Privacy Policy
Waypoint is a Bible-reading app built to respect your privacy. It shows no ads, uses no third-party analytics or tracking, and never sells your data. This page explains what it stores, why, and how to delete it.
Who runs Waypoint
Waypoint is independently operated by one developer. The service and its database run on a private server rented from Google Cloud, administered solely by the developer. Your data is not handed to a third-party platform to use for its own purposes. You can reach us any time at [email protected].
What we collect
Only what the app needs to work:
- Account details: if you create an account, your email address and a password (stored only as a salted, hashed value we cannot read).
- Display name and friend code: a name shown on leaderboards and a short code so friends can add you.
- Reading progress: the days you mark complete and rest days you take, so your streak, points, and plans follow you between devices.
- Friend connections: the friend requests you send and accept.
- Device information: a per-device identifier and platform (Android/iOS) to allow you to stay logged in.
- Notification token: if you turn on reminders, the token your phone's operating system issues so notifications can reach that device. It is deleted when you turn reminders off, sign out, or delete your account.
- Support messages: if you contact support from within the app, the message and the app version and platform you sent it from.
Waypoint does not collect your location, contacts, advertising identifiers, or usage analytics.
How we use it
Your data is used solely to provide the app: to sync your reading progress across your devices, compute your streaks and points, show leaderboards among you and your friends, deliver the daily reminders you enable, and answer support requests. It is not used for advertising or profiling.
How it's shared
We do not sell or rent your data, and we do not share it with third parties for their own purposes. Limited data is handled by service providers only to run the app:
- Email delivery: a transactional email provider sends password-reset emails and relays your support messages. It receives only what's needed to deliver that mail.
- Network delivery: a content-delivery/tunnel provider carries encrypted traffic between your device and the server.
- Notification delivery: Firebase Cloud Messaging, run by Google, delivers reminders and alerts to your device. It receives your notification token and the contents of the notification itself, because that is what it has to hand to your phone. It receives nothing else about you.
- Hosting: Google Cloud provides the server the app runs on. It holds the encrypted disk the database sits on and does not process your data for its own purposes.
Your display name, points, and streaks are visible to people you've added as friends (and on shared leaderboards), because that's the point of those features.
Reminders and notifications
Reminders come two ways. Ones your device schedules for itself never leave your phone. Others are sent from the server through Firebase Cloud Messaging: the daily verse, and alerts such as a friend request. Those pass through Google's delivery service on the way to you, so the text of the notification is visible to it in transit.
You control all of it in the app's settings and in your device's notification settings. Turning reminders off deletes the token that lets the server reach your device.
Data retention and deletion
We keep your data for as long as your account exists. You can permanently delete your account and all associated data at any time:
- In the app, open Account and choose Delete account. You will be asked for your password to confirm it is you.
- On the web, use the Delete account page.
- Either way, deletion removes your account, reading history, stats, friendships, enrolments, notification tokens, and device records from the database. It is immediate and cannot be undone.
Children
Waypoint is not directed to children under 13, and we do not knowingly collect data from them. If you believe a child has provided us data, contact us and we'll remove it.
Security
Passwords are stored using industry-standard salted hashing (Argon2id) and are never stored or transmitted in plain text. Traffic between the app and the server is encrypted in transit.
Changes to this policy
If this policy changes, we'll update this page and the "last updated" date above. Continued use of the app after a change means you accept the updated policy.
Contact
Questions about your privacy or this policy? Email [email protected].