Privacy Policy
Last updated: 9 August 2026
Bible Flame
Contact: hello@bibleflame.org
Who We Are
Bible Flame is a Bible study app designed for Coptic Orthodox Sunday school students. It is operated by Bible Flame ("we", "us", or "our"). This policy explains what information we collect, how we use it, and your rights.
If you have any questions, contact us at hello@bibleflame.org.
Who Uses Bible Flame
Bible Flame is designed for children. Children do not create their own accounts. All accounts are created by authorised Sunday school teachers or administrators. Teachers create a child's account using only the child's name; the system generates a username and PIN, which the teacher then gives to the child. Children never enter personal information themselves.
What Information We Collect
Information created by teachers when setting up a child's account
- Display name (the child's full name, entered by the teacher)
- Username (auto-generated by the system)
- PIN (4-digit PIN, auto-generated and stored in hashed form — we cannot read it)
- Cohort and class (the cohort, and optionally the class, the child is assigned to)
- Church (the church the child belongs to)
Information collected automatically when the app is used
- Lesson activity — which lessons were completed, quiz answers submitted, and scores
- Verse recitations — which verses were recited and whether they were scored correctly
- Streaks — consecutive days of lesson completion (calculated from activity data)
- Stickers and badges earned — collectible rewards unlocked through lesson completion
- Timezone — your device's local timezone, used to correctly calculate daily streaks (e.g. so a lesson completed at 11pm counts as that local day, not the next UTC day)
- Journal responses — free-text answers a child writes in their own words in response to reflection questions. These are stored exactly as typed
A note about free-text answers. A journal response is written by the child, so we cannot control what it contains. It is the only place in the app where a child types freely — reactions on the Community Board are a fixed set of five, and the report form offers a short list of reasons with no free-text box. We ask teachers to remind children not to type personal details such as a home address, phone number or email address. If you believe a journal response contains personal information that should be removed, contact us at hello@bibleflame.org and we will delete it.
Speech recognition (verse recitation feature)
When a child recites a Bible verse:
- The device's microphone captures speech locally on the device
- On iPhone/iPad: speech is processed entirely on-device — audio never leaves the phone
- On Android: on Android 12 and above, speech is processed on-device; on older Android devices, speech may be processed by Google's on-device speech service
- We do not record or store audio. Only the text transcript is sent to our server for scoring
- The transcript is not stored. It is sent to our server, used to score the recitation, and then discarded. We keep only the date of the recitation and whether it was scored correctly
What we do NOT collect
We never ask for, and our system never records, any of the following. The one exception is a child's own journal response, which we cannot filter — see the note above.
- Email addresses from children
- Phone numbers
- Photos or camera data
- IP addresses
- Device identifiers (advertising IDs, hardware serial numbers)
- GPS or location data
- Contacts or calendar data
Sharing on the Community Board
Some Bible studies include a reflection question with a free-text answer — a journal response. By default a journal response is private: visible only to the child who wrote it, and to their Sunday school teachers and church administrators.
A child may choose to share an individual response to the Community Board, a feed inside the app. Sharing is never automatic and is never on by default — the child makes the choice for each response separately.
Each church administrator chooses how the Community Board works for a group, and there are three settings:
- Off — there is no board. Nothing can be shared, and the feed does not appear in the app. This is the setting a group has unless an administrator turns the board on.
- Reviewed — a shared response goes to a teacher or church administrator first. Until they approve it, only the child who wrote it and the leaders can see it.
- Open — a shared response appears on the board straight away, without review. Leaders can still remove it afterwards.
Ask your Sunday school which setting your child's group uses.
When a response is visible on the board:
- It is visible to other children in the same cohort — the group that child studies with — shown alongside their display name and their avatar. It is not visible to children at other churches, or in other cohorts.
- Avatars are not photographs. A child's avatar is generated automatically from their account; no photo is ever uploaded or stored.
- Other children in that cohort can react to it, using a fixed set of five reactions. There is no free-text commenting on the board.
- A child can unshare their own response at any time, which removes it from the board and makes it private again.
- A teacher or administrator can remove a post at any time. Removal is permanent — a removed post cannot be shared again by the child.
Children can also report a post they believe is inappropriate, choosing from a short list of reasons; there is no free-text box on the report form. They can block another child so that the two no longer see each other's posts. We keep a record of reports (which reason was chosen, and when) and of blocks, so that leaders can act on them and so that a block stays in effect.
If an administrator turns the board off for a group, the feed disappears from the app immediately and previously shared responses stop being visible to other children.
How We Use This Information
| Information | How it's used |
|---|---|
| Name, username, PIN | To identify the child and allow them to log in |
| Lesson activity and scores | To show progress to the child, calculate points and rewards, and help teachers see how students are going |
| Timezone | To correctly calculate daily and weekly streaks |
| Verse transcripts | To score recitations and award halos |
| Stickers and badges | To track collectible rewards earned |
| Journal responses | To let a child review their own reflections, and to let their teachers read and respond to them |
| Shared posts, reactions, reports and blocks | To operate the Community Board, to let leaders moderate it, and to keep a block in effect |
We do not use any of this information for advertising, profiling, or any purpose other than operating the app.
Analytics
We use PostHog for optional usage analytics. When enabled, this records events such as "lesson completed" or "verse recited" along with the lesson or verse identifier, score, and app version.
PostHog is configured to:
- Not collect IP addresses
- Not collect device identifiers
- Not collect geolocation
Analytics can be disabled entirely by the app operator via a server environment variable.
Who We Share Information With
We do not sell, rent, or share children's personal information with third parties for commercial purposes.
Within the app, a journal response that a child chooses to share becomes visible to other children in their cohort — see Sharing on the Community Board above. Nothing else a child does in the app is visible to other children.
Outside the app, we use the following services:
| Service | What is shared | Why |
|---|---|---|
| Neon (PostgreSQL hosting) | All app data | Encrypted database hosting |
| AWS S3 | Lesson audio and images uploaded by teachers | Media file storage — no child PII in these files |
| PostHog (optional) | Anonymised usage events | Analytics — no IP, no device ID, no name |
| Expo | App binary | Mobile app deployment platform — no runtime data collection |
Children's Privacy (COPPA and Australian Privacy Act)
Bible Flame is designed for children and we take this responsibility seriously.
- No self-registration. Children cannot create their own accounts. All accounts are created by authorised adults (teachers or church administrators).
- No email or contact information requested from children. The only identifying information we ask for is a display name, entered by the teacher; login credentials are generated by the system. Children are never asked for an email address, phone number or address. The one place a child types freely is a journal response, and we ask teachers to remind children not to include personal details there.
- Child-to-child visibility is off by default and always opt-in. A child's work is private unless they choose to share it, one response at a time. The Community Board is switched off for a group unless a church administrator turns it on, a child can unshare a response at any time, and leaders can remove any post.
- Parental/guardian rights. Parents or guardians may request to review, correct, or delete their child's information by contacting us at hello@bibleflame.org or by asking their Sunday school teacher to access the admin portal.
- Account deletion. Teachers and administrators can delete a child's account at any time. Deletion removes all associated data immediately and permanently — lesson history, scores, journal responses, shared posts, stickers, and badges — with one exception, described under Data Retention below.
- Data minimisation. We collect only what is necessary for the app to function.
If you believe we have inadvertently collected information from a child without appropriate authorisation, please contact us immediately at hello@bibleflame.org and we will delete it promptly.
Data Retention
Data is retained for as long as a child's account is active. When an account is deleted, all associated data is deleted immediately and permanently — lesson history, scores, journal responses, shared posts, reactions, stickers, badges, and saved logins. There is no retention period, and we do not archive deleted accounts.
One exception — the administrative activity log. We keep a security log of administrative actions: who created, updated or deleted an account, and when a login succeeded or failed. Because a record of a deletion has to outlive the account it describes, these entries keep the display name, the date and time, and which platform was used (iOS, Android or web). They contain no lesson content, no journal text, no scores, and no contact details. To request removal of a child's name from this log, contact us at hello@bibleflame.org.
Security
We protect data using:
- Encrypted HTTPS connections for all data in transit
- Hashed PIN storage (PINs are never stored in readable form)
- Rate-limited login (5 failed attempts triggers a 15-minute lockout)
- JWT session tokens with expiry
- Encrypted database hosting (Neon)
Your Rights
Parents, guardians, and authorised church administrators may:
- Access — request a copy of the information held for a child
- Correct — ask us to correct inaccurate information
- Delete — request deletion of a child's account and all associated data
- Withdraw — ask us to remove the child from the app
To exercise any of these rights, contact us at hello@bibleflame.org or speak to your Sunday school teacher who can take action directly through the admin portal.
Request Account Deletion
To request deletion of your child's account and all associated data, email us at hello@bibleflame.org with your child's username and the name of their Sunday school.
We will action all deletion requests within 7 days. Deletion removes all associated data immediately and permanently — lesson history, scores, journal responses, shared posts, stickers, and badges — with one exception, described under Data Retention above.
Alternatively, any authorised Sunday school teacher or administrator can delete a child's account directly through the admin portal at any time.
Changes to This Policy
We will post any updates to this page and update the "Last updated" date at the top. If changes are significant, we will notify church administrators directly.
Contact
Bible Flame hello@bibleflame.org bibleflame.org