Privacy

Privacy

No reader accounts. No advertising. No remote reading analytics. Optional reading preferences learn only on your device. This policy explains the limited information used by panashe.org and the native apps.

Effective: October 10, 2026

Who operates Panashe

panashe.org is the developer and service operator responsible for this website, the native mobile apps, and the Panashe services they use. The core reader works without an account. On the website, Panashe services receive passages you choose to share with Communion, suggestions, and diagnostics when they are enabled. The Apple app sends nothing to Panashe.

What stays on your device

The website or app stores your appearance and reading preferences, audio choices, last-opened book and chapter, whether certain notices have been shown, and your journey: the daily devotion chosen for you each day, the hour it was first opened, and the passages you bring to it in Communion. Your devotion is chosen on the device from a random seed stored with the journey. If you share a passage on the website, the browser also stores a generated installation identifier and a record of what it shared.

The Apple app also stores your Covenant stage and Scripture-mode progress, including the current reading position, completed chapters, days read, credited reading or listening duration, pace samples, and mode/reset state. These records support continuing your reading and are not sent to Panashe.

These records remain until you clear Panashe's site or app data or remove the app. Clearing local data does not delete a suggestion or diagnostic already received by the server. On Apple devices, some of these records can also be kept in your own iCloud account, as described below.

Personalize Daily readings is off by default. If you turn it on, the app keeps broad passage themes and a hashed reference key with capped reading time while Scripture is visible, the app is in front, and you have interacted recently. The profile retains at most 28 days, 32 entries per day, two minutes per entry per day, and ten minutes per day. It contains no Scripture text. Reference hashes are not a guarantee of anonymity. This information never leaves the device, is excluded from backups and iCloud synchronization, and is deleted when you turn the preference off or choose Forget reading preferences. Time spent does not measure understanding, belief, or readiness for harder passages.

What a backup contains

A backup contains reading preferences, the last-opened passage, the journey of devotions and Communion, Covenant stage, and Scripture-mode state and progress when present. It does not include notice state, suggestions, or diagnostics. Restoring combines journey and Scripture progress with existing records; ordinary preferences and saved positions are restored from the backup.

iCloud on Apple devices

If you are signed in to iCloud, the Apple app keeps the same records a backup contains in step across your own Apple devices: your reading preferences, the last-opened passage, your journey of devotions and Communion, Covenant stage, and Scripture-mode state and progress. Journey and Scripture progress use explicit merges. It does this with iCloud key-value storage, which Apple operates under your Apple Account and its own privacy policy. Panashe does not receive these records and cannot read them.

To stop syncing, turn off iCloud for Panashe in your device's iCloud settings, or sign out of iCloud. The app keeps working, with everything stored only on the device. Removing the app from a device does not delete the copy kept in iCloud.

Widgets, Watch, Messages, Siri, Spotlight, and Handoff

On Apple devices, the app stores a snapshot of today’s devotion reference and words in its shared App Group for the widget and Messages extension on the same device. The Watch app receives a snapshot from your iPhone through Apple WatchConnectivity and stores it on your watch. These snapshots are not sent to Panashe. The Messages extension sends a passage through Apple Messages only when you choose to send it; Apple and the recipient process the message under their own services.

Spotlight indexes the name, title, and introduction of each chapter in your chosen translation on the device, so you can find a chapter from search. It does not index your journey or Communion. When you ask Siri or Shortcuts to open today's reading, continue reading, or read today's passage aloud, Siri handles your request under Apple's privacy policy, and the app answers on the device.

Handoff offers the chapter on screen, its book and number only, to your other Apple devices signed in to the same Apple Account. Apple carries it between your devices. If the other device does not have Panashe, it may open that chapter on panashe.org, where the website sections of this policy apply.

A panashe.org link can open the matching screen in the Apple app. To allow this, Apple fetches a small association file from panashe.org that names the app; the app itself sends nothing to Panashe.

Suggestions without an account

If you use the Suggestions form, Panashe receives the subject and message you choose to send. The form asks for neither a name nor an email address, and drafts are not deliberately persisted on the device. The server may store a daily, salted one-way hash derived from the request's network address to enforce an abuse limit; the application database does not store the raw address. Suggestions are retained for project review and scheduled for deletion after 90 days; they may be removed earlier.

Automatic diagnostics

On the website, when diagnostics are enabled and Panashe encounters an unexpected software error, it may send the platform, app and build version, an allowlisted error name, a route template when available, and a capped set of sanitised stack frames. Panashe does not send arbitrary error message text, full URLs, Scripture text, reading history, or suggestion text in these reports. The server may attach the same type of daily network hash for rate limiting. Diagnostic records are used only for reliability and are scheduled for deletion after 30 days.

Information when you connect

Cloudflare hosts, delivers, and protects Panashe, its API, and its application database. It processes the shared Communion passages, suggestions, and diagnostic payloads described here on Panashe's behalf, along with ordinary request information such as an IP address, requested path, timestamp, headers, and general device characteristics. Connections to the Panashe API use HTTPS. Panashe requires service providers processing data on its behalf to protect it consistently with this policy and applicable law, and remains responsible for that processing.

Panashe uses daily, salted one-way network hashes for service protection. Records from the same network on the same UTC day can carry the same anti-abuse value. Stored submissions and diagnostics are available only through protected administrative tools.

Communion and sharing

In the Apple app, your Communion is yours. The passages you bring to your devotion are kept in your journey on your device, in your backup, and, if you use iCloud, in your own iCloud account. They are never sent to Panashe. You can separately choose to share a passage through system sharing or Messages.

On the website, Communion is shared with everyone. When you bring a passage there, Panashe receives the selected Scripture reference and the installation identifier generated by the browser. Before storage, the server converts that identifier into a daily, salted one-way hash and may create a daily hash from the request's network address; these enforce one share per browser and a small limit per network each day. The reference appears on the website's Communion page for everyone, without a name. After the day settles, the hashes are removed, and the reference is deleted after the previous three completed UTC days. The Apple app has no shared feed; sharing through system services happens only when you choose it.

What we do not collect

No reader accounts. No public profiles. No advertising identifiers. No remote reading analytics or advertising tracking. The native Apple app do not process payments, collect payment information, or display external donation methods. Panashe does not sell personal information or build advertising profiles from reading.

Sharing, backups, and system services

On the native apps, Share Passage sends the selected passage to the device share sheet. On the website, Panashe uses the share interface when available and otherwise copies the passage and canonical link to the clipboard. These actions do not upload the passage to Panashe.

Backup export creates a JSON file containing the backup fields described above; web downloads it locally and native passes it to the system share sheet. Backup import uses a system file or document picker. Panashe does not receive these files, but an app or provider you choose may process them. On Apple devices, Listening reads chapter text with voices bundled in the app and runs entirely on the device. On the website, Listening passes chapter text to the speech voice or service selected by the browser or device.

Offline reading and network use

Prepared Scripture, the last-opened passage, reader settings, your daily devotion, and your own Communion remain available offline after the relevant files are present on the device. Sharing with the website's Communion feed and Suggestions require a connection.

The website requests the book files and paths needed to display what you open, so Cloudflare can process those paths as ordinary request data described above. Panashe does not use those requests to build reading-history analytics. Searches and reading progress are not submitted as analytics.

Third-party providers

Panashe uses Cloudflare for hosting, delivery, API infrastructure, and service protection. Panashe does not use Google Analytics, advertising pixels, or social trackers. Device speech, sharing, and document services act only when you choose those features. On Apple devices, iCloud, Siri, Spotlight, and Handoff are Apple services that act under Apple's privacy policy. See Cloudflare's privacy policy for its own data practices.

The website's About page includes an external Ko-fi link and a Bitcoin-address copy action. Ko-fi receives information only after you choose to leave Panashe for its site. These support methods are not displayed in the native Apple app.

Retention, deletion, and contact

Local records, including your journey, remain until you clear Panashe's site or app data or remove the app. A copy kept in iCloud stays with your Apple Account, under Apple's iCloud settings, even after the app is removed. Diagnostics are scheduled for deletion after 30 days. Shared Communion passages lose their anti-abuse hashes when the day settles and are deleted after the previous three completed UTC days. Suggestions are scheduled for deletion after 90 days and may be removed earlier.

For a privacy question, correction, or deletion request, email info@panashe.org. To locate a server record, include the approximate UTC date and the shared Scripture reference, suggestion subject, or distinctive text. Because Panashe has no accounts and does not ask for identity, a record may be impossible to identify without enough specific information.

Your choices

You may use the core reader without creating an account. You may choose not to send suggestions, bring or share passages in Communion, share passages elsewhere, export backups, use a device speech service, or sync through iCloud. You may clear local data through browser or device settings or by removing the app.

You may leave Personalize Daily readings off, turn it off to delete its profile, or forget the profile while keeping the option on. These choices do not change saved Daily readings, witnesses, or your Scripture-mode progress.

Changes

This policy will be revised when collection, retention, providers, or product behavior changes. The effective date above identifies the latest version covering the website and native apps.

AboutChurchPrivacySupport