CBC of Pevely — Privacy Policy
Last updated: 2026-07-12
This app serves two audiences at Community Bible Church of Pevely:
the broader (anyone
who signs in, no membership required) and the church's
Internal users (Members,
Facilitators, and Admins). Community users only see items the church has
explicitly flagged as Public; Internal users see additional content based
on their role. This page describes what data the app collects and what we
do with it. Questions? Contact
[email protected].
Who sees what
- Community — anyone with a Google or Apple sign-in. Sees only
events, announcements, and content the church has marked
Public. Can submit a request to become a Member.
- Member — sees public + member-only content; can RSVP to
events, post to the Prayer Board, and opt into volunteer teams (some
teams require approval before access).
- Facilitator / Facilitator Admin / Admin — internal church
leadership roles with progressively more management capability
(creating events, approving members and volunteers, moderating
content, viewing audit logs).
Account information we store
- When you sign in with Google or Apple, we receive your email address
and (if available) your name. These come from your identity provider
— we never see your password.
- We store your display name, optional phone number, role (Community,
Member, Facilitator, Facilitator Admin, Admin), and the list of
volunteer teams you've opted into.
- We assign a session token after sign-in so you don't have to re-enter
credentials on every request. The token expires after 30 days.
Content you submit (Internal users only)
- Event RSVPs and assignments.
- Prayer requests (text, until date, visibility choice, anonymous
flag). Anonymous requests hide your identity from other viewers
— but administrators can still see who submitted, so that
abuse can be traced and addressed.
- "I prayed for this" taps and prayer-request view counts (per user,
per request).
- Reports you file against other content; users you block.
- Profile settings (notification preferences, contact-sharing toggle).
- Household/family groupings, if you or the church report who is in
your household. You can ask for a correction from inside the app.
- Volunteer team membership, schedules, and schedule-swap requests
for teams you serve on.
- Personal events you create for your own calendar. These are visible
only to you; church administrators cannot read their contents.
Community users have read access only to Public-flagged content. They
do not submit user-generated content; the Prayer Board, Volunteer Board,
and event RSVPs are gated to Members and above.
Content moderation
Prayer requests submitted by Internal users are screened for harmful
content using two layers, both running on our own server. No
prayer-request text is sent to any third-party AI service:
- Local heuristics — checks for obvious spam, gibberish,
repeated characters, all-caps, and URL spam.
- Detoxify — an open-source content-moderation model
that runs locally on our server. It classifies text across
categories (toxicity, severe toxicity, obscene, threat, insult,
identity hate). Nothing leaves our infrastructure.
If content is flagged or if the church administrator has enabled
"review every request", the request enters a moderation queue and is
reviewed within 24 hours.
Technical and security data
- We store the IP address and approximate country (via Cloudflare's
CF-IPCountry header) of authenticated requests in an
audit log. This protects the community from abuse and is visible
only to administrators.
- If you grant push notification permission, your APNs device token
is stored so we can deliver notifications. Removing the app deletes
the token from your device; we clear our copy the next time APNs
reports it as invalid.
What we do not do
- We do not sell, rent, or share your data with advertisers.
- We do not embed third-party analytics SDKs.
- We do not track you across other apps or websites.
- We do not send prayer-request text, audit data, or member info to
external AI services.
How long we keep data
Account and content data is retained while you have an active account.
You can delete your own prayer requests; administrators can delete any
content that violates community standards. To delete your full account
and all associated data, contact
[email protected]
— we'll remove your record within 14 days.
Children
The app is not designed for users under 13. We do not knowingly
collect information from children under that age.
Changes
If we materially change this policy, we'll post a notice in the app
and update the "Last updated" date above.
Contact
[email protected]