Thrive Church App: Privacy Policy
⚠️ DRAFT PREPARED FOR REVIEW. THIS IS NOT LEGAL ADVICE.
This draft was written by reading the app's actual database rules and source code, so that it describes what the software really does rather than what we hope it does. It has not been reviewed by a lawyer. Have it checked by Taiwan-qualified counsel before adopting or publishing it. Sections marked [GAP] describe things the app does not currently do; those should be fixed or the wording changed before this goes live.
⚠️ 本文件為送審草稿,不構成法律意見。
本草稿係依據 App 實際的資料庫規則與程式碼撰寫,目的是描述軟體真正的行為,而非我們期望的行為。本文尚未經律師審閱。發布或採用前,請交由具台灣律師資格者審核。標示 [GAP] 的段落說明 App 目前尚未做到的事項,應於正式上線前修正,或調整文字說明。
Last updated 最後更新:[DATE] Version 版本:[POLICY_VERSION]
Applies to: the Thrive Church member app (iOS and Android) and the staff web admin. 適用範圍: Thrive Church 成員 App(iOS 與 Android),以及同工使用的後台網站。
Languages. This policy is published in English and Traditional Chinese. The two versions are meant to say the same thing. If they ever differ, the [CONTROLLING_LANGUAGE] version governs.
語言。 本政策以英文與繁體中文發布。兩個版本的內容應為一致。若兩者有任何歧異,以 [CONTROLLING_LANGUAGE] 版本為準。
The five things you most need to know#
1. Staff cannot read your private chats with other members. Not your direct messages, not your group chats, not your family group rooms. There are four exceptions, and we list all four in section 6.1. Please read them.
2. Some things you might expect to be private are not. Every staff account can read your full profile, every message you send to the staff team, every care or benevolence request you submit, and every sermon response form you fill in. Details in sections 5 and 6.
3. "Anonymous" prayer is anonymous to people, not to the database. Other members and ordinary staff never see who wrote an anonymous prayer request. But your name is stored on the post, and the safeguarding officer can see it. Do not use anonymous prayer to say something you need nobody to ever trace to you.
4. Your data is stored outside Taiwan, and notifications show message previews. Everything lives on Supabase servers in Singapore. That is a cross-border transfer of your personal data out of Taiwan, and section 8 explains it. Push notifications carry the sender's name and up to 140 characters of the message through Expo, Apple, and Google before they reach your lock screen.
5. You can delete your account, and nothing is erased for 30 days. Tap delete and your account switches off immediately, but nothing is destroyed until day 30, so you can change your mind. Deletion scrubs your profile, and only your profile. Your name stays, word for word, on any form you submitted, on any sermon response you wrote, and on donation records imported from the church's accounts. Section 11 lists exactly what survives and why.
1. About this policy#
This policy explains what personal data the Thrive Church app collects, why we collect it, who can see it, how long we keep it, and what you can ask us to do about it.
We have tried to write it in normal language. Where the honest answer is "a person does this by hand, not the software", we say so. Where the app does not do something you might reasonably assume it does, we say that too, and mark it [GAP].
Taiwan's Personal Data Protection Act (the PDPA) is the law that governs how we handle your data.
2. Who we are, and how to reach us#
[LEGAL_ENTITY_NAME] ("Thrive Church", "we", "us") is responsible for the personal data in this app. Under the PDPA we are the non-government agency collecting and using your data.
- Registered address: [REGISTERED_ADDRESS]
- Website: [CHURCH_WEBSITE]
- For anything about your data, including all the rights in section 11: [DATA_CONTACT_EMAIL]
- Phone: [DATA_CONTACT_PHONE]
- For safety concerns, reports, or anything involving a child: [SAFEGUARDING_CONTACT_EMAIL]
- For giving, receipts, and your ID number: [FINANCE_CONTACT_EMAIL]
We aim to answer data requests within [RESPONSE_DAYS] days.
3. What we collect, and why#
3.1 When you sign up#
To create an account we collect your email address and a password. Passwords are handled by our login provider and we never see them. We also record the date and time you accepted this policy.
After that, a two-step onboarding form asks for the following. We are listing it field by field, because "only your name is required" would not be true.
Step 1, about your name and how to reach you:
| Field | Required? | What it is |
|---|---|---|
| Which names you go by | Required | Both Chinese and English, Chinese only, or English only |
| English name | Required if you said you have one | Your display name |
| Chinese name | Required if you said you have one | Stored separately from the English one |
| Chinese name on your name tag | Optional | Full name, or given name only. Stored as name_tag_zh_short |
| Gender | Required | The only two options are male and female. There is no "other", no "prefer not to say", and no way to skip the question and still finish the form |
| LINE ID | Optional | |
| Phone | Optional |
Step 2, about your connection to Thrive. This step is only asked once, when you first sign up:
| Field | Required? | What it is |
|---|---|---|
| Family group | Required | One of: I am in a family group, I would like to join one, Sunday-only is good for now |
| Which family group | Required if you said you are in one | A free-text name of the group or of its leader. You tell us this; staff do not record it for you |
| Membership | Required | One of: I am a member, I would like to learn about it, not right now |
From your last two answers we also store two flags you never see on screen: whether you are waiting to be placed in a family group (family_group_pending), and whether you should be followed up about membership (membership_interest). Saying you are already a member and saying you want to learn about it both set the second flag, because both mean a staff member will get in touch. Saying you are a member does not make you one in our records; staff confirm that separately.
You can skip the whole form. There is a Skip button in the corner, and if you use it, nothing above is collected. Two honest notes about skipping. First, you cannot skip only the gender question: inside the form, gender is mandatory, and there is no way to answer part of the form and leave it blank. Second, skipping is close to permanent. The Profile screen's Update my info reopens step 1 only, without the gender question, so once you have skipped, gender, your family group answer, and your membership answer can only be set by asking a staff member. Staff approval may also take longer without them.
We use all of this to know who you are, to let other members find you, to let leaders reach you, and, in the case of gender, to decide which gendered family group rooms and gendered prayer walls you can see.
About a profile photo. The Profile screen lets you choose or take a picture, and your account has a place to store one. Today that picture is only held in your phone's memory for the current session. Nothing uploads it, nothing saves it, and it is gone when you close the app. So we do not currently hold a profile photo for anyone. If we change that, we will update this policy first.
About language. Your choice of English or Chinese, and light or dark mode, are saved on your own device only. They are never sent to us.
Staff record, about you and not by you: whether your account is approved, whether you are an attender or a member, your role (member, servant team, or staff), and which family group you are actually placed in once they have confirmed it.
We do not ask for your date of birth or your age anywhere in the app. See section 12.
3.2 Your family group#
If you join a family group we store your membership of that group and your role in it (leader, co-leader, helper, or member).
Your leader can record attendance at each meeting: whether you were there, and optionally a reason if you were not (sick, work, travel, family, or other) plus a free-text note. This is recorded by your leader about you, not by you. Repeated absence shows up in a staff list so someone can check in on you.
We also store photos uploaded to your family group, with captions.
Family group meeting locations are often somebody's home, so we store addresses and access notes such as door codes.
3.3 Messages#
The app has several kinds of messaging and they are not protected the same way. This matters, so please read section 6.
- Direct messages, group chats you create, and family group rooms. We store the message text, any photo, GIF, sticker, or poll, who sent it, when, which message it is a reply to, and reactions.
- Messages to the staff team. A separate conversation between you and the Thrive staff team.
- Unsent messages. You have 15 minutes to withdraw a message you sent. See section 6.1 for what withdrawing does and does not do.
Not yet active. Read receipts, typing indicators, @mentions, retained edit history, and saved link previews have been written but are not switched on, and none of them exists on our database today. Nothing is being recorded for any of them. We have left them out of the rest of this policy on purpose, because describing data we do not hold would be misleading. We will update this policy before any of them goes live.
3.4 Prayer#
- Prayer wall posts, church-wide and family group, including whether you chose to post anonymously. Posts drop off the wall after 7 days but the record is kept, see section 9.
- Who prayed for a post, and reactions.
- Blocks, if you block a poster.
3.5 Your private study material#
Sermon notes, your prayer journal, reading plan progress, reading reflections, saved verses and highlights, memorised verses, and bookmarks.
These are yours alone. The database rule on each of these is a single line: you, and nobody else. Not other members, not leaders, not staff, not the safeguarding officer.
One exception you should know about: reading progress inside a family group is shared with that group. Anyone in your group can see each member's name next to the chapters they have finished.
3.6 Forms you fill in#
- Connection cards. Anyone can submit one, including a visitor who has never signed up. We collect your name, email, phone, LINE ID, how you heard about us, what you are interested in, and any free-text notes.
- Family group signup. Name, gender, phone, LINE ID, languages you speak, whether you are a member, whether you are a college student, a grad student, or not a student, how long you expect to stay in Taipei, which nights work, and which district of Taipei you live in.
- Membership class, baptism interest, retreat signups, and similar.
- Sermon response forms. Your name, LINE ID, your written reflection, next steps you chose, and a prayer request.
Staff record follow-up attempts against these forms: who called you, when, how, what happened, and a written note.
3.7 Care and benevolence requests#
If you ask the church for help we store the type of need you selected (financial, medical, employment, family, care, or other), your description in your own words, how urgent it is, how you want us to contact you, and whether you agreed to share it with your family group leader.
Staff then record a contact log about your case, including free-text notes.
Requests cannot be submitted anonymously. Your name is always attached.
3.8 Giving and tax receipts#
If you record a donation we store the date, amount, currency, purpose, and the last five digits of your bank account.
If you want a Taiwanese tax receipt uploaded on your behalf, we ask for your name for the receipt, mailing address, contact details, and your national ID or ARC number. This is entirely optional and only for tax receipts.
We also import a spreadsheet exported from the church's accounting software and match transactions to members. That file may contain donors who do not use the app.
3.9 Notifications#
If you allow notifications we store a push token for your device, your device model name (for example "iPhone 15"), the platform, and your notification preferences and quiet hours.
3.10 Safety and records#
- An audit log of administrative actions: who did what, to what, and when. It does not record message content.
- A rate limit log: a timestamp each time you send a message, file a report, or post a prayer request.
- Reports you file about a message, which include a frozen copy of that message.
- Safeguarding flags and legal holds. See section 6.6.
3.11 What we do not collect#
We want to be specific, because these are real and unusual choices:
- No analytics, no tracking, and no crash reporting. There is no Google Analytics, no Firebase, no Sentry, no Amplitude, and nothing similar anywhere in the app. We do not measure which screens you visit or how long you stay.
- We do not log your IP address in the app. The database has columns for it, but nothing writes to them. Two exceptions are in section 7: Google receives your IP if you search for a GIF, and our hosting provider logs staff IPs for the staff admin site.
- No advertising, no data selling, and no data sharing for marketing. Ever.
- No location tracking.
- No access to your contacts, calendar, or photo library beyond a photo you deliberately choose to upload.
4. Why we are allowed to hold this#
Under the PDPA we rely on the following, depending on the data:
- Your consent. You accept this policy when you sign up and we record the timestamp. Filling in an optional field is itself a choice to give us that information.
- Our relationship with you. Running a church you belong to requires a member record, a family group list, and a way to contact you.
- A specific legal duty. Donation and tax receipt records exist because tax law requires them.
- Protecting someone's life, body, freedom, or property. This is the basis for keeping safety records and for legal holds, even when you have asked us to delete your account.
Health information gets a higher standard. The PDPA treats medical and health data as special category data. In this app that means the medical parts of a care or benevolence request, a "sick" reason on an attendance record, and children's allergy and medical notes. We rely on your explicit choice to tell us, and only ever in the context of you asking for help. You never have to give us health information to use the app.
A note on religious belief. Taiwan's PDPA does not classify religious belief as special category data, so under Taiwanese law most of what is in this app is ordinary personal data. We recognise that in practice nearly everything here (your attendance, your prayer requests, your baptism interest, and your reading habits) is a record of your faith and your private spiritual life. We treat it as sensitive regardless of what the law requires. If you live in the EU or the UK, tell us at [DATA_CONTACT_EMAIL] and we will handle your data to the stricter standard those laws expect.
5. Who can see your data inside the church#
5.1 The roles#
| Role | What it is |
|---|---|
| You | Your own account. |
| Approved members | Anyone the church has approved. They see the member directory. |
| Family group leaders | Leaders, co-leaders, and helpers of a group, for their own group only. |
| Staff | Church staff accounts. The broadest everyday access. |
| Safeguarding officer | One or more named people who handle reports and safety matters. This is the one permission that can only be granted directly in the database, never from the staff admin website, so no staff member can give it to themselves. |
| Finance | The small group who handle giving. Granted by a super admin, from the staff admin website. |
| Super admin | The people who decide who gets finance access and who else is a super admin. A super admin grants both from the staff admin website. The app refuses to remove the last remaining super admin. |
| Database administrator | Whoever holds the keys to our database account. |
5.2 What each role can see#
Swipe sideways to see every column.
| Your data | You | Other members | Your FG leader | Staff | Safeguarding officer | Finance |
|---|---|---|---|---|---|---|
| Name (and a photo, if one is ever stored: see 3.1) | Yes | Yes | Yes | Yes | Yes | Yes |
| Phone, LINE ID, email | Yes | Hidden by default | Hidden by default | Yes, always | Yes | Yes |
| Gender | Yes | No | Yes, in your group | Yes | Yes | Yes |
| Your role, membership status, family group | Yes | Yes | Yes | Yes | Yes | Yes |
| Private chats and DMs | Yes | Only people in the chat | No | No | Only via a report or an audited export | No |
| Messages to the staff team | Yes | No | No | Yes, all staff | Yes | Yes |
| Prayer wall posts (named) | Yes | Yes | Yes | Yes | Yes | Yes |
| Prayer wall posts (anonymous) | Yes | Hidden | Hidden | Hidden | Can unmask | Hidden |
| Notes, prayer journal, highlights | Yes | No | No | No | No | No |
| Reading progress | Yes | No | Yes | Yes | Yes | Yes |
| Family group attendance | Yes | No | Yes | Yes | Yes | Yes |
| Sermon response forms | Yes | No | No | Yes, all staff | Yes | Yes |
| Connection cards and signup forms | Yes | No | No | Yes, all staff | Yes | Yes |
| Care and benevolence requests | Yes | No | Only if you agreed | Yes, all staff | Yes | Yes |
| Staff notes about your care case | No | No | No | Yes | Yes | Yes |
| Giving records and bank digits | Yes | No | No | No | No | Yes |
| Your national ID or ARC number | Yes | No | No | No | No | Yes, and every look-up is logged |
| Reports you file | No | No | No | No | Yes | No |
| Event RSVPs | Yes, your own | Only the total | Only the total | Yes, individually | Yes | Yes |
5.3 Things that commonly surprise people#
- Your contact details are hidden from other members by default. Your name appears in the directory, and your photo would too if we stored one. Your phone, LINE ID, and email do not, unless the setting is changed. [GAP] There is currently no switch in the app to change this. If you want your contact details shown, or want to be sure they are hidden, email [DATA_CONTACT_EMAIL] and a staff member will set it for you.
- Staff see your profile in full. The directory hides your phone number from other members. It does not hide it from staff. Staff can also edit your profile.
- Poll votes are not secret. If you vote in a poll in a chat, everyone in that chat can see how you voted.
- Event RSVPs look anonymous, and are not. Other members only ever see a total, and you only see your own answer. Every staff account can see exactly who said going, maybe, or cannot make it. They use it to plan, but you should know it is not a secret ballot either.
- You cannot read a report you filed. Once you report a message, it goes to the safeguarding officer and only the safeguarding officer can open it. That includes the reason you typed. Nobody else can read it, and neither can you. We know that is an odd thing to be told, and the reason is that a report is designed so that nothing about it can be used to work out who filed it. If you want a record of what you reported, keep your own note before you send it, or email [SAFEGUARDING_CONTACT_EMAIL].
- Reading progress in your family group is a shared list. Everyone in your group sees who has finished which chapters.
- Your family group leader can see and record your attendance, including a reason and a note.
6. The sensitive parts, explained plainly#
6.1 Private messages between members#
Staff cannot read your direct messages, your group chats, or your family group rooms. This is enforced by the database itself, not by the app being polite. An early version of the app did let staff read them, and that was deliberately removed.
There are exactly four exceptions, and you should know all of them:
- The safeguarding officer can retrieve a full transcript of every conversation you were part of, if there is a safety reason to. This includes messages you unsent and messages hidden by our retention schedule. Every single retrieval is written to the audit log.
- Anyone in a conversation can report a message. Reporting freezes a copy of that message and sends it to the safeguarding officer. This is the intended route for private content to reach someone who can act on it.
- A staff member who is in the chat reads it like everybody else in it. Being staff gives no extra access; being in the room does.
- Whoever administers our database can technically read anything. The keys to a database can open the whole database. We restrict who holds them, but no software rule can prevent it. Your messages are not end-to-end encrypted.
When you unsend a message, the other people see only a note that a message was withdrawn. The text is hidden from everyone, including you. It is not erased. The record stays for the retention period in section 9, and the safeguarding officer can still retrieve it. You have 15 minutes to unsend. A notification that has already reached someone's phone cannot be recalled.
Staff cannot remove a message from a chat room. That ability does not exist in the app. If a message worries you, use the report button.
6.2 Messages to the staff team#
This is a separate conversation from your chats with other members, and it is not private in the same way.
Every staff account can read every message in it. It is a shared inbox by design, so that no single person is the sole holder of a difficult conversation, and so that someone always replies. That is a deliberate accountability decision, but it means when you write to "the staff team", you are writing to all of them, not to one person.
When staff reply, the notification on your phone deliberately shows no preview of what they wrote.
6.3 Prayer requests, including the anonymous option#
Anonymous means anonymous to people, not to the system.
When you post anonymously, your name is hidden from other members, from family group leaders, and from ordinary staff. That hiding is enforced by the database, and it was tightened twice after we found ways around it during our own review.
But your name is stored on the post, and the safeguarding officer can see it. We keep the link because a prayer request is sometimes how someone tells us they are in danger, and we need to be able to reach that person.
So, honestly: anonymous prayer is a good way to share something you would rather other members did not attach to your face. It is not a way to say something you need nobody to ever trace back to you. If you need that, please talk to someone in person.
If you block an anonymous poster, we do the blocking on our side so you never learn who it was.
6.4 Care and benevolence requests#
These are among the most sensitive things in the app. If you tell us about an illness, a job loss, a debt, or a family crisis, that text is stored.
- Every staff account can read your request in full, including the free text.
- Your family group leader can read it only if you ticked the box to share it with them. That box is a real control and it works.
- Staff keep a contact log about your case, with their own notes. You cannot read that log. We think you should be able to see notes about yourself, and that is on our list to change.
- There is no way to delete a care request, not by you and not by staff. See section 9.
- Requests cannot be anonymous.
6.5 Giving, bank digits, and your ID number#
This is the one area where ordinary staff have no access at all. Not a filtered view, not a summary. Nothing.
Only the small finance group can see donation records, and finance access can only be granted by a super admin, never by an ordinary staff account.
Your national ID or ARC number gets the strongest handling in the app:
- It is only collected if you ask for a tax receipt to be uploaded on your behalf.
- It is encrypted before it is stored, using a key kept in a separate vault, so it is not readable even in a copy of the database.
- Every single time it is decrypted, that is written to the audit log with who did it and when.
- If you withdraw your consent, the number is erased, not just marked inactive. That is a real deletion and it happens immediately.
Tax receipt PDFs are stored in a private area where you can only ever reach files in your own folder. Those PDFs may contain your ID number.
6.6 Safeguarding reports, flags, and legal holds#
Anyone can report a message. When you do:
- A copy of the message is frozen at that moment, so an edit or an unsend cannot change the evidence.
- The report goes only to the safeguarding officer. Ordinary staff cannot see reports at all, and neither can you, after you send it. There is exactly one rule in the database for reading a report, and it is "are you the safeguarding officer". Filing one does not give you a copy or a status page. If you want a record, keep your own note before you send it.
- A legal hold is automatically placed on the person who wrote the message. A legal hold means nothing they were part of gets deleted, by anyone, until the hold is lifted.
- The person reported is not told, and the app deliberately gives them no way to find out. That protects you as the reporter.
If you are under a legal hold and you ask us to delete your account, we will refuse and keep the data, under the PDPA exception for protecting someone's life, body, freedom, or property. We will not necessarily tell you why, because doing so could identify a reporter.
Dismissing a report never automatically lifts a hold. Lifting one is always a separate, deliberate, logged action by the officer.
7. Who outside the church receives your data#
We do not sell your data and we never share it for marketing. These are the only companies that receive any of it, and exactly what they get.
| Who | What they receive | Where they are |
|---|---|---|
| Supabase | Everything. Our whole database, login system, file storage, and server functions. | Singapore |
| Expo | Your push token, the sender's name, and up to 140 characters of the message, every time you get a notification. | United States |
| Apple and Google | The same notification content, because Expo delivers through Apple's and Google's notification services. | United States and elsewhere |
| Google (Tenor) | If you search for a GIF: your IP address and what you typed. Your device contacts Google directly. Anyone who later scrolls past that GIF also loads it from Google. | United States |
| Crossway (ESV) | The Bible passage reference only. No account, no device, and no identifying information. Most requests never reach them because we cache the text. | United States |
| Vercel | Standard web logs (IP, browser, and page) for staff using the admin website. Member data does not pass through Vercel's servers; the admin site talks to Supabase directly from the staff member's browser. | United States |
| Apple App Store and Google Play | Standard app distribution and crash information collected by the stores themselves. | United States and elsewhere |
The push notification preview is worth pausing on. If someone sends you a direct message, the first 140 characters of that message and the sender's name travel to Expo, then to Apple or Google, and then onto your lock screen. That is real message content leaving Taiwan every time. If you do not want that, turn off notification previews in your phone's own settings, or turn off message notifications in the app.
Things we are sometimes assumed to use, and do not. The church uses accounting software, but the app is not connected to it; a person exports a spreadsheet and uploads it by hand. There is no analytics or advertising service of any kind.
Google Drive: built, but not in use. We want to be precise here rather than reassuring. The app contains a finished design for moving older family group photos out to a Google Drive folder to save storage. Your account has a field recording where each photo lives, with "Google Drive" as one of the possible answers, and there are three server functions and a shared Drive helper file written for it. None of it is switched on. The code says so itself, no photo has ever been moved, and every family group photo is in our own private storage today. Turning it on would send church photos to Google, which is a new transfer of your data out of Taiwan to a new company. We will update this policy and tell you before that happens.
8. Where your data is stored, and transfers outside Taiwan#
Your data is stored outside Taiwan. Our database provider does not operate a data centre in Taiwan. Our project runs in Singapore, on Amazon Web Services infrastructure in the Asia Pacific (Singapore) region. Our provider is a company incorporated in the United States, which means United States legal process could in principle reach it.
This is an international transfer of personal data out of Taiwan, and the PDPA requires us to tell you so rather than leave it implied. By using the app you are agreeing to your data being held in Singapore and, for notifications, passing through the United States.
Push notifications pass through servers in the United States, as set out in section 7.
[GAP] The region above is taken from the connection settings stored in our own code. Before this policy is published, whoever administers the Supabase project should confirm it in the Supabase dashboard, because the dashboard is the authority and this is a disclosure we are legally required to get right.
We have no way to keep this data inside Taiwan while using this software. If that is not acceptable to you, please contact us at [DATA_CONTACT_EMAIL] before creating an account.
9. How long we keep things#
What gets deleted automatically#
Only messages. A job runs every night at 03:17 Taipei time and does two things:
- Chat messages and messages to the staff team are hidden from everyone after 12 months.
- They are permanently destroyed 24 months after that, so 36 months in total.
Between month 12 and month 36 the message is invisible to you, to other members, and to staff. Only the safeguarding officer can retrieve it, and only with an audit record.
Nothing is deleted if it has been flagged for safety reasons, if there is an open report about it, if the person who wrote it is under a legal hold, or if anyone in that conversation is under a legal hold.
What we keep indefinitely#
Everything else. We want to be blunt about this rather than imply a schedule we do not run.
| Data | How long | Notes |
|---|---|---|
| Chat and staff team messages | 12 months visible, destroyed at 36 | Automatic |
| Prayer wall posts | Indefinitely | They disappear from the wall after 7 days, and you can delete your own, but the record stays |
| Photos in chats and family groups | Indefinitely | Photo files are not removed when the message that carried them is destroyed |
| Connection cards and signup forms | Indefinitely | |
| Care and benevolence requests | Indefinitely | No deletion route exists at all |
| Family group attendance | Indefinitely | |
| Sermon responses and reading records | Indefinitely | |
| Giving and tax records | Intended 7 years for tax purposes | [GAP] Nothing in the software enforces this. In practice they are kept indefinitely until deleted by hand |
| Audit log | Permanent | Deliberate. It cannot be edited or deleted by anyone |
| Safety flags, reports, and anything under legal hold | Indefinitely | Deliberate. Released only by a specific, logged decision |
| Push tokens | Until you sign out, ask for deletion, or remove the app | |
| A log of when you sent messages or posted | Indefinitely | [GAP] This is meant to be cleared after 7 days, but the clean-up is not scheduled |
If you want something specific deleted sooner, ask us at [DATA_CONTACT_EMAIL]. A person will do it by hand.
10. How we protect your data#
- Row level security. Every table in the database carries its own access rules, checked by the database on every single query. The app cannot ask for data you are not allowed to see, even if a bug tried to.
- Encryption in transit. All traffic between the app and our servers is encrypted.
- Your national ID is encrypted at rest with a key stored separately from the data, and every decryption is logged.
- Private file storage. Chat photos, family group photos, and tax receipts are in private storage with rules tied to your membership of that chat, group, or account.
- Split permissions, with one exception we should be clear about. An ordinary staff account cannot promote itself to anything. Finance access and super admin can be granted from the staff admin website, but only by someone who is already a super admin, and every grant and removal is written to the audit log. Being on the finance team does not let you add anyone to it. Safeguarding officer is the only permission that cannot be granted from the website at all; it is set directly in the database, so nobody can hand themselves the ability to read reports and unmask anonymous prayer.
- An audit log that nobody can edit. Administrative actions are recorded permanently. No account, including a super admin, can change or delete an entry.
- Report details are kept from ordinary staff, so that filing a report cannot expose the person who filed it.
- No third-party analytics, so there is no extra copy of your behaviour anywhere else.
What we cannot promise#
- Messages are not end-to-end encrypted. Anyone with our database keys can read them. We limit who has those keys.
- One of our storage areas is public: images published by staff for the church. Do not treat that one as private. Chat photos, family group photos, and tax receipts are all in private storage.
- Notification previews leave our systems, as explained in sections 7 and 8.
- A determined staff member with access to a surface can screenshot or copy anything they can see. No software rule stops that. This is why staff access is limited by role and why administrative actions are logged.
11. Your rights, and how to use each one#
Under PDPA Article 3 you have five rights. Here is exactly how each works today, including which ones need a person rather than a button.
The right to ask what we hold, and to see it#
Email [DATA_CONTACT_EMAIL].
[GAP] There is no "download my data" button in the app. The only export tool that exists is a safeguarding tool for the officer, it covers messages only, and it is not a way to answer this request. A staff member will assemble your data by hand from the database. We aim to reply within [RESPONSE_DAYS] days.
The right to a copy of your data#
Same route: [DATA_CONTACT_EMAIL]. We will provide it in a readable format. We may charge a reasonable fee for the work, as the PDPA permits.
The right to correct or complete your data#
Some of this you can do yourself. In the app, go to Profile, then Update my info. You can change your English name, your Chinese name, which of them you go by, how your Chinese name is printed on a name tag, your LINE ID, and your phone number.
These need a staff member: your email address (it is your login), your gender, your family group, your membership status, and your role. The Update my info screen deliberately leaves gender out, so once it is set at signup you cannot change it yourself. Email [DATA_CONTACT_EMAIL] and a staff member will correct it.
The right to stop us collecting, processing, or using your data#
Several controls exist in the app and genuinely work:
- Notification preferences and quiet hours, in Settings.
- Read receipts, off by default.
- Block another member. This hides their messages from you everywhere and stops direct messages in both directions.
- Tax receipt consent. Withdraw it and your ID number is erased immediately.
- Sharing a care request with your family group leader. A per-request choice.
- Posting a prayer request anonymously. With the honest limits in section 6.3.
[GAP] There is no general "withdraw my consent but keep my account" option. We record your consent once at sign-up, and the only complete way to stop us processing your data is to delete your account. If you want us to stop a specific use of your data, email [DATA_CONTACT_EMAIL] and we will handle it as a manual request.
The right to have your data deleted#
In the app: Settings, then Account, then Delete my account.
| When | What happens |
|---|---|
| The moment you tap delete | Your account switches off. You disappear from the directory, member features stop, and notifications stop. Nothing is erased. Your name, email, photo, phone, and LINE ID are untouched. |
| The next 30 days | A cooling-off period. Sign back in and cancel, or ask a staff member to cancel for you. Everything comes back exactly as it was. |
| Day 30 | Permanent deletion runs. Your profile is scrubbed, your account is removed, and everything attached to it is destroyed. |
What is destroyed on day 30: your chat messages, prayer wall posts, personal notes, prayer journal, reading records, saved verses, giving profile including any encrypted ID number, push tokens, and notification settings.
What survives, and why. Please read this part carefully, because "deleted" does not mean every trace of your name is gone.
The day 30 job scrubs one place: your profile. Your name, Chinese name, email, photo, phone, and LINE ID are overwritten there, and your login is destroyed. Everywhere else, records that pointed at your profile simply stop pointing at it. The link is cut. Any text in those records that happens to contain your name was typed or copied in as plain text, and cutting the link does not touch plain text. So:
- The audit log. The record of who did an administrative action loses its link to you. The entry itself stays permanently, and if you were the subject of an action your account's internal id can still appear in it.
- Safety reports and flags. The reporter and the reported person stop being linked to any account. The frozen copy of the reported message stays word for word, and so does the reason the reporter typed. Safety evidence has to outlive the accounts involved, and a report with the evidence stripped out would be useless to the person who has to act on it.
- Connection cards, family group signups, membership and baptism interest, retreat signups, and every other form you submitted. These keep a snapshot of the name, email, phone number, and LINE ID you typed at the time. That snapshot was taken on purpose, so a form does not go stale when someone later changes their details, and it is exactly why deleting your profile does not remove it. The text you wrote stays, and so does your name on it.
- Sermon response forms. Same thing. Your name and LINE ID as you typed them stay on the response, along with your written reflection and your prayer request.
- Financial records. The donation rows imported from the church's accounting software keep the donor name exactly as the accounting software recorded it. The link to your account is cut; the name is not. Your own submitted donation entries keep the amount, the date, and the last five digits of your bank account, no longer attached to you. Your giving profile, including any encrypted national ID number, is destroyed.
- Everything, if you are under a legal hold. In that case the deletion is refused entirely and the request waits until the hold is lifted.
If this matters to you, ask us. Email [DATA_CONTACT_EMAIL] and a staff member can go and remove your name from the surviving records by hand, except from anything held for safety or tax reasons. That is a manual job, and we would rather do it than have you find out later.
Two things you should know before you tap delete:
- [GAP] If you have ever submitted a care or benevolence request, automatic deletion currently cannot complete. This is a defect we have identified and not yet fixed. Your account will still be switched off on day one, but the final deletion will need a staff member to complete it by hand. Email [DATA_CONTACT_EMAIL] and we will handle it.
- If you are a parent with a child recorded in the children's ministry, deleting your account would also delete your child's record, including their allergy and medical notes. Please talk to us first.
One more honest note. A small number of accounts requested deletion under an older version of the app, which erased profile details immediately. If you cancelled such a request, your access came back but your name, email, photo, phone, and LINE ID were already gone and you will have been asked to enter them again. We are sorry about that; it is fixed now.
If you are not happy with how we handled it#
Contact us first at [DATA_CONTACT_EMAIL]. If we do not resolve it, you can complain to the relevant Taiwanese authority for personal data protection, or seek a remedy in court under the PDPA.
[GAP] There is currently no privacy contact form inside the app. The messages feature goes to the staff team, which is not a privacy channel and is itself covered by the retention schedule. Please use email.
12. Children and young people#
We need to be straightforward here, because this is the weakest part of the app.
The app does not ask anyone's age, and it cannot tell whether an account belongs to a minor. There is no birth date, no age field, and no age check anywhere. This matters because our community includes first-year university students, some of whom are under 18.
What this means in practice:
- Someone under 18 can sign up in exactly the same way as an adult, and consents to this policy on their own behalf.
- No feature is limited by age. Age does not scope the directory, chats, or prayer requests.
- [GAP] We have no parental or guardian consent process in the app.
If you are under 18 and using this app, please talk with your parent or guardian about it, and tell us at [DATA_CONTACT_EMAIL] so we can handle your data with extra care and answer any questions they have.
If you are a parent or guardian and you want to see, correct, or delete data about your child under 18, email [DATA_CONTACT_EMAIL] and we will treat it as a priority.
Children's ministry check-in. The database contains a design for children's check-in, including a child's name, birth date, allergies, medical notes, dietary needs, special needs, photo consent, authorised pickup people, and emergency contacts. This is not switched on and no part of the app writes to it. No child's record exists in it today. We will update this policy, and ask parents for consent properly, before we ever turn it on.
Reporting a concern about a child. Contact [SAFEGUARDING_CONTACT_EMAIL] immediately. Our approach to child safety, mandatory reporting, and preserving evidence is set out in our separate Safeguarding and Retention Policy.
13. Changes to this policy#
If we change this policy we will update the date at the top and publish the new version at [POLICY_URL].
If a change materially affects you, for example if we start collecting a new kind of data or send data somewhere new, we will tell you in the app before it takes effect.
[GAP] The app does not currently have a way to ask you to accept an updated policy. Your consent is recorded once, at sign-up, and does not update when this document does. Until we build that, we will announce material changes in the app and give you time to leave or ask questions.
14. Questions#
Anything at all: [DATA_CONTACT_EMAIL].
We would rather answer an awkward question than have you assume the worst, or the best.
PLACEHOLDERS TO FILL IN 待填寫項目#
Every placeholder used above, in one list. Nothing should be published while any of these remains. 以下為上文使用的所有預留欄位。任一項未填妥前,均不得發布。
| Placeholder | What it needs | Who can supply it |
|---|---|---|
[LEGAL_ENTITY_NAME] | The church's registered legal entity name, in English and Chinese. This is the data controller under the PDPA, so it must be the registered body, not the trading name. | Church administration |
[REGISTERED_ADDRESS] | Registered address of that entity. | Church administration |
[CHURCH_WEBSITE] | Public website address. | Church administration |
[DATA_CONTACT_EMAIL] | A monitored address for all data requests. Appears many times. Should be a role address, not a personal one, so it survives staff changes. | Church administration |
[DATA_CONTACT_PHONE] | Contact phone number. | Church administration |
[SAFEGUARDING_CONTACT_EMAIL] | Address that reaches the safeguarding officer. May be the same as above only if the officer monitors it. | Safeguarding officer |
[FINANCE_CONTACT_EMAIL] | Address for giving, receipts, and ID number questions. | Finance |
[CONTROLLING_LANGUAGE] | Which language version governs if the English and the Chinese ever disagree. Recommend Traditional Chinese for a Taiwan-registered entity whose members read Chinese and whose disputes would be heard by a Taiwanese court. Must match the answer given in the Terms of Service. | Church administration, with counsel |
[RESPONSE_DAYS] | Target response time for data requests. The PDPA sets outer limits for responding to review and copy requests; pick a number the church can actually meet. | Church administration, with counsel |
[DATE] | Date the final version is adopted. | Church administration |
[POLICY_VERSION] | Version number, for example 1.0. | Church administration |
[POLICY_URL] | The public URL where this policy is hosted. This must also be entered into the app's church settings as privacy_url. If that field is blank, the app shows no privacy policy link at all, which fails both Apple's review requirement and the PDPA notice duty. Treat publishing this URL as a launch gate. | Church administration |
NOTES FOR REVIEWERS 審閱者注意事項#
Not part of the policy. Remove before publishing. These are the points where the draft had to describe something imperfect, or where a claim depends on something that must be checked first.
Verify before publishing:
- Supabase region: resolved as Singapore, still confirm it.
mobile/supabase/.temp/pooler-urlpoints ataws-1-ap-southeast-1, which is AWS Asia Pacific (Singapore). Section 8 now states Singapore. Confirm in the Supabase dashboard before publishing, because the dashboard is authoritative and this is a PDPA cross-border disclosure. - Chat features: resolved. Read receipts, typing indicators, @mentions, edit history, and link previews are NOT live. Migration
0109_chat_modern_features.sqlis headed "NOT YET APPLIED" and a read-only probe of the live database confirms it:chat_read_receipts,chat_message_edits,chat_mentions,chat_message_links, andlink_previewsall return PGRST205 (table not in the schema cache), whilechat_messages,chat_polls,event_rsvps,message_reports, andmessage_reactionsreturn 42501 (table exists, no anon grant). Section 3.3 now describes only what is live and marks the rest as not yet active. Also note0110_guest_response_intake.sqlis likewise not applied. Thelink-preview-imagespublic bucket is created by 0109, so it does not exist either; section 10 has been corrected from two public buckets to one. - Confirm who can decrypt a national ID. Migration 0050 gated this on any staff account; 0066 narrowed it to finance only. Section 6.5 asserts finance only. Verify against the live database, because this is the single highest-consequence claim in the document.
- Confirm migrations 0066, 0067, 0069, 0071, 0073, and 0074 are applied. All carry stale "UNAPPLIED" headers, and sections 5, 6.5, and 10 depend on them.
Contradictions between the app's own wording and what it enforces. These should be fixed in code, not papered over in the policy:
- The sermon response form is the most serious. The option reads "No, please do not share, only for Pastor David to see." The database policy
sr_select_staffin0007_sermons_announcements.sql:140lets every staff account read every response. The app makes a promise it does not keep. Either narrow that policy to a named person, or change the wording on the form. Until one of those happens, section 5.2 of this policy contradicts the form the member is looking at while they type.
Defects this draft had to disclose as [GAP]:
- Account deletion cannot complete for anyone who has submitted a care request.
benevolence_requests.user_idis declaredon delete restrict(0015_benevolence.sql:45), and the nightly purge has no per-row exception handling. The first such account in the queue will fail the whole batch, so every other member scheduled for purge that night is blocked too, every night, silently. This means the 30-day deletion promise is currently not delivered. Highest priority fix. directory_visibilityhas no user interface. The database honours it correctly, but nothing in the app or the admin site can change it. A privacy control that a member cannot reach is not a control.- There is no member-facing data export. Access and copy requests are fully manual, assembled by hand from at least eight tables.
- There is no consent withdrawal or re-consent flow. Consent is a single timestamp set once at sign-up and never updated when the policy changes.
- No age or minor handling exists at all. Given a student population, this is a real exposure and section 12 could only describe the absence.
rate_limit_prune()is never scheduled, so the behavioural log grows without limit.- The retention sweep deletes message rows but not storage objects, so chat photos outlive the destroyed messages that carried them.
- Retention Tier 2 (7 years for financial records) has no code behind it. Nothing deletes financial data, and nothing protects it from ad hoc deletion either.
- Members cannot read the staff contact log about their own care case, which sits awkwardly against the PDPA right to review one's own data.
- Gender is mandatory at signup, binary, and unchangeable by the member.
mobile/app/onboarding/index.tsx:137-150marks itrequired: truewith exactly two options and no opt-out, and the edit branch omits the field entirely so the member can never correct it themselves. Section 3.1 had to disclose this. - A member cannot read a report they filed.
message_reportshas one SELECT policy, officer-only (0034_retention_reports_flags.sql:169). Sections 5.2, 5.3, and 6.6 now say so. - Every staff account sees individual event RSVPs.
event_rsvps_select_staff(0080_polls_and_event_rsvps.sql:21). Members only ever get the aggregate, which makes it easy to assume staff do too. - Contact snapshots survive account deletion verbatim.
app.purge_deleted_accounts()(0108_account_deletion_fix.sql:276-326) scrubspublic.profilesand nothing else.form_submissions.contact_name/email/phone/line_id(0011_forms.sql:28-31),sermon_responses.name/line_id(0007_sermons_announcements.sql:85-86),qb_donations.donor_name_qb(0010_giving.sql:69), andmessage_reports.message_body(0034:156) are all plain text behindon delete set nullforeign keys, so the link is cut and the text is not. Section 11 now discloses this precisely. - Nothing writes
profiles.photo_url. The Profile screen's photo picker callsupdateUser({ photoUrl }), which is in-memory session state only (mobile/app/_layout.tsx:185-187). There is no avatars bucket. So the app appears to support profile photos and does not store one.
Consistency note: the existing mobile/docs/safeguarding-and-retention-policy.md section 7 states that staff "cannot read member↔member chat". That is true of the app, but it is silent on database administrator access. Section 6.1 of this policy discloses it. Consider aligning the safeguarding document so the two do not appear to disagree.