Effective September 9, 2026
Privacy Policy
Nemora is a private place to journal, reflect, and meet what you write with Scripture. We treat those words with the gravity they deserve. This page explains what we collect, how it is protected, and when it is processed to power the experience. The current journal and supported earlier versions differ in storage and sharing, so those differences are called out below.
How your data is protected
- Protected on your device. The current journal keeps its archive in an account-scoped app container using iOS Data Protection.
- Encrypted in transit. Network requests use TLS. Account-backed server data is protected by our infrastructure and scoped to the signed-in account.
- Automated processing. AI features run automatically. Access by Nemora and its providers is limited to operating, securing, supporting, and complying with law.
- Bounded provider processing. Nemora sends only the content needed for a requested feature. New saved responses use Anthropic while Nemora's server-owned job keeps the bounded request durable so it can retry and finish if you leave the app. Previously accepted saved-response jobs retain the provider assigned when they began. Entry conversations, reflections, and portraits use OpenAI background processing, which temporarily stores response state for accepted work; OpenAI documents this temporary state as lasting roughly ten minutes. Nemora does not use either provider as your journal archive. Separately, under OpenAI's standard API data controls, abuse-monitoring logs may contain API inputs and outputs and are retained for up to 30 days by default. Providers may also process or retain limited data under their applicable security and abuse-prevention terms.
What we collect
Account information. Where free access is available, you can write and read the Bible without creating an account. Guest writing uses a separate protected local archive. If you later sign in, it is kept with that account on the same device; signup does not create a cloud journal backup. An account is required for Pro features. You can continue with Google, sign in with Apple, or use a six-digit code sent to your email address. Supabase stores the email address or Apple private relay address associated with the account, an account identifier, the selected sign-in provider, and authentication records. An optional profile name and photo stay on your device and are not uploaded by Nemora.
Journal content. The current journal keeps entries, drafts, generated responses, entry conversations, and entry-owned reflections in a protected, account-scoped archive on your device. Saved weekly portraits are also kept in protected, account-scoped files on your device. The journal does not use our server as the source of truth for that archive, and there is currently no cross-device sync for new journal changes. Earlier versions stored journal entries, responses, conversations, portraits, and related metadata in account-scoped Supabase records. The current journal may import those records, but import does not delete the older database records or portrait files. Those sources remain available to the migration unless separately deleted.
To let an automatic weekly portrait begin after a week closes even when the app is not open, Nemora may temporarily store bounded text from the current week and, when needed, the newest just-closed week. Each weekly source contains no more than 100 entry excerpts, no more than 400 characters per excerpt and 4,000 characters total, plus the selected portrait style, up to 500 characters of visual direction, and an opaque identifier for that device’s local archive. It is not a copy of your journal archive, is not the source of truth for your journal, and is never used to merge or sync journals across devices.
To prepare a daily devotional while the app is closed, supported versions send your time zone, Bible translation, custom instructions (up to 500 characters), and a bounded snapshot of committed journal writing: up to 2,000 characters from one recent entry and up to four relevant excerpts of 220 characters each. Drafts, generated responses and conversations are excluded. Dated excerpts older than 30 days are not used. The last synchronized device supplies this preparation context; it does not synchronize your journal archive. Daily generation uses OpenAI, with Scripture resolved from our vetted Bible text. Completed devotionals and their dates and translation are saved to your account so they can be recovered on another device, and downloaded readings remain available locally. The preparation snapshot expires after 30 days without a new sync. Each job's private source and vetted grounding text are erased on completion or permanent failure, with a two-day expiry backstop. Account deletion erases the daily records and preparation context. We attempt to cancel unfinished provider work; a short-lived queue may retain only opaque provider request identifiers for that purpose.
When you manually ask Nemora to paint a week, the service temporarily keeps that same bounded portrait envelope so an accepted request can retry and finish after the app closes. This manual retry source is tied to one account and one portrait job, is not exposed as journal history or cross-device sync, and has a maximum lifetime of six hours.
Feature inputs and preferences. When you request a response, conversation, reflection, portrait, or narration, we process the journal text and settings needed for that request. This can include custom instructions, portrait direction, response depth, Bible translation, voice, appearance, playback, and reminder choices. Anything you choose to write may include sensitive information, including religious beliefs.
Service data. We keep account-linked usage and quota records, notification delivery records when alerts are enabled, and limited diagnostic and security metadata needed to operate the service. To make saved responses, entry conversations, reflections, and portraits resumable, our server keeps account-scoped request identifiers, processing status, generated response output, and derived portrait metadata. Portrait job records do not contain raw journal prompts; separate service-only bounded sources exist only while automatic or manually requested portrait curation still needs the week excerpts.
While a saved response is being created, its service-only job temporarily holds your selected entry (up to 8,000 characters), up to four dated memory excerpts (up to 220 characters each), optional custom instructions (up to 500 characters), response depth and translation, and the vetted passage coordinates and one or two exact verses needed for grounding. On success, failure, or cancellation, Nemora removes that request and grounding payload. A successful job retains only the generated prose, vetted passage coordinates and translation, a Scripture insertion position, and operation metadata—not your entry, memory excerpts, custom instructions, or verse text.
While an entry-conversation reply is being created, its service-only job temporarily holds your selected entry (up to 8,000 characters), the current question and no more than six complete recent question-and-answer exchanges (up to 1,500 characters per message), up to four dated memory excerpts (up to 220 characters each), optional custom instructions (up to 500 characters), response depth and translation. It also holds the app-owned prompt and output schema needed to replay the same accepted operation safely. Nemora removes that frozen request on success, failure, or cancellation; a database backstop fails and removes any still-active frozen request after 24 hours. A successful job retains the generated reply and operation metadata, not your selected entry, conversation context, memory excerpts, or custom instructions.
Reflections use that same durable journal-generation service and its internal
journal_chat transport. For a reflection request, the service-only job instead freezes your
selected entry, its saved response, up to four dated memory excerpts, optional custom instructions,
response depth and translation, and the app-owned prompt and schema needed to create it. The
frozen source follows the same terminal cleanup and 24-hour active-job backstop described above. A
successful terminal job may retain the generated reflection text and
operation metadata, not your entry, saved response, memory excerpts, or custom instructions. After
validation, the app attaches that output to your journal entry as a typed artifact rather than a
chat turn. It is not added to semantic memory.
Subscription status. Apple processes iOS payments. We receive signed purchase information such as product, original transaction, account binding, environment, expiration, and revocation status so the service can provide the access you bought. We do not receive your card number.
How we use journal content
- To store, search, and display your journal.
- To select relevant context from your past entries when a later response benefits from it.
- To generate Scripture-rooted responses and conversations about the entry you chose.
- To create reflections attached to the entry you chose.
- To create weekly portraits and captions from the entries in that week.
- To generate narration when you ask Nemora to read something aloud.
In the current journal, semantic matching happens on your device with Apple’s Natural Language framework. Vectors derived from committed entry text are held in memory for the app session and rebuilt from the protected local archive; they are not saved to your account or sent to an embedding provider. When a new saved response benefits from continuity, Nemora may send the current entry and up to four matched excerpts from earlier entries to Anthropic. A previously accepted response can finish with the provider assigned when it began. For an entry conversation or entry-owned reflection, Nemora may send the same bounded entry and memory context to OpenAI. A reflection request also includes that entry's saved response; a conversation request may include a bounded portion of that entry’s prior conversation. Generated response prose and reflection artifacts are not indexed as memory.
AI-generated response prose is not treated as a factual memory about you. Scripture shown in the app is rendered from vetted translation data rather than authored by the model.
AI and service providers
Nemora uses service providers to perform specific jobs on our behalf:
- Supabase provides authentication, account-backed database records, server functions, and storage used by supported features.
- OpenAI processes bounded journal context for entry conversations, reflections, and weekly portrait briefs and images through its API. It may also finish saved-response jobs previously accepted on the OpenAI route.
- Anthropic processes bounded journal context for passage selection and pastoral prose in new saved responses through its API.
- ElevenLabs receives the text and voice choice needed to create narration.
- Apple provides Sign in with Apple, StoreKit subscription processing, notifications, on-device Natural Language processing, and the system share sheet.
- Google provides the OAuth identity flow used when you choose Continue with Google.
For weekly portraits in the current journal, bounded journal excerpts are used in the first OpenAI step to derive a visual brief; the image-generation step receives that derived prompt rather than the raw entries. Before a newly generated portrait is uploaded, Nemora encrypts the PNG with AES-256-GCM under a random key held only by the service. The encrypted object uses an opaque random storage namespace that does not contain the account identifier. The signed-in app retrieves it through an authenticated decryption service, then saves it into the protected journal archive on the device; Nemora does not issue a signed download link to that ciphertext. Completed plaintext portraits created by supported earlier versions may still be recovered through a short-lived signed link.
OpenAI and Anthropic state that commercial API inputs and outputs are not used to train their general models by default. Anthropic, OpenAI, and ElevenLabs may process data under their applicable business terms, including for security, abuse prevention, and service operation.
Advertising and tracking
On Nemora’s public marketing pages (the homepage and the pricing, FAQ, how-it-works, personalized-devotional-app, and scripture-integrity pages), Meta Pixel measures page visits and taps on links to Nemora’s App Store listing. It may receive the public page URL and ordinary browser and device information. The Pixel is never loaded on journal-entry, conversation, reflection, or portrait share pages, or on the privacy, terms, or support pages, and it does not receive share contents or unguessable URLs. Nemora also does not load the Pixel when the browser sends a Global Privacy Control signal.
When the Nemora app launches, the Meta App Events SDK starts in a limited mode that sends no advertising identifier, and its app-event payloads carry no account, email, transaction, or journal content. The first time the plan screen appears, the Nemora app asks once through Apple’s App Tracking Transparency prompt whether Nemora may use app activity to measure and improve its advertising. Your answer never changes access to the app. Only an explicit “Allow” enables the advertising identifier: if you decline or your device restricts tracking, Nemora does not allow Meta to access the IDFA or another advertising identifier, and it may still send privacy-limited app events without the IDFA for Meta’s aggregated measurement. If you allow tracking, Meta may use the IDFA with those events to measure and optimize Nemora ads across companies’ apps and websites.
The only direct Meta events Nemora sends are app activation, completed registration, privacy-bounded onboarding stages, verified trial start, and verified paid-subscription start. Meta may receive the event name and time, ordinary app/device and network context and, for a verified trial or subscription, its price and currency. Nemora disables Meta’s automatic event, purchase, and advanced-matching features. It does not send Meta your name, email, account identifier, product or transaction identifier, journal text, custom instructions, Scripture, conversations, reflections, or portraits.
For every reader, Nemora also registers numeric install, completed-registration, trial-start, and paid-subscription milestones with Apple’s privacy-preserving attribution system. Apple may send a signed, crowd-anonymous postback to the ad network whose impression won attribution. Meta may use those aggregate postbacks to measure and optimize Nemora’s advertising.
What we do not do
- We do not sell your journal content.
- We do not send journal text to advertisers or use it to target advertising.
- We do not ask a model to invent, quote, or rewrite the Scripture text displayed in a response.
Sharing
When you choose Share for a journal entry, its conversation, a reflection, or a weekly portrait, Nemora creates an unguessable public website link. Anyone with the link can open and forward its immutable snapshot without signing in. Each action publishes only the item named in its confirmation:
- An entry link contains the entry text, its saved Nemora response, and any displayed vetted Scripture passage. It excludes the conversation and attached reflections.
- A conversation link contains only complete, settled reader-and-Nemora exchanges. It excludes the entry, saved response, drafts, failed or pending turns, reflections, and reflection focuses.
- A reflection link contains its settled body and a bounded title copied from its opening. The full text is readable on the website. The snapshot excludes your optional focus, private voice settings, and the journal content that shaped the reflection.
- A portrait link contains only a web-sized copy of the portrait, its week, selected medium, and caption.
When someone chooses Listen on a current shared reading, its already-published text is sent to ElevenLabs using Nemora’s default narration voice. Nemora stores the resulting audio and reading timings with that share so later listeners can reuse them. This audio is accessible only through the active link and is deleted with the share when it expires or is revoked. No source journal, private focus, or memory is added to the narration request. Playback never starts automatically.
Every journal share also excludes semantic memories, custom instructions, generation state, other entries, and account identity. A reflection’s bounded public title, the opening lines of an entry or reflection, the first shared conversation exchange, or the portrait itself may appear in the link preview created by a messaging or social service. Those third parties may retain a preview they already fetched in caches outside Nemora’s control, even after its Nemora link ends. These journal-artifact and portrait links expire automatically after 30 days and their expired snapshots are removed by a daily cleanup. Deleting a whole journal entry ends its entry link and every conversation/reflection link belonging to that entry. Deleting only a conversation or reflection ends every link for that exact item, and account deletion removes all shares sooner. Choosing Save to Photos writes the selected portrait to your Apple photo library and does not create a public link.
Supported earlier journey and devotional features can also create an unguessable public link. A journey link contains its published route, settings, day titles, and reading references, but excludes the original request, progress, check-ins, semantic memories, custom instructions, generated daily prose, and account identity. A devotional link contains the finished prose and visible prompts chosen for publication. These links do not expire automatically. Revoke a link in the app where available, delete its source journey, delete the account, or contact support for help ending it.
Retention and deletion
Temporary on-device semantic vectors last only for the app session. Current journal entries remain until you delete them, successfully delete the account, or remove the app. Saved portrait files remain until Nemora replaces or removes them, you successfully delete the account, or you remove the app, subject to any device backup you control. Legacy account-backed records and image sources remain after import; deleting an imported local entry does not delete its older server source.
When you use Listen inside the app, Nemora reuses available narration or sends the selected text and voice to ElevenLabs. Audio and timing data may be cached on your device. Exact Bible chapter readings from the bundled translations are also stored as shared narration assets, so readers using the same voice and text can reuse one generation. These Bible assets contain no journal writing or reader identifiers and remain available independently of any account. Private journal and reflection narration is not newly written to server file storage. Shared-link narration follows the separate sharing rules above. Deleting a journal entry or one of its attached reflections clears the regenerable device narration cache before the writing is removed. Because that cache is unindexed, this may also clear cached narration for retained writing, which can generate and cache narration again when it is played. Earlier app versions may have created private account-scoped server narration caches; those legacy copies remain covered by the retention and account-deletion rules below. The device cache can be reclaimed by iOS and is cleared after a successful in-app account deletion. Signing out alone does not delete it.
Resumable saved-response, entry-conversation, and reflection jobs can retain generated output and processing metadata as terminal job results until account deletion; Nemora also attempts to prune terminal records older than 90 days during later generation requests. Completed portrait job metadata and the private server copy of its encrypted image remain so an interrupted device can recover the result, and are retained until account deletion unless Nemora removes them earlier. Nemora conservatively removes old encrypted portrait objects that are not referenced by a completed job.
An automatic weekly portrait source normally exists only until the first portrait stage commits a validated, derived image prompt; that same database transaction deletes the entry excerpts before image generation begins. Turning weekly portraits off, replacing the active local-archive scope, or successfully deleting the account deletes any unconsumed weekly sources immediately. Nemora keeps at most the two newest unlinked automatic week sources for an active local archive. As a backstop, each source expires 14 days and 4 hours after the exact reader-local Sunday boundary that closed the week, and the hourly recovery worker removes expired sources.
A manual portrait retry source is deleted in the same transaction that commits its validated, derived image prompt, and is also deleted on cancellation, permanent failure, exhausted retries, account deletion, or its six-hour expiry. The derived image prompt and completed private image follow the portrait-job retention described above.
If you enable alerts, Apple provides an APNs device token. We store it with an opaque installation identifier and your account to deliver generic service-completion alerts in features that support them; those alerts do not contain journal text. We attempt to unregister the token on sign-out and remove its server record on account deletion or when Apple reports that it is invalid. A scheduled journal reminder is created by iOS on your device; supported versions may also store the chosen reminder time with account settings.
To delete the account, open Profile, find Account, and choose Delete account. After confirmation succeeds, Nemora deletes the Supabase authentication account and account-linked database records, including public shares, push tokens, entitlement and quota records. It also deletes the current journal archive, including conversations and attached reflections, plus saved portraits, the semantic session cache, and narration device cache in that account’s space on the device. The account-deletion service cancels in-progress journal jobs and removes account-scoped job records, current and legacy private portrait objects, and private narration metadata and audio. For encrypted portraits, deletion erases the service-held decryption keys before sweeping storage. Any ciphertext left by an interrupted or late upload is therefore unreadable, and a durable opaque inventory allows the storage sweep to resume. Deletion is irreversible.
Deleting your Nemora account does not cancel an Apple subscription. Apple will continue billing until you cancel it in Settings → your name → Subscriptions. Cancel before deleting the account if you do not want it to renew.
You may contact us through our support page for access, deletion, or other privacy requests. Depending on where you live, you may have additional privacy rights.
Subscriptions
Nemora offers monthly and annual subscriptions. Subscriptions are sold and processed by Apple, and we never receive your payment-card details. Manage or cancel a subscription in your Apple Account settings; Apple’s billing and refund policies apply.
Children
Nemora is not directed to children under 13, and we do not knowingly collect personal information from them. If you believe a child has given us personal information, contact us and we will delete it.
Changes
If this policy changes, we will update the effective date above and post the revised policy at this URL. Material changes will be surfaced in the app.