Privacy Policy
Last updated: September 6, 2026 (version 2026-09-06.v8)
What we collect. Your account details (email and sign-in identity, handled by our authentication provider), the studies, notes, and questions you create, your Study Credit activity, and — for purchases — the billing information you enter with our payment processor, Stripe. We do not see or store full card numbers.
What we use it for. Operating your account, delivering and recording your studies, managing subscriptions and credits, and sending the service emails a paid account requires (such as receipts and failed-payment notices). No marketing lists without your consent, no selling of data, no advertising trackers.
Development and launch update signups. If you join this optional list, we hold the email address you give us and the moment you consent — used only for Let Scripture Answer development and launch updates. You can ask to have it removed at any time via Help & Contact. The list is separate from creating or operating an account, and outbound updates are sent manually by our team, not by an automated mailing system.
Artificial intelligence services. To generate an answer and independently review it, LSA sends your question and the approved Bible evidence for it to AI model providers under a zero-data-retention contract — they do not use your content to train their models and do not retain it beyond serving the request. See Why You Can Trust LSA for the specific protections in plain language.
Billing address. Checkout collects your billing address. It is used for payment processing and to determine where sales tax obligations may apply; where tax applies, it is shown before you pay.
Your controls. You can export your studies, notes, questions, and history as JSON at any time. Deleting your account removes your studies, notes, conversations, highlights, bookmarks, preferences, and policy acceptances from the live system immediately. Where backups exist, a deleted record may still exist in an encrypted backup for a limited time afterward — used only to recover from a system failure, never accessed for any other purpose — as a best-effort target window, not a fixed or promised one. We retain a minimal account-action audit record (an internal account identifier, the action, and its timestamp) for security and abuse prevention, and records of financial transactions as required for accounting and legal compliance.
Help & Contact requests. If you submit the Help & Contact form — whether or not you have an account — we store the request type (support or update-list removal), the reply email you give us, your optional message, and its review status (including any note an admin adds while reviewing it). This queue is separate from the development-and-launch-update list and from your account: it exists only so an approved team member can review and act on the request by hand. It is never used for marketing, and submitting it does not sign you up for anything. Separately, to prevent duplicate submissions and abuse, we turn your email and the request's idempotency key into one-way (HMAC-hashed) fingerprints for rate limiting — those fingerprints never reveal or store the original values, distinct from the reply email stored with your request above. After a successful submission, a separate usage record notes only the public intake mode and whether it was a support or removal request, so we can measure whether the form works. That record contains no request identifier, email address, message, or other free-form content.
Help & Contact retention. Help & Contact requests (including requests to be removed from the launch-updates list) are reviewed and resolved by hand by an approved team member — not automatically. Once a request is resolved, we redact the reply email and message text from the record; we keep the request type and timestamps for audit. Older resolved records are subject to removal under our data retention process. A separate, general usage record notes only whether the request was a support question or a removal request — it does not include a request identifier, email address, or message, and is never linked back to your specific request. You can ask us to remove a launch-updates address by submitting a removal request through Help & Contact.
Questions or removal. If you have an account, sign in and use Support Center from your account settings. If you do not, use Help & Contact to reach us or to ask that your development-and-launch-update address be removed entirely — no account is required, and a private queue holds the request for a person to review.