Privacy by design
Privacy Policy
Remy is designed to help people memorize Scripture while collecting as little personal information as possible. This policy describes the current beta build and will be reviewed again before public App Store release.
Information stored on your device
The app stores the following information locally:
- chosen Bible passages and user-entered custom passage text;
- recall progress, review timing, and completion history;
- an optional local profile label;
- unfinished learning or review session state;
- Wonder and equipped Remy gear; and
- sound, haptic, reminder, song favorites, and optional Flock preferences.
This information powers Remy’s learning, review, persistence, and companion features. The local Scripture-memory database is not synchronized to an app-owned server.
Optional ESV passage lookup
If you select the English Standard Version (ESV), Remy sends only the Bible reference needed for that passage through Remy’s secure passage service to Crossway’s ESV API. The lookup does not include a Remy account identifier, profile label, learning history, review result, custom text, voice data, Wonder, purchases, or Flock data. The passage service does not cache the returned ESV text; the app may retain recently used ESV passages on your device within its documented licensing limits.
Remy’s hosting provider and Crossway may process ordinary connection data, such as an IP address and request time, to deliver and protect the service. ESV lookups require an internet connection unless that passage is already retained on your device.
Voice recall
If you choose Say the passage, Remy requests microphone and speech-recognition permission and uses Apple’s on-device recognition to follow or compare your recitation with the selected passage. Remy provides no network-recognition fallback, does not write the audio to a file, clears recognized words after the attempt, and stores only a coarse indication that voice participated in a completed recall.
Listening popularity
Remy may send a bounded signal when you meaningfully play or favorite one of the twelve owner-authored songs. A meaningful play requires actual listening for at least the shorter of 15 seconds or half the song; moving the seek control does not count. The request contains only an allowlisted song code, a random app-installation code unrelated to your learner profile or Flock identity, a random play-event code when needed to prevent duplicates, and the play or current favorite state. It does not contain Scripture text or references, memory practice, review results, profile labels, Remy status, Wonder, purchases, Journeys, voice data, contacts, location, or an advertising identifier.
Remy’s service converts the installation code to a one-way digest before storage. Play-event deduplication records expire after 90 days. Current favorite membership expires after 400 days unless the app refreshes it or you remove the favorite. The developer’s metrics view returns song-level totals and rankings, not installation-level records. Vercel and Remy’s storage provider may process the bounded records and ordinary connection data, such as an IP address and request time, to deliver and protect the service. There is no third-party analytics SDK or cross-app tracking.
Optional private Flock
If you choose to create or join one or more Flocks during the private pilot, Remy creates an opaque random installation session and uses Remy’s private service. Invited participants can see:
- a first name or nickname of up to 30 characters (the app asks you not to enter a full legal name, contact information, or an official Remy role and rejects obvious contact-like, harmful, or impersonating entries);
- the identifiers of equipped Remy gear;
- aggregate counts of passages learned, passages practiced over time, and completed Journeys;
- an update time; and
- fixed, prewritten encouragements and their sender, recipient, and time.
Flock does not share Scripture text or references, custom passages, review attempts or history, accuracy, assistance, failures, schedules, overdue status, voice data, Wonder balance, purchases, or Remy’s live condition. It is private and invitation-only, with no public search, contact upload, free-text chat, public feed, or leaderboard.
The installation session requires no email, password, Apple identity, or contact access. Its token is stored in the iOS Keychain and sent only to Remy’s service over HTTPS; the service uses a one-way digest as its identifier. Private invitations expire after seven days. A member profile in each Flock remains until that member leaves that Flock, the owner removes it, or the owner closes the Flock; other memberships remain intact. Fixed encouragement records expire after 30 days. Vercel and Remy’s storage provider may process ordinary connection data and these bounded Flock records to deliver and protect the feature.
Information collected by the developer
Outside the optional ESV lookup, bounded listening-popularity signals, and Flock projection described above, the current app does not automatically transmit Scripture text, learning history, advertising data, location, contacts, photos, voice recordings, or speech transcripts to the developer or third parties. Remy’s Flock service is not a general account or messaging system, but the developer and infrastructure processors can technically access its bounded installation identifiers, profile projections, and fixed encouragements. Listening metrics are limited to the pseudonymous records and aggregate counts described above.
If you deliberately open the system share sheet for a learning-evidence summary, you choose the recipient and should review the summary before sharing. TestFlight and the operating system may process installation, diagnostic, crash, or feedback information under Apple’s terms and privacy policy. Feedback you submit through TestFlight is provided to the developer.
App waitlist and beta signup
If you join the app waitlist for the iPhone beta on this website, Remy stores your email, your confirmation that you are 18 or older, your optional choice of who may use Remy, and the signup time. This is used only to contact you about the Remy beta. Do not enter a child’s email or other personal details.
We use your email to request a TestFlight invitation from Apple. We also keep an invitation status, attempt count, and processing times so we can avoid duplicate invites and recover failed requests. Apple sends the invitation and manages its tester records under Apple’s privacy policy.
The signup and invitation status are stored with Vercel and Upstash for up to 180 days. Removing a signup cancels pending invitation work; it does not recall an email already sent by Apple. You can also ask us to remove your TestFlight access. The website does not add an ad tracker, analytics tool, or account. The providers may process ordinary connection data, such as an IP address and request time, to deliver and protect the form. Email hi@jamkoo.art to ask for removal.
Children
Remy does not require a child to create a Remy account, provide an email address, join a public social network, or view behavioral advertising. The website beta form is for adults and must not be submitted by a child. Flock should be used by minors only with parent or guardian supervision and known, trusted invitees during the pilot. Do not use a child’s full legal name as a Flock display name. The pilot is not yet approved for broad school, youth-group, or church deployment.
Data sharing and sale
The current app does not sell personal information and contains no advertising or third-party analytics SDK. Deleting the app removes its local app container, subject to device backup and operating-system behavior, but does not by itself prove deletion of server-held Flock, listening records, or a website beta signup. Listening and beta-signup records expire as described above. A participant can leave, an owner can remove a participant, and an owner can close a Flock. Complete self-service session deletion and final retention behavior remain external-release requirements.
Security and changes
Local data is protected by the security controls of your device and the iOS app sandbox. Private Flock access uses high-entropy bearer and invitation tokens, one-way token digests, server-side membership checks, bounded retention, and HTTPS. Listening popularity uses strict allowlists, one-way installation digests, bounded retention, rate limits, and aggregate-only owner access. Storage credentials, the metrics access secret, the beta signup access secret, and the ESV credential remain on Remy’s server, not inside the distributed app. This policy will be updated before Remy adds broader cloud sync, recoverable accounts, broader analytics, crash-reporting services, off-device speech processing, advertising, or other off-device processing.
Contact
Privacy questions and support requests can be sent to hi@jamkoo.art.