Privacy Policy

Effective Date: May 21, 2026 Last Updated: May 21, 2026

Welcome to Rock — a Bible and devotional app named after Psalm 18:2 ("The LORD is my rock, and my fortress, and my deliverer"). This Privacy Policy explains what information we collect, how we use it, who we share it with, and the rights you have over your data.

We wrote this in plain language because we believe transparency is part of treating people well. If anything here is unclear, email us at felipe2521.gv@gmail.com and we will explain.


1. Who We Are

Rock (the "App", "we", "us", or "our") is operated by Felipe Gonzalez Varona, an individual developer doing business as "Rock App." Felipe Gonzalez Varona is the person responsible for Rock and is the data controller for the personal information described in this policy. You can reach the operator directly at felipe2521.gv@gmail.com.

If the operating party changes as the project grows, we will update this policy and the "Last Updated" date above.


2. Scope

This Privacy Policy applies to:

Rock is currently offered on the App Store in the United States. It does not apply to third-party services we link to or interact with, which have their own privacy policies. We name those third parties in Section 6 so you know exactly who is involved, and we describe the protection they are required to provide.


3. Information We Collect

We try to collect as little information as possible. Here is everything we collect, why we collect it, and where it goes.

3.1 Anonymous Device Identifier

The first time you launch Rock, the App generates a random anonymous identifier and stores it securely in the iOS Keychain on your device. This identifier lets us link your subscription and saved content to your device without knowing who you are. It is not your Apple ID, your phone number, your email, your advertising identifier (IDFA), or any other persistent identifier assigned by Apple. We do not use the IDFA, and we do not track you across other apps or websites.

3.2 Sign in with Apple (Optional)

If you choose to sign in, we use Sign in with Apple. Apple sends us:

You can use Rock without signing in. Signing in lets you sync content across devices and restore your subscription on a new device.

3.3 Content You Create — and the Guidance Feature

Rock's guidance feature is optional. When you choose to use it, you describe a struggle in your own words. Before that text leaves your device, the App tells you that the guidance feature sends what you write to our AI provider; choosing to submit it is how you consent to that processing. If you do not want your words sent off the device, simply do not use the guidance feature — the rest of the App (the offline Bible, reading plans, the journal) works without it.

When you submit a struggle, that text is:

  1. Sent to Anthropic's Claude API so the model can generate a scripture recommendation and brief reflection, and
  2. Used by our backend to keep a short, rolling record of your recent interactions (see Section 3.4).

Prayer-journal entries, bookmarks, highlights, and verses you save to memorize are created and stored on your device and sync through your own private iCloud (see Section 3.6). They are not sent to our backend.

You decide what to type. We recommend not including information you would not want stored — for example, the full names of other people, government identifiers, or financial details.

3.4 Recent Interactions (Backend)

So that your daily verse and upcoming reminders can adapt to what you have recently shared, our backend keeps a rolling record of your most recent interactions — up to your last 20. Each record contains a short excerpt of the struggle you described (truncated to roughly 500 characters), the date, and a few themes the AI identified. This is stored in our backend database (see Section 6.4) and is associated with your anonymous identifier or your account.

3.5 Subscription Status

If you subscribe to Rock Plus, Apple provides our backend with the information needed to confirm you have an active subscription — the product purchased, the renewal status, and Apple's transaction identifiers. We do not receive your payment card information. All payments are handled by Apple.

3.6 Content Synced Through Your Private iCloud

Your prayer journal, bookmarks, highlights, memorized verses, and struggle history are stored on your device using Apple's SwiftData framework and sync through your own private iCloud account (Apple CloudKit). This data lives in your personal iCloud private database. We cannot read it — the developer has no access to your private CloudKit data. It is governed by Apple's iCloud terms and privacy policy, encrypted in transit and at rest by Apple, and tied to your Apple ID. If iCloud is unavailable or you are not signed into iCloud, this content stays local to your device only.

3.7 Crash Logs

If Rock crashes, Apple may collect a crash log and share it with us through Apple's standard developer tools (Xcode Organizer / App Store Connect) only if you have enabled "Share With App Developers" in iOS Settings. We do not embed any third-party crash SDK. We use crash logs solely to fix bugs.

3.8 What We Do Not Collect

We want to be just as clear about what we do not touch:


4. How We Use Your Information

We use the information described above only for the following purposes:

  1. To personalize scripture recommendations. When you describe what you are going through, we send that text to Anthropic's Claude API, which returns suggested KJV scripture passages and brief commentary tailored to your situation.
  2. To process AI requests. Claude needs your text to generate a response. We send only what is needed for the request.
  3. To adapt your daily verse and reminders. Your rolling recent-interactions record helps the App choose a daily verse and upcoming reminders that reflect your current season.
  4. To manage your subscription. We verify your subscription with Apple to confirm Rock Plus is active.
  5. To keep the Service running and secure. Our backend keeps short-lived server logs and rate-limit counters to operate the Service, prevent abuse, and fix problems.
  6. To respond to you. If you email us, we use your message and email address to reply.
  7. To comply with law. We may use or disclose information if required by valid legal process or to protect rights and safety.

We do not use your information for advertising. We do not build advertising profiles. We do not sell your information. We do not perform automated decision-making that produces legal or similarly significant effects on you.


5. Legal Bases for Processing (GDPR)

If you are in the European Economic Area, the United Kingdom, or Switzerland, the legal bases we rely on are:

You can withdraw consent at any time by stopping use of the guidance feature and, if you wish, requesting deletion of your data (Section 12).


6. Who We Share Information With

We share information only with the service providers listed below, and only to the extent needed to operate Rock. Each of these providers is bound by contract and by its own published terms to provide the same or an equivalent level of protection for your data as described in this policy. We do not sell personal information. We do not share personal information for cross-context behavioral advertising.

6.1 Anthropic, PBC

Anthropic operates the Claude API, which generates the scripture recommendations at the heart of Rock. When you use the guidance feature, the text you type is transmitted to Anthropic for processing.

Under Anthropic's Commercial Terms, Anthropic does not use API inputs or outputs to train its models. Anthropic retains data only as described in its standard retention policy, which you can review here: https://www.anthropic.com/legal/commercial-terms

6.2 Apple Inc.

Apple operates the App Store, Sign in with Apple, In-App Purchase, and the iCloud/CloudKit service that syncs your saved content. Apple's privacy practices are governed by Apple's privacy policy.

6.3 Vercel Inc.

Vercel hosts our backend API. Your requests pass through Vercel's infrastructure in transit. Vercel maintains standard server logs (IP addresses, request timestamps) for short periods for security and reliability.

6.4 Upstash, Inc.

Upstash provides the Redis database our backend uses to store minimal user records: your anonymous identifier or account record, your subscription status, your rolling recent-interactions record (Section 3.4), short-lived caches of your daily and upcoming verses, and rate-limit counters.

6.5 Legal and Safety

We may disclose information if we believe in good faith that doing so is required by law, necessary to enforce our Terms, or necessary to protect the rights, property, or safety of users or the public.

6.6 Business Transfers

If Rock is ever acquired, merged, or otherwise transferred, personal information may be transferred as part of that transaction. We will notify you and honor the commitments in this policy.


7. International Data Transfers

Rock's backend runs on infrastructure that may be located in the United States and other countries. If you use Rock from outside the United States, your information will be transferred to and processed in countries that may have different data protection laws than your home country. Where required, we rely on appropriate safeguards (such as Standard Contractual Clauses) for international transfers.


8. How Long We Keep Information

When data is no longer needed, we delete or de-identify it.


9. Security

We protect your information with reasonable safeguards:

No system is perfectly secure. If we learn of a breach that affects your personal information, we will notify you and any required authorities as the law requires.


10. Children's Privacy

Rock is not directed to children under 13 (United States) or under 16 (European Economic Area). We do not knowingly collect personal information from children below these ages. If you believe a child has provided us with information, please email felipe2521.gv@gmail.com and we will delete it.

Parents and guardians: if your child is old enough to use Rock, we encourage you to use it together. Scripture is a family conversation.


11. Your Rights

Depending on where you live, you have some or all of the following rights:

To exercise any right, email felipe2521.gv@gmail.com. We may need to verify your identity (for example, by confirming control of the account email) before acting on your request. We will respond within the timeframes required by applicable law (generally 30–45 days).


12. Deleting Your Data

You can delete your data in the following ways:

  1. Content on your device and in iCloud: Delete a journal entry, bookmark, highlight, or memorized verse inside the App to remove it. Deleting the Rock app from your device removes the locally stored content; to also remove the copy synced to your private iCloud, use iOS Settings → your name → iCloud → Manage Account Storage, or delete the App's iCloud data there.
  2. Your backend records: Email felipe2521.gv@gmail.com from your account email (or with your request details) and we will delete your backend records — your user record, subscription record, and recent-interactions history. If you signed in with Apple, we will also revoke the Sign in with Apple connection.

We are adding an in-app "Delete My Data" control so this can be done directly from Settings; until then, the email request above is the way to have your backend records deleted, and we will honor it promptly.

After deletion, residual copies may remain in encrypted backups for a short period before being overwritten on the normal backup rotation schedule.


13. Do Not Track

Some browsers send a "Do Not Track" signal. There is no consensus standard for how apps and websites should respond. Rock does not perform behavioral tracking, so this is not relevant to how we operate, but we want to mention it for transparency.


14. California Notice (CCPA / CPRA)

If you are a California resident, you have specific rights under the California Consumer Privacy Act and the California Privacy Rights Act. The information you can access is described in Section 3. The purposes for which we use it are described in Section 4. The categories of recipients are described in Section 6.

We have not sold or shared personal information in the preceding 12 months as those terms are defined under California law.

To exercise your California rights, email felipe2521.gv@gmail.com with "California Privacy Request" in the subject line.


15. Changes to This Policy

We may update this Privacy Policy from time to time. When we make material changes, we will update the "Last Updated" date at the top and, where appropriate, notify you in the App or by email. Continued use of Rock after changes take effect means you accept the updated policy.


16. Contact Us

For any privacy question, request, or concern, please email:

Felipe Gonzalez Varona — felipe2521.gv@gmail.com

We read every message and we try to respond quickly. Thank you for trusting Rock with your story.