Privacy Policy
Last updated: March 25, 2026
Legal entity operating this service: Gospel Publishers
Contact (privacy): support@gospelpublishers.com
This policy describes how we collect, use, store, and share personal information when you use our audiobook service, including our website, API, and mobile applications that connect to it.
1. Information we collect
1.1 Account and profile
- Name and email address when you create an account or update your profile.
- Password (stored using secure one-way hashing; we do not store your password in plain text).
- Email verification status, if you use verification.
- If you sign in with Google or Apple, we may receive identifying information those services provide (such as your email, name, and a provider-specific user id). We store what we need to maintain your account and sign-in.
1.2 Purchases and access
- Which books you have purchased or unlocked, and when that access was granted.
- For paid purchases processed online, our payment provider receives the information required to complete the transaction; we typically retain payment references (for example, a payment intent identifier from our provider) and do not store full card numbers on our servers.
1.3 Listening activity
- Playback progress per chapter (for example, position in seconds and last updated time) so we can sync your place in an audiobook across sessions and devices.
1.4 Authentication and security (technical data)
- API tokens issued when you sign in from a supported client (for example, our mobile apps), used to authenticate requests until they expire or are revoked.
- On our website, standard session cookies and related session data as needed to keep you logged in.
- Server logs and session records may include technical details such as IP address, user agent, and timestamps as part of normal web application operation (for example, Laravel session storage).
1.5 Mobile apps
- The apps may store login tokens and basic profile display information locally on your device (for example, your name) to keep you signed in and show the UI. That storage follows the platform’s usual security model for app data.
We do not use this policy to describe every field in our database (such as internal admin roles or catalog metadata). This section focuses on personal information tied to you as a user.
2. How we use your information
We use the information above to:
- Create and secure your account, and authenticate you (including optional social sign-in).
- Process purchases, grant access to content, and maintain a record of entitlements.
- Save and sync listening progress for your experience.
- Operate, secure, and improve the service; detect abuse; and comply with law where required.
- Send transactional email (such as account, security, or purchase-related messages) using an email delivery provider (see section 3.3).
- Diagnose failures using error and crash monitoring (see section 3.3), so we can fix bugs and improve reliability.
3. How we share personal information
We do not sell your personal information.
We share personal information only in these situations:
3.1 Payment processing
Stripe (or another processor we use for the same purpose) receives the data necessary to authorize and complete payments and to meet its own legal and anti-fraud obligations. Card details are handled according to that provider’s practices (for example, often directly on their systems, not retained by us as full card data). Stripe’s privacy notice applies to how they process payment information.
3.2 Sign-in with Google or Apple
When you choose Google or Apple sign-in, authentication is handled by that provider. They process information under their respective privacy policies. We receive only what they send us to create or link your account (as described in section 1).
3.3 Service providers (processors)
We use vendors that help us run the service. They process personal information only on our instructions, to provide their services to us, and are not allowed to use it for their own unrelated marketing. This includes:
- Cloud hosting and storage (infrastructure that may host application data and media).
Transactional email delivery: We use a third-party email delivery service to send email from our application—for example, account-related notices, security messages (such as password reset), purchase or receipt confirmations, or similar transactional communications. To deliver those messages, the provider receives your email address, the content of the email, and metadata needed for delivery (such as sender identifiers, subject line, and timestamps). The provider also processes technical and operational data it needs to transmit, measure, and secure mail. These providers act as processors on our behalf under contract; we do not use them to send third-party marketing on their own behalf. Their privacy notices apply to how they handle data on their systems.
Error and crash monitoring: We may use third-party error monitoring (sometimes called crash reporting or application performance monitoring). When an error occurs in our servers or apps, these tools can receive diagnostic data such as stack traces, the type of device or browser, app version, request path or URL, timestamps, and related technical context. Personal data is not the goal of this processing, but some information could relate to you (for example, if an error message or log line includes an account identifier, or if request details are attached to an event). We configure such tools to limit unnecessary personal data where we can, and the vendors act as processors under contract. Their own privacy policies govern how they handle data on their systems.
We are not in the business of sharing your data with advertisers, data brokers, or unrelated third parties beyond what this section describes and what the law requires.
3.4 Legal and safety
We may disclose information if we believe in good faith it is necessary to comply with law, regulation, legal process, or governmental request; to protect the safety of any person; to address fraud, security, or technical issues; or to protect our rights or property.
4. Retention
We keep personal information as long as your account is active and as needed to provide the service, meet legal, tax, and accounting obligations, resolve disputes, and enforce our agreements. When you delete your account (where we offer that), we delete or anonymize personal information subject to any retention required by law (for example, invoicing or tax records involving payments).
5. Security
We use industry-standard measures appropriate to the nature of the service (including encryption in transit where applicable, access controls, and secure handling of credentials). No method of transmission over the Internet is completely secure; we work to protect your information but cannot guarantee absolute security.
6. Your choices and rights
Depending on where you live, you may have rights to access, correct, delete, or export your personal information, to object to certain processing, or to withdraw consent where processing is consent-based. You may also have the right to lodge a complaint with a supervisory authority.
To exercise these rights, contact us at the address in the header. We may need to verify your request before we act on it.
7. International transfers
Our servers and service providers may be located in countries other than yours. Where required, we use appropriate safeguards (for example, contractual clauses) for cross-border transfers. [Customize for your actual hosting regions and legal setup.]
8. Children
The service is not directed at children under 13 (or the minimum age required in your jurisdiction). We do not knowingly collect personal information from children. If you believe we have collected information from a child, contact us and we will take appropriate steps.
9. Third-party links and content
The service may link to third-party sites or embed third-party components (for example, a payment widget). This policy does not govern those third parties; review their policies before sharing information with them.
10. Changes to this policy
We may update this policy from time to time. We will post the updated version with a new “Last updated” date and, where appropriate, notify you through the service or by email.
11. Contact
Questions about this policy: [privacy or support email]