Privacy Notice
This notice explains, in plain English, what personal data Fellowship collects, why, how long we keep it and what rights you have. Fellowship processes data that can reveal your religious beliefs, and prayer requests may reveal health or family matters. These are special-category (sensitive) personal data under the Nigeria Data Protection Act 2023 (NDPA) and the EU/UK General Data Protection Regulation (GDPR), and we treat them with particular care.
Who we are
The data controller is [Controller name, address, contact]. Our data protection contact is [Data protection officer / contact name and email]. You can also send a privacy request from Settings → Privacy & Data.
What we collect and why
- Account: email address and password (handled by our authentication provider) — to let you sign in.
- Age: your birth month and year only, and an age band (13–17 or 18+) — to protect young people and meet legal duties. We never store a full date of birth, and we do not store anything for people under 13.
- Profile: name, username, optional photo, optional short bio, optional broad location (city/region only), and your timezone — so the community can recognise you and so “today” matches your local time.
- What you share: prayer requests, testimonies, posts, replies, questions, answers, comments, reactions and images — to provide the service. These are deleted after 72 hours.
- Settings and consents: notification preferences, blocks and mutes, and a record of what you agreed to and when.
- Safety and security: reports, moderation actions, sign-in events and rate-limit counters — to keep the community safe and secure.
- Push notifications: if you enable them, a push subscription for your device.
We do not collect exact location, phone numbers or contacts, and we do not use third-party analytics, advertising or tracking. We use only essential cookies (to keep you signed in and to remember your timezone and theme), so there is no cookie banner. Images are re-encoded and all metadata, including GPS location, is removed before they are stored.
Our lawful bases
- Explicit consent (NDPA s.30; GDPR Art. 9(2)(a)) for processing data that reveals religious belief and any sensitive information you choose to share. You give this separately at sign-up and can withdraw it at any time.
- Contract (GDPR Art. 6(1)(b)) to provide your account and the features you use.
- Legitimate interests (GDPR Art. 6(1)(f)) for security, preventing abuse and moderating reports — balanced against your rights.
- Legal obligation where the law requires us to keep or disclose information.
- Parental/guardian consent for users aged 13–17 (NDPA s.31).
How long we keep data
| Data | How long |
|---|---|
| Community content (prayer requests, testimonies, posts, replies, questions, answers, comments, reactions, prayers, encouragements, check-ins) and attached images | 72 hours from creation, then permanently deleted |
| Prayer follow-ups (private copy for the person who asked) | Until you answer it, or 7 days |
| In-app notifications | 30 days |
| Report evidence snapshots | Until the report is resolved, plus 7 days (weekly purge) |
| Moderation actions log (no post content) | Life of the account + 2 years, then anonymised |
| Security and sign-in logs | 12 months |
| Rate-limit records | 48 hours |
| Push notification subscriptions | Until you unsubscribe, or the first failed delivery |
| Deleted accounts | Profile hidden immediately; personal data purged within 30 days (after a 7-day grace period); moderation log entries anonymised |
| Parent/guardian consent records | Until the young person turns 18 or the account is deleted, plus 1 year |
Anonymous posting
When you post anonymously, other members never see your name, photo or username, and our systems never send your identity to their devices. Moderators and administrators can see who wrote an anonymous post only while handling a report about it, and each time this happens it is recorded in the moderation log.
AI and your data
Administrators may use an AI service (Anthropic) to help draft the official Daily Word. Only administrator instructions and Bible references are sent. Nothing you post is ever sent to an AI provider. Every AI draft is reviewed and approved by a person before anyone sees it.
Who processes data for us
- Supabase — database, authentication and file storage.
- Vercel — hosting and scheduled jobs.
- Anthropic — AI drafting of Daily Words (administrator prompts only; no user content).
- Resend — transactional email such as parent/guardian consent.
- Web push services (such as those run by Google, Apple and Mozilla) — to deliver notifications you have enabled.
Some of these providers may process data outside Nigeria, the UK or the EU (for example, in the United States). Where they do, we rely on appropriate safeguards such as adequacy decisions or standard contractual clauses, as required by the NDPA and GDPR. [Confirm hosting regions and transfer mechanisms]
Young people (13–17)
You must be at least 13 to use Fellowship. For users aged 13–17 we ask a parent or guardian to consent by email before the account becomes active. Young people’s locations are never shown, their profiles are only visible to members of circles they share, they cannot upload images or create circles, they have stricter limits, and their reports are prioritised by moderators.
Your rights
You can, at any time, from Settings → Privacy & Data:
- Access and portability — download a copy of your data (JSON).
- Rectification — edit your profile.
- Erasure — delete your account (7-day grace period, then permanent deletion).
- Withdraw consent — this starts account deletion, because Fellowship can’t work without it.
- Object or restrict, or ask any question — send a privacy request.
If you are unhappy with how we handle your data, please contact us first. You also have the right to complain to the Nigeria Data Protection Commission (NDPC) (ndpc.gov.ng), the UK Information Commissioner’s Office (ico.org.uk), or the data protection authority in your EU country.
Security and breaches
Data is encrypted in transit, access is restricted by role, and security events are logged. If a personal data breach is likely to affect your rights, we will notify the NDPC within 72 hours and tell you without undue delay where required.
Privacy Notice version 1.0. Last updated [date].