Privacy Policy

Last updated 3 September 2026

Your sermon notes are yours. SermonNotes stores them so they reach your other devices and survive a lost phone, and shows them to other people only when you choose to share them. There is no advertising in this app, no analytics or tracking of any kind, and your notes are never sold, rented, or used to train anybody's AI.

This policy explains what SermonNotes collects, why it needs it, who else can see it, and how to get rid of it. It covers the SermonNotes iPhone and iPad app and the website at sermonnotes.uk.

Who is responsible for your data

SermonNotes is run by Peter Smith, based in the United Kingdom. For the purposes of the UK GDPR and the Data Protection Act 2018, that is the data controller for the information described here — meaning the person who decides what is collected and why, and the person you can hold to this policy.

Contact for anything in this document, including any request to see or delete your data: hello@sermonnotes.uk.

What SermonNotes collects

Only what the app actually needs to work. There is no hidden collection and no third-party analytics or advertising software in the app at all.

WhatWhyWhere it is kept
Your account — name, email address, and a display handle you choose. Optionally the name of your church. To sign you in, to keep your notes attached to you rather than to one phone, and so friends can find you by your handle. Firebase Authentication and Firestore.
Your notes and studies — titles, dates, speaker and series names, the text you write, the Bible passages you attach, and any images you add. To store them, to sync them between your devices, and to restore them if you lose or replace your phone. On your device, and in Firestore under your account.
Things you share — notes you mark as shared, devotion posts, comments, and Amens. To show them to the friends you have chosen to share with. Firestore. Visible to your friends — see below.
Your friends list — who you are connected to, pending friend requests, and anyone you have blocked. To run the friends feed and to keep blocked people out of it. Firestore.
A record of notes you delete — the note's internal identifier and when you deleted it. Not its title or anything you wrote. So your other devices know the note was deleted on purpose, rather than uploading it again because they have not seen it. Firestore, under your account, readable only by you.
Reports you make — the content reported, who posted it, and who reported it. So that abusive or offensive content can be reviewed and removed. Required of every app with a public feed. Firestore, readable only by us.
App usage that stays on your phone — your reading streak, your service schedule, reminder times, and your appearance and reading settings. To run the streak, the countdown to your next service, and your reminders. Reminders are scheduled by iOS on your device. Mostly on your device; the streak also syncs to your account.

What SermonNotes does not collect

Who else can see your notes

Notes are private by default. A note is visible to nobody but you unless you deliberately mark it as shared.

When you do share a note, it becomes visible to the people you have accepted as friends inside the app — nobody else. It is not public, it is not indexed by search engines, and there is no way for a stranger to browse it. Friends can leave a comment or an Amen on a shared note, and can ask to take a copy; a copy is only made if you agree to it. You can stop sharing a note at any time, which removes it from your friends' feeds.

Devotion posts work the same way: they go to your friends and no further.

Companies that process data on our behalf

SermonNotes is a small app and does not run its own servers. These are the other organisations involved:

Google (Firebase)

Firebase Authentication holds your sign-in details, and Cloud Firestore holds your account, notes, and anything you have shared. Google acts as a data processor — it stores and transmits this data on our instructions and does not use it for its own purposes. Firebase App Check is also used to verify that requests come from the real SermonNotes app rather than from something pretending to be it; it uses Apple's own device attestation and identifies the app, not you.

Data is stored in Google Cloud's europe-west2 (London) region, in the United Kingdom. It is not transferred outside the UK for storage.

YouVersion (Bible text)

Bible passages come from the YouVersion Platform API. When the app fetches a passage it sends the reference and the translation you asked for — for example "John 3:16" in whichever translation you have chosen — together with the app's own API key. It does not send your name, your email, your account, or anything you have written.

Crossway (the English Standard Version)

The ESV is the one translation that does not come from YouVersion — Crossway licence it themselves, and their API is the only route to it. It works the same way: asking for a passage sends the reference and the app's own API key, and nothing else. If you never choose the ESV, the app never contacts Crossway at all.

Both Bible services are based in the United States, so a request for a passage leaves the UK — but all that travels is a reference like "John 3:16". As with any request to any website, their servers can see the internet (IP) address it came from. Neither is sent an account, a name, or an identifier for you, so neither can tell one SermonNotes reader from another or build a picture of what any one person reads.

Apple and Google sign-in

If you sign in with Apple or with Google, that company confirms to us who you are and supplies your name and email address. Sign in with Apple lets you hide your real email address behind a private relay address; if you do that, the relay address is all we ever see, and it works exactly as well. Your password is never seen by SermonNotes on any of these routes.

Why we are allowed to hold it — the legal bases

How long it is kept

Your notes and account are kept until you delete them. Deleting an individual note removes it from your account and from any friend's feed it appeared in.

Deleting your account deletes everything. Settings → Account → Delete Account removes your profile, every note and study, your posts, comments, and Amens, your friendships and friend requests, and your Firebase sign-in record. Your handle is released for someone else to use. This is immediate and it cannot be undone — take an export first if you want to keep anything. Deleted data may persist in Google's routine backups for a short period before being overwritten.

When you delete a note, we keep a record that you deleted it. That record holds the note's internal identifier and the date and time — not its title, its text, or anything you wrote. It exists so that your other devices can tell the difference between a note you deleted and one they simply have not received yet; without it, a phone that was switched off when you deleted something would helpfully upload it again. The record is removed when you delete your account.

Reports of abusive content are kept after the reported content is removed, because a record of what was dealt with is the only way to deal with a repeat offender.

Your rights

Under UK data protection law you have the right to:

Write to hello@sermonnotes.uk for any of these. We will answer within one month. There is no charge.

If you think your data has been mishandled, you can complain to the UK Information Commissioner's Office at ico.org.uk, or on 0303 123 1113. We would rather you told us first so we can put it right.

Security

Everything travels over an encrypted connection, and Firestore security rules enforce — on the server, not just in the app — that you can only read your own notes and those a friend has actually shared with you. Firebase App Check rejects requests that do not come from a genuine copy of the app.

No system is perfect, and we would rather say so than pretend otherwise. If something goes wrong that puts your data at risk, we will tell you and the ICO as the law requires.

Children

SermonNotes is not aimed at young children and you should be 13 or over to create an account. If you are under 16, please ask a parent or guardian before signing up. If you believe a child has created an account, write to us and we will remove it.

Changes to this policy

If this policy changes in a way that matters, the date at the top will change and the app will tell you about it rather than quietly swapping the page. Continuing to use SermonNotes after a change means you accept it.

Contact

Peter Smith
hello@sermonnotes.uk
United Kingdom