Information We Collect

How We Use Your Information

AI and Automated Processing

Data Sharing and Third-Party Services

Cookies and Tracking Technologies

Data Protection and Security

Data Retention

International Data Transfers

Your Rights

Children's Privacy

Changes to This Policy

Contact Information

Privacy Policy

  1. Introduction

Welcome to Manna ("we," "us," or "our"). Manna is an AI-powered Bible devotional service that provides daily Scripture readings, reflections, and conversational Bible study experiences.

This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our website and services (collectively, the "Service"). Please read this policy carefully. By accessing or using the Service, you agree to the terms of this Privacy Policy.

If you do not agree with the terms of this Privacy Policy, please do not access or use the Service.

  1. Information We Collect

2.1 Information You Provide Directly

  • Account Information: When you create an account, we collect your email address, display name, and password. If you sign up using Google, we receive your name, email address, and profile picture from Google.

  • Profile Preferences: Bible version preference, timezone, daily devotional delivery time, and voice settings for text-to-speech audio.

  • Onboarding Data: How you heard about Manna and your initial preferences.

  • Payment Information: When you subscribe to a paid plan, your payment is processed by Lemon Squeezy. We do not directly store your credit card number or full payment details. We receive transaction identifiers, subscription status, and plan details from Lemon Squeezy.

  • Partner Information: If you use our Duo plan, you may provide the email address of your partner to send an invitation.

  • Communications: Any messages or feedback you send to us directly.

2.2 Information Generated Through Your Use of the Service

  • Conversation Data: Messages you send to and receive from our AI-powered chat feature, including Scripture references discussed.

  • Devotional History: Your Daily Bread reading history and engagement.

  • Streak Data: Your daily visit records and consecutive reading streaks.

  • Newsletter Preferences: Your email subscription preferences and interaction with our newsletters.

2.3 Information Collected Automatically

  • Log Data: IP address, browser type, operating system, referring URLs, pages visited, and timestamps.

  • Device Information: Device type, screen resolution, and language settings.

  • Cookies and Similar Technologies: Session tokens for authentication and preferences. See Section 6 for details.

  1. How We Use Your Information

We use the information we collect to:

  • Provide and maintain the Service, including generating personalized Daily Bread devotionals and AI-powered conversations.

  • Process your subscription and manage your account, billing, and plan features.

  • Personalize your experience, such as delivering content in your preferred Bible version, language, and voice settings.

  • Send you communications, including daily devotional emails (if opted in), service updates, and account notifications.

  • Improve the Service by analyzing usage patterns, identifying issues, and developing new features.

  • Ensure security by detecting and preventing fraud, abuse, or unauthorized access.

  • Comply with legal obligations and enforce our terms of service.

  1. AI and Automated Processing

Manna uses artificial intelligence to generate devotional content and provide conversational Bible study. Here is how AI interacts with your data:

  • Content Generation: We use OpenAI's language models to generate Daily Bread devotionals (Context, Reflection, Question, and Prayer) based on selected Scripture passages. This content generation does not use your personal data.

  • Chat Conversations: When you use the chat feature, your messages are sent to OpenAI's API to generate contextual, Scripture-based responses. Your conversation history within a session may be included for context.

  • Text-to-Speech: We use OpenAI's text-to-speech service to generate audio versions of devotional content. No personal data is included in these requests.

  • Data Processing by AI Providers: Messages processed by OpenAI are subject to OpenAI's usage policies. OpenAI does not use data submitted through our API to train their models.

  • No Automated Decision-Making: We do not use AI to make automated decisions that produce legal or similarly significant effects on you.

  1. Data Sharing and Third-Party Services

We do not sell your personal information. We share your data only with the following categories of third-party service providers, and only as necessary to operate the Service:

Service Provider / Purpose / Data Shared

  1. Supabase / Authentication, database hosting / Account data, user content, preferences

  2. OpenAI / AI content generation, chat, text-to-speech / Chat messages, Scripture content (no personal identifiers)

  3. Lemon Squeezy / Payment processing, subscription management / Email, subscription plan, billing details

  4. Vercel / Website hosting and delivery / Log data, IP address

We may also disclose your information if required by law, legal process, or governmental request, or if we believe disclosure is necessary to protect our rights, your safety, or the safety of others.

  1. Cookies and Tracking Technologies

We use the following cookies and similar technologies:

  • Authentication Cookies: Essential cookies managed by Supabase to maintain your login session. These are strictly necessary for the Service to function.

  • Preference Cookies: Store your settings such as Bible version and display preferences.

We do not use third-party advertising cookies or cross-site tracking technologies. We do not use analytics tracking tools that share data with advertisers.

You can configure your browser to refuse cookies, but this may prevent you from using certain features of the Service.

  1. Data Protection and Security

We implement appropriate technical and organizational measures to protect your personal information, including:

  • Encryption: All data is transmitted using TLS/SSL encryption (HTTPS).

  • Access Controls: Database access is restricted through Row Level Security (RLS) policies, ensuring users can only access their own data.

  • Authentication Security: Passwords are hashed and stored securely through Supabase Auth. We never store passwords in plain text.

  • Infrastructure Security: Our hosting providers (Supabase, Vercel) maintain SOC 2 compliance and implement industry-standard security practices.

  • Minimal Data Sharing: When sending data to AI providers, we strip unnecessary personal identifiers.

While we strive to protect your personal information, no method of transmission over the Internet or electronic storage is 100% secure. We cannot guarantee absolute security.

  1. Data Retention

We retain your data as follows:

  • Account Data: Retained for as long as your account is active. Upon account deletion, your personal data will be deleted within 30 days, except where retention is required by law.

  • Conversation History: Stored for as long as your account is active. You may delete individual conversations at any time.

  • Daily Bread History: Your devotional reading history is retained for the lifetime of your account to support the history and streak features.

  • Payment Records: Transaction records are retained as required by applicable tax and financial regulations (typically 7 years).

  • Backup Data: Backups containing your data may persist for up to 90 days after deletion before being permanently removed.

  1. International Data Transfers

Manna is operated from South Korea, and our service providers are located in the United States and other countries. If you access the Service from outside the United States, your information may be transferred to, stored, and processed in the United States or other jurisdictions where our service providers operate.

By using the Service, you consent to the transfer of your information to countries outside your country of residence, which may have different data protection rules. We ensure that any international data transfers are conducted with appropriate safeguards in accordance with applicable data protection laws.

  1. . Your Rights

Depending on your location, you may have the following rights regarding your personal information:

  • Access: Request a copy of the personal data we hold about you.

  • Correction: Request correction of inaccurate or incomplete data.

  • Deletion: Request deletion of your personal data, subject to legal retention requirements.

  • Portability: Request your data in a structured, commonly used, and machine-readable format.

  • Objection: Object to the processing of your personal data for certain purposes.

  • Withdrawal of Consent: Withdraw consent for data processing where consent is the legal basis.

  • Restriction: Request restriction of processing of your personal data.

For California Residents (CCPA/CPRA)

California residents have additional rights under the California Consumer Privacy Act:

  • The right to know what personal information is collected, used, shared, or sold.

  • The right to request deletion of personal information.

  • The right to opt out of the sale of personal information. We do not sell personal information.

  • The right to non-discrimination for exercising your privacy rights.

For European Residents (GDPR)

If you are in the European Economic Area (EEA), our legal bases for processing your data include: performance of our contract with you, your consent, our legitimate interests, and compliance with legal obligations.

To exercise any of these rights, please contact us at the email address provided in Section 13.

11. Children's Privacy

The Service is not intended for children under the age of 13 (or 16 in the European Economic Area). We do not knowingly collect personal information from children under these ages. If we become aware that we have collected personal data from a child under the applicable age, we will take steps to delete that information promptly.

If you are a parent or guardian and believe your child has provided us with personal information, please contact us immediately.

12. Changes to This Policy

The Service is not intended for children under the age of 13 (or 16 in the European Economic Area). We do not knowingly collect personal information from children under these ages. If we become aware that we have collected personal data from a child under the applicable age, we will take steps to delete that information promptly.

If you are a parent or guardian and believe your child has provided us with personal information, please contact us immediately.

13. Contact Information

If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us at:

Manna Email: [your-email@example.com]

We will respond to your inquiry within 30 days.

Last Updated: FEB 18, 2026