Cardinal app icon
Cardinal
Your Bible & Study Companion

Privacy Policy

Last updated: June 3, 2026

Your privacy matters. Cardinal is designed to collect as little personal information as possible. This policy explains what is collected, how it is used, and your choices as a user.

1. Information We Collect

Information you provide:

Automatically collected information:

Information we do not collect:

2. How We Use Your Information

We use the information collected only to:

3. AI Features and Third-Party Processing

When you use any AI feature (Ask, sermon reflection, or Custom Path generation), your message and the relevant Scripture context are sent to our backend server and forwarded to Anthropic, our AI provider, for processing by their Claude API.

Anthropic processes the request to generate a response and returns it to our server, which streams it back to your device. Anthropic's handling of your data is governed by their own privacy policy: anthropic.com/privacy.

By using the AI features, you consent to this processing. Please do not include personally sensitive information (such as your full legal name, home address, financial details, government identifiers, or detailed medical information) in AI prompts.

Our backend does not retain the full text of your prompts or responses after the request completes. We may temporarily log error events and request metadata for debugging and abuse prevention.

4. iCloud Sync

If you are signed into iCloud on your device, the App uses Apple's CloudKit service to sync your private app data (verses, highlights, Bible notes, chat history, sermon notes, Quiet Time sessions, prayer items) to your private iCloud database. This sync is between your own Apple devices only.

5. Camera, Microphone, and Speech Recognition

Camera (optional): The App can use the camera to capture verses from books or screens for memorization. Captured images are processed entirely on-device using Apple's Vision framework. Images are not sent to our servers and are not retained after the recognized text is extracted.

Microphone and speech recognition (optional): The App can transcribe verses you speak aloud using Apple's built-in speech recognition. Audio is handled by Apple's SFSpeechRecognizer service, which may send audio to Apple's servers for transcription per Apple's policy. Cardinal does not store audio recordings and does not transmit them to our backend.

Both features are off by default and only used when you initiate them. You can deny or revoke camera, microphone, and speech-recognition permissions at any time in iOS Settings.

6. Subscriptions and Redemption Codes

Subscription purchases are processed entirely by Apple through StoreKit. We receive a signed entitlement confirming whether a subscription is active for your device. We never receive your payment information or Apple ID.

Redemption codes (used for granting free AI message credits) are tied to your anonymous device identifier on our server. The server stores only the count of remaining credits and which codes have been redeemed. This data is not linked to your identity.

7. Data Retention

8. Data Sharing

We do not sell your personal information. We share information only:

9. Children's Privacy

The App is not directed at children under 13 years of age (or 16 in the European Economic Area). We do not knowingly collect personal information from children. If you believe a child has provided us information, contact us at the address below and we will promptly delete it.

10. Your Rights

Depending on your location, you may have rights regarding your personal information, including the right to access, correct, or delete information associated with your device identifier, the right to opt out of certain data processing, and rights under the GDPR (EEA residents), the UK GDPR, the CCPA/CPRA (California residents), and other applicable laws.

To exercise these rights, contact us at Bridges@duck.com. Because we do not collect identifying information, we may ask you to provide additional details (such as the approximate date you began using the App or the device on which you used it) so we can associate a request with the limited data we hold.

11. Security

All communication between the App and our backend uses HTTPS (TLS). We implement reasonable technical and organizational measures to protect your information. However, no method of transmission over the internet or electronic storage is completely secure, and we cannot guarantee absolute security.

12. International Transfers

Our backend and Anthropic's services are operated in the United States. If you access the App from outside the United States, your information may be transferred to, stored, and processed in the United States or other countries where our service providers operate.

13. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be communicated through the App or by updating this page. Continued use after changes take effect constitutes acceptance of the revised policy.

14. Contact

For privacy-related questions or requests:

Jed Bridges
Bridges@duck.com