← Back to Postil

Privacy Policy

Last Updated: July 27, 2026

Postil is operated by Joshua Seevers, a sole proprietor ("I," "me," or "Postil"). This Privacy Policy explains what information I collect through the Postil mobile app and postil.app website (the "Service"), how I use it, and the choices you have.

By using the Service, you agree to the practices described here. This Privacy Policy is incorporated into the Postil Terms of Service.

1. Information I Collect

1.1 Information You Provide Directly

When you create an account, I collect your email address; a display name; your password (if you sign up with email — stored hashed, never in plain text, and never seen by me); a checkbox confirmation that you are 13 or older (see Section 7 — I do not ask for or store your actual date of birth); optionally, an avatar you pick from a built-in set (there is no photo upload); and, if you sign in with Apple or Google instead, the name/email those providers share with the app on first sign-in.

I also collect anything you submit directly: comments you post, content you save or "upcross" (like), creators you follow, creators you suggest I add, reports you file about content or other users, users you block, and messages you send to support (Settings → Help & Support, or emailing support@postil.app).

If you subscribe to Postil Pro, your subscription is purchased and billed entirely through Apple's App Store — I receive confirmation that you're subscribed (via Apple/RevenueCat), but I never see or store your payment card details.

1.2 Information Collected Automatically

I collect basic device and app-usage information through Sentry (crash/error reporting) and PostHog (product analytics) — things like device model, OS version, app version, screens viewed, and what caused a crash if one happens. This is used to fix bugs and understand which features are actually used, not to build an advertising profile of you.

If you enable notifications, I store a device push token (via Apple/Expo's push service) so I can send you a notification when someone replies to your comment or a creator you follow posts something new. You can turn this off in Settings.

I do not collect precise or approximate location data. Postil has no location-based features.

1.3 Advertising

The free tier of Postil shows ads served by Google AdMob within the main content feed, Bible verse content cards, and inside video/podcast/article readers. AdMob may collect a device advertising identifier (IDFA) and use it to serve and measure ads, subject to your iOS App Tracking Transparency choice (you'll be prompted; you can decline and still use the app — ads will be shown but not personalized to your device). Postil Pro subscribers do not see ads in the main feed or Bible verse content cards (video/podcast/article ads are unaffected, since those run through a separate ad path — see Terms of Service Section 3.1).

I do not use Google Analytics, Facebook/Meta ads tools, or any other ad or analytics network beyond AdMob, Sentry, and PostHog.

1.4 Third-Party Content

Postil aggregates publicly available RSS feeds and, for video, publicly available YouTube data. When you view embedded YouTube content, YouTube/Google collects your viewing activity per their own Privacy Policy (policies.google.com/privacy) — that collection happens on YouTube's side, not through anything Postil does. When you tap out to an external article or website via Postil's in-app browser, that site's own tracking (if any) applies, and I don't control it.

2. How I Use Information

I use your information to run the Service (create your account, show your saved/followed content, sync your reading position in the Bible, post your comments), process your Postil Pro subscription status via RevenueCat, send you push notifications and transactional emails (account verification codes, password reset codes, Help & Support responses — sent via Resend) if you haven't opted out, generate AI-powered summaries and Bible verse cross-references for content (see below), screen display names and comments for profanity before they post, review reports and enforce the Terms of Service (including blocking abusive accounts), and fix bugs / understand feature usage via Sentry and PostHog. I may also use your email address to send you marketing communications about Postil (new features, content recommendations, and similar updates) — every marketing email includes an unsubscribe link, and opting out of marketing email never affects transactional emails you need to use the Service.

I don't sell your personal information, and I don't share it with advertisers beyond the device-level advertising identifier AdMob itself collects to serve ads (Section 1.3).

2.1 AI Processing

Content summaries, category tags, and Bible verse cross-references are generated using a third-party AI language model API. Content text (titles, descriptions, article text) is sent to that API to generate these outputs. Your personal account data and comments are not sent to this AI for training purposes, and I don't use your data to train any AI model.

3. How Long I Keep Information

If you delete your account (Settings → type "DELETE" to confirm), deletion is immediate and permanent — your profile, comments, saved/upcrossed/followed items, hidden items, blocks, and push token are deleted right away, not after a grace period. Some records tied to reports you filed or that were filed against your account may be retained briefly to complete review of an in-progress report. Your Postil Pro subscription record on Apple/RevenueCat's side is retained by them independently, per their own retention rules, so that restoring a prior purchase continues to work even after account deletion.

Crash/analytics data collected via Sentry and PostHog is retained according to those providers' standard retention windows, and isn't something I separately archive.

4. Who I Share Information With

4.1 Service Providers

I use the following third-party services to run Postil, each of which processes data only as needed to provide their service to me: Supabase (database, authentication, and file storage); RevenueCat and Apple (subscription/purchase processing); Google AdMob (ad serving); Resend (transactional email — account verification codes, password resets, support messages); Sentry (crash/error reporting); PostHog (product analytics); Vercel (hosting for postil.app and the admin dashboard); and Anthropic (the AI provider used to generate content summaries/tags, as described in Section 2.1).

4.2 Legal Disclosures

I may disclose information if required by law (court order, subpoena), to investigate fraud or abuse, to enforce the Terms of Service, or to protect the safety of users or the public.

4.3 No Sale of Personal Information

I do not sell your personal information to third parties.

5. Data Security

Data is encrypted in transit (TLS) and at rest where supported by Supabase. Passwords are hashed, never stored in plain text. Access to the admin dashboard requires a password plus a one-time email code. That said, no system is perfectly secure, and I can't guarantee absolute security of your information.

6. Your Privacy Rights

6.1 In-App Controls

From Settings, you can view and delete items you've hidden or creators you've hidden/blocked, turn off push notifications, change your display name and avatar, and permanently delete your account and all associated data.

6.2 GDPR Rights (EU/EEA/UK Users)

If you're located in the EU, EEA, or UK, you have the right to access, correct, delete, restrict processing of, or receive a portable copy of your personal data, and to object to certain processing. Email admin@postil.app to make a request — I'll respond within 30 days. You may also lodge a complaint with your local Data Protection Authority.

6.3 CCPA Rights (California Residents)

California residents have the right to know what personal information I collect, request deletion of it, correct inaccurate information, and non-discrimination for exercising these rights. Since I don't sell personal information, there's no "opt out of sale" mechanism needed. Email admin@postil.app to make a request.

6.4 How to Reach Me

For any privacy request — access, deletion, correction, or a general question — email admin@postil.app with your account email and what you're requesting. Account deletion can also be done directly and immediately in-app via Settings, without needing to email anyone.

7. Children's Privacy (COPPA)

Postil is not intended for children under 13. Account creation requires you to confirm, via a checkbox, that you are 13 or older — Postil does not collect or store an actual date of birth, only this self-attestation. If I ever become aware that an under-13 account exists anyway, I will delete it and its associated data immediately. If you're a parent and believe your child has an account, email support@postil.app.

8. International Users

Postil is operated from the United States, and data is stored and processed in the U.S. (via Supabase's infrastructure). By using the Service from outside the U.S., you understand your information will be transferred to and processed in the U.S.

9. Third-Party Links

Postil links out to, and displays in an in-app browser, third-party articles, YouTube videos, and podcast content. Those sites/services have their own privacy practices that I don't control — review their policies independently before sharing information with them.

10. Changes to This Policy

I may update this Privacy Policy as the app changes. Material changes will be reflected here with an updated date. Continuing to use Postil after a change takes effect means you accept the updated policy.

11. Contact

Privacy requests and legal notices: admin@postil.app

General support: support@postil.app