Privacy Policy

Last updated: September 19, 2026 (version 2026-09-19)

1. Overview

This Privacy Policy explains what information Feason LLC (“Feason,” “we,” “us”), a California limited liability company, collects, how we use it, and the choices you have. It applies to your use of feason.com, our mobile applications, Chrome extension, developer interfaces, and related features (the “Service”). By using the Service, you acknowledge the practices described here. This policy does not replace a separate affirmative choice where applicable law requires one. This policy should be read together with our Terms of Service.

Privacy at a glance:

  • We do not sell personal information. We do not send your name, email, Feason account id, written content, or detailed study records to advertising providers. With your optional web measurement consent, Google Ads receives course-start and signup conversion events and related technical information, as explained in Section 12.
  • Feason is built around faith and scripture study, so information you choose to provide may reveal religious or philosophical beliefs. We treat that information as sensitive and use it only to provide, personalize, secure, and support the Service.
  • AI, voice, video, church, payment, connected-app, sign-in, email, hosting, and notification features use the service providers named below. Their retention and data-use settings are not identical, so Section 5 describes them separately.
  • You can access, export, correct, and delete your account data.

The Service is available in supported locations and is not offered to, or directed at, persons in the European Economic Area, the United Kingdom, or France and French territories. We operate the Service from the United States and process information under applicable U.S. law and, where applicable, the privacy laws of the countries and regions where we do offer the Service.

2. Information We Collect

Information you provide to us:

  • Account information: name, email, password hash (for email sign-in), profile details (display name, username, bio, profile photo), sign-in provider identifiers and tokens, and your date of birth, which we use to enforce age requirements for certain features (such as direct messaging). Apple refresh tokens are encrypted before storage.
  • Content you create: published gleams and saved gleam drafts, articles, replies, comments, journal entries, acts of faith, scripture and lecture notes, fellowship comments on verses, memorization cards, saved study plans, course submissions, research projects, research annotations and share links, and curated images. Journal entries are encrypted on your device with a key derived from your password or journal passphrase before storage. Setup or unlock sends that credential to our server over an encrypted connection for verification; see Section 8 for this distinction.
  • Chrome extension sharing data: when you explicitly open or invoke the Feason Chrome extension, it can read the current page title and URL so you can choose to attach that page to a gleam. It reads selected text only when you choose the Feason action from Chrome’s context menu. Feason receives the source and text only when you choose to post them. The extension does not monitor or collect your browsing history in the background.
  • Photos you submit to Behold: if you use the Behold feature, the photo you upload is sent to our AI provider (Anthropic) to be described, and is then stored with the description, mood, themes, and scripture anchor generated from it. Please do not upload photos of other people without their agreement, or images containing sensitive information. You can delete a capture, and its stored image, at any time.
  • Reading groups: if you create or join a group, we store your membership and role, the reflections and replies you contribute to group sessions, your reactions to other members' reflections, and — if you host — the session details and meeting notes you record. This content is visible to the other members of that group.
  • AI conversation data: the messages you send to the Feasy, Feasy Evolved, and Lexicon chat features, and the responses generated for you, along with the thread they belong to. For Feasy Evolved answers we additionally store the scripture passages and cross-references used as the basis of the answer, plus the verifier's per-claim verdict, so we can re-render those when you revisit the conversation without re-running the model.
  • Voice recordings and transcripts: on the web, when you choose voice input for Feasy or scripture memorization, the recording is transmitted to OpenAI for transcription. In the iOS app, Apple Speech Recognition processes voice input on the device when the device and language support it; otherwise iOS may send the audio to Apple for server-based recognition. Feason does not intentionally save the raw recording after recognition completes. The returned transcript may be stored if you send it as a chat message or save the related memorization activity.
  • Live Flock voice rooms: when you choose to join a live voice room and enable your microphone, your live audio and the participant, room, device, connection, and quality metadata needed to operate the call transit LiveKit's real-time infrastructure and are shared with the other participants in that room. This is separate from Feason's voice-transcription features. Feason's current web and iOS implementations do not request LiveKit Egress or another recording or transcription process for Flock voice rooms.
  • Church searches: the city, postal code, address, or other location you type into church search, together with any denomination filter. We send the location query to Google Maps to geocode it and return nearby results. We do not request your device's precise GPS location for this feature.
  • Church profiles and relationships: public church information and publications supplied by church administrators; administrator roles, invitations, and verification requests; churches you follow; and any “My Church” connection you choose, including its approval status and visibility. A follow or connection can reveal a religious affiliation. My Church connections are private by default; church owners and administrators can see requests and the member’s profile name and image, but cannot use the connection to access journals, private study activity, messages, or inferred interests.
  • Plan-a-visit requests: the name, email address, optional planned date, and message you submit to a church. If you are signed in, we also associate the request with your account until the request or account is deleted. The request is visible to that church’s owners and administrators so they can contact you.
  • Purchase and giving information: for a web course purchase, we store the course, amount, currency, payment status, purchase or refund time, and Stripe checkout and payment identifiers. For giving through a church’s connected Stripe account, we store the church, amount, currency, one-time or monthly cadence, status, and Stripe transaction or subscription identifiers, plus your account identifier if you were signed in. Stripe receives the email, account reference, transaction, device, and payment information needed to process checkout and prevent fraud. Feason does not store full card or bank-account details.
  • Calendar data: events you create in Feason, including their title, time, location, and notes. If you separately connect Google Calendar, we request read-only event access and display matching Google events in Feason. We store the OAuth access and refresh tokens needed to maintain that connection in encrypted form. We do not copy connected Google events into our database or use calendar contents for feed personalization, advertising, or AI training.
  • Study, formation, and research records: reading-plan enrollment and daily progress, meditation completion time and platform, and theology-course enrollment. When you are signed in to the theology course, we also store synced drafts, reading traces, every submitted assessment attempt and its AI feedback (including attempts that require revision), course feedback you choose to send, and completion receipts. We retain unsuccessful attempts in your account records and include them in your data export, but only accepted attempts count toward course completion. Study records also include lecture comments, Together journey progress, friend-streak invitations and the chosen daily practice. For an accepted friend streak, the paired fellow can see whether you completed that practice on each shared day. Study records also include private Feason Context study items and research projects, saved evidence packets and annotations, and any read-only research links you create.
  • Device-only Challenges on iOS: your private challenge, connected actions, insights, and reflection links are stored in an encrypted archive on that device, excluded from device backups. They do not sync to Feason's servers and are not included in an account data export. Linking an existing shared reflection does not change the audience of that reflection. Delete these local records in the feature; signing out or deleting your server account does not erase this archive. Device loss or removal of local app data can make these records unavailable.
  • Native course notebooks: iOS course notes and local study progress may be saved in a device-only notebook, separate from account-synced course submissions. This notebook does not sync to Feason, is excluded from device backups and server-account exports, and remains on the device after sign-out or account deletion. It is shared by accounts using that app installation; clear local notes before letting another person use it.
  • Carry It Forward records: the private real-world act you choose, its scripture or reading source, an optional reminder time, whether you complete or release it, and the structured outcome categories you select. These records are not posted to your profile or community feed, and we do not send them to advertising providers.
  • Connected applications: if you authorize a third-party client to use Feason Context, we store the client, approved scopes, authorization and revocation times, hashed access credentials, and limited access and security audit records. A client receives only the scopes you approve, and you can revoke it from Connections.
  • Direct messages: the private one-to-one messages you send to and receive from other members, and the conversation they belong to. Unlike your encrypted journal, direct messages are not end-to-end encrypted: they are encrypted in transit and at rest, but our systems and authorized staff can access their contents when necessary to respond to abuse reports, enforce our Terms, keep members safe, or comply with the law.
  • Communications: anything you send us through the contact form, support or privacy requests, DMCA notices, or an intimate-image removal request.
  • Reports: if you flag another user's content, we record the post you reported, the reason you provided (if any), the time of the report, and your account id. Reports are used for moderation and abuse prevention.

Information we collect automatically:

  • Usage data: reading progress, streaks, interactions with writings, memorization review history, quiz attempts, the searches you run in the app, and scripture engagement tied to your account.
  • Feed interaction signals (adults only): for members 18 or older, which posts they view, save, hide, or engage with in the feed. We use these derived signals to build a private interest profile that personalizes the feed (see Section 3). For members under 18, or where we cannot confirm adult eligibility from the date of birth on the account, we do not create or retain these derived signals or a private feed-interest profile; we show the non-personalized Latest feed instead. Journal contents are excluded from feed profiles; the feed does not decrypt or use them.
  • Push notification data: if you enable notifications, we store the device token Apple assigns to the mobile app or the endpoint and encryption keys supplied by your browser's push service. Notification providers receive the notification content needed for delivery. You can disable notifications in your device or browser settings.
  • Technical data: IP address, browser type, device type, and timestamps, used for abuse prevention, rate limiting, and security logging.
  • Security event records: for security-relevant activity such as authentication attempts, rate-limit denials, scheduled-job access, user reports, and moderator actions, we store the event category, time, outcome, route, limited context, and keyed pseudonymous fingerprints derived from relevant account, email, IP, or resource identifiers. The ledger does not store raw passwords, authentication tokens, cookies, request bodies, or reported content.
  • Link-preview fetches: when you post content that contains a URL, our server fetches publicly available metadata from that URL once (title, description, and the domain it resolves to) and stores a short cached summary with your post. The outbound fetch security record contains pseudonymous account and IP fingerprints, the target host, and a timestamp for abuse prevention. We do not re-host or proxy images from the destination site.
  • Consented acquisition analytics: if you accept analytics, we store a random first-party session identifier, the Feason page where the visit began, the referring site’s hostname, campaign tags in the URL, and whether that visit led to signup, onboarding, or a saved study action. The analytics record does not store the referring page’s full URL, advertising identifiers, or a raw IP address.
  • First-party product analytics: with web analytics consent, and in the iOS app only after you switch on Product analytics in Account settings, we record a closed set of feature events such as app launch, onboarding completion, reading, saving, sharing, and feature completion. Records can include a random per-install identifier, platform, app and operating-system versions, event time, your account id while signed in, and small predefined properties such as a score or feature name. They never include free text, message contents, advertising ids, or your raw IP address. Switching iOS analytics off immediately drops queued events.
  • Current iOS install attribution: newer app versions use Apple's SKAdNetwork registration for privacy-preserving install attribution, without the Meta or AppsFlyer SDKs. Apple may send aggregated attribution postbacks under its platform rules. The following disclosure remains relevant to earlier installed versions, depending on which version is on your device.
  • iOS install attribution in earlier app versions: on the first open of a new iOS installation, Meta Core receives an app-activation event and limited app, device, and technical information so Meta can measure whether a Facebook or Instagram ad led to the installation. AppsFlyer Strict receives app-install or launch and technical information, such as device and operating-system details, timestamps, IP-derived information, and an AppsFlyer identifier, to attribute installs and detect attribution fraud. The Strict SDK removes IDFA collection and the AdSupport dependency. Apple also may send delayed, aggregated SKAdNetwork postback copies to AppsFlyer. Feason does not send either provider your name, email, Feason account id, contacts, content, religious interests, sign-in or onboarding activity, course activity, purchases, or community activity, and does not configure AppsFlyer with a Feason customer-user id or downstream in-app events.
  • These disclosures continue to apply to installed iOS builds that contain those SDKs. Removing an attribution SDK from a later app build does not stop an earlier installed build from operating until that device updates or removes it.
  • Email delivery records: when we send account or notification email, we record the provider message id, category, subject, delivery status, timestamps, and bounce or complaint detail so we can troubleshoot delivery and suppress mail to addresses that reject it.
  • Cookies and browser storage: a session cookie to keep you signed in and a small number of first-party values to remember preferences and consent. If you allow optional measurement, Google Ads may also use an advertising click identifier and related cookies to attribute a useful action to an ad. We do not use those signals for remarketing or personalized advertising.

Lecture notes. Where these live depends on whether you are signed in, and the difference matters. Signed in: the notes you take in the Lecture feature, the video they were taken against, and its title are stored on our servers so they reach every device you use and survive a cleared cache. They are readable by us in the same way a gleam or a writing is — unlike your journal, they are not encrypted in your browser. Signed out: notes stay in that browser’s local storage, are never sent to us, and are erased permanently if you clear site data. Notes written while signed out are not uploaded when you later sign in unless you choose to import them; we ask first rather than moving them for you. Either way, Lecture notes are not used to personalize your feed, and we do not use their contents to train models.

Information from third parties: if you sign in with Google or Apple, we receive an account identifier and the profile information that provider makes available with your permission, which may include your name, email, or profile picture. Apple may provide a private relay email address instead of your personal email.

3. How We Use Your Information

We use your information to:

  • Provide, maintain, secure, and improve the Service;
  • Understand which search and campaign visits lead people to useful study actions;
  • Measure which campaign, including a Meta ad, led to an iOS app installation;
  • Create and authenticate your account;
  • Display your profile, activity, and public content to other users;
  • For members 18 or older, personalize the feed by ranking content using signals from activity on the Service (public posts, saves, and feed interactions — never an encrypted journal). Members under 18, and members whose adult eligibility cannot be confirmed, receive the non-personalized Latest feed. Feed personalization affects only the order and selection of content shown; it has no legal or similarly significant effect;
  • Deliver notifications about interactions with your content or streaks, by email and (if you enable them) push notification. You can manage email notifications in your email preferences and unsubscribe at any time;
  • Generate AI responses in the Feasy, Feasy Evolved, and Lexicon chats;
  • Transcribe voice input and generate optional spoken output;
  • Connect participants and carry live audio in Flock voice rooms;
  • Provide private study indexing, research workspaces, and authorized developer connections;
  • Measure feature reliability and usage through the first-party analytics described above;
  • Return church-search results for a location you enter;
  • Operate church profiles, administrator teams, verification, follows, private-by-default membership connections, visit requests, and giving links;
  • Process purchases, refunds, and course access, and route gifts to a connected church;
  • Combine events you create in Feason with events from a calendar you connect;
  • Detect, investigate, and prevent abuse, fraud, and security incidents;
  • Respond to support, privacy, moderation, copyright, and intimate-image removal requests;
  • Comply with legal obligations and enforce our Terms.

We do not sell your personal information and Feason does not operate a program to train its own models on your private content. AI providers process inputs under their own commercial terms and account-level controls; the provider-specific training and retention differences we can verify are stated in Section 5.

4. International Users & Legal Bases

The Service is not offered to, or directed at, persons in the European Economic Area, the United Kingdom, or France and French territories, and we do not market it in those locations.

Where the data-protection law of a location in which we do offer the Service requires a legal basis for processing, we rely as appropriate on: (a) performance of a contract, to provide the Service you request; (b) our legitimate interests in securing, maintaining, and improving the Service and preventing abuse, balanced against your rights; (c) your consent, for processing that requires it, which you may withdraw at any time; and (d) compliance with legal obligations.

5. Service Providers & AI Features

Our Feasy and Feasy Evolved chats send your prompts, conversation history, and limited contextual information (such as which in-app page you are viewing) to OpenAI's API for inference. Lexicon sends the same kinds of chat data to Anthropic's API. Under these providers' current commercial API defaults, inputs and outputs are not used to train their models. OpenAI may retain eligible API content for abuse monitoring for up to 30 days, and Anthropic generally deletes API inputs and outputs within 30 days, subject in each case to security, legal, and separately agreed retention exceptions.

Pre-publication culture checks. When you submit a public gleam, its text is sent through Vercel AI Gateway to Anthropic, or directly to Anthropic if the gateway is unavailable, before publication to classify likely safety or community-culture violations. Neither provider receives your Feason account identifier with this request. This means draft text may be processed even when the check asks you to revise it and the gleam is never published. The check's decision is not used to decide whether a denomination, doctrine, or viewpoint is correct. The same commercial data-use and retention terms described above apply.

Theology lesson and artifact reviews send your submitted work and the assigned-course context needed to apply the rubric to the configured OpenAI model through Vercel AI Gateway, or directly to OpenAI if the gateway is unavailable. Oral-defense practice and assessment send your answers, the authoritative transcript, any practice judgment you supply, and assigned-course context. Assessed mode sends an artifact identifier and integrity hash, not the retained artifact contents. Feason stores submitted lesson, artifact, and assessed oral-defense attempts and their AI feedback as part of your account course record. Oral-defense practice is not retained in that server-side course record.

Feasy Evolved additionally sends each question to Voyage AI for embedding (a numerical representation used to find related scripture passages in our database). Voyage receives the question text only; it does not receive your account identifier. Voyage's standard API terms may permit it to retain and use API inputs to improve its services unless Feason's Voyage organization has activated the provider's data-use opt-out. We do not promise zero retention for Voyage processing.

Other AI-assisted study features. Personal study-plan generation sends your question to Voyage AI to retrieve relevant passages, then sends the question and passages to Anthropic to create a plan. We save the question and plan with your account. Scripture explanations send the selected verse and reference to Anthropic; reading-group overviews send the session title and assigned Scripture context, not members' private reflections. Automated replies to public news comments send the public comment and article context to Anthropic. The provider data-use and retention terms above apply to these flows too.

Voice transcription. On the web, voice input in Feasy or scripture memorization is sent to OpenAI's audio transcription API. OpenAI receives the recording but not your Feason account identifier, and states that its audio-transcription endpoint does not retain input as abuse-monitoring logs or application state under default controls. In the iOS app, Apple Speech Recognition transcribes locally when supported; otherwise Apple may process the recording on its servers under Apple's policies. Apple does not receive a Feason account identifier from the speech-recognition request.

If you use voice mode, the generated reply text is sent to ElevenLabs to create spoken audio. ElevenLabs does not receive your account identifier. ElevenLabs may retain API inputs and generated audio and may use eligible data to improve its services unless account-level data-use or zero-retention controls apply; Feason does not promise zero retention for this processing.

Live Flock voice rooms. Live room audio is carried through LiveKit's real-time WebRTC infrastructure so participants can hear one another. LiveKit receives the live media stream and the participant, room, device, connection, and quality metadata needed to establish, secure, and troubleshoot the call. Feason's current web and iOS implementations do not request LiveKit Egress, agent recording, or another recording or transcription process for these rooms, and Feason does not intentionally retain room audio after the call. LiveKit may retain limited operational, security, diagnostic, and usage records as our processor under its agreement with Feason; see LiveKit's Privacy Policy.

Feason Context embeddings. Private study items, personal-index text, research queries, and public-corpus search queries may be sent to the embedding provider configured for Feason Context: Vercel AI Gateway routing to OpenAI, OpenAI directly, or Voyage AI. The provider receives the text needed to create the numerical embedding but not your Feason account identifier. The resulting vector is stored with the private item or in a short-lived query cache so semantic search works.

Behold photos. When you submit a photo to Behold, the image itself is sent to Anthropic's API so the model can describe what it shows and suggest a scripture anchor. Anthropic receives the image and does not receive your account identifier. The same commercial terms described above apply: images sent through the API are not used to train Anthropic's models under its commercial defaults, and its usual 30-day deletion period is subject to the security, legal, and separately agreed retention exceptions described above. We store the resulting description and the image itself in our own storage until you delete the capture.

We store the resulting conversation transcripts in our database so you can revisit and manage them. For Feasy Evolved we additionally store the scripture passages and cross-references used to ground each answer and the verifier's per-claim verdict. You can rename and delete any AI conversation from the chats list, and you can export or delete your account data from your profile settings; deletion removes it from our database.

Feasy Evolved answers are AI-generated. The verifier is a separate model that checks each theological claim against the scripture passages used; it reduces but does not eliminate the possibility of error. Feasy Evolved is a study tool, not a substitute for pastoral guidance, theological education, or the teaching authority of your church.

Please do not send sensitive personal information, confessions, medical or legal details, passwords, or payment data through the AI Features. If your question to Feasy Evolved indicates a possible personal crisis (suicidal ideation, abuse, self-harm), the Feasy Evolved interface will surface crisis-line resources alongside any answer. These detections are non-blocking and best-effort; please reach out to a trusted person or one of the listed resources directly.

Other service providers and recipients we use:

  • Supabase — database and file storage.
  • Vercel — application hosting.
  • Stripe — payment processing for web course purchases and, when enabled, connected-account checkout and onboarding for church giving. Stripe receives the transaction, contact, device, fraud-prevention, and payment information needed for the feature. Church representatives submit identity, tax, and bank information through Stripe-hosted onboarding; Feason stores only the connected-account identifier and routing/status fields, not those identity documents or bank credentials. Stripe also handles information under its own Privacy Policy.
  • Google — optional authentication, read-only Calendar connection, church geocoding and place search, user-requested embedded YouTube video, and consent-gated Google Ads conversion measurement. Different Google services receive the information described in this Policy only when you use the corresponding feature.
  • Apple — optional authentication, push notification delivery, and iOS speech recognition. Apple receives authentication requests; your device token and notification content; or voice audio when server-based recognition is needed, as applicable.
  • Meta Platforms — first-open attribution for the iOS app. Meta receives the limited activation and technical information described in Section 2. Meta Core's own privacy manifest identifies device information used for advertising measurement and tracking. Feason disables advertising-identifier collection and all automatic or downstream app events, but Meta processes the activation under its own terms and privacy policy.
  • AppsFlyer — install attribution and fraud detection in iOS app versions that include AppsFlyer Strict. It receives the limited install, launch, device, network, and campaign information described in Section 2, along with copies of Apple’s delayed, aggregated SKAdNetwork postbacks. Strict mode removes IDFA collection and the AdSupport dependency. AppsFlyer handles that information under its Services Privacy Policy.
  • Anthropic — AI model inference for Lexicon, pre-publication culture checks, study plans, Scripture explanations, reading-group overviews, automated replies to public news comments, content tagging for the feed, and Behold image descriptions.
  • Voyage AI — query and document embeddings used for Feasy Evolved, personal study-plan retrieval, feed features, and Feason Context when configured.
  • OpenAI — AI model inference for Feasy and Feasy Evolved, embeddings when configured, and web audio transcription for voice input and scripture recitation.
  • ElevenLabs — text-to-speech generation when you use Feasy voice mode and narration generation for published content.
  • LiveKit — real-time audio transport and participant/room connection services for live Flock voice rooms; this flow is not Feason voice transcription, and Feason's current web and iOS implementations do not request LiveKit Egress or agent recording.
  • Resend — transactional email delivery (welcome emails, notification emails, streak reminders, and the daily digest). Resend receives your email address and the content of the email being sent.
  • Browser push services — notification delivery if you enable web push. The service selected by your browser receives the subscription endpoint and encrypted notification payload needed for delivery.
  • Upstash — Redis-backed rate limiting, used when configured to enforce abuse thresholds across multiple server instances. Stores counter values under keyed pseudonymous fingerprints derived from rate-limit buckets; raw account, email, and IP identifiers and user content are not sent in those keys.
  • Slack — operational notifications. Signup notices contain your name, email address, and sign-in method; security digests contain aggregate event counts and categories, not event fingerprints or user content.
  • bolls.life and dictionaryapi.dev — Scripture text and word definitions. These are accessed for content and do not receive your account identifiers.

We give service providers only the information needed for the identified feature and require them to protect it under the applicable contract or commercial terms. They operate their own systems, however, so their documented retention, security, and account-control exceptions also apply as described above.

Embedded video (Lecture). When you open a video in the Lecture feature, your browser contacts YouTube and Google directly to load the player and stream the video. That connection is between you and Google, not routed through us: Google receives your IP address, device and browser information, and the video you requested, and may set cookies or other storage in your browser under the Google Privacy Policy. We embed through YouTube’s privacy-enhanced domain (youtube-nocookie.com), which reduces but does not eliminate that storage. We do not send Google your name, email, or Feason account identifier, and we do not receive your YouTube account, viewing history, or watch behavior in return. No video loads until you paste a link and open it.

Reference data attribution. Feasy Evolved's scripture corpus is the World English Bible (public domain). Cross-references are sourced from openbible.info under the Creative Commons Attribution 4.0 License.

The Greek New Testament is the SBL Greek New Testament (CC BY 4.0). Word-by-word tagging, grammar and glosses are adapted from STEP Bible (Tyndale House, Cambridge), available at github.com/STEPBible under the Creative Commons Attribution 4.0 License. Strong's numbering is public domain. Sense breakdowns shown alongside a word are Feason's own, counted from that tagging.

6. Sharing of Information

We share information only as needed to run the Service:

  • With the service providers and other recipients described in Section 5, for the purposes explained there;
  • With Meta Platforms and AppsFlyer, solely for the limited iOS install attribution described in Sections 2 and 5;
  • With other users, for your public profile and the content you choose to post publicly (gleams, threads, replies, fellowship comments, and public profile fields);
  • With the other members of a reading group you join, for your membership and the reflections, replies, reactions, and meeting notes you contribute to that group;
  • With church owners and administrators, for a church-connection request and for the name, email, planned date, and message in a plan-a-visit request you direct to that church;
  • With Stripe for course purchases and giving checkout, including refunds, disputes, fraud prevention, receipts, and related transactions; with the connected church for gifts and recurring giving, as described above;
  • With a connected Feason Context client, only after you authorize that client and only for the scopes shown on the authorization screen;
  • With anyone who has a research share link you deliberately create, until the link expires or you revoke it. The shared page contains the project and evidence packet identified when you created the link, not your unrelated private study data;
  • With authorities or other parties if required by law, to enforce our Terms, or to protect the rights, property, or safety of Feason, our users, or the public;
  • In connection with a merger, acquisition, financing, or sale of assets, subject to standard confidentiality protections.
  • At your direction or with your consent.

Journal entries, scripture and lecture notes, saved lexicon words, drafts, private research projects, and private AI conversations are not shown to other members unless you use a sharing feature, such as publishing a Feasy exchange or creating a research share link. Private does not mean that Feason or its providers cannot process the data: journal text is stored encrypted as explained in Section 8. Our systems and authorized staff may access other private records when needed to operate the requested feature, provide support, address safety or security issues, or comply with law. AI and other provider processing is described in Section 5. Direct messages are visible to you and the member you exchange them with; because they are not end-to-end encrypted, authorized staff may review reported or flagged messages for safety, moderation, and legal compliance.

7. Data Retention

We retain your information for as long as your account is active, and for a limited period afterwards as needed to comply with legal obligations, resolve disputes, and enforce our agreements. When you delete content, we remove it from the active Service promptly; residual copies may remain in protected backups until they are overwritten through our normal backup-rotation cycle. Backup copies are isolated from ordinary use and are restored only for disaster recovery or another legitimate continuity need.

Content removed by our moderators for violating our community guidelines is hidden from the Service rather than immediately destroyed: we retain it for a limited period so we can review appeals, identify repeat abuse, and comply with legal obligations. Such content is permanently deleted when your account is deleted.

Gleam drafts, account-saved lecture notes, private study items, research projects and evidence packets, course work, reading-plan progress, meditation completions, and Together journey progress are kept until you delete the item where a control is offered or delete your account. A read-only research link remains usable until its expiration date, revocation, project deletion, or account deletion, whichever comes first.

First-party product analytics are retained for 180 days and then removed by rolling cleanup. If an event is linked to your account, account deletion removes that linked record earlier. A signed-out event has no account id, but the same random installation id is used before and after sign-in, so events from one installation can be associated with later signed-in activity from that installation.

Feason Context authorization codes are removed shortly after use or expiration. Revoked or expired OAuth tokens are generally removed 30 days after revocation or refresh-token expiration. Connection consent and user-bound access records remain while the connection or account exists and are removed on account deletion. Email delivery and suppression records remain while needed to deliver mail, diagnose bounces or complaints, and honor suppression choices; records still linked to your account are deleted with it.

Local course enrollment, progress, follow-up email, and purchase records linked to your account are deleted when you delete the account. Stripe and the relevant financial institutions may retain their own transaction, fraud-prevention, dispute, tax, and legal records under their policies and applicable law; deleting Feason’s account copy does not direct those independent records to be erased.

Church follows, My Church connections, administrator roles, and signed-in plan-a-visit requests are deleted with your account. Plan-a-visit requests sent while signed out are kept with the church profile until that profile is deleted or a verified deletion request is completed, subject to legal exceptions. Church profiles, publications, invitations, verification history, and other shared organization records may remain after the account identifier of a departing administrator or reviewer is removed. Giving ledgers may also remain after the Feason account identifier is removed for accounting, fraud prevention, disputes, and legal compliance; Stripe and the church retain their own transaction records under their respective policies and obligations.

Pseudonymous security event records are generally retained for about 90 days so we can detect abuse patterns, investigate incidents, and verify security controls, then removed by a daily rolling cleanup. Temporary operational delays, an active security investigation, or legal obligations may require limited records to be kept longer. These records may remain after account deletion for that limited period where needed for security and abuse prevention; they are not used for feed personalization or advertising.

When you delete your account, we delete your personal data within 30 days, except for the limited information we are required or permitted by law to keep. This includes drafts, lecture notes saved to your account, linked product analytics and email delivery records, Feason Context private-study and research records, OAuth grants, connected-client credentials, user-bound access logs, signed-in plan-a-visit requests, and Feason’s local course-purchase record. Shared group, church-organization, or scheduling records that other members still rely on may remain after we remove your profile and account identifiers from those records. Lecture notes taken while signed out were never sent to us and so cannot be deleted by us — they stay in the browser that wrote them until you clear that browser’s site data or clear them in the feature.

Raw voice recordings are passed through to OpenAI on the web or processed by Apple Speech Recognition on iOS and are not intentionally stored in Feason's database or file storage. Provider-side handling is described in Section 5. Returned transcripts follow the retention period of the chat or memorization record in which you use them. When you delete an Apple-linked account, we attempt to revoke the stored Apple refresh token as part of account deletion.

Live Flock voice-room audio transits LiveKit while the call is active. Feason does not intentionally store that audio or a transcript. Feason's current web and iOS implementations do not request LiveKit Egress or agent recording for the current voice-room flow. LiveKit may retain limited operational, security, diagnostic, and usage records for its documented and contracted retention periods.

Connected Google Calendar events are fetched when you view the calendar and are not retained as event copies by Feason. Disconnecting attempts to revoke the Google grant and permanently removes Feason's encrypted token copy. Feason-created events and any remaining calendar connection are deleted with your account.

8. Security

We use reasonable technical and organizational measures to protect your information, including encryption in transit (TLS), scoped database access, rate limiting on abuse-prone endpoints, and audit logging. No system is perfectly secure; if we become aware of a data breach that materially affects you, we will notify you as required by applicable law.

Journal encryption and credential verification. The web and iOS apps encrypt journal text on your device using AES-256 and a key derived from your account password or separate journal passphrase. Stored entries contain encrypted text rather than readable journal text. However, setup and credential-based unlock send that password or passphrase to Feason over an encrypted connection so our server can hash or verify it. This is not a guarantee that Feason never receives your encryption credential, and we do not describe it as a zero-knowledge system. On iOS, the app can save the credential in the device Keychain protected by biometric access. There is no journal-content recovery service if you lose the required credential. Valid legal process may require disclosure of records we hold, including encrypted entries and account metadata.

9. International Transfers

The Service is operated from the United States. Our sub-processors may process your data in the United States and in other countries. Where required by applicable law, we use recognized transfer mechanisms, such as adequacy decisions or contractual safeguards, to protect your information when it is transferred outside your home jurisdiction.

10. Your Rights & Choices

We offer the following controls to all users, whether or not a particular state privacy law applies to Feason:

  • Access a copy of the personal data we hold about you;
  • Correct inaccurate personal data;
  • Delete your personal data (through your profile, or by contacting us);
  • Export your content in a portable format — “Export your data” in your profile settings produces a machine-readable JSON file covering your account and profile; posts, drafts, notes, course work, reading and meditation records; group and Together contributions; church relationships, organization activity, linked visit requests, course purchases, and linked giving records; AI conversations; private Feason Context study and research records; connected-client metadata; first-party analytics linked to your account; the direct messages you sent; feed-personalization signals; and reports you filed. Journal entries are included in encrypted form only; the export does not decrypt them. Credential secrets, vector embeddings, received messages written by another person, and pseudonymous security records not keyed to your account are excluded;
  • Withdraw consent where processing is based on consent.

California personal-information categories. During the preceding 12 months, we have collected the following categories of personal information described by California law: identifiers and account records; internet or other electronic-network activity; commercial information such as purchase and giving records; user-provided or IP-derived location information; audio, visual, and other electronic content; inferences used for feed personalization; and sensitive personal information, including account credentials, message contents, and information that may reveal religious or philosophical beliefs. We collect these categories directly from you, automatically from your browser or device, from Google or Apple when you choose their sign-in services, from other users who interact with you, and from public pages involved in link previews. We use them for the purposes in Section 3, disclose them for business purposes to the provider categories in Sections 5 and 6, and retain them as described in Section 7. We have not sold these categories. The Google Ads conversion measurement and historical Meta and AppsFlyer iOS install signals described above involve advertising measurement. Whether a disclosure is legally considered “sharing” depends on the applicable law, provider terms, and use of the data; removing advertising identifiers alone does not decide this. These flows do not include your written content or Feason account identifier, but an interaction with a faith-based service may itself suggest an interest in religion.

California residents (CCPA / CPRA). Where these laws apply to Feason and your information, you have rights to know, delete, correct, obtain a portable copy, opt out of sale or sharing, and limit covered uses or disclosures of sensitive personal information, subject to legal exceptions. The controls offered to all users above remain available regardless of statutory coverage. We do not sell personal information. Use Cookie Settings in the footer to decline optional web measurement, or contact us to exercise applicable rights, including rights relating to an earlier iOS installation. We honor applicable Global Privacy Control signals as explained in Section 12. Information about your religious or philosophical beliefs, private messages, and certain health details can be sensitive personal information. We use it for the service, personalization, safety, and support purposes described in this Policy; any use requiring separate consent or a right to limit remains subject to those legal requirements.

Other U.S. state privacy laws. Residents of states with comparable privacy laws (including Virginia, Colorado, Connecticut, Utah, Texas, and similar jurisdictions) may have analogous rights to access, correct, delete, and obtain a copy of their data, opt out of covered sale, targeted advertising, or profiling, and appeal a denial of a request. Feason does not sell personal information. Optional web conversion measurement and historical iOS install attribution are described in Sections 2, 5, and 12. Feason's feed ranking does not make legal or similarly significant decisions about you. Statutory rights and exceptions depend on the law that applies to the processing.

Consumer Health Data Privacy Policy

Our separate Consumer Health Data Privacy Policy explains the health-related information that may arise when you choose to use Feason, its sources, purposes, recipients, and rights under Washington's My Health My Data Act. It covers Washington residents and people whose consumer health data is collected in Washington, as provided by that law.

European Economic Area and United Kingdom. We do not offer or direct the Service to persons in these locations. That availability restriction does not determine whether a privacy law applies to particular processing or remove rights you may have under applicable law. If you believe you hold rights under the EU GDPR, UK GDPR, or another privacy law, contact us and we will assess and respond to your request.

You can exercise most rights directly in your profile. For other requests, contact us through the Contact page, email info@feason.com with the subject “Privacy Request,” or write to the mailing address in Section 15. We may need to verify your identity before acting, using information proportionate to the request. We will respond within the deadline required by the law that applies and explain any permitted extension or denial. You do not need to create an account to submit a request. An authorized agent may submit a request for you; we may ask for proof of signed permission and may verify your identity directly. If we deny a request, you may appeal by replying to the decision or submitting a new message marked “Privacy Appeal.” We will not discriminate against you for exercising your rights.

11. Children's Privacy

The Service is not intended for children under 13, and we do not knowingly collect personal information from them. If we learn that we have collected information from a child under 13, we will suspend the account, stop using the information, and delete it unless law permits or requires a limited retention. Parents and guardians who believe their child has provided us with information should contact us.

12. Cookies & Similar Technologies

We use a small number of first-party cookies and browser-storage values to sign you in, remember your preferences, and protect against abuse. If you select “Allow optional measurement” in the cookie notice, we also create a random visit identifier in your current browser tab for acquisition measurement and a random installation identifier in local storage for the first-party product events described in Section 2. Selecting “Decline optional measurement” prevents both kinds of web analytics. If you allow optional measurement, we also load Google Ads conversion measurement. Google may receive your IP address, browser and device information, the advertising click identifier associated with your visit, and notice that you started a course or created a web account. We do not send Google your Feason account id, email, written work, scripture activity, theological views, or the contents of private features. We configure the tag with ad personalization disabled, do not build remarketing audiences from this data, and do not use session-replay tools. Google processes this information under its Privacy Policy and explains its business-data practices on its Business Data Responsibility page. You can clear cookies and site data in your browser at any time, or reopen Cookie Settings from the site footer to change your choice. Declining retires the random analytics identifiers stored in that browser and stops future analytics collection; it does not retroactively erase records already collected. Clearing authentication cookies will sign you out.

Two kinds of browser storage are worth naming separately. Lecture notes taken while signed out are held in local storage on your device and are never transmitted to us — clearing site data deletes them for good, while notes on your account are unaffected by clearing site data (see Section 2). And opening a video in Lecture loads YouTube’s player, which may set its own cookies or storage under Google’s policy rather than ours (see Section 5).

Chrome extension storage. The Feason Chrome extension stores an authentication token and short-lived composer state in Chrome’s local extension storage so you can remain signed in and finish an action you started. That storage is scoped to the extension and can be removed by signing out, clearing the extension data, or uninstalling the extension.

Feason’s use of information received from Chrome APIs adheres to the Chrome Web Store User Data Policy, including the Limited Use requirements.

Feason’s use and transfer of information received through the optional Google Calendar connection also adheres to the Google API Services User Data Policy, including its Limited Use requirements.

Do Not Track and Global Privacy Control. Your cookie-notice choice controls optional web acquisition and product analytics. Where a browser Global Privacy Control signal is legally applicable, we treat it as an opt-out request for browser-based sale or sharing. Browser signals cannot control the separate first-open event from the native iOS app; contact us using Section 15 to exercise any applicable privacy right. We do not respond to the older, non-standardized Do Not Track signal.

13. Affiliate Links

Feason participates in the Amazon Services LLC Associates Program. When you click affiliate links and make a purchase, Amazon may collect information under its own privacy policy. We receive aggregate commission reports only; we do not receive personal details about your purchases.

14. Changes to This Policy

We may update this Policy from time to time. We will post the updated version and, if changes are material, notify you within the Service before they take effect. Where required, we will ask for renewed consent before applying a new practice to your information. The “Last updated” date identifies the current version.

15. Contact

For privacy questions or to exercise your rights, reach us via the Contact page and mark your message “Privacy Request,” email info@feason.com, or write to us at: Feason LLC, 2108 N St # 16806, Sacramento, CA 95816, USA.