DRAFT — PENDING LEGAL REVIEW. This document is not final and is not legal advice.

EnKrist — Privacy Policy


1. Who we are (Controller)

EnKrist is a private, access-restricted online community platform for members of a faith community to share reflection, prayer, witness, and communal life. Registration is not open to the public — it requires a valid access code (see §4). The data controller is EnKrist LLC, 200 Public Sq, Ste 3000, Cleveland, OH 44114 ("EnKrist," "we," "us"). Contact for privacy matters: legal@enkrist.com. No Data Protection Officer is appointed; one is not required at the current stage.

2. Scope and the honest boundary of this policy

This Privacy Policy explains what personal data we process and why. It sits alongside our [Terms of Service] (the platform–user agreement) and our Acceptable Use Policy (conduct and content). Those documents govern their own subjects; this one governs privacy and data handling.

Stage of the service — this policy covers the MVP / closed pilot. EnKrist is at an early, access-restricted pilot stage. This policy describes the data practices of the service as it exists today: an adults-only, access-code-gated community with text-and-image content, private one-to-one and group messaging, and communities that members create and join. As EnKrist develops beyond the pilot, planned capabilities will materially change what personal data we process and how — and we will not extend the platform into any of them without first updating this policy, obtaining the legal review each requires, and (where the change affects the basis on which you agreed) re-seeking your consent (§13). Those planned capabilities include, without limitation:

  • Family / guardian-constituted circles involving minors — which would introduce a children's-data regime (verifiable guardian/parental consent, US COPPA and GDPR Art. 8, a children's privacy notice, age assurance, and CSAM/NCMEC handling). Not part of the current service (see §8).
  • Audio and video — media capture, storage, processing, and provenance handling.
  • Removal of the access-code wall (public access) — content addressed to "everyone" becoming reachable by the open internet rather than only admitted members, changing the exposure and the basis of publication.
  • Payments, subscriptions, or advertising/notices — payment and billing data and the associated compliance surface.
  • Notifications delivered by email or push — additional external processors and preference/opt-out handling (the current service is in-app only).
  • Institutional verification — verification and certification records for organisations.

Adults only. EnKrist is an 18+ platform. We are not built for, and do not knowingly admit, minors. Community types that would gather minors (family, school, and ministry-to-minors) cannot be created on the platform — this is enforced structurally, not merely promised (see §8).

3. The most important thing: we process special-category (religious) data

EnKrist exists to support faith-community life. By its nature, the platform processes data that reveals your religious beliefs and religious community affiliations — a special category of personal data under Article 9 of the UK/EU GDPR (and analogous "sensitive data" regimes elsewhere).

  • What makes it special-category: your membership in a faith community, the communities you join, and the devotional, prayer, and witness content you author all reveal religious belief.
  • Our lawful basis for processing it: your explicit consent under Article 9(2)(a), obtained at sign-up. At registration you must affirmatively check a consent box stating, in substance: "I agree to the terms and consent to EnKrist processing my faith-community data to provide this service." We record that you consented, and the version of the terms you consented to.
  • You can withdraw this consent at any time from your account settings, by a step no harder than the one by which you gave it. Withdrawal causes us to stop processing and erase your special-category faith data (§7); it does not require you to delete your whole account — you may keep a minimal account (email and display name only) or close the account entirely (§9). Withdrawal does not affect the lawfulness of processing before withdrawal.

4. What personal data we collect

We collect only what the service needs. We do not buy personal data, and we do not sell it.

(a) Account & identity — email address; a display name; a securely hashed password (managed by our authentication provider; we never store your password in readable form). A valid access code is required to register — registration is gated, not open to the public; the code gates sign-up only and is not retained as profile data.

(b) Profile — an optional short bio; an optional profile photo (avatar) you upload.

(c) Faith-community data (special category — see §3) — your community memberships and roles; the communities you create or join; and the content you author: witness posts, reflections, prayers, comments, and the audience scope you choose for each (private / your community / specific communities / everyone-within-the-platform).

(d) Messaging — private one-to-one and group chat messages you send, and contact requests ("pings") and group invitations. Messages are visible only to their participants.

(e) Engagement — reactions and acknowledgements you make (e.g., "Amen," "pray with," favoriting a prayer), and read/receipt state.

(f) Consent records — a record that you agreed to our terms and to the Acceptable Use Policy, and the version of each, with a timestamp (kept as an audit of lawful basis).

(g) Safety & moderation — reports you file or that concern you, and moderation actions, including a first-class "child-safety" report category routed to elevated review (see §8, and the Acceptable Use Policy).

(h) Technical & usage — data necessarily processed to operate the service: authentication session data, security and access logs, and product-analytics events (see §6 and our [Cookie & Analytics Notice]). We do not build advertising profiles.

5. Why we process it (purposes & lawful bases)

PurposeData usedLawful basis (GDPR)
Create and operate your account; provide the core service4(a)(b)(c)(d)(e)Performance of a contract, Art. 6(1)(b); and for religious/faith data, explicit consent, Art. 9(2)(a)
Restrict registration to access-code holders4(a)Legitimate interests, Art. 6(1)(f) — protecting a private community from open sign-up
Security, abuse prevention, moderation, and safety (incl. child-safety)4(a)(g)(h)Legitimate interests, Art. 6(1)(f); and compliance with legal obligations, Art. 6(1)(c), where reporting is legally required
Record and evidence your consent4(f)Legal obligation / legitimate interests (accountability, Art. 5(2))
Send essential transactional emails (verify email, reset password)4(a)Performance of a contract, Art. 6(1)(b)
Understand product usage to improve the service4(h)Consent (for non-essential analytics/cookies — see §6); otherwise legitimate interests for strictly-essential measurement

6. Cookies, analytics, and tracking

We use strictly-necessary cookies to keep you signed in and secure (set by our authentication provider). We also use a product-analytics service (PostHog) to understand how the service is used so we can improve it. We do not use advertising cookies and do not track you across other websites.

Details of each cookie/technology, its purpose, and how to control it are in our [Cookie & Analytics Notice]. Where consent is required for non-essential analytics, we will obtain it via a consent mechanism before those technologies are set.

No automated decision-making or advertising profiling. We do not use your personal data to make decisions about you that are solely automated and produce legal or similarly significant effects (GDPR Art. 22), and we do not build advertising or behavioural profiles of you. Our analytics are used in aggregate to improve the service; decisions that affect you — such as moderation or safety actions — involve human review.

7. How long we keep it (retention)

We keep your personal data for as long as your account is active. When you close your account or withdraw consent (§9), we erase your personal data through a dedicated deletion process, subject to narrow exceptions where we are legally required or permitted to retain specific records — for example, records relating to a safety report or unlawful-content matter that we must preserve to meet a legal obligation.

Consent-record exception (retained because of, not despite, your rights). Because your explicit consent is the lawful basis for our processing (§3), we retain a minimal, isolated proof-of-consent record — that you consented, and to which version, with a timestamp — even after your other personal data is erased. This record contains no faith content; it exists solely so we can demonstrate that our processing before erasure was lawful (GDPR Art. 5(2) accountability). We keep it for [LIMITATION PERIOD — counsel to set, e.g., the limitation period applicable to claims], then delete it. Other specific retention periods: [RETENTION SCHEDULE — counsel to set durations per category].

8. Children and structural safety (why "adults-only" is more than a promise)

EnKrist is for adults (18+). In the current service, the platform structurally prevents the creation of the community types that would gather minors — family, school, and ministry-to-minors communities cannot be instantiated by any means (a database-level constraint, not a checkbox). Because the platform cannot distinguish adult ministry from ministry to minors, ministry-type communities are un-instantiable in their entirety for now.

This is a deliberate scope boundary of the current adults-only service — not a permanent limitation of EnKrist. Families, youth, and ministry contexts that involve minors are deferred, not foreclosed: they are walled out only until they can be offered correctly, behind the children's-privacy protections such features require — age assurance, verifiable parental/guardian consent, and the associated safeguarding and reporting duties — and would be introduced only with qualified legal counsel, under a separate children's-privacy notice. Until then, this Policy and the service are for adults.

We do not knowingly collect personal data from anyone under 18. If we learn that a minor has provided personal data, we will delete it. Age-verification, guardian-consent, and mandatory child-safety-reporting infrastructure are deliberately not built for this adults-only service and are gated, behind qualified legal counsel, to any future feature that could be reachable by minors.

9. Your rights

Subject to applicable law, you have the right to: access your data; rectify inaccurate data; erase your data ("right to be forgotten"); restrict or object to processing; data portability (receive your data in a portable format); and withdraw consent at any time.

Withdrawing your consent — as easy as giving it, and not conditioned on deleting your account. Because your explicit consent is our lawful basis for processing your faith data (§3), you may withdraw it at any time from your account settings, by a step no harder than the one by which you gave it. When you withdraw:

  • we stop processing your special-category faith data and erase it (your faith-community content and memberships), because we have no other lawful basis to keep it;
  • because that data is intrinsic to the service, you will no longer be able to use the core faith-community features — but you are not required to delete your entire account in order to withdraw. You may instead keep a minimal account (email address and display name only) that no longer processes any faith data, or you may go on to close the account entirely. The choice is yours.

Withdrawal does not affect the lawfulness of processing carried out before you withdrew.

  • Export: you can download your personal data from your account settings (a machine-readable export is provided).
  • Erasure / account closure: you can close your account, which triggers deletion of your personal data (subject to §7).
  • How to exercise other rights or ask a question: contact legal@enkrist.com. We will respond within [STATUTORY PERIOD — e.g., one month under GDPR].
  • Complaints: if you are in the UK/EEA, you may lodge a complaint with your supervisory authority ([e.g., the ICO / your local DPA]).

10. Who we share it with (processors & sub-processors)

EnKrist is the data controller for all personal data processed on the platform, including member-to-member content and its moderation; community administrators act under our rules and terms and do not thereby become independent controllers of platform data. We do not sell your personal data. We share it only with service providers ("processors") who process it on our instructions to run the platform, under contract:

ProviderRoleData involved
[Supabase]Database, authentication, file storage (core hosting of member data)4(a)–(g)
[Vercel]Application hosting / content deliverytechnical/usage 4(h)
[Resend]Transactional email (verification, password reset)email address 4(a)
[PostHog]Product analyticsusage 4(h)

We may also disclose data where legally required (e.g., a lawful request from authorities) or where necessary to protect the safety of a person or the public — including reporting unlawful material through lawful channels (see the Acceptable Use Policy and our internal handling procedures).

US state privacy laws (California and comparable states). For members in California and other US states with comparable laws, "sell" and "share" are terms of art defined broadly — "share" can include disclosing personal information for cross-context behavioural advertising even where no money changes hands. We do not sell your personal information for money, and we do not use it for cross-context behavioural advertising.

11. International transfers

[If member data is hosted or processed outside the UK/EEA:] Where your personal data is transferred outside the UK/EEA, we rely on [adequacy decision / Standard Contractual Clauses / UK International Data Transfer Agreement] to ensure it is protected to an equivalent standard. [If all processing is in-region, state that instead.]

12. Security

We protect your data with: encryption in transit; access controls; and row-level data isolation — a member's content is technically accessible only to the audiences the member selected, enforced in the database rather than only in the application. No system is perfectly secure, and we cannot guarantee absolute security. In the event of a personal-data breach, we will notify the relevant supervisory authority where required, without undue delay and, where feasible, within 72 hours of becoming aware (GDPR Art. 33), and we will notify affected members without undue delay where the breach is likely to result in a high risk to their rights and freedoms (GDPR Art. 34).

13. Changes to this policy

We may update this policy. If we make a material change to how we handle your data, we will notify you and, where the change affects the basis on which you agreed, ask you to review and re-consent — consistent with how the platform versions consent (each policy version is tracked so a change can re-prompt agreement).

14. Contact

Questions or requests: legal@enkrist.com. Postal: 200 Public Sq, Ste 3000, Cleveland, OH 44114.