Rhema - Privacy Policy
Last updated: 12 July 2026
1. Introduction
This Privacy Policy explains how Rhema collects, uses, shares and protects personal data. Rhema is a real-time scripture detection service for churches: a desktop application that listens to live sermon audio, detects Bible references (direct quotes, paraphrases and allusions) and displays or sends the corresponding verse text to your presentation or output system.
This policy is written in UK English and is governed by the laws of England & Wales. It covers the personal data for which Rhema is itself responsible. Where Rhema processes data on behalf of a subscribing church, a separate agreement governs that processing - see section 2.
2. Who we are and our role
Rhema was founded by David Adebiyi - a software engineer and serial entrepreneur who joined his church’s technical team at 14 and still actively serves today. David built Rhema to automate the repetitive processes and streamline operations that every church technical department faces. His mission: build a tool for the house of the Lord that provides genuine value for every team behind the service.
Rhema is operated by David Adebiyi, trading as Rhema, a sole trader established in the United Kingdom. (Rhema is not currently incorporated as a limited company; this section will be updated if that changes.)
How to contact us:
- All queries (privacy, legal, support): hello@rhema.store
- Website: rhema.store
Our dual role
Rhema acts in two distinct capacities, and it matters which one applies to a given piece of data:
-
Processor (sermon and detection content). When the application captures live sermon audio, transcribes it, detects scripture and produces transcripts and detection traces, Rhema processes that content on behalf of, and on the instructions of, the subscribing church (the “Customer”). The Customer is the controller for that content. This processing is governed by our Data Processing Agreement (DPA), provided to subscribing churches on request - not by this policy.
-
Controller (account, billing and website data). When we handle the personal data of account holders, billing contacts, support contacts and website visitors, Rhema is the controller. This policy governs that processing.
This split is important because sermon content is religious in nature and may reveal religious or philosophical beliefs (a “special category” of data under UK GDPR Article 9 - see sections 3 and 4). For that content the Customer is responsible for the lawful basis and the Article 9 condition (typically the not-for-profit religious-body condition under Article 9(2)(d), or explicit consent); Rhema processes it only as a processor under the DPA.
3. The personal data we collect, and why
The table below covers the data for which Rhema is the controller. For sermon/detection content (where Rhema is a processor), see section 4 and the DPA.
| Data category | What it includes | Purpose | Lawful basis (UK GDPR) |
|---|---|---|---|
| Account & contact details | Name, email address, organisation/church name, role | Create and administer your account; authenticate you; communicate about the service | Art. 6(1)(b) performance of a contract |
| Billing data | Subscription tier, seat count, transaction records, billing email. Card data is handled by Stripe - Rhema never stores card numbers | Take payment, manage subscriptions, issue invoices | Art. 6(1)(b) contract; Art. 6(1)(c) legal obligation (tax/accounting) |
| Licence & device identifiers | Licence key, machine fingerprints (a random per-device UUID - not a hardware serial), seat bindings, tier | Enforce licensing and seat limits; bind devices to your subscription; prevent misuse | Art. 6(1)(b) contract; Art. 6(1)(f) legitimate interests (licence integrity) |
| Usage metering | Cloud-transcription seconds consumed per month, per seat | Enforce included hours (8 hrs/seat/month), show remaining hours, meter top-ups | Art. 6(1)(b) contract; Art. 6(1)(f) legitimate interests (fair use) |
| Support communications | Emails and messages you send us, and our replies | Provide support; resolve issues; keep a record | Art. 6(1)(f) legitimate interests (assisting customers) |
| Operational/diagnostic logs | Session metadata, transcript text and detection traces (Pro/Max), retained for support, debugging and reliability | Diagnose faults, improve detection reliability | Art. 6(1)(f) legitimate interests (service reliability). Where logs contain sermon content, Art. 9(2) conditions are the Customer’s responsibility as controller |
| Website / cookie data | See section 10 | Operate and secure the website | Art. 6(1)(f) legitimate interests; consent for any non-essential cookies |
We collect this data directly from you when you sign up, subscribe, use the application or contact us, and (for billing) via Stripe.
4. Audio transience - how live audio is handled
We have designed Rhema so that congregation audio is never retained:
-
Free tier - fully offline. All audio is captured and processed on the device, using on-device (offline) voice detection and local matching. No audio or transcript leaves the device. Bible text is limited to the King James Version (public domain).
-
Pro / Max - audio is transient. Live sermon audio is streamed to a cloud speech-to-text provider for real-time transcription. Audio is processed in transit and is not stored or retained by Rhema or that provider. Short transcript windows are sent to an AI verification provider to confirm matches; matched verse text is retrieved from a Bible-text provider. Max adds real-time display translation (via a machine-translation provider) and text-to-speech (via a voice provider).
-
Transcripts on the device. During a session, the session transcript is stored locally on the Customer’s machine and is discarded when the application closes.
-
No recordings. Rhema does not retain recordings of congregation or sermon audio.
The only sermon-derived text that may persist with Rhema is in operational/diagnostic logs (Pro/Max), retained for a limited period - see sections 3 and 8.
5. Our lawful bases for processing
We rely on the following lawful bases under UK GDPR Article 6:
- Performance of a contract (Art. 6(1)(b)) - to provide the service to account holders and subscribers: account administration, licensing, seat and usage management, and billing.
- Legitimate interests (Art. 6(1)(f)) - for licence integrity, fair-use metering, service reliability and diagnostics, security, and responding to support requests. We have weighed these interests against your rights and consider them proportionate: the data involved is limited, expected by users of a licensed B2B service, and not used for any purpose you would not reasonably anticipate. You may object at any time (see section 9).
- Consent (Art. 6(1)(a)) - for any marketing communications and for any non-essential cookies. You may withdraw consent at any time.
- Legal obligation (Art. 6(1)(c)) - to retain billing and tax records as required by UK tax and accounting law.
For special-category (religious) content within sermon material, the relevant Article 9 condition is determined and met by the Customer (church) as controller; Rhema processes such content only as a processor on the Customer’s instructions.
6. Who we share data with (recipients and processors)
We do not sell personal data. We share it only with service providers (“processors”) who act on our instructions, and where required by law. To protect our supply chain and our customers, we describe these providers by capability rather than name in this public document; the full named list of sub-processors is set out in our Data Processing Agreement, provided to subscribing churches on request.
We use:
- Stripe - our payment processor (you transact with Stripe directly; Rhema does not store card data).
- A cloud speech-to-text provider - real-time transcription of live audio (Pro/Max; audio not stored).
- An AI verification provider - confirming scripture matches from short transcript windows (Pro/Max).
- A Bible-text provider - retrieving matched verse text (Pro/Max).
- A machine-translation provider - real-time display translation (Max).
- A text-to-speech (voice) provider - spoken output (Max).
- Our hosting/infrastructure provider - storing licence data, usage metering and operational logs.
- Our email delivery provider - transactional and support emails.
We may also disclose data to professional advisers, or to authorities, where required to comply with the law or to establish, exercise or defend legal claims.
7. International data transfers
Several of our processors are located in the United States. Where we transfer personal data outside the UK, we put appropriate safeguards in place: the UK International Data Transfer Addendum to the EU Standard Contractual Clauses, or the UK International Data Transfer Agreement (IDTA), together with the providers’ own technical and organisational safeguards. Rhema does not route this processing through EU-only endpoints. You can ask us for details of the safeguards used by contacting hello@rhema.store.
8. How long we keep your data
| Data category | Retention period |
|---|---|
| Billing & tax records | Approximately 6 years, as required by UK tax and accounting law |
| Account & contact details | For the life of your subscription, then a short wind-down period |
| Licence & device identifiers | For the life of the subscription, plus a short period afterwards |
| Usage metering | For the life of the subscription (monthly figures; unused hours do not roll over) |
| Operational/diagnostic logs (incl. transcript text & detection traces) | 30 days, then deleted or anonymised |
| Support communications | As long as needed to handle the matter, then a reasonable archival period |
| On-device session transcripts | Held locally during a session only; discarded when the app closes |
We do not retain congregation audio recordings at all.
9. Your rights
Where Rhema is the controller, you have the following rights under UK GDPR:
- Access - a copy of the personal data we hold about you.
- Rectification - correction of inaccurate or incomplete data.
- Erasure - deletion of your data in certain circumstances.
- Restriction - limiting how we use your data in certain circumstances.
- Portability - receiving certain data in a portable, machine-readable format.
- Objection - objecting to processing based on legitimate interests, and to direct marketing at any time.
- Withdraw consent - where we rely on consent (e.g. marketing, non-essential cookies), at any time, without affecting prior processing.
- Complain to the ICO - see section 12.
To exercise any of these rights, email hello@rhema.store. We will respond within one month (extendable by two further months for complex requests, and we will tell you if so). There is normally no charge.
Where the data relates to sermon/detection content, Rhema is a processor and the church is the controller. If you are a member of a congregation, please direct such requests to your church; we will support the church in responding.
10. Cookies and analytics
We keep tracking to a minimum. The Rhema desktop application does not use advertising or third-party tracking cookies.
For the rhema.store website, we use two categories of cookies:
Essential cookies (always active)
These are strictly necessary to operate and secure the site. They include your cookie-consent preference. No consent is needed for these under UK GDPR.
Analytics cookies (consent required)
When you click “Accept” on our cookie banner, we load PostHog, a product analytics platform, which collects the following:
| Data | Purpose |
|---|---|
| Page views and navigation paths | Understand which pages visitors find useful and where they drop off |
| Click and scroll interactions | Learn which features and content attract the most interest |
| Session recordings | Replay anonymised visits to identify usability issues (password fields are always masked) |
| Heatmaps | Visualise where visitors click and scroll on each page |
| Page performance metrics | Monitor load times and rendering performance |
| Referral source and UTM parameters | Understand how visitors find us (search, social, direct link) |
| Device, browser and operating system | Ensure the site works well across platforms |
| Approximate geographic region | Derived from IP address; we do not store raw IP addresses |
| Session duration and page-leave timing | Measure engagement and identify pages that need improvement |
We do not use cross-site tracking, advertising cookies, or retargeting pixels. PostHog data is hosted in the European Union (Frankfurt, Germany).
If you click “Accept Essential”, no analytics cookies are set and PostHog is not loaded. You can change your preference at any time by clearing your browser’s local storage for rhema.store and refreshing the page.
11. Children
Rhema is a business tool for churches and their operators and is not directed at children. We do not knowingly collect personal data from children through our account, billing or website services.
Any personal data relating to members of a congregation (including children) that may arise within sermon content is handled by the church as controller, under its own lawful basis and Article 9 condition, and is governed by the DPA - not by this policy.
12. Changes, contact and complaints
Changes to this policy. We may update this policy from time to time. When we make material changes, we will update the “Last updated” date above and, where appropriate, notify you. Please review it periodically.
Contact us. For any privacy, legal or support question, email hello@rhema.store. We ask that you give us the opportunity to resolve any concern first.
Complain to the ICO. If you are not satisfied, you have the right to complain to the UK supervisory authority:
Information Commissioner’s Office (ICO) Website: ico.org.uk Helpline: 0303 123 1113
Raising a complaint with the ICO does not affect any other legal remedy you may have.