Skip to main content

Terms of Service

Version v0.3-2026-09-18 · effective September 18, 2026

Doersteps Terms of Service

WORKING DRAFT v0.3 - NOT YET REVIEWED BY AN ATTORNEY *This draft must receive professional legal review before any organization outside the founding beta signs up. Review is calendared alongside the LLC formation milestone.*

*v0.2 (2026-07-30) incorporates the 2026-07-29 field audit: renamed from XALT, disclosed per-person engagement analytics and data-access covenants, corrected promises the architecture cannot keep (audit-log immutability, fork continuity vs. deletion, anonymization of recorded media), added breach-notification, legal-hold, and assignment clauses, and fixed a liability cap that evaluated to zero for unpaid organizations. Changes are drafting improvements for the attorney to review, not legal advice.*

*v0.3 (2026-09-18) aligns the draft with what the platform can actually keep as of the founding pilot, following the 2026-09-17 field audit: accounts are 18+ during the pilot (minor accounts are planned, not available); two-factor authentication is available but not enforced; video engagement analytics are not yet offered; backups are daily with seven-day retention and point-in-time recovery is not yet enabled; the processor list marks providers not yet in use. Audit logging, break-glass access, export and the organization-closure snapshot are described as the platform now implements them. Changes are drafting improvements for the attorney to review, not legal advice.*

Last updated: 2026-09-18 (draft v0.3)

1. Who We Are

Doersteps ("the Platform," "we," "us") is a ministry software platform operated by [ENTITY NAME - currently sole proprietorship, to become LLC]. Doersteps provides tools for discipleship pathways, leadership training, small group management, and ministry communication.

2. Accounts and Eligibility

2.1. During the founding pilot you must be at least 18 years old to create an account. Support for accounts held by people aged 13–17, with the safeguards described in 2.2, is planned but not yet available; until it is, an organization may record a younger participant only as a non-account record under 2.5. When minor accounts become available, organizations may raise (but not lower) the minimum age for their own members.

2.2. When minor accounts become available, users under 18 may be subject to additional safeguards configured by their organization, including linked parent or guardian accounts. Where an organization enables parental consent requirements, a parent or guardian must approve the minor's account before it becomes active.

2.3. You agree to provide accurate information and to keep your login credentials secure. Two-factor authentication is available for every account. Your organization may require it for accounts at leader level and above; during the founding pilot it is not enforced.

2.4. Each account belongs to one person. Sharing accounts is not permitted.

2.5. Records about people who do not hold accounts. Organizations may keep records about people who have no Doersteps account, including children under 13 tracked on a roster by their ministry and people who have not yet signed up. These people are not users and do not agree to these terms; the organization that records them is responsible for having a lawful basis to do so and for honoring their rights. We provide a route for such a person (or their parent or guardian) to make a data request to us directly.

2.6. Data-access covenants. People whose role lets them see other people's records may be required to sign a versioned data-handling covenant before that access is granted. Your organization, or we, may require re-signature when the covenant is updated. Signatures are recorded in a consent ledger with the version signed and the time of signature. Declining, or letting a required signature lapse, removes the elevated access, not the account.

3. Organizations and Roles

3.1. Doersteps accounts exist within organizations (churches, campus ministries, and similar groups). Your organization's administrators control your role, permissions, and what you can see and do within their organization.

3.2. Your organization is responsible for how it configures Doersteps, including chat visibility settings, safeguarding features, engagement-analytics settings, and content curation for its members.

3.3. Organization administrators may remove members, change roles, and in serious cases fully remove a person's access and contact surface within their organization. These actions are logged.

4. Transparency About Visibility (Read This Section)

Doersteps is ministry oversight software. It is built so that spiritual care can be supervised. By using Doersteps you acknowledge:

4.1. Group chats and channels are visible to your organization's leadership chain. This is disclosed in the chat interface itself.

4.2. Direct messages are private from ordinary view, but organization administrators hold an audited emergency access capability ("break-glass"). Any such access requires a recorded reason and is visible to other administrators in the organization's audit log.

4.3. Pathway submissions, reflections, and related content are visible to your assigned leaders and your organization's staff according to your organization's configuration.

4.4. Leader notes about members flow upward to those responsible for leader development. Members do not see leader notes.

4.5. Platform-level access: Doersteps platform staff can technically access tenant data for support, safety, and legal compliance purposes. Every platform-level read of tenant data is written to that organization's own audit log, which organization administrators can inspect at any time.

4.6. Doersteps chats are not end-to-end encrypted, by design, because organizational safeguarding requires readability. Do not use Doersteps for communications you need to keep from your organization's leadership.

4.7. Engagement analytics, including per-person video viewing — not yet offered. Video engagement analytics are not part of the Platform today. When they are offered, and when you watch video content in Doersteps, the Platform will record how you watched it: how much you watched, where you stopped, whether you skipped, and what playback speed you used. Where your organization enables it, designated staff can see this attributed to you by name, not only as an anonymous average.

This exists so organizations can tell whether required content was actually engaged with, in the same way attendance is recorded. It is treated as participation data, not as an assessment of your spiritual life, and it is never used to rank people against each other. Your organization controls whether the feature is on at all and which roles can see it; by default, small-group leaders cannot, and campus staff can.

4.8. Practice records. Where your organization uses practice thresholds, the amounts you log are visible to you and to your assigned leader. Staff see only whether a threshold has been met, never the underlying quantities, and these amounts are never ranked or compared between people.

5. Content You Create

5.1. You retain ownership of content you create on Doersteps (curriculum, submissions, messages, files).

5.2. You grant Doersteps a limited license to host, display, transmit, and back up your content solely to operate the Platform.

5.3. Curriculum publishing. When you publish curriculum with Organization or Public visibility, you grant other permitted organizations and users the right to view, copy ("fork"), and adapt that curriculum within the Platform, with attribution preserved. Withdrawn content stops appearing in catalogs, while existing forks continue to function.

5.4. What survives your departure, and what does not. Section 10.2 deletes an organization's data after the recovery period. That includes media files the organization hosted. Where another organization has forked your curriculum:

  • The fork's text, structure, and settings are copies held by the forking organization and continue to work.
  • Video, audio, and other large media served from your organization's storage stop working when that storage is deleted. We cannot both honor deletion and keep serving your files.

Forking organizations are notified when upstream media becomes unavailable and see a clear placeholder rather than a silent break. If you need media continuity after you leave, the forking organization must host its own copy while your account is still active.

5.5. Rights affirmation. By publishing content to the public catalog you affirm that you own or have rights to all included material, including video, audio, images, and text. You are solely responsible for rights violations in content you publish.

5.6. Doersteps does not endorse user-published content. Attribution of source is displayed so organizations can evaluate content for themselves. Doersteps does not referee theology.

5.7. We may remove content that violates law, these terms, or platform safety policies. Flagging, withdrawal, and removal processes preserve continuity for students mid-course wherever possible.

6. Acceptable Use

You agree not to: - Break the law or help anyone else do so - Harass, abuse, exploit, or endanger any person, especially minors - Upload malicious code or attempt to breach Platform security - Misrepresent your identity or organizational affiliation, including falsely claiming affiliation to obtain discounts - Scrape, resell, or bulk-export data belonging to people who have not authorized you - Circumvent safeguarding features, moderation states, or access controls

6.1. Real human voices only. Audio and video you upload must be recorded by the actual people speaking. Do not upload synthetic, cloned, or AI-generated voices, and do not use a synthetic voice to represent a teacher, leader, or any other person. Formation happens through real people; a ministry teaching through a manufactured voice is not what this Platform is for. This applies to curriculum, submissions, and any other uploaded media.

Accessibility tooling that does not impersonate a person — captions, transcripts, screen readers, and text-to-speech a reader turns on for themselves — is permitted and encouraged.

Violations may result in suspension or termination. Where minors' safety is involved, we may act immediately and report to authorities as required by law.

7. Safeguarding and Mandatory Reporting

7.1. Doersteps provides safeguarding tools (escalation flags, oversight visibility, leader requirement checklists, parent accounts). Organizations are responsible for configuring and using them appropriately for their context.

7.2. Doersteps is not a crisis service. The Platform's escalation features route concerns to your organization's designated people, not to Doersteps staff or emergency services.

7.3. Organization leaders may be mandatory reporters under their local law. Nothing in these terms limits any legal reporting obligation.

8. Billing

8.1. Paid plans are priced by seats (active accounts) plus optional add-ons (such as SMS credits and AI usage). Current pricing is displayed on the pricing page.

8.2. Affiliation discounts (including the Chi Alpha discount) apply only after affiliation is verified through our approval process, and may be revoked if affiliation ends. If you upgrade before verification completes, the discount applies going forward from verification, with a credit for the difference in the current billing period.

8.3. Founding pricing: organizations subscribed under early access pricing keep that pricing for as long as their subscription remains continuously active.

8.4. Prepaid add-on credits (SMS, AI) do not expire while your subscription is active but are not refundable.

8.5. You may upgrade, downgrade, or cancel at any time, effective at the next billing cycle.

9. SMS and Communications Consent

9.1. By providing a phone number and opting in, you consent to receive text messages from your organization through the Platform. Message and data rates may apply.

9.2. You may opt out of SMS at any time by replying STOP or changing notification settings. Opting out never blocks your access; the Platform falls back to other channels.

9.3. Transactional email (login links, receipts, required notices) is part of operating your account and cannot be fully disabled while your account is active.

10. Data Ownership and Export

10.1. Your organization's data belongs to your organization. Export is available at all times without gatekeeping.

10.2. Upon subscription cancellation, organization data enters a 90-day frozen recovery period during which you may export or reactivate. After that period, data is deleted, subject to legal retention requirements, the personal-record provision in 10.3, the legal-hold provision in 10.6, and the audit log provisions in 10.5.

10.3. What an individual keeps when an organization closes. A person's own formation history does not disappear because the organization that recorded it shut down. When an organization's data is deleted under 10.2, each person who took part keeps a permanent frozen snapshot of their own record — what they completed, when, and what was attested — which they can continue to view and share.

The snapshot is the person's copy, not the closed organization's records: it does not include leader notes about them, other people's data, or the organization's operational content. Media files are not included in the snapshot; it is a record of formation, not an archive of video.

10.4. Individual users may close their accounts. Formation records (such as pathway submissions and attestations) are part of the issuing organization's records; account closure anonymizes personal identifiers as required by applicable law rather than deleting organizational history.

Honest limit on anonymization: removing a name from a database row does not anonymize a voice recording, a video of a person, a photograph, or free-written text in which a person describes their own identifiable circumstances. Where you have submitted such content, we delete it rather than claim to anonymize it, unless a legal-hold obligation under 10.6 requires its retention. If deleting it would destroy an organization's record of a formation event, the record of the event (what was completed and attested) is retained without the media.

10.5. Audit logs. Audit logs are append-only and tamper-evident. The database rejects updates and deletions to audit records, and this restriction applies to our own administrative database credentials, not only to organization users.

We state this precisely rather than promising the impossible: we operate the database, so we could in principle alter its underlying storage. What we commit to is that (a) no ordinary path — including our own support tooling — can modify an audit record, (b) every platform-level read is itself written to the organization's log, and (c) tampering would be evident rather than silent. Audit logs survive within the retention window even after tenant deletion, for integrity and legal purposes.

10.6. Legal holds. If we receive a legal obligation to preserve specific data (litigation, subpoena, regulatory demand, or a credible safeguarding investigation), we will suspend deletion of the affected data for as long as that obligation lasts. A legal hold overrides the deletion timelines in 10.2, 10.3, and 10.4 for the specific data covered. Where we are legally permitted to tell you, we will.

11. Service Availability, Security, and Incidents

11.1. We aim for high availability but do not guarantee uninterrupted service. Maintenance windows and outages may occur.

11.2. We perform automated daily backups, retained on a rolling seven-day schedule. Point-in-time recovery is not yet enabled and will be enabled before any organization outside the founding pilot is onboarded. You are encouraged to maintain your own exports of critical data.

11.3. Breach notification. If we determine that a security incident has compromised personal data belonging to your organization or its members, we will notify the organization's administrators without undue delay and no later than 72 hours after we determine a breach affecting your data has occurred. Notice will describe what we know, what data was involved, what we are doing, and what you should do. Where the law requires you to notify affected individuals, we will give you the information you need to do so.

12. Termination

12.1. You may stop using Doersteps at any time. Organizations may cancel per Section 8.5.

12.2. We may suspend or terminate accounts or organizations for material violation of these terms, non-payment, legal requirement, or serious safety risk. Where practical, we will provide notice and export opportunity consistent with Section 10.

13. Disclaimers and Limitation of Liability

13.1. THE PLATFORM IS PROVIDED "AS IS" WITHOUT WARRANTIES OF ANY KIND, EXPRESS OR IMPLIED.

13.2. DOERSTEPS IS A SOFTWARE TOOL. IT DOES NOT PROVIDE PASTORAL CARE, COUNSELING, OR EMERGENCY SERVICES, AND IS NOT RESPONSIBLE FOR THE CONDUCT OF ORGANIZATIONS OR USERS.

13.3. TO THE MAXIMUM EXTENT PERMITTED BY LAW, OUR TOTAL LIABILITY FOR ANY CLAIM IS LIMITED TO THE GREATER OF (A) THE AMOUNTS YOU PAID US IN THE TWELVE MONTHS BEFORE THE CLAIM AROSE, OR (B) ONE HUNDRED U.S. DOLLARS.

[Attorney note: the previous draft capped liability at amounts paid, which is zero for free-tier and beta organizations — a cap of zero is unenforceable in several jurisdictions and reads as bad faith. A floor is included here as a starting point; please advise on the appropriate figure and on whether safeguarding-related claims should be carved out of the cap entirely.]

13.4. Some jurisdictions do not allow certain limitations; in those places, these limits apply to the fullest extent permitted.

14. Changes to These Terms

We may update these terms. Material changes will be announced in-app or by email with reasonable notice. Continued use after the effective date constitutes acceptance.

15. Assignment and Change of Control

15.1. You may not transfer your rights under these terms without our written consent.

15.2. We may assign these terms and transfer the data they cover to a successor entity in connection with a reorganization, incorporation, merger, acquisition, or sale of assets. This expressly includes the planned transfer from the current sole proprietorship to the LLC that will operate the Platform. A successor is bound by these terms, including the privacy commitments and the visibility disclosures in Section 4, until they are changed under Section 14.

15.3. We will give organization administrators notice before personal data is transferred to a successor entity.

16. Governing Law

These terms are governed by the laws of the State of Texas, USA, without regard to conflict of law principles. [Confirm venue with attorney at LLC formation.]

17. Contact

Questions about these terms: [SUPPORT EMAIL]

Terms of Service · Privacy Policy