PRIVACY POLICY

Privacy Policy

Last updated:

This Policy explains what information Bible Gacha / 聖書ガチャ collects or uses, why it is needed, how it is stored, and how external services may process it. It focuses in particular on Google sign-in, saving and syncing Collection, Favorites, and History, and the use of Google Analytics.

1. Operator and scope

The service is named “Bible Gacha / 聖書ガチャ.” It is operated by Ryotaro Takamatsu (the “Operator”). This Policy applies to the Bible Gacha website, sign-in features, online saving features, and other handling of information within the service.

2. Information we collect or use

Depending on the features you use, Bible Gacha collects or uses the following categories of information:

  • Account and authentication information: your email address, identifiers required for authentication that are provided by Google or another identity provider, account information in Amazon Cognito, and information required to maintain a sign-in session.
  • Service-use data: data required for saving and syncing features, such as your Collection, discovered verses, Favorites, History, draw activity, and related usage status.
  • On-device data: guest Collection, Favorites, History, and settings such as language, theme, sound, and vibration.
  • Access and technical information: page views, interaction events, device/browser information, and other information processed by services such as Google Analytics for service improvement and stable operation.

3. Google sign-in and account linking

Google sign-in is provided through Amazon Cognito using Google authentication. The Google scopes currently requested are openid and email. Bible Gacha handles the Google Account email address and authentication identifier needed for sign-in. It does not request access to the contents of Gmail, Google Drive, Google Calendar, or similar Google services.

Bible Gacha does not receive your Google Account password. Password entry and authentication are handled by Google.

If an email address that Google provides as verified matches an existing Bible Gacha account, the accounts may be linked so that the same user can continue using the existing Bible Gacha account and its data.

Google user data is used for sign-in, account identification, account linking, and the security and support activities directly required for those functions. If Bible Gacha changes how Google user data is used, this Policy and any required in-product disclosures will be updated.

4. Saving Collection, Favorites, and History

When you use Bible Gacha as a guest, data such as your Collection, Favorites, and History is stored primarily in browser storage such as IndexedDB. Clearing site data or changing devices can cause this local data to be lost.

When you sign in, data such as your Collection, Favorites, and History is stored and synchronized both on the device and in AWS. Data created while using Bible Gacha as a guest may be imported into the signed-in account when you choose to do so.

5. Google Analytics

Bible Gacha uses Google Analytics 4 (GA4) to understand usage and improve the service. Google may process information such as page views, aggregate interaction events, and device/browser information through GA4.

Bible Gacha is designed not to send email addresses, Amazon Cognito user IDs (sub), the contents of Favorites or History, or a per-user chronological sequence of Scripture browsing activity to Google Analytics. Google Signals and advertising-personalization signals are also disabled. While authentication tokens or other sign-in material are present in the browser session, the Google Analytics tag itself is not loaded.

Authentication pages (auth.html and oauth-callback.html) do not load Google Analytics. Login events are not sent from an authenticated browser context. Normal public pages may use analytics when the visitor is not signed in, according to this Policy.

How Google uses information from sites or apps that use its services

6. Cookies and browser storage

Bible Gacha may use cookies, IndexedDB, localStorage, sessionStorage, and similar browser technologies for sign-in state, authentication processes such as PKCE, preferences, on-device data, and analytics.

You can delete or restrict cookies and site data in your browser settings. Doing so may affect sign-in status, preferences, guest data, or other features.

7. Purposes of use

Bible Gacha uses the information it handles for the following purposes:

  • To provide sign-in, user identification, account linking, and authentication security.
  • To save and synchronize Collection, Favorites, History, and related data on-device or online.
  • To provide Scripture display, draws, search, and other service features.
  • To investigate problems, protect security, maintain the service, and improve features.
  • To measure and analyze usage in aggregate without intentionally sending directly identifying account information to Google Analytics.

8. External services

Bible Gacha uses the following external services where necessary to provide its features:

  • Amazon Web Services (AWS) / Amazon Cognito: authentication, account management, and online saving.
  • Google Sign-In / Google OAuth: sign-in with a Google Account.
  • Google Analytics: usage analytics.
  • API.Bible / FUMS: retrieval and display of Scripture text and related content, and the Fair Use Management System (FUMS) used to report Scripture usage. Through a Bible Gacha server relay, FUMS receives a token associated with the API request, random device and session identifiers, and, when signed in, a SHA-256 hash of the internal Amazon Cognito user ID (sub). Bible Gacha does not send email addresses or other directly identifying account information to FUMS.

These providers may process information necessary to provide their respective services. Their handling of information is also subject to their own terms and privacy policies. If Bible Gacha adds another sign-in provider or similar service in the future, this Policy will be updated.

9. Retention and security

The Operator seeks to apply reasonable safeguards appropriate to the nature of the information and the scale of the service, including encrypted communications, managed authentication infrastructure, and access controls. Bible Gacha is designed not to collect authentication secrets, such as your Google password, when they are not required to provide the service.

Information is intended to be retained only for as long as needed to provide the service, protect security, investigate incidents, fulfill the purposes described in this Policy, or comply with applicable legal obligations.

10. Account and data deletion

To request deletion of your account and online-saved data, contact the address in Section 11. Where needed, the Operator may verify your identity and will then provide instructions regarding the applicable data and deletion process. Information that must be retained for legal or security reasons may be kept only to the extent necessary.

Local guest data stored in your browser can be deleted using your browser’s site-data controls.

11. Contact and changes to this Policy

For questions about this Policy, personal data, or account/data deletion, contact takamatsu11919911@gmail.com.

This Policy may be updated when features, external services, laws, or applicable policies change. If there is a material change in how Google user data is used, Bible Gacha will update the relevant disclosures and, where required, notify users and obtain renewed consent before using the data for the new purpose.