← Theo Support

Privacy Policy — Theo (BibleLock)

Effective Date: August 31, 2026 Last Updated: August 31, 2026 Version: 2.0


1. Who We Are and How to Reach Us

Theo (also marketed as BibleLock) is an iOS application developed and operated by Landslide Studios LLC, a limited liability company based in North Carolina, United States. For the purposes of the EU and UK General Data Protection Regulation, Landslide Studios LLC is the data controller for the personal data described in this Policy.

Privacy contact tommy@landslidestudios.com
Postal address Available on request to the address above
App Theo | Bible Study Lock — App Store ID 6760088556
Website https://theo.app

We do not currently employ a Data Protection Officer. Appointment is not mandatory for us under Article 37 GDPR because we are not a public authority, our core activities do not consist of large-scale regular and systematic monitoring, and our processing of special category data is not large scale within the meaning of that Article. If that changes, we will appoint one and update this Policy.

How to complain. You can raise a privacy complaint directly with us at the address above, and we will acknowledge it within 30 days. Section 12 lists the regulator for your region where one applies, and you may complain to them directly at any time without coming to us first.


2. Scope and Summary

This Policy applies to everyone who uses Theo, anywhere in the world. It describes what we collect, why, who else sees it, how long we keep it, and what you can require us to do.

The short version:


3. What We Collect

3.1 Stored On Your Device Only

Collected during onboarding and through everyday use, held in iOS local storage. Not transmitted to us, except where Section 3.3 (AI) or Section 3.2 (account sync) applies:

Blocked app selections are a special case. They are held as opaque tokens issued by Apple's FamilyControls framework. The tokens are meaningless outside your device, cannot be resolved back to app names by us, and are technically incapable of being transmitted to our servers. We never learn which apps you block.

You can erase all on-device data at any time from Settings → Delete My Data, or by deleting the app.

3.2 Account Data (Supabase)

If you sign in with Apple or Google, we store on Supabase (PostgreSQL, United States):

Every row is protected by PostgreSQL Row-Level Security, enforced in the database rather than in app code. You can read your own rows and rows that someone has deliberately shared with you. Nothing else.

3.2.1 Journal Privacy Levels

Level Who can read it Sent to an AI provider?
Private (default) You only No
Theo can read You, and Theo during your conversations Yes — text is embedded by OpenAI; matching excerpts go to Anthropic as context
Shared to a group You and members of that group No

The level is yours to set and change at any time. Lowering it stops future processing; Section 9 covers deletion of what already exists.

3.3 Data Sent to AI Providers

When you send a message to Theo, our AWS Lambda proxy transmits to Anthropic:

Separately, when you opt a journal entry into "Theo can read," its text is sent to OpenAI once to generate an embedding. OpenAI is not involved in generating Theo's replies.

We never send your email address, surname, payment details, location, Private journal entries, or your blocked-app selections.

We do not retain the raw text of your chat messages on our servers. The Lambda receives your message, forwards it, streams the reply back, and discards it. We do store summarised conversation memories in AWS DynamoDB so Theo remembers context between sessions; these expire automatically (Section 9).

Neither Anthropic nor OpenAI trains models on this data. Both operate under commercial API terms that exclude API traffic from model training.

3.4 Analytics and Diagnostics

Neither is used for advertising. Theo contains no advertising SDKs, performs no tracking as Apple defines it, and does not use the App Tracking Transparency framework because it has nothing to ask for. Our privacy manifest declares NSPrivacyTracking = false.

3.5 Feedback

If you submit feedback: the category and message you write, app version and build, device model and iOS version, and your username or anonymous analytics ID. Stored in Supabase.

3.6 Social Features

If you join groups or add friends, your username, display name, and streak rank are visible to those people. If your church enables a public web leaderboard at theo.app/c/<slug> and you have "discoverable by username" switched on, that information may be publicly visible. Both conditions must be true; the setting is off by default and lives in Settings → Privacy.


Theo is not offered in the EEA, UK, or Switzerland (Section 12.1). We nonetheless map every purpose to a GDPR Article 6 basis, because it is the clearest way to show what we do and why, and because it holds us to the stricter standard everywhere:

Purpose Data Legal basis
Provide the core app Profile, progress, preferences Contract — Art. 6(1)(b)
Sync your account across devices Account data (§3.2) Contract — Art. 6(1)(b)
Generate AI replies Message, first name, denomination, journal excerpts Consent — Art. 6(1)(a), plus explicit consent under Art. 9(2)(a) for the religious element
Personalise Scripture suggestions Spiritual profile, progress Consent — Art. 6(1)(a)
Social and leaderboard features Username, display name, streak Consent — Art. 6(1)(a)
Process subscriptions Subscription status Contract — Art. 6(1)(b)
Send push notifications APNs token Consent — Art. 6(1)(a)
Product analytics Usage events, person properties Consent — Art. 6(1)(a)
Crash diagnostics Crash reports Legitimate interests — Art. 6(1)(f): keeping the app functional. Balancing test on file.
Security, abuse prevention, enforcing our Terms Account and usage data Legitimate interests — Art. 6(1)(f)
Comply with legal obligations As required Legal obligation — Art. 6(1)(c)

Where we rely on consent, you may withdraw it at any time without affecting the lawfulness of what came before. Where we rely on legitimate interests, you may object under Article 21 and we will stop unless we can show compelling grounds that override your rights.


5. Religious Belief and Other Special Category Data

This section matters more than any other in this Policy. Please read it.

Theo is a Christian Bible study app. Several things you tell us reveal your religious or philosophical beliefs, which Article 9 GDPR, UK GDPR, and comparable laws elsewhere treat as a protected special category requiring stricter handling than ordinary personal data:

We process it only on your explicit consent, applying the Article 9(2)(a) GDPR standard as our own benchmark worldwide. That means:

Health-adjacent data. Fasting records, focus session history, and conversations touching on emotional wellbeing may be treated as health or "consumer health data" under some laws — notably Washington's My Health My Data Act and Nevada SB 370. Our separate Consumer Health Data Privacy Policy covers this and is linked from the same place as this Policy.

We do not sell special category data. We do not use it for advertising, profiling with legal effect, or any inference beyond serving you inside the app.


6. How Theo's AI Works, and What That Means for You

6.1 You Are Talking to a Machine

Theo is an artificial intelligence system, not a human being and not a member of clergy. Every reply is machine-generated. Theo has a name, an avatar, and a warm conversational manner, and it remembers earlier conversations — none of that makes it a person. We state this in the app before your first message, and we restate it here so there can be no confusion.

This disclosure is made in accordance with Article 50(1) of the EU Artificial Intelligence Act (Regulation (EU) 2024/1689), which has applied since 2 August 2026, and with California Senate Bill 243, in force since 1 January 2026.

6.2 The Models Behind It

Role Provider Model
Generating Theo's replies Anthropic PBC (United States) Claude Haiku 4.5
Journal embeddings for semantic search OpenAI, L.L.C. (United States) text-embedding-3-small

We may change models or providers to improve quality, reliability, or cost. If we add or substitute an AI provider, we will update this Policy, and where the change is material we will notify you in the app and seek fresh consent before sending your data anywhere new.

6.3 What Theo Is Not

Theo is not a substitute for Scripture, for your pastor, or for professional medical, mental health, legal, or financial advice. It can be wrong. It can misquote or misattribute Bible verses. Verify anything that matters against your Bible and a person you trust.

6.4 Crisis Handling

If your message suggests suicidal ideation, self-harm, or acute crisis, Theo is designed to break out of ordinary conversation and surface crisis resources — in the United States, the 988 Suicide & Crisis Lifeline; elsewhere, region-appropriate services and emergency numbers. This protocol operates before the model generates a reply, so it does not depend on the model behaving correctly.

We publish this protocol here as required by California SB 243 §22602. Theo is not an emergency service. If you are in danger, contact your local emergency number.

6.5 If You Are 13–17

Theo periodically reminds younger users that they are talking to an AI and that taking a break is a good idea. Sexually explicit content is refused for all users regardless of age.

6.6 Automated Decisions

We do not make decisions producing legal or similarly significant effects about you by automated means. Theo does not decide anything about your eligibility, pricing, employment, credit, or access to services. There is no Article 22 GDPR automated decision-making in Theo, and nothing that would engage the automated-decision transparency obligation entering Australian law on 10 December 2026. If that ever changes, this Policy will say so before it does.

Content personalisation — which chapter Theo suggests, which reading plan it recommends — is automated, but it only shapes suggestions you are free to ignore.


7. Who Else Receives Your Data

These are our processors and sub-processors. Each is bound by a written data processing agreement incorporating the European Commission's Standard Contractual Clauses where required.

Provider Role What it receives Retention Location
Supabase Database, auth, storage Account data (§3.2) Life of your account United States
Anthropic AI replies Message text, first name, denomination, turn count, journal excerpts, conversation memory Auto-deleted within 30 days; up to 2 years only where a Usage Policy violation is being enforced United States
OpenAI Journal embeddings Text of journals opted into "Theo can read" Up to 30 days for abuse monitoring, then deleted United States
Amazon Web Services Lambda proxy, DynamoDB memory Chat traffic in transit; summarised memories at rest Lambda retains nothing; memories per §9 United States
Firebase Crashlytics (Google) Crash reporting Crash reports, device and OS, anonymous install ID ~90 days United States
PostHog Product analytics Usage events, person properties 365 days United States
Apple Sign in, payments, push, Screen Time Opaque user ID, email or relay address; payment handled entirely by Apple Per Apple's policy United States
Google Sign in with Google Opaque user ID, email, name Per Google's policy United States

Neither Anthropic nor OpenAI uses this data to train models.

We have never sold personal information, and we have never shared it for cross-context behavioural advertising, as those terms are defined in the CCPA and comparable state laws. We do not intend to. If that ever changes, we will amend this Policy and provide the opt-out the law requires before any such disclosure occurs.

We may disclose data where legally compelled by valid process, or where necessary to protect life, safety, or our legal rights. We will notify you unless legally barred from doing so.

If Theo is ever sold or merged, your data may transfer to the acquirer, who will remain bound by this Policy or must obtain fresh consent. You will be told before it happens.


8. Security

No system is perfectly secure. Where a breach is likely to result in a risk to your rights, we will notify the competent supervisory authority within 72 hours of becoming aware, as Article 33 GDPR requires, and notify you directly without undue delay where the risk is high. Where US state breach-notification law applies, we will comply with its timelines too.


9. How Long We Keep Things

Category Retention
On-device data Until you delete it or remove the app
Account and profile Life of the account; deleted within 30 days of a deletion request
Journals and embeddings Life of the account; deleted within 30 days of deletion
Chat message text Not retained — discarded after the reply streams
Conversation memories (DynamoDB) 180 days, then auto-expired by TTL
Short-term conversation context 60 days, then auto-expired by TTL
AI provider copies ≤30 days at Anthropic and OpenAI
Analytics (PostHog) 365 days
Crash reports (Crashlytics) ~90 days
Feedback submissions Up to 30 days after a deletion request
Records we must keep by law As long as the law requires, no longer

Deleting your account triggers deletion across Supabase and DynamoDB. Deletion at AWS begins immediately and normally completes within minutes; if a service is briefly unavailable we retry with exponential backoff for up to 24 hours. Backups roll off within 30 days.


10. Where Your Data Goes

Theo is operated from the United States, and all of our providers process data in the United States. If you use Theo from anywhere else, your data is transferred to the United States.

Theo is not offered in the EEA, the UK, or Switzerland (Section 12.1), so routine transfers out of those regions do not arise. Our agreements with the providers named in Section 7 nonetheless incorporate the European Commission's Standard Contractual Clauses (Decision 2021/914) and equivalent transfer terms, which continue to cover any legacy data, alongside encryption in transit and at rest and the data minimisation described in Section 3.3.

We do not rely on your consent as a transfer mechanism. Article 49 consent is a derogation intended for occasional transfers and is not an appropriate basis for routine transfers. You may request a copy of the relevant clauses by writing to us.

Some destination countries do not offer protection equivalent to your home jurisdiction, and public authorities there may have access rights that your own law would not permit. The safeguards above are designed to address that, but we would rather you knew.


11. Your Rights, Wherever You Are

We extend the following to every user, in every country, regardless of whether your local law requires it:

Doing it yourself, immediately: Settings → Export My Data (access and portability), Settings → Delete My Data (deletion), Settings → Privacy (consent and visibility controls), Settings → Delete Account (full account deletion).

Or ask us: tommy@landslidestudios.com. We respond within 30 days, extendable by 60 days for genuinely complex requests, and we will tell you if we extend. Verification is proportionate: we ask you to write from your registered email, or confirm details only the account holder would know. We do not charge, unless a request is manifestly unfounded or excessive — in which case we will say so and explain why rather than quietly ignoring it.

You may use an authorised agent where your local law provides for one.


12. Regional Rights

12.1 EEA, United Kingdom, and Switzerland

Theo is not offered in the European Economic Area, the United Kingdom, or Switzerland. As of 31 August 2026 we withdrew the App from all App Store territories in those regions. We do not market, sell, or make Theo available there, we do not monitor the behaviour of people located there, and we do not target those markets in any language.

Because we do not offer goods or services to people in those territories, Article 3(2) GDPR and the equivalent UK and Swiss provisions do not extend to us, and the Article 27 requirement to appoint a local representative does not arise.

We are telling you this plainly rather than leaving a GDPR section in place that implies a presence we do not have. If you are in one of these regions and hold a legacy account created before the withdrawal, we still honour every right in Section 11 — access, portability, correction, deletion, restriction, objection, and withdrawal of consent — and you may exercise them at tommy@landslidestudios.com on the same 30-day timeline. Should we re-enter these markets, we will appoint the representatives the law requires and update this Section before doing so.

12.2 California

Under the CCPA as amended by the CPRA, you may know, delete, correct, opt out of sale or sharing, and limit the use of sensitive personal information.

Whether we meet the CCPA's applicability thresholds in any given year, we honour these rights.

12.3 Other US States

Residents of Colorado, Connecticut, Delaware, Florida, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah, and Virginia have rights of access, correction, deletion, portability, and opt-out of targeted advertising, sale, and profiling with legal effect. We honour all of them through the mechanisms in Section 11.

Notes that actually matter:

12.4 Washington and Nevada — Consumer Health Data

Washington's My Health My Data Act and Nevada SB 370 apply regardless of our size. Our separate Consumer Health Data Privacy Policy sets out what we treat as consumer health data, the consent we obtain, your right to withdraw it, and your right to have that data deleted — including from our processors. It is published alongside this Policy and linked from the app.

12.5 Canada

Under PIPEDA and provincial law, you may access and correct your data and withdraw consent. Quebec residents additionally have rights to data portability and to be informed about automated decisions under Law 25; as Section 6.6 notes, Theo makes none. You may complain to the Office of the Privacy Commissioner of Canada, or to the Commission d'accès à l'information du Québec.

12.6 Brazil

Under the LGPD you may confirm processing, access, correct, anonymise, block, delete, port, learn with whom we share, and withdraw consent. Our legal bases are consent (Art. 7, I) and contract performance (Art. 7, V). Religious data is dado pessoal sensível under Art. 11 and is processed only on your specific, highlighted consent. You may complain to the ANPD.

12.7 Australia and New Zealand

Under the Privacy Act 1988 (Cth) and the Australian Privacy Principles, you may access and correct your personal information and complain to the OAIC. Religious beliefs are "sensitive information" under APP 3.3 and require your consent, which Section 5 describes. We do not use automated decision-making of the kind covered by the APP 1.7 transparency obligation commencing 10 December 2026. New Zealand users have equivalent rights under the Privacy Act 2020 and may complain to the Office of the Privacy Commissioner.

12.8 India

Under the Digital Personal Data Protection Act 2023 and the DPDP Rules 2025, you may access, correct, erase, nominate another person to act for you, and grieve. We process on your consent. As implementation phases in through 2026 and 2027 — including the Consent Manager framework — we will align and update this Policy.

12.9 Rest of World

We extend Section 11 rights to all users. This is in addition to whatever your national law provides, including:

Jurisdiction Law Regulator
Japan APPI Personal Information Protection Commission
South Korea PIPA Personal Information Protection Commission
China PIPL Cyberspace Administration of China
Singapore PDPA PDPC
Thailand PDPA PDPC Thailand
Vietnam Personal Data Protection Law Ministry of Public Security
Indonesia PDP Law Ministry of Communication
South Africa POPIA Information Regulator
Nigeria NDPA 2023 NDPC
Kenya Data Protection Act 2019 ODPC
Saudi Arabia PDPL SDAIA
UAE Federal Decree-Law 45/2021 UAE Data Office
Turkey KVKK KVKK Authority
Israel Privacy Protection Law PPA

Several of these jurisdictions restrict cross-border transfers. Where your national law requires consent for transfer to the United States, your use of Theo's cloud features following this notice constitutes that consent, and you can avoid all transfers by using Theo without an account and without the AI assistant.


13. Children and Teenagers

Theo is for ages 13 and up. The under-13 option is deliberately absent from the age selection screen, and the app is built so that we do not knowingly collect personal information from anyone under 13. We do not operate a child-directed service under COPPA, and Theo is not in the Kids Category.

If we learn that a user is under 13, we delete their information promptly and terminate the account. If you are a parent or guardian who believes your child has used Theo, write to tommy@landslidestudios.com and we will act on it.

Ages 13–17. Where your app store provides an age signal or a parental consent signal — including under the Texas App Store Accountability Act and Utah's equivalent — we honour it. We do not serve advertising to anyone. We do not sell or share minors' data for any purpose. Section 6.5 covers AI safeguards for younger users.

Higher digital-consent ages. Some countries set the age of valid consent to data processing above 13. If you are under your country's threshold, a parent or guardian must consent before you use Theo. Have them contact us and we will handle it.


14. Changes

We will update this Policy when the app or the law changes. The version number and Last Updated date at the top always reflect the current text.

For material changes — a new AI provider, a new category of data, a new purpose, or any new disclosure of your data — we will notify you in the app before the change takes effect, and where the change concerns data processed on your consent, we will ask for fresh consent rather than assuming continued use implies it. Superseded versions are archived and available on request.


15. Contact

Privacy questions, rights requests, and complaints: tommy@landslidestudios.com

We answer within 30 days. If you are unsatisfied with our response, Section 12 lists the regulator for your region, and you may complain to them directly at any time — you do not need our permission and you do not need to come to us first.


App Details

App Name Theo | Bible Study Lock
Apple ID 6760088556
Bundle ID com.biblelock.app
Developer Landslide Studios LLC
Subscriptions com.biblelock.annual, com.biblelock.monthly
Policy version 2.0 — August 31, 2026