My Adventist Library · Last updated: 6 August 2026
My Adventist Library ("the app", "we") is a library of Ellen G. White writings and custom books with reading, notes and community discussion, together with My Church — a place to find your local Seventh-day Adventist church, join it, and keep up with its life. This policy explains what information the app handles and how it is used. We do not sell your data, and the app shows no advertising.
When you create an account we store your name, email address, password (stored as a secure hash — we never see it), account type, and an optional profile photo. If you sign in with Google or Apple we receive your name and email from that provider instead of a password.
Content you create in the app — discussion posts, comments, likes, uploaded books or PDFs, reports of inappropriate content — is stored on our server and, where you post it publicly, visible to other users together with your display name.
Asking to join a church sends that church's admin team an application. Only your name is required. Everything else is optional, and the form says so: a phone number (so the church can call or message you), a photo, the year you were born, your gender, and a home address you may place on a map.
The application also asks whether you have been baptised and whether you would like Bible studies. These answers, and your membership of a church itself, say something about your religious beliefs. We treat them as sensitive: they are used only to help your own church care for its members, they are never used for advertising, they are never sold, and they are visible only to that one church's admin team.
A church may add its own questions to its join form. Your answers to those go to that church's admin team in the same way.
You may join as a household rather than alone, and a church's admin team may add a relative to a household afterwards. For each person that records a name, their place in the family, and optionally a photo, an email address and the year they were born — including for children.
No account and no password is created for anyone added this way. If someone later signs up with the email address recorded for them, that record becomes theirs to control and delete. Until then it can be removed by the church's admin team or by whoever added it.
If you tap "Near me", the app asks your device for your location and sends it to our server once, to sort churches by distance. That position is not stored. Browsing by conference or searching by name works without it, and the app never asks until you tap.
Separately, you may set a home location on your church profile — an address, a map pin, or both. That one is stored, because its purpose is to be found: it is what lets your church's admin team see roughly where its members live. It is yours to change or remove at any time, and removing it takes you out of that search.
Fellow members cannot see it unless two separate things are both true. Your church must have turned on member-to-member visibility, and you must have switched on sharing for yourself — which starts off and stays off until you change it. Even then other members see only the map pin, never your street address, and a household appears once rather than once for each person in it. Removing your location switches the sharing off with it.
Maps are drawn with tiles from OpenStreetMap. Displaying a map sends your IP address and the area being viewed to their servers.
Scanning your church's QR code records that you were present on that date. One scan may record your whole household. Scanning at a church you have not joined records you there as a visitor — your name and email are shown to that church's welcome team, and your own church is not told. Your baptism status and where you normally worship are not passed on.
A church may require you to be near the building to check in, so that its code cannot be used from home. Where it does, the app asks your device for your location at the moment you scan and sends it once. The position itself is not kept — only how far away you were, so the church can see whether its own rule is set sensibly.
The guest form asks for a name; an email address and a phone number are optional. A number you give there is shown to that church's welcome team so they can call or message you, and to nobody else.
Attendance is visible to that church's admin team, who can also export it.
Group chat messages, and any photos, video or audio you attach, are visible to the members of that church. A one-to-one conversation — with a leader, or with another member — is visible to the two of you and to nobody else in the church. Both show when a message has been seen.
One exception, and it is deliberate: if a message is reported, our moderators can read that conversation in order to act on the report. The app stores require somebody to be able to, and a service where nobody can act on harassment is not a safer one. Nothing is read without a report.
A prayer request is the most closely held thing in the app. It is visible to the person who wrote it and to that one church's admin team — its creator and everyone holding a leadership title. Not other members. Not denominational staff. Not our own staff. You can withdraw one at any time.
A church's admin team can see its member list, member locations, attendance and prayer requests. Denominational staff appointed over a conference, union or division can see counts for the churches beneath them — how many churches, members and pastors — and never member details. Our own staff can see what is needed to moderate reported content and to keep the service running, with the single exception of prayer requests, which they are deliberately shut out of.
A church chooses whether its member list and its location are shown publicly or only to its members.
A church may also open its roll to its own members. Where it does, members see one another's names, photos and households — and nothing else. Phone numbers, addresses, dates of birth, baptism status and answers to the church's own questions stay with the admin team.
Reading progress, bookmarks, highlights, notes, downloaded books and offline content are stored locally on your device. Some of these (bookmarks, progress, highlights) also sync to our server when you are signed in, so they follow you across devices. You can delete downloaded content anytime from Settings, and remove synced data by deleting your account.
If you allow notifications, we store a device push token (Firebase Cloud Messaging) linked to your account so we can notify you about replies, likes, group discussion posts, church announcements and messages, and newly published books. The token is removed when you sign out. You can disable notifications in your device settings at any time.
We count how the app is used — which screens are opened, which books and lessons are read, what is searched for — in two places, and they know different amounts about you.
Firebase Analytics (Google) is given no name, email or account number. It does give every installation its own anonymous identifier and records your device model, operating system, app version, language and the country your connection appears to come from. That is enough to count how many people use the app and what they open; it is not enough to say that any of it was you.
Our own server keeps the same kind of record, and when you are signed in it is stored against your account. We use it to see which books and lessons are worth keeping and improving, never to build a profile for advertising.
The app does not request or use an advertising ID, and none of this is shared with anyone for advertising.
The app uses Google Firebase (sign-in, push notifications and analytics), Sign in with Apple (on Apple devices), Cloudflare (content delivery and file storage for covers, images, media and PDFs), and OpenStreetMap (map tiles). These providers process data under their own privacy policies. EGW writings are retrieved from the EGW Writings public API.
We use your information only to operate the app: authenticate you, sync your library, deliver notifications you opted into, show your posts to the community, let your church run its own membership, attendance and messages, count views and downloads, and moderate reported content. We do not sell or rent personal data, and we do not use it for advertising.
You can report content and block other users. Reports are reviewed by moderators and may result in content removal. Blocking hides a user's content from you; the blocked user is not notified.
Your account data is kept while your account is active. You can delete your account in the app (Profile → Edit Profile → Delete Account) or request deletion at myadventistlibrary.com/delete-account; this permanently removes your profile, synced library data, church membership and device tokens from our server. Public posts you made may remain visible without your name or be removed at our discretion.
Attendance records are a historical fact about a service and are kept by the church even after someone leaves it, with their name on the row so the record stays readable. Ask that church's admin team, or us, if you want yours removed.
To remove a family member's record, ask your church's admin team, or contact us at the address below.
The app is suitable for general audiences and is not directed at children. We do not knowingly let children under 13 create their own accounts without parental consent.
Adults do enter details about children: a parent joining as a household, or a church's admin team adding a child to one, records that child's name, place in the family and optionally a photo, email address and year of birth. Only a year, never a full date of birth, and never a password. A parent or the church's admin team can remove that record at any time. If you believe a child's information is held here and should not be, contact us and we will delete it.
We may update this policy as the app evolves. Material changes will be announced in the app. Continued use after a change means you accept the updated policy.
Questions or requests about your data: [email protected]