Effective August 18, 2026
Privacy Policy
Your account stores your journeys, generated devotionals, reading progress, narrated audio, custom instructions, journey requests, and daily check-ins so they can be restored after reinstalling the app. Your own words may also help find relevant context for future devotionals. We do not track you, show ads, or sell your data.
What we collect
Your email address. Creating an account is required to use the app. If you sign in with Apple and choose “Hide My Email,” we only ever receive Apple’s private relay address — not your real one. It is stored by our authentication provider (Supabase) and used for one thing: letting you sign back into your account.
A record that a devotional was generated. Each time the app writes a devotional or plans a journey, we store a row with your account ID, which of the two kinds of request it was, how many tokens it used, and the time. This enforces a daily limit that stops automated abuse of our AI costs. It does not contain what you wrote or what you read.
Your subscription status. We store your account ID, subscription product, expiration, and revocation status after verifying Apple’s signed transaction. This lets our server enforce the same access the app shows. We do not receive or store payment-card or billing-address details.
Your reading archive. We store generated journeys and devotionals, reading progress, narration files and timings, custom writing instructions, your selected Bible version, your favorite journeys and loved devotionals, and your daily-reminder preference and time so generated content and your choices can return after reinstalling. iOS notification permission and the actual repeating schedule stay on your device.
Notifications for completed writing. If you allow notifications, Apple gives the app a device notification token. We store that token with an opaque installation ID and your account so our server can tell you when a journey or devotional finishes after you leave or close the app. The token is a delivery address, not notification content or an advertising identifier. We ask Apple and our server to stop using it when you log out; it is also removed when Apple says it is invalid or when you delete your account.
The words you give the app. We store journey descriptions and optional daily check-ins until you delete the journey or your account. They restore your history and let future devotionals find genuinely related past context. AI-generated prose is excluded from this memory index.
If you explicitly love a devotional, future devotional writing may receive up to two short prose-only excerpts from loved devotionals as examples of the voice you liked. This is a separate style-preference channel: loved prose is not embedded, is not treated as factual memory about you, cannot choose a Bible passage or checkpoint, and is removed from future use when you unlove it or delete its journey.
If you add a journey to Favorites, the journey creator may use a compact description of that saved preference—your original request and the duration, daily time, activities, and Scripture amount you chose—to make future journey invitations more relevant. It does not send the saved journey's daily devotionals or full day list for this purpose.
Mustard Tree selects this context automatically and only when it is a strong semantic match for the current devotional. There is no AI-authored profile or memory summary. Deleting a journey removes its reader-authored context from future recall; deleting your account removes all account-linked context.
Content you choose to share
When you use Share, we create an unguessable public link. A shared journey includes its title, description, length, daily route, Bible references, and reading preferences. It does not include your original request, progress, check-ins, memories, custom instructions, or generated daily devotionals. Someone who starts it receives the same route, but their devotionals are written for them.
A shared devotional is an immutable snapshot of that day’s finished writing and visible checkpoint prompts. It does not include the check-in, memories, or custom instructions that may have shaped the writing. Anyone with the link can read its contents, so do not share a devotional if its finished prose contains something you want to keep private. Deleting the source journey or your account disables its links.
How AI providers process content
To write a devotional, the app sends the text you have written — your description of what you want a journey about, your check-in notes, and your custom instructions — plus up to two short prose-only excerpts from devotionals you explicitly loved and the day’s vetted Bible passages (one or more) — to OpenAI’s API, through our server. Loved excerpts are sent only to calibrate writing style, not as facts about you. The model writes only devotional prose and chooses where the app places each vetted passage. When you use Ask about this reading, the app sends your question, that day’s vetted passages and its devotional prose, your original request for that journey, your custom instructions, and your earlier questions about that same day to OpenAI through our server; your check-ins and reading memories are not included. Those questions and answers are kept only on your device, tied to that day, and are never used to write devotionals or added to semantic recall. To personalize journey invitations and the bounded creator, we may also send up to five compact saved-journey preferences described above; their generated days and devotionals are excluded. We also use OpenAI to create mathematical embeddings from reader-authored journey descriptions and check-ins for semantic recall. API responses are requested with storage disabled.
- OpenAI processes that content under their own terms. See OpenAI’s Privacy Policy.
- ElevenLabs receives generated devotional text, and the vetted Scripture text of a passage you choose to listen to, to create narration audio. See ElevenLabs’ Privacy Policy.
- Bible passages are sent only as grounding context. The app never displays model-written verse text: Scripture and any Scripture quotations shown to you are rendered from the Bible version you selected from the vetted translations bundled inside the app.
Your custom instructions may include sensitive information such as your church or religious tradition. Adding it is optional. It is stored with your account so the preference can be restored, but it is not placed in the semantic memory index.
What remains only on your phone
- Your highlights
- Your profile name and photo, if you add one
- Your scene images, appearance choice, and playback settings
- iOS notification permission and the scheduled local-notification request
These items are removed if you delete the app and are not restored by the reading archive. Your tree is derived from account-backed reading progress, so its growth can be rebuilt.
Subscriptions
Subscriptions are sold and processed by Apple. We never receive your payment details — not your card, not your billing address. The app sends Apple-signed subscription evidence to our server so it can verify whether generation is available for your account. Manage or cancel in your Apple ID settings; Apple’s refund and billing policies apply.
What we do not do
- We do not use advertising, ad networks, or ad identifiers.
- We do not track you across other apps or websites.
- We use no third-party analytics, attribution, or crash-reporting SDKs. Production AI requests go through our server to the processors named above.
- We do not sell, rent, or share your personal information for advertising. The generation processing described above is the only disclosure of the text you submit.
Deleting your account and data
Deleting an individual journey removes that journey’s description, daily check-ins, generated devotionals, questions asked about its readings, reading progress, and semantic-personalization rows from the device and server. Those words cannot be recalled into a future devotional. Only an anonymous completed-day count remains on the device so deleting a journey does not shrink your tree.
Profile → Delete account permanently deletes your account and email address, generation-log rows, server reading archive (including journeys, devotionals, progress, inputs, preferences, narration metadata and stored audio), check-in notes, locally stored reading memories and questions you asked about readings, descriptions you gave journeys, pending journeys, and your profile name and photo.
Your completed days, growth, highlights, finished journeys, generated devotionals, and non-personal app settings may remain locally on that device so deleting a required account does not erase your tree. Check-ins, memory timestamps, Custom Instructions, pending requests, reader desire/brief text, loved-devotional voice preferences, and personalized starter data are removed from that device. Retained content is no longer stored by the deleted account and will not return after uninstalling. Deleting the app removes the remaining local content too.
You may also contact us through our support page to request deletion.
Children
Mustard Tree is not directed to children under 13, and we do not knowingly collect personal information from them. If you believe a child has given us personal information, contact us and we will delete it.
Changes
If this policy changes, we will update the effective date above and post the revised policy at this URL. Material changes will be surfaced in the app.