‹ Back to Pasture

Pasture

Privacy policy

Last updated 16 September 2026

This policy explains what Pasture collects, why, who it is shared with, and what you can do about it. It applies to the Pasture mobile app and the services behind it.

1. Who we are

Pasture is published by Scaleswift Digital Services LLP (“we”, “us”). We are the controller of the personal data described here. Pasture is distributed through the Apple App Store and Google Play.

2. An account exists before you make one

Pasture creates an anonymous account for your device the first time you open the app. This is what lets your answers and settings survive a restart without asking you to sign up. It is identified by a random id and is not linked to your email or phone number.

Signing in with Apple, Google, or an email code attaches a real identity to that same account. It does not create a second one, and nothing already attached to your account is lost.

3. What we collect

Account

  • A random account identifier, created on first launch.
  • Your email address, only if you sign in with an email code.
  • The identifier and email address Apple or Google returns, only if you use that sign-in. With Sign in with Apple you may choose to hide your real address, and we receive only the relay address.

What you tell the app

  • Your answers during onboarding, which include information about your wellbeing and your faith: why you came (for example anxiety, grief, or growing in faith), how you have been lately, how often you pray and read Scripture, your faith tradition, what you want more of, and when things feel heaviest.
  • Things you choose to type, such as your lamb’s name and one good thing from your day.
  • Your age range, how much time you have on a normal day, the acts of care you pick, and whether and when you would like a daily reminder.
  • Your lamb’s name, the acts of care in your daily rhythm, the verses you keep, and the series you walk.
  • Your daily check-ins: how you are feeling and the feelings you pick.
  • What you write in the app, such as notes, prayers, and reflections.
  • Activity: the acts of care, check-ins, and series days you complete, and when.

Device and technical

  • Platform, device model, operating system version, app version, language, and time zone.
  • A device identifier: the Apple vendor identifier (IDFV) on iOS, which is specific to apps from this publisher, or the Android ID on Android.
  • The advertising identifier. On iOS (the IDFA) only if you allow tracking when iOS asks; if you decline, it is not collected and not shared. On Android, the Google advertising ID, which you can reset or delete in your device settings.
  • Your IP address, which any server sees when the app connects to it.
  • How you use the app, such as the screens you view and the buttons you tap, including session recordings.
  • Crash reports and diagnostic logs when something goes wrong.

What we never collect

  • Your contacts, photos, calendar, microphone, camera, or data from Apple Health or other health apps. The app requests access to none of these.
  • Precise location. At most we infer a country-level region from your device or store settings.
  • Payment card details. Purchases are handled entirely by Apple or Google; we never see a card number.

4. Sensitive information

  • We use it to run and personalise the app for you, for example to suggest tools and to shape how the app talks to you.
  • It is stored in our database, where row-level security limits each account to its own records.
  • It is not sent to Meta or AppsFlyer. What they receive is described in section 7, and it contains none of your answers.
  • Nobody reviews it clinically or watches it in real time. If you are in danger, contact your local emergency number, as our terms explain.

5. Why we use it

  • To run the app: save your answers and settings and pick up where you left off.
  • To personalise it: tailor suggestions and wording to what you told us.
  • To operate subscriptions: know whether you have an active plan and restore it on a new device.
  • To fix problems: diagnose crashes and errors.
  • To understand what works: which screens people finish and where they get stuck, so the app can be improved.
  • To measure advertising: understand which campaign brought a new user, where you have allowed it. This never uses your wellbeing information.
  • To send reminders you have asked for, and only if you granted notification permission.

We do not sell your personal information, and we do not use your answers to build advertising profiles about you.

6. Legal bases

Where the UK or EU GDPR applies, we rely on: your explicit consent, for the wellbeing information you choose to give us; performance of a contract, to provide the app and your subscription; legitimate interests, to keep the service secure, diagnose faults, and understand aggregate usage; and consent, for advertising measurement and push notifications. You can withdraw any consent at any time, as described in section 10.

7. Who we share it with

We use a small number of processors. Each receives only what it needs, and several are absent entirely from builds that are not configured for them.

  • Supabase: the database and sign-in behind the app. Holds your account, your answers, and your subscription status.
  • Apple: App Store purchases, subscription status, and Sign in with Apple.
  • Google: Google Play purchases on Android, and Google sign-in if you use it.
  • RevenueCat: records which subscription you hold, so it survives a reinstall, along with device identifiers.
  • Superwall: decides which paywall to present. Receives your subscription status and which version of onboarding you saw, never your answers.
  • Sentry: crash and error reports.
  • PostHog: product analytics, so we can see which screens work.
  • OneSignal: delivery of the reminders you opt into. Receives your account id and push subscription.
  • Meta and AppsFlyer: advertising attribution, only where configured and only within the choice you made in the tracking prompt. They receive your random account id, device and advertising identifiers, and a few events such as finishing onboarding, seeing a paywall, and starting or completing a purchase. They never receive your onboarding answers or anything else you tell the app about how you feel.

If we add a feature that uses an outside AI provider to respond to you, we will update this policy to name that provider and what it receives before the feature is available to you.

We may also disclose information where the law requires it, or to protect the rights and safety of our users or ourselves.

8. Where it is processed

We and our processors operate internationally, so your data may be processed outside the country where you live, including in India and the United States. Where personal data leaves the UK or EEA we rely on the standard contractual clauses or an equivalent safeguard.

9. How long we keep it

Your account and what you have entered in the app are kept while your account exists. Crash and analytics records are kept for a limited retention period set with each provider, typically no more than 12 months. Records we must retain for tax or legal reasons are kept for as long as that obligation lasts.

10. Your choices and rights

  • Tracking: iOS asks once. You can change the answer at any time in Settings › Privacy & Security › Tracking. On Android, reset or delete your advertising ID in your device settings.
  • Notifications: revoke notification permission in your device settings at any time.
  • Delete your account: use You › Delete account in the app, or write to us. We will delete your account and the information attached to it, including your wellbeing answers, apart from records we must keep for legal reasons.
  • Access, correction, portability, objection, restriction, and withdrawing consent: write to us and we will respond within 30 days.

If you are in the UK or EEA you may complain to your data protection authority. If you are in California, we do not sell or share personal information as those terms are defined by the CCPA, and we will not discriminate against you for exercising any right.

11. Security

Data is encrypted in transit. Access to the database is restricted by row-level security so that an account can only reach its own records. No system is perfectly secure, and we cannot guarantee absolute security.

12. Children

Pasture is not directed at children under 13, or under 16 in jurisdictions where a higher minimum age applies, and we do not knowingly collect their personal information. If you believe a child has provided us with data, contact us and we will delete it within 5 business days of verifying your identity and your relationship to the child.

13. Changes

We will update the date at the top of this page when this policy changes, and will tell you in the app if the change is significant.

14. Contact

For any question or request about this policy or your data:

Scaleswift Digital Services LLP

support@getpasture.app

https://getpasture.app

© 2026 Scaleswift Digital Services LLP. All rights reserved.