BibleDiary 隱私權政策
更新日期:2026 年 9 月 15 日
BibleDiary 是一款心情日記 App,搭配聖經經文陪伴。這份政策說明我們如何處理你的資料。開發者:王俊智(Jun Zhi Wang),聯絡信箱 junzhi1117@gmail.com。
日記內容儲存在你的裝置上
你寫下的日記、心情、書籤與讀經計畫紀錄會加密儲存在裝置本機(AES-256-GCM),加密金鑰保存在 iOS Keychain 或 Android Keystore,不會離開裝置,也不會上傳到我們的伺服器,除非你另外啟用下方的「跨裝置同步」。
你也可以另外開啟「日記鎖」,用生物辨識或裝置密碼保護日記畫面;這是選用功能,與資料加密分開運作。
帳號與登入
BibleDiary 使用 Firebase Authentication 提供 Google 或 Apple 登入。登入後我們會取得你的帳號識別碼(User ID),以及 Google/Apple 依你的選擇提供的電子郵件地址,用來識別你的帳號、管理訂閱權益與同步設定。我們不會取得你的密碼。
AI 經文推薦
當你在某一篇日記按下「請 AI 推薦經文」並明確同意後,App 才會把那一篇日記的文字與你選填的心情傳送到我們自架的後端服務(Cloud Run),再轉交 Google Gemini 產生建議。這個傳送只在你每次主動同意時發生,不會自動或在背景進行。我們的伺服器不會儲存日記內容或 AI 回覆;伺服器只保留一筆用量紀錄(帳號識別碼與請求次數/時間),用來限制每日請求數以避免濫用。
跨裝置同步(選用,預設關閉)
你可以選擇開啟跨裝置同步,將日記、書籤、讀經計畫與完成紀錄備份到雲端,以便在其他裝置繼續使用。這項功能採用端對端加密:資料會先在你的裝置上用只有你持有的「復原金鑰」加密,才上傳到 Google Cloud(Firestore,資料儲存於台灣 asia-east1)。我們的伺服器只會看到加密後的內容、帳號識別碼、請求時間與資料筆數等中繼資訊,看不到日記的實際文字。復原金鑰不會被上傳,若遺失金鑰,雲端中已加密的資料將無法復原。單純登入不會自動開啟同步,需要你另外明確啟用。
匯出備份
你可以在 App 內把日記、書籤與讀經計畫匯出成 JSON 備份檔,檔案會以你自訂的密碼加密後才寫入裝置。備份檔只存在你的裝置與你自行分享的位置,我們不會收到這份檔案。
訂閱與購買
BibleDiary 的付費功能由 Apple App Store 或 Google Play 完成付款,並由 RevenueCat 協助驗證與同步訂閱權益。BibleDiary 與 RevenueCat 會處理你的帳號識別碼、購買的商品、平台、訂閱狀態與到期時間,藉此確認你的訂閱權益;我們不會收到或保存完整的信用卡號。購買前,系統商店會顯示實際價格與自動續訂條款。
我們不會做的事
- 不會在背景讀取或掃描你的日記內容。
- 不會在未經你同意的情況下,把日記文字傳給任何第三方。
- 不會出售你的個人資料。
- 目前沒有在 App 中嵌入廣告或第三方追蹤/分析工具。
刪除帳號與資料
你可以在 App 內「帳號」設定中永久刪除帳號,這會移除我們伺服器上與你帳號相關的雲端同步資料、登入紀錄與用量紀錄。裝置本機的日記資料可透過解除安裝 App 或在裝置設定中清除。已透過 App Store/Google Play 訂閱的項目,仍須另外在商店中取消,刪除帳號不會自動取消商店訂閱。
兒童隱私
BibleDiary 不是針對兒童設計的 App,我們不會刻意收集兒童的個人資料。
政策更新
若本政策有重大變更,我們會更新本頁的「更新日期」,並視情況在 App 內另行通知。
聯絡方式
如對隱私權、資料存取或刪除有任何問題,請寄信至 junzhi1117@gmail.com。
BibleDiary Privacy Policy
Last updated: September 15, 2026
BibleDiary is a mood journal app paired with Bible scripture companionship. This policy explains how we handle your data. Developer: Jun Zhi Wang, contact junzhi1117@gmail.com.
Your journal stays on your device
Your journal entries, moods, bookmarks and reading-plan records are encrypted and stored locally on your device (AES-256-GCM); the encryption key is kept in iOS Keychain or Android Keystore, never leaves your device, and is never uploaded to our servers unless you turn on cross-device sync below.
You can also optionally enable a Journal Lock, protected by biometrics or your device passcode. This is a separate, opt-in feature.
Account and sign-in
BibleDiary uses Firebase Authentication for Google or Apple sign-in. After you sign in, we receive your account identifier (User ID) and the email address Google/Apple chooses to share, used to identify your account and manage subscription entitlements and sync settings. We never receive your password.
AI scripture recommendation
Only when you tap "Get AI scripture recommendation" on a specific entry and explicitly consent does the app send that entry's text and your optional mood to our own backend service (Cloud Run), which forwards it to Google Gemini to generate a suggestion. This only happens when you actively consent each time; it never runs automatically or in the background. Our server does not store journal text or the AI reply; it keeps only a usage record (account ID and request count/time) to enforce daily rate limits and prevent abuse.
Cross-device sync (optional, off by default)
You may choose to enable cross-device sync to back up entries, bookmarks, reading plans and completion records to the cloud so you can continue on another device. This feature is end-to-end encrypted: data is encrypted on your device with a recovery key that only you hold, before being uploaded to Google Cloud (Firestore, stored in Taiwan, asia-east1). Our servers only see the encrypted content plus metadata such as account ID, request time and record counts — never the plaintext of your journal. The recovery key itself is never uploaded; if you lose it, encrypted cloud data cannot be recovered. Signing in alone never turns sync on; you must enable it explicitly.
Exported backups
You can export your entries, bookmarks and reading plans as a JSON backup file inside the app; the file is encrypted with a password you choose before it is written to your device. Backup files stay on your device and wherever you choose to share them; we never receive a copy.
Subscriptions and purchases
Paid features in BibleDiary are billed through the Apple App Store or Google Play, and RevenueCat helps verify and sync your subscription entitlements. BibleDiary and RevenueCat process your account identifier, purchased product, platform, subscription status and expiration date to confirm your entitlement; we never receive or store your full card number. The store shows the actual price and auto-renewal terms before purchase.
What we don't do
- We do not read or scan your journal content in the background.
- We do not send your journal text to any third party without your consent.
- We do not sell your personal data.
- The app currently has no advertising or third-party analytics/tracking SDKs embedded.
Deleting your account and data
You can permanently delete your account in the app's Account settings, which removes your cloud sync data, sign-in records and usage records from our servers. Local journal data can be removed by uninstalling the app or clearing app data on your device. Store subscriptions must be cancelled separately in the App Store or Google Play; deleting your account does not automatically cancel a store subscription.
Children's privacy
BibleDiary is not directed at children, and we do not knowingly collect personal data from children.
Changes to this policy
If we make material changes to this policy, we will update the date above and, where appropriate, notify you in the app.
Contact
For any privacy, access or deletion questions, contact junzhi1117@gmail.com.