Privacy Policy
Effective Date: May 6, 2026 |
Last Updated: May 15, 2026
This Privacy Policy describes how the Romans 12:2 mobile app and its supporting web service ("Romans 12:2", "we", "us", "our") collect, use, and share your information. It applies to the iOS app published as "Romans 12:2" (com.niparrotta.romans122) and the API server it talks to. By using the app, you agree to this policy.
If something in this policy is unclear, email us at support@romans122app.com.
Table of contents
- Who we are and how to contact us
- Scope
- Information we collect
- How we use your information
- AI voice processing (ElevenLabs)
- No-impersonation rule
- Subscriptions and billing
- Push notifications
- Email
- Third-party processors
- Sign in with Apple and Sign in with Google
- Analytics and tracking
- Device identifier and the 5-device cap
- How long we keep your information
- Deleting your account
- Accessing or exporting your information
- Children's privacy
- International data transfers
- Security
- Your rights
- Changes to this policy
- Governing law
1. Who we are and how to contact us
Romans 12:2 is a mobile meditation app that turns short Scripture-based meditations into audio narrated either by a built-in voice or by a synthetic clone of your own voice. The app and its supporting service are operated by the Romans 12:2 team.
For privacy questions, data access requests, or account deletion help, email support@romans122app.com.
2. Scope
This policy covers:
- The Romans 12:2 mobile app on iOS.
- The Romans 12:2 API server (hosted on Replit) that the app talks to for sign-in, audio generation, subscription state, push notifications, and email.
It does not cover third-party websites or apps that we do not control, even if we link to them from inside the app.
3. Information we collect
We collect only what we need to run the app and keep your account working. Specifically:
- Account information. Your email address and a password (which we store only as a salted scrypt hash — we never store your plaintext password). If you sign in with Apple or Google, we receive a verified identifier from that provider instead of a password.
- Display name. An optional name you can set on your profile, used to address you in the app and in emails.
- Voice recording. A roughly 30-second voice sample, recorded only if you choose the "Create my voice" feature. This is sent to our AI voice provider to build a synthetic voice model — see §5.
- Generated meditation audio. The MP3 files we render for you, so you do not have to wait for them every time. They are stored under a path keyed to your account.
- Listening history. Anonymous-leaning playback events such as "meditation started" and "meditation completed", used to power streaks, monthly summaries, and aggregate product analytics.
- Per-install device identifier and label. A random identifier the app generates the first time it runs on your device, plus a friendly label (for example, "iPhone 15"), used to enforce a session limit (see §13). We do not collect Apple's IDFA.
- Push notification token. If you allow notifications, the app receives a token from Apple that we store so we can send you reminders.
- Subscription state. Whether you currently have an active premium entitlement, sourced from RevenueCat. We do not store your full Apple receipt.
- Support messages. If you contact support from inside the app or by email, we keep your message and our reply.
- Marketing and product email preferences. Whether you have opted in to marketing or product update emails, plus the timestamp of when you changed each preference.
- Narrator preference, reminder window, and reminder time. Stored on your device and mirrored to your account so it follows you to a new install.
- IP address and basic request logs. Like most web services, our servers see your IP address with each request and write standard HTTP request logs (path, status, latency) for security, abuse prevention, and debugging.
We do not collect your location, contacts, browsing history, search history, health data, or financial information. Apple handles your payment details directly during App Store purchases — they never reach our servers.
4. How we use your information
We use the information above to:
- Run the app and keep you signed in across devices.
- Generate AI voice meditations using your chosen voice.
- Deliver push notifications and reminders you have opted into.
- Bill subscriptions through Apple and reflect your entitlement in the app via RevenueCat.
- Respond to support requests and send transactional emails such as welcome and password-reset messages.
- Send marketing or product emails — but only if you have opted in.
- Measure how the app is used, in aggregate and on an anonymous basis, so we can improve it.
- Detect, prevent, and respond to abuse, fraud, and security incidents.
We do not sell your personal information, and we do not use it to build advertising profiles.
5. AI voice processing (ElevenLabs)
If you choose to create a personalised voice, the app records roughly 30 seconds of your voice and sends that recording to ElevenLabs, our AI voice provider, so they can train a synthetic voice model ("voice clone") tied to your account inside their system.
- The raw audio sample is discarded from our servers immediately after upload. Our backend does not keep a copy.
- ElevenLabs retains the trained voice model for as long as it exists in their system. ElevenLabs may also retain the original training sample as part of the model — please refer to ElevenLabs' own privacy policy at https://elevenlabs.io/privacy for the most current details on their retention practices.
- You can delete your cloned voice at any time from the Profile screen in the app. When you do, we ask ElevenLabs to delete the voice model on a best-effort basis and clear our reference to it.
- Deleting your account also triggers a best-effort deletion of the voice model at ElevenLabs.
- We use ElevenLabs solely to generate audio for you. ElevenLabs' own use of voice data is governed by their privacy policy linked above.
6. No-impersonation rule
When you record your voice sample, the app asks you to confirm three things, in line with the in-app consent screen:
- The voice you are recording is your own and you have the right to record and submit it.
- You understand the recording will be processed by ElevenLabs and stored to generate audio in your voice.
- You will not use this feature to impersonate anyone else, and you understand that misuse may result in account termination.
We take impersonation seriously. If we have a credible report or evidence that you have used the voice clone feature to impersonate another person, we may terminate your account and delete your voice model.
7. Subscriptions and billing
Romans 12:2 Premium is sold as an auto-renewable subscription through the Apple App Store.
Subscription Details:
- Subscription Name: Romans 12:2 Premium
- Subscription Options: Monthly and Yearly (auto-renewable)
- Pricing: Current prices are displayed on the in-app paywall before purchase. Prices vary by region and are shown in your local currency.
Payment Terms:
- All billing is handled by Apple through the App Store. We never see your payment card or full Apple ID.
- Payment will be charged to your Apple ID account at confirmation of purchase.
- We use RevenueCat to confirm the status of your subscription and to mirror it to your in-app entitlement.
Auto-Renewal Terms:
- Subscription automatically renews unless auto-renew is turned off at least 24 hours before the end of the current period.
- Your account will be charged for renewal within 24 hours prior to the end of the current period.
- The cost of renewal will be the same as the original subscription unless we notify you of a price change in advance.
Managing Your Subscription:
You can manage and cancel subscriptions in your Apple ID Account Settings after purchase. To cancel:
iOS Settings → [Your Name] → Subscriptions → Romans 12:2 → Cancel
You can only cancel a subscription from the App Store / iOS Settings — we cannot cancel an Apple subscription on your behalf from inside the app.
Account Deletion vs Subscription Cancellation:
If you delete your account while a subscription is still active, you must also cancel it in the App Store; otherwise Apple will continue to bill you.
Refunds:
Refund requests are handled by Apple at:
Terms of Use (EULA):
This application uses Apple's Standard End User License Agreement (EULA), which can be found at:
https://www.apple.com/legal/internet-services/itunes/dev/stdeula/
By subscribing to Romans 12:2 Premium, you agree to both this Privacy Policy and the Apple Standard EULA.
8. Push notifications
If you allow notifications, the app receives a push token from Apple and stores it on our server. We use that token to send:
- The daily reminder you configured in the app.
- Occasional product updates relevant to your account.
Push notifications are delivered via Apple Push Notification service (APNs) through the Expo Push relay.
You can stop notifications at any time:
- Operating system level: turn off notifications for Romans 12:2 in iOS Settings.
- In-app: use the reminder toggle on the Profile screen.
If Apple tells us a token is no longer registered, we drop it from your account automatically.
9. Email
We send two kinds of email through Resend, our email delivery provider:
- Transactional email — welcome messages, password resets, account notifications, and similar messages necessary to operate the app. These are sent regardless of your marketing preferences because they are required to use your account.
- Marketing or product email — only if you have opted in on the Profile screen.
Every marketing or product email includes:
- A one-click unsubscribe header (RFC 8058) recognised by major mail clients, and
- A clearly visible unsubscribe link in the footer.
Resend records standard send metadata (recipient, subject, timestamp, delivery status) so we can audit deliverability.
10. Third-party processors
We rely on the following third parties to operate the app. Each is covered by their own privacy policy, linked below.
We do not currently send data to any analytics or advertising SDK beyond what is listed above. In particular, the app does not call Meta / Facebook App Events from the iOS binary today. If we add a new processor, we will update this policy before the change ships.
11. Sign in with Apple and Sign in with Google
If you choose Sign in with Apple, Apple sends us a verified token that contains a stable identifier and an email address. Apple may provide a private relay email instead of your real Apple ID email — we treat the relay address as your email and never see your true Apple ID.
Sign in with Google is implemented in the app but is currently disabled in the production build. When we enable it, we will update this policy in the same release. If enabled, Google would provide us with a verified token containing a stable identifier, your email, and your name.
12. Analytics and tracking
Where configured, we use PostHog for anonymous product analytics (for example, "a meditation was started" or "the upgrade prompt was shown"). PostHog events are not linked to your Romans 12:2 user id — we deliberately do not call PostHog's identify() API with your account.
We also keep our own server-side log of meditation playback events linked to your account, so we can power features like streaks and your monthly summary.
We do not track you in Apple's sense of the word. Specifically:
- We do not request Apple's advertising identifier (IDFA).
- We do not show the App Tracking Transparency prompt, because we do not link your data to data collected by other apps or websites for advertising, and we do not share your data with data brokers.
- We do not run the Meta / Facebook SDK.
Because PostHog uses an anonymous distinct identifier that we do not tie to your account, we have no key by which to delete your past PostHog events when you delete your account. The events themselves remain anonymous.
13. Device identifier and the 5-device cap
The first time you sign in on a device, the app generates a random identifier that lives in your device's secure storage. We use that identifier to enforce a limit of five active sessions per account and to show you the list of devices currently signed in to your account, on the Profile → Your devices screen.
You can sign out a device from that screen at any time. Signing out a device immediately revokes its session.
14. How long we keep your information
In short:
- Account data (email, hashed password, display name, preferences) — kept until you delete your account.
- Generated meditation audio — kept until you delete your account.
- Cloned voice model at ElevenLabs — kept until you delete the voice from the Profile screen, or delete your account.
- Listening history on our server — kept until you delete your account.
- Streaks and monthly statistics on your device — kept until you sign out or uninstall the app.
- Push token — kept until you sign out, the token rotates, you delete your account, or Apple tells us the token is no longer valid.
- Per-install device identifier — kept until you uninstall the app on that device, or delete your account.
- Subscription receipt summary at RevenueCat — per RevenueCat's retention.
- Email send logs at Resend — per Resend's retention policy.
- Server request logs and IP addresses — per our hosting provider's log retention windows; rate-limit windows are roughly one day.
- Support messages — currently retained for our records even after account deletion (see §15). You can email us to request manual deletion.
- Anonymous PostHog events — not deleted on account deletion (we have no identifier to delete by); they remain unlinked to you.
15. Deleting your account
You can delete your account from inside the app: Profile → Delete account. When you do, we immediately:
- Delete your account row and the data linked to it in our database (preferences, push token, sessions, listening history, narrator preference, marketing/email opt-ins).
- Delete the generated meditation audio we stored for you in Google Cloud Storage.
- Ask RevenueCat to delete your customer record.
- Ask ElevenLabs to delete your cloned voice model on a best-effort basis.
What is not deleted automatically:
- Apple subscriptions. If you have an active App Store subscription, you must cancel it in the App Store / iOS Settings. Apple will otherwise continue to bill you. We cannot cancel an Apple subscription on your behalf.
- Support request rows. Today, support messages you have sent us are retained even after account deletion, because they are stored separately from your account. Email support@romans122app.com if you would like us to delete those manually.
- ElevenLabs voice model, if the deletion request to ElevenLabs fails. We retry on a best-effort basis. If you suspect your voice model is still present at ElevenLabs after account deletion, email us and we will request manual deletion.
- Anonymous PostHog events, as explained in §12.
- Email send logs at Resend, which are retained per Resend's own policy.
- Server access logs, which contain your IP address as part of ordinary HTTP logging and which expire on our hosting provider's schedule.
If the in-app deletion path fails for any reason, email support@romans122app.com and we will delete your account manually.
16. Accessing or exporting your information
To request a copy of the personal information we hold about you, or to ask us to correct it, email support@romans122app.com from the email address associated with your account. We will respond within a reasonable period, and in any case within the time required by the laws that apply to you (for example, 30 days under GDPR).
17. Children's privacy
Romans 12:2 is not directed to children. We do not knowingly collect personal information from children under 13 (or under 16 in the European Economic Area and the United Kingdom). If you believe that a child has provided us with personal information, email support@romans122app.com and we will delete it.
18. International data transfers
Our processors — including ElevenLabs, RevenueCat, Resend, Google Cloud, and Replit — may store and process your information in the United States and other jurisdictions outside your home country. By using the app, you understand that your information may be transferred to and processed in those jurisdictions, which may have different data protection rules than your own. Each of these processors maintains its own cross-border transfer terms in its privacy policy linked in §10.
19. Security
We take reasonable steps to protect your information, including:
- Encryption in transit. All traffic between the app and our servers, and between our servers and our processors, uses HTTPS / TLS.
- Hashed passwords. We never store your plaintext password. We store a salted scrypt hash.
- Secure on-device storage. Your authentication token is stored in the iOS Keychain (and the Android Keystore on Android, where applicable) using expo-secure-store.
- Access controls on our backend. Server credentials, third-party API keys, and connector credentials are managed through the hosting provider's secret store, not embedded in the app.
- Session caps. A maximum of five active sessions per account, so a stale device cannot accumulate access indefinitely.
No system is perfectly secure. If we ever become aware of a breach that affects your information, we will notify you in line with the laws that apply to us.
20. Your rights
Depending on where you live (for example, the EU/UK under GDPR or California under CCPA), you may have the following rights:
- Access. Ask us what personal information we hold about you.
- Correction. Ask us to correct inaccurate information. You can also edit your display name directly from the Profile screen; for changes to your email address, contact support.
- Deletion. Delete your account and the personal information tied to it (see §15).
- Opt-out of marketing. Toggle marketing and product email off on the Profile screen, or use the one-click unsubscribe link in any marketing email.
- Portability. Email us to request an export of your account data.
- Right to lodge a complaint with your local data protection authority.
To exercise any of these rights, email support@romans122app.com from the email address associated with your account. We will not discriminate against you for exercising your rights.
21. Changes to this policy
We may update this policy from time to time. When we make a material change, we will update the Last updated date at the top of this document and notify you in the app or by email before the change takes effect.
22. Governing law
[TO BE COMPLETED BY LEGAL COUNSEL] — the governing law and dispute-resolution clause for this policy is intentionally left as a placeholder for legal review.
Questions? Email support@romans122app.com.