Legal
Privacy Policy
Last updated 31 July 2026
1. Who this policy is from
Scholia ("Scholia", "we", "us") is operated by an individual, not a company, as a free and non-commercial project. For anything in this policy - questions, requests, complaints - write to clement@ishimwe.dev.
2. What we collect
Three things, and nothing beyond them:
- Your account. Your email address, and a password if you signed up with one. Passwords are handled by our authentication provider and stored as hashes - they are never visible to us. If you sign in with Google instead, Google tells us your email address and basic profile details; we never receive your Google password.
- Your notes. The titles and contents of the notes you write, the verses you attach to them, and the times they were created and last changed.
- API keys. If you create a key for scripts, we store its label, its permissions, its creation and expiry times, and a hash of the key. The key itself is shown once and never stored in a readable form.
We do not ask for your name, your address, your phone number, your church or your date of birth. We do not collect payment details, because there is nothing to pay for.
3. Technical data and analytics
- Sign-in session. Your browser stores a session token so you stay signed in between visits. It is strictly necessary for the app to work; clearing your browser storage signs you out.
- Analytics. We use Vercel Analytics and Speed Insights to count page views and measure page loading performance. It records the page visited, the referring site, and coarse device, browser and country information. It sets no advertising cookies and does not follow you across other websites; the results we see are aggregate counts, not a profile of you.
- Server logs. Our hosting providers keep short-lived operational logs, which include IP addresses, for security and debugging. We do not use them to build a picture of individual users.
4. Why we hold it
To sign you in and keep you signed in; to store your notes and give them back to you on your next visit; to let scripts you have authorised reach your own data; to keep the service secure and working; and to understand, in aggregate, whether the site is being used and whether it is fast enough. That is the whole list.
5. Who else processes it
Scholia is a small project and it stands on other people's infrastructure. These providers process data on our instructions, and only to run the service:
- Supabase - accounts, sign-in and authentication tokens.
- Vercel - hosting for this website, plus the analytics described above.
- Render - hosting for the API server and the database that holds your notes.
- Google - only if you choose to sign in with Google, and only to the extent needed to complete that sign-in.
We do not sell your data, rent it, trade it, or hand it to advertisers or data brokers. We would disclose data only if we were legally required to, and never as a matter of routine.
6. Where your data lives
These providers run their servers outside Rwanda, mainly in the European Union and the United States, so your data is stored and processed abroad. By using Scholia you understand that this is where the service runs.
7. How long we keep it
Your notes stay until you delete them or ask us to close your account. A deleted note is removed from the live database; backups taken before the deletion may retain a copy for a short period until they roll over. Revoked API keys are kept as revoked records so an old key cannot be reused.
8. Your rights
You can ask us to:
- tell you what we hold about you;
- send you a copy of your notes in a machine-readable form;
- correct anything that is wrong;
- delete your account and everything attached to it.
Email clement@ishimwe.dev from the address on your account and we will act on it. There is no charge, and no attempt will be made to talk you out of leaving. Depending on where you live, you may also have the right to complain to a data protection authority.
9. Security
Traffic to the site and the API is encrypted in transit. Passwords and API keys are stored as hashes, never as readable text. Access to your notes requires a token issued to your account. No system is perfect, and this one is maintained by one person - if you would not want something read by anyone else under any circumstances, think twice before typing it into any web app, including this one.
10. Children
Scholia is not directed at children under 13, and we do not knowingly create accounts for them. If you believe a child has signed up, write to us and the account will be removed.
11. Changes to this policy
If this policy changes, the date at the top of the page changes with it. If a change is significant - a new processor, a new category of data - we will say so clearly in the app rather than quietly editing the text.
See also our Terms of Use and the sources and licences behind the study data.