Privacy policy
Last updated: 29 September 2026
Contents
This policy explains what information the Hosanna application collects, what we use it for and what you can do about it. It's written to be understood: if something isn't clear, write to us and we'll clarify it.
First things first, because it's what gets asked the most: Hosanna does not sell your data and does not show ads. It does use a Meta measurement tool to know which ads bring new people to the app; on iPhone that only happens if you allow it when the system asks, and you can change it whenever you want from Settings. It's explained in detail below.
1. Who is responsible
The controller of your data is START NODE, S.A., with registered address at Calle D, El Cangrejo, Bella Vista, Edificio Clarion Victoria, ground floor, Panama City, Republic of Panama, developer of the Hosanna application. You can reach us at hello@startnode.com.
2. What data we collect
Before you register: nothing that identifies you
When you first open the app an anonymous session is created. We don't ask for an email, a name or any permission: we just generate a random identifier so we can keep your streak, your favourites and your progress. That identifier is not tied to you or to your device, and on its own it doesn't tell us who you are.
If you register
Registering is optional and is done with Apple or Google. When you do, that anonymous session becomes your account and we add:
- Email address. It's what identifies your account.
- First and last name, if the provider gives them to us or if you fill them in.
- Profile picture, if you pick one of ours or upload your own.
- Google or Apple identifier. We receive that identifier, your email and your name; never your password, which never travels to us at any point.
- If you use Apple's Hide My Email, we receive the relay address Apple generates and never your real one.
- Onboarding preferences: your time of day, the reminder time and the language.
There's no username-and-password registration: we don't handle passwords of any kind.
What gets generated as you use the app
- Your streak and the dates you opened the app, along with your time zone (so the day starts when it starts where you live).
- Favourites, amens and songs played, to build your lists and to know what content works.
- Progress in studies and devotionals, to pick up where you left off.
- Bible chapters read today, to apply the free plan's limit.
- App usage log: which screens you open, the welcome steps, what content you open or listen to and for how long, whether you tapped the Premium plan, together with the app version, the phone model and system, language, time zone and a random installation identifier. It stays on our servers and is not shared with anyone. It never includes what you write (prayers, chat messages, names): for the chat, for example, we only keep that you sent a message and its length.
What you write
- Your prayers and your list of who you pray for. They're private: they aren't shown to other people or published anywhere.
- Your messages in the chat with the Bible. See section 5, which has its own detail.
From the device
- Push notification token and platform (iOS or Android), only if you agree to receive notifications.
- Minimal technical data for each request to the server (IP address, date and time), in the usual logs of any web server.
- Device advertising identifier (IDFA on iOS, GAID on Android) and install data, collected by the Meta SDK to measure campaigns. On iOS only if you accept the tracking prompt the system shows; if you decline, the identifier is not collected. See section 4.
- Crash reports: if the app fails, the technical detail of the failure is sent (where it happened, device model, system and app version) along with your account identifier, so it can be reproduced. The content of your prayers or messages is not sent.
3. What we use it for
| Data | What for |
|---|---|
| Email and identity | Create your account, sign you in and recover it. |
| Preferences | Show you the content for the time of day you chose. |
| Streak and opens | Keep count of your days in a row. |
| Favourites and plays | Build your lists and sort the catalogue by what's most played. |
| Prayers | Save them so you have them on all your devices. |
| Chat | Answer your questions about the Bible. |
| Push token | Send you the daily reminder and new content alerts. |
| Subscription status | Know whether you have Premium active. |
| Usage log | Understand at which step people get stuck, which content helps most, and compare two versions of a screen to keep the one that works better. It also tells us which of our campaigns each install came from (the data the store or the ad leaves at install time), so we know which Hosanna ads bring people who then use the app. It is not shared with Meta or anyone else and is not used to show you ads. |
We don't make automated decisions with legal effects on you. We do tell Meta some anonymous or pseudonymised facts (that the app was installed, that someone registered, that a trial or a subscription started) to measure our campaigns and so that Meta can show Hosanna's ads to people similar to those already using it. That's what the stores call "tracking", which is why on iOS we ask you first.
4. Who we share it with
Only with the providers needed for the app to work, and only with what each one needs:
| Provider | What it receives | What for |
|---|---|---|
| OpenAI | The text of your chat messages | Generate the answer |
| RevenueCat | An identifier for your account and the purchase receipt | Validate your subscription |
| Apple / Google | Sign-in and payment data | Authenticate you and charge the subscription |
| Apple, Google and Expo notification services | Your device token and the text of the notice | Deliver the notification |
| Meta Platforms (Facebook) | App events (install, registration, trial start, purchase) with the device advertising identifier if you gave permission, and in the case of a purchase, your email and user identifier irreversibly hashed to attribute the conversion | Measure which ads work and optimise Hosanna's advertising. You can withdraw the permission on iOS from Settings → Privacy → Tracking, and on Android from Settings → Google → Ads. Meta's policy: facebook.com/privacy/policy |
| Sentry | The technical detail of app and server errors, with your account identifier and no other personal data | Detect and fix failures. Sentry's policy: sentry.io/privacy |
| Our hosting provider | The data stored on the server | Keep the app online |
We may also share data if required by a competent authority or a legal obligation. Beyond that, nobody else receives it.
Some of these providers are outside your country, so your data may be processed on servers abroad, with the contractual safeguards each one offers.
5. The chat with the Bible
The chat uses an OpenAI language model. When you ask something, we send OpenAI the text of your conversation and some context so the answer is yours and not generic: your first name if you gave it to us, which studies you're in and how many days in a row you've been opening the app. We do not send your email, your account identifier or anything that would let OpenAI know who you are.
Under the OpenAI API terms, that content is not used to train their models and is kept for a limited period for abuse monitoring, after which it is deleted.
Three things worth keeping in mind:
- Your conversations are stored on your phone, not on our servers. You can read them again from this device, and they disappear if you uninstall the app. Deleting your account doesn't touch them, because we never had them.
- The answers are generated by an automated model and can be wrong. We always show the verses cited so you can read them in the Bible.
- Don't write in the chat sensitive data you don't want leaving your device (health, financial or third-party data).
6. Notifications
Notifications are optional and we ask for them with the system prompt. If you accept, we store your device token so we can send them. You can turn them off whenever you want from your phone's settings; the token stops working and we retire it.
7. Subscriptions and payments
Hosanna Premium is charged through the App Store or Google Play, depending on where you subscribed. We never see or store your card details: the charge is processed entirely by the store.
From the purchase we receive, via RevenueCat, whether your subscription is active and until when. That's what unlocks the content, nothing else.
8. How long we keep it
- Your account data and your content: as long as the account exists. Deleting it deletes them.
- Server technical logs: a short period, for security and diagnostics.
- App usage log: up to 24 months; then it is deleted. If you delete your account, it is no longer linked to it.
- Purchase receipts: for as long as the applicable accounting and tax rules require, even if you deleted the account.
9. Your rights
You can ask at any time for:
- Access — to know what we hold about you.
- Rectification — to correct what's wrong.
- Erasure — to have it deleted.
- Portability — to receive a copy in a readable format.
- Objection and restriction — to have us stop using it for certain purposes.
Write to hello@startnode.com from your account's email address and we'll answer within 30 days. If you think we didn't resolve it properly, you can complain to Panama's data protection authority or to the one in your country of residence.
10. How to delete your account
You can delete your account and all of its content yourself, from the app or from here. The step by step, and exactly what gets deleted, is in Delete your account.
11. Security
All traffic between the app and our server is encrypted (HTTPS). Your phone's session is stored in the operating system's secure keychain, not in plain text. Since sign-in is only with Apple or Google, we don't store passwords: there isn't one that could leak. Even so, no system is infallible: if we detect a breach affecting your data, we'll tell you.
12. Minors
Hosanna is not directed at children under 13 and we don't knowingly collect data from that age group. If you are a parent or guardian and believe a minor in your care created an account, write to us and we'll close it.
13. Changes to this policy
If we change it, we update the date above. When the change is significant, we let you know inside the app before it takes effect.
14. Contact
For any question about this policy or about your data: hello@startnode.com.
This is a translation provided for convenience. In case of any discrepancy, the Spanish version prevails.