This Privacy Policy explains how Orange Forge LLC (“Orange Forge,” “we,” “us”) collects, uses, shares, and protects information when you use the Covenant Circles mobile application (the “Service”). By using the Service, you agree to the practices described here.
1. Who we are and how to contact us
Data controller:
Orange Forge LLC
7901 4th St N, Ste 300
St. Petersburg, FL 33702
U.S.A.
- General questions: info@covenantcircles.app
- Privacy questions, data requests, deletion requests: privacy@covenantcircles.app
- Moderation appeals: moderation@covenantcircles.app
EU / UK representatives. Where required by GDPR Article 27 or UK GDPR, we will appoint and identify here a representative established in the EEA and the UK before commencing processing of EEA/UK personal data. We have not yet engaged a representative; the Service is not yet offered to EEA/UK residents. If you reach us from the EEA, UK, or Switzerland in the meantime, you may contact us at privacy@covenantcircles.app, but please note this address is not a substitute for an Article 27 representative.
2. What we collect and why
We collect only the minimum data needed to operate the Service.
2.1 Information you provide
- Display name, optional nickname. Required to identify you to other Circle members.
- Birthday. Used to verify age (13+ minimum) and compute your displayed age. Birthday itself is never shown to other users; only the calculated age.
- Gender. Shown to other Circle members.
- Email address. Optional. If you link an email, we use it for sign-in across devices, password recovery, magic-link authentication, and to send moderation or account notifications.
- Daily check-in answers, prayer requests, replies, reactions. Visible to the 3–5 members of the Circles you belong to.
- Circle metadata you create. Circle name, optional discovery blurb, tags.
- Reports you file. When you report another member’s content, the report text and any attached screenshot.
2.2 Information collected automatically
- Device identifiers. Firebase Cloud Messaging (FCM) push token, device platform (Android/iOS), app version, OS version. Used to deliver push notifications and to diagnose crashes.
- Anti-abuse device identifier. On Android we read
Settings.Secure.ANDROID_ID(a 64-bit identifier scoped to your device + Google account + the Covenant Circles app signing key). On iOS we readidentifierForVendor(the equivalent per-vendor-per-device identifier). We store this only when an administrator has chosen to enforce an account suspension at the device level — see Section 5.4. We do not use this identifier for analytics, advertising, or anything other than enforcing existing bans against repeat-evasion attempts. - Authentication metadata. Sign-in timestamps, IP address at sign-in (kept by Supabase Auth for security purposes). IP address is used for security and abuse investigation only — never as a hard block by itself.
- Crash reports. When the app crashes, Firebase Crashlytics captures the stack trace, device model, OS version, and other technical context. Does not include the contents of your check-ins, prayers, or replies.
- Usage analytics. Firebase Analytics records anonymized events such as screens viewed, session length, feature usage. Linked to a randomly-generated app instance ID, not to your name or email.
2.3 What we do not collect
- We do not collect your phone number.
- We do not collect your precise location.
- We do not access your contacts, photos, calendar, microphone, or camera unless you explicitly attach a screenshot to a report.
- We do not use third-party advertising trackers.
3. Lawful basis for processing
For users in the EEA, UK, Switzerland, or Brazil, we rely on the following lawful bases:
| Data | Purpose | Lawful basis |
|---|---|---|
| Profile (name, age, gender) | Provide the Service | Contract performance |
| Check-ins, prayers, replies | Provide the Service | Contract performance |
| Sign-in, account notifications | Contract performance | |
| FCM token | Deliver push notifications | Consent (you must opt in) |
| Anti-abuse device identifier | Enforce suspensions against repeat-evasion attempts | Legitimate interest (anti-abuse) |
| Crash reports | Diagnose and fix bugs | Legitimate interest |
| Usage analytics | Improve the Service | Legitimate interest |
| Reported content + admin review | Moderation and safety | Legitimate interest |
You may withdraw consent for push notifications at any time in Settings.
4. How your information is used
- To operate the Service. Showing your check-ins, prayers, and replies to fellow Circle members.
- To authenticate you. Magic-link emails for cross-device sign-in.
- To send notifications. Daily digest reminders (only if you opt in), reply pushes (only if you opt in), and moderation notifications.
- To moderate the Service. When a member reports another member’s content, our administrators may review the specific reported message and a small amount of surrounding context (typically up to 5 messages above and below the reported one) to make a decision. We do not routinely read Circle content. Every administrator action — including dismissal of a report — is logged with timestamp and reviewer identity, and we retain those moderation logs for at least 18 months.
- To improve the Service. Anonymized analytics inform product decisions.
- To comply with law. Including reporting Child Sexual Abuse Material to NCMEC and law enforcement as required.
We do not use your content — including check-ins, prayers, or replies — to train any machine learning model.
5. Who can see your information
5.1 Other Circle members
Members of a Circle you belong to see your display name, age, gender, daily check-in answers, non-anonymous prayer requests, and your replies and reactions. Anonymous prayer requests are stored without your user ID being visible to other members and are shown as “Anonymous.”
5.2 Discoverable Circles
If a Circle is marked discoverable, its name, blurb, tags, and member count are visible to any signed-in user. Messages and member profiles within a discoverable Circle remain private to its members.
5.3 Orange Forge administrators
Our administrators may access your account profile (name, age, gender, linked email); specific content you have reported, or content reported about you, plus a small amount of surrounding context — only when a moderation review is in progress; aggregate technical telemetry (crashes, analytics); and the anti-abuse device identifier of an account they have suspended, when they have explicitly chosen to enforce that suspension at the device level. Administrator actions are logged in an audit trail.
5.4 Device-level enforcement of suspensions
When an administrator suspends an account, they may additionally choose to record the device identifier described in Section 2.2 against the suspension. While the suspension is active, future sign-ups or sign-ins from that same device will be refused with an explanatory message and an appeal email link. This is opt-in per suspension, not automatic. We use it for repeat offenders, content involving minors, threats of violence, or attempts to evade an existing ban. Device-level enforcement is lifted automatically when the underlying suspension expires or is lifted on appeal.
5.5 Service providers (sub-processors)
We share specific data with the following providers, each under a Data Processing Agreement that restricts use to providing services to us:
| Provider | Data shared | Purpose | Region |
|---|---|---|---|
| Supabase, Inc. | Profile, check-ins, prayers, replies, auth credentials, FCM tokens | Database, authentication, storage | United States |
| Resend, Inc. | Email address, sign-in / notification email contents | Transactional email delivery | United States |
| Google LLC (Firebase) | FCM token, crash reports, anonymized analytics events | Push notifications, crash reporting, usage analytics | United States |
| Apple, Inc. / Google LLC | Subscription status (if applicable) | Payment processing | United States |
We do not sell your information to third parties for advertising or any other purpose.
5.6 Legal disclosures
We may disclose information when required by law, subpoena, or other legal process, or when we believe in good faith that disclosure is necessary to (a) comply with a legal obligation, (b) protect the rights or safety of Orange Forge, our users, or the public, or (c) detect, prevent, or address fraud, security, or technical issues.
6. International data transfers
The Service is operated from the United States. If you are accessing the Service from outside the United States, your information will be transferred to and processed in the United States, where data protection laws may differ from those in your jurisdiction.
For transfers from the European Economic Area, United Kingdom, Switzerland, or Brazil to the United States, we rely on the European Commission’s Standard Contractual Clauses (SCCs), equivalent UK and Swiss data transfer agreements, and appropriate safeguards as defined in the relevant data protection law. You may request a copy of the SCCs by emailing privacy@covenantcircles.app.
7. Data retention
| Data | Retention |
|---|---|
| Account profile | Until you delete your account; then up to 30 days for full removal, plus up to 90 days in routine backups. |
| Check-ins, prayers, replies, reactions | Same as account. |
| Linked email address | Same as account. |
| Authentication logs | 90 days. |
| Crash reports | 90 days. |
| Analytics events | 14 months. |
| Moderation reports | 3 years from filing. |
| Moderation audit log | 18 months minimum, longer where required by law. |
| Banned email blocklist | Until the ban is lifted by an administrator. |
| Device blocklist | Until the underlying ban is lifted on appeal or expires by its set duration. Erasure requests under Section 8 will replace the identifier with a salted hash so the block remains enforceable while no longer being personally identifying. |
8. Your rights
Depending on where you live, you may have some or all of the following rights regarding your personal data:
- Access — Request a copy of the data we hold about you.
- Rectification — Correct inaccurate data.
- Erasure (“right to be forgotten”) — Request deletion of your data.
- Portability — Receive your data in a structured, commonly used format.
- Restriction of processing — Limit how we use your data.
- Objection — Object to processing based on legitimate interest.
- Withdraw consent — Where processing is based on consent, withdraw it without affecting prior processing.
- Lodge a complaint — With your local data protection authority.
To exercise any of these rights, email privacy@covenantcircles.app. For GDPR / UK GDPR requests we respond without undue delay and in any event within one month of receipt; where the request is complex we may extend that period by up to two further months and will tell you within one month if we do. For U.S. state-law requests we respond within the period required by the applicable statute (typically 45 days, with one 45-day extension where reasonably necessary).
8.1 California (CCPA / CPRA)
If you are a California resident, you have the rights described above plus the right to limit our use of sensitive personal information (account log-in credentials and the contents of your in-app communications), the right to non-discrimination for exercising any CCPA right, and the right to designate an authorized agent to make a request on your behalf. We do not sell personal information and we do not share it for cross-context behavioral advertising. To exercise: privacy@covenantcircles.app.
8.2 Other U.S. states
If you reside in Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, Tennessee, Iowa, Indiana, Delaware, New Hampshire, New Jersey, or another U.S. state with a comprehensive consumer privacy law, you may have rights of access, correction, deletion, portability, opt-out of sale or sharing, opt-out of profiling for decisions producing legal or similarly significant effects, and the right to appeal a denied request. Email privacy@covenantcircles.app.
8.3 Brazil (LGPD)
If you are a resident of Brazil, you have rights of confirmation of processing, access, correction, anonymization, portability, deletion, information about sharing, and revocation of consent. Contact privacy@covenantcircles.app.
9. Children
The Service is for users 13 and older. We do not knowingly collect personal information from anyone under 13. If you are a parent or guardian and believe your child under 13 has provided us with personal information, contact us at privacy@covenantcircles.app and we will delete it. For users between 13 and 16 in jurisdictions where heightened consent applies (e.g. some EU member states), parental consent may be required.
10. Security
We use industry-standard technical and organizational measures to protect your information: all data in transit is encrypted via TLS 1.2+; data at rest is encrypted by Supabase (database) and Google (Firebase services); row-level security policies restrict access at the database level; administrator access is gated behind email + password authentication and logged. No system is perfectly secure. If you become aware of unauthorized access to your account, contact info@covenantcircles.app immediately.
11. Changes to this Policy
We may update this Policy from time to time. Material changes will be communicated via email and a banner in the app at least 14 days before taking effect. Continued use after that date constitutes acceptance.
12. Contact
For privacy questions, data requests, or to exercise any right described in Section 8: privacy@covenantcircles.app
For general questions: info@covenantcircles.app
For moderation appeals: moderation@covenantcircles.app
13. Sub-processor data processing agreements
The sub-processors disclosed in Section 5.5 each offer Data Processing Agreements (DPAs) under their standard commercial terms. Before processing personal data of EEA, UK, or Swiss residents we will: (a) execute each provider’s DPA incorporating the EU Standard Contractual Clauses (and UK / Swiss equivalents); (b) confirm our role and theirs (controller / processor / sub-processor) for each data flow; and (c) keep an internal record of those agreements and supplementary measures (technical and organizational) consistent with the Schrems II analysis.