Effective Date: August 31, 2026 Last Updated: August 31, 2026 Version: 2.0
Theo (also marketed as BibleLock) is an iOS application developed and operated by Landslide Studios LLC, a limited liability company based in North Carolina, United States. For the purposes of the EU and UK General Data Protection Regulation, Landslide Studios LLC is the data controller for the personal data described in this Policy.
| Privacy contact | tommy@landslidestudios.com |
| Postal address | Available on request to the address above |
| App | Theo | Bible Study Lock — App Store ID 6760088556 |
| Website | https://theo.app |
We do not currently employ a Data Protection Officer. Appointment is not mandatory for us under Article 37 GDPR because we are not a public authority, our core activities do not consist of large-scale regular and systematic monitoring, and our processing of special category data is not large scale within the meaning of that Article. If that changes, we will appoint one and update this Policy.
How to complain. You can raise a privacy complaint directly with us at the address above, and we will acknowledge it within 30 days. Section 12 lists the regulator for your region where one applies, and you may complain to them directly at any time without coming to us first.
This Policy applies to everyone who uses Theo, anywhere in the world. It describes what we collect, why, who else sees it, how long we keep it, and what you can require us to do.
The short version:
Collected during onboarding and through everyday use, held in iOS local storage. Not transmitted to us, except where Section 3.3 (AI) or Section 3.2 (account sync) applies:
Blocked app selections are a special case. They are held as opaque tokens issued by Apple's FamilyControls framework. The tokens are meaningless outside your device, cannot be resolved back to app names by us, and are technically incapable of being transmitted to our servers. We never learn which apps you block.
You can erase all on-device data at any time from Settings → Delete My Data, or by deleting the app.
If you sign in with Apple or Google, we store on Supabase (PostgreSQL, United States):
Every row is protected by PostgreSQL Row-Level Security, enforced in the database rather than in app code. You can read your own rows and rows that someone has deliberately shared with you. Nothing else.
| Level | Who can read it | Sent to an AI provider? |
|---|---|---|
| Private (default) | You only | No |
| Theo can read | You, and Theo during your conversations | Yes — text is embedded by OpenAI; matching excerpts go to Anthropic as context |
| Shared to a group | You and members of that group | No |
The level is yours to set and change at any time. Lowering it stops future processing; Section 9 covers deletion of what already exists.
When you send a message to Theo, our AWS Lambda proxy transmits to Anthropic:
Separately, when you opt a journal entry into "Theo can read," its text is sent to OpenAI once to generate an embedding. OpenAI is not involved in generating Theo's replies.
We never send your email address, surname, payment details, location, Private journal entries, or your blocked-app selections.
We do not retain the raw text of your chat messages on our servers. The Lambda receives your message, forwards it, streams the reply back, and discards it. We do store summarised conversation memories in AWS DynamoDB so Theo remembers context between sessions; these expire automatically (Section 9).
Neither Anthropic nor OpenAI trains models on this data. Both operate under commercial API terms that exclude API traffic from model training.
Neither is used for advertising. Theo contains no advertising
SDKs, performs no tracking as Apple defines
it, and does not use the App Tracking Transparency framework
because it has nothing to ask for. Our privacy manifest declares
NSPrivacyTracking = false.
If you submit feedback: the category and message you write, app version and build, device model and iOS version, and your username or anonymous analytics ID. Stored in Supabase.
If you join groups or add friends, your username, display name, and
streak rank are visible to those people. If your church enables a public
web leaderboard at theo.app/c/<slug>
and you have "discoverable by username" switched on,
that information may be publicly visible. Both conditions must be true;
the setting is off by default and lives in Settings →
Privacy.
Theo is not offered in the EEA, UK, or Switzerland (Section 12.1). We nonetheless map every purpose to a GDPR Article 6 basis, because it is the clearest way to show what we do and why, and because it holds us to the stricter standard everywhere:
| Purpose | Data | Legal basis |
|---|---|---|
| Provide the core app | Profile, progress, preferences | Contract — Art. 6(1)(b) |
| Sync your account across devices | Account data (§3.2) | Contract — Art. 6(1)(b) |
| Generate AI replies | Message, first name, denomination, journal excerpts | Consent — Art. 6(1)(a), plus explicit consent under Art. 9(2)(a) for the religious element |
| Personalise Scripture suggestions | Spiritual profile, progress | Consent — Art. 6(1)(a) |
| Social and leaderboard features | Username, display name, streak | Consent — Art. 6(1)(a) |
| Process subscriptions | Subscription status | Contract — Art. 6(1)(b) |
| Send push notifications | APNs token | Consent — Art. 6(1)(a) |
| Product analytics | Usage events, person properties | Consent — Art. 6(1)(a) |
| Crash diagnostics | Crash reports | Legitimate interests — Art. 6(1)(f): keeping the app functional. Balancing test on file. |
| Security, abuse prevention, enforcing our Terms | Account and usage data | Legitimate interests — Art. 6(1)(f) |
| Comply with legal obligations | As required | Legal obligation — Art. 6(1)(c) |
Where we rely on consent, you may withdraw it at any time without affecting the lawfulness of what came before. Where we rely on legitimate interests, you may object under Article 21 and we will stop unless we can show compelling grounds that override your rights.
This section matters more than any other in this Policy. Please read it.
Theo is a Christian Bible study app. Several things you tell us reveal your religious or philosophical beliefs, which Article 9 GDPR, UK GDPR, and comparable laws elsewhere treat as a protected special category requiring stricter handling than ordinary personal data:
We process it only on your explicit consent, applying the Article 9(2)(a) GDPR standard as our own benchmark worldwide. That means:
Health-adjacent data. Fasting records, focus session history, and conversations touching on emotional wellbeing may be treated as health or "consumer health data" under some laws — notably Washington's My Health My Data Act and Nevada SB 370. Our separate Consumer Health Data Privacy Policy covers this and is linked from the same place as this Policy.
We do not sell special category data. We do not use it for advertising, profiling with legal effect, or any inference beyond serving you inside the app.
Theo is an artificial intelligence system, not a human being and not a member of clergy. Every reply is machine-generated. Theo has a name, an avatar, and a warm conversational manner, and it remembers earlier conversations — none of that makes it a person. We state this in the app before your first message, and we restate it here so there can be no confusion.
This disclosure is made in accordance with Article 50(1) of the EU Artificial Intelligence Act (Regulation (EU) 2024/1689), which has applied since 2 August 2026, and with California Senate Bill 243, in force since 1 January 2026.
| Role | Provider | Model |
|---|---|---|
| Generating Theo's replies | Anthropic PBC (United States) | Claude Haiku 4.5 |
| Journal embeddings for semantic search | OpenAI, L.L.C. (United States) | text-embedding-3-small |
We may change models or providers to improve quality, reliability, or cost. If we add or substitute an AI provider, we will update this Policy, and where the change is material we will notify you in the app and seek fresh consent before sending your data anywhere new.
Theo is not a substitute for Scripture, for your pastor, or for professional medical, mental health, legal, or financial advice. It can be wrong. It can misquote or misattribute Bible verses. Verify anything that matters against your Bible and a person you trust.
If your message suggests suicidal ideation, self-harm, or acute crisis, Theo is designed to break out of ordinary conversation and surface crisis resources — in the United States, the 988 Suicide & Crisis Lifeline; elsewhere, region-appropriate services and emergency numbers. This protocol operates before the model generates a reply, so it does not depend on the model behaving correctly.
We publish this protocol here as required by California SB 243 §22602. Theo is not an emergency service. If you are in danger, contact your local emergency number.
Theo periodically reminds younger users that they are talking to an AI and that taking a break is a good idea. Sexually explicit content is refused for all users regardless of age.
We do not make decisions producing legal or similarly significant effects about you by automated means. Theo does not decide anything about your eligibility, pricing, employment, credit, or access to services. There is no Article 22 GDPR automated decision-making in Theo, and nothing that would engage the automated-decision transparency obligation entering Australian law on 10 December 2026. If that ever changes, this Policy will say so before it does.
Content personalisation — which chapter Theo suggests, which reading plan it recommends — is automated, but it only shapes suggestions you are free to ignore.
These are our processors and sub-processors. Each is bound by a written data processing agreement incorporating the European Commission's Standard Contractual Clauses where required.
| Provider | Role | What it receives | Retention | Location |
|---|---|---|---|---|
| Supabase | Database, auth, storage | Account data (§3.2) | Life of your account | United States |
| Anthropic | AI replies | Message text, first name, denomination, turn count, journal excerpts, conversation memory | Auto-deleted within 30 days; up to 2 years only where a Usage Policy violation is being enforced | United States |
| OpenAI | Journal embeddings | Text of journals opted into "Theo can read" | Up to 30 days for abuse monitoring, then deleted | United States |
| Amazon Web Services | Lambda proxy, DynamoDB memory | Chat traffic in transit; summarised memories at rest | Lambda retains nothing; memories per §9 | United States |
| Firebase Crashlytics (Google) | Crash reporting | Crash reports, device and OS, anonymous install ID | ~90 days | United States |
| PostHog | Product analytics | Usage events, person properties | 365 days | United States |
| Apple | Sign in, payments, push, Screen Time | Opaque user ID, email or relay address; payment handled entirely by Apple | Per Apple's policy | United States |
| Sign in with Google | Opaque user ID, email, name | Per Google's policy | United States |
Neither Anthropic nor OpenAI uses this data to train models.
We have never sold personal information, and we have never shared it for cross-context behavioural advertising, as those terms are defined in the CCPA and comparable state laws. We do not intend to. If that ever changes, we will amend this Policy and provide the opt-out the law requires before any such disclosure occurs.
We may disclose data where legally compelled by valid process, or where necessary to protect life, safety, or our legal rights. We will notify you unless legally barred from doing so.
If Theo is ever sold or merged, your data may transfer to the acquirer, who will remain bound by this Policy or must obtain fresh consent. You will be told before it happens.
No system is perfectly secure. Where a breach is likely to result in a risk to your rights, we will notify the competent supervisory authority within 72 hours of becoming aware, as Article 33 GDPR requires, and notify you directly without undue delay where the risk is high. Where US state breach-notification law applies, we will comply with its timelines too.
| Category | Retention |
|---|---|
| On-device data | Until you delete it or remove the app |
| Account and profile | Life of the account; deleted within 30 days of a deletion request |
| Journals and embeddings | Life of the account; deleted within 30 days of deletion |
| Chat message text | Not retained — discarded after the reply streams |
| Conversation memories (DynamoDB) | 180 days, then auto-expired by TTL |
| Short-term conversation context | 60 days, then auto-expired by TTL |
| AI provider copies | ≤30 days at Anthropic and OpenAI |
| Analytics (PostHog) | 365 days |
| Crash reports (Crashlytics) | ~90 days |
| Feedback submissions | Up to 30 days after a deletion request |
| Records we must keep by law | As long as the law requires, no longer |
Deleting your account triggers deletion across Supabase and DynamoDB. Deletion at AWS begins immediately and normally completes within minutes; if a service is briefly unavailable we retry with exponential backoff for up to 24 hours. Backups roll off within 30 days.
Theo is operated from the United States, and all of our providers process data in the United States. If you use Theo from anywhere else, your data is transferred to the United States.
Theo is not offered in the EEA, the UK, or Switzerland (Section 12.1), so routine transfers out of those regions do not arise. Our agreements with the providers named in Section 7 nonetheless incorporate the European Commission's Standard Contractual Clauses (Decision 2021/914) and equivalent transfer terms, which continue to cover any legacy data, alongside encryption in transit and at rest and the data minimisation described in Section 3.3.
We do not rely on your consent as a transfer mechanism. Article 49 consent is a derogation intended for occasional transfers and is not an appropriate basis for routine transfers. You may request a copy of the relevant clauses by writing to us.
Some destination countries do not offer protection equivalent to your home jurisdiction, and public authorities there may have access rights that your own law would not permit. The safeguards above are designed to address that, but we would rather you knew.
We extend the following to every user, in every country, regardless of whether your local law requires it:
Doing it yourself, immediately: Settings → Export My Data (access and portability), Settings → Delete My Data (deletion), Settings → Privacy (consent and visibility controls), Settings → Delete Account (full account deletion).
Or ask us: tommy@landslidestudios.com. We respond within 30 days, extendable by 60 days for genuinely complex requests, and we will tell you if we extend. Verification is proportionate: we ask you to write from your registered email, or confirm details only the account holder would know. We do not charge, unless a request is manifestly unfounded or excessive — in which case we will say so and explain why rather than quietly ignoring it.
You may use an authorised agent where your local law provides for one.
Theo is not offered in the European Economic Area, the United Kingdom, or Switzerland. As of 31 August 2026 we withdrew the App from all App Store territories in those regions. We do not market, sell, or make Theo available there, we do not monitor the behaviour of people located there, and we do not target those markets in any language.
Because we do not offer goods or services to people in those territories, Article 3(2) GDPR and the equivalent UK and Swiss provisions do not extend to us, and the Article 27 requirement to appoint a local representative does not arise.
We are telling you this plainly rather than leaving a GDPR section in place that implies a presence we do not have. If you are in one of these regions and hold a legacy account created before the withdrawal, we still honour every right in Section 11 — access, portability, correction, deletion, restriction, objection, and withdrawal of consent — and you may exercise them at tommy@landslidestudios.com on the same 30-day timeline. Should we re-enter these markets, we will appoint the representatives the law requires and update this Section before doing so.
Under the CCPA as amended by the CPRA, you may know, delete, correct, opt out of sale or sharing, and limit the use of sensitive personal information.
Whether we meet the CCPA's applicability thresholds in any given year, we honour these rights.
Residents of Colorado, Connecticut, Delaware, Florida, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah, and Virginia have rights of access, correction, deletion, portability, and opt-out of targeted advertising, sale, and profiling with legal effect. We honour all of them through the mechanisms in Section 11.
Notes that actually matter:
Washington's My Health My Data Act and Nevada SB 370 apply regardless of our size. Our separate Consumer Health Data Privacy Policy sets out what we treat as consumer health data, the consent we obtain, your right to withdraw it, and your right to have that data deleted — including from our processors. It is published alongside this Policy and linked from the app.
Under PIPEDA and provincial law, you may access and correct your data and withdraw consent. Quebec residents additionally have rights to data portability and to be informed about automated decisions under Law 25; as Section 6.6 notes, Theo makes none. You may complain to the Office of the Privacy Commissioner of Canada, or to the Commission d'accès à l'information du Québec.
Under the LGPD you may confirm processing, access, correct, anonymise, block, delete, port, learn with whom we share, and withdraw consent. Our legal bases are consent (Art. 7, I) and contract performance (Art. 7, V). Religious data is dado pessoal sensível under Art. 11 and is processed only on your specific, highlighted consent. You may complain to the ANPD.
Under the Privacy Act 1988 (Cth) and the Australian Privacy Principles, you may access and correct your personal information and complain to the OAIC. Religious beliefs are "sensitive information" under APP 3.3 and require your consent, which Section 5 describes. We do not use automated decision-making of the kind covered by the APP 1.7 transparency obligation commencing 10 December 2026. New Zealand users have equivalent rights under the Privacy Act 2020 and may complain to the Office of the Privacy Commissioner.
Under the Digital Personal Data Protection Act 2023 and the DPDP Rules 2025, you may access, correct, erase, nominate another person to act for you, and grieve. We process on your consent. As implementation phases in through 2026 and 2027 — including the Consent Manager framework — we will align and update this Policy.
We extend Section 11 rights to all users. This is in addition to whatever your national law provides, including:
| Jurisdiction | Law | Regulator |
|---|---|---|
| Japan | APPI | Personal Information Protection Commission |
| South Korea | PIPA | Personal Information Protection Commission |
| China | PIPL | Cyberspace Administration of China |
| Singapore | PDPA | PDPC |
| Thailand | PDPA | PDPC Thailand |
| Vietnam | Personal Data Protection Law | Ministry of Public Security |
| Indonesia | PDP Law | Ministry of Communication |
| South Africa | POPIA | Information Regulator |
| Nigeria | NDPA 2023 | NDPC |
| Kenya | Data Protection Act 2019 | ODPC |
| Saudi Arabia | PDPL | SDAIA |
| UAE | Federal Decree-Law 45/2021 | UAE Data Office |
| Turkey | KVKK | KVKK Authority |
| Israel | Privacy Protection Law | PPA |
Several of these jurisdictions restrict cross-border transfers. Where your national law requires consent for transfer to the United States, your use of Theo's cloud features following this notice constitutes that consent, and you can avoid all transfers by using Theo without an account and without the AI assistant.
Theo is for ages 13 and up. The under-13 option is deliberately absent from the age selection screen, and the app is built so that we do not knowingly collect personal information from anyone under 13. We do not operate a child-directed service under COPPA, and Theo is not in the Kids Category.
If we learn that a user is under 13, we delete their information promptly and terminate the account. If you are a parent or guardian who believes your child has used Theo, write to tommy@landslidestudios.com and we will act on it.
Ages 13–17. Where your app store provides an age signal or a parental consent signal — including under the Texas App Store Accountability Act and Utah's equivalent — we honour it. We do not serve advertising to anyone. We do not sell or share minors' data for any purpose. Section 6.5 covers AI safeguards for younger users.
Higher digital-consent ages. Some countries set the age of valid consent to data processing above 13. If you are under your country's threshold, a parent or guardian must consent before you use Theo. Have them contact us and we will handle it.
We will update this Policy when the app or the law changes. The version number and Last Updated date at the top always reflect the current text.
For material changes — a new AI provider, a new category of data, a new purpose, or any new disclosure of your data — we will notify you in the app before the change takes effect, and where the change concerns data processed on your consent, we will ask for fresh consent rather than assuming continued use implies it. Superseded versions are archived and available on request.
Privacy questions, rights requests, and complaints: tommy@landslidestudios.com
We answer within 30 days. If you are unsatisfied with our response, Section 12 lists the regulator for your region, and you may complain to them directly at any time — you do not need our permission and you do not need to come to us first.
| App Name | Theo | Bible Study Lock |
| Apple ID | 6760088556 |
| Bundle ID | com.biblelock.app |
| Developer | Landslide Studios LLC |
| Subscriptions | com.biblelock.annual, com.biblelock.monthly |
| Policy version | 2.0 — August 31, 2026 |