Skip to main content

Privacy Policy

Version v0.3-2026-09-18 · effective September 18, 2026

Doersteps Privacy Policy

WORKING DRAFT v0.3 - NOT YET REVIEWED BY AN ATTORNEY *This draft must receive professional legal review before any organization outside the founding beta signs up. Texas TDPSA applies now; broader review (GDPR and other state laws) is needed as the customer base grows.*

*v0.2 (2026-07-30) incorporates the 2026-07-29 field audit: renamed from XALT, disclosed per-person engagement analytics and data-access covenants, corrected the lawful-basis statement for religious data, corrected claims the architecture cannot keep (AI never touching submissions, audit-log immutability, anonymization of recorded media), permitted the campus-consented national census transfer that the previous wording forbade, completed the processor list, and added a breach-notification timeline. Changes are drafting improvements for the attorney to review, not legal advice.*

*v0.3 (2026-09-18) aligns the draft with what the platform can actually keep as of the founding pilot, following the 2026-09-17 field audit: accounts are 18+ during the pilot; two-factor authentication is available but not enforced; video engagement analytics are not yet offered; backups are daily with seven-day retention and point-in-time recovery is not yet enabled; providers not yet in use are marked in Section 8. Changes are drafting improvements for the attorney to review, not legal advice.*

Last updated: 2026-09-18 (draft v0.3)

1. The Short Version

  • Doersteps is ministry software. The data on this platform is, by its nature, religious data — one of the most sensitive categories of personal information. We treat it that way.
  • Your organization controls most of what happens to your data within their ministry. We host it.
  • We never sell personal data. Ever.
  • We do not share your personal information between organizations unless you choose to share it, category by category, revocable instantly. The one narrow exception, described in Section 6, is aggregate statistical reporting your organization consents to — counts, never your name.
  • AI features never read your spiritual submissions for meaning and never score your spiritual health. That is a hard product line, not a settings toggle. Section 7 explains precisely where automated processing does and does not touch your content.
  • When video engagement analytics are offered (they are not yet), the Platform will record how you watched a video, and your organization may be able to see that attributed to you. Section 5 explains this plainly.
  • Export is always open. Your data is yours.

2. Who Is Responsible

Doersteps is operated by [ENTITY NAME]. For most data on the Platform, your organization (your church or campus ministry) determines why and how your data is used, and Doersteps processes it on their behalf. For account-level data (your login, platform settings, billing), Doersteps is the responsible party.

[Attorney note: a written processor agreement (DPA) between the operating entity and each organization does not yet exist. It is required before organizations outside the founding beta are onboarded, and should be prepared alongside this policy.]

3. What We Collect

Account data: name, email, phone number (optional), authentication records, security settings.

Profile and ministry data (configured by your organization): may include birthday, key spiritual dates (salvation, baptism, leadership dates), graduation date, group memberships, attendance, and organization-defined custom fields including light personal details (such as a favorite snack) used for care and community. Some organizations additionally collect voluntary demographic information; where they do, answering is always optional and a "prefer not to say" choice is always available.

Formation data: pathway enrollment and progress, doerstep submissions (which may include text, photos, voice, video, and files), attestations, reflections, practice records, and leader notes about development. This is the most sensitive data on the Platform and is access-restricted as described in Section 5.

Communications: messages in group chats, channels, and direct messages; announcements; prayer requests; notification preferences.

Engagement data: how you interact with content, including — for video, once video analytics are offered — how much you watched, where you stopped, whether you skipped forward, and the playback speed you used. See Section 5 for who can see this.

Usage and technical data: device and browser information, log data, and analytics necessary to operate and secure the Platform.

Billing data: subscription details and payment records. Card processing is handled by our payment processor; we do not store full card numbers.

4. Religious Data and Our Legal Basis

Because Doersteps serves ministries, nearly all platform data can reveal religious beliefs and practice. Where laws (such as GDPR or state privacy laws) give special protection to religious data, we treat platform data under those heightened standards.

Legal basis. For data in the special category (which includes religious belief and practice, and any health, demographic, or safeguarding information an organization collects), processing rests on your explicit, specific, informed, freely given, and withdrawable consent, captured per purpose and recorded in a consent ledger with the version of the notice you agreed to.

We state it that way deliberately. An earlier draft cited "your organization's legitimate ministry purposes" as a basis for special-category data; legitimate interest is not a lawful basis for special-category processing under GDPR, and consent that is bundled into signup or unavoidable in order to participate in a ministry is not freely given. Where an organization needs to process such data without workable consent, a different basis must be identified for that specific purpose, and this policy will name it.

Ordinary (non-special-category) operational data — your login, notification preferences, attendance for the organization's own administration — is processed to deliver the service your organization has asked us to provide.

[Attorney note: consent freely given is genuinely hard in a ministry context, where declining may feel socially costly. Please advise on how to structure consent for the demographic and census fields specifically, and whether any of it should instead rest on a non-consent basis with an opt-out.]

5. Who Can See What

Visibility follows your organization's structure, and is disclosed in-product:

  • Group chats and channels are visible to your organization's leadership chain above the group.
  • Direct messages are private from ordinary view. Organization administrators hold an audited emergency-access capability; every use requires a recorded reason and appears in the organization's audit log, visible to its administrators.
  • Pathway submissions and reflections are visible to your assigned leader(s) and organization staff per your organization's configuration. Reflections stay with the discipleship relationship in which they were written.
  • Leader notes flow upward to those responsible for leader development and are never visible to the member they concern.
  • Attendance and membership are visible to your group's leaders and your organization's staff.
  • Practice records, where your organization uses them, are visible to you and your assigned leader. Staff see only whether a threshold was met — never the amounts — and the amounts are never compared between people.
  • Video engagement, attributed to you by name — not yet offered. When video analytics are offered and your organization enables them, designated staff will be able to see how you watched a given video: percentage watched, where you stopped, whether you skipped, and playback speed. This is treated as participation data — the video equivalent of attendance — and is never used to assess your spiritual life or to rank people. Your organization chooses whether the feature is on and which roles can see it; by default small-group leaders cannot and campus staff can. Aggregate viewing statistics (how a video performs across everyone) are shown separately from any named-person view.
  • Demographic information, where an organization collects it, may be visible at the individual level only to staff who hold a dedicated sensitive-data permission and who have signed the data-handling covenant described below; every such access is logged. Above the level of your own campus, this information is only ever reported as suppressed aggregate counts.
  • Parent/guardian linked accounts (where enabled for minors) can see schedules, announcements, leader contact information, and attendance — never chats, direct messages, or submissions, unless the organization configures otherwise.
  • Platform staff can technically access tenant data for support, safety, and legal compliance. Every platform-level read is written to the affected organization's own audit log.

Data-handling covenants. People whose role lets them see other people's records may be required to sign a versioned data-handling covenant before that access is granted, and to re-sign when it is updated. Signatures are recorded in a consent ledger. This is a condition of the access, not of the account: declining removes the elevated visibility, not membership.

6. Cross-Organization Sharing: You Hold the Keys

If you belong to more than one organization on Doersteps (for example, a campus ministry and a church):

  • Organizations cannot see each other's personal data about you.
  • You may grant specific sharing, category by category (for example: attendance, serving schedule, credentials), and revoke any grant instantly.
  • Credentials you earned (such as a completed leadership pathway) travel with you only if you choose to show them; underlying submissions remain with the issuing organization.
  • Staff of different organizations can be connected to each other only through your grant, never on their own initiative.

Aggregate reporting to a parent or national body. Some organizations belong to a wider body (for example, a campus ministry within its national fellowship) that asks for an annual statistical report. Where your organization chooses to participate, the Platform transmits counts and totals only — how many people were involved in something — never your name, your record, or a row that identifies you. Small counts are suppressed so that individuals cannot be identified by subtraction. This is a transfer between separate legal entities and is disclosed here for that reason; it is controlled by your organization's decision to participate, and it is the only circumstance in which any data about your participation leaves your organization without your individual grant.

If you connect an external account (such as Planning Center) to your profile, we read only what that connection permits, only for the purposes you granted, and you may disconnect at any time.

7. AI and Automated Processing

Where AI-assisted features are enabled (such as curriculum drafting assistance or report narration), they operate under a hard product boundary:

  • AI never reads or analyzes doerstep submissions, reflections, or pastoral conversations for meaning.
  • AI never scores, ranks, or evaluates any person's spiritual health.
  • AI is never part of crisis or escalation pipelines.
  • AI does not ghost-write personal pastoral messages.

One honest exception, stated precisely. If you submit a voice or video response, the Platform may run mechanical speech-to-text transcription on it, so that your leader can read what you said instead of watching a recording, and so captions exist for accessibility. That is a machine converting audio to text. It is not analysis: nothing scores it, summarizes it, draws conclusions about you from it, or feeds it into any model that evaluates people. Transcription runs only on media you submit for that purpose, and the resulting transcript carries the same visibility restrictions as the submission itself. You can decline transcription for your own submissions.

AI processing for permitted features uses a third-party provider (Anthropic) under contractual data protection terms. Content sent for AI processing is limited to what the feature requires.

8. Service Providers

We use a small set of processors to operate the Platform, currently: Supabase (database and authentication), Railway (application hosting), Cloudflare (DNS, network, and R2 object storage for video and media), Sentry (error monitoring — configured not to attach user identity or request contents to error reports), Resend (transactional email), Anthropic (AI features — not yet in use), Stripe (payment processing — not yet in use; billing is dormant), and an SMS provider (not yet in use). Each processes data only to provide their service to us. A current list is available on request and is kept up to date as providers change.

9. What We Never Do

  • Sell personal data
  • Use ministry data for advertising
  • Share personal data between organizations without your grant (aggregate statistical reporting under Section 6 is counts only, never personal data)
  • Scan private communications for marketing or profiling
  • Allow platform staff access without audit logging

10. Retention and Deletion

  • Active organizations control their own data and its retention within the Platform.
  • Cancelled organizations: data is frozen for 90 days (export or reactivation available), then deleted, except where law requires longer retention or a legal hold applies.
  • Your own copy survives. When an organization's data is deleted, each person who took part keeps a permanent frozen snapshot of their own formation record — what they completed and when — which they keep and can show. It contains their own record only: not leader notes about them, not other people's data, not the organization's media.
  • Closed individual accounts: personal identifiers are anonymized in accordance with applicable law (including the Texas Data Privacy and Security Act and, where applicable, GDPR). Organizational formation records (attestations, aggregate history) are retained by the issuing organization in anonymized or membership-record form as permitted by law.

Limit of anonymization, stated honestly: a voice recording, a video of a person, a photograph, or free text in which someone describes their own identifiable situation cannot be anonymized by removing a name. Where you have submitted such content, we delete it rather than claim to anonymize it, unless a legal hold requires retention. The record that a formation event occurred (what was completed and attested) may be retained without the media. - Legal holds: where we are legally obliged to preserve specific data, deletion is suspended for that data until the obligation ends. - Audit logs are append-only and tamper-evident, retained for integrity and legal purposes. The database rejects modification of audit records, including through our own administrative credentials. We do not claim they are beyond our physical reach — we operate the database — but no ordinary path, including our support tooling, can alter them, and every platform read is itself logged. - Backups are automated daily and retained on a rolling seven-day schedule; point-in-time recovery is not yet enabled and will be before any organization outside the founding pilot is onboarded. Deleted data may persist in backups until those backups age out.

11. Your Rights

Depending on your location, you may have rights to access, correct, delete, export, or restrict processing of your personal data, and to withdraw consent. For data controlled by your organization, we will route your request to them and support their response. Where you are recorded by an organization but do not hold an account, you (or your parent or guardian) may still make a request to us directly at the address below. To exercise rights: [PRIVACY EMAIL]. We respond within the timelines required by applicable law. We do not discriminate against anyone for exercising privacy rights.

12. Minors

During the founding pilot Doersteps accounts require a minimum age of 18. Support for accounts held by people aged 13–17 is planned; when it is available, organizations may raise the minimum age, and where they enable minor accounts (13–17), additional safeguards apply, including optional linked parent accounts and configurable consent flows. Parent links expire automatically when the minor turns 18, with notice to both parties.

Children under 13 who are recorded but do not have accounts. A ministry may keep records about a child under 13 who takes part in it — a name on a roster, attendance, a guardian's contact details — without that child having an account or using the Platform. In that case the organization is responsible for obtaining any parental consent the law requires and for having a lawful basis to keep those records. A parent or guardian may contact us directly at the address below to see, correct, or delete what is held about their child, and we will route the request to the organization and support its response.

13. Security

Security measures include: row-level security enforced in the database, two-factor authentication (available for every account; your organization may require it for leader-level accounts and above), passwordless login options, encryption in transit, role-scoped access throughout, append-only audit logging, and daily backups whose restoration will be tested before any organization outside the founding pilot is onboarded.

Breach notification. No system is perfectly secure. If we determine that a security incident has compromised personal data, we will notify the affected organization's administrators without undue delay and no later than 72 hours after making that determination, and will notify individuals and regulators where the law requires it. Notice will state what we know, what data was involved, what we are doing, and what you should do.

14. International Users

The Platform is operated from the United States. If you use it from elsewhere (including through Chi Alpha's global work), your data is processed in the United States under this policy. Additional regional terms may be added as the Platform grows internationally.

15. Changes

We will announce material changes in-app or by email with reasonable notice before they take effect.

16. Contact

Privacy questions and requests: [PRIVACY EMAIL] Postal address: [ADDRESS - add at LLC formation]

Make a privacy request → You do not need an account, and you can ask on behalf of a child.

Terms of Service · Privacy Policy