Privacy

Privacy

No reader accounts. No advertising. No behavioral analytics. This policy explains the limited information used by panashe.org and the native apps.

Effective: July 18, 2026

Who operates Panashe

Panashe is the developer and service operator responsible for this website, the native mobile apps, and panashe.org. The core reader works without an account. Panashe services are used for the common daily Communion, suggestions, and diagnostics when they are enabled.

What stays on your device

The website or app stores your appearance and reading preferences, audio choices, last-opened book and chapter, and whether certain notices have been shown. If you take part in Communion, it also stores an app- or browser-generated installation identifier and a local record of each Scripture reference successfully submitted from that installation.

These records remain until you clear Panashe's site or app data or remove the app. Clearing local data does not immediately delete a suggestion, retained Communion record, or diagnostic already received by the server.

What a backup contains

A backup contains only reading preferences and the last-opened passage. It does not include the installation identifier, notice state, local Communion history, suggestions, or diagnostics.

Suggestions without an account

If you use the Suggestions form, Panashe receives the subject and message you choose to send. The form asks for neither a name nor an email address, and drafts are not deliberately persisted on the device. The server may store a daily, salted one-way hash derived from the request's network address to enforce an abuse limit; the application database does not store the raw address. Suggestions are retained for project review until they are manually removed.

Automatic diagnostics

When diagnostics are enabled and Panashe encounters an unexpected software error, it may send the platform, app and build version, an allowlisted error name, a route template when available, and a capped set of sanitised stack frames. Panashe does not send arbitrary error message text, full URLs, Scripture text, reading history, or suggestion text in these reports. The server may attach the same type of daily network hash for rate limiting. Diagnostic records are used only for reliability and are scheduled for deletion after 30 days.

Information when you connect

Cloudflare hosts, delivers, and protects Panashe, its API, and its application database. It processes the Communion submissions, suggestions, and diagnostic payloads described here on Panashe's behalf, along with ordinary request information such as an IP address, requested path, timestamp, headers, and general device characteristics. Connections to the Panashe API use HTTPS. Panashe requires service providers processing data on its behalf to protect it consistently with this policy and applicable law, and remains responsible for that processing.

Panashe uses daily, salted one-way network hashes for service protection. Because the same daily hash can protect Communion, Suggestions, and diagnostics, records from the same network on the same UTC day can carry the same anti-abuse value. Stored submissions and diagnostics are available only through protected administrative tools, apart from Scripture references intentionally shown in Communion.

Communion witnesses

When you bring a witness, Panashe receives the selected Scripture reference and the installation identifier generated by the app or browser. Before database storage, the server converts that identifier into a daily, salted one-way hash and may create a daily hash from the request's network address. These values enforce daily device and network limits without creating a public profile. The application database does not store the raw network address or reusable installation identifier.

When the day settles, the device hash is replaced with a non-reusable row marker and the network hash is removed. The date, submitted Scripture reference, creation timestamp, and row marker remain available through the live day and the previous three completed UTC days, then are deleted automatically.

What we do not collect

No reader accounts. No public profiles. No advertising identifiers. No behavioral analytics or tracking. The native iOS and Android apps do not process payments, collect payment information, or display external donation methods. Panashe does not sell personal information or build advertising profiles from reading.

Sharing, backups, and system services

On the native apps, Share Passage sends the selected passage to the device share sheet. On the website, Panashe uses the share interface when available and otherwise copies the passage and canonical link to the clipboard. These actions do not upload the passage to Panashe.

Backup export creates a JSON file containing the backup fields described above; web downloads it locally and native passes it to the system share sheet. Backup import uses a system file or document picker. Panashe does not receive these files, but an app or provider you choose may process them. Listening passes chapter text to the speech voice or service selected by the device.

Offline reading and network use

Prepared Scripture, the last-opened passage, and reader settings remain available offline after the relevant files are present on the device. Communion and Suggestions require a connection. Panashe requests the canonical daily passage so readers receive the same opening reading, with a prepared fallback when that service is unavailable.

The website requests the book files and paths needed to display what you open, so Cloudflare can process those paths as ordinary request data described above. Panashe does not use those requests to build reading-history analytics. Searches and reading progress are not submitted as analytics.

Third-party providers

Panashe uses Cloudflare for hosting, delivery, API infrastructure, and service protection. Panashe does not use Google Analytics, advertising pixels, or social trackers. Device speech, sharing, and document services act only when you choose those features. See Cloudflare's privacy policy for its own data practices.

The website's About page includes an external Ko-fi link and a Bitcoin-address copy action. Ko-fi receives information only after you choose to leave Panashe for its site. These support methods are not displayed in the native iOS or Android apps.

Retention, deletion, and contact

Local records remain until you clear Panashe's site or app data or remove the app. Diagnostics are scheduled for deletion after 30 days. Communion anti-abuse hashes are retired at settlement, and Communion records are deleted after the live day plus the previous three completed UTC days. Suggestions remain until manually removed.

For a privacy question, correction, or deletion request, email info@panashe.org. To locate a server record, include the approximate UTC date and the exact Scripture reference, suggestion subject, or distinctive text. Because Panashe has no accounts and does not ask for identity, a record may be impossible to identify without enough specific information.

Your choices

You may use the core reader without creating an account. You may choose not to send suggestions, participate in Communion, share passages, export backups, or use a device speech service. You may clear local data through browser or device settings or by removing the app.

Changes

This policy will be revised when collection, retention, providers, or product behavior changes. The effective date above identifies the latest version covering the website and native apps.

ChurchAboutPrivacy