answers — the struggles you selected, your root causes, what you wrote about why, your escape plan, and when you tend to be tempted.
These are encrypted on your phone with AES-256-GCM using a key held in your device's secure hardware storage. If you turn on Cloud Backup in Settings, they are uploaded, but only as ciphertext. The key is never sent to us in a readable form — it is wrapped with a passphrase that only you know, and we have no way to recover it. What we can see on our servers is that a record exists, when it changed, and roughly how big it is. Not what it says.
This is a real guarantee, not a figure of speech: if you forget your backup passphrase, we cannot recover your journal for you. Nobody can.
Tier 2 — On our servers, and we can read it.
This is the part earlier versions of this policy got wrong, so we want to be blunt about it:
- Your recovery tracking — the struggle category you set as your focus, your current and longest streak, your check-in dates, how many times you've resisted, how many times you've relapsed, and your streak history.
- Your devotional progress — which plans you've started, paused, and finished.
- Your app settings — reminder times, theme, and whether App Lock is on.
- Your account — your email or Apple/Google sign-in identifier, an optional display name, an optional profile photo, and your subscription status.
This backup happens automatically once you're signed in. It is not something you switch on, and today it is not encrypted in a way that hides it from us — it is stored as ordinary readable data in our database, protected by access controls and our hosting provider's encryption at rest, but readable by us. We do this so that a new phone, a reinstall, or a lost device doesn't cost you your streak.
We are working to bring this tier under the same end-to-end encryption as your journal. Until we have shipped that and updated this policy to say so, assume we can read anything in this list.
Tier 3 — Never leaves your device.
Your saved verses and favorites, your notification schedule, how often you said you struggle, what you've tried before, the pledges you affirmed in your covenant, your content interests, and your app usage counters. We never receive a copy of any of it.
3. The information we collect
We've grouped this by why we have it. We've flagged sensitive information clearly, because it gets extra protection (see Section 5).
a) Information you give us
| What | When | Where it goes |
|---|---|---|
| Account details — a display name (which can be a handle or anonymous, not your legal name), email address, your sign-in method (email/password, Apple, or Google), and an optional profile photo | When you sign up | Our backend (Supabase) |
| Onboarding answers — the struggle categories you select, root-cause questions, why you want to change, your escape plan, and when you tend to be tempted | During onboarding | On your device. Also uploaded end-to-end encrypted if you turn on Cloud Backup — we cannot read it (Tier 1) |
| Your primary struggle, streaks, check-ins and relapse counts — which struggle you're focused on, whether you resisted or struggled each day, and your streak history | As you use the app | Backed up to our servers automatically, unencrypted to us — we can read this (Tier 2) |
| Devotional progress and app settings — plans started and finished, reminder times, theme, App Lock on/off | As you use the app | Backed up to our servers automatically — we can read this (Tier 2) |
| Saved verses and favorites | As you use the app | On your device only — never uploaded (Tier 3) |
| Journal entries — anything you write in your private journal, including attached photos | As you use the app | On your device, encrypted. Uploaded as ciphertext only if you turn on Cloud Backup — we cannot read it (Tier 1) |
| Feedback and support messages — bug reports, feature requests, and anything you write to us | When you contact us or submit feedback | Our support inbox (by email) |
🔒 Sensitive information. Your struggle categories and your check-in history can reveal religious beliefs and information about your mental and behavioral health (and, for some categories, matters relating to sex life). The law treats this as especially sensitive. We only collect it because it is the whole point of the app — to give you Scripture, devotionals, and tracking tailored to your actual struggle. Please read Section 5 for how we handle it and how to withdraw. Note specifically that your primary struggle category and relapse counts are in Tier 2 — stored on our servers in a form we can read — while your fuller onboarding answers are in Tier 1 and we cannot.
b) Information collected automatically
| What | Purpose | Service provider |
|---|---|---|
| Subscription / purchase data — which plan you have (weekly, annual, or lifetime), trial and renewal status where applicable, and an app-specific user identifier | To deliver and manage your premium access | RevenueCat (and Apple / Google, who actually process the payment) |
| Crash and diagnostic data — app version, device model and operating system, and technical logs when something breaks | To find and fix bugs and keep the app stable | Sentry |
| Product analytics — a fixed list of app events (finishing onboarding, viewing the upgrade screen, choosing or purchasing a plan, starting a trial), tied to your account identifier, plus standard device and app metadata such as OS version and locale | To understand which parts of the app people actually use and where they get stuck | PostHog |
About the analytics. We deliberately kept this narrow. We send a specific, hand-written list of events and nothing else — there is no automatic screen or tap capture, no session recording or replay, and we have turned off location lookup from your IP address. Your journal, your struggle categories, your check-ins and your relapse counts are never included. You can turn analytics off entirely in Settings → Privacy; it is on unless you turn it off.
One thing worth knowing: the same short event names are also attached to crash reports as breadcrumbs, so that when something breaks we can see what you were doing just before. Those breadcrumbs are sent even if you turn analytics off, because they go to our crash reporter rather than our analytics provider. They contain the event name only — never your content.
We have configured our crash-reporting to strip personal information before it is sent — your email, the content of your struggles and journal entries, and other sensitive fields are removed; your user ID is replaced with a random value that changes every time you open the app; and it is set up not to attach your IP address. Crash reports are about the code, not about you.
c) What we deliberately do not collect
- ❌ We do not collect precise location.
- ❌ We do not use advertising identifiers (no IDFA, no Android Advertising ID) and we do not show the App Tracking Transparency prompt, because we don't track you.
- ❌ We do not access your contacts.
- ❌ We do not use your camera. The app has no camera feature at all.
- ❌ We do not build advertising profiles about you.
- ❌ We do not use push notifications, and we hold no push token for your device. Every reminder is scheduled locally on your phone.
Two permissions we do use, and exactly what happens with them:
- Photos. You can attach images to a journal entry and set a profile picture. We use your system photo picker, so we never get access to your photo library — only to the specific images you hand us. Journal photos are encrypted on your device and only ever leave it as ciphertext inside an encrypted entry. Your profile picture is the exception: see the note on profile photos in Section 9.
- Microphone. You can dictate instead of typing. Your voice never leaves your device. We force speech recognition to run on-device, and — because that setting can silently fall back to sending audio to a server on devices that don't support it — we check first and simply don't offer the microphone at all when on-device recognition isn't available. We receive the finished text as part of your entry, never the audio.
📝 Note for future releases: features described in our broader product materials — accountability-partner matching, community forums, group features, and an AI coach — are not part of the current release and are not yet collecting any data. When we launch them, we will update this policy before they go live and tell you what changes. (Cross-device backup used to be on this list. It has shipped, and Section 2 describes how it actually works.)
d) Website waitlist & referrals (singuard.org)
If you join the waitlist on our website, we store your email address, when you joined, whether and when you confirmed or unsubscribed, and — if you arrived through a friend's invite link — a reference to that friend's waitlist entry (used only to count referrals toward their reward). Your own invite link uses a random code; when you open someone's link, their code is kept only in your browser for that visit (session storage). The website sets no cookies and runs no analytics.
- Purpose: to email you a confirmation link, let you know when SinGuard launches, and honor referral rewards.
- Service providers: Supabase (storage) and Resend (email delivery).
- Retention: waitlist entries that are never confirmed are deleted after 60 days. Every waitlist email includes an unsubscribe link, and you can ask us to delete your entry at any time at info@singuard.org.
4. How we use your information
We use your information to:
- Run the core app — track your streaks, show your daily targeted verse, deliver your devotionals, and power Temptation Mode.
- Personalize your experience — match Scripture, devotional content, and your "Know Your Triggers" report to the specific struggle and root cause you told us about.
- Manage your account and premium access — authenticate you, sync and restore your data, and handle premium billing (subscriptions or one-time lifetime purchase) through the app stores.
- Keep the app working and safe — fix crashes, prevent abuse, and improve performance.
- Respond to you — answer support requests and act on feedback.
- Meet legal obligations — comply with applicable laws and respond to lawful requests.
We do not use your information for advertising, and we do not sell or rent it.
5. Sensitive information and your consent (please read)
Because Sin Guard processes information that can reveal your religious beliefs and your health, this category gets special treatment under laws like the EU/UK GDPR and US state privacy laws.
- We rely on your consent to process this sensitive information. You give it by choosing your struggle during onboarding and continuing to use the app, having been given this policy. We use it for one purpose only: personalizing your Scripture, devotionals, reminders, and Temptation Mode to the struggle you actually named.
- You can withdraw your consent at any time by deleting your data or your account in Settings → Account, or by emailing us at info@singuard.org. Withdrawing doesn't undo anything we lawfully did beforehand, but it stops further processing and we delete the underlying data.
- We use this data only to serve you — never to profile you for outside purposes, never for advertising, never sold, and never shared with anyone beyond the service providers in Section 6 that are strictly needed to run the app.
- Some of it, we can read. Your primary struggle category and your relapse counts are in Tier 2 (Section 2) — on our servers, readable by us. Your fuller onboarding answers and your journal are in Tier 1 and are not.
🛠 An honest note about consent. A previous version of this policy said we ask you to tick a dedicated consent box during onboarding, separately from our Terms. That screen does not exist yet. We are adding it, and until it ships this section describes what actually happens rather than what we intended. We would rather tell you that than leave the earlier claim standing. If you are in the EEA or UK and want your sensitive data removed in the meantime, email info@singuard.org and we will delete it — no explanation needed.
6. Who we share data with
We do not sell or rent your personal information, and we do not share it with anyone for their own marketing or advertising.
We do rely on a small number of trusted service providers ("processors" / "sub-processors") to run the app. They only process data on our instructions, for the purposes below, under contracts that require them to protect it. Here is the complete list:
| Provider | What they do for us | What they receive | Their terms |
|---|---|---|---|
| Supabase | Hosts our backend database and handles sign-in/authentication | Your account data (email or Apple/Google identifier, optional display name), your optional profile photo, and your Tier 2 backup — primary struggle, streaks, check-ins, relapse counts, devotional progress and app settings — in readable form. Also your Tier 1 data (journal, onboarding answers) but only as ciphertext neither we nor Supabase can decrypt. Your saved verses never reach Supabase. | supabase.com/privacy |
| RevenueCat | Manages premium plans (subscriptions and the one-time lifetime purchase) | Your subscription/purchase status and an app-specific user identifier. RevenueCat does not use this to track you across other apps for advertising. | revenuecat.com/privacy |
| Resend | Delivers the emails we send — waitlist confirmations, launch announcements, and account emails (sign-up confirmation, password reset) | Your email address and the content of the email being delivered. Nothing else. | resend.com/legal/privacy-policy |
| Sentry | Crash and error reporting | Technical diagnostic data (app version, device model, OS, crash logs) and short event-name breadcrumbs. Configured to exclude your IP address and to carry no account identifier. | sentry.io/privacy |
| PostHog | Product analytics — which features get used and where people get stuck | A fixed list of app event names, your account identifier, and standard device/app metadata. No journal content, struggle categories, check-ins or relapse counts. No automatic capture, no session replay, no IP-based location. Turn it off in Settings → Privacy. | posthog.com/privacy |
| Apple (App Store, Sign in with Apple) | Processes payments and, if you choose it, authentication | Payment information (we never see your card details) and, for Sign in with Apple, a verified identifier and an email (which may be Apple's private relay address) | apple.com/legal/privacy |
| Google (Google Play, Google Sign-In) | Processes payments and, if you choose it, authentication | Payment information (we never see your card details) and, for Google Sign-In, your basic profile/email | policies.google.com/privacy |
We may also disclose information if required by law (for example, a valid legal request), or to protect the safety of someone where we believe there is a risk of serious harm, or in connection with a business transfer (such as a merger or acquisition), in which case we will notify you and this policy will continue to protect your information.
7. Where your data is processed (international transfers)
We and our service providers are based in the United States, and your information is processed there. If you use Sin Guard from the European Economic Area, the United Kingdom, or another region with data-transfer rules, your information will be transferred to the United States. Where required, we rely on appropriate safeguards (such as the European Commission's Standard Contractual Clauses) provided by our service providers. You can contact us for more detail.
8. How long we keep your data
- On-device data: kept until you delete it in the app or uninstall the app.
- Account data and backed-up data: kept while your account is active. When you delete your account we delete it from our active systems — your account record, your Tier 2 backup, your encrypted Tier 1 data, your encryption keys, and your profile photo all go. Residual copies may persist in our hosting provider's encrypted backups for a short period (no longer than 30 days) before being overwritten.
- Subscription and purchase records: retained as long as needed to manage your premium access and meet legal/accounting obligations. When you delete your account we also ask RevenueCat to erase your purchase history. That request is best-effort and we will retry it, but it is not instantaneous. Note that deleting your account does not cancel a subscription — only Apple or Google can do that, from your device's account settings.
- Purchase event log: we keep a small internal log of subscription events (an event ID, an account identifier, and the event type) to stop duplicate billing events being processed twice. It contains no journal, struggle or health data. This log is now deleted along with your account. If a late billing event arrives from the app store afterwards — a subscription expiring months later, for example — we process it without writing your identifier back into the log.
- Crash/diagnostic data: retained on a rolling basis (typically up to 90 days) and then deleted.
- Product analytics: events already sent to PostHog are not automatically purged when you delete your account, though your device stops being linked to a user identity. Email us if you want them deleted and we will request it.
- Support and feedback: kept as long as needed to address your issue, then periodically deleted.
9. How we protect your data
- Encryption in transit: all data moving between the app and our backend is protected with industry-standard TLS encryption.
- Encryption at rest: data stored in our backend is encrypted at rest by our hosting provider.
- Access controls: we use database-level row security and limit access to your data to what is strictly necessary to operate the service.
- End-to-end encryption for your journal: AES-256-GCM, with the key held in your device's secure hardware store and only ever backed up wrapped under a passphrase we never receive. This is the strongest protection we offer and it is why we genuinely cannot read your journal.
- Pseudonymity by design: you can use a display name or handle instead of your real name.
- Encryption on your device: app data stored locally is encrypted using a key held in your device's secure storage. On the rare device where that secure storage is unavailable, the app falls back to storing local data unencrypted rather than failing to start — your sign-in tokens are never subject to that fallback.
- Minimization: we collect as little as possible, which is the best protection of all.
🖼 About profile photos. If you add a profile picture, it is stored at a web address that is publicly reachable — anyone who has or correctly guesses that address can view the image, without signing in. The address contains a random account identifier and the list of stored images cannot be browsed, so it is not practically discoverable, but we would rather you knew than assumed it was private. Nothing else about your account is exposed this way. If that isn't a trade you want to make, simply don't set a profile picture — the app works exactly the same without one. We are moving these to authenticated, expiring links.
No system is perfectly secure, and we can't promise absolute security. But we treat your data as if it were our own, because the trust you place in this app is the whole foundation of it.
10. Your rights and choices
Everyone
- Choose whether your journal is backed up at all. Cloud Backup is off until you turn it on in Settings, and when it is on we hold only ciphertext.
- Turn off product analytics in Settings → Privacy, at any time, without losing any app functionality.
- Access and edit your information in the app.
- Delete your data or your entire account from Settings → Account inside the app. Deleting your account removes your backed-up data from our systems, subject to the two exceptions we list plainly in Section 8.
- Withdraw consent to sensitive-data processing at any time (see Section 5).
- Skip the profile photo if you'd rather not have an image at a publicly reachable address (see Section 9).
If you are in the EEA or UK (GDPR)
You have the right to: access your data; correct it; delete it ("right to be forgotten"); restrict or object to processing; data portability; and withdraw consent. Our legal bases are your consent (for sensitive information and other optional processing), performance of our contract with you (to provide the app and your subscription), and our legitimate interests (to keep the app secure and working). You also have the right to lodge a complaint with your local data protection authority, though we'd appreciate the chance to resolve it first.
If you are in California or another US state with privacy rights
Depending on your state, you may have the right to: know what personal information we collect and how we use it; access and delete it; correct it; and limit the use and disclosure of your sensitive personal information. You also have the right not to be discriminated against for exercising these rights.
- We do not "sell" or "share" your personal information as those terms are defined under California law (no cross-context behavioral advertising), so there is nothing for you to opt out of in that respect — but you can still delete your data and limit our use of sensitive information at any time.
- We only use your sensitive personal information to provide the app you asked for, which is a permitted purpose.
To exercise any of these rights, use the in-app controls or email info@singuard.org. We will verify your request (usually by confirming control of your account email) and respond within the timeframe required by law.
11. Children
Sin Guard is intended for adults. You must be at least 18 years old to use it. We do not knowingly collect personal information from anyone under 18. If you believe a minor has provided us with information, contact us at info@singuard.org and we will delete it.
12. Changes to this policy
If we make material changes — especially before launching a new feature that collects new data — we will update the "Last updated" date and, where appropriate, notify you in the app. Continuing to use Sin Guard after a change means you accept the updated policy.
13. Contact us
Questions, requests, or concerns about your privacy:
BeBetter Software LLC
732 S 6th St Ste R, Las Vegas, NV 89101, USA
Privacy: info@singuard.org
Support: info@singuard.org
Sin Guard — Find Freedom, Together.