Skip to content
Cadence

Privacy Policy

Effective

Cadence is a Bible reading plan app. This policy explains what the app collects, why it collects it, who else sees it, and how to get rid of it.

The short version: Cadence collects the minimum it needs to give you a reading plan that follows you between devices. There is no advertising, no third-party profiling, and nothing is sold or shared for advertising. The app contains no analytics or tracking SDK of any kind.

This website is the one place that differs, and it differs only with your permission: the marketing pages you are reading now can load Google Analytics, and do so only if you accept it. §12 explains exactly what that does and how to change your answer.

Cadence is offered in the United States. It is operated by Kerr Ventures LLC, which is the company responsible for the information described here and for both the app and this website.

1. What we collect

Your email address. You sign in by asking for a link sent to your email. There is no password. Your email address is held by our authentication provider (Supabase) and stored alongside your profile so we can identify your account.

Your reading plans. The name of each plan, the books and passages it covers, the date each day falls on, and which readings you have marked as done. This is what makes your progress and your streak work.

Your app preferences. Your chosen translation, reader layout, text size and font, whether notifications are on, the time you set for the daily reminder, and your device’s timezone. See §3 for what the timezone is used for — it is used for two things, not one.

Group information, if you join a group. The display name you choose for that group, which group you are in, whether you have turned progress sharing on, and your own copy of the group’s plan.

Group messages and reactions. Anything you post in a group discussion, which day of the plan it relates to, what it is a reply to, and any emoji reactions you add. Other members of that group can see these.

The description you type for an AI-generated plan. If you use the “describe your plan” feature, the words you type are sent to Anthropic to build the schedule. We ask for your permission before the first time this happens, and you can build a plan by hand instead without any text leaving the app.

Because that box is free text, it can contain anything you choose to put in it, including personal or sensitive information. Please do not put anything confidential in it. We do not store what you type. It is held in memory for the length of the request, passed to Anthropic, and then gone — unless you later choose to report the plan it produced, which is the one exception and is described in the next paragraph. What we do store is the plan that comes back: its name, and the day-by-day schedule of passages and labels the model produced.

There is one exception, and it only happens if you ask for it. If an AI-generated plan comes out wrong, the Plans tab offers to report it. Until you tap that, the description that produced the plan is kept on your phone and nowhere else — we never receive it. If you do report a plan, we then store that one description, the plan it produced, and any note you add, so we can work out what went wrong. You are shown exactly what will be sent before it is sent, and nothing is sent if you back out. Reporting one plan does not send us any of your others.

A push notification token, if you turn notifications on. This identifies your installation of the app so a notification can be routed to it. It is not an advertising identifier: no other app can read it, and it goes to no advertising network.

Moderation records. If you block another reader or report a message, we store that so we can act on it and keep the block in effect. A report also stores a copy of the reported message’s text as it was at the moment you reported it, so that deleting a message is not a way to erase a complaint about it.

At most once a day, and only when something has actually been reported, our servers email a summary to our own support address, so that a person sees a report rather than it waiting for someone to go looking. That summary contains internal reference numbers for the reported message, the group it is in and the account that posted it, together with the reason chosen, how many people reported it, and when. It does not contain the message, and it does not identify who reported it. Reporting is never announced to the group or to the group’s creator — in a small group that would identify the reporter by elimination.

Basic operational records. When something goes wrong on our servers we record the kind of error, the route it happened on, a status code and a count, and — where the request was signed in — the account id it belonged to. These records hold no message text, no request body, no email address and no IP address.

Which version of the app is in use. Each request tells our servers which version of Cadence sent it, and we keep a daily count of how many requests came from each version. It is how we know whether a fix has reached people before we rely on it. These counts are not attached to your account: the record is a number per version per day, with nothing in it that says which requests were yours.

Crash reports. If a screen in the app stops working, the app sends us a short technical record of the failure: the type of error, its message, the names of the on-screen components involved, when it happened and how many times, and which version and update of the app was running. A crash report has no field for your email address, your plans, your progress, your group messages or the text of a passage — we do not put any of those in it, and it carries no account id. The one part that is free text is the error message, which is written by the software that failed rather than by you. It is filtered on your device before it is sent: quoted values, email addresses, web links and long numbers are removed, and what remains is cut to 300 characters. We have written that filter to be cautious and we check the app’s own error messages against it, but it is a precaution rather than a guarantee about every message the software could ever produce. Crash reports go to our own servers. There is no crash-reporting or analytics service in the app — though, as with everything else, the company that hosts our servers necessarily processes the report in the course of storing it for us.

What your reading may reveal

Cadence never asks your religion and has no field for it. But what you read, when you read it, and which groups you join can suggest or reveal religious belief, and we treat that information with that in mind. It is not used for advertising, it is not profiled, and it is not sold or shared. Reading progress is shown to other people only if you turn that on (§4).

What we do not collect

  • We do not use any analytics, advertising, attribution or tracking SDK in the app. There are none in it, and every dependency was reviewed one at a time to be able to say so. This website is a separate thing and does use Google Analytics, with your consent — see §12.
  • We do not access GPS or any precise location. We do collect your device’s timezone, which suggests a broad region — see §3.
  • We do not collect an advertising identifier of any kind, and the app never shows the iOS tracking prompt because there is nothing to track.
  • We do not collect your contacts or photos.
  • We do not require your legal name. You choose a display name for each group, and it does not have to be your real name — though it will be your real name if you choose to make it so.
  • We do not ask for your date of birth, address, or payment details.
  • We do not store your IP address. Our servers keep no IP address in any table.
  • We never see or store your password, because there isn’t one.

2. Why we collect it

What Why
Email address To sign you in and to identify your account
Plans and completion marks To show you today’s reading, your progress and your streak
Preferences To make the app work the way you set it up, on any device
Timezone To decide which calendar day is “today” for you, and to meet a licence condition (§3)
Group membership and display name So the group can show who is in it
Messages and reactions To deliver group discussion
Progress sharing setting To decide whether the group can see that you finished a day
AI plan description To generate the plan you asked for. Sent to Anthropic; not stored by us
Blocks and reports To enforce a block and to review reported content
Push token To deliver the notifications you turned on (§3)
Operational records To find and fix faults, and to prevent abuse
App version counts To know whether a fix has reached people, and what is still running
Crash reports To find out that the app is broken for someone, and fix it

3. Two things worth being precise about

Notifications: what is sent from where

Every notification Cadence sends comes from our servers. This used to be split — the daily reminder was scheduled by your own device and never touched the internet — and it changed on 4 September 2026, so if you have read this section before, this is the paragraph that is different.

The daily reminder is sent by our servers now. To decide whether to send it at all, our server looks at the plans on your account and asks whether the day’s reading is still unfinished; it is not sent on a rest day, or after you have already read. Your device cannot answer that question at the moment a notification fires, which is why the reminder moved. The cost of that is what this section has to be plain about: the reminder now travels over the internet, so it needs a connection and a registered device, and it can arrive up to half an hour after the time you chose.

Group and streak notifications are sent by our servers too. Three further kinds: someone posted in a group discussion, someone in your group finished a day’s reading, and a reminder that your streak is still open in the afternoon. All four are delivered through Expo’s push notification service, which passes them to Apple’s Push Notification service on iOS or Google’s Firebase Cloud Messaging on Android. Each of those companies handles the notification in order to deliver it to your device.

What we send with a notification is deliberately thin: a title, a short line of text, and a routing hint saying which screen to open. The message you would be notified about is not in it — a discussion notification says that somebody posted, not what they said. No account id and no passage text is included.

Turning notifications on enables all three kinds. You can turn each of them off separately in Settings, and turning the main switch off stops all of them.

When we delete the push token. We delete it when you turn notifications off, when you sign out on that device, when you delete your account, and when Apple or Google tells us through Expo that the app is no longer installed.

Two honest qualifications. Turning notifications off or signing out sends us a request to remove it, and if your device has no connection at that moment the request cannot arrive — signing out still works, and the token is then removed the next time one of the other events happens. And a token identifies an installation of the app rather than a person, so if someone later signs in to a different Cadence account on the same device, that token becomes theirs.

Timezone

Your timezone is used for two things.

The first is obvious: deciding which calendar day counts as “today” for you, so a reading marked done at 11pm counts for the right day.

The second is a licensing condition and we would rather state it than let you discover it. The King James Version is under Crown copyright in the United Kingdom, and our Bible text provider’s terms require us not to serve it to readers there. Your timezone is the only location-like signal Cadence has, so we use it to identify readers in the United Kingdom, the Crown dependencies and the British Overseas Territories, and to move those readers to a different translation. We do not use your timezone for anything else, and we do not derive or store a country from it.

4. Who can see your reading progress

By default, no other Cadence user. When you create or join a group, Cadence asks whether the group may see when you finish a day, and the answer defaults to no. If you leave it off, other members of the group see your display name and nothing about your reading — and that is enforced on our servers, not just hidden in the app, so it is not in the data your app receives either. If you turn it on, they can see whether you have finished each day’s reading and you count towards the group’s daily total; your streak and your day-by-day calendar are still not shared. You can change this at any time in the group’s screen.

Groups are reachable only by an invite code. There is no public directory of groups, and no way to search for a person.

This is about other Cadence users. It does not mean nobody at all: the people and companies in §5 process your information in order to run the service.

5. Who else receives your information

We use a small number of service providers to run Cadence. We do not sell your personal information, and we do not share it for cross-context behavioural advertising.

One of them is an advertising company: Google, which provides the website analytics described below. That is precisely why this website asks before it loads anything of Google’s, and loads none of it if you say no. Every other provider listed here is not an advertising network and none of them is sent anything for advertising.

Each of them is bound by a contract requiring them to protect your information with privacy and security protections consistent with this policy, to use it only to provide their service to us, and not to use it for their own purposes.

Other members of a group you join see your display name, your messages and reactions, and — only if you turn it on — whether you finished each day’s reading.

Kerr Ventures personnel. People working for us can reach the database in order to operate the service, and can review a reported message and the account identifiers attached to it in order to act on the report. Access is limited to what the job requires.

Supabase — handles sign-in, issues the sign-in link sent to your email address, and hosts the database that stores your plans, groups and messages.

Railway — hosts our API servers and, as the company running them, processes the traffic that reaches us, including the network address your device connects from.

Cloudflare — hosts this website, and runs the email routing for support@cadencebible.app, so it handles messages you send us there, including a request to delete your account.

Google (Analytics) — on this website only, and only if you accepted it. Google Analytics records that a visit happened, which pages of this site it touched, roughly what part of the world it came from, and what kind of browser and device it used. It stores cookies in your browser so that a return visit can be recognised as the same one. Google works the rough location out from the network address your device connects from; it does not pass that address to us, and we never see it.

We run no advertising in Cadence — not on this website and not in the app — and we do nothing with these figures beyond reading them. No profile is built here, and nothing collected is joined to your account, because the two are never connected in the first place.

What Google does with what it collects is governed by Google’s own terms and privacy policy rather than by anything we can promise you, and those are worth reading if this matters to you. The control that does not depend on Google is the one in §12: decline, and none of Google’s code ever runs.

What it never sees is as important: Google Analytics runs on the marketing pages and nowhere else. It is not in the app, it is not in the reader, and it is never given your account id, your email address, your plans, your progress, your groups, or anything you read.

Anthropic — when you use the “describe your plan” feature, the description you type is sent to Anthropic’s API to generate the schedule. Only the text of that description is sent: no account id, no email address, no plans, no progress and no group messages go with it. If you would rather no text left the app this way, use the manual builder instead, which builds the plan on your own device and sends nothing to Anthropic.

Crossway (the ESV API) and API.Bible — supply the Bible text you read. When you open a reading, the passage reference (for example “John 3”) is sent to whichever service provides your chosen translation. The request comes from our servers, not from your device, and your email address and account id are never sent.

For the translations supplied by API.Bible, their licence requires us to report usage to their Fair Use Management System so publishers can count readers. We send a pseudonym with each report — a one-way salted hash of your account id, not the id itself and not anything that identifies you — along with the tokens their service returns for the passages served. The same reader produces the same pseudonym over time, which is the point of it: it lets a publisher count people rather than requests. This applies to API.Bible translations only; the ESV has no equivalent mechanism.

Expo — delivers the notifications described in §3, and also serves the over-the-air updates that keep the app current, which your device fetches directly from Expo.

Apple (Push Notification service) and Google (Firebase Cloud Messaging) — carry a notification the last step to your device, as described in §3.

Resend — delivers the email Cadence sends. That is two things and only two.

The first is your sign-in link, so Resend handles your email address every time you sign in. The link itself is issued by Supabase; Resend is the service that carries the message to your inbox.

The second is the daily summary of reported messages described in §1, which goes from our servers to our own support address. That one never carries your email address, your plans, your progress, or the text of any message.

Nothing else goes through Resend — not your daily reminder, which is a push notification rather than an email (see §3), and no marketing, because we do not send any.

If Cadence is sold, merged or transferred, your information may transfer with it as part of that business. If that happens, we will say so on this page before it takes effect, and the information stays subject to a policy at least as protective as this one.

We may also disclose information where we are legally required to, or where it is reasonably necessary to investigate a safety problem, prevent fraud, or enforce our terms.

6. Where data is stored

Cadence’s database and servers are in the United States, and Cadence is offered in the United States.

The website analytics described in §5 are processed by Google, on Google’s own infrastructure in the United States and elsewhere. If you are visiting from the UK or the EEA, that transfer happens only because you agreed to it, and it stops when you withdraw.

7. Deleting your account

You can delete your account from Settings → Delete account in the app. The app tells you what will go before you confirm.

Account data is removed from our active systems when the deletion completes. That includes your account and profile, your sign-in identity, every plan you have made and everything you marked done, your group memberships, your messages and reactions, your push notification tokens, the blocks you made and the blocks made against you, and any groups you created — which deletes them for everyone else in them too. It also includes any report about one of your messages, and the stored copy of that message’s text.

Limited copies may remain temporarily in encrypted backups or in a service provider’s systems, and are deleted on the schedule in §8. We may retain narrowly limited information where reasonably necessary for an active safety investigation, to prevent fraud, to enforce a suspension, or to meet a legal obligation.

Deletion happens in two systems — the one that owns your sign-in and the one that owns everything you have done — and in rare cases the second step can fail after the first has succeeded. If that happens the app tells you so and asks you to try again; your data is already gone, and trying again removes the sign-in identity. If you are ever unsure, email us and we will confirm.

If you would rather ask us to delete your account for you, email support@cadencebible.app from the address you signed up with.

You can also delete an individual message you posted, or an individual plan, without deleting your account.

8. How long we keep things

What How long
Your plans, groups, messages, reactions and preferences For as long as your account exists; deleted when you delete it
The description you type for an AI plan Not stored by us at all. Anthropic applies its own API retention, which under its standard commercial terms is up to 30 days, subject to safety and legal exceptions
A plan you chose to report as wrong, with the description that produced it and any note you added 90 days
Moderation reports and the stored copy of a reported message Until either the reporting or the reported account is deleted, and in any case no longer than 12 months
Push notification tokens Until you turn notifications off, sign out on that device, delete your account, or the app is uninstalled — whichever comes first
Operational error records (including the account id, where there is one) No longer than 30 days from when the record is written
Crash reports No longer than 30 days
App version counts No longer than 30 days
Records of notifications we sent 7 days
Encrypted database backups 30 days
Email you send to our support address Up to 24 months, unless we need it longer for a legal reason
Counts of how much the AI and Bible-text services were used Kept indefinitely. These are totals per day with no account, device or person in them

The 90-day, 30-day and 7-day periods above are enforced by jobs that run automatically, and the limits are fixed in the app’s source code rather than in a settings dashboard, so that the number published here cannot quietly be changed to a different one.

About backups. We take an encrypted backup of the database every night and keep each one for 30 days. A backup taken before you deleted your account still contains your data until it expires. We do not use backups to restore individual accounts, and a deleted account is not brought back by one.

9. Children

You must be at least 13 years old to use Cadence, which is the same rule as our Terms of Use. We ask you to confirm this when you create an account.

Cadence is a general-audience service. It is not directed at children, it is not offered in the App Store Kids Category, and we do not knowingly collect information from anyone under 13. If we learn that an account belongs to someone under 13, we will suspend it and delete the account and its information.

If you believe a child under 13 has given us information, email support@cadencebible.app and we will delete it.

10. Security

Traffic between the app and our servers is encrypted in transit. Your sign-in session is held in your device’s secure storage. Database backups are encrypted. Sign-in is by emailed link, so there is no password to be reused or stolen. No system is perfectly secure, but we do not store anything we do not need.

11. Your choices and your rights

Reviewing and correcting your information. Your email address, display names, preferences and plans are all visible in the app and can be changed there. If you want to see or correct something the app does not show you, email support@cadencebible.app from the address you signed up with and we will help.

Deleting your information. See §7. You can delete your whole account from inside the app, or ask us to do it for you.

Notifications. You can turn them on or off, in whole or by kind, in Settings, and in your device’s own settings.

AI. We ask before the first time anything you type is sent to Anthropic, and the manual plan builder is always available as an alternative that sends nothing.

Website analytics. Use Cookie settings, at the foot of any page of this site, to turn Google Analytics on or off. It is as easy to withdraw as it was to give, it takes effect immediately, and turning it off also clears the cookies that were set. This is a per-browser setting, because it is stored in the browser rather than on your account.

Depending on where you live, you may have additional rights over your personal information. Email us and we will honour them.

12. Tracking, and “Do Not Track”

Cadence does not track you across other companies’ websites or apps for advertising, and does not permit advertising networks to collect information through Cadence.

The app collects nothing of this kind at all. No analytics SDK, no attribution SDK, no advertising identifier, and no tracking prompt, because there is nothing to prompt about.

This website is the exception, and only if you agree. If you accept the banner, Google Analytics sets cookies in your browser and reports your visits to this site to Google, as described in §5. That is analytics — counting visits and seeing which pages people find useful — rather than advertising: we run no ads anywhere in Cadence and build no profile of you. It covers the pages of this website and never reaches into the app.

If you decline, or close the banner without answering, none of Google’s code is loaded and no request is made to Google at all. Declining does keep one small record in your browser — your answer, and nothing else — so that we can honour it without asking again on every page. Closing the banner without answering keeps nothing, and you will be asked again.

Visitors in the UK and the EEA are asked before anything loads. Everywhere else analytics starts on, and Cookie settings at the foot of any page turns it off.

Because the app does no tracking, and because this website’s analytics are governed by the banner rather than by a request header, browser “Do Not Track” signals do not change how the service operates. Cookie settings is the control that does.

Cadence does not sell personal information, and does not share it for cross-context behavioural advertising.

13. Changes to this policy

If we change this policy we will update the effective date at the top of this page. If a change materially affects how we handle your information, we will say so in the app before it takes effect, so that you can read it and decide.

14. Contact

Cadence is operated by Kerr Ventures LLC, which is responsible for the information described in this policy.

Kerr Ventures LLC
808 Ribbonleaf Lane
Fuquay Varina, NC 27526-3718
United States

Questions about this policy, or about your data: support@cadencebible.app.

Email reaches us faster than post does, and it is the right route for anything about your account or your data.