Privacy Policy
Effective and last updated: September 3, 2026
This policy explains how Marrow handles information when you use the Marrow mobile and desktop applications, the Marrow server, or marrowbible.com (together, the “Service”). Marrow is operated under the name Marrow. Questions and privacy requests can be sent to privacy@marrowbible.com.
1. The short version
- You can read the Bible without creating an account.
- Bible content, reading progress, preferences, and notes are stored on your device. Notes are sent to Marrow only when you use note sync.
- AI requests are sent only when you use an AI feature. Marrow AI and the bring-your-own-key option currently use OpenAI.
- The Android app uses Firebase Crashlytics for crash diagnostics when crash reporting is enabled. Marrow does not use Google Analytics or send product-usage analytics.
- RevenueCat and the applicable app store process purchase and subscription information.
- We do not sell personal information or use it for targeted advertising.
2. Information kept on your device
- Bible and search data — the Berean Standard Bible, pre-computed search data, and related reading resources.
- Reading and app preferences — such as your last-read location, completed chapters, theme, font, line spacing, Kids Mode settings, dismissed tips, and AI-provider choice.
- Notes — verse notes and journal entries are stored locally. If your account has note sync, the app automatically syncs changes at app launch, after login, after saving a note, and when sync access becomes active.
- Credentials and keys — session credentials and any OpenAI API key you provide are stored using operating-system-backed secure storage when available. If secure storage is unavailable, Marrow does not persist those sensitive values in unencrypted fallback storage.
- AI responses — responses may be cached in memory for the current app session and are cleared when the app process closes.
Uninstalling Marrow or clearing its app data removes locally stored Marrow data according to your operating system's behavior. Deleting your Marrow account does not automatically erase copies that remain on your devices.
3. Account and authentication data
If you create or use an account, Marrow processes:
- your email address and, when provided by Google or Apple sign-in, your display name;
- an internal Marrow user ID, your sign-in method, email-verification status, and account timestamps;
- a securely hashed password for password-based accounts; Marrow does not store the original password;
- the identity provider and provider-specific account identifier for Google or Apple sign-in; and
- hashed verification, password-reset, and refresh tokens used to secure your account.
Google and Apple process information under their own privacy policies when you use their sign-in services. Marrow uses Resend to deliver verification and password-reset email, which means Resend receives your email address and the transactional message.
4. Synced notes
When note sync is available on your account, Marrow sends note text, the associated Bible location or journal date, modification timestamps, and deletion status to the Marrow server. The server associates those records with your internal Marrow user ID.
Deleting an individual synced note marks the server record as deleted so the deletion can propagate to your other devices. The deleted record, including its prior content, may remain until you delete your account.
5. AI features
Marrow offers two ways to use AI:
- Marrow AI — the app sends the request to the Marrow server, which forwards it to the OpenAI API using Marrow's account.
- OpenAI with your own key — the app sends the request directly to the OpenAI API using the API key you supplied.
Depending on the feature, an AI request may include the selected verse or chapter, surrounding Bible text, a topic or question you enter, and the age setting when Kids Mode is enabled. Marrow does not intentionally include your notes, name, or email address in the AI prompt.
The Marrow server does not store AI prompt or response bodies in its application database. It does store your internal user ID, the type of AI feature used, an estimated response-token count, and a timestamp for quota and service operation. OpenAI may retain API content and related metadata under its API data-retention policy; by default, abuse-monitoring logs may be retained for up to 30 days. When you use your own key, your own OpenAI account settings also apply.
6. Purchases and subscriptions
On Android and iOS, Marrow uses RevenueCat together with Google Play or Apple's App Store. RevenueCat receives an anonymous app-user identifier before sign-in and Marrow's internal user ID after sign-in, along with purchase history, product, store, entitlement, subscription-status, and related device or app information needed to process purchases, restore access, prevent fraud, and provide subscription analytics.
Desktop checkout may use Stripe. Stripe receives the information needed to complete the checkout and process payment. Marrow stores subscription status and entitlements, provider and subscription identifiers, and limited checkout records. Marrow does not receive or store your full payment-card number.
7. Crash diagnostics and analytics
- Android crash reports — Firebase Crashlytics collection is available in the Android app and may be enabled by default. Reports can include installation and session identifiers, crash stack traces, app version, device model and architecture, operating-system version, device state, timestamps, and diagnostic logs. You can disable “Send crash reports” in Settings; the change applies after restarting Marrow. Google generally retains Crashlytics reports and associated identifiers for 90 days. See Firebase privacy and security information.
- Desktop crash logs — desktop builds write diagnostic logs locally. Marrow receives them only if you choose to attach or send them with a support request.
- Product analytics — Marrow does not include Google Analytics and does not transmit reading history, screen views, or feature-use analytics. Analytics-style events inside the app are written only to local diagnostic logging.
8. Server and network data
When the app or website connects to a service, the receiving service can process network and request information such as IP address, date and time, request path, response status, app or browser details, and device identifiers. Marrow's application server records request method, path, response status, security events, and error details. Sensitive authorization headers are not included in application logs.
The Marrow server and database are hosted by Railway in the United States. On Marrow's current hosting plan, application logs are retained for seven days. Account and synced-service data are stored in Marrow's PostgreSQL database.
9. Website and downloads
Marrow's website does not run product analytics or advertising trackers. The site and app may contact:
- the website host to deliver pages and protect the service;
- Google Fonts to load typefaces; and
- GitHub to check releases and download the Bible database or app updates.
Those providers receive ordinary network data such as your IP address and browser or app request information. Their own privacy policies govern their processing.
10. Service providers and disclosures
Marrow discloses information only as needed to provide a feature you request, operate and secure the Service, process payments, comply with law, or protect users and the Service. Current service-provider categories include:
- Railway for server and database hosting;
- OpenAI for AI requests;
- Google and Apple for sign-in, app distribution, and purchases;
- Firebase Crashlytics for Android crash diagnostics;
- RevenueCat and Stripe for subscriptions and payments;
- Resend for transactional email;
- GitHub for releases and downloadable data; and
- the website host and Google Fonts for website delivery.
Marrow does not sell personal information, rent it, or disclose it for cross-context behavioral advertising.
11. Retention
| Information | How long it is kept |
|---|---|
| Local app data | Until you delete it, clear the app's data, or uninstall the app, subject to operating-system backups and behavior. |
| Account, OAuth identity, synced notes, AI usage metadata, and Marrow subscription records | Until your Marrow account is deleted, unless a longer period is required for security, fraud prevention, dispute resolution, or law. |
| Verification and password-reset records | The links expire after 24 hours and one hour, respectively. Associated hashed records may remain until account deletion. |
| Application server logs | Seven days on the current Railway hosting plan, unless a specific record must be preserved longer to investigate abuse, a security incident, or a legal claim. |
| Firebase Crashlytics reports | Google generally retains crash reports and associated identifiers for 90 days before beginning removal. |
| Billing and provider records | For the subscription lifecycle and as long as the payment, app-store, accounting, tax, fraud-prevention, and legal requirements of Marrow or the provider require. |
Service providers may retain information under their own policies, including in backups, fraud-prevention systems, and legally required records.
12. Delete your account or data
To request deletion, email privacy@marrowbible.com from the email address associated with your Marrow account and use the subject “Delete my Marrow account.” If you cannot email from that address, explain that in your message so we can verify account ownership another way.
After verification, we aim to complete the request within 30 days. Deleting the account removes the Marrow account record, synced notes, OAuth links, authentication tokens, AI usage and quota records, Marrow subscription and checkout mappings, and other database records tied to the account. It does not automatically:
- erase local notes or settings from devices;
- cancel an app-store or Stripe subscription;
- remove records that Google, Apple, RevenueCat, Stripe, OpenAI, Resend, Firebase, Railway, or another provider must retain under its own obligations; or
- remove limited records Marrow must keep for legal, security, fraud-prevention, or dispute-resolution purposes.
You can request deletion of a particular synced note by deleting it in the app. As explained in Section 4, the server keeps a deletion record so that change can sync; delete the account to remove the server-side note records associated with it.
13. Your choices and rights
- Use Marrow for offline Bible reading without creating an account.
- Do not use Marrow AI or the bring-your-own-key OpenAI option.
- Disable Android crash reporting in Settings.
- Request access, correction, a copy, or deletion of information associated with your account.
- Cancel subscriptions through the platform where you purchased them.
Privacy rights vary by location and may include rights to know, access, correct, delete, restrict, object, or receive a portable copy of personal information. Marrow will not discriminate against you for making a privacy request. Send requests to privacy@marrowbible.com.
14. Security
Marrow uses safeguards designed to protect information, including HTTPS/TLS in transit, password and token hashing, operating-system-backed storage for sensitive values where available, authenticated access to synced records, least-necessary service-provider access, and redaction of authorization headers from application logs. No security measure can guarantee absolute protection.
15. Children
Marrow is not directed to children under 13, and the Google Play listing targets users age 13 and older. Kids Mode is intended for a parent or other adult to use while reading with a child; it is not an invitation for a child under 13 to create an account. If you believe a child has provided personal information to Marrow, email privacy@marrowbible.com so it can be deleted.
16. International processing
Marrow is operated from and primarily hosted in the United States. Service providers may process information in the United States and other countries. Depending on where you live, those countries may have privacy laws different from those in your jurisdiction.
17. Changes and contact
We will update this page and its “last updated” date when our practices materially change. If appropriate, we may also provide notice in the app or by email.
Privacy and data requests: privacy@marrowbible.com
General support: hello@marrowbible.com