Last updated · 2 August 2026

Privacy Policy

This Privacy Policy explains how Berea (“Berea”, “we”, “us”) processes personal data when you use the public site at tryberea.study, the study workspace at app.tryberea.study, and related APIs. Berea is an advanced Bible-study platform: Scripture reading, original languages, hybrid search, a curated library, collaborative notes and layouts, and research agents that show their tools and citations. We wrote this policy for that product—not as a generic template.

1. Who is responsible

Berea operates the services under the domains tryberea.study and app.tryberea.study. For privacy requests, contact us at privacy@tryberea.study (or the contact channel published on the site). If we appoint a different legal entity as controller, we will update this page and, where required, notify you.

If you use Berea through a team (church, seminary, study group), the team administrator may also process your workspace activity under their own instructions. In those cases we act as processor for team-controlled content and as controller for your account credentials and product telemetry described below.

2. What this policy covers

It covers: creating and signing in to an account; using the study workspace (reader, parallel versions, interlinear and lexicon, search, library uploads, notes, study layouts); inviting or joining teams; running research agents; browsing the marketing site; and receiving transactional email (confirmations, password reset, invitations).

It does not cover third-party Bible editions, commentaries, or websites you open outside Berea, nor model providers’ own consumer products when you use them independently of our agents.

3. Data we collect

Account data: email address, display name or full name you provide, authentication identifiers from Supabase Auth, optional locale and theme preferences, and role within the product (for example client or admin). If you sign in with a social provider, we receive the identifiers and profile fields that provider shares with us for sign-in.

Study content you create: notes, annotations anchored to passages, study layouts (open tabs, versions, resources), saved searches or navigation state stored for your account, and documents you edit in collaborative surfaces.

Library and files: books or resources you upload or register, metadata you assign (title, description, type), storage paths in our object storage, and derived chapter or parse data needed to open them in the reader.

Team and collaboration: team membership, invitations, presence signals while you edit together, and revision history for shared documents where that feature is enabled.

Agent activity: prompts and instructions you send to research agents, tool traces (which search, lexicon, or library tools ran), model outputs, citations shown in the product, and acceptance or rejection of proposed inserts into your notes. We treat agent threads as part of your study workspace content.

Technical and security data: IP address, device/browser type, approximate time zone, cookies or local storage keys needed for session, locale, layout memory scoped to your user, and logs for abuse prevention, uptime, and debugging. We do not sell advertising profiles.

4. Why we process it

To provide the service you request: authenticate you, sync your study space across devices, open Scripture and library resources, run search and lexicon features, and execute agent runs with visible tool traces.

To enable teams: share layouts and documents with members you invite, show presence, and keep access aligned with team roles.

To secure the platform: detect abuse, enforce rate limits, recover accounts, and investigate incidents.

To improve reliability: aggregate diagnostics (for example error rates) that do not require reading the substance of your private notes when we can avoid it.

To communicate about the account: verification, password reset, security notices, and team invitations. Marketing email is only sent if you opt in where applicable.

To comply with law: respond to lawful requests and keep records we are required to keep.

6. Research agents and AI processing

Berea’s agents are designed for verifiable study: they plan steps, call tools (search, lexicon, library, and related helpers), and surface citations. Prompts, tool results, and model completions are processed to produce the answer you see in the dock or conversation.

We use infrastructure providers (including GPU/API inference such as NVIDIA NIM / Nemotron where configured) to run models. Those providers process the content of the request solely to return a response to Berea, under our agreements with them. Do not paste secrets or third-party confidential material into agent prompts unless you are willing for that text to be processed by those subprocessors.

Agent outputs are assistive. They are not pastoral counsel, academic grading, or a substitute for reading the primary text and licensed sources yourself. You remain responsible for what you publish or teach from an agent draft.

We do not use your private notes or library uploads to train public foundation models for unrelated customers. If a specific feature ever requires a different training or retention practice, we will describe it in-product and update this policy before enabling it by default.

7. Scripture text, lexicon, and library licenses

Biblical text, Strong’s-style lexicon data, and curated library works may be subject to third-party copyright and license terms. We provide access inside Berea under those licenses; this Privacy Policy does not grant you extra rights to redistribute those works outside the product.

When you upload your own files to the library, you represent that you have the right to store and use them in Berea. We process those files to make them readable in your workspace and, if you share them with a team, for that team’s members.

8. Who we share data with

Infrastructure subprocessors that host the app, API, database, auth, file storage, email delivery, and model inference. Typical categories include cloud hosting, Supabase (auth/database/storage), email transactional providers, and AI inference APIs. We require them to process data on our instructions and to apply appropriate security.

Team members and invitees you deliberately share with inside Berea.

Authorities when required by law, or professional advisors under confidentiality when needed to protect our rights or users’ safety.

We do not sell personal data. We do not share study content with data brokers for advertising.

9. International transfers

Our providers may process data in the United States, the European Economic Area, or other countries. Where required, we rely on appropriate safeguards (such as Standard Contractual Clauses) or adequacy decisions. You can ask us for more detail about the safeguards that apply to your region.

10. Retention

Account and workspace data are kept while your account is active. If you delete your account, we delete or irreversibly anonymize personal data within a reasonable period, except where we must retain limited records (billing disputes if any, security logs, or legal holds).

Agent threads and notes follow the same lifecycle as your workspace unless you delete them earlier. Backups are rotated on a schedule and expire after the backup window.

Local device data (for example layout pointers in localStorage) stays on your browser until you clear it or sign out; signing out clears Berea layout keys on that device so the next user is not shown your workspace arrangement.

11. Security

We use encryption in transit (HTTPS), access controls, row-level security patterns in the database where applicable, and least-privilege service credentials. No online service is perfectly secure; if you discover a vulnerability, please report it to privacy@tryberea.study or the security contact on the site.

12. Your rights

Depending on your location, you may have rights to access, correct, delete, or export your personal data; to object or restrict certain processing; and to withdraw consent. You may also lodge a complaint with your local supervisory authority.

To exercise rights, email privacy@tryberea.study from the address on your account. We may need to verify your identity. Team-owned documents may require coordination with the team admin before we can delete shared material still needed by others.

13. Cookies and similar technologies

We use essential cookies and local storage for authentication session, locale preference (for example berea-locale on the marketing site), theme, and study-layout memory scoped to your user id. These are required for the product to function as designed.

If we add optional analytics or marketing cookies, we will present a choice where required by law and list them here.

14. Children

Berea is aimed at adults and mature students capable of creating an account. We do not knowingly collect personal data from children under 16 (or the higher age required in your country) without appropriate consent. If you believe a child has registered, contact us and we will delete the account.

15. Changes to this policy

We may update this policy as the product evolves (new modules, providers, or legal requirements). The “Last updated” date at the top will change. Material changes will be highlighted on this page or notified by email when appropriate. Continued use after the effective date constitutes acceptance of the updated policy where permitted by law.

16. Contact

Privacy questions and requests: privacy@tryberea.study. Product site: https://www.tryberea.study. Workspace: https://app.tryberea.study.