JOMATS FZCO
Privacy Policy
HolyNote is designed so your personal library stays on your device. Information is sent to our service only when a feature needs online processing, such as creating an AI note or Scripture study.
- HolyNote currently works without a user account or cloud note sync.
- Your saved notes, recordings, images, chat history, reading preferences, and Today progress are stored locally on your device.
- Audio, reviewed Scripture text, YouTube links, and questions are sent only when you request an online AI feature.
- Religious reflections, prayers, and sermons can reveal sensitive beliefs. Please share only content you are comfortable processing online.
- We do not sell personal data or show third-party advertising.
1. Who we are
HolyNote and its related services (together, “HolyNote” or the “Service”) are provided by JOMATS FZCO, company number DSO-FZCO-14516, at Dubai Silicon Oasis, DDP, Building A2, Dubai, United Arab Emirates (“we”, “us”, or “our”). JOMATS FZCO is the controller of personal data described in this policy.
For privacy questions or requests, email support@holynote.app and include “HolyNote Privacy” in the subject line, or use the details on our Support page.
2. Information stored on your device
HolyNote stores the following information locally so the app can work:
- notes, folders, transcripts, generated summaries, Scripture studies, flashcards, and reflections;
- recorded or imported audio and any images you attach to a note;
- Bible chat history, highlights, personal verse notes, reading position, and display preferences;
- Today completion, streak progress, onboarding choices, and app settings.
This local information is not automatically synced to a HolyNote account. You can delete notes and conversations inside the app. Removing the app or erasing its data generally removes local information, although copies may remain in device backups controlled by you or Apple.
3. Information processed online
| Information | When and why it is processed | Typical handling |
|---|---|---|
| Recorded or imported audio and recording notes you enter | When you ask HolyNote to transcribe a sermon or recording and create a structured note. If you type notes during that recording, those notes are sent as context for the note you requested. | Uploaded over encrypted HTTPS and used for the requested processing. Audio is temporarily stored and then normally removed after the job finishes. |
| YouTube link and derived audio or captions | When you ask HolyNote to create a note from content you are authorized to process. | The URL is sent to our server. Temporary media or captions are used to prepare the requested transcript and note, then normally removed after processing. |
| Reviewed Scripture text and reference | When you confirm a scanned passage and request an AI study. | Text recognition begins on your device. The reviewed text, not the scan photo, is sent after you choose “Use this passage.” |
| Questions and conversation context | When you ask the note assistant or Bible chat a question. | The question and relevant note or Scripture context are sent to create the requested answer. |
| Technical and security data | When the app connects to our service, to deliver requests, verify paid access, limit abuse, diagnose failures, and protect the Service. | May include a random installation identifier, IP address, request identifier, date and time, requested route, response status, app or device technical information, and error metadata. The installation identifier links an AI request to its Adapty subscription profile and to jobs created by that installation. Request bodies and authorization credentials are redacted from application logs. |
HolyNote does not need your name, email, contact list, precise location, or Apple account credentials to provide its current core features.
4. Camera, microphone, photos, and notifications
We request device permission only when needed for a feature you choose:
- Microphone: to record a sermon or other audio you choose to capture.
- Camera: to scan a Bible passage or add a photo to a note.
- Photo library or Files: to select an image or audio file you choose to import.
- Notifications: for optional reminders or completion prompts you enable.
You can change these permissions in iOS Settings. Denying a permission affects only the related feature.
5. AI processing and sensitive content
HolyNote uses OpenAI API services to transcribe audio and generate requested notes, studies, and answers. We configure supported Responses API requests with storage disabled. OpenAI states that API inputs and outputs are not used to train its models by default unless the API customer opts in. OpenAI may retain API content in abuse-monitoring logs for up to 30 days unless a different approved retention control applies or longer retention is legally required. See OpenAI’s API privacy information.
Sermons, prayer requests, religious beliefs, names, voices, and personal stories can be sensitive. Avoid including information you do not have the right to share. AI output may be inaccurate or incomplete; verify Scripture wording and important conclusions before relying on or sharing them.
6. Service providers
Depending on the app version and the features you use, we may use the following processors:
- OpenAI — audio transcription and generation of requested AI notes, studies, and answers.
- Apple — App Store distribution, payments, subscription management, device permissions, and optional notification services.
- Adapty — subscription status, paywall delivery, purchase analytics, and an anonymous app profile. In HolyNote’s current iOS configuration, collection of the Apple advertising identifier (IDFA) and IP address by the Adapty SDK is disabled. Adapty may process purchase history, app-instance or other device identifiers, device model, operating system, language, and paywall interactions. See Adapty’s End-Users Privacy Policy.
- AppsFlyer — installation attribution and measurement of selected app or subscription events. Depending on configuration and consent, it may process an AppsFlyer identifier, IP address, device and app information, install source, and event data. See AppsFlyer’s Privacy Policy.
- GitHub Pages — hosts this public policy and support website and may process standard web request data under GitHub’s policies.
We do not intentionally send the content of your sermons, prayers, Scripture scans, notes, or AI questions to Adapty or AppsFlyer. HolyNote uses the same pseudonymous installation identifier as the Adapty customer identifier so our server can verify Premium access; the signed credential itself is not sent to AppsFlyer or Adapty.
7. Analytics, attribution, and tracking
HolyNote does not show third-party ads or sell personal data. The current iOS build may use AppsFlyer to measure installations and selected product or subscription events, but it does not access Apple’s advertising identifier (IDFA), enable Apple-defined cross-app tracking, or request permission through App Tracking Transparency (ATT). If a future version proposes to use IDFA or other Apple-defined tracking, we will update this policy and request permission before enabling it where required.
8. Subscriptions and purchases
Apple processes App Store payments and manages your Apple subscription account. We do not receive your full payment-card number. We and Adapty may receive purchase identifiers, product, price, currency, transaction timing, renewal, trial, refund, and subscription-status information so we can provide paid access, restore purchases, prevent fraud, and understand subscription performance.
9. Retention and deletion
- Local content: remains on your device until you delete it, erase app data, or remove it through device management or backup controls.
- Temporary media: is normally deleted from HolyNote’s processing server when the job succeeds, fails, or is cancelled. A system crash may delay cleanup until operational maintenance.
- AI job transcripts and results: remain in the current server’s temporary in-memory job store for no more than 24 hours by default, or until the service restarts.
- Provider data: is retained under the service provider’s policy, including OpenAI’s default abuse-monitoring period described above and Apple, Adapty, or AppsFlyer records needed for purchases, attribution, fraud prevention, and legal compliance.
- Security logs: are kept only as long as reasonably necessary for security, reliability, abuse prevention, dispute handling, and legal obligations.
Because HolyNote currently has no user account, we may not be able to associate an anonymous server job or provider profile with your identity after it expires. For a privacy request, provide only the minimum identifiers needed to locate relevant records. Do not email sermon audio, prayer text, or other sensitive content.
10. Legal bases
Where laws such as the GDPR or UK GDPR apply, we process information as necessary to provide the features you request and perform our agreement with you; with consent for optional permissions or tracking where required; for legitimate interests such as security, reliability, fraud prevention, and service improvement; and to comply with legal obligations.
11. International transfers
JOMATS FZCO is based in the United Arab Emirates, and our providers may process information in the United States and other countries. Where required, we rely on lawful transfer mechanisms and contractual safeguards provided by our processors.
12. Your choices and rights
Depending on where you live, you may have rights to access, correct, delete, restrict, object to, or obtain a copy of personal data, withdraw consent, and complain to a data-protection authority. You may also:
- delete local notes and chats in HolyNote;
- revoke camera, microphone, photo, or notification permission in iOS Settings;
- manage or cancel subscriptions in your Apple account;
- contact us for a privacy request at support@holynote.app.
We will not discriminate against you for exercising a privacy right.
13. Children
HolyNote is not directed to children under 13, or a higher minimum age where required by local law. We do not knowingly collect personal information from a child without appropriate authorization. If you believe a child has provided information, contact us so we can review and delete it where applicable.
14. Security
We use safeguards such as encrypted HTTPS transport, secret separation, access controls, request limits, restricted temporary storage, redacted application logs, and deletion routines. No service can guarantee absolute security, so please avoid uploading information that is unnecessary for the feature you request.
15. Changes to this policy
We may update this policy when HolyNote, its providers, or legal requirements change. We will update the date above and provide additional notice when required. Material changes apply prospectively unless the law permits otherwise.
16. Contact
JOMATS FZCO
Dubai Silicon Oasis, DDP, Building A2
Dubai, United Arab Emirates
Company number: DSO-FZCO-14516
Telephone: +971 4 228 52 85
Email: support@holynote.app (subject: HolyNote Privacy)