Skip to content
ScriptureDepth

Privacy Policy

Last updated: 4 September 2026

Who is responsible for your data

ScriptureDepth is operated by a Norwegian sole proprietorship (enkeltpersonforetak), organisation number 937 473 737, registered in Norway. We are the data controller for the personal data described below. Our postal address is available on request by email.

Privacy questions, and all requests about your rights: hello@scripturedepth.com. We have not appointed a data protection officer; we are not required to.

The short version

You can read the whole site without an account and without being tracked. We ask for an email address if you want an account, the devotional, or the free email course. We run no advertising pixels and set no analytics cookies; the only traffic measurement is cookieless and cannot be traced back to you. We do not sell your data.

What we collect, why, and on what basis

Account data

Email address and a hashed password, or — if you sign in with Google — the email address and basic profile Google returns. Held to create and run your account and keep you signed in.

Basis: performance of a contract (GDPR Art. 6(1)(b)). Kept until you ask us to delete the account, then removed within 30 days.

What you write: AI chat, study notes, saved answers, reading plan progress

Questions you ask the study chat, notes you save on a chapter, answers you choose to save or share, and which reading plan days you have ticked off. These are stored so the features work and so your history is there next time.

Basis: performance of a contract (Art. 6(1)(b)). Because these are free-text entries on a Bible study site, what you write may itself reveal your religious belief or something about your personal circumstances — that part rests on your explicit consent (Art. 9(2)(a)), which we ask for in so many words the first time you save a note or a conversation while signed in, and record with the date. You can withdraw it from your account page at any time; withdrawing deletes every stored note and saved conversation. Kept until you withdraw, delete the entry, or delete your account.

Devotional and email course subscriptions

Your email address, plus which day of the five-day course you have reached. Used only to send the emails you asked for.

Basis: consent (Art. 6(1)(a)). Kept until you unsubscribe — every email carries an unsubscribe link. Course state is deleted when the five days end.

Purchases

If you buy Pro or a study pack, Stripe handles the payment and we store the resulting subscription or order record (your user id, Stripe customer and session ids, plan or pack, amount, status). We never see or store your card number.

Basis: performance of a contract (Art. 6(1)(b)) and our legal obligation to keep accounting records (Art. 6(1)(c)). Sales records are kept about five years after the end of the financial year, as Norwegian bookkeeping law (bokføringsloven) requires.

Transactional email

Email confirmations, password resets, purchase receipts and account notices, sent through Resend.

Basis: performance of a contract (Art. 6(1)(b)).

Security and abuse prevention

Short-lived counters keyed to your IP address and, for password-reset and verification emails, your email address. They exist so nobody can flood an inbox or hammer the AI chat.

Basis: legitimate interests in keeping the service available and not being used to spam other people (Art. 6(1)(f)). These counters expire on their own within minutes to a few hours.

Anonymous traffic measurement

Vercel Analytics and Vercel Speed Insights count page views and page-load timings. They set no cookies and store no identifier we can trace back to you. Clicks on a few buttons and links, and completed purchases, are also counted through our own server: the event name, the page, and for a purchase the product and amount are forwarded to Google Analytics under a random one-off id, with no cookie and none of your details, so Google receives counts it cannot tie to a person.

Basis: legitimate interests in knowing whether the site works (Art. 6(1)(f)).

Why we run no tracking on a Bible study site

A record of which pages you open here is a record of Bible chapters, Christian topics and study material, so it can indicate your religious belief. That is a special category of data under GDPR Art. 9(1), and the Norwegian Data Protection Authority (Datatilsynet) reached exactly that conclusion in 2026 about another Norwegian Bible website that ran advertising pixels. We therefore run no Google Analytics script, no Meta pixel and no other third-party tracker, and we set no analytics or advertising cookie. If that ever changes, we will ask for your explicit consent first, name the companies involved, and make refusing exactly as easy as accepting.

The full list of cookies and storage keys, with lifetimes, is in the Cookie Policy.

AI chat and study notes

When you ask the study chat a question, the question and the relevant Scripture context are sent to OpenAI, which generates the answer. We store the exchange so you can find it again; Pro accounts keep a full history. Study notes you write on a chapter are stored in our database and are visible only to you unless you explicitly share an answer.

Be aware that what you type is content: if you write about your own doubts, health, family or faith, that text is stored and is processed by OpenAI as part of producing an answer. Please do not enter information about other people that they would not want shared. You can delete any note at any time. Pro and trial accounts can download all of their notes from the account page; on the free plan that button is not available, so email us and we will send you the same export.

Who processes data for us

We do not sell your personal data and we do not share it with anyone beyond the providers that run the service:

  • Supabase Inc. (United States) — database, authentication, account and content storage.
  • Vercel Inc. (United States) — hosting, request logs, and the cookieless Analytics and Speed Insights described above.
  • Resend Inc. (United States) — sending transactional, devotional and course email. Resend stores account data, email metadata and delivery logs in the United States regardless of where the mail is sent.
  • OpenAI Ireland Ltd (Ireland, processing in the United States) — generating AI chat answers and the AI-written study material.
  • Stripe (Stripe Payments Europe Ltd, Ireland, and Stripe Inc., United States) — payments, subscriptions and receipts. Stripe is an independent controller for its own fraud-prevention and compliance purposes.
  • Upstash Inc. (United States) — the Redis store holding email-course subscriber addresses and the short-lived rate-limit counters.
  • Google (Google Ireland Ltd and Google LLC) — Google Analytics, server-side only: the cookieless event and purchase counts described above, sent under a random one-off id. No Google script runs in your browser.
  • Amazon — some articles recommending books and study tools link to Amazon with an Amazon Associates tag, so a purchase can be credited to this site. Amazon is not our processor: we send it nothing. Your browser goes to Amazon only if you click, and from that point Amazon is an independent controller under its own privacy notice.

Those affiliate links are marked as sponsored links and are set out in the Affiliate Disclosure. A click on one is counted through our own server as an affiliate_click event naming the article and the product, under a random one-off id, with no cookie and nothing that identifies you.

We may also disclose data where the law requires it, or to establish or defend a legal claim.

Transfers outside the EEA

Most of the providers above are in, or transfer data to, the United States. Those transfers are covered as follows:

  • Adequacy decision (Art. 45) — Vercel, Stripe, Google and Upstash are certified under the EU–US Data Privacy Framework.
  • Standard Contractual Clauses (Art. 46(2)(c)) — Supabase, Resend, and OpenAI. OpenAI is not certified under the Data Privacy Framework; its transfers rely on the Clauses.

You can ask us for more detail about the safeguards for any specific provider at the address above.

How long we keep things

  • Account, chat history, study notes, reading progress — until you delete them or delete your account (removed within 30 days of the request).
  • Devotional and course subscriptions — until you unsubscribe.
  • Cookieless event and purchase counts in Google Analytics — up to 14 months, with no identifier that reaches you.
  • Security and rate-limit counters — minutes to a few hours.
  • Sales and accounting records — about five years after the end of the financial year, as bokføringsloven requires.

The last item is a real limit on erasure: if you ask us to delete your account, we still have to keep the record that a sale happened. GDPR Art. 17(3)(b) allows exactly this where another law requires retention.

Your rights

Under the GDPR you have the right to:

  • Access a copy of the personal data we hold about you (Art. 15).
  • Rectification — have inaccurate data corrected (Art. 16).
  • Erasure — have your data deleted (Art. 17), subject to the accounting-record limit above.
  • Restriction of processing while a dispute is resolved (Art. 18).
  • Portability — receive your data in a machine-readable form, or have it sent elsewhere (Art. 20).
  • Objection to processing based on our legitimate interests (Art. 21).
  • Withdraw consent at any time, without affecting what was done before you withdrew it (Art. 7(3)).

To exercise any of these, email hello@scripturedepth.com from the address on your account. We answer within one month of receiving the request, as Art. 12(3) requires; if a request is unusually complex we may extend that by up to two further months and will tell you why within the first month.

If you think we have handled your data badly, you can complain to the Norwegian Data Protection Authority, Datatilsynet datatilsynet.no, postkasse@datatilsynet.no. You may also complain to the supervisory authority where you live or work.

Your right to object to direct marketing

You have the right to object at any time to the processing of your personal data for direct marketing, including the profiling that goes with it. This is an absolute right: if you object, we stop, and there is nothing for us to weigh against it (GDPR Art. 21(2)–(3)).

In practice: use the unsubscribe link at the foot of any devotional or course email, or email hello@scripturedepth.com and say so. No reason needed.

Children

ScriptureDepth is not aimed at children. In Norway a child can consent to information society services from the age of 13 (personopplysningsloven § 5), so you must be at least 13 to create an account. If you believe a younger child has given us personal data, email us and we will delete it.

Changes to this policy

If we change what we collect or why, we will update this page and move the date at the top. If the change affects something you consented to, we will ask again rather than assume the old answer still stands.

Contact

Norwegian sole proprietorship, org. nr. 937 473 737 · postal address on request ·hello@scripturedepth.com