AskScripture

Privacy

What happens to your question

People ask this app things they would not say out loud. That earns a straight answer about where those questions go — including the parts that are not reassuring. Everything below was checked against Microsoft's published terms and against our own live configuration on 16 August 2026, and anything we could not verify has been left off the page rather than softened into something vaguer.

This page is about the questions you ask. The company-wide policy covering accounts, payments, and your legal rights is at deepanchorstudio.com/privacy.

Where your question goes

Your question is sent to Microsoft's Azure OpenAI service, running in Microsoft's own Azure environment. It is not sent to OpenAI, and it never touches ChatGPT or the OpenAI API.

Your questions are processed in the United States, in Microsoft's East US region.

We authenticate to that service with a managed identity — there is no shared API key sitting in configuration that could leak.

To show you what Christian thinkers have said on video, your question text — and only that — also goes to TypeSafe, which matches it with what they have said and checks the quality of those answers. TypeSafe never receives your name, email, or profile. TypeSafe does not train or fine-tune any AI models on your questions, and its service is hosted in the United States (checked against TypeSafe's privacy policy on 27 September 2026). To improve answers, we may keep a reworded, anonymous version of a question, with personal details removed. It is never linked to your account.

It is not used to train AI

Microsoft does not use your questions or the answers to train or improve any AI model — not OpenAI's, not Microsoft's.

The model itself is stateless. It does not remember your question after it answers it.

What can be stored, and who can read it

This is the part most apps leave out, so read it carefully rather than skipping to the end.

Microsoft runs automated abuse monitoring on the service. If its systems flag a question or an answer as potentially abusive, a sample can be stored and reviewed — by automated systems first, and in some cases by authorized Microsoft employees. That store sits in the same US geography, is separated by customer, and reviewers can only reach content that has already been flagged, through audited just-in-time access.

We have not applied for, and do not have, Microsoft's "modified abuse monitoring" exemption, which would turn that storage off.

What matters most about that storage is what is not in it. We do not attach anything to your question that identifies you — not the name on your account, not your email address, not your device, not any account identifier. There is nothing in what we send that ties a question back to you, or that links two questions to the same person. What travels with your question is the profile detail used to write the answer — a first name if you entered one, an age range for a child, the faith background you chose — and a first name you typed yourself is not an identity.

So the honest summary is not "nothing is ever stored." It is: nothing you ask is used to train anything, nothing goes to OpenAI, nothing we send identifies you, and a flagged sample can be stored and read under those specific conditions.

What we are not claiming

A privacy page is only worth reading if the things it does not say are as deliberate as the things it does. These are claims we could easily have made and did not:

  • We do not publish a deletion timeline. You will see "deleted after 30 days" on a lot of pages like this one. We could not verify a figure we would be willing to stand behind, so we do not print one — and we are not printing "briefly" or "temporarily" either, which is the same unverified claim with the number taken off.
  • We do not claim "zero data retention." We do not have the arrangement that phrase would refer to. See the section above.
  • We do not claim your questions are never seen by a human. Human review is conditional, not impossible, and saying otherwise would be false.

If we obtain a documented answer on retention, it goes on this page with its date, and this section shrinks.

Voice conversations, and what happens to the audio

A voice conversation sends your microphone audio, live, to two services: LiveKit, which carries the call, and Microsoft Azure Speech, which turns speech into text and turns the reply back into speech.

The text of what you said then goes to a different part of the system than a typed question does. A typed question goes to our answer endpoint, which returns a written answer and can pull verse text from a licensed Bible translation. A spoken question goes to a live conversation session, which is built for back-and-forth and has no verse-lookup step — which is why the app tells you to read the written answer when you want the exact words of a passage. We describe the difference rather than smooth it over, because it is a real one.

What is the same is the part this page is about: both paths run on the same Microsoft Azure OpenAI service, under the same terms, so Where your question goes, It is not used to train AI and What can be stored, and who can read it apply to a spoken question exactly as they apply to a typed one. Beyond LiveKit and Azure Speech, named above, the voice path introduces no further provider and no additional storage.

We do not record your voice. The app has no recording feature, and nothing in our service writes the audio to a file, a database, or storage of any kind. There is no recording to keep, and so there is nothing for us to retain: our retention period for voice audio is none, because we never hold a copy. The audio is processed as it streams and is gone when the conversation ends. What can outlive the call is the text transcription, under the conditions described in What can be stored, and who can read it — the same conditions that apply to a typed question, and no others.

Nobody's voice is identified, matched, or enrolled. We do not create a voiceprint. We do not use speaker recognition, speaker identification, or speaker separation, and we do not attempt to work out who is speaking, their age, their gender, or their emotional state from how they sound. Your audio is used to work out what was said, and for nothing else. This is a property of how the system is built, not a promise about how we intend to behave: the capability is not enabled anywhere in our voice path.

Voice is not offered on a child profile. When a question is being asked about a child, the app does not present a voice conversation at all, and when the app tells our server that a session is on a child profile, the server refuses it before any microphone stream can begin. That refusal is not a setting a parent can turn off, and it is not something a subscription unlocks.

The honest limit on that second sentence: the server can only refuse what it is told about, and app versions released before this check existed do not send the profile with the request. For those versions the protection is the app itself — it does not offer the voice control on a child profile — rather than a server refusal behind it. We are measuring how many requests still arrive without a profile, and the server-side refusal becomes unconditional once that number reaches zero. We would rather state that plainly than describe an enforcement that is one release ahead of the phones it runs on.

As with the rest of this page, the parts we cannot verify are named rather than smoothed over: what we control is that we take no copy, and that no voice is ever identified or matched. What LiveKit and Microsoft do inside their own systems is governed by their terms, and we do not publish a number for it that we have not been able to confirm.

Your profiles and saved answers

Your saved answers and the profiles you set up — for yourself, a child, or a friend — are stored on your device, under a key scoped to your account. Your device is the copy the app reads from.

They are also copied to our server. An earlier version of this page said they were not, and that was wrong; it is corrected here. Whenever a profile or a saved answer changes, the app sends the current set to our sync endpoint, which stores it in Google Firestore against your account id. The purpose is restoring your profiles and saved answers when you reinstall the app, sign in on another device, or sign back in after signing out — which is also why signing out clears the copy on the device but not the copy on the server.

Two details that are easy to get wrong, so we state them exactly:

  • Profiles are stored for every signed-in account. That includes the names and any details you enter into a profile for a child or a friend.
  • Saved answers are stored for subscribers only. On a free account the app still transmits them with the profile, but the server does not write them — they are dropped on receipt and only the profile is kept.

Nothing else about you is in that record: no question history, no conversation text, and no voice. The app has no direct access to the database — every read and write goes through an endpoint that requires your signed-in session — and the record is keyed to your account id rather than to your device.

What we cannot yet claim here: the app does not currently offer an in-app control that deletes this server-side copy, and we are not going to describe a retention period we do not enforce. Until that control ships, deletion is a request to support@deepanchorstudio.com, and we will say so plainly rather than imply the record expires on its own.

The one other thing we send

Along with your question, the app sends your device's language-and-region tag — for example "en-US" or "en-GB". It is used for exactly one purpose: choosing which crisis resource to show if a question is classified as a safety concern. The app does not request or use your location. That is described in full in our crisis protocol.

Worth being precise about, because it is a safety matter rather than a privacy one: that tag is a formatting preference, not a statement of where you are. Someone in Britain whose phone is set to "en-US" is a perfectly ordinary configuration. So the app never treats the tag as proof of location — whenever it shows or speaks a resource that only answers in one country, it shows the international directory alongside it, so a route that works where you actually are is always present.

When this page changes

The claims above are true of a specific configuration, not of "AI" in general, so they are re-checked when that configuration changes — a different model or region, a change to how the service is authenticated, or a change in Microsoft's published terms. The verification date at the top of this page is the date of the last check, and it moves only when a check is actually done.


Questions about any of this go to support@deepanchorstudio.com.