This page explains what Cella collects about you, why, how long it is kept, and what you can do about it. It is written to be read, not skimmed past. If something here is unclear, ask and it will be fixed.
The short version. Cella needs an email address and a password to give you an account. Everything else about your reading is optional and off by default. Cella does not sell anything, does not advertise, and runs no third-party analytics. You can download everything Cella holds about you, or delete all of it, from inside the app. New accounts can only be created in the United States for now.
Cella is built and run by David Whitlow, a sole owner based in the United States. He decides what is collected and why. That is one person, not a company department.
Cella is a United States service for now. New accounts can only be created from the United States and its territories: Puerto Rico, the US Virgin Islands, Guam, American Samoa, and the Northern Mariana Islands. If you are somewhere else and you try to sign up, Cella will turn you away.
Three things follow from that, and they are worth saying plainly.
This is the complete list. Nothing is collected that is not named here.
| What | Why |
|---|---|
| Email address | To identify your account, verify it, and send password resets |
| A hash of your password | To check your password at sign-in |
| Account creation and last-login timestamps | To run the account and show you when it was last used |
| Birth year, asked once at signup | An age check. See section 12. |
| Founding member status and plan expiry date, for the first 100 verified readers | To give you the founding membership you paid for |
Cella never stores your actual password. A hash is a one-way scramble. It can confirm a password you type is the right one, but it cannot be turned back into your password.
| What | Why |
|---|---|
| Session records: when a session was created, last seen, and when it expires, plus the IP address and browser user-agent string used | To keep you signed in, and to let you see and end sessions that are not yours |
| An authentication log: sign-ins, failed attempts, and password resets, each with IP address and user-agent | To detect and investigate someone trying to break into an account |
| A second-factor secret, only if you turn on an authenticator app | To check your six-digit codes |
This is the security minimum. An app that cannot tell a sign-in from a break-in cannot protect your account. It is kept narrow and it is deleted on the schedule in section 8.
| What | Why |
|---|---|
| Feedback notes you submit | To read what you said and improve the app |
| What | Why |
|---|---|
| Which Bible passages, books, chapters, verses, words and sources you open, with timestamps and how long you stayed | To show you your own reading history and progress inside the app. Collected only if you give separate consent. |
Section 4 explains this one properly.
United States law does not treat a record of what you read in the Bible as anything unusual. There is no federal rule that makes it a protected category, and no state rule that stops an app collecting it quietly and calling it product usage. Cella treats it as protected anyway. That is a choice, not a legal requirement, and it is worth saying which one it is.
The reason is simple. A list of the passages you opened, in order, with how long you sat on each one, is a record of what you were wrestling with. Grief has a reading pattern. So does doubt, and shame, and a decision someone has not told anyone about yet. What a person reads in Scripture is nobody's business but theirs. It is not product usage data, and Cella will not pretend it is just because the law would let it.
So:
Cella does not sell data, does not share it for advertising, and runs no third-party analytics. There is no advertising network, no tracking pixel, no analytics vendor.
Two companies handle data on Cella's behalf, and only on Cella's instructions:
| Who | What they handle |
|---|---|
| Cloudflare, Inc. | All hosting. The site (Pages), the application code (Workers), the database (D1), and file storage (R2). Everything described on this page lives on Cloudflare. |
| Resend | Sending email, and only two kinds: account verification and password resets. Resend sees your email address. No marketing email is sent through it, or at all. |
Beyond those two, your data may be disclosed only where the law requires it, for example a valid court order. If that happens and Cella is permitted to tell you, it will.
Cella is run from the United States and your data is held there. Cloudflare and Resend both run global networks, so data can pass through or sit on servers in other countries as part of how those networks work. That is a fact of using this app and it is stated here rather than buried.
| What | How long |
|---|---|
| Account data: email, password hash, birth year, timestamps, founding member status, second-factor secret | For as long as your account exists. When you delete your account it is removed immediately and completely, not after a delay. |
| Session records | Until the session expires or you sign out, then removed |
| Authentication log | 12 months from the entry, or immediately when you delete your account, whichever comes first |
| Reading log | 24 months from each entry. Deleted immediately and in full if you withdraw consent, and deleted with your account. |
| Feedback notes | 24 months, or until you ask for them to be removed |
Deleting your account is immediate and cannot be undone. There is no waiting period in which it could be recovered, by you or by us. Please be sure before you confirm it.
These are open to every reader, wherever you are, whether or not a law where you live requires them.
These are built and working, not promises.
Use the address in section 1. You will get an answer within 30 days.
California's privacy law applies to a business only if it meets at least one of three thresholds. Under California Civil Code section 1798.140(d), a business must either have had annual gross revenues over $25,000,000 in the preceding calendar year, or annually buy, sell, or share the personal information of 100,000 or more consumers or households, or derive 50 percent or more of its annual revenues from selling or sharing consumers' personal information.
Cella meets none of the three. It is a free app with no revenue at all, it is nowhere near 100,000 consumers, and it does not sell or share personal information, so the third threshold is zero by definition. So the CCPA does not currently apply to Cella.
Two things about that. First, the rights it would have given you are in section 9 anyway, because they should be. Second, if Cella ever crosses one of those lines, this page will say so and the formal California rights will be written out in full.
The Children's Online Privacy Protection Rule (16 CFR Part 312) covers personal information collected online from children under 13. Cella is a general audience app: it is not directed at children, and it does not knowingly collect anything from anyone under 13. Section 12 explains the age check that keeps it that way.
Every US state has a law requiring notice when personal information is exposed in a security breach. The details vary by state, including how fast notice has to go out and who else has to be told. If your data is ever caught up in a breach, Cella will notify you as required by the law of your state, and will tell you what happened plainly rather than in the language these notices are usually written in.
There is none. Cella does no automated decision-making and no profiling. Nothing about your account, your access, or what you are shown is decided by an algorithm reading your data.
You have to be at least 13 to have a Cella account.
Signup asks for your birth year once. If the year you give makes you under 13, the account is not created. The reason for the line is COPPA (16 CFR Part 312), which governs the online collection of personal information from children under 13.
If you believe a child under 13 has an account here, email the address in section 1 and it will be deleted along with everything attached to it.
Please raise it with Cella first. It is one person and he would rather fix it than have you go elsewhere. Use the address in section 1.
You do not have to come here first, though. You can complain to your state attorney general, or to the Federal Trade Commission at reportfraud.ftc.gov.
If this notice changes, the date at the top changes with it. For anything that materially affects you, particularly anything touching the reading log, you will be told in the app or by email before it takes effect, and consent will be asked for again rather than assumed.