our promise
private, always.
no account. no ads. no third-party tracking. undertext names what leaves Your device, why it leaves, and how the services that carry it are configured.
what undertext knows
undertext has no login, advertising, or third-party tracking software, and it does not build an account profile of You. reading, Grace, voice transcription, licensed translations, and private writing each follow the specific path below.
when the full app first uses Grace or voice search, Amazon Cognito creates and retains a random credential identity for this installation. it exists only to issue short-lived AWS credentials for app functionality. it is not an undertext account, and it contains no name, email address, advertising identifier, reading history, or journal text. undertext does not use it for analytics, advertising, real-world identification, or tracking.
reading and cached scripture
Your reading preferences, including haptics, keep-screen-awake, and daily-verse time, are stored locally. scripture chapters You open are kept in the app's iOS cache and remain available offline while they are cached. iOS may clear that cache when it needs space; reconnect once to fetch a chapter again.
scripture and licensed translations
scripture is delivered from undertext.org over HTTPS. a chapter request necessarily gives the hosting service the request's IP address and file path while it is fulfilled. individual request logging and derived reading analytics are off, and only aggregate service-health counts remain.
the KJV and Sacred Name Edition use undertext's own reading data. NIV, Amplified, NASB, and BSB are requested live through undertext's translation proxy from YouVersion. licensed text remains only for the current reading session and never enters a Grace request.
private writing
Your journal uses Your private CloudKit database when it is available, then local storage on this device, then temporary memory. the journal shows which layer is protecting Your writing. local storage does not claim cross-device sync, and temporary memory can be lost when the app closes. if a journal save fails, the writing remains visible with a retry action.
Your library uses that same private CloudKit, local storage, then temporary memory order for highlights, saved verses, and Your last reading place.
Grace
Grace is optional. when You choose send, undertext sends Your current question, up to eleven earlier messages from this launch, the passage on the screen with its original-language context, and up to eleven earlier verse stops from this launch. the 4.1 release path routes that request through Amazon Bedrock to Claude from Anthropic. on iOS, Grace asks for explicit permission before the first send, and You can change that choice in Settings.
when You choose the mic, Your spoken audio streams through Amazon Transcribe to make an editable draft. Amazon Transcribe is separate from Grace's Bedrock text path. the draft is not sent to Grace until You choose send.
Amazon Bedrock is configured with request and response retention set to none, the Amazon Transcribe organization opt-out is applied, and no prompt, response, audio, or transcript is written to application logs.
notifications
if You turn on the daily verse, Apple schedules the reminder locally on Your device. no server is involved in scheduling it, and the notification content is not sent to undertext during that scheduling.
children
undertext is suitable for all ages. it does not create accounts or direct advertising at children. the same paths and protections described above apply to readers of every age.
changes
if this policy changes, this page will show the updated words and the release where they take effect.
contact
privacy questions: matthewgennings@gmail.com.