Privacy
Questions about scripture reveal religious conviction, which EU law treats as a special category of personal data. The design decision that follows from that is simple: do not hold them.
There is one exception, and it only happens if you ask for it: an account holder can save a finding, which stores that answer. We ask for your explicit consent the first time, before anything is saved, and you can decline and download the file instead.
What we do not store
- Your questions and the answers. The conversation lives in your browser and is sent with each question so the answer can follow on from the last. It is not written to a database, and it is not written to our logs. Closing the tab ends it.
- Anything about you, unless you have an account. The site works fully without one — reading, search and asking questions need no account and no address.
- Advertising or analytics trackers. There are none.
What we do store
- An anonymous session cookie, holding a random identifier with no meaning outside this site. Its only purpose is counting your questions against the daily limit. It is not linked to you.
- A daily question count against that random identifier, held in memory and discarded when the day rolls over.
- Ordinary server logs — timestamps, IP addresses, and errors — kept briefly for security and abuse prevention. Neither the questions you ask nor the words you search for appear in them: the web server's request log is switched off for exactly that reason.
If you have an account
An account is either created for you — in which case you are given a one-time password to replace with your own the first time you sign in — or created by you at sourcetext.ai/signup, where you choose the address and the password yourself.
If you create it yourself, we email that address twice at most: once with a link to confirm it is yours, and again only if you ask us to resend that link or to reset your password. We send nothing else to it — no newsletter, no product mail — and we pass it to nobody. The mail goes through a transactional email provider acting as our processor, which is the only third party that sees the address.
Confirming the address is required before you can sign in, because it is the only thing that ties an account to a person who can be reached. An account that is never confirmed is deleted after seven days, along with everything it holds — which is nothing, since it was never signed in to. The links we send expire on their own: 24 hours to confirm an address, one hour to reset a password, and each works once.
- Your email address, because it is how you sign in, and a hash of your password. We never hold the password itself and cannot recover it.
- A session cookie for the browser you signed in from, and a record of that session so signing out really ends it.
- Your daily question count, so the limit survives a restart.
- The findings you choose to save — the question, the answer, and the claims it recorded. This is the special-category data described above, and the lawful basis is your explicit consent under GDPR Article 9(2)(a), collected in a dialog the first time you save anything. We record when you gave it. Saving nothing means storing nothing.
We keep all of it until you delete it. There is no retention timer, because a study you built is meant to last; deleting your account removes every part of it immediately and permanently.
Who else is involved
Answering a question means sending it, and the scripture retrieved to answer it, to Anthropic, whose model generates the response. Anthropic processes it to produce the answer. Nothing identifying you is sent with it — no name, no account, not the session identifier.
The site runs on our own servers in Helsinki, Finland, inside the EU.
Your rights
Under the GDPR you may request access to, correction of, or erasure of personal data we hold about you. Without an account we hold almost none: with no stored conversations, there is usually nothing to retrieve or erase beyond a short-lived log entry.
With an account, two of those rights are buttons rather than requests. Download everything in Settings gives you a zip containing your account details and every saved finding as a Markdown file, and Delete account erases the account and all of it at once. You may withdraw your consent to storing findings at any time by deleting them, or the account. For anything else, write to [email protected] and we will answer within 30 days.
You may also complain to the Danish Data Protection Agency, Datatilsynet.
Data controller
Allegro IT ApS · CVR 34593701
Fyrrelien 8, 8920 Randers NV, Denmark
[email protected]
Last updated 6 August 2026.