Tota Scriptura Bible Community
Privacy Policy
This policy covers the Tota Scriptura Bible Community app. The dgmd-software.de website has its own, separate privacy policy. The app's Terms of Service are published too.
1. Who is responsible
- Provider
- DGMD Software Solutions UG (haftungsbeschränkt)
- Address
- Luko - Dorfstr. 41, 06869 Coswig (Anhalt) OT Luko, Sachsen-Anhalt, Germany
- contact@dgmd-software.de
We are the controller for the personal data described here.
2. What we collect, and why
Your account
When you create an account we store your email address and a password, which is stored only in hashed form by Firebase Authentication and is never visible to us.
Purpose: to give you an account. Basis: Art. 6(1)(b) — performance of a contract.
Your profile
A name, a nickname, whether you prefer your real name shown, and optionally a profile photo. Your nickname or name appears beside anything you post publicly.
Basis: Art. 6(1)(b).
Your private study
Notes, bookmarks, categories and reading preferences, including which Bible passages they relate to. These are visible only to you. Nobody else, including us, browses them in the ordinary course of running the service.
Basis: Art. 6(1)(b).
What you post
Discussion topics and messages, the passage they relate to, and the time you posted. These are visible to other users. In private study groups they are visible to that group.
Content of this kind can reveal religious beliefs, which makes it special-category data within the meaning of Art. 9 GDPR. We treat it accordingly: it is not used for advertising, not used to profile you, and not passed to any third party other than those named here.
Basis: Art. 6(1)(b).
Safety and moderation
- Content you report, and reports about your content, including a copy of the reported text as it was at the time.
- A moderation record of decisions made about your content, and any appeal you file.
- Any restriction applied to your account and the reason for it.
- People you have blocked (visible only to you).
Basis: Art. 6(1)(f) — our legitimate interest, and that of other users, in a service that is safe to use, and compliance with our obligations as a hosting service.
Notifications
If you turn them on, a device token so we can send push notifications, and which topics, groups or passages you follow.
Basis: Art. 6(1)(a) — consent, withdrawable at any time in the app or in your device settings.
Diagnostics
If the app crashes, Firebase Crashlytics records the error, your device model and operating system version, and your user identifier.
Basis: Art. 6(1)(f) — keeping the app working.
Feedback
Anything you write in Send feedback, plus the app version and platform, and your email address if you choose to give one.
Basis: Art. 6(1)(f), or Art. 6(1)(a) where you supply contact details.
3. Automated checking of content
Messages, topic titles, nicknames and profile photos are checked
automatically before they become visible to others, using
OpenAI's moderation service (api.openai.com). For customers in
the EEA the processor is OpenAI Ireland Ltd., based in
Ireland. Where OpenAI passes data to affiliates outside the EEA, it does so
under the Standard Contractual Clauses or an adequacy decision.
OpenAI retains API inputs for up to 30 days for abuse monitoring and then deletes them, unless legally required to keep them. They are not used to train OpenAI's models.
Content that appears to break our Rules is withheld and reviewed by a person. No decision to remove your content is made by automated means alone — you can appeal, and a person reads the appeal.
Basis: Art. 6(1)(f). Transfer: protected by the Standard Contractual Clauses incorporated into OpenAI's Data Processing Addendum.
4. Who else processes your data
| Who | What | Where |
|---|---|---|
| Google (Firebase / Google Cloud) | Hosting, database, files, authentication, notifications, crash reports | Data stored in the EU (eur3); processing in europe-west1 |
| OpenAI Ireland Ltd. | Automated content checking | Ireland; onward transfers outside the EEA under SCCs |
We do not sell your data, we do not use it for advertising, and we do not profile you.
5. How long we keep it
- Your content and account data: until you delete them or your account. Inactive accounts are not deleted automatically — we do not delete your data unless you ask us to.
- Moderation records: retained after account deletion with your identity removed, as the record of decisions taken.
- Deletion requests: retained as evidence that erasure was requested and when.
6. Your rights
In the app, under Your data:
- Export — a machine-readable copy of your data (Art. 20).
- Delete your account (Art. 17). Your private study, profile and account are deleted. Messages and topics you posted publicly remain in the conversations they belong to, with your name removed, because other people took part in those discussions and their contributions are their data too.
You may also request access (Art. 15), correction (Art. 16), restriction (Art. 18) or object to processing (Art. 21) by writing to contact@dgmd-software.de. Where processing rests on consent, you may withdraw it at any time without affecting what was done beforehand.
You may complain to a supervisory authority. Ours is:
Landesbeauftragter für den Datenschutz Sachsen-Anhalt
Leiterstraße 9, 39104 Magdeburg, Germany
7. Children
The service is not for people under 18. We do not knowingly collect data from them. If you believe a child has an account, write to contact@dgmd-software.de and we will remove it.
8. Changes
We will post any change on this page and update the date below. Significant changes will be notified in the app.
Last updated: September 2026. This is a courtesy translation; in case of doubt, the German version prevails.