Privacy Policy
Last updated: 2 September 2026
Lilies is a daily devotional. It is built so that almost nothing about your reading leaves your phone, and this page says exactly what does.
Who is responsible
Julien Montagne, publisher of Lilies, as an individual. Contact: julienmtg@outlook.fr.
There is no account
Lilies asks for no email address, no password and no sign-in. You are never asked to identify yourself, and there is nothing to log into.
What stays on your phone
None of the following is sent anywhere. It lives in the app's own storage and is removed when you delete the app.
- The first name you give during the questions, if you give one.
- Everything you write: journal lines, notes, and the verses you highlight.
- Which readings you have finished, how many mornings you have kept, and the season you joined.
- Your reminder time, your translation and your appearance setting.
- The 365 daily readings, the seasons, and the whole Bible in both translations.
What is sent to our server
Our server is lilies.julienmontagne.com. Three things reach it.
| What | When | Why |
|---|---|---|
| A random device identifier | Once, on first launch | A string of random characters created on your phone and kept in its keychain. It identifies a phone, not a person, and it is not derived from anything about you or your device. |
| The question you type in Ask, the reading you are on, and your translation | Only when you send a message in Ask | To compose an answer. Your questions are not stored: the server has no place to put them, and it keeps no conversation history. Closing the screen ends it. |
| A request counter | Ask | To stop one phone from overwhelming the service. It holds a count and a time, no content. |
Ask, and the company behind the answer
To write an answer, your question is passed to Google's Gemini API. Google processes it under its own terms as our service provider. It is sent without your name, without your notes and without anything else from the app.
Every verse an answer shows you is read out of our own copy of Scripture from its reference. The model is never allowed to write Scripture, which is a matter of accuracy rather than privacy, but it is worth knowing.
Ask is the only part of Lilies that needs a connection. Everything else works with the phone in aeroplane mode.
Subscriptions
Payment is handled entirely by Apple. We never see your name, your address or your card. To know whether your subscription is active, we use RevenueCat, which receives the purchase from Apple and tells our server which product you hold, whether it is active, and when it expires. We store that and the raw notification it arrives in.
Analytics
We use PostHog to count how the app is used. Automatic capture is switched off: there is no screen recording, no session replay, and no list of screens you visited. Only a fixed set of events is sent, each attached to the random device identifier above.
What is never sent: your first name, your journal, your notes, your highlights, and anything you type in Ask.
What you said you are carrying is not sent. The opening questions ask what you are going through, and the answer stays on your phone: the app records only how many things you ticked, never which. What we do record is which season was built for you, because that is how we learn which one to write next.
Notifications
Reminders are scheduled by the app on your own phone. Nothing is pushed from a server, and no push token is collected. Turning them off in iOS Settings stops them completely.
What Lilies does not do
- No advertising, no advertising identifier, and no third-party ad networks.
- No tracking of you across other apps or websites, and no data sold or shared for advertising.
- No location, no contacts, no photo library, no microphone, no health data.
- No social features. Nothing you write is visible to anyone else, ever.
How long any of it is kept
The device record and the subscription status are kept while the app is installed and for up to 24 months after the last time the app contacted the server, then deleted. Ask questions are not kept at all. Analytics events are kept for 12 months.
Deleting what we hold
Deleting the app removes everything on the phone, immediately and irreversibly — including your notes and your journal, which exist nowhere else. To have the device record and the analytics events on our side deleted, write to julienmtg@outlook.fr. It is done within 30 days.
Your rights
Wherever you live, you can ask what we hold about your device, ask for a copy, ask for it to be corrected, or ask for it to be deleted, at the address above. If you are in the European Economic Area or the United Kingdom, the legal basis is our legitimate interest in running and improving the app, and you may also object to that processing or complain to your supervisory authority. If you are in California, we do not sell or share personal information as those words are defined there, and we will not treat you differently for exercising any right.
Children
Lilies is written for adults and is not directed at children under 13. We do not knowingly collect anything from them.
Who processes data for us
- Apple — the App Store, payment, and the subscription itself.
- RevenueCat — subscription status.
- Google — the Gemini API, for Ask only.
- PostHog — analytics, on servers in the United States.
- Our hosting provider — the server itself, in Europe.
Changes
If this policy changes, the date at the top changes with it, and a material change will be said in the app before it takes effect.