Skip to privacy notice

Pilot notice

Privacy at BibleBot

Last updated September 20, 2026. This notice describes the current invitation-only pilot.

Registration data

BibleBot asks for your first name, last name, email address, and an optional referral. A short-lived signup request holds these details while Cognito verifies your email. After confirmation, your name and email are associated with your Cognito account. The referral is included in a registration notice to BibleBot support and is then removed from the signup request after successful delivery.

Invitation requests

When you request an invitation, we store your name, email, optional study experience, learning goals and referral, review status, and submission time. Only designated reviewers can read requests or approve access. Request records are scheduled for deletion after 90 days. Support receives a notice linking to the private review inbox; approved requests receive an email-bound invitation. Please do not include private or sensitive details in learning goals.

Security and invitation data

Invitation and signup controls retain one-way keyed forms of email addresses, account identifiers, and network addresses, plus campaign counts and timestamps. Raw QR invitation tokens are not stored by the service. Expired temporary records use automated cleanup, which may occur after their stated expiry time.

AI usage

Ask requests are sent to Amazon Bedrock to generate responses. BibleBot records account-scoped call counts, token counts, estimated cost, model identity, status, and timestamps to enforce limits. The quota records do not store your prompt or the generated answer.

Feedback

When you submit the in-app feedback form, BibleBot stores your selected category, feedback text, the BibleBot area and page URL where you opened the form, related page state, browser details, an optional reply email, a pseudonymous account identifier, and the submission time. Signed-in feedback is retained for up to 365 days. Public feedback without sign-in stores the category, message, area, sanitized page URL, optional passage context and reply email, and submission time for 90 days; it does not attach an account identifier. Records are then scheduled for automated deletion. Opening feedback does not send a report; you can inspect the included context before submitting. Drafts in the feedback overlay stay only in the current page until you navigate away. A system email tells BibleBot support that feedback is ready for review; the notice includes submission metadata but not your feedback text.

Optional feature diagnostics

When enabled, optional feature reporting uses your Preferences choice, which defaults off. Reports contain tool/action names, outcomes, timing, release versions, coarse device information and temporary random session identifiers. They do not contain questions, search text, notes, drafts, reading history or account identifiers. Selected server failures are recorded separately for reliability without a session identifier. Sanitized diagnostic events are retained for 30 days. Turning off optional reporting clears queued browser events; it does not remove already received reports or essential service logs.

Private questions, when available

This separate form uses sign-in to obtain a short-lived submission token. Your question record does not contain your account identity, but this is not fully anonymous: the operator may be able to correlate infrastructure records, timing or details you write. Only users assigned the Private Questions role can read the inbox. Question contents are not emailed, sent to AI or included in product analytics. Drafts stay only on the current page. Submissions expire from the inbox after 90 days; physical deletion may take longer during automated cleanup. The first version does not provide a reply inbox or account-based recovery.

Maps

When a BibleBot map is displayed, your browser requests basemap tiles directly from CARTO. CARTO receives request data that includes your IP address, the referring page, browser user-agent, BibleBot's CARTO API key, timestamps, and request volumes so it can provide, secure, monitor, and limit the basemap service. BibleBot is the controller of this request data and CARTO processes it on BibleBot's behalf. CARTO states that it truncates IP addresses when received, retains the resulting request logs for 30 days, and stores them in the United States. CARTO may use subprocessors for this service. See CARTO's privacy notice and subprocessor list.

Service providers

The pilot uses Amazon Web Services for authentication, storage, application hosting, and AI inference; SMTP2GO for transactional email; and CARTO for map basemaps. Replies and support mail are received at the BibleBot support mailbox.

Questions

Contact support@biblebot.io with privacy or account questions.

Return to registration · Acceptable use