Privacy Policy
Olive & Cross · Effective August 26, 2026
Olive & Cross is designed as a private place for daily Scripture, prayer, reflection, and journaling. This policy explains what the app stores, what leaves your device, and the choices available to you.
Information stored on your device
Olive & Cross does not require an account. By default, your journal entries and Bible bookmarks, highlights, and last-read position are kept in a local-only store on this device. That store is excluded from the device’s iCloud backup. If you explicitly enable private iCloud backup, the app moves those journal and Bible-library records into your private Apple CloudKit database so they can appear on your Apple devices. Olive & Cross does not operate or receive a copy of that private CloudKit database. Turning private iCloud backup off copies those records back to local-only storage and queues deletion of the app’s private CloudKit records. Apple syncs that deletion when iCloud and the network are available; keep the app installed and online until the sync has had time to complete.
Your first name, saved devotionals, daily and guided-journey progress, prayer requests and check-ins, notification preferences, AI-consent preference, analytics preference and queue, and conversation history remain in Apple system storage on this device; enabling journal and Bible iCloud backup does not move those other categories to CloudKit. The standard weekly recap is calculated on your device from this local activity and does not upload or quote your journal. Deleting the app generally removes local information, but it may not by itself remove records previously synced to your private CloudKit database. Use Delete All Personal Data in Profile → Privacy & Safety to remove the app’s local personal data and queue deletion of its private-CloudKit journal and Bible records.
Daily rhythm preferences, saved Scripture-memory verses, review progress, and weekly intentions remain in protected storage on this device and are excluded from device backup. They are never sent to AI. Evening sessions are narrated with an AI-generated voice. When you listen, the app downloads that session’s pre-recorded audio file from the Olive & Cross website; the request names only the session and language, contains nothing you have written, and is handled like any ordinary web download. When a file cannot be downloaded, Apple’s on-device narration reads the session instead and that audio is created locally. Downloaded and locally created audio is saved only on this device. Optional practice reminders use generic text that does not reveal your intention or verse. Delete All Personal Data removes these records, their reminders, and saved evening audio.
Journal lock and exports
If you turn on Journal Lock, Olive & Cross asks Apple’s LocalAuthentication system to evaluate Face ID, Touch ID, or the device passcode before showing your journal. Biometric templates and passcode values remain under Apple’s control; Olive & Cross receives only the authentication result and cannot read or store your biometric or passcode data.
Journal export happens only when you request it. The app prepares a PDF or portable data file on the device and presents Apple’s file exporter so you choose whether and where to save it. Olive & Cross does not automatically upload an exported file. The exported file may contain private journal content, and Apple or any storage provider you select may process it under their own terms.
Optional AI companion
The AI companion is optional. After you explicitly enable it, Reflect sends the message you submit plus up to eight recent messages from the selected conversation to the Olive & Cross backend and OpenAI so the response can keep short-term context; exact bundled passages may also be included for Bible references in that context. Prayer and Questions send only the new request. Verse also sends one exact passage from a bundled public-domain Bible: WEB Updated or ASV in English, Reina-Valera 1909 in Spanish, or Kulish–Pului 1905 in Ukrainian. If you separately opt in to an AI weekly summary, only the journal entries you explicitly select and submit for that summary are included; conversation history, Scripture context, profile data, streaks, and other journal entries are excluded from that request. Your journal, first name, streak, reminder preference, and other app data are never included automatically.
OpenAI API requests are sent with response storage disabled. OpenAI may still process or temporarily retain limited request data for security and abuse prevention under its applicable service terms. Olive & Cross does not use submitted reflections for advertising, sell them, or use them to train its own models.
Microphone and read-aloud
If you choose voice prayer, microphone audio is processed by Apple’s on-device speech recognition while you record. Olive & Cross does not upload or retain that audio. The resulting transcript remains editable and is submitted for AI processing only if you tap Send. Devotional read-aloud uses Apple’s on-device speech synthesizer and does not send the devotional audio to Olive & Cross or OpenAI.
Device and subscription verification
When the AI companion is enabled, Apple DeviceCheck provides a short-lived, authenticated device token to the Olive & Cross backend. The backend uses that token to ask Apple for two privacy-preserving device bits that record how many complimentary AI responses the device has used. Apple also reports the month in which those bits last changed; the backend uses only that month to renew the three complimentary responses each calendar month. It also converts the token into a keyed pseudonymous lock identifier while a response is being prepared so simultaneous requests cannot update those bits incorrectly. The raw DeviceCheck token is not written to the lock store, and the lock normally expires within 60 seconds. Apple maintains the two bits so reinstalling the app or deleting local data does not reset the current month’s complimentary allowance. Olive & Cross does not create a server profile from this information.
For Premium subscribers, the app may also send an Apple-signed StoreKit transaction proof. The backend verifies its signature, product, expiration, and revocation status in real time to confirm access. The proof is not retained by Olive & Cross after the request is serviced.
Service protection and technical data
Like other internet services, the Olive & Cross backend and its hosting provider receive technical connection information, such as a network address, when servicing a Companion request. Olive & Cross application code does not write the raw network address to its rate-limit counter store. It first converts the address into a keyed pseudonymous value that is used only to count requests during the active rate-limit window, currently 10 minutes. The counter then expires automatically and is not combined with Companion text, purchase information, or an account identity.
The backend also keeps one global daily count of AI requests to control service cost. That count contains no user, device, network-address, or conversation identifier and expires automatically. Infrastructure providers may process routine technical request data for delivery, reliability, and security under their applicable terms. Olive & Cross does not use these service-protection records for advertising, analytics profiles, or cross-app tracking.
Optional private product analytics
Private product analytics is optional, separate from AI consent, and off by default. If you turn it on, the app counts a small allowlisted set of actions—such as completing onboarding or a daily practice, opening a paywall, or completing a purchase—and combines matching actions on your device before sending them. It may include only broad categories such as free or Premium, monthly or annual, the part of the app where an action occurred, and a coarse days-since-install group: day 0, days 1–6, days 7–29, days 30–89, or days 90 and later.
Analytics never sends your journal or prayer content, Bible text, Bible search words, AI conversation content, name, contact information, or a user, device, account, or installation identifier. It does not send the time an action occurred. The app attempts at most one analytics upload per UTC day. Each batch receives a new random retry code that is used only to prevent that one batch from being counted twice; it is deleted after acknowledgement and is not reused as an identity.
The Olive & Cross backend assigns its receipt day and stores only combined daily counts. Combined daily counts are deleted automatically after 180 days. A one-way hash of the random retry code is deleted after 45 days. The analytics route does not copy IP addresses or browser/app User-Agent values into the analytics store, although hosting and network providers necessarily process routine connection data to deliver and secure the request under their own terms.
Olive & Cross does not use a third-party analytics SDK, advertising SDK, tracking cookie, or tracking pixel. These counts are used only to understand broad product retention and conversion, not to build a profile, identify a person or device, advertise, or track activity across apps or websites. Turning analytics off immediately deletes the app’s queued analytics and any batch waiting to retry. You can also delete collected analytics while leaving the preference available for future counts.
Purchases
Subscriptions are processed by Apple through StoreKit. Olive & Cross receives entitlement status and transaction information needed to unlock Premium, but does not receive your full payment-card details.
Notifications
If you opt in, the app schedules local daily reminders on your device. You can also choose a private, generic local check-in reminder for an individual prayer request; the notification does not include the prayer’s title or notes. You can disable reminders in the app or in iOS Settings.
Tracking and advertising
Olive & Cross does not include advertising SDKs, does not sell personal information, and does not track you across apps or websites.
Safety
Olive & Cross offers spiritual reflection, not emergency, medical, mental-health, legal, or pastoral services. AI can be incomplete or mistaken. If you may be in immediate danger, contact local emergency services. In the United States or Canada, call or text 988.
Your choices and deletion
You can revoke AI consent or turn private analytics off at any time in Profile → Privacy & Safety. Turning analytics off deletes its local queue and pending retry batch. You can delete individual journal entries or conversation history, or use Delete All Personal Data to remove the local journal and Bible store, conversation history, prayer and progress data, profile data, local analytics, and preferences. If private iCloud backup is enabled, Delete All also queues deletion of the journal and Bible records in the app’s private CloudKit store. Apple syncs those deletions when iCloud and the network are available; Olive & Cross can verify its local mirrored-store change but cannot confirm immediately that deletion has reached Apple’s servers. Keep the app installed and online until the sync has had time to complete. Purchases remain associated with your Apple Account.
Already combined server analytics cannot be linked back to you or selected for person-level deletion because they contain no user, device, account, or installation identity; those combined counts expire within 180 days. Because Olive & Cross does not require an account and does not retain raw DeviceCheck tokens or StoreKit proofs as a profile, there is no Olive & Cross server profile to delete. Short-lived rate-limit counters and device locks expire automatically and cannot be used to retrieve app content. Deleting personal data does not reset Apple’s device-level complimentary-use bits.
Children
Olive & Cross is not directed to children under 13 and does not knowingly collect personal information from children.
Changes
We may update this policy as the app evolves. Material changes will be reflected here with a new effective date and, when appropriate, communicated in the app.
Contact
Olive & Cross is published by TSM Digital. For privacy questions, support requests, or deletion concerns, email sergemoraru@gmail.com.