Daily Bread Chrome Extension

Privacy Policy

Last updated: September 4, 2026

Daily Bread is a Chrome extension that displays a daily Bible verse when you open a new tab. This policy separates the product and account information needed to provide the extension from the optional analytics information used to improve it.

Product and account information

Daily Bread stores your Bible translation, theme, schedule and related product preferences in Chrome storage so the extension can work locally. Configured reminder times are product settings and are not analytics properties.

Signing in is optional. If you sign in by email or Google, Firebase Authentication processes your email address, authentication information and available profile name. Daily Bread can sync your translation, theme and schedule preferences to your Firebase account. The Firebase account identifier and account information are not linked to analytics.

To display Bible, devotional, prayer and video material, Daily Bread requests the selected material from Firebase and the applicable Bible or YouVersion service. Those product requests are separate from the analytics described below.

Your analytics setting

Analytics is on by default. For a new installation it starts when you press Continue on the Welcome screen. For an installation that already existed when this version arrived, it starts the next time Daily Bread opens. Closing Welcome without pressing Continue leaves it off until you do. Nothing is backfilled. One switch in Settings covers both final aggregate counts and the optional recent-action timeline, and Daily Bread opens Settings once after your first verse so you can see it. Turning it off stops both streams immediately.

Turning the switch off stops both streams immediately, clears ordinary analytics still only on this device, and schedules deletion of the random timeline. The same switch and the full details appear in Settings.

Final aggregate counts

Daily Bread can count bounded feature outcomes such as meaningful verse views, Settings and Go Deeper use, devotional, video, prayer and chapter use, theme or translation changes, reminder outcomes, schedule categories, account-state categories, failures, Done and coarse return patterns.

Aggregate reporting uses no installation Person. Person processing and geolocation enrichment are disabled. A total is a count for one metric date, metric and dimension value. It carries no installation, account, session or content identifier.

Daily totals are published once per day, contain no identifier, and are not linked from one day to the next. On a day with very few users, a total may reflect a single installation. Several small totals for one date may describe an unnamed installation's day at the granularity of the bounded categories. An anonymous contribution already accepted by the relay cannot be separated back out.

Recent-action timeline

A separate random installation profile can record the order of Daily Bread actions. The complete categories are: experience start and end; meaningful verse view; Go Deeper request, open, close, page kind, position, count and navigation direction; video source, duration range, progress, completion or bounded failure category; original-link open; Settings source; schedule discovery; changed preference type; Easter egg activation; bounded feature failure category; Done; and the ending reason, last Daily Bread surface and elapsed-time range.

The timeline accepts only those 18 named event categories, their closed bounded properties, sequence numbers, a bounded extension version and 15-minute occurrence windows. It rejects arbitrary events, properties, metadata, strings and exact action times. A date and approximate time can still create inference risk about use of a religious product.

The random timeline is not a Firebase account, advertising identity, fingerprint or hardware-derived device identity. Its sole PostHog Person property is an authorization fence. Daily Bread does not cross-reference the random profile with Firebase accounts, websites, support records, content, schedules or another identifying dataset.

Relay, providers, access and exact timestamps

When analytics is on and the production service is available, Daily Bread sends accepted analytics to a first-party relay hosted on Google Cloud and Firebase in the EU region. The relay keeps the aggregate and timeline streams separate and sends their allowed outputs to separate PostHog Cloud EU projects. The extension does not contact PostHog directly and does not load PostHog's browser library.

Routine timeline review is available only to Ed through a locked first-party gateway with Google sign-in and MFA. It shows ephemeral aliases and bounded fields, does not expose raw epoch identifiers across responses, and provides no arbitrary timeline export. Routine provider UI access to the timeline project is prohibited.

PostHog and authorized break-glass provider administrators can technically access exact provider ingestion timestamps; Daily Bread processes the latest exact value only inside its locked review query to derive one quarter-hour-or-coarser epoch freshness bucket and never exposes, exports, or analyzes the value at exact granularity.

The event occurrence timestamp supplied by Daily Bread is already the 15-minute action bucket. It is different from PostHog's technical exact ingestion timestamp.

Network metadata, logs and operational data

Hosting infrastructure transiently processes an IP address to deliver and protect a relay request. Daily Bread does not store or forward an IP address as an analytics property. A purpose-separated transient digest may exist only for one bounded rate-limit window and is then purged.

Analytics platform logs exclude request and response bodies, identifiers, credentials, secrets, exact events and raw errors and use bounded platform retention. Operations telemetry contains only a schema version, one of five route labels, one of ten coarse outcomes and a count. It contains no request value or identifier.

Enrollment responses and provider outbox payloads are encrypted at rest. Purpose-separated HMAC addresses protect the bounded receipts, caps, deduplication records, review records and audit addresses that require them.

Information excluded from analytics

Analytics does not collect host-page URLs or titles, referrers, DOM or form contents, browser history, Bible text, devotional or prayer text, media URLs or content, tab, frame or sender metadata, precise location, email addresses, Firebase UIDs, Google subjects as analytics, account content, exact schedules, free-form errors, stack traces, advertising or device identifiers, keystrokes, autocapture, screenshots, recordings or session replay.

Daily Bread does not use analytics for ads, sale of data, targeting, fingerprinting, account linkage, engagement scoring, experiments, feature flags or AI analysis. It uses the bounded information only for internal product improvement and service safety.

Dashboard meaning and populations

Daily Bread uses five dashboard units:

Live timeline charts cover only the self-selected timeline-sharing cohort and are not representative of all installations. Final charts use privacy-filtered installation-days after aggregate closure. Daily Bread does not combine a live-cohort numerator with a final-aggregate denominator. Final charts sum the released count values rather than event rows or PostHog Persons.

Retention and aggregate clocks

For an aggregate metric date, D means that date at 00:00:00 UTC and does not claim to be the installation's local midnight. The earliest accepted receipt is D minus 14 hours. The submission cutoff is D plus 7 calendar days and 12 hours. Normal close is D plus 8 calendar days and 12 hours. A fixed 48-hour close retry grace does not admit new contributions. From the earliest permitted receipt, aggregate temporary state has an 11-day-2-hour maximum.

Daily Bread keeps final first-party aggregate totals for 24 calendar months, then atomically excludes and purges its own copies. PostHog keeps its aggregate copy under its plan retention, currently up to seven years, and its published deletion and backup practices. Daily Bread does not control that provider retention and does not claim that PostHog physically deletes aggregate cells after 24 months.

Timeline events waiting only on the device retry for up to 24 hours. A random timeline epoch lasts no more than 90 days, then review is fenced and asynchronous deletion of the PostHog Person and associated events begins. After full confirmation, a minimal non-action deletion proof may remain for up to 120 days to detect reappearance.

Turning analytics off, reset and re-enable

Turning analytics off in Settings stops new aggregate and timeline capture immediately, clears ordinary unsent analytics data on the device, revokes the random timeline and schedules its Person and events for deletion. Already-requested revocation, deletion, expiry and reconciliation continue as privacy work even while capture is off.

If enrollment never started, analytics can be enabled later. If an enrollment was active or uncertain, re-enable stays blocked until deletion or absence is confirmed. Re-enable then creates a fresh random timeline that is not linked to the old one, and nothing is backfilled.

A Daily Bread clear-storage action starts analytics shutdown before clearing product state. If the browser is offline, server deletion cannot finish until a later connection. If the extension is uninstalled or its browser-managed data is erased before the deletion request leaves the device, Daily Bread can lose the local receipt needed to finish that request. The server-side 90-day expiry and deletion process remains the fallback.

Settings reports the current state as one of these exact statuses: On; On; sharing will begin when connected; On; timeline delivery delayed; On; sharing temporarily unavailable; Refreshing the random timeline…; Off; Turning off…; Turning off and deleting timeline…; Deletion delayed; retrying; Review new analytics information; or Analytics unavailable.

Review records and access retention

Review sessions expire after 15 idle minutes or 60 absolute minutes and cannot outlive the verified Google credential. Daily Bread attempts synchronous deletion on logout, replacement, expiry and cleanup. Physical cleanup has a two-hour target with readback and alert. A managed database TTL backstop whose deletion tail is typically within 24 hours is required before launch but is not configured in this draft's code state.

Review access audit records contain no raw account identity or PostHog Person identifier. They have a 30-day deadline, daily day-31 purge and readback, and a day-32 alert. Provider break-glass access requires paired first-party and provider-native evidence, has a 90-day audit deadline, and is restricted to the Ed security-reader boundary.

Your choices and rights

You can use Daily Bread without signing in. You can view and change local preferences in Settings, turn analytics off, and request help with access, correction or deletion of account information. Depending on applicable law, you may also have rights to restriction, objection, portability, withdrawal of consent and complaint to a data protection authority.

Turning analytics off is the withdrawal mechanism for future collection. Daily Bread cannot identify and remove one anonymous contribution after the relay has accepted it. Contact us to exercise an applicable right or ask how it applies to product, account or analytics information.

Contact and policy changes

Email: e.kibomaseeds@gmail.com

If this policy changes, Daily Bread will update the date above. A material analytics notice change stops capture and requires a new choice before collection can resume.