Who we are
Sabbath is a Christian meditation and prayer app. We help you create personalized, Scripture‑rooted meditations. This policy explains what we collect, why we collect it, and how we protect it.
What we collect
- Account info: name, email, authentication identifiers.
- Discovery inputs: chat messages, optional voice memos, journal notes, selected emotions or goals.
- Generated content: meditation scripts, audio chunks and final audio.
- Usage, attribution, and device info: installs, sessions, campaign or referral information, product interactions, timestamps, IP or network metadata, device and operating-system details, app version, and request metadata.
- Billing info: subscription and payment status handled by Apple or Stripe; we do not store full card details.
How we use your information
- To personalize meditations and maintain your session history.
- To operate core features (generation, playback, storage) and improve quality and safety.
- To provide customer support and communicate important updates.
Attribution and analytics
We use bounded analytics and advertising-attribution data to understand whether the product works and which campaigns lead to installs or subscriptions.
- The iOS app uses AppsFlyer to measure installs, campaign attribution, sessions, selected product interactions, and server-verified subscription lifecycle events. AppsFlyer may receive campaign data, IP or network metadata, device and operating-system details, app version, an AppsFlyer-generated install identifier, and an opaque Sabbath account identifier after sign-in.
- AppsFlyer is configured in strict mode. The app does not request App Tracking Transparency permission or collect Apple's IDFA for AppsFlyer.
- We never send journal entries, meditation text, email addresses, authentication tokens, or payment-card details to AppsFlyer. Apple and Stripe remain the payment authorities; AppsFlyer receives only bounded purchase lifecycle data after server verification.
- On the website, Google Analytics and Google Ads plus the Meta Pixel and Conversions API measure visits and checkout activity under their respective privacy controls.
- Microsoft Clarity provides masked session-replay and interaction analytics only on non-sensitive public marketing, legal, resource, intentionally public meditation-share, and adult-facing kids-resource pages. Clarity is not loaded on sign-in, sign-up, guest generation, account, discovery, journey, library, private player, or dashboard pages.
Processors and storage
We rely on vetted providers to deliver the service:
- Authentication, database and storage: Supabase (managed Postgres) and object storage (S3‑compatible).
- AI models: OpenAI and Google (Gemini) for text; ElevenLabs for text‑to‑speech audio.
- Payments: Apple for in-app purchases and Stripe for hosted subscriptions and invoicing.
- Attribution and analytics: AppsFlyer for the iOS app, and Google, Meta, and Microsoft Clarity for bounded website measurement.
- Hosting and delivery: our API and web app hosting with secure TLS, signed URLs for media access.
Where possible we use signed, time‑limited URLs, least‑privilege API keys, rate limiting, and encryption in transit. See Product and Pricing for general features; see the repository SECURITY.md for engineering details.
AI processing (Google Gemini, OpenAI, ElevenLabs)
To personalize your meditations, we send portions of your inputs (for example, discovery chat text, journal notes, and summarized voice transcripts) to model providers to generate script text and narration audio. We do not send your account password or payment information.
- Text models (Google Gemini, OpenAI): receive the necessary prompt context to produce a personalized script and short summaries. According to provider documentation, content may be temporarily retained for abuse detection and service reliability and is not used to train models without opt‑in; see each provider’s policy.
- Voice (ElevenLabs): receives the script text and voice settings to synthesize audio. We do not send your raw account credentials to ElevenLabs.
If you prefer not to share certain information, avoid including sensitive details in discovery or journal inputs. You may request deletion of your account and associated content at any time.
Data retention
- Discovery transcripts and notes are retained to personalize future sessions until you delete your account or request removal.
- Generated audio and scripts are stored so you can replay history.
- We keep minimal logs for reliability and abuse prevention.
Your choices
- Access and correction: update your email and settings in the app.
- Deletion: Delete your account in the app from Account > Delete Account. If you cannot access the app, email support for help recovering access first.
- Communication: you can opt out of non‑essential emails.
Children
Sabbath is not directed to children under 13. Do not use the service if you are under the applicable age in your region.
International transfers
Providers may process data in the United States and other regions. We use reputable vendors and standard safeguards appropriate to the services they provide.
Changes
We may update this policy. We will post the new effective date and, when material, notify you in‑app or by email.