Privacy
Biblion is a Bible reader, not a business built on knowing who you are. It includes no third-party scripts, sends no email, and gives your data to nobody — with the single exception of the company whose server it runs on, named below, which stores it and does nothing else with it. The only advertising it carries is an occasional sponsored line in search results and, rarely, a clearly marked sponsored article — both written or reviewed by hand and served from this same server: no ad network, no tracking, and nothing recorded about who saw them. A sponsored line carries two plain totals, times shown and times followed; a sponsored article has only the same anonymous readership totals every article has. That is the whole of the measurement. This page sets out exactly what is stored, why, for how long, and what you can do about it — in plain terms first, and then in the specific terms the GDPR asks for.
Operator
Operated by Mint Labs, s. r. o., Ostravska 1014/8, 040 11 Kosice, Slovakia. Questions about anything here go through the contact form. The terms of use cover the service itself — this page covers your data, and is the one to believe where the two seem to differ. Last updated August 17, 2026.
Which Biblion this is about
Biblion is five things: this website, an app for iPhone, an app for Android, an app for Mac, and an app for Windows. Everything after this section describes the website, because the website is the only one of the five that holds anything about you at all.
The iPhone app has no account. It is bought once and opens; there is no registration, no sign in, and nothing to sign in to. Your notes and your starred verses are made and kept on the phone, in the app’s own storage, and no copy of them reaches this server — so nothing you write there can be handed over, lost here, or asked for back. The app sends exactly one thing, described under If you only read below: the counting report, which is a bare total for the day with no account, no name and no identifier of any kind attached, together with the app’s own version number. It carries no advertising and no third-party code.
The Android app has no account either, and sends nothing at all — not the counting report, not anything else. It is bought once and opens; there is no registration and nothing to sign in to. Your notes and your starred verses are made and kept on the phone, in the app’s own storage, and no copy of them reaches this server. Every request it makes is a request for something — the text of a translation, a narration, a map, the commentary, the Hebrew and Greek dictionary — and every one of them is a plain fetch carrying no body: there is nothing in it about you, because the app holds nothing about you to put there. It carries no advertising, no analytics and no third-party code. If you write your notes out to a file, the file is made on the phone and handed to Android’s own share menu, where you choose where it goes; it does not come here.
The Mac app has no account either, and cannot reach the network at all. It ships without the permission macOS requires before a program may open a connection, so nothing it does can be sent anywhere — not to us, not to anyone. It does not even send the counting report.
The Windows app has no account either, and sends nothing at all — not the counting report, not anything else. Its whole library sits on your own disk and it has no need of a network. The reason is worth stating exactly rather than borrowing the Mac’s: macOS lets an app ship without the permission a program needs before it may open a connection, and Windows has no equivalent switch for a desktop application. So this is a fact about what the program contains rather than a limit the system imposes on it — there is nothing in it that opens a connection.
So the sections below about registering, recovery codes, closing an account, and a reading position that follows you between devices are about the website alone. They stay exactly as they were, because the website’s accounts are unchanged — and the website can be read in full without one.
The camera in the iPhone and Android apps
The app can read a page of a printed Bible through the camera and work out which chapter is open. All of that happens on the phone: the picture is examined as it arrives and let go, and the words it saw are matched against a list of chapters that ships inside the app itself. No photograph is taken, nothing is written to the phone’s storage, and nothing about the page is sent here. That is a limit built into how the feature works rather than a promise about how we behave — the recognition has no server to ask, so there is nothing for it to send.
On the iPhone two counters move, both of them described in the next section and neither of them about you: the scan raises the tally of reading as its own kind, and opening the chapter it finds raises that tally exactly as opening any chapter does. On Android not even that happens, because that app sends no counting report of any kind. On both, what the page said, which chapter was found, and whether the answer was right are recorded nowhere.
What is stored
If you only read
You can read the whole Bible, search it, follow cross-references and look up Hebrew and Greek without an account and without telling us anything. Nothing you read is recorded against you. No profile is built, and there is nothing to build one from.
Four things are noted even so. The first is a daily visit count: once per day your network address is combined with that date and a secret value held on the server, and the result is passed through a one-way hash. Only that hash is stored — your address itself never is. Because the date is part of what is hashed, the same visitor produces a different value tomorrow, so the count cannot follow anyone from one day to the next. It exists to answer “how many people used the site today” and can answer nothing else. Alongside it sits a small report your browser sends once per page, and it is the thing that separates a reader from a machine. It says three things and no more: that a browser opened the page rather than an automated program fetching it; which site you followed a link from, if any, described below; and which part of this site the page belongs to — the reader, the commentary, the maps, a book introduction, or which of the four devotionals. Never which chapter, and never which day’s reading: the part of the site, and nothing narrower, so the report cannot say what you read. Where a visit began is counted once for the visit rather than once for every page, and like the tally it is kept as a plain number for the day with no column for who arrived. It carries no account, no name and no identifier of any sort. Most of what asks this site for pages is not a person, and without that report there is no way to count the ones who are.
The second is a tally of reading: when a chapter, a commentary, a devotional, a map or a narration is opened — or a printed page is scanned with the app’s camera — a counter for that day goes up by one. A counter holds the date, the kind of thing opened, whether it was opened on the website or in the iPhone app, and the number. There is no column for who did the opening, so the tally cannot say — a signed-in reader raises the same counters as anyone else, and no record connects the two. The app sends its counts in the same shape, as bare totals with no account, name or device identifier attached; the one other thing it reports is its own version number, kept so that outdated versions can be retired without cutting anyone off unawares.
The third is the search log: the words typed into the search box, with the translation and scope searched, how many verses were found, and the time. It carries no account, no session, no network address, not even a scrambled one — so a search cannot be traced to a person, and two searches cannot even be grouped as having come from the same one. That is a deliberate limit built into the table rather than a promise about how we behave, and it exists so that the search can be made better at finding things.
The fourth is the referring site: when you arrive by following a link, your browser tells this site which site the link was on, and the bare name of that site — example.com, never the page, never anything after it — is added to a count for the day. Arriving with no referring site at all, as you do by typing the address or opening a bookmark, is counted in the same way as its own entry. The web address your browser offers can carry more than that name, and the rest is discarded as it arrives rather than stored and trimmed later: what was on the page you came from, and anything that page had put into its own address, is never written down here. Like the tally of reading, the count holds no column for who arrived, so it can say that eleven visits came from somewhere yesterday and can never say that you were one of them. Links you follow inside this site are not counted at all. It exists to answer whether anyone is finding the site, and where from.
There are also allowances. Searching the whole Bible is the most expensive thing this site does, so each connection is allowed 200 searches an hour — far more than reading requires, and enough to stop a script pulling the text a query at a time. Counting them keeps no address: as with the visit count above, your address is combined with the current hour and the server’s secret value and passed through a one-way hash, and only that hash and a number are stored. Because the hour is inside the hash, the same connection is a different value next hour, and the rows are deleted as soon as their hour has passed. It holds no queries and never learns what you searched for. Two more allowances work the same way — one for the small report an article page sends about time spent reading (120 reports an hour), one for the counting reports the app sends (120 an hour) — each with the same one-way hash and the same sweep. They exist so a script cannot inflate the numbers, and like the first they can be connected to nobody. A signed-in request made to this site’s programming interface has an allowance of its own, counted against the sign-in rather than the address so that a shared network is never slowed by one busy connection; it is stored in the same one-way form, holds only a count, and is swept with the hour like the rest.
If you keep things without an account
Notes, starred verses and bookmarked articles can be made without signing in. They are kept in your session — the store on the server that the biblion_sid cookie below points at — and the session is tied to your browser, not to you: no name, no address, nothing that could identify you. The cookie does not outlive your browser, so when the visit ends the session is beyond anyone’s reach, and the server sweeps it away for good within thirty days. No copy exists anywhere else. If you register or sign in before then, they move into the account and become account data, under everything the next section says; if you do not, they simply expire.
If you have an account
An account holds what you give it and what you make with it:
- Registration: a username and a password (stored only as a hash, never as text), a first name so the site can greet you, a last name, and an email address. The email address exists so that you can sign in with it instead of your username, and it is used to send exactly one thing, once, and only if you ask: if you lose both your password and your recovery code, an administrator can issue a new code and mail it to you, and that is the only way back into an account at that point. Nothing else is ever sent to it — no confirmation, no newsletter, no notification — and the site itself still sends no mail of any kind: that one message is written by a person, by hand, and can go only to the address stored on the account, never to an address given in the request. Accounts registered before 2 August 2026 were asked only for a first name, and are not required to supply the other two.
- A recovery code, shown to you once and stored only as a hash, so a forgotten password can be reset without email.
- What you write: your notes and your favorite verses.
- Where you are: your last reading position, so it follows you between devices.
- What you have read and studied: which chapters, and which Strong's and cross-reference pages — kept so the badges can be earned and so the community numbers described below have something true to count.
- What the dove holds: the verses and daily readings you have marked Inspired — a yes with no text attached. Others only ever see it folded into a count of at least five.
- Invitation links you make: the code, when it was made, how long it lasts, whether it was used, and the private note you filed it under — a name only you see. No address is stored: an invitation is a link you carry yourself, because this site sends nothing.
- Reading circles: which circles you sit in. A circle's members — up to twelve people who each joined through the same link, past a page saying exactly this — see your username and your progress in that circle's plan. That is all joining shares, and leaving ends it.
- How you like it: your translation, the layers you keep on, the look of the page, the verse-selection colour, the reading size, your time zone, and your chosen devotional.
- Sign-in records: the time and network address of your most recent successful sign-in, and a log of refused sign-ins — the name typed, the address it came from and when — which is what stops someone guessing passwords. Passwords themselves are never written to that log, right or wrong.
- If an administrator has blocked your account: that it is blocked, when, and the reason given — which is shown to you, in full, the next time you try to sign in.
Three of those feed the community numbers — the most-read chapters on the front page, the popular-verse marks in the study view, and the Inspired counts. Each is a sum across accounts, and no sum is ever shown until at least five readers stand behind it, so a number can never point at a person; below the floor, nothing appears at all. The sums are recomputed from the same account data described above — nothing extra is collected to make them — and what your account contributes to them disappears when the account does.
If you write to us
Because this site sends no email, the contact form is the only way to reach a person here. What you send through it is stored so that it can be read and, where we have promised to, answered: your message, what you said it was about, the name and email address you chose to give, your network address, and the time. If you were signed in, the message is linked to your account.
The name and the address are optional, except for the two kinds of message that carry a promise of an answer — a problem with your account, and anything about your privacy or your data — where an address is needed because there would otherwise be nowhere for the answer to go. The site does not send that answer. It has no means to send anything at all: your address is shown to the administrator who reads the message, and if they write back they do it from their own email account, as one person writing to another. Your address is used for that and nothing else.
You do not need an account to write, and that is deliberate — someone who cannot sign in, or who has already closed their account, still needs a way to ask us something. Messages you sent while signed in are deleted along with everything else when you close your account. Messages sent without an account are not linked to one, so we have no way to find them for you; if you want one removed, write in and say when you sent it.
Cookies and local storage
Every cookie below is set by this site alone, and no other party sets a cookie here.
| Name | What it holds | Who gets it | How long |
|---|---|---|---|
__Host-biblion_csrf |
A random value that means nothing by itself. Every form the site shows you carries the same value, and a form is only acted on when the two agree — which is what stops another site submitting one in your name. It identifies nothing, describes nothing, and is never written down anywhere. | Everyone | Until the browser closes |
biblion_sid |
An identifier for your session — what keeps you signed in and, while you are signed out, the key to any notes, starred verses and bookmarks you keep for the visit. | Readers who sign in, and readers who keep something for the visit. A visit that only reads is never given one. | Signed out, until the browser closes. Signed in, thirty days from your last visit, renewing itself each day you return. |
bib_pop |
Whether the popular-verse marks are shown in the study view — a single on or off. | Only if you use that switch while signed out; signed in, the choice lives on your account instead | One year |
bib_tz |
The name of your time zone, such as Europe/Budapest. It is how the site knows which day it is where you are, so the devotional and the dates are yours rather than the server's. It is a place name, not an identifier. |
Everyone | One year |
bib_bg |
The background mood you picked from the menu — dawn, day, dusk or night. | Only if you pick one while signed out | One year |
lastpos |
The book, chapter and verse you last read, so the site can offer to resume. Signed in, this is kept on your account instead. | Readers without an account | One year |
A little is also kept in your browser's own storage rather than in a cookie. It is never sent to the server: biblion.devReminder remembers that you have already seen today's devotional reminder, so it is shown once and not again; and a handful of values — the verse you have selected, your last search, and which section of a page you had open — live only until the tab is closed.
None of this is used to advertise to you, to profile you, or to follow you to any other site.
Why each thing is stored
Everything above is stored for one of three reasons, and nothing is stored for a reason not on this list:
- Because the site cannot work otherwise. The session cookie signs you in; your account holds the things you asked it to hold; your time zone decides which day's reading you are shown.
- Because you chose it. Your preferences, your mood, your reading place, your devotional.
- Because the site has to be able to defend and count itself. Refused sign-ins are recorded so passwords cannot be guessed at leisure; visits are counted and reading is tallied, in the forms described above, so we know whether anyone is reading and which parts are used.
Who else sees it
Nothing is sold, rented, traded or handed to anyone. There are no advertisers, no analytics companies, no social widgets and no tracking scripts — the fonts, the icons and the code are all served from this site itself, so reading a chapter sends your browser nowhere else.
The server is rented from Amazon Web Services EMEA SARL, which necessarily stores the data in order to hold it, and does so as our processor — under contract, on our instructions, and with no right to use it for anything of its own. The machine is in its eu-central-1 (Frankfurt) region, in Germany. Nobody at that company has any reason to look at your notes, and nothing about this arrangement lets them make use of them.
Listening is the one part of reading that reaches a different address. The recordings are far too large to serve from the site itself, so they come from a delivery network run by the same host, at cdn.biblionapp.com. When you press play, your browser asks it for an audio file, and that request carries what any web request carries, your network address included. It carries no cookie, because that is a different host from this one, and it carries no account and nothing you have written. A chapter you only read makes no such request at all.
There is no payment company in the picture at all. The site takes no money from you, has nothing to sell you, and holds no card details, because none are ever entered here.
The last exception is the possibility that a court or the law compels disclosure. If that ever happened we would tell you, unless telling you were itself forbidden.
How long it is kept
- Your account and everything on it: until you close it. Closing it deletes the account and every note, favorite, preference, reading position, record of reading and study, badge, sign-in record, dove mark, invitation link and circle seat with it — immediately, in one operation, with nothing kept back; your contribution to the community numbers goes when the sums are next remade, and a circle left empty by your going folds entirely. One thing outlives that moment, briefly: the server keeps rolling backup copies of its database, so that a disk failure cannot take everyone’s notes with it, and a closed account remains inside those until they expire — every copy is deleted within 14 days of being made. The backups exist to restore the whole service after a failure and for nothing else: they are never opened to look at anyone’s data, and never used to bring a closed account back.
- What you keep without an account: until the session ends, and no longer — unless you register or sign in first, in which case it moves into the account and the rule above applies instead.
- Refused sign-ins: 90 days, then deleted automatically.
- Messages you send us: until they have been read and dealt with, then deleted. There is no automatic expiry, because a message is not a log entry — some are worth keeping and acting on months later. Anything you sent while signed in goes when you close your account.
- The search log: 90 days, then deleted automatically. It cannot be connected to you at any point in that time.
- The search and reading-time allowances: one hour. Each row is deleted as soon as its hour has passed, and holds only a one-way hash and a count.
- The daily visit count: kept as a running record. It consists only of a one-way hash and a date, and is not connected to a person even on the day it is made.
- The tally of reading: kept as a running record, like the visit count. Each row is a date, a kind and a number; there was never a person in it to remove. The list of app versions is kept the same way — a version number and the day it last reported.
Your choices
- Read without an account. Everything except the badges works signed out — notes, favorites and bookmarks included, which then last for the visit and move into an account only if you make one.
- Take your writing with you. Your notes and favorite verses can be exported as Markdown — plain text you can keep or move elsewhere — from Account & preferences, at any time, without asking anyone.
- Correct anything. Your name, email, password and every preference are editable on the same page.
- Leave completely. Close your account, at the foot of that page, erases everything as described above. You are asked for your password, and then once more to confirm.
- Refuse the cookies. Your browser can block or delete them. The site will still let you read; you will simply be signed out, and it will not know your time zone or your place.
How it is protected
Passwords and recovery codes are stored only as hashes, so they cannot be read back — not by us either. The session cookie is marked so that scripts cannot read it and other sites cannot send it, and is encrypted in transit wherever the site is served over HTTPS. Every form that changes anything carries a token that makes it useless to submit from elsewhere. Repeated wrong passwords slow down and then pause, by name and by address together, so that guessing is impractical and so that nobody can lock you out of your own account by guessing at it.
No system is perfect. If you find something wrong, the contact form reaches us, and we would rather hear it from you.
Children
Biblion is not directed at children, asks for no age, and collects nothing that would identify one. If you believe a child has given us information that should not be here, write to us through the contact form and it will be deleted.
Changes to this policy
If what Biblion stores changes, this page changes with it, and the date at the top changes too. Material changes will be noted on the site rather than made quietly.
For readers in the EU and EEA
If you are in the European Union or the European Economic Area, the General Data Protection Regulation gives you specific rights, and requires us to be specific in return. Everything above applies; this section states it in the terms the regulation uses.
Who is responsible
The controller of your personal data is Mint Labs, s. r. o. (company number 52874052), Ostravska 1014/8, 040 11 Kosice, Slovakia, reachable through the contact form or by writing to that address. There is one processor, and no others: Amazon Web Services EMEA SARL, which hosts the server and delivers the chapter recordings, acting on our instructions under a data processing agreement. Given the nature and scale of the processing described here, no data protection officer is appointed and none is required.
What we rely on to process it
- Performance of a contract (Article 6(1)(b)) — for your account and everything held on it. You asked for an account; these are the things it is made of.
- Legitimate interests (Article 6(1)(f)) — for the record of refused sign-ins, which protects your account and the site from password guessing; and for the daily visit count and the tally of reading, neither of which can be linked to a person: the count because it is one-way hashed and different each day, the tally because it stores no visitor at all. In each case the interest is the security and continuation of the service, and the effect on you is minimal by design. You may object to any of these, and we would then have to show compelling grounds or stop.
- Consent is not relied on, because nothing here is stored that would require it. No cookie is used for advertising, analytics or tracking; those that exist are either strictly necessary for a service you asked for, or a preference you set yourself. So there is no cookie banner, because there is nothing here to consent to.
Your rights
You have the right of access to your personal data, and to rectification, erasure, restriction of processing, portability, and objection to processing based on legitimate interests. Three of these you can exercise yourself, immediately, without asking us and without waiting: access and portability through the Markdown export, rectification through Account & preferences, and erasure through Close your account. For anything else, or if you would rather we did it, use the contact form and choose a privacy or data request; we will answer within one month.
There is no automated decision-making and no profiling — nothing about you is inferred, scored or decided by machine.
Where your data is
The data lives on a server rented from Amazon Web Services EMEA SARL in its eu-central-1 (Frankfurt) region, physically in Germany, which is in the European Union. Your account, your notes, your reading and everything else described above stay there and do not leave the EEA.
There is no exception to that, and no transfer to a third country to make safe: no standard contractual clauses and no adequacy decision are relied on, because nothing here leaves.
If the site itself ever moves to a region outside the EEA, this page will say so and name the safeguard relied on before it happens.
If we get it wrong
You have the right to complain to a supervisory authority — the data protection authority of the country you live or work in, or where you think the problem happened. We would rather you told us first, through the contact form, but you are not obliged to.