Privacy Policy

Effective August 2, 2026

Who this is for

Coptic Leader is used by adult ministry volunteers and leaders. It also stores information about the children served by the ministry, entered by those authorized adults — children do not have accounts and do not use the app. Each church controls the information about its own community; we store and process it on the church's behalf.

What we collect

About adult users: name, mobile number, email (if you use Apple/Google sign-in), a hashed login PIN, linked sign-in methods, device push tokens, and sign-in records.

About children (entered by authorized adults): name, age, grade/group, photo and photo-permission status, allergies and medical notes, general notes, and parent/guardian contact details.

Activity: messages, attendance, lessons, outreach logs, RSVPs, and similar ministry records.

We do not collect biometric or government-ID data, and we do not use this information for advertising.

How we use information

Only to run the ministry-coordination features, authenticate users, send service and reminder notifications, keep the app secure, and comply with law. We do not sell personal information or use it for third-party advertising.

How information is shared

Only with service providers that help us run the app (such as our database/hosting, SMS, and push providers) under contracts that require them to protect it, or where required by law.

Children's information

Information about children is entered by authorized adults who confirm they have the appropriate authority and consents. We apply data minimization, retention limits, no advertising or sale, and access controls. Parents and guardians may request access, correction, or deletion through their church.

Retention

We keep information only as long as needed to provide the service, then delete or anonymize it. When a church stops using the app, its data is deleted or returned per our agreement with that church.

Security

We treat information about children as the most sensitive data in the app and protect it in layers.

Encryption in transit. All traffic between your device and our servers is encrypted with HTTPS/TLS. Our mobile apps do not permit unencrypted connections.

Encryption at rest. Our database provider encrypts all stored data with AES-256. In addition, home addresses and dates of birth — for children and adults alike — are separately encrypted by the app itself using AES-256-GCM before they are written to the database. The key for that encryption is held outside the database, so a copy of the database on its own does not reveal those fields.

Account protection. Sign-in PINs are stored only as salted one-way hashes, never in readable form. Repeated failed sign-in attempts trigger automatic lockouts that lengthen with each attempt. Sessions can be revoked immediately: signing out, resetting a PIN, or deactivating an account invalidates existing sign-ins on every device.

Access controls. Access is limited by role and by class, so a servant sees the children in their own class. Photos and file attachments are permission-checked individually on every request rather than merely hidden from view, and all files are kept in private storage with no public links.

Monitoring and audit. Privileged actions are written to an audit log, sign-ins are recorded with shortened IP addresses, and unusual patterns of failed sign-ins generate automatic alerts to the operator.

Ongoing maintenance. Our software dependencies are automatically scanned for known vulnerabilities, the database is backed up daily, and the web app sets modern browser protections including HSTS, a Content Security Policy, and clickjacking protection.

No advertising or tracking. The app contains no third-party advertising or tracking software, and no information is used for advertising.

No method of transmission or storage is 100% secure, and we cannot guarantee absolute security. If we learn of a breach affecting your information, we will notify affected parties as required by law.

Your rights

You may delete your account from within the app, and request access, correction, export, or deletion of your information. Some requests are coordinated with your church, which controls its community's data.

Contact

Questions about privacy? Contact your ministry administrator or the app operator.