Skip to content

Privacy Policy · Last updated August 4, 2026

How we handle your data.

1.Introduction

Welcome to TrulyRandomVerse. This Privacy Policy applies to our Website (trulyrandomverse.com), our Progressive Web App (PWA), and our Browser Extension.

Most of the site can be used without an account — random-verse browsing, search, verse pages, articles, and the extension all work anonymously. The AI Bible study companion at /ai is the one exception: it requires Google Sign-In so we can enforce daily usage caps and prevent abuse. Section 2 covers what we collect when you use it.

You can also sign in by choice, to have your reading plan, saved verses and preferences follow you between devices. That is optional and changes nothing for anyone who doesn't; section 7 covers what an account holds and how to see or delete it.

2.AI features (Beta)

The AI companion is in free, time-limited Beta. The Beta Terms spell out the deal in plain language; the clauses below are the legal version.

What we collect when you use AI features

  • Your Google account info (Google sub-id, email, name, profile picture) via Google Sign-In.
  • The questions you ask and the AI's answers — both stored encrypted at rest (AES-256-GCM) — plus tool-call metadata (which curated tools the AI consulted, with what arguments).
  • Approximate language (auto-detected from your browser, then stored on your account so future sessions skip detection).
  • Hashed IP + light fingerprint for abuse detection (rate limits, anomaly checks). Stored ≤30 days.

How we use it

  • Operate the service — return answers, enforce daily caps, persist conversation history so you can return to it.
  • Debug quality issues and improve prompts/tools.
  • Detect abuse via anomaly detection and rate limits.

Third parties

  • Google Gemini API (paid tier). Every question and answer transits Google's API. We use the paid tier; per Google's Gemini API Additional Terms of Service, Google does not use paid-tier API prompts or responses to train their models. Content is processed transiently and may be retained briefly for abuse monitoring per Google's terms.
  • Google Sign-In. Handles authentication; we receive only the standard openid email profile claims (no contact-list or Drive access, ever).

Retention

  • Conversations: kept until you delete them or your account.
  • Sessions: auto-purge after 30 days of inactivity.
  • Anomaly / login logs: 30 days, then deleted by cron.

Deletion

  • Per-conversation: from /account/conversations — single click + confirm; hard-deletes the conversation row and its messages.
  • Whole account: from /account — hard-deletes every conversation and its messages, all sessions, and the PII columns on the user row (name, email, picture, language). Aggregate spend numbers in our token ledger are kept but de-linked (user_id set to NULL) — they contain no content.

Beta-specific clause

During the public Beta we may review the AI's responses to debug quality, identify abuse, and improve our prompts and tools — review is answers-only: our admin tools never decrypt or display your questions. The AI's responses are never made public. After Beta this clause is reviewed and either narrowed or removed depending on whether ongoing review is necessary; we'll update this page accordingly.

Never

  • We do not sell your data.
  • We do not show ads on the AI page.
  • We do not use your AI conversations for advertising profiles anywhere on the site.

Children

The AI companion is intended for users 13+ (or the applicable minimum age in your jurisdiction). Google handles age gating on the sign-in side.

3.Cookies & consent

When you first visit our site, a consent banner allows you to choose which types of cookies and data collection you allow:

  • Essential Only: Only technical cookies and storage required for the site to function (theme preference, font size, dismissed popups). No analytics cookies are set.
  • Accept All: In addition to essential cookies, this enables analytics tracking (Google Analytics), which may set its own cookies.

You can change your cookie preferences at any time by clearing your browser's Local Storage for this site, which will cause the consent banner to reappear on your next visit.

4.Analytics

We use three analytics services to understand how visitors use our site:

  • Google Analytics 4 (GA4): When you consent to analytics cookies, Google Analytics collects anonymized usage data such as pages viewed, session duration, and approximate geographic region. We use Google Consent Mode v2, which means even without consent, limited anonymized data is collected without cookies. Google may process this data on servers in the United States. Google's Privacy Policy.
  • Microsoft Clarity: Clarity records anonymized interaction data (clicks, scrolling, page structure) so we can find and fix usability problems — it is how several bugs on this site have been caught. Text you type is masked by Clarity before it leaves the page. Clarity receives a consent signal from the banner: if you choose Essential Only, it is told not to use cookies. Data may be processed by Microsoft in the United States. Microsoft's Privacy Statement.
  • Matomo (Self-Hosted): We run Matomo analytics on our own server in cookieless mode. This means no tracking cookies are set on your device, and your data never leaves our server. IP addresses are anonymized. This tracking is GDPR-compliant without requiring consent.

5.Advertising

This site displays no advertising. There are no ad units on any page. Until July 2026 this section described Google AdSense; the ad library and its ad units were removed.

One technical detail, in the interest of accuracy: the Google tag that powers our analytics also carries a Google Ads conversion ID, so page views make requests to Google advertising domains (googlesyndication.com, doubleclick.net) as part of Google's consent-mode measurement. If you choose Essential Only, these requests are cookieless and Google states they are not used for ad personalization; advertising storage is only enabled if you choose Accept All. No ads are shown to you in either case.

6.The Browser Extension

Our Browser Extension is designed to function entirely within your browser environment, unless you deliberately connect it to an account.

  • Local Data: Your history and favorites are stored using chrome.storage.local. Unless you connect the extension to a TrulyRandomVerse account, this data never leaves your specific computer.
  • Connecting an account (optional, from version 4.2): You can pair the extension with your account using a code from Your data. Once paired, the verses you save in the extension are stored on your account, so they are the same ones you see on the website and on your other devices. It reaches your saved verses and nothing else — not your reading plan, not your searches, not your account settings. Disconnect from either the extension or Your data, and it stops immediately. An extension that has never been paired sends us nothing about you at all.
  • Synced Data: Your preferences (like Bible version) are stored using chrome.storage.sync. This leverages your personal Google Account to sync settings between your computers. This data is encrypted by Google; we have no access to it.
  • API Usage: When you click "Random Verse," the extension sends an anonymous request to our server to retrieve the text. No user-identifiable data is sent with this request.

7.Website & PWA data handling

When you use trulyrandomverse.com or install our PWA:

  • Local Storage: We use your browser's built-in LocalStorage to save your verse history, favorites, theme preference, and font settings. If you are not signed in, this data stays on your device and we have no access to it.
  • Service Worker: Our PWA uses a Service Worker to cache static assets (CSS, fonts, icons) for faster loading. No personal data is stored in this cache.
  • Server Logs: Our host automatically logs basic technical details (IP address, browser type, timestamp). These logs are used solely for security monitoring and are not used to build user profiles.

If you sign in

Signing in is optional everywhere except the AI companion. When you are signed in, some of what used to live only in your browser is also kept on your account, so it follows you between devices: your reading plan, your saved verses and their notes and collections, a few display preferences, and the verse pages you have opened (the most recent 50).

  • We ask before moving anything. Data already in your browser when you sign in is not swept up. You are shown what is there and asked once; if you say no, nothing moves, and you can change your mind later at Your data. Anything you save while signed in goes to your account as you do it, the same way a saved verse has always gone to your browser.
  • Searches are separate, and off. Nothing you type into a search box is stored on your account unless you turn that on yourself at Your data. If you do, the last 10 searches are kept, encrypted at rest. Turning the setting off deletes them.

Everything above can be deleted from Your data — the searches and the verse-page history each have their own delete, separately from deleting your account. Deleting your account removes all of it.

8.Third-party services

We use the following third-party services:

  • Google Analytics — Web analytics (see Section 4)
  • Cloudflare — CDN, security, and performance optimization. Cloudflare may set essential security cookies. Cloudflare Privacy Policy.
  • Google Fonts — Font delivery (loaded locally where possible to minimize external requests).

If we link to external Bible reference sites, we are not responsible for the privacy practices of those external websites.

9.Your rights & control

You possess full control over your information:

  • Cookie Consent: Use the consent banner to choose "Essential Only" to block analytics cookies.
  • Delete Local Data: Clear your browser's Local Storage for this site to remove all preferences, history, and favorites. If you are signed in, this clears only this device — what your account holds is restored the next time you visit. Use Your data to remove it from the account, or delete your account entirely.
  • Google Opt-Out: Visit Google Analytics Opt-out Browser Add-on to block GA4 entirely.
  • Extension Data: Uninstall the Browser Extension or clear its storage to remove all local data.
  • AI account data: Manage and delete from /account — per-conversation delete on /account/conversations, whole-account delete in the Danger Zone. See section 2 above for what's retained vs purged.
  • Synced account data: See and delete everything your account holds at Your data — what is stored, which devices you have signed in on, and separate deletes for your searches and your verse-page history. The searches setting is off until you turn it on. See section 7.

Under GDPR, CCPA, and similar regulations, you have the right to request information about what data we process. If you are not signed in, random-verse browsing, search, articles, and the extension stay anonymous — there is no profile to access for that traffic. Signing in creates a Google-Sign-In-backed account, which the AI companion requires and the rest of the site does not; what that account then holds is set out in sections 2 and 7. You can access, correct, or delete it yourself from /account and /account/data, or contact us at the address in section 11 for any request the in-app controls don't cover.

10.Changes to this policy

We may update this Privacy Policy from time to time. Changes will be posted on this page with an updated "Last Updated" date. Continued use of the site after changes constitutes acceptance of the updated policy.

11.Contact us

If you have any questions about this policy or the privacy of our services, please contact us at [email protected].