Privacy Policy
Effective date: September 21, 2026
Koinonia Harvest (the “App”) is a private community app for churches. Your church is a closed space: members of your congregation see each other, and no one outside it does. This policy explains what we collect, why, and who it reaches.
The App is operated by Koinonia Harvest INC., a nonprofit corporation, PO Box 599, Springfield, OR 97477, United States.
1. Who can use the App
You must be 18 or older to create an account. The App is not directed to children, and we do not knowingly collect information from anyone under 18. If we learn that we have, we delete it.
Joining requires a church code from your church. You cannot browse or join a congregation without one.
2. What we collect
Information you give us
- Account details: your email address and password, used to sign in.
- Profile details: your display name, and optionally your full name. Your initials, drawn from your name, appear to other members as your avatar.
- Your church: the church code you enter, which links your account to one congregation.
- What you post: prayer requests, help requests, encouragements, answered-prayer testimonies, and direct messages to other members.
- Your preferences: notification settings, and the list of members you have blocked.
Information the App generates
- Activity: which requests you have prayed for or offered help on, your prayer streak, and the badges you have earned.
- Device token: a push notification token for each device you sign in on, so we can deliver notifications.
- Crash and performance data: if the App crashes or errors, a diagnostic report, tagged with your user ID and church ID so we can trace the problem.
What we do not collect
- We do not collect your location. The App has no location features.
- We do not collect your date of birth, and we do not ask for your phone number.
- We do not use advertising identifiers, and there is no advertising in the App.
3. Who can see what you post
Every prayer or help request you post has a single visibility choice, made by you when you post it:
- Whole church — visible to every member of your congregation in the App.
- Staff only — visible only to your pastoral staff and church administrators.
Your church’s pastoral staff and administrators can see member profiles, staff-only requests, and content that has been flagged for review. Your church’s pastoral staff can also read direct messages exchanged within your church, and the platform administrator can read them across churches. Every conversation in the App says so. We do this so that staff can help a member who is being harassed or pressured over messages, and can act on messages the automated safety review holds back. Direct messages are still never visible to other members, and never to anyone outside your church.
Your content is never visible to members of any other church. Congregations are isolated from one another at the database level.
4. Service providers who process your data
We do not sell or rent your personal information. We use the following providers to operate the App, and each receives only what it needs:
| Provider | What it receives | Why |
|---|---|---|
| Supabase | All app data — account, profile, posts, messages | Hosting and database (United States) |
| Anthropic | The text of prayer requests, help requests, and messages | Automated safety review before content appears |
| Expo | Your device push token, and notification titles and bodies | Delivering push notifications |
| Sentry | Crash reports, your user ID and church ID | Diagnosing errors and crashes |
About the safety review. When you post a request or send a message, its text is sent automatically to Anthropic’s Claude API, which checks it for content that would violate our Community Guidelines — threats, harassment, scams, and similar. This happens before the content becomes visible to others. Anthropic does not use this text to train its models, and does not retain it for its own purposes. We use this because a church app carries tender things — illness, addiction, marriages under strain — and automated review lets us protect members without a person reading every post.
We may also disclose information if required by law, court order, or where we believe in good faith it is necessary to prevent harm.
5. How long we keep your data, and how to delete it
You can request deletion of your account from within the App, under Settings.
When you request deletion, a 30-day grace period begins. You can sign back in during that window to cancel. After 30 days, your account is permanently deleted and your past posts are anonymized rather than erased — the author’s name is removed, but the request itself remains. We do this so that a prayer chain other members responded to does not vanish out from under them. If you want a post gone entirely, delete the post itself before deleting your account.
You can download a copy of your data at any time from Settings, which produces a file containing your profile, your posts, and your activity.
6. Security
Data is encrypted in transit. Access is enforced at the database level, so one church’s data cannot be reached from another church’s account. No system is perfectly secure, and we cannot guarantee absolute security.
7. Your choices
- Update your profile at any time in the App.
- Turn notifications off in the App’s notification settings, or in your device settings.
- Block another member, which hides their content from you and yours from them.
- Report content that violates our Community Guidelines, from the post or message itself.
8. Changes to this policy
We may update this policy. If we change it materially, we will post the updated policy here with a new effective date, and where appropriate notify you in the App.
9. Contact
Questions about this policy or your data: Dillon@koinoniaharvest.com, or Koinonia Harvest INC., PO Box 599, Springfield, OR 97477.
