Privacy Policy
Last updated: August 5, 2026
This Privacy Policy describes how the Scriptio mobile application collects, processes and protects your personal data. It is published by Jérémie Sidler, a natural person residing in Switzerland, canton of Vaud.
This Policy complies with the following legal frameworks:
- Regulation (EU) 2016/679 of 27 April 2016 (GDPR)
- Swiss Federal Act on Data Protection of 25 September 2020 (FADP / nLPD), in force since 1 September 2023
- Regulation (EU) 2022/2065 on a Single Market for Digital Services (DSA), applicable since 17 February 2024
- Children's Online Privacy Protection Act (COPPA, 15 U.S.C. §§ 6501-6506)
- California Consumer Privacy Act as amended by the California Privacy Rights Act (CCPA/CPRA)
- Apple App Store Review Guidelines, sections 1.2 and 5.1.1
- Google Play Data Safety Policy
By using the Application, you acknowledge having read this Policy. You can consult it at any time from Settings › Privacy Policy within the Application or at https://scriptio.org/privacy.
1. Data Controller
1.1 Identity
- Name: Jérémie Sidler
- Capacity: natural person, independent publisher
- Country: Switzerland (canton of Vaud)
- Contact email: scriptioorg@gmail.com
The Publisher's legal status may evolve as the project develops (association, company, foundation). Any substantial change will be communicated to users via in-app notification and by updating this Policy.
1.2 Representative in the European Union
In accordance with Article 27 GDPR and Article 13 DSA, and given that the Publisher is not established within the European Union but offers services to persons located in the European Union, a representative will be appointed prior to the availability of the service on European application stores, as a contact point for supervisory authorities and data subjects. The full contact details will be published in this section as soon as the appointment is effective.
Pending this appointment, all data protection requests may be sent directly to the Publisher at scriptioorg@gmail.com.
This representative may be contacted on any matter relating to personal data protection or content reporting under the DSA, independently of the possibility of contacting the Publisher directly.
1.3 Data Protection Officer
The Publisher is not required to appoint a Data Protection Officer (DPO) under Article 37 GDPR or Article 10 FADP. All data protection requests may be sent directly to scriptioorg@gmail.com.
2. Data we collect
We collect the following categories of data, strictly limited to what is necessary for the use of the Application and in accordance with the data minimisation principle (Art. 5(1)(c) GDPR, Art. 6 para. 3 FADP).
2.1 Account data (collected at sign-up)
- Email address (required — authentication)
- First and last name (required — account identity)
- Password, hashed by our authentication provider Supabase (never stored or accessible in plain text, including by us) — unless you sign in with Apple or Google, in which case no password exists on our side
- Technical identifier passed on by Apple or Google if you use their sign-in button, together with the associated email address — with “Sign in with Apple”, that address may be a private relay address provided by Apple
- Profile picture (optional)
- Date of birth or age range (used solely to verify the minimum-age requirement)
2.2 Profile data voluntarily provided
- Short biography
- Country, region, city of residence (optional)
- Language preferences (FR, EN, ES, IT, PT, DE, PL)
- Profile picture, editable at any time
2.3 Religious category data — SENSITIVE DATA
During onboarding, you choose a membership category among: faithful, clergy, consecrated life, theologian, with a more specific role where applicable (priest, deacon, religious, nun, seminarian, etc.). If you indicate that you are not Catholic, the Application records the status you choose (for example: Orthodox, Protestant, another religion, atheist or agnostic), attached to the 'faithful' category; you may also prefer not to say. This status enjoys the same safeguards as the category itself. From Profile › Edit profile you may, if you wish, add your functions in the Church, your commitments and — for a theologian profile — your religious tradition; those three fields are optional and appear on your public profile.
This information reveals your religious beliefs within the meaning of Article 9 GDPR and Article 5(c) FADP. It therefore constitutes sensitive personal data, subject to enhanced protection.
The processing of this category of data is based on your explicit consent, obtained at sign-up through a clear affirmative act: you choose your own category on a dedicated screen, with no preselected value. You may change it at any time from Profile › Edit profile › My faith profile. As this category is necessary for the service to work, withdrawing it entirely means deleting your account, which you can do at any time from Settings › Delete my account, without affecting the lawfulness of processing carried out beforehand.
2.4 Clergy / consecrated life verification data (optional)
If you apply for verification (verified-profile badge), we process:
- Official documents you submit (letter of obedience, diocesan attestation, theology diploma, religious-engagement certificate, etc.), as scans or photographs
- Your institutional email if you use the recognised-domain verification path
- The identifier of a sponsoring verified account, where applicable
These documents also constitute sensitive data within the meaning of Article 9 GDPR (religious beliefs and, where applicable, identity-related data). They are stored on restricted-access Supabase Storage (EU region — Frankfurt), encrypted at rest, and accessible only to the Publisher in the strict context of evaluating the request.
Retention periods for verification documents:
- Request under review: retained until the decision or the withdrawal of the request
- Approval: automatic deletion within 30 days of decision
- Refusal: 30 days retained to allow you to challenge the decision, then automatic deletion
- Withdrawal of request: immediate deletion
2.5 Usage-generated data
- Bible annotations (text entered, verse range, annotation type among 13 categories, chosen visibility: private, friends, public)
- Voice notes (audio files attached to annotations where applicable)
- Verse highlights (colour, range)
- Annotation drafts
- Collections of annotations you organise
- Friends list and friendship-request status
- Subscriptions to verified profiles
- Amens given to public annotations
- Content reports you submit
- List of blocked users
Voice notes are stored as audio files without biometric processing: we perform no voice analysis, speaker recognition, automatic transcription, or voiceprint creation. These files therefore do not constitute biometric data within the meaning of Article 4(14) GDPR.
2.6 Technical and operational data
- Push notification token (Apple APNs or Google FCM token, linked to your account to enable push delivery)
- Display preferences (light/dark theme, text size, language)
- Anonymised error logs generated upon failure and sent to our diagnostics tool Sentry to enable fixes (see § 4.1)
- Administrative-action logs when the Publisher exercises moderation or administration functions (internal audit)
- Account-creation and last-login timestamps
2.7 Data we do NOT collect
For information, the Application does not collect:
- Your precise (GPS) geolocation
- Your address book
- The list of applications installed on your device
- Your off-Application activity (cross-app or cross-site tracking)
- Advertising identifiers (IDFA on Apple, AAID on Google)
- Biometric data
- Health data
- Banking or financial data (the Application is free with no in-app purchase)
- The images you scan via the text-scan feature: optical character recognition is performed entirely on your device (Apple Vision technology on iOS, Google ML Kit on Android); the image is neither transmitted to our servers nor retained, and only the text you choose to insert is saved, just like keyboard input
3. Purposes and legal bases
We process your data for the following purposes, on the legal bases indicated:
- Account creation and management, authentication — legal basis: performance of the contract (Art. 6(1)(b) GDPR)
- Display of membership-category badge — legal basis: explicit consent (Art. 6(1)(a) and 9(2)(a) GDPR)
- Verification of clergy / consecrated status — legal basis: explicit consent (Art. 9(2)(a) GDPR) + legitimate interest in moderation (Art. 6(1)(f))
- Reading, annotation, sharing with friends or subscribers — legal basis: performance of the contract (Art. 6(1)(b) GDPR)
- Push notifications — legal basis: consent (Art. 6(1)(a) GDPR, toggle in Settings)
- Content moderation, report handling — legal basis: legal obligation (DSA Art. 16-17) + legitimate interest (Art. 6(1)(c) and 6(1)(f) GDPR)
- Security, abuse prevention, fraud prevention — legal basis: legitimate interest (Art. 6(1)(f) GDPR)
- Backups and service continuity — legal basis: legitimate interest (Art. 6(1)(f) GDPR)
- Handling rights-exercise requests — legal basis: legal obligation (Art. 6(1)(c) GDPR)
No advertising purpose. We process no data for advertising, direct marketing, commercial prospecting, advertising profiling, A/B testing of users, or resale. We use no third-party analytics tool (Google Analytics, Meta Pixel, etc.).
4. Subprocessors and recipients
To operate the Application, we entrust part of the processing to specialised subprocessors within the meaning of Article 28 GDPR and Article 9 FADP. Each is bound to the Publisher by a Data Processing Agreement (DPA) ensuring an appropriate level of protection.
4.1 List of subprocessors
- Supabase Inc. (Delaware-incorporated US company) — database hosting, authentication (accounts, hashed passwords, sessions), Storage (audio, verification documents) and server functions — data stored in the European Union (Frankfurt, Germany, AWS infrastructure) — no physical transfer outside the EU, but Supabase Inc. remains subject to US laws (see § 5 on international transfers)
- Apple Inc. (One Apple Park Way, Cupertino, CA 95014, USA) — Apple Push Notification service (APNs) for delivery of push notifications to iOS devices, and the “Sign in with Apple” service if you choose that sign-in method — data in the United States — framework: DPF + Standard Contractual Clauses
- Google LLC (1600 Amphitheatre Parkway, Mountain View, CA 94043, USA) — Firebase Cloud Messaging (FCM) for delivery of push notifications to Android devices, and Google account sign-in if you choose that sign-in method — data in the United States — framework: DPF + Standard Contractual Clauses
- Expo Inc. (USA) — intermediate Expo Push Notification service used to relay notifications to APNs and FCM, and Over-The-Air update service (EAS Update) — data in the United States — framework: DPF + Standard Contractual Clauses
- Vercel Inc. (440 N Barranca Avenue #4133, Covina, CA 91723, USA) — hosting of the scriptio.org marketing website. This site processes only non-identifying technical audience data and uses no tracking cookies. Framework: DPF + Standard Contractual Clauses.
- DeepL SE (Maarweg 165, 50825 Cologne, Germany) — on-demand machine translation (the “Translate” button) of the body of an annotation written in another language — data processed within the European Union (Germany) — subprocessor established in the EU and subject to the GDPR; under the DeepL API Pro subscription, submitted texts are deleted immediately after translation and are not used to train its models. Only the annotation body is transmitted (never the quoted verse), and the resulting translation is cached so the same text is not sent again.
- Functional Software, Inc. (dba Sentry, 45 Fremont Street, San Francisco, CA 94105, USA) — crash-reporting and error-diagnostics service (Sentry), enabled only in the production build of the Application to detect and fix malfunctions — technical diagnostic data only (error type, app version, device model, operating system), stripped of personal data by an automatic filter before sending — data in the United States — framework: Standard Contractual Clauses (EU Decision 2021/914). No annotation, voice note or biblical content is transmitted.
4.2 No sharing with commercial third parties
The Publisher does not sell, rent or share your data with third parties for commercial, advertising or profiling purposes.
4.3 Disclosure to authorities
Your data may be disclosed to competent authorities (judicial, administrative, tax) upon lawful request under applicable law. Any such disclosure is subject to a prior validity check.
5. International data transfers
Part of your data is stored and processed within the European Union (Supabase, Frankfurt region).
Certain technical data transits via the United States through the subprocessors Apple, Google, Expo and Sentry. These transfers are governed by:
- The adherence of these subprocessors to the EU-U.S. Data Privacy Framework (DPF), recognised by adequacy decision of the European Commission of 10 July 2023
- The Standard Contractual Clauses adopted by the European Commission (Decision 2021/914 of 4 June 2021), supplementary to the DPF
You can request a copy of the applicable Standard Contractual Clauses by writing to scriptioorg@gmail.com.
For Swiss users, these transfers are also governed by the Federal Council's recognition of the DPF in its Swiss-U.S. variant (Swiss-U.S. Data Privacy Framework), in force since September 2024.
6. Retention periods
- Account data (email, name, hashed password): for the entire lifetime of the account
- Annotations, highlights, collections, drafts: for the entire lifetime of the account
- Voice notes (audio): for the entire lifetime of the account
- Verification documents — request under review: retained until the decision or the withdrawal of the request
- Verification documents — approved: 30 days maximum after decision, then automatic deletion
- Verification documents — refused: 30 days after notification, then automatic deletion
- Verification documents — request withdrawn: immediate deletion
- Institutional email (recognised-domain verification route): for the entire lifetime of the account
- Deleted account (upon your request): immediate anonymisation, definitive deletion within 30 days (grace period for cancellation)
- Anonymised error logs: 90 days
- Administrative-action logs: 3 years (traceability and internal audit obligation)
- Technical backups (Supabase): 7 to 30 days per the provider's backup policy
- Email exchanges with support: 3 years
At the end of these periods, data is definitively deleted or irreversibly anonymised.
7. Security — Technical and organisational measures
In accordance with Article 32 GDPR and Article 8 FADP, we implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk.
Technical measures
- TLS 1.2+ encryption in transit for all communications (HTTPS)
- Encryption at rest for sensitive files (Supabase Storage, AES-256)
- Authentication handled by Supabase Auth: password hashed (bcrypt), never accessible in plain text; sign-in also possible with Apple or Google, without a password
- Session tokens stored in iOS Keychain / Android Keystore, encrypted by the operating system
- Restrictive access policies at the database level (PostgreSQL Row Level Security)
- Private Storage bucket for verification documents and voice notes (time-limited signed URLs)
- Automatic deletion of verification documents at the end of the procedure
- Regular, encrypted backups
- Regular security updates across the technical stack
Organisational measures
- Production data access strictly limited to the Publisher
- Administrator authentication protected by PIN + Keychain
- Audit log of any sensitive administrative action
- Internal data-breach management procedure (notification to the Swiss FDPIC and competent EU supervisory authorities without undue delay and at the latest within 72 hours pursuant to Art. 33 GDPR)
- Internal documentation of processing activities (records of processing under Art. 30 GDPR and Art. 12 FADP)
Data breach notification
In the event of a personal-data breach likely to result in a risk to your rights and freedoms, you will be informed directly (in-app notification and email) under the conditions of Art. 34 GDPR.
8. Your rights
You have the following rights over your personal data under the GDPR and FADP.
8.1 List of rights
- Right of access (Art. 15 GDPR, Art. 25 FADP): obtain confirmation that your data is processed and receive a copy
- Right to rectification (Art. 16 GDPR, Art. 32 FADP): correct inaccurate or incomplete data
- Right to erasure or 'right to be forgotten' (Art. 17 GDPR, Art. 32 FADP): request the deletion of your data
- Right to restriction of processing (Art. 18 GDPR): temporarily suspend the processing of your data
- Right to data portability (Art. 20 GDPR, Art. 28 FADP): receive your data in a structured, commonly used and machine-readable format (JSON), and transmit it to another controller
- Right to object (Art. 21 GDPR): object, on grounds relating to your particular situation, to processing based on legitimate interest
- Right to withdraw consent at any time, without affecting the lawfulness of prior processing (Art. 7(3) GDPR)
- Right to issue directives regarding the fate of your data after death (only for users residing in France, Art. 85 French Data Protection Act)
8.2 How to exercise your rights
Most of these rights can be exercised directly within the Application:
- Access, rectification: Profile › Edit profile
- Account deletion: Settings › Delete my account (definitive deletion within 30 days, in compliance with Apple App Review Guidelines 5.1.1 (v))
- Withdrawal of consent — notifications: Settings › Notifications
- Withdrawal of consent — religious category: Profile › Edit profile › My faith profile
For other requests (portability, objection, restriction, full access), write to scriptioorg@gmail.com specifying the nature of your request. We respond within one month (extendable by two months for complex cases, with prior notice).
Proof of identity may be requested where required by the nature of the request (Art. 12(6) GDPR) — for example, a copy of an ID document with the handwritten note 'For the exercise of my GDPR rights with Scriptio'.
8.3 Right to lodge a complaint
If you believe that the processing of your data does not comply with applicable regulations, you may lodge a complaint with a supervisory authority, in particular:
- Switzerland: Federal Data Protection and Information Commissioner (FDPIC), Feldeggweg 1, 3003 Bern — https://www.edoeb.admin.ch/
- France: CNIL, 3 place de Fontenoy, 75007 Paris — https://www.cnil.fr/
- Belgium: APD/GBA — https://www.autoriteprotectiondonnees.be/
- Other EU countries: the supervisory authority of your country of residence — https://edpb.europa.eu/about-edpb/about-edpb/members_en
9. Minors and parental consent
9.1 Minimum age
The minimum age required to create a Scriptio account is 13 years.
9.2 Users aged 13 to 16 in the European Union
In accordance with Article 8 GDPR, users residing in an EU Member State and under 16 years of age must obtain the consent of one of their legal representatives to create an account and use the social features of the Application (shared annotations, friendships, subscriptions, notifications).
Some Member States have set a lower threshold (e.g. 15 in France, 14 in Spain or Italy). The applicable threshold is that of your country of residence.
If you are a minor, by creating an account you declare having obtained this parental authorisation. Your legal representatives may at any time request the deletion of your account by writing to scriptioorg@gmail.com.
9.3 Religious category reserved for 16+
Given the sensitive nature of the religious category under Article 9 GDPR, and in accordance with the European Data Protection Board guidelines 5/2020 on consent, the declaration of a religious membership category is not accessible to users under 16 years of age, regardless of any parental consent.
Users aged 13 to 15 may use the Application without declaring this category. They will be able to declare it from their 16th birthday.
9.4 Users residing in the United States (COPPA)
In accordance with the Children's Online Privacy Protection Act (15 U.S.C. §§ 6501-6506), the Application is not directed to children under 13 and we do not knowingly collect personal data from children under 13. If we discover that an account has been created by a child under 13, we delete it without delay. Parents or guardians may report such an account to scriptioorg@gmail.com.
10. Cookies, trackers and App Tracking Transparency
10.1 Mobile application
The Scriptio mobile Application uses no cookies. It embeds:
- No tracking pixel
- No advertising SDK
- No third-party analytics SDK (Google Analytics, Firebase Analytics, Meta SDK, Amplitude, Mixpanel, etc.)
- No session-replay tool (Hotjar, FullStory, etc.)
The Application uses only a crash-reporting tool (Sentry) for technical stability and bug-fixing purposes, with no advertising or cross-application tracking purpose whatsoever (see § 4.1).
10.2 App Tracking Transparency (iOS)
In accordance with Apple's App Tracking Transparency framework, we declare that we conduct no cross-app or cross-site tracking (in the Apple sense) and do not request ATT authorisation. The Privacy Manifest (PrivacyInfo.xcprivacy) embedded in the Application reflects this absence of tracking.
10.3 scriptio.org website
The associated website scriptio.org may use only strictly necessary technical cookies for site operation (e.g. remembering the selected language). In accordance with EDPB guidance and CNIL recommendations on cookies, these cookies do not require prior user consent. No third-party advertising or audience-measurement cookies are used.
11. Special provision — Residents of the European Union
This section sets out the specifics of GDPR application for users residing in an EU Member State.
EU representative: see section 1.2.
Legal basis for transfers to the United States: EU-U.S. Data Privacy Framework + Standard Contractual Clauses (see section 5).
12. Special provision — Residents of Switzerland
This section sets out the specifics of FADP application for users residing in Switzerland.
As the Publisher is domiciled in Switzerland (canton of Vaud), the FADP applies directly. The Publisher:
- Maintains a record of processing activities (Art. 12 FADP)
- Carries out a data protection impact assessment (DPIA within the meaning of Art. 22 FADP) for high-risk processing, in particular the processing of sensitive data (religious category, verification documents)
- Notifies the Swiss Federal Data Protection and Information Commissioner (FDPIC) of any data breach presenting a risk to personality or fundamental rights, without undue delay (Art. 24 FADP)
Your rights under Articles 25 to 32 FADP cover the same guarantees as those described in section 8.
13. Special provision — Residents of the United States (California)
This section sets out the specifics of CCPA/CPRA application for residents of California.
Categories of personal information collected: identifiers (email, name), commercial information (the service is free), Internet information (technical logs), user-generated content (annotations), sensitive information (religious category, verification documents).
Purposes: see section 3.
Rights of California consumers
- Right to know what information is collected and its source
- Right of access and copy
- Right of deletion
- Right of rectification
- Right to limit the use of sensitive information
- Right to non-discrimination for exercising these rights
Sale and sharing of information
Scriptio does not sell or share your personal information within the meaning of CCPA/CPRA. Accordingly, no 'Do Not Sell or Share My Personal Information' link is required. We also do not process sensitive information for any purpose other than those necessary to provide the service.
Exercise of rights: scriptioorg@gmail.com. Response within 45 days.
14. Changes to this Policy
We reserve the right to amend this Policy to reflect technical, legal or service developments.
In case of substantial modification (e.g. addition of a new purpose, a new subprocessor, change of retention period, change of legal basis), you will be informed:
- By push notification in the Application
- By banner displayed at Application launch
- At least 30 days before the effective date of the new version
The applicable version is always the one accessible from the Application at the time you use it. Earlier versions are retained and may be obtained on request to scriptioorg@gmail.com.
15. Contact and complaints
For any question relating to this Policy, your personal data or the exercise of your rights:
- Primary email: scriptioorg@gmail.com
- EU representative: will be appointed prior to active availability of the service in the European Union (see § 1.2). In the meantime, EU users may contact the Publisher directly via the email address above.
- Postal address: available on duly motivated request
- Website: https://scriptio.org/privacy
In case of complaint, you may also turn to:
- In Switzerland: the FDPIC — https://www.edoeb.admin.ch/
- In France: the CNIL — https://www.cnil.fr/
- In another EU Member State: the supervisory authority of your country of residence — https://edpb.europa.eu/about-edpb/about-edpb/members_en
- In the United States (California): the California Privacy Protection Agency — https://cppa.ca.gov/