Privacy Policy
How BibleBridge handles data for site owners and their visitors.
BibleBridge is designed to be privacy-friendly by default. We collect the minimum data necessary to operate the service and do not track, profile, or sell user information.
1. What We Collect from Site Owners
When you install BibleBridge or create an account, we may collect:
- Domain name: to provision and identify your API key
- Site name: displayed in your reader header and account dashboard
- Email address: only if you create an account or claim a provisioned key (optional for free tier)
- IP address: for rate limiting and abuse prevention during provisioning
- Platform and version info: sent during auto-provisioning to help diagnose compatibility issues; not shared with third parties
- Post and page content: if you enable Auto-Tagging, the text of a post or page is sent to our API to detect Scripture references; results are cached for 7 days so the same content isn't sent again
BibleBridge installations may automatically provision a free API key by sending your site URL and site name to the BibleBridge API. No manual registration is required.
2. What We Collect from Visitors
Ordinary Bible chapter reading (KJV and BSB) is served entirely from files bundled in your WordPress installation and never reaches BibleBridge's servers - we have no visibility into what visitors read.
When visitors use features that connect to BibleBridge's API (search, cross-references, reading plans, Scripture Atlas, and similar), their browser's request is relayed through your WordPress installation, not sent directly by the visitor's browser. For these requests, we process:
- IP address: used for rate limiting on relayed requests
- Requested content: which searches, topics, or other API-backed content is accessed
- Independent verification ping: separately, the visitor's browser also sends a small signed confirmation directly to BibleBridge on page load, bypassing your WordPress installation. This includes the visitor's IP address and browser user-agent, logged to verify that automated-traffic detection is working correctly. It is not linked to any personal information and is not used to track or profile individual visitors.
We do not collect visitor names, email addresses, or any personal information. We do not use cookies, tracking pixels, or analytics on visitor requests.
3. Local Storage on Visitor Devices
The BibleBridge reader uses the visitor's browser local storage for features like bookmarks, highlights, notes, reading progress, theme preference, and sync codes. This data is stored entirely on the visitor's device and is not transmitted to BibleBridge servers unless the visitor explicitly uses the cloud sync feature.
4. Cloud Sync
Visitors may optionally sync their reading data across devices using a self-generated sync code. No email or account is required. Sync data (highlights, notes, progress) is stored on BibleBridge servers and associated only with the sync code, not with any personally identifiable information.
5. Payment Information
Payments are processed by Stripe. BibleBridge does not store credit card numbers or payment credentials. Stripe's privacy policy governs the handling of payment data.
6. Data Sharing
We do not sell, rent, or share personal data with third parties. Data may be disclosed only if required by law or to protect the security of the Service.
7. Data Retention
API usage counts are stored for the current day only and reset at midnight UTC. Account information is retained as long as your account is active. You may request deletion of your account and associated data by contacting [email protected].
8. Static Assets and Data Requests
The BibleBridge reader's CSS, JavaScript, fonts, images, and both included Bible translations (KJV and BSB) are bundled with the plugin and served directly from your own WordPress installation. No separate BibleBridge-hosted CDN is used to deliver these files, and ordinary chapter reading never leaves your server. Search results, cross-reference data, and other API-backed features are requested server-to-server from BibleBridge's API by your WordPress installation itself, not directly by your visitors' browsers. The one exception is the independent verification ping described in Section 2, which is sent directly from the visitor's browser.
9. Security
All communication between the reader and BibleBridge servers uses HTTPS encryption. API keys are transmitted via secure query parameters. Account sessions use secure, HTTP-only cookies.
10. holybible.dev Standalone Reader (This Site Only)
The standalone Bible reader at holybible.dev/bible/read uses Cloudflare Turnstile to distinguish real visitors from automated traffic before serving scripture content. This applies to holybible.dev's own site only. It is not part of the BibleBridge plugin distributed to other installations, and does not affect visitors on other sites running BibleBridge. Turnstile sets a short-lived verification cookie and may process limited technical signals (such as browser and device characteristics) as described in Cloudflare's Turnstile Privacy Addendum.
11. Changes to This Policy
This policy may be updated from time to time. Continued use of the Service after changes take effect constitutes acceptance of the updated policy.
12. Contact
Privacy questions may be directed to [email protected].