Last updated 10 September 2026
Credence is free and does not ask who you are. You can use all of it without signing in, we never see a password, and nothing you do here is ever sold. Signing in is optional, and the only thing it does is keep your progress if you clear your browser or change phones; see Signing in below. This policy covers credence.faith and the Credence app.
The first time Credence opens, your browser or device makes up a random identifier for itself and stores it locally. It is not your advertising ID, phone number, IMEI or any other device serial. It is a number we invented, and it means nothing outside Credence. It is what lets your progress, your chat thread and your notifications find their way back to you without you ever signing in. It is not used to profile you or to follow you around other apps and websites.
So we can see which lessons work and which ones lose people, the app sends a small number of events to our own server:
Your answers to the introduction questions (how familiar you are with the Bible, and what you want out of it) are stored alongside your identifier.
We do not collect your phone number, contacts, photos or location. Unless you choose to sign in we have no name for you beyond the display name you pick for chat, and no email address at all; see Signing in below for what changes if you do. The app asks for no permissions beyond network access, and notifications if you say yes to them.
If you open the chat, you choose a display name and a cartoon avatar. Pick a first name or a nickname, not your full name, and please don't type anything private into the thread. Your messages, that display name and your avatar are stored on our server and can be read by the mentors who answer. A step that invites you to ask your mentor a question sends your answer into the same thread.
Until a human mentor picks up your thread, replies may come from an automated helper. To write those replies your messages so far and your display name are sent to an outside AI provider, who processes them to produce the answer. Replies from the helper are labeled as such in the app.
If you allow notifications, your browser or phone gives us a delivery token so a mentor's reply can reach you. It is used for nothing else, and turning notifications off in your browser or phone settings ends it.
On the very first visit we record which site linked you here: only the site's name, not the full address, because a full link can carry somebody else's search words. We also keep any campaign tags in the address you arrived on, and the name of the ad-click tag it carried, not its value. That is recorded once and not rewritten afterwards, so it says where you came from rather than where you were last.
To reproduce bugs we keep a coarse record of your browser, operating system, whether you are on a phone, tablet or desktop, and your screen size in the usual buckets. It is stored as those buckets, not as the full technical description your browser sends.
We advertise Credence on social platforms, and their measurement pixels set cookies so our advertising partners can tell us whether an ad brought someone who actually started learning, and can show our ads to people like them. The pixels are told when you open the app and when you reach a milestone such as finishing a lesson. Your lesson answers and your chat messages are never sent to them.
In the EU nothing is loaded until you tap Accept on the banner; tap Decline and no advertising cookie is ever set. Your choice is remembered on your device, and clearing your browser data asks again. If we ever add another advertising partner, the banner comes back rather than quietly loading it. Outside the EU the pixels load on arrival.
Your lesson progress, your XP, the lesson you left half-finished, your sound setting, your display name and avatar, and the random identifier are all stored in your browser's own storage. Chat messages are not kept there: they are fetched from the server each time you open the chat. Clearing your browser data, or uninstalling the app, erases all of it, and a fresh identifier is made the next time you open Credence.
If you are signed in, two things differ: the device also holds the token that keeps you signed in, and a copy of your progress and XP is kept on our server, which is the whole point. Clearing your browser no longer loses them, because signing in again brings them back.
Everything above goes to a server we run ourselves, apart from the AI replies and the advertising pixels described in their own sections. We keep it for as long as Credence needs it: the chat thread so a mentor can pick up where you left off, and the usage events so we can compare a course now with the same course a year ago. We delete it when it stops being useful, or sooner if you ask.
You never have to sign in. Every lesson, the map, your XP and the chat all work without an account, and that is how the app opens. Signing in does exactly one thing: it keeps a copy of which lessons you have finished and how many points you have on our server, so it comes back if you clear your browser or move to a new phone.
You can use an account you already have: Google, Apple or Facebook, whichever of them the
app offers you. The only things we keep are your name and email address. We
ask for the smallest sign-in permission each of them offers, which at Google and Facebook
also hands over a link to your profile picture; we throw it away and store nothing but those
two fields. We never ask for your friends or your posts, and we are told nothing about what
you do anywhere else. We never see your password: you type it on their site, not ours, which
also means that provider knows you use Credence, exactly as it would for any other site you
sign into with them. If you use Sign in with Apple and choose to hide your
address, what we receive is one of Apple's @privaterelay.appleid.com forwarders,
and that is all we ever have.
Your email address is kept so the account can be found again and erased on request, and so we can send you the three emails below. It is not shown to your mentor, not shown anywhere in the app, and never sent to an advertising partner. Signing in with two different providers makes two separate accounts, even if the address is the same. We do not link them, because an email address is not proof of who someone is.
We send you email in exactly three situations, and no others:
Nothing you answer or type is ever in an email. No lesson answer, no chat message, not even who wrote to you. At most an email knows your name and how many points you have. We send at most one a day, and only a handful ever.
Every email has a one-click unsubscribe link at the bottom, and the account sheet in the app has the same two switches, one for mentor replies and one for reminders. Turning them off changes nothing else about your account. The emails are delivered by Amazon SES, which is told your address so it can deliver them and nothing more.
There are no in-app purchases and no links out to social media. Three things are worth a parent's attention: the chat puts a child in touch with a mentor, and the mentor can see the display name they picked; if you accept the cookie banner, an advertising partner is told about milestones such as finishing a lesson; and signing in is optional but does give us an email address, which we then use to send the three emails described above. The first two carry nothing a child types, the emails carry nothing a child types either and can be switched off in one click, and signing in can be skipped entirely, since the app is fully usable without it.
Ask us to erase everything tied to your device and we will: the chat thread, the events, the device record and, if you made one, the account and everything in it. Send the request from the app, or tell us your display name and the email address you signed in with, so we can find the right records. Questions, corrections and complaints are welcome at info@credence.faith.