Privacy policy
Effective October 11, 2026 · Pre-release service
Native operates Lamp. Contact contactnativeinc@gmail.com with privacy questions or requests.
Your choices
You can read Scripture without an account. Without an account, your journal, reading position, reading plans and daily completion are kept only on your device and in your own device backups; we do not receive them, and Settings can delete them. Creating cloud storage is optional and requires agreement. AI processing, optional faith preferences, and optional analytics have separate controls. Your journal is not sent to AI. Turning off AI processing stops new AI requests; delete existing chat entries or your account to remove stored history.
Data used to provide the service
You sign in with Apple or Google, and Firebase Authentication keeps your login. If you choose Sign in with Apple, Apple provides an account identifier; we do not request your name or email from Apple. If you choose Google, Google shares your name, email address and profile picture with Firebase Authentication, which keeps them with your login; Lamp's service uses only the account identifier. Lamp uses an account identifier, locale, timezone, routine preferences, and consent records to operate your account. If you choose to provide religious tradition or faith topics, these may reveal religious beliefs and are used for the features you enable. Journal entries, your questions and their answers (kept as conversations you can return to), and daily completion records are stored for your account. So the app opens quickly, it also keeps a copy of your signed-in account content (profile, journal, conversations and today's reflection) on this device, protected by the device's encryption and excluded from device backups; signing out or deleting your account removes it.
If you enable AI, your question and, for a follow-up, a limited excerpt of the preceding question and answer are sent to OpenAI along with public Scripture evidence. Avoid entering information about other people that you are not entitled to share. This is not confidential professional advice.
If you report a problem with an answer, your email app opens with a draft containing the question, the answer and its citations. Nothing is sent unless you choose to send that email.
Subscriptions
Lamp’s features, except the daily verse widget, require a free trial or subscription purchased through Apple. When the subscription page appears, the app starts RevenueCat with an anonymous app identifier so it can record your purchase, trial status and renewals; RevenueCat does not receive your name, email, journal, questions or faith preferences at that point. We remind you on your device two days before a free trial ends. If you later sign in and choose to connect your subscription to your account, a disclosure is shown first, and RevenueCat then links the purchase to your Lamp account identifier so your answers can be verified. If you installed Lamp from an Apple Search Ads ad, Apple’s AdServices framework provides campaign attribution (such as the campaign and keyword, never an advertising identifier), which RevenueCat records with your purchase so we can see which ads lead to subscriptions. This does not track you across other companies’ apps or websites. RevenueCat processes your Lamp account identifier, purchase and subscription history, product identifiers, locale and currency. We use this information for subscription access, fraud prevention and purchase reporting. We do not send RevenueCat your journal, questions, answers, email address or faith preferences. Apple processes payments; we do not receive your payment-card information.
Optional product analytics and subscription transaction records are separate. Turning off optional usage events does not remove records needed to provide and administer a subscription. See RevenueCat’s privacy policy and Apple’s App Store privacy information.
Service providers and security
We use Google Firebase for authentication and crash reporting, Mixpanel for product analytics when usage data is on, Apple for Sign in with Apple and Google for Google sign-in when you choose them, Render for the API, Neon for database hosting, OpenAI for AI processing, and RevenueCat for subscription services when enabled. Data may be processed in the United States and other locations where these providers operate. Private journal, profile, and conversation content use server-managed encryption in our database and encrypted transport. This is not end-to-end encryption; the service can decrypt data to fulfill your requests.
Our OpenAI requests disable response storage. OpenAI’s API policies describe separate abuse-monitoring retention, generally up to 30 days, with applicable exceptions. This setting does not guarantee zero provider retention. See OpenAI’s data controls.
Optional Bible downloads
If you choose the King James Version where it is offered, Lamp downloads its reviewed source directly from eBible.org and keeps a verified copy on your device for offline reading. eBible.org receives the network information needed to deliver the file, including your IP address; Lamp sends no account or device identifier with this download. Availability uses the country of your App Store account, which is stored locally and sent with KJV question and reflection requests to check availability. It is not used for analytics or to determine your physical location.
If you play a chapter’s audio, our server sends the app to our copy of the public-domain recording at audio.nativeuno.com, stored with Cloudflare, which then streams it. Cloudflare receives the network information needed to deliver the audio, including your IP address; Lamp sends no account or device identifier with it.
Analytics and logs
To keep answers fast and fair for everyone, the service records how long each answer took and whether it succeeded, without its content. When use is unusually heavy, our server automatically checks patterns in your recent questions (for example, many near-identical questions in a short time); this stores only a control status for your account, not new copies of your questions, and a person reviews any lasting restriction. To stop automated misuse, the app sends two technical proofs with each new question: Apple’s App Attest through Firebase App Check confirms the request comes from the genuine app, and Apple’s DeviceCheck lets us limit how many accounts ask questions from one device. DeviceCheck stores two bits for the device at Apple; we keep only the time an account was counted, never a device identifier. The daily verse widget downloads the reviewed verse schedule from our server twice a day, and the app downloads the next month of reviewed daily reflections at most twice a day; these requests carry no account or device identifier. If usage data is on (Settings), the app sends Mixpanel which steps you take in the app — for example finishing a reflection, reading a chapter, asking a question, saving a journal entry, or opening and completing the subscription page — with a random identifier for this installation and, once you sign in, your Lamp account identifier. These events never include the text of your journal, questions, answers or reading, and Mixpanel is not given your IP address for location. We use them to understand which parts of Lamp help people keep a daily habit and to improve the app; they are not used for advertising. Turning usage data off in Settings stops them. The app also sends anonymous usage counts: daily totals of steps such as viewing an onboarding screen, opening the subscription page, starting or completing a purchase, or placing the widget. They carry no account, device or install identifier, and we do not store IP addresses with them. You can turn them off in Settings. Optional product events contain bounded action names and timestamps, not raw questions, answers, journal text, or faith-topic values. Turning off analytics removes the account’s stored product events.
Crash reports are on by default and can be turned off in Settings. When on, Firebase Crashlytics receives crash diagnostics: device model, operating-system and app versions, an installation identifier and technical details of the crash. Crash reports are not linked to your account and do not include your journal, questions, answers or reading. Operational providers may process network, device, security, and diagnostic information needed to operate their services. We do not sell personal information or use cross-app advertising tracking.
Retention and deletion
Account content remains until you delete it or the account. Deleted chat and journal text is removed from live storage; minimal request identifiers, revision information, and usage totals may remain to prevent duplicate requests and limit abuse. Account deletion removes live profile, journal, chat, and completion content. The app also provides a separate step to delete the Firebase login account. If you signed in with Google, deleting the login also removes Lamp’s access to your Google account. You can remove Lamp from Sign in with Apple at any time in your Apple Account settings.
Deleting your Lamp account does not cancel an Apple subscription. Use Apple subscription settings to manage or cancel it. If your account was connected to RevenueCat, account deletion also queues a request to remove its RevenueCat customer record. This is separate from removing your live Lamp content: the provider may accept a request before its deletion work has finished. We retain a protected account reference, request status and attempt timestamps to process and follow up on the request. These records contain no journal or question text. Contact our support address for the status or to request review of residual subscription records. Apple transaction records are separate and may be retained for transaction administration or legal requirements.
A pseudonymous deletion-blocking record is retained to prevent old credentials or restored data from recreating a deleted account. Service-wide spending totals contain no question text. Provider recovery copies and legally required security records may not disappear immediately. Contact us for retention details or to request review of residual records. Our pre-release backup and recovery procedures are still being validated; this policy does not promise immediate deletion from every provider copy.
Access and contact
The in-app export includes your local account content, consent, subscription enrollment and question-usage records; it does not include all records held by Apple or RevenueCat. Use the in-app export and deletion controls, or contact us to request access, correction, deletion, or withdrawal of optional consent. We may need to verify account ownership. The service is intended for adults and is not directed to children under 13. If you believe a child has provided personal data, contact us.
Changes
We will update this page when practices change and seek new consent where required for a materially different use of optional sensitive content.