SourceText

Privacy

Questions about scripture reveal religious conviction, which EU law treats as a special category of personal data. The design decision that follows from that is simple: do not hold them.

There is one exception, and it only happens if you ask for it: an account holder can save a finding, which stores that answer. We ask for your explicit consent the first time, before anything is saved, and you can decline and download the file instead.

What we do not store

What we do store

If you have an account

An account is either created for you — in which case you are given a one-time password to replace with your own the first time you sign in — or created by you at sourcetext.ai/signup, where you choose the address and the password yourself.

If you create it yourself, we email that address twice at most: once with a link to confirm it is yours, and again only if you ask us to resend that link or to reset your password. We send nothing else to it — no newsletter, no product mail — and we pass it to nobody. The mail goes through a transactional email provider acting as our processor, which is the only third party that sees the address.

Confirming the address is required before you can sign in, because it is the only thing that ties an account to a person who can be reached. An account that is never confirmed is deleted after seven days, along with everything it holds — which is nothing, since it was never signed in to. The links we send expire on their own: 24 hours to confirm an address, one hour to reset a password, and each works once.

We keep all of it until you delete it. There is no retention timer, because a study you built is meant to last; deleting your account removes every part of it immediately and permanently.

Who else is involved

Answering a question means sending it, and the scripture retrieved to answer it, to Anthropic, whose model generates the response. Anthropic processes it to produce the answer. Nothing identifying you is sent with it — no name, no account, not the session identifier.

The site runs on our own servers in Helsinki, Finland, inside the EU.

Your rights

Under the GDPR you may request access to, correction of, or erasure of personal data we hold about you. Without an account we hold almost none: with no stored conversations, there is usually nothing to retrieve or erase beyond a short-lived log entry.

With an account, two of those rights are buttons rather than requests. Download everything in Settings gives you a zip containing your account details and every saved finding as a Markdown file, and Delete account erases the account and all of it at once. You may withdraw your consent to storing findings at any time by deleting them, or the account. For anything else, write to [email protected] and we will answer within 30 days.

You may also complain to the Danish Data Protection Agency, Datatilsynet.

Data controller

Allegro IT ApS · CVR 34593701
Fyrrelien 8, 8920 Randers NV, Denmark
[email protected]

Last updated 6 August 2026.