Selah Mobile App
Privacy Policy
Last updated: July 15, 2026
Selah (“we”, “us”, “our”) is a Christian faith-based mobile app for Bible reading, note-taking, sermon capture, and community. This policy explains what the Selah app collects, why, who we share it with, and the choices and rights you have — including how to delete your account or your data.
This document covers the Selah mobile app only. Looking for the policies that cover myselahh.com and the Bible API instead? See the website’s Privacy Policy and Terms of Service.
1. Who we are
Selah is operated by an individual developer based in Nigeria (“the Developer”). For any privacy question, request, or concern, contact contact@myselahh.com. This policy covers the Selah mobile app specifically. The myselahh.com website and Bible API are a separate product with their own Privacy Policy.
2. Information you give us directly
- Account credentials. Email address and password at sign-up, handled by our authentication provider.
- Profile. Display name/handle, bio, avatar photo, and church affiliation, shown to other users.
- Notes. Titles, body text, folders, linked verses, and colors of every note you write. Notes are private by default and visible only to you unless you choose to share or post them.
- Commons posts, comments, likes, and stories. Anything you post to the community feed, which is visible to other Selah users by design.
- Sermon and voice recordings, and their transcripts. Captured when you use the recorder to capture a sermon or dictate into a note, so we can convert your speech to text and save it in your notes.
- Live voice audio in Read Together rooms. Captured only while your microphone is switched on in a live reading room, and relayed in real time to the other participants in that room — see §4 for how this is handled technically.
- Questions you ask Ask AI / Berean, and any note text you choose to include as context, used to generate a grounded, cited answer from Scripture.
- Photos from your library that you actively choose to attach as a note or event cover image.
- Quizzes, flashcards, and attempt scores you create or complete. Daily quiz scores also appear on a public leaderboard showing your handle, display name, avatar, and score.
- Reports and blocks you file against other content or accounts, used for community moderation and safety.
- Subscription and AI-credit selections you make, used to manage your plan tier and credit balance.
- Giving/donation details (name, amount, contact information) when you give to a church event through the app, used to process your gift and record it against the receiving church.
- Church verification documents — government-issued ID, proof of registration or address, bank account details, and tax information — collected only if you, as a church admin, apply to verify a church so it can receive donations. These are reviewed by a small internal team and stored in a private, access-restricted file store. They are never shown to other users.
- Messages you send us, such as support requests or deletion requests, so we can respond to you.
3. Information collected automatically
- Device and diagnostic data. Device model, app version, OS version, crash logs, stack traces, and IP address, collected via our crash-reporting tool to diagnose and fix bugs.
- Push notification token, used to deliver reminders and notifications you have enabled.
- Reading activity and usage counters — streak dates and feature-usage counters — used to power streaks, your Journey stats, and periodic “Wrapped” summaries.
- Presence data in a Read Together room — which verse you’re on, whether your mic is on — shown live to other participants in that room. This is ephemeral and is not written to permanent storage.
4. Information from third parties
- App Store / Google Play. Purchase and subscription receipts are validated through RevenueCat, which we link to your Selah account so we know your subscription tier and credit balance. We never receive your full payment card details.
- Payment processors. If you give to a church event, our payment processors handle your payment details directly and share with us only the confirmation, amount, and the giving record needed to credit the receiving church.
5. Permissions Selah requests on your device
- Microphone — to record sermons and to dictate speech into your notes.
- Speech recognition (iOS) — to transcribe your spoken words into note text.
- Photo library — only when you choose to attach a photo to a note or event cover.
- Notifications — to deliver reminders, streak nudges, and, if enabled, church announcements.
We do not request location, contacts, or camera-capture permissions. You can decline any permission above; the related feature will simply be unavailable until you grant it.
6. How we use your information
- Provide, operate, and maintain the Service — accounts, notes, Bible content, Commons, and live reading rooms.
- Transcribe audio you record, either fully on your device (offline mode) or through our cloud transcription pipeline (Standard / High-accuracy modes).
- Generate AI-assisted answers and verse explanations, grounded in Scripture.
- Process subscriptions, AI credits, and optional giving to churches.
- Send notifications you have opted into.
- Maintain security, detect abuse, and enforce rate limits and credit gating.
- Diagnose crashes and bugs.
- Comply with legal obligations.
We do not sell your personal data, and we do not use third-party advertising or ad-tracking SDKs.
7. How we share your information
We share data only with the service providers necessary to run Selah, under contracts that require them to protect your data:
- Supabase — primary database, authentication, and row-level security. Handles account, profile, notes, posts, streaks, and credit-ledger data.
- Cloudflare — server-side logic, media and audio storage, our cloud transcription engine, push fan-out, and the Bible-content proxy. Handles sermon audio (cloud transcription tiers only), images, push tokens, and transcripts.
- Anthropic (Claude) — powers Ask AI / Berean. For everyday questions, verse lookups, and quiz/flashcard generation, only the text you type is sent, and it is not attached to your account. For the optional “structure my sermon note with AI” feature, your full sermon transcript is sent under your authenticated account.
- RevenueCat — subscription and purchase management. Receives your account ID (used as its customer ID) and your purchase/subscription/entitlement status.
- Payment processors — process payment details you enter for a gift to a church.
- Expo (EAS / Expo Push) — app builds, over-the-air updates, and push delivery. Receives your push token and device platform.
- Crash and error monitoring — device info, crash logs, and IP address, to keep the app stable.
- Stock photo search — receives search terms you type when choosing a cover image; no account data is sent.
- Live voice relay — carries the live audio stream in a Read Together room in real time; the stream itself is not stored by us.
- Bible content sources — supply Scripture text, commentary, and cross-references for verse and reference lookups; this involves no personal data.
We may also disclose information if required by law, to protect the rights, property, or safety of Selah, our users, or the public, or in connection with a merger, acquisition, or sale of assets (with notice to you).
8. Public content and community features
Anything you post to the Commons feed, comment, or share as a story is visible to other Selah users by design, and may be viewed, copied, or screenshotted outside our control once shared. Your daily quiz results also appear on a public leaderboard showing your handle, display name, avatar, and score. If you submit ID, address, or bank documents to verify a church, that information is visible only to the small internal team that reviews verification applications — never to other users.
9. Data retention
- Your account data (profile, notes, posts) is retained for as long as your account is active.
- If you request account deletion (§11), we delete your profile, notes, posts, comments, stories, streaks, and credit balance from our active systems, subject to the limited retention below.
- We may retain records required for tax, accounting, or fraud-prevention obligations relating to payments or giving, for the period required by applicable law, and anonymized or aggregated data that can no longer identify you.
- Crash logs are retained per our crash-reporting provider’s standard retention window before automatic deletion.
- Content you posted publicly to the Commons feed before deletion may continue to exist in other users’ screenshots or copies outside our systems; we cannot recall those.
10. Security
- All network communication between the app and our servers is encrypted in transit using HTTPS/TLS. Live voice in Read Together rooms uses encrypted WebRTC (DTLS-SRTP).
- Authentication tokens stored on your device are encrypted at rest.
- Access to production data is restricted by Postgres Row-Level Security policies — the app itself never holds admin/service-role credentials; those live only on our servers.
- Our crash-reporting tool is configured to not collect default personal information and never records your screen — your notes and prayers are never captured as screen recordings.
- Church verification documents are stored in a private, access-restricted file store, never exposed via a public URL.
- No method of transmission or storage is 100% secure, and we cannot guarantee absolute security.
11. Account & data deletion
You can request deletion at any time:
- In-app: Settings → Delete Account
- From the web — no need to reinstall the app — using the links below
Delete My Account — permanently deletes your account, profile, notes, posts, comments, streaks, and credit balance.
Request Data Deletion — request deletion of your data without necessarily closing your account, for example if you interacted with us without creating an account, or want specific data erased while you keep using the app.
12. Your rights
Depending on where you live, you may have the right to:
- Access the personal data we hold about you
- Correct inaccurate data
- Delete your account and/or your data (see §11)
- Export or port your data in a portable format
- Object to or restrict certain processing
- Withdraw consent at any time, where processing is based on consent
- Lodge a complaint with your local data protection authority — for example, Nigeria’s NDPC under the Nigeria Data Protection Act 2023, or your local EU/UK/US authority if applicable
To exercise any of these rights, email contact@myselahh.com. We will respond within a reasonable time and no later than required by applicable law.
13. Children’s privacy
Selah is not directed to children under 13 (or the minimum age required in your country), and we do not knowingly collect personal data from children under that age. If you believe a child has provided us with personal data, contact contact@myselahh.com and we will delete it.
14. International data transfers
Our service providers may process data in countries other than your own, including the United States and the European Union. Where required, we rely on appropriate safeguards, such as standard contractual clauses, for these transfers.
15. Changes to this policy
We may update this Privacy Policy from time to time. If we make material changes, we will notify you in-app or by email before the change takes effect. The “Last updated” date above reflects the latest revision.
16. Contact us
Questions, requests, or complaints about this policy or your data: contact@myselahh.com.
Questions about this policy? Contact us at contact@myselahh.com.