Privacy Policy

Last updated: August 12, 2026

1. Overview

This Privacy Policy explains what information Feason LLC (“Feason,” “we,” “us”), a California limited liability company, collects, how we use it, and the choices you have. It applies to your use of feason.com, our mobile applications, Chrome extension, and related features (the “Service”). By using the Service, you acknowledge the practices described here. Where applicable law requires consent, we ask for it separately. This policy should be read together with our Terms of Service.

Privacy at a glance:

  • We do not sell personal information or use cross-site behavioral advertising.
  • Feason is built around faith and scripture study, so information you choose to provide may reveal religious or philosophical beliefs. We treat that information as sensitive and use it only to provide, personalize, secure, and support the Service.
  • AI, voice, video, church-search, sign-in, email, hosting, and notification features use the service providers named below. Use those features only with information you are comfortable sending to the identified provider.
  • You can access, export, correct, and delete your account data.

The Service is available in supported locations and is not offered to, or directed at, persons in the European Economic Area, the United Kingdom, or France and French territories. We operate the Service from the United States and process information under applicable U.S. law and, where applicable, the privacy laws of the countries and regions where we do offer the Service.

2. Information We Collect

Information you provide to us:

  • Account information: name, email, password hash (for email sign-in), profile details (display name, username, bio, profile photo), sign-in provider identifiers and tokens, and your date of birth, which we use to enforce age requirements for certain features (such as direct messaging). Apple refresh tokens are encrypted before storage.
  • Content you post: gleams, articles, replies, comments, journal entries, acts of faith, scripture notes and tags, fellowship comments on verses, memorization cards, saved study plans, and curated images. Journal entries are encrypted in your browser with a key derived from your passphrase before they reach our servers — we store only the ciphertext and cannot read them (see Section 8).
  • Chrome extension sharing data: when you explicitly open or invoke the Feason Chrome extension, it can read the current page title and URL so you can choose to attach that page to a gleam. It reads selected text only when you choose the Feason action from Chrome’s context menu. Feason receives the source and text only when you choose to post them. The extension does not monitor or collect your browsing history in the background.
  • Photos you submit to Behold: if you use the Behold feature, the photo you upload is sent to our AI provider (Anthropic) to be described, and is then stored with the description, mood, themes, and scripture anchor generated from it. Please do not upload photos of other people without their agreement, or images containing sensitive information. You can delete a capture, and its stored image, at any time.
  • Reading groups: if you create or join a group, we store your membership and role, the reflections and replies you contribute to group sessions, your reactions to other members' reflections, and — if you host — the session details and meeting notes you record. This content is visible to the other members of that group.
  • AI conversation data: the messages you send to the Feasy, Feasy Evolved, and Lexicon chat features, and the responses generated for you, along with the thread they belong to. For Feasy Evolved answers we additionally store the scripture passages and cross-references used as the basis of the answer, plus the verifier's per-claim verdict, so we can re-render those when you revisit the conversation without re-running the model.
  • Voice recordings and transcripts: when you choose voice input for Feasy or scripture memorization, the recording is transmitted to OpenAI for transcription. Feason does not intentionally save the raw recording after that request completes. The returned transcript may be stored if you send it as a chat message or save the related memorization activity.
  • Church searches: the city, postal code, address, or other location you type into church search, together with any denomination filter. We send the location query to Google Maps to geocode it and return nearby results. We do not request your device's precise GPS location for this feature.
  • Calendar data: events you create in Feason, including their title, time, location, and notes. If you separately connect Google Calendar, we request read-only event access and display matching Google events in Feason. We store the OAuth access and refresh tokens needed to maintain that connection in encrypted form. We do not copy connected Google events into our database or use calendar contents for feed personalization, advertising, or AI training.
  • Direct messages: the private one-to-one messages you send to and receive from other members, and the conversation they belong to. Unlike your encrypted journal, direct messages are not end-to-end encrypted: they are encrypted in transit and at rest, but our systems and authorized staff can access their contents when necessary to respond to abuse reports, enforce our Terms, keep members safe, or comply with the law.
  • Communications: anything you send us through the contact form, DMCA notices, or support requests.
  • Reports: if you flag another user's content, we record the post you reported, the reason you provided (if any), the time of the report, and your account id. Reports are used for moderation and abuse prevention.

Information we collect automatically:

  • Usage data: reading progress, streaks, interactions with writings, memorization review history, quiz attempts, the searches you run in the app, and scripture engagement tied to your account.
  • Feed interaction signals: which posts you view, save, hide, or engage with in the feed. We use these signals to build a private interest profile that personalizes your feed (see Section 3). Your encrypted journal is excluded from this profile by construction — the server cannot read it.
  • Push notification data: if you enable notifications, we store the device token Apple assigns to the mobile app or the endpoint and encryption keys supplied by your browser's push service. Notification providers receive the notification content needed for delivery. You can disable notifications in your device or browser settings.
  • Technical data: IP address, browser type, device type, and timestamps, used for abuse prevention, rate limiting, and security logging.
  • Security event records: for security-relevant activity such as authentication attempts, rate-limit denials, scheduled-job access, user reports, and moderator actions, we store the event category, time, outcome, route, limited context, and keyed pseudonymous fingerprints derived from relevant account, email, IP, or resource identifiers. The ledger does not store raw passwords, authentication tokens, cookies, request bodies, or reported content.
  • Link-preview fetches: when you post content that contains a URL, our server fetches publicly available metadata from that URL once (title, description, and the domain it resolves to) and stores a short cached summary with your post. The outbound fetch security record contains pseudonymous account and IP fingerprints, the target host, and a timestamp for abuse prevention. We do not re-host or proxy images from the destination site.
  • Consented acquisition analytics: if you accept analytics, we store a random first-party session identifier, the Feason page where the visit began, the referring site’s hostname, campaign tags in the URL, and whether that visit led to signup, onboarding, or a saved study action. The analytics record does not store the referring page’s full URL, advertising identifiers, or a raw IP address.
  • Cookies and browser storage: a session cookie to keep you signed in and a small number of first-party values to remember preferences and consent. We do not use advertising or cross-site tracking cookies.

Lecture notes. Where these live depends on whether you are signed in, and the difference matters. Signed in: the notes you take in the Lecture feature, the video they were taken against, and its title are stored on our servers so they reach every device you use and survive a cleared cache. They are readable by us in the same way a gleam or a writing is — unlike your journal, they are not encrypted in your browser. Signed out: notes stay in that browser’s local storage, are never sent to us, and are erased permanently if you clear site data. Notes written while signed out are not uploaded when you later sign in unless you choose to import them; we ask first rather than moving them for you. Either way, Lecture notes are not used to personalize your feed, and we do not use their contents to train models.

Information from third parties: if you sign in with Google or Apple, we receive an account identifier and the profile information that provider makes available with your permission, which may include your name, email, or profile picture. Apple may provide a private relay email address instead of your personal email.

3. How We Use Your Information

We use your information to:

  • Provide, maintain, secure, and improve the Service;
  • Understand which search and campaign visits lead people to useful study actions;
  • Create and authenticate your account;
  • Display your profile, activity, and public content to other users;
  • Personalize your feed: we rank content using signals from your activity on the Service (your public posts, saves, and feed interactions — never your encrypted journal). Personalization affects only the order and selection of content shown to you; it has no legal or similarly significant effect on you;
  • Deliver notifications about interactions with your content or streaks, by email and (if you enable them) push notification. You can manage email notifications in your email preferences and unsubscribe at any time;
  • Generate AI responses in the Feasy, Feasy Evolved, and Lexicon chats;
  • Transcribe voice input and generate optional spoken output;
  • Return church-search results for a location you enter;
  • Combine events you create in Feason with events from a calendar you connect;
  • Detect, investigate, and prevent abuse, fraud, and security incidents;
  • Respond to support, privacy, moderation, and copyright requests;
  • Comply with legal obligations and enforce our Terms.

We do not sell your personal information, and we do not use your content to train third-party AI models.

4. International Users & Legal Bases

The Service is not offered to, or directed at, persons in the European Economic Area, the United Kingdom, or France and French territories, and we do not market it in those locations.

Where the data-protection law of a location in which we do offer the Service requires a legal basis for processing, we rely as appropriate on: (a) performance of a contract, to provide the Service you request; (b) our legitimate interests in securing, maintaining, and improving the Service and preventing abuse, balanced against your rights; (c) your consent, for processing that requires it, which you may withdraw at any time; and (d) compliance with legal obligations.

5. AI Features & Sub-Processors

Our Feasy and Feasy Evolved chats send your prompts, conversation history, and limited contextual information (such as which in-app page you are viewing) to OpenAI's API for inference. Lexicon sends the same kinds of chat data to Anthropic's API. Under these providers' commercial API terms, inputs and outputs are not used to train their models by default and may be retained for a limited period for trust-and-safety purposes, unless longer retention is required by law.

Feasy Evolved additionally sends each question to Voyage AI for embedding (a numerical representation used to find related scripture passages in our database). Voyage receives the question text only; it does not receive your account identifier. Voyage's standard terms apply.

Voice transcription. When you use voice input in Feasy or scripture memorization, the audio recording is sent to OpenAI's audio transcription API. OpenAI receives the recording but not your Feason account identifier. OpenAI states that API audio-transcription inputs are not used for model training and are not retained as abuse-monitoring logs or application state under its default endpoint controls.

If you use voice mode, the generated reply text is sent to ElevenLabs to create spoken audio. ElevenLabs does not receive your account identifier.

Behold photos. When you submit a photo to Behold, the image itself is sent to Anthropic's API so the model can describe what it shows and suggest a scripture anchor. Anthropic receives the image and does not receive your account identifier. The same commercial terms described above apply: images sent through the API are not used to train Anthropic's models and are retained only for a limited period (up to 30 days) for trust-and-safety purposes. We store the resulting description and the image itself in our own storage until you delete the capture.

We store the resulting conversation transcripts in our database so you can revisit and manage them. For Feasy Evolved we additionally store the scripture passages and cross-references used to ground each answer and the verifier's per-claim verdict. You can rename and delete any AI conversation from the chats list, and you can export or delete your account data from your profile settings; deletion removes it from our database.

Feasy Evolved answers are AI-generated. The verifier is a separate model that checks each theological claim against the scripture passages used; it reduces but does not eliminate the possibility of error. Feasy Evolved is a study tool, not a substitute for pastoral guidance, theological education, or the teaching authority of your church.

Please do not send sensitive personal information, confessions, medical or legal details, passwords, or payment data through the AI Features. If your question to Feasy Evolved indicates a possible personal crisis (suicidal ideation, abuse, self-harm), the Feasy Evolved interface will surface crisis-line resources alongside any answer. These detections are non-blocking and best-effort; please reach out to a trusted person or one of the listed resources directly.

Other sub-processors we rely on:

  • Supabase — database and file storage.
  • Vercel — application hosting.
  • Google — optional authentication, read-only Calendar connection, church geocoding and place search, and user-requested embedded YouTube video. Different Google services receive the information described in this Policy only when you use the corresponding feature.
  • Apple — optional authentication and push notification delivery in our mobile app. Apple receives authentication requests, or your device token and notification content, as applicable.
  • Anthropic — AI model inference for Lexicon, content tagging for the feed, and image description for Behold photos.
  • Voyage AI — query embeddings used by Feasy Evolved to retrieve related scripture passages.
  • OpenAI — AI model inference for Feasy and Feasy Evolved, plus audio transcription for voice input and scripture recitation.
  • ElevenLabs — text-to-speech generation when you use Feasy voice mode.
  • Resend — transactional email delivery (welcome emails, notification emails, streak reminders, and the daily digest). Resend receives your email address and the content of the email being sent.
  • Browser push services — notification delivery if you enable web push. The service selected by your browser receives the subscription endpoint and encrypted notification payload needed for delivery.
  • Upstash — Redis-backed rate limiting, used when configured to enforce abuse thresholds across multiple server instances. Stores counter values under keyed pseudonymous fingerprints derived from rate-limit buckets; raw account, email, and IP identifiers and user content are not sent in those keys.
  • Slack — operational notifications. Signup notices contain the sign-in method but not your name or email; security digests contain aggregate event counts and categories, not event fingerprints or user content.
  • bolls.life and dictionaryapi.dev — Scripture text and word definitions. These are accessed for content and do not receive your account identifiers.

Embedded video (Lecture). When you open a video in the Lecture feature, your browser contacts YouTube and Google directly to load the player and stream the video. That connection is between you and Google, not routed through us: Google receives your IP address, device and browser information, and the video you requested, and may set cookies or other storage in your browser under the Google Privacy Policy. We embed through YouTube’s privacy-enhanced domain (youtube-nocookie.com), which reduces but does not eliminate that storage. We do not send Google your name, email, or Feason account identifier, and we do not receive your YouTube account, viewing history, or watch behavior in return. No video loads until you paste a link and open it.

Reference data attribution. Feasy Evolved's scripture corpus is the World English Bible (public domain). Cross-references are sourced from openbible.info under the Creative Commons Attribution 4.0 License.

The Greek New Testament is the SBL Greek New Testament (CC BY 4.0). Word-by-word tagging, grammar and glosses are adapted from STEP Bible (Tyndale House, Cambridge), available at github.com/STEPBible under the Creative Commons Attribution 4.0 License. Strong's numbering is public domain. Sense breakdowns shown alongside a word are Feason's own, counted from that tagging.

6. Sharing of Information

We share information only as needed to run the Service:

  • With the sub-processors listed above, under contractual confidentiality;
  • With other users, for your public profile and the content you choose to post publicly (gleams, threads, replies, fellowship comments, and public profile fields);
  • With the other members of a reading group you join, for your membership and the reflections, replies, reactions, and meeting notes you contribute to that group;
  • With authorities or other parties if required by law, to enforce our Terms, or to protect the rights, property, or safety of Feason, our users, or the public;
  • In connection with a merger, acquisition, financing, or sale of assets, subject to standard confidentiality protections.
  • At your direction or with your consent.

Journal entries, scripture notes, saved lexicon words, and private AI conversations are visible only to you — unless you use an explicit sharing feature (for example, publishing a Feasy exchange as a public gleam), in which case the content you chose to share becomes public like any other post. Direct messages are visible to you and the member you exchange them with; because they are not end-to-end encrypted, authorized staff may review reported or flagged messages for safety, moderation, and legal compliance.

7. Data Retention

We retain your information for as long as your account is active, and for a limited period afterwards as needed to comply with legal obligations, resolve disputes, and enforce our agreements. When you delete content, we remove it from the active Service promptly; residual copies may remain in encrypted backups for up to 30 days before being purged on a rolling basis.

Content removed by our moderators for violating our community guidelines is hidden from the Service rather than immediately destroyed: we retain it for a limited period so we can review appeals, identify repeat abuse, and comply with legal obligations. Such content is permanently deleted when your account is deleted.

Pseudonymous security event records are generally retained for about 90 days so we can detect abuse patterns, investigate incidents, and verify security controls, then removed by a daily rolling cleanup. Temporary operational delays, an active security investigation, or legal obligations may require limited records to be kept longer. These records may remain after account deletion for that limited period where needed for security and abuse prevention; they are not used for feed personalization or advertising.

When you delete your account, we delete your personal data within 30 days, except for the limited information we are required or permitted by law to keep. Lecture notes saved to your account are deleted with it. Lecture notes taken while signed out were never sent to us and so cannot be deleted by us — they stay in the browser that wrote them until you clear that browser’s site data or clear them in the feature.

Raw voice recordings are passed through to OpenAI for transcription and are not intentionally stored in Feason's database or file storage. Returned transcripts follow the retention period of the chat or memorization record in which you use them. When you delete an Apple-linked account, we attempt to revoke the stored Apple refresh token as part of account deletion.

Connected Google Calendar events are fetched when you view the calendar and are not retained as event copies by Feason. Disconnecting attempts to revoke the Google grant and permanently removes Feason's encrypted token copy. Feason-created events and any remaining calendar connection are deleted with your account.

8. Security

We use reasonable technical and organizational measures to protect your information, including encryption in transit (TLS), scoped database access, rate limiting on abuse-prone endpoints, and audit logging. No system is perfectly secure; if we become aware of a data breach that materially affects you, we will notify you as required by applicable law.

Journal entries are end-to-end encrypted. Discernment journal entries are encrypted in your browser using AES-256 with a key derived from your passphrase before they are sent to us. We store only ciphertext and never receive your passphrase or key, so we cannot read, recover, or disclose your journal contents — to anyone, including in response to legal process. This also means that if you lose your passphrase, your journal entries cannot be recovered by us.

9. International Transfers

The Service is operated from the United States. Our sub-processors may process your data in the United States and in other countries. Where required by applicable law, we use recognized transfer mechanisms, such as adequacy decisions or contractual safeguards, to protect your information when it is transferred outside your home jurisdiction.

10. Your Rights & Choices

We offer the following controls to all users, whether or not a particular state privacy law applies to Feason:

  • Access a copy of the personal data we hold about you;
  • Correct inaccurate personal data;
  • Delete your personal data (through your profile, or by contacting us);
  • Export your content in a portable format — “Export your data” in your profile settings produces a machine-readable JSON file covering your account and profile, everything you have posted or written, your study and memorization records, your group contributions, your AI conversations, the direct messages you sent, your feed-personalization signals, and the reports you filed. Journal entries are included in encrypted form only, because we cannot decrypt them;
  • Withdraw consent where processing is based on consent.

California notice at collection. During the preceding 12 months, we have collected the following categories of personal information described by California law: identifiers and account records; internet or other electronic-network activity; user-provided or IP-derived location information; audio, visual, and other electronic content; inferences used for feed personalization; and sensitive personal information, including account credentials, message contents, and information that may reveal religious or philosophical beliefs. We collect these categories directly from you, automatically from your browser or device, from Google or Apple when you choose their sign-in services, from other users who interact with you, and from public pages involved in link previews. We use them for the purposes in Section 3, disclose them for business purposes to the provider categories in Sections 5 and 6, and retain them as described in Section 7. We have not sold or shared these categories for cross-context behavioral advertising.

California residents (CCPA / CPRA). You have the right to know, delete, correct, and limit the use and disclosure of sensitive personal information, and to opt out of any sale or sharing of personal information. We do not sell or share personal information as those terms are defined under the CCPA/CPRA. The Service collects information that may reveal religious or philosophical beliefs (including any tradition or denomination you choose to provide and the content you post), which is treated as “sensitive personal information” under the CPRA. We use this information solely to provide the Service you requested and do not use or disclose it for any purpose that would require an additional opt-out under §7027 of the CPRA regulations.

Other U.S. state privacy laws. Residents of states with comparable privacy laws (including Virginia, Colorado, Connecticut, Utah, Texas, and similar jurisdictions) may have analogous rights to access, correct, delete, and obtain a copy of their data, opt out of covered sale, targeted advertising, or profiling, and appeal a denial of a request. Feason does not sell personal information or use it for cross-context behavioral advertising, and its feed ranking does not make legal or similarly significant decisions about you.

European Economic Area and United Kingdom. We do not offer or direct the Service to persons in these locations, so we do not process personal information on the basis that the EU GDPR or UK GDPR applies to us. If you believe you hold rights under one of those laws, contact us and we will respond to your request.

You can exercise most rights directly in your profile. For other requests, contact us through the Contact page, email info@feason.com with the subject “Privacy Request,” or write to the mailing address in Section 15. We may need to verify your identity before acting. An authorized agent may submit a request for you; we may ask for proof of signed permission and may verify your identity directly. If we deny a request, you may appeal by replying to the decision or submitting a new message marked “Privacy Appeal.” We will not discriminate against you for exercising your rights.

11. Children's Privacy

The Service is not intended for children under 13, and we do not knowingly collect personal information from them. If we learn that we have collected information from a child under 13, we will suspend the account, stop using the information, and delete it unless law permits or requires a limited retention. Parents and guardians who believe their child has provided us with information should contact us.

12. Cookies & Similar Technologies

We use a small number of first-party cookies and browser-storage values to sign you in, remember your preferences, and protect against abuse. If you select “Accept” in the cookie notice, we also create a random identifier in your current browser tab to measure whether a visit leads to signup and a useful study action. Selecting “Decline” prevents that analytics record. We do not use advertising cookies, cross-site trackers, or session-replay tools. You can clear cookies and site data in your browser at any time; clearing authentication cookies will sign you out.

Two kinds of browser storage are worth naming separately. Lecture notes taken while signed out are held in local storage on your device and are never transmitted to us — clearing site data deletes them for good, while notes on your account are unaffected by clearing site data (see Section 2). And opening a video in Lecture loads YouTube’s player, which may set its own cookies or storage under Google’s policy rather than ours (see Section 5).

Chrome extension storage. The Feason Chrome extension stores an authentication token and short-lived composer state in Chrome’s local extension storage so you can remain signed in and finish an action you started. That storage is scoped to the extension and can be removed by signing out, clearing the extension data, or uninstalling the extension.

Feason’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Do Not Track and Global Privacy Control. Because we do not sell or share personal information for cross-context behavioral advertising and do not permit third-party advertising trackers, browser Do Not Track and Global Privacy Control signals do not change our current practices. Your cookie-notice choice still controls our optional first-party acquisition analytics. If our practices change in a way that makes a legally recognized opt-out signal applicable, we will honor that signal as required by law and update this Policy.

13. Affiliate Links

Feason participates in the Amazon Services LLC Associates Program. When you click affiliate links and make a purchase, Amazon may collect information under its own privacy policy. We receive aggregate commission reports only; we do not receive personal details about your purchases.

14. Changes to This Policy

We may update this Policy from time to time. We will post the updated version and, if changes are material, notify you within the Service before they take effect. Where required, we will ask for renewed consent before applying a new practice to your information. The “Last updated” date identifies the current version.

15. Contact

For privacy questions or to exercise your rights, reach us via the Contact page and mark your message “Privacy Request,” email info@feason.com, or write to us at: Feason LLC, 2108 N St # 16806, Sacramento, CA 95816, USA.