Privacy Policy
This Privacy Policy (the "Policy") explains how Trinity Force Co., Ltd. ("Company," "We," "Us," or "Our") collects, uses, discloses, and protects information in connection with the Easy Bible mobile application (the "Service").
This Policy is effective as of July 30, 2026. If we make material changes, we will notify you by posting the updated Policy in the app and/or by other reasonable means.
01Definitions
- Company / We / Us / Our refers to Trinity Force.
- User / You / Your refers to a natural person who downloads, accesses, or uses the Service.
- Application / Service means the Easy Bible mobile application.
- Personal Data means any information relating to an identified or identifiable individual.
- Sensitive Personal Data / Special Category Data means Personal Data revealing religious or philosophical beliefs, health, or other categories recognized as sensitive under applicable law (see Article 2).
- Service Provider means a third party that processes Personal Data on Our behalf to help Us operate the Service (e.g., cloud hosting, analytics, crash reporting, payment processing, AI response generation).
- Usage Data means data collected automatically through use of the Service (e.g., app events, device identifiers).
- Data Controller (for GDPR purposes) refers to the Company.
- Business / Consumer (for CCPA/CPRA purposes) have the meanings given in the California Consumer Privacy Act, as amended.
- Apple refers to Apple Inc. Google refers to Google LLC.
02Information We Collect
We collect only the minimum information necessary to operate the Service.
| Category | Data Collected | When | Retention |
|---|---|---|---|
| Account (Sign-in) | Name, e-mail address, via Apple or Google Sign-In. Not collected for anonymous/guest use. | Sign-up / Sign-in | Until account deletion or consent withdrawal |
| User Content | Text or voice content you write or record in the app. This may reveal religious beliefs and can qualify as Sensitive Personal Data (CCPA) / Special Category Data (GDPR). | When you use the content feature | Until you delete it or delete your account |
| Purchases | Subscription and purchase history (via RevenueCat) | Subscription / purchase | Legally required periods (see Article 3); otherwise until account deletion |
| Device & Usage Data | Device identifier, anonymous app-usage events (via PostHog); GeoIP is disabled and no personal profile is built | Automatic, while using the app | 12 months from last use, or account deletion, whichever is earlier |
| Crash Data | Anonymous crash logs, no personal identifiers (via Sentry) | Automatic, on error | 12 months from collection |
We do not collect precise location, phone number, physical address, or payment card numbers. We do not use performance/tracing telemetry beyond crash reporting.
Sensitive Personal Data. Because User Content may reveal religious beliefs, We obtain a separate, specific consent (distinct from our general Terms/Policy consent) before processing it. You may decline this separate consent; if you do, the content feature will not be available to you, since storing that content without consent is not offered as an alternative.
Voice Input. If you use voice input, your device's operating system (iOS/Android) may send the audio to Apple's or Google's servers to convert it to text. That audio does not pass through Our servers, and the applicable platform's privacy policy governs that processing.
AI Processing. User Content you submit is sent through OpenRouter to the Google Gemini API to generate a response. Under standard (paid) API terms, this content is not used to train Google's models. It may be retained for a limited period by OpenRouter and/or Google for abuse prevention, safety review, and legal compliance, in accordance with their own policies, which may change from time to time.
03How We Use Your Information
- Account management: identity verification, fraud prevention, handling inquiries and complaints.
- Core service delivery: generating AI responses to User Content, managing subscriptions and payments.
- Service stability: diagnosing crashes, and analyzing anonymous usage trends to improve the Service.
We currently do not use any advertising SDK and do not engage in interest-based / online behavioral advertising. If this changes, We will update this Policy in advance.
04How We Share Your Information
We do not sell Personal Data. We share Personal Data only with the Service Providers below, strictly to operate the Service, and, where required, with public authorities to comply with law.
| Service Provider | Purpose | Data Shared | Privacy Policy |
|---|---|---|---|
| Apple Inc. / Google LLC | Sign-in authentication | Name, e-mail | apple.com/legal/privacy / policies.google.com/privacy |
| OpenRouter, Inc. / Google (Gemini API) | AI response generation | User Content | openrouter.ai/privacy / policies.google.com/privacy |
| Supabase, Inc. | Database hosting and backup | Account data, User Content | supabase.com/privacy |
| Sentry (Functional Software, Inc.) | Crash diagnostics | Anonymous crash logs | sentry.io/legal/privacy |
| PostHog, Inc. | Anonymous usage analytics | App events, device identifier | posthog.com/privacy |
| RevenueCat, Inc. | Subscription management | Purchase history, device identifier | revenuecat.com/privacy |
We may also disclose Personal Data where necessary to comply with legal process, respond to lawful requests from public authorities, protect Our rights or the rights of others, or in connection with a merger, acquisition, or sale of assets.
05International Transfer of Data
The Service is operated from the Republic of Korea. Most of Our Service Providers listed in Article 4 are based in the United States, so your Personal Data will generally be transferred to and processed in the United States. By using the Service, You consent to this transfer, which may involve data protection standards that differ from those in your home country. You may withdraw this consent, but doing so will prevent you from using features that depend on these providers (sign-in, AI responses, subscription management).
06Data Security
We apply administrative, technical, and physical safeguards appropriate to the sensitivity of the data, including: a designated privacy officer; access controls limiting who can view Personal Data; encryption of data in transit (e.g., HTTPS); anonymization of crash and analytics data; and periodic internal review of these measures. No method of transmission or storage is 100% secure, and We cannot guarantee absolute security.
▶ Personal Information Protection Officer
Name: Jinwoo Hong
E-mail: [email protected]
07Your Rights Under the GDPR (EU / UK / Switzerland Residents)
We do not currently direct-market the Service to the EU, UK, or Switzerland and have not appointed an EU/UK representative under Art. 27 GDPR / UK GDPR. This section is provided for completeness and readiness; if the Service begins actively targeting EU/UK/Swiss users, this section and Our operational setup (including an EU representative) will need to be revisited.
If European data protection law (GDPR, UK GDPR, or the Swiss FADP) applies to you, you have the right to:
- Access the Personal Data We hold about you and receive a copy of it.
- Rectify inaccurate or incomplete Personal Data.
- Erase your Personal Data, where there is no overriding reason for Us to continue processing it.
- Restrict or object to Our processing of your Personal Data, including for direct marketing.
- Receive your Personal Data in a portable, machine-readable format, where technically feasible.
- Withdraw consent at any time, without affecting the lawfulness of processing before withdrawal.
- Lodge a complaint with your local data protection authority.
Our legal bases for processing include: your consent (including explicit consent for Special Category Data), performance of a contract with you, compliance with legal obligations, and Our legitimate interests in operating and improving the Service.
To exercise these rights, contact Us at [email protected]. We may ask you to verify your identity before responding.
08Your Rights Under the CCPA/CPRA (California Residents)
If you are a California resident, you have the right to:
- Know what Personal Data We collect, use, and disclose, and the categories of sources and recipients.
- Request deletion of Personal Data We have collected from you, subject to certain legal exceptions.
- Correct inaccurate Personal Data We hold about you.
- Limit the use of Sensitive Personal Information. The only Sensitive Personal Information We collect is User Content that may reveal religious belief. We use it solely to provide the feature you requested (generating an AI response) — a use that CCPA/CPRA permits without an opt-out, because it is reasonably necessary to provide the service you asked for.
- Not be discriminated against for exercising any of these rights.
We do not sell or share (as defined by the CCPA/CPRA) Personal Data, and We do not use any advertising SDK, so there is currently no "Do Not Sell or Share My Personal Information" mechanism to operate — there is nothing being sold or shared. If this changes, We will add the required opt-out mechanism and update this Policy first.
To exercise your CCPA/CPRA rights, contact Us at [email protected]. We will respond within 45 days of a verifiable request, extendable once by another 45 days with notice to you.
Our Service does not respond to browser Do Not Track (DNT) signals at this time.
09Singapore Users (PDPA)
If you access the Service from Singapore, the Singapore Personal Data Protection Act 2012 ("PDPA") may apply. Consistent with the PDPA, We collect Personal Data only with notification of purpose and, where required, your consent; We use it only for the purposes disclosed in this Policy; and you may withdraw consent, access, or request correction of your Personal Data by contacting Us at [email protected]. In the event of a data breach that is likely to result in significant harm, We will notify the Personal Data Protection Commission (PDPC) and affected individuals as required by law.
10Children's Privacy
The Service is not directed to children under the age of 14 (or the minimum age required by your local law), and We do not knowingly collect Personal Data from children under that age. If We learn that We have collected Personal Data from a child without appropriate consent, We will delete it. Parents or guardians who believe We may have collected such information should contact Us at [email protected].
11Links to Other Websites
The Service may contain links to third-party websites or services not operated by Us. We are not responsible for the privacy practices of those third parties, and We encourage you to review their privacy policies.
12Changes to This Policy
We may update this Policy from time to time. Material changes will be notified through an in-app notice or other reasonable means prior to becoming effective. The "Effective Date" above reflects the latest revision.
13Contact Us
If you have questions about this Policy or wish to exercise any of the rights described above, please contact Us:
E-mail: [email protected]