Emmaus — Privacy Policy
Disciple Maker LLC ("Emmaus," "we," "us," or "our") built the Emmaus app (the "App") to be a private, grace-centered companion for your walk with God. Because you may share some of the most personal things in your life with the App — your prayers, your struggles, your family, your spiritual state — we take your privacy seriously, and we want this policy to be clear and honest about what we collect, why, who processes it, and the control you have over it.
This Privacy Policy explains how we handle information in connection with the App. It is incorporated into our End-User License Agreement & Terms of Use. Emmaus is based in the United States, and the App is intended for a U.S. audience; if you use it from elsewhere, you consent to processing in the United States.
The short version.
- We collect only what we need to run the App for you: your account info, your profile, and the content you create (journals, prayers, goals, chat, and AI memories).
- To power the AI Companion and voice, relevant content is sent to our AI providers (Anthropic and OpenAI) after you affirmatively enable AI. You can decline and use Emmaus without AI.
- We do not sell your data. We do not use it for advertising. We do not allow our AI providers to use it to train their models. We do not track you across other apps or websites.
- Email: we send very little — today, one welcome guide from hello@getemmaus.app, to your account address or a contact address you give us. You can turn email off, or change the address, in Settings → Email. No tracking pixels, and no open or click tracking.
- Walking partners: connect with someone and they can see only the prayer requests you choose to share, plus your daily rhythms and current focus — one way only in a discipling connection, where the disciple sees nothing of the discipler's walk. Prayers start private. Coach conversations, journal and examen entries, and saved verses are never shared with a partner. Always by invitation, and either person can end it at any time.
- Your calendar, if you turn it on, is read on your phone and stays there. Nothing about your events is sent to us or to anyone else.
- Scripture: when a passage isn't in our own library, your phone fetches the public-domain text from bible-api.com directly. All that goes with it is the passage reference — nothing about you.
- You can export your data and delete your account and all associated data from within the App at any time. You can also view, edit, and delete the AI's memories, or turn AI learning off.
- We do not collect Apple Health or wearable data in Version 1.
- Children under 13: before asking for child account details, Emmaus sends a direct parent notice and obtains a signed parent or guardian consent form through a private emailed link. The signed submission is recorded as approval automatically. The parent separately chooses AI, voice, and connections and can later review, correct, withdraw, or delete.
1. Information We Collect
We collect the following categories of information, all provided by you or generated through your use of the App.
1.1 Account and authentication information.
- Email address and authentication credentials when you sign up with email/password, an email sign-in link, or Sign in with Apple. If you use Sign in with Apple and choose Apple's private email-relay option, we receive a relay address rather than your personal email.
- A user account identifier (a random ID assigned by our system) used to associate your data with your account.
1.2 Profile information. Information you provide to personalize the App, such as your first name or display name, time zone, preferred Bible translation, faith stage, and voice preference.
We also store a coarse age range (under 13, 13–15, 16–17, or 18+) and how it was obtained (for example, Apple's Declared Age Range feature or a manual range choice). We intentionally do not ask for or store a date of birth.
1.3 Content you create ("User Content"). The heart of the App. This includes:
- Journal and examen entries and reflections;
- Prayer requests and prayer-list items;
- Goals, your "Future Self" vision, and related plans;
- Chat messages you exchange with the AI Companion;
- AI long-term memory — durable facts the App extracts and stores so the Companion can remember your story over time (for example: people you mention, prayer requests, goals, recurring struggles, wins and answered prayers, preferences, and spiritual rhythms). Some of these facts are flagged as sensitive and given extra care.
- Notes, memory verses, habit logs, weekly reviews, and similar content.
1.4 Voice audio (transient, for voice features). If you use conversational voice, we capture audio recordings of what you say through your device microphone and send them for transcription so the Companion can understand and respond, and we generate spoken audio replies. Microphone access is requested only when you use voice, and you can always type instead. Voice audio is processed transiently to produce a transcript; see Section 3 (retention).
1.5 Sensitive information. Because of what the App is for, the content you share may include religious and spiritual beliefs and information about your mental or emotional state. Apple and various laws treat these as sensitive categories. We collect this only to provide the App's core features to you and never for advertising, profiling for third parties, or tracking.
1.6 Subscription and purchase information. When you subscribe, we receive subscription status and purchase history (for example, whether your subscription is active, the product, trial status, and renewal/expiration) from Apple through our subscription-management provider RevenueCat, associated with an app-user identifier. Apple processes your payment; we do not receive or store your full payment-card details.
1.7 Content reports. If you use the "Report a concern" control on an AI message, or report a walking partner or something they sent you, we collect the reported content and your report so we can review it (see Sections 5.1 and 6). A restricted operational alert tells the owner that a report is waiting using only its random report identifier, type, and time; the alert never contains the reported words, your account identifier, or your contact information.
1.8 Limited technical and diagnostic information. To keep the service running and secure, our infrastructure processes basic technical data such as device/app version, IP address (for security and connectivity), and error/diagnostic logs. We use this for reliability, security, and abuse prevention, not to build advertising profiles.
1.9 Contact address and email preference. If you would rather we wrote to a different address than the one you sign in with, you can give us a contact email address, and we use it instead. We also store your email preference (whether email from Emmaus is on or off) and the date a welcome message was sent, so it cannot be sent twice. Your contact address is visible only to you — never to a walking partner or a discipler.
1.10 Connections and invitations. If you invite someone to walk with you, we store the invitation — a random link token, the label you typed for that person, any email address or phone number you entered, the kind of connection you proposed, and whether it was accepted — and, once accepted, the connection itself, including which person (if either) is the discipler. Encouragements you send or receive are stored with both people. Emmaus does not send the invitation for you: the link leaves from your own device through your device's share sheet, and anything you typed about the person is kept only so you can see whom you invited and take the invitation back.
1.11 Your calendar — read on your device, never collected. If you turn on calendar features, Emmaus asks iOS for access to your calendar so it can show what is ahead today and remind you before you are due somewhere. This one works differently from everything else in this section, and the difference is the point:
- Your events are read on your device and stay there. Event titles, times, locations and attendees are never sent to our servers, never stored in our database, and never included in anything sent to an AI provider. Reminders are scheduled locally by your phone.
- Emmaus only reads. It never creates, changes, or deletes anything in your calendar — there is no code in the App that writes to your calendar at all.
- About the permission iOS shows you. iOS does not offer a read-only permission request for calendar events: an app that needs to read your events has to ask for full access, and that is the prompt you will see. We ask for it because it is the only one iOS offers, and we use it only to read. The limit is in what Emmaus does, not in what iOS makes us ask for — and we would rather tell you that plainly than word it so it sounds like iOS is holding us to it.
- You can decline, or turn it off later in Settings → Calendar, or revoke it entirely in iOS Settings → Privacy & Security → Calendars. Declining costs you nothing else in the App.
1.12 What we do NOT collect in Version 1.
- We do not collect Apple Health (HealthKit) data, wearable/fitness data, or biometric health data.
- We do not collect your precise location, contacts, photos, or camera content. (If you use Face ID / Touch ID to lock the App, that biometric check is performed by iOS on your device; we never receive your biometric data.)
- We do not use advertising identifiers or App Tracking Transparency tracking.
1.13 Parent consent information. For a person under 13, we initially create a random consent-request record and a short-lived security record used to rate-limit pairing attempts. A parent enters the pairing code and their own email. We then collect the parent's name, relationship to the child, the child's first name, required and optional consent choices, electronic signature, signed-form image, timestamps, and authorization history. Submission through the private emailed link records approval automatically and sends a receipt to the parent. The raw signed form is kept in a private storage area that has no ordinary user access; an authorized owner can open it only through a short-lived signed link. The rate-limit record uses a one-way protected value derived from the network address, not the raw address, and is deleted after 48 hours. We use this information to give direct notice, record permission, secure the process, manage the child account, and document compliance.
2. How We Use Your Information (Purposes)
We use your information only for the following purposes:
- To provide the App's core features — create and secure your account; store and display your journals, prayers, goals, and reflections; generate personalized devotionals, morning briefs, examens, and weekly reviews.
- To power the AI Companion and voice — send your messages and relevant content to our AI providers to generate responses, maintain the Companion's long-term memory so it can walk with you over time, transcribe your speech, and produce spoken replies (see Section 4).
- To personalize your experience — tailor content to what you've shared and what matters to you.
- To manage your subscription — verify entitlement to premium features and support restore-purchases across your devices.
- To keep you safe — operate the App's safety systems, including crisis detection and content moderation, and to review reports you submit (see Section 6).
- To send notifications you've chosen — deliver reminders and briefs you have enabled; you control these and can turn them off at any time.
- To write to you by email — send one welcome guide after onboarding and necessary account or parent-consent messages from hello@getemmaus.app. We do not send marketing newsletters, use tracking pixels, or track opens or clicks. Turning email off in Settings stops ordinary Emmaus email, but it does not stop a legally required parent notice, a parent-requested privacy response, or sign-in/password-reset email.
- To connect you with people you choose — create and accept invitations, keep a connection active, show a walking partner or a discipler the parts of your walk that the connection covers, and carry encouragements between you (see Section 5).
- To maintain, secure, and improve the App — reliability, troubleshooting, fraud and abuse prevention, and product improvement using non-identifying or aggregated information where feasible.
- To comply with law — meet legal obligations and enforce our Terms.
We do not use your information to sell to third parties, to serve you ads, or to track you across other companies' apps or websites.
3. Data Retention
We keep your information for as long as your account is active and as needed to provide the App. Specifically:
- Account and User Content are retained until you delete the specific item, delete your account, or ask us to erase them.
- AI long-term memories persist so the Companion can remember your story, until you edit, archive, delete them, or use "Forget everything," or delete your account.
- Voice audio is processed transiently to generate a transcript and is not retained as a permanent recording after transcription; the resulting transcript is stored as part of your chat content (which you can delete).
- Your contact address and email preference stay with your profile until you change them or delete your account.
- Connections, invitations, and encouragements are kept while they are in use. Ending a connection stops the sharing immediately and marks the connection ended rather than erasing the record of it; an invitation link that is never accepted expires after 30 days. Deleting your account deletes your connections, the invitations you created, and the encouragements you sent and received — which means the person on the other side loses them too.
- Safety event logs contain only the account identifier, conversation identifier, safety category, template version, and time — not a second copy of what the person said. They are automatically deleted after 30 days.
- Parent-consent records: unfinished or denied requests and their signed evidence expire and are deleted after 30 days if no child account claims them. For an approved child account, we keep the parent notice version, consent choices, timestamps, authorization history, and restricted signed-form evidence while the account is active because those records are the authorization for collection. After the parent withdraws or the child account closes, that narrow consent record is kept for no more than 3 years solely to demonstrate authorization, answer a parent request, resolve a dispute, or comply with law, and is then automatically deleted. It is not used to operate a profile, personalize the App, or market to anyone. Parent pairing rate-limit records are deleted after 48 hours. Child account content follows the shorter ordinary deletion rules above and is not kept for this consent-record period.
- Backups: residual copies may persist in encrypted managed backups for up to 7 days after deletion and are then purged in the ordinary course. A backup is used only for disaster recovery, not to restore one deleted account into the live service.
- We may retain limited information longer where required to comply with legal obligations, resolve disputes, or enforce our agreements.
4. AI Processing and Sub-Processors (Important Disclosure)
To provide AI features, we share the content you submit with trusted service providers ("sub-processors") that process it on our behalf and under contract, only to deliver the service to you. We select providers that offer the same or equal protection required by applicable law and by Apple's guidelines.
| Sub-processor | What it does | What is sent to it |
|---|---|---|
| Anthropic (Claude API) | Powers the AI Companion, devotionals, briefs, and reflections | Your chat messages, and relevant profile, memory, prayer, goal, and reflection content needed to generate a response |
| OpenAI | Powers voice text-to-speech and speech-to-text, generates text embeddings used to organize the Companion's memory, and provides safety moderation for Companion input and output | Voice audio you record (for transcription), text to be spoken aloud, text used to create embeddings, and Companion messages checked for safety |
| Supabase | Hosts our database, authentication, storage, and secure server functions | Your account and all User Content, stored on our behalf |
| RevenueCat | Manages your subscription entitlement | An app-user identifier and subscription status received from Apple |
| Resend | Delivers user email (for example, the welcome message) and restricted internal operational alerts | The recipient address and message contents. A report-queue alert contains only random report identifiers, report types, and times — never reported content, user identifiers, or user contact information. Turning email off stops email sent to you; it does not disable internal security notifications. |
| Apple | App distribution, In-App Purchase billing, Sign in with Apple, and privacy-preserving Declared Age Range where available | Payment and purchase data (processed by Apple); your email or private relay if you use Sign in with Apple; a coarse age range and declaration category if you choose to share it |
One more service, and it is not a sub-processor. When a passage is not in our own Scripture library, the App fetches the public-domain World English Bible text from bible-api.com, a free public Bible API — and it does so directly from your device, not through our servers. Because it is your device making that request, we want to be exact about it:
- What is sent: the passage reference only, in the web address — for example,
John 3:16. That is the entire request. - What is not sent: your name, your email, your account identifier, your journals, your prayers, or anything else about you. There is nothing in the request that identifies you to them, and we send them nothing about you separately.
- What they can see anyway: as with any website your phone connects to, your device's IP address reaches them, and they can see which passage was asked for. We have no contract with them and no control over their logs, so we are not going to claim otherwise.
- When it happens: only when you open a passage we could not serve ourselves. Scripture you read from our own library never touches them.
We call this out separately because Section 5 says we share information only as described in this policy, and a request leaving your phone to a company we have not named would make that untrue.
When AI processing occurs. After you affirmatively enable AI, content is sent when you ask the Companion or voice for a response, request a generated devotional or review, or when Emmaus prepares an enabled personalized morning brief as you open the App or through a reminder you chose. Turning AI processing off blocks future provider-backed requests. Scripture reading, prayer lists, journaling, memory verses, and everything you do with a walking partner work without AI.
Your explicit choice. Before Emmaus sends your content to Anthropic or OpenAI, the App names those providers, explains the categories of content that may be sent, and asks you to choose “I agree — enable AI” or “Not now — use without AI.” We store the time and version of an affirmative choice. You may decline and use the non-AI portions of Emmaus, or turn future AI processing off later in Settings → Your data → AI processing permission. Turning it off prevents future provider calls; it does not by itself delete messages or memories already stored in Emmaus, which you may delete through the controls described in Section 8.
No training on your data. We do not permit Anthropic or OpenAI to use your content to train or improve their AI models. Your content is sent only to generate responses for you, under commercial terms that restrict such use.
Provider retention. “Not used for training” and “zero data retention” are different promises. Unless and until our applicable provider account and contract show Zero Data Retention (“ZDR”) in writing, provider abuse-monitoring or service logs may retain API inputs or outputs for a limited period under the provider's business/API terms (commonly up to 30 days), subject to legal and security exceptions. We do not claim that ZDR is active merely because source code or an API key exists. We verify ZDR separately for the exact provider organization, project/workspace, models, and API features in use.
We may engage other sub-processors as the App evolves; if we make a material change to how AI processing works, we will update this policy and, where appropriate, ask for renewed consent.
5. How We Share Information
We share information only as described here:
- With sub-processors who process data on our behalf to run the App, as listed in Section 4.
- For legal reasons, if required by law, subpoena, or valid legal process, or to protect the rights, property, or safety of Emmaus, our users, or the public.
- In a business transfer, such as a merger, acquisition, or sale of assets, in which case we will require the recipient to honor this policy or notify you and provide choices where required.
- With your direction, when you choose to share content out of the App (for example, using your device's native share sheet to send something to a person you choose).
- With a walking partner or a discipler you invited, and only as described in Section 5.1 below.
- With
bible-api.com, when your device asks it for a passage we could not serve from our own library — the passage reference and nothing else, as described in Section 4.
We do not sell your personal information, we do not "share" it for cross-context behavioral advertising, and we do not disclose it to data brokers or ad networks.
5.1 Walking partners and discipleship connections
Emmaus lets you walk with someone. Nothing here happens automatically: a connection exists only when one person sends an invitation and the other person accepts it, and the accept screen states what will be shared, and in which direction, before anyone agrees to it.
There are two kinds of connection:
- Walking partners (peer). Each person can see only the prayer requests the other person explicitly chooses to share, plus their daily rhythms (the habits they keep and whether they checked them off) and current focus (their goals). Prayer requests start private. The connection is otherwise mutual and symmetrical.
- Discipling. The sharing runs one way only. The discipler can see only the prayer requests the disciple chooses to share, plus the disciple's daily rhythms and current focus. The disciple sees nothing of the discipler's walk — not their prayers, not their rhythms, not their focus.
Encouragements go both ways in either kind of connection: a short note either person can send the other, stored for both of them.
What is never shared with a partner or a discipler, in either kind of connection:
- your conversations with the AI Companion and its long-term memories of you;
- your journal and examen entries, and your reflections;
- your memory verses, saved devotionals, weekly reviews, and Future Self vision;
- your contact email address or the address you sign in with.
Either person can end a connection at any time ("Disconnect", on that person's screen in the App). Ending it stops the sharing immediately — what you could see of each other stops being visible — and your own notes and history remain yours. You can invite each other again later.
If someone treats you badly. On that same screen you can block the person, which ends the connection and stops them reaching you again, and report them or a specific note they sent. Reports come to us for review, and we may suspend or terminate accounts over abuse. You can also write to support@getemmaus.app at any time. When you report someone, we receive the note you reported and what you tell us about it, so that we can act on it (Section 1.7).
Aside from this, and aside from anything you deliberately send out of the App yourself, your content stays private to your account.
6. Safety, Moderation, and Crisis Handling
To keep the App safe, we operate automated safety systems, including a crisis-detection tripwire and content moderation that run on messages to and from the AI Companion. If the system detects signals of self-harm, suicide, abuse, child abuse, or danger, the Companion responds with a scripted compassionate message and real crisis resources (for example, the U.S. 988 Suicide & Crisis Lifeline, Crisis Text Line at 741741, the National Domestic Violence Hotline at 1-800-799-7233, the Childhelp National Child Abuse Hotline at 1-800-422-4453, and 911 for emergencies). This deterministic route does not call an AI provider and remains available even if AI processing is turned off or feature limits have been reached. Every AI message includes a "Report a concern" control; reports are retained as immutable evidence for review, and the owner receives a minimal-content operational alert as described in Section 1.7. We keep minimal safety-event records as described in Section 3. The App is not monitored continuously and is not a crisis service — in an emergency, contact 988 or 911 (or your local emergency number).
7. Security
We protect your information with administrative, technical, and physical safeguards appropriate to its sensitivity, including:
- Encryption in transit (HTTPS/TLS) and encryption at rest for stored data;
- Row-Level Security (RLS) in our database, so your records are reachable only by your authenticated account — and, for the narrow set of content a connection covers, by a walking partner or a discipler whose invitation you accepted (Section 5.1). The database itself enforces this, one row at a time, rather than the App deciding what to show;
- Server-side handling of all AI provider keys — the App never calls AI providers directly from your device, and provider API keys are never stored on your device;
- Least-privilege access controls and authentication for our systems.
No method of transmission or storage is 100% secure, and we cannot guarantee absolute security, but we work to protect your information and to promptly address issues we become aware of.
8. Your Choices and Controls
You are in control of your data. From within the App you can:
- Delete your account and all associated personal data — in Settings → Your data → Delete account. This permanently removes your profile, journals, examens, prayer requests, goals, AI memories, reflections, and related data, subject to the retention and backup practices in Section 3. It also ends your connections and removes the invitations you created and the encouragements you sent and received. If you signed in with Apple, you can additionally stop Emmaus from using your Apple ID in iOS Settings → [your name] → Sign-In & Security → Sign in with Apple. Deleting your account does not cancel your Apple subscription — cancel it separately in your Apple Account settings (Settings > [your name] > Subscriptions, or https://apps.apple.com/account/subscriptions).
- Export your user-facing account data — in Settings → Your data → Export my data, download your profile, User Content, AI memories, connection/invitation data visible to your account, current subscription status, and reports you filed. The in-App archive does not contain provider/infrastructure logs, internal security and rate-limit records, aggregate business metrics, or financial records we are required or permitted to keep. You may contact support@getemmaus.app for an applicable legal access request covering personal information outside the in-App archive.
- Turn email off, or change where we write — in Settings → Email you can switch email from Emmaus off entirely, see which address we would use, and give us a different one. Turning it off stops every email we send; sign-in and password-reset emails are separate and only go out when you ask for them.
- Control what a partner or discipler can see — accept a connection only after the accept screen tells you what it shares and in which direction, and end any connection at any time with Disconnect on that person's screen. Ending it stops the sharing immediately.
- Manage the AI's memories — view what the Companion remembers (grouped by category), edit or delete individual memories, archive them, or use "Forget everything" to erase all AI memory. You can also pause memory so the Companion keeps working but stops learning new facts.
- Disable or decline AI features — you can decline AI processing and use the App's non-AI features, and you can turn conversational voice off and type instead.
- Control notifications — enable or disable each type of reminder and set times; nothing is gated on notifications, and you can turn them all off.
- Control the microphone — grant or deny microphone access in iOS Settings; declining does not lock you out, because typed input is always available.
- Control the calendar — turn calendar features off in Settings → Calendar, or revoke access entirely in iOS Settings → Privacy & Security → Calendars. Because your events are only ever read on your device (Section 1.11), turning it off leaves nothing behind on our side to delete.
Depending on where you live, you may have additional rights under laws such as the California Consumer Privacy Act (CCPA/CPRA) or the EU/UK GDPR — including rights to access, correct, delete, and port your data, and to object to or restrict certain processing. Because most of these controls are built directly into the App, you can exercise them yourself at any time; you may also contact us at support@getemmaus.app and we will respond as required by law. We will not discriminate against you for exercising your privacy rights. Where processing is based on your choice to use AI features, you can stop at any time and delete what the App remembers about you in Settings.
9. Children's Privacy
Emmaus may be used by a child under 13 only through its parent-managed process. Before account creation, we ask only for a coarse age range. If the range is under 13, the App creates a random request and displays a pairing code; it does not ask for the child's name, email, journal, prayer, voice, coach message, or other account content. The parent or legal guardian must use the code, receive our direct notice by email, choose each optional feature, choose a parent-controlled account email, and sign the consent form. Submitting the signed form automatically records approval and updates the child's device. The child login must use that approved parent-managed account email; it may be a unique alias if the parent's own address already has an Emmaus account.
The core consent covers account storage and the Bible, prayer, journal, goal, and planning features. AI coaching, AI voice, and walking-partner connections are separate parent choices. Database and server controls enforce those choices even if a screen is bypassed. A parent may use their private management link to request access or correction, withdraw permission, or permanently delete the child account. Withdrawal immediately blocks the account and removes active connections; deletion removes the child sign-in and stored account content, subject to the backup and narrow legal-record practices in Section 3. The child can also delete the account from the blocked-account screen.
Apple's age-range signal helps minimize data, but Emmaus remains responsible for obtaining and honoring consent. A manual age-range fallback is provided when Apple does not share a range or the API is unavailable. If you believe a child bypassed the process or provided information without valid permission, contact support@getemmaus.app and we will investigate and delete it as required. Users 13 through the age of majority should involve a parent or guardian where applicable law requires it.
10. International Users and Data Transfers
Emmaus operates in the United States, and your information is processed and stored in the United States and in the regions used by our sub-processors. If you access the App from outside the United States, you understand that your information will be transferred to and processed in the United States, where data-protection laws may differ from those in your country. Where required, we rely on appropriate safeguards for such transfers.
11. Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes, we will update the "Last updated" date above and, where appropriate, provide notice in the App. If a change materially expands how we use or share your information — including changes to AI processing — we will seek your consent where required. Your continued use of the App after an update takes effect constitutes acceptance of the updated policy.
12. Contact Us
If you have questions, requests, or concerns about this Privacy Policy or your data, contact us at:
Disciple Maker LLC Email: support@getemmaus.app 126 Hammocks Court, Green Acres, Florida 33413