Amos Standard is a Bible study and prayer app. It holds things people do not usually write down: questions they would not ask aloud, prayers, and private notes. This page explains what we keep, what we send elsewhere, and what we refuse to collect. It is written to be read, not to be survived.
Amos Standard is made and run by Viktar Danilchyk, one developer based in Poland. You can reach me at privacy@amosstandard.com — a real address, read by a person.
What we collect
Your account. You sign in with Google. We receive your email address and basic profile information from Google. We never receive your Google password.
What you create in the app. Your conversations — the questions you ask and the answers you receive — your prayer journal, your notes, your bookmarks, your reading progress, and your settings. This is stored so the app can show it back to you.
Unless you ask a question privately. Some questions are not ones you want kept anywhere, including here. The private chat — the eye icon beside New Chat — is not written down at all: no conversation, no question, no answer, nothing added to your history, and no record that you opened it. It lives in the browser tab you typed it in and ends when you leave the page; there is nothing to delete afterwards because nothing was stored. The one thing it cannot change is the section below — your question still has to reach the provider that answers it.
Basic technical data. Standard web server logs, and error reports when something breaks. Error reports are configured to exclude the contents of your requests. Neither the logs nor the error reports contain the text of your questions, private chat or not.
If you report a problem with a text. The source cards carry a “Report a problem” button for when a passage in our library is damaged — a garbled word, a footnote spliced into a verse, a wrong author or date. What is sent is the reference of that passage and whatever you type into the box, and nothing from your conversation goes with it. These reports are read by a person, because that is the only way they get fixed.
If you ask for an invitation. Amos Standard is in a closed beta, so the front page offers a waiting list. If you put your address there, we keep that address and the date, and nothing else — no name, no account, no profile. We use it to send you an invitation and for nothing else, and you can ask us to remove it at any time by writing to privacy@amosstandard.com.
What we do not collect
We do not sell your data. We do not share it with advertisers. There is no advertising in Amos Standard, and there are no advertising trackers on it.
We do not send your questions, answers, notes, or prayer journal to our analytics provider. The prayer journal and notes screens report nothing at all — not even the fact that you visited them.
There is no session recording and no heatmap tracking. The screen shows your question, the answer, your journal and your notes; a recording of it is not something we are willing to hold, or to hand to anyone else.
How your questions are answered
This is the part most apps do not spell out, and it is the part you should know.
When you ask a question, the text of your question is sent to the AI providers we use to produce an answer. Here is exactly who gets what, and why:
| Provider | What we send | Why |
|---|---|---|
| OpenAI (privacy policy) — based in the United States | The text of your question, plus the passages our search found for it | First your question is turned into a mathematical representation so we can search our library of Christian texts. Then OpenAI writes the answer you read. |
| Mistral AI (privacy policy) — based in France | The same, but only if OpenAI is unavailable | Our standby answer generator. On an ordinary day it receives nothing at all. |
We do not send your email address or your account number with the question. The provider receives the words you typed, not who typed them — unless you write something identifying into the question itself. The one exception is the name you may have set in Settings: if you have given one, it travels with the question, because that is what lets the answer address you. Leave it empty and nothing of the sort is sent.
How long they keep it, and what they do with it. OpenAI keeps requests for up to 30 days to watch for abuse of its service, and then deletes them; it does not use them to train its models. Mistral does not use them for training either — we have turned that setting off on our account — and it would only ever see a question on a day OpenAI is down.
Before a question leaves us, we strip the things people type by accident: email addresses, phone numbers, card-length runs of digits, and links carrying a token. We do not touch names — this library is made of them, and removing Paul or Jerusalem would make the question unanswerable.
Be clear about what that does and does not do. It removes what could tie a question back to a person; it cannot remove the substance of the question, because the substance is what we were asked to answer. So please treat anything you type into the question box as leaving our systems, and consider that when writing about something deeply private.
This applies to a private chat too. A private chat stops us from keeping your question; it does not stop the provider above from receiving it, because a question nobody reads cannot be answered. What it means in practice: nothing of it stays with us, and OpenAI holds it for up to 30 days for abuse monitoring, unnamed, before deleting it.
One more check runs on your question. It goes to OpenAI’s moderation service — the same company, no one new — which looks for a single thing: a sign that you may be about to harm yourself. If it sees one, nothing is blocked and nothing is refused; the answer is written as it always would be, and a short note appears beside it suggesting you also speak to someone who can be with you. We do not record that this happened, and it is not kept with your conversation.
Your prayer journal and your notes are not sent to any AI provider. They stay in our database.
Who else handles your data
Each of these holds data under its own privacy policy, linked so you can read it:
- Supabase (policy) — our database and sign-in provider.
- Vercel (policy) — hosts the website.
- Fly.io (policy) — hosts our services.
- Google (policy) — sign-in.
- Sentry (policy) — error reporting, configured to exclude personal data.
- Cloudflare (policy) — an invisible check that runs before an answer is generated, to keep automated traffic off it.
- PostHog (policy) — usage analytics, described below. Your data is held in PostHog’s European region.
Usage analytics, and how to turn them off
We record which parts of the app are used — for example, that a question was asked, or that someone opened the sources behind an answer — so we can tell what is worth building. These records never contain your questions, your answers, your notes, or your journal. Your email address is never sent to our analytics provider either: there you are a random string of characters and nothing more, which is what lets us see that someone came back on Tuesday without knowing who. A private chat reports nothing at all — not even that a question was asked, because the time you asked one is itself something you may not want recorded.
You can turn this off in Settings. The setting belongs to your account, not to the device you set it on, so turning it off on your phone also turns it off on your laptop. We will not ask you again, and nothing about the app works worse if you say no.
If you are in the European Economic Area or the United Kingdom, analytics stay off until you turn them on in that same place. There is no banner and no prompt — interrupting your first screen with a choice you have no way to evaluate is not something this app will do to you.
If the law asks for your data
We may have to disclose data when a valid legal order requires it — a court, or an authority acting within its powers. This has never happened, and we will say so here for as long as it stays true.
If it does happen, we will tell you, unless we are forbidden from telling you. We will not hand over more than the order actually demands. And we will not volunteer your data to anyone who merely asks politely, however official the letterhead.
Who can read what you write
Amos Standard is made by one person, so there is no “authorised personnel” to hide behind. I hold the keys to the database. Technically, I can read what is in it, and any policy that implies otherwise would be a lie told with a straight face.
So here is the rule I hold myself to, and you should hold me to it as well:
- I do not read your conversations, your notes, or your prayer journal.
- I open the database to repair something that is broken, or to answer a support message you have written to me about — and for nothing else. Not to see how the product is doing, and not out of curiosity.
- When I need to know whether something works, I use my own account.
- There is no team, no contractor, and no dashboard anywhere that displays your text to anyone.
A promise is worth more when something enforces it. Because your text is encrypted in the database (see Security), opening the database is not enough to read it — the key lives with the application, not beside the data. That does not put your journal beyond me, and I will not pretend it does. It does mean nobody reads it by accident, and it means the answer to “who else could” is genuinely nobody.
How long we keep things, and how to delete them
We keep what you create until you delete it. We do not currently delete old conversations or notes on a schedule. A private chat creates nothing to keep, so nothing here applies to it.
You do not have to delete everything to delete something. Any single conversation, note, journal entry, bookmark, or memorised verse can be removed on its own, whenever you want, without touching the rest.
You can delete your account yourself, at any time, in Settings. It removes everything: your conversations, your prayer journal, your notes, your bookmarks, your reading progress, and your usage records. It is immediate and it cannot be undone. There is no thirty-day grace period, no archived account sitting somewhere in case you change your mind, and nothing for us to restore if you ask.
Many services have to add a caveat here about backups — a deleted account lingering in a nightly snapshot for a month. On the plan our database runs on, there are no automatic backups at all, so there is no such copy and no such lingering. When it is gone, it is gone from everywhere.
If that ever changes — a service holding this much of people’s inner life ought to be able to survive a hardware failure, and backups are how that is done — we will say so here and tell you how long a deleted account would then persist, before the change takes effect and not after.
If you would rather have a copy of your data first, write to privacy@amosstandard.com and we will send it within one month.
Why we are allowed to hold this (legal bases)
Amos Standard is run by one person living in Poland, so European data protection law (the GDPR) applies to everyone who uses it — including users in the United States. That is a higher standard than US law alone would ask for, and we are glad of it. It means we have to name the basis for each thing we do:
- To provide the app — your account, your conversations, your notes, your journal, your settings: performance of our contract with you.
- Your religious beliefs — your chosen tradition, your prayers, and the questions you ask all reveal religious belief, which the law treats as a special category requiring more care: your explicit consent, given when you create your account. You may withdraw it at any time by deleting your account, and we will delete the data with it.
- Keeping the service working and secure — error reports, server logs: our legitimate interest in a service that functions and is not abused.
- The waiting list — your consent, given by typing your address in and submitting it. Withdraw it by writing to us, and the address is deleted.
- Usage analytics — our legitimate interest in knowing which parts of the app are worth building, made fair by collecting no content and by letting you switch it off. In the EEA and the UK analytics are off until you turn them on.
Sending data outside your country
Amos Standard is run from Poland, and most of the services it depends on are based in the United States — including the provider that answers your questions. Using the app means your data is processed there, under privacy laws that differ from your own. The standby answer generator is in France, inside the European Economic Area.
Your rights
Depending on where you live, you may have the right to access, correct, delete, or obtain a copy of your personal data, to restrict or object to processing, to withdraw consent, and to appeal if we refuse. If you are in California, this includes rights under the CCPA/CPRA; we do not sell or share personal information as those terms are defined there.
You also have the right to complain to a data protection authority. Ours is Poland’s UODO (Urząd Ochrony Danych Osobowych), ul. Stawki 2, 00-193 Warsaw, Poland, and if you live in the EEA you may complain to your own country’s authority instead.
Write to privacy@amosstandard.com and we will respond within one month.
Security
Your data travels over encrypted connections, and it does not sit in the database as readable text. Your conversations, your notes, your prayer journal, and the tradition you have chosen are encrypted before they are stored, with the key held by the application and never kept in the database itself.
What that buys you is specific, so here is the honest version. If someone obtained a copy of our database — a stolen password to it, a leaked backup, a demand served on our database provider instead of on us — they would find unreadable text. What it cannot protect against is a break-in to the application itself, which necessarily holds the key. And it is not end-to-end encryption: you sign in with Google, so there is no password of yours to build a key from, and your question has to be readable to be answered at all.
Scripture passages you have saved are stored as ordinary text. They are the public Bible, and keeping them searchable is worth more than hiding what everyone can already read.
No system is perfect, and we will not claim otherwise.
If something goes wrong. If your data is exposed in a way that puts you at real risk, we will write to you and tell you what happened, what was affected, and what we did about it — without undue delay, and without waiting until we have a comfortable version of the story. We will also report it to our supervisory authority within 72 hours, as the law requires.
Children
Amos Standard is not intended for children under 18. We do not knowingly collect data from them. If you believe a child has created an account, write to us and we will remove it.
Changes
If we change this policy in a way that affects what we collect or who receives it, we will say so in the app before the change takes effect — not quietly, and not only by changing the date at the top. Every change is also listed below, in plain words, so you can see what moved and when.
What has changed
- August 23, 2026 — Added a way to report a damaged passage in the library. It sends the passage’s reference and what you write, never any part of your conversation, and it is read by a person so the text can be fixed.
- August 23, 2026 — Added the private chat: questions asked there are not stored and are not counted in usage analytics. This collects less than before, not more, and adds no new recipient of your data.
- August 6, 2026 — First published.
Contact
See also the Terms of Use.