Privacy Policy
Last updated: August 13, 2026
Scroll & Cross ("we", "our", or "the app") is a free Bible study application. We are committed to protecting your privacy. This policy explains what data we collect, how we use it, and your rights.
1. Information We Collect
1.1 Data You Provide
- Account information: If you sign in (optional), we store your email address to enable cloud sync of your bookmarks, notes, and highlights. Each sign-in request is also recorded with the email address requested and the IP address it came from, so we can rate-limit abuse of the sign-in email.
- Bookmarks, notes, and highlights: Stored locally on your device. If you opt into cloud sync, they are also stored on our servers.
- Devotional listening history: If you are signed in, we record which devotional readings you have listened to, so that list stays in sync across your devices.
- Feedback: If you submit feedback through the app, we store your name, email address, message, and the IP address the message was sent from, and we email a copy to ourselves.
- Giving: If you make a donation, the email address you enter is passed to Stripe with the payment, and the IP address of the request is recorded so we can rate-limit abuse.
1.2 Data Collected Automatically
- Usage analytics: We record which books, chapters, and verses are opened, which translation is selected, which views (maps, timeline, quiz, devotionals, sermons) are used, share actions, the length of search queries (never the query text itself), the hostname of the site that referred you, and timestamps. Each event carries a random session identifier that lives only in the current browser tab and is not linked to your account or email address.
- Approximate location: Our server attaches the country, region, city, continent, and time zone that Cloudflare derives from your IP address to every analytics event, so we can see roughly where readers are. This is an IP-based estimate, city-level at best — the app never asks for device or GPS location.
- IP address and browser information: As with any website, our servers receive your IP address and browser user agent with every request, and use them to serve the site and limit abuse. Analytics ingestion stores only a rotating hourly hash of your IP address, never the raw address; the sign-in, feedback, and giving records described above do store the raw address.
- Crash reports: When the app hits an unexpected error, it sends us the error message, the technical stack trace, the address of the page it happened on, your browser user agent, the platform (web, iOS, or Android) and the app version, and our server records the IP address the report came from. No account or email address is attached, and nothing is sent unless something goes wrong.
- API.Bible usage reporting: When you read or listen to a chapter in CSB, GNT, or NASB 2020, your browser loads a reporting pixel from API.Bible (their FUMS reporting, required by their licence). It carries a usage token for that chapter, a random device identifier stored in your browser (the
fumsDeviceId value, kept until you clear site data), and a random per-tab session identifier. Because your browser makes that request directly, API.Bible also receives your IP address and user agent.
1.3 Data We Do NOT Collect
- We do not collect precise or device location — no GPS, and the app never asks for location permission (see the IP-based estimate described in section 1.2)
- We do not access your contacts, photos, or files
- We do not use advertising trackers, ad networks, or cross-site tracking cookies
- We do not sell any data to third parties
2. How We Use Your Data
- To provide cloud sync of your bookmarks, notes, and highlights across devices
- To authenticate your account via magic link sign-in
- To respond to feedback you submit
- To improve the app based on aggregated usage patterns, including which passages are read and roughly which countries and cities readers are in
- To diagnose and fix the errors reported by the crash reports described in section 1.2
- To rate-limit sign-in emails, feedback, giving requests, and analytics traffic so the service is not abused
- To report translation usage to API.Bible, as their licence requires
3. Third-Party Services
The app uses the following third-party services:
- Cloudflare: Hosting, content delivery, and the database our servers write to. Cloudflare also supplies the IP-based country, region, and city estimate described in section 1.2. Subject to Cloudflare's Privacy Policy.
- Crossway (ESV API): ESV Bible text is fetched by our server rather than by your browser, so none of your personal data is sent to Crossway. Subject to Crossway's Privacy Policy.
- API.Bible: CSB, GNT, and NASB 2020 chapter text and audio are fetched by our server, but the usage-reporting pixel described in section 1.2 is loaded by your browser, so API.Bible receives your IP address, user agent, and the random device and session identifiers. Subject to API.Bible Terms.
- Stripe: If you choose to give a donation, payment processing is handled by Stripe, which receives the email address you enter. We never see or store your full card number. Subject to Stripe's Privacy Policy.
- Brevo: Used to send magic link sign-in emails and our own notification emails; it receives the recipient email address and the message. Subject to Brevo's Privacy Policy.
- Resend: Fallback email provider, used when Brevo is unconfigured or rejects a message; it receives the same email address and message. Subject to Resend's Privacy Policy.
4. Data Storage and Security
- Local data (bookmarks, notes, highlights, reading history) is stored on your device using browser storage and is never sent to our servers unless you enable cloud sync.
- Cloud-synced data is stored in a Cloudflare D1 database with access restricted to authenticated users only.
- Analytics events are stored in that same database, and the dashboards that query them are restricted to approved administrator accounts.
- All data transmission uses HTTPS encryption.
- We do not store passwords — authentication uses secure magic links sent to your email.
5. Data Retention
- Local data persists until you clear your browser/app data.
- Cloud-synced data is retained as long as your account exists.
- Sign-in, feedback, and giving rate-limit records (email address and IP address) are deleted automatically after 24 hours.
- Feedback messages, including the IP address they were sent from, are kept until you ask us to delete them.
- Crash reports, including the IP address they were sent from, are deleted automatically after 30 days.
- Analytics events, including the approximate location attached to them, are retained indefinitely. They are not linked to your account or email address, so we cannot single out and remove an individual person's events on request.
- You can delete your synced data at any time by contacting us.
6. Children's Privacy
Scroll & Cross does not knowingly collect personal information from children under 13. The app is suitable for all ages but account features (sign-in, sync) are intended for users 13 and older.
7. Your Rights
You have the right to:
- Access the personal data we hold about you
- Request deletion of your data
- Opt out of cloud sync at any time (your data remains local)
- Use the app without creating an account
8. Changes to This Policy
We may update this privacy policy from time to time. Changes will be posted on this page with an updated date. Continued use of the app after changes constitutes acceptance.
9. Contact Us
If you have questions about this privacy policy or your data, contact us at:
Email: support@scrollandcross.com
Website: scrollandcross.com
See also our Terms of Service.