Privacy Policy

Effective and last updated: September 3, 2026

This policy explains how Marrow handles information when you use the Marrow mobile and desktop applications, the Marrow server, or marrowbible.com (together, the “Service”). Marrow is operated under the name Marrow. Questions and privacy requests can be sent to privacy@marrowbible.com.

1. The short version

2. Information kept on your device

Uninstalling Marrow or clearing its app data removes locally stored Marrow data according to your operating system's behavior. Deleting your Marrow account does not automatically erase copies that remain on your devices.

3. Account and authentication data

If you create or use an account, Marrow processes:

Google and Apple process information under their own privacy policies when you use their sign-in services. Marrow uses Resend to deliver verification and password-reset email, which means Resend receives your email address and the transactional message.

4. Synced notes

When note sync is available on your account, Marrow sends note text, the associated Bible location or journal date, modification timestamps, and deletion status to the Marrow server. The server associates those records with your internal Marrow user ID.

Deleting an individual synced note marks the server record as deleted so the deletion can propagate to your other devices. The deleted record, including its prior content, may remain until you delete your account.

5. AI features

Marrow offers two ways to use AI:

Depending on the feature, an AI request may include the selected verse or chapter, surrounding Bible text, a topic or question you enter, and the age setting when Kids Mode is enabled. Marrow does not intentionally include your notes, name, or email address in the AI prompt.

The Marrow server does not store AI prompt or response bodies in its application database. It does store your internal user ID, the type of AI feature used, an estimated response-token count, and a timestamp for quota and service operation. OpenAI may retain API content and related metadata under its API data-retention policy; by default, abuse-monitoring logs may be retained for up to 30 days. When you use your own key, your own OpenAI account settings also apply.

6. Purchases and subscriptions

On Android and iOS, Marrow uses RevenueCat together with Google Play or Apple's App Store. RevenueCat receives an anonymous app-user identifier before sign-in and Marrow's internal user ID after sign-in, along with purchase history, product, store, entitlement, subscription-status, and related device or app information needed to process purchases, restore access, prevent fraud, and provide subscription analytics.

Desktop checkout may use Stripe. Stripe receives the information needed to complete the checkout and process payment. Marrow stores subscription status and entitlements, provider and subscription identifiers, and limited checkout records. Marrow does not receive or store your full payment-card number.

7. Crash diagnostics and analytics

8. Server and network data

When the app or website connects to a service, the receiving service can process network and request information such as IP address, date and time, request path, response status, app or browser details, and device identifiers. Marrow's application server records request method, path, response status, security events, and error details. Sensitive authorization headers are not included in application logs.

The Marrow server and database are hosted by Railway in the United States. On Marrow's current hosting plan, application logs are retained for seven days. Account and synced-service data are stored in Marrow's PostgreSQL database.

9. Website and downloads

Marrow's website does not run product analytics or advertising trackers. The site and app may contact:

Those providers receive ordinary network data such as your IP address and browser or app request information. Their own privacy policies govern their processing.

10. Service providers and disclosures

Marrow discloses information only as needed to provide a feature you request, operate and secure the Service, process payments, comply with law, or protect users and the Service. Current service-provider categories include:

Marrow does not sell personal information, rent it, or disclose it for cross-context behavioral advertising.

11. Retention

InformationHow long it is kept
Local app dataUntil you delete it, clear the app's data, or uninstall the app, subject to operating-system backups and behavior.
Account, OAuth identity, synced notes, AI usage metadata, and Marrow subscription recordsUntil your Marrow account is deleted, unless a longer period is required for security, fraud prevention, dispute resolution, or law.
Verification and password-reset recordsThe links expire after 24 hours and one hour, respectively. Associated hashed records may remain until account deletion.
Application server logsSeven days on the current Railway hosting plan, unless a specific record must be preserved longer to investigate abuse, a security incident, or a legal claim.
Firebase Crashlytics reportsGoogle generally retains crash reports and associated identifiers for 90 days before beginning removal.
Billing and provider recordsFor the subscription lifecycle and as long as the payment, app-store, accounting, tax, fraud-prevention, and legal requirements of Marrow or the provider require.

Service providers may retain information under their own policies, including in backups, fraud-prevention systems, and legally required records.

12. Delete your account or data

To request deletion, email privacy@marrowbible.com from the email address associated with your Marrow account and use the subject “Delete my Marrow account.” If you cannot email from that address, explain that in your message so we can verify account ownership another way.

After verification, we aim to complete the request within 30 days. Deleting the account removes the Marrow account record, synced notes, OAuth links, authentication tokens, AI usage and quota records, Marrow subscription and checkout mappings, and other database records tied to the account. It does not automatically:

You can request deletion of a particular synced note by deleting it in the app. As explained in Section 4, the server keeps a deletion record so that change can sync; delete the account to remove the server-side note records associated with it.

13. Your choices and rights

Privacy rights vary by location and may include rights to know, access, correct, delete, restrict, object, or receive a portable copy of personal information. Marrow will not discriminate against you for making a privacy request. Send requests to privacy@marrowbible.com.

14. Security

Marrow uses safeguards designed to protect information, including HTTPS/TLS in transit, password and token hashing, operating-system-backed storage for sensitive values where available, authenticated access to synced records, least-necessary service-provider access, and redaction of authorization headers from application logs. No security measure can guarantee absolute protection.

15. Children

Marrow is not directed to children under 13, and the Google Play listing targets users age 13 and older. Kids Mode is intended for a parent or other adult to use while reading with a child; it is not an invitation for a child under 13 to create an account. If you believe a child has provided personal information to Marrow, email privacy@marrowbible.com so it can be deleted.

16. International processing

Marrow is operated from and primarily hosted in the United States. Service providers may process information in the United States and other countries. Depending on where you live, those countries may have privacy laws different from those in your jurisdiction.

17. Changes and contact

We will update this page and its “last updated” date when our practices materially change. If appropriate, we may also provide notice in the app or by email.

Privacy and data requests: privacy@marrowbible.com
General support: hello@marrowbible.com