Legal
Privacy Policy
The Challenge App is operated by Challenge App LLC ("we", "us"). We decide what the app collects and why, and we are responsible for it.
Write to us at admin@challengeyourfaith.com about anything in this policy — a question, a correction, a copy of your data, or a deletion request.
You can also write to us on paper:
Challenge App LLC, 21049 Devonshire St., Chatsworth, CA 91311, United States. Online at challengeyourfaith.com.
This policy describes the app as it actually works. Where something is imperfect, we say so.
Who else is involved
The Challenge App is licensed to churches, which run programs inside it. Freedom Church is a program partner, not the operator. When you register with a church's code, that church receives your registration record — your name, email, phone number and which group you joined — because it is the church that placed you in the program and organises your group. The church is responsible for what it does with that information. We are responsible for the app.
Who may use the app
You must be 13 or older. The Challenge App is not directed to children under 13 and we do not knowingly collect information from them. We ask for your date of birth at registration to enforce this. An account one of our system administrators creates by hand is the exception: they may enter a date of birth and they may leave it blank, so for those accounts the check is the administrator's judgement rather than a date we hold. We create those accounts for group leaders we already know. If you believe a child under 13 has an account, email admin@challengeyourfaith.com and we will delete it.
What we collect
Things you give us when you register — or that an administrator enters for you
- First and last name, and the display name shown to your group.
- Email address.
- Phone number.
- Date of birth.
- A password, stored only as a hash — we never see the one you choose. The exception is an account one of our system administrators creates by hand: they type that first password themselves, so they know it until it is changed. It is stored the same way; the difference is that a person chose it and remembers it.
Most people type all of that in themselves. Group leaders are often set up before a program starts: one of our system administrators enters those details, sets a first password, and hands it over. If that is how your account was made, replace that password — our Support page says how, and why signing out first matters.
Things you create by using the app
- Group chat. The text of your messages, and the photos, videos and files you share, along with their file names and types. Reactions and likes.
- Profile photo. Optional: if you have not added one, the app shows your initial instead. You add, change or remove it from the Me tab of the app installed on your phone or tablet — not on the website. Before it uploads, the app crops the picture you choose to a square and saves a new JPEG copy of it on your device, no larger than 512 × 512 pixels, and it uploads that copy rather than the original.
- Daily check-ins. Which of your group's daily challenges you completed, on which day. Those challenges are written by your group leader and in practice include religious practice ("SOAP", "Pray for your group") and physical activity ("100 push-ups"). A check-in is therefore a record of your religious practice and your fitness activity, and we treat it as sensitive.
- Reading progress. Which library chapters you have opened, how far through one you are, and when you finished it.
- Bible highlights. The verses you highlight, recorded by book, chapter and verse, and when you highlighted them. Copying or sharing a verse does not send us the verse, or the fact that you copied or shared it; it goes to your device's clipboard, or to the app you choose to share it with.
- Points and streaks derived from your check-ins.
- Notifications we have sent you, and whether you have read them.
- Spiritual gifts assessment. If you take it, your answers to a questionnaire of statements about yourself, and the gift profile computed from them — the scores for each gift, the gifts it ranks highest for you, and a copy of the answers that result was worked out from. Your answers to that questionnaire are a self-description of your religious life, and we treat them as sensitive.
Things your device gives us
- An Expo push token for each install that has notifications turned on. It identifies that installation so a notification can reach it.
Things about your access
- Subscription state — whether your access comes from a church grant or a purchase, its status, and the Stripe identifiers that describe it. We never see or store your card number.
- During registration, a truncated one-way hash of your IP address and the email address the confirmation code was sent to, used to rate-limit abuse of the registration form. We do not store the raw IP address.
What we do not collect
No location data. The app requests no location permission and contains no location code. No contacts. No audio recording. No browsing or search history. No advertising identifier.
We do not currently strip embedded metadata from the photos, GIFs, videos and files you share in group chat before they upload: the app uploads each one as your device hands it over. If a file you share already contains location data in its own metadata, that data travels with the file to your group. Remove it before sharing anything you would rather not disclose. We intend to fix this.
A profile photo is not uploaded as the original file — the app uploads the new copy it makes on your device, as described above. We have not yet confirmed whether that copy keeps any of the original's embedded metadata, so do not rely on it to remove location data either.
What we do not do
- No advertising. There are no ads in the app and we do not sell ad space.
- No analytics SDK, no crash-reporting SDK, no attribution SDK. None is installed. We have verified this against the app's own dependency list.
- No tracking. We do not track you across other companies' apps or websites, and we do not link your data to anything from a data broker. The app never shows the App Tracking Transparency prompt because it has nothing to ask for.
- No sale or sharing of personal information for advertising, ever.
The one exception worth naming honestly: the Stripe payments library is compiled into the app on every platform and reports its own product-interaction telemetry to Stripe. That is Stripe's own processing for fraud prevention and service operation, not ours, and it is not used for advertising.
Who can see what, inside the app
- Your group sees your display name, your profile photo if you have added one, your messages, the photos, videos and files you post, your reactions, your check-in progress and your points.
- Your group leader sees everything the group sees, and additionally sees reports made about content in that group, including a frozen copy of the reported message.
- Our system administrators can see every report and the reported content, so that a report about a leader has somewhere to go.
- Our system administrators can create an account and set its first password. We do this to set up group leaders before a program starts, and nothing in the app limits it to them. Until that password is changed, the administrator who chose it can sign in as that account — and that means everything the account can do, including posting in its group under its display name, reading anything it can read, and permanently deleting it, because the password is also what confirms a deletion. Church staff cannot do this; only a system administrator can. A password you chose yourself is never readable by anybody, including us. The bullet below is why that is less protection than it sounds.
- Our system administrators can also change the email address on an account. We do this so that mail can reach somebody whose address is wrong — usually mistyped when they registered, sometimes typed by the administrator who set the account up. Nothing in the app limits it to those accounts: it works on an account you registered yourself, and changing your password does not put it out of reach. We refuse it on only a few accounts — one that is deleted or suspended, one that signs in through another provider, and our own administrators' accounts. Nobody proves they can open the new address before we start using it: an administrator types it, records how they checked it with you, and the app treats it as confirmed on that word alone. Know what that moves. The code that sets a new password is sent to the address on your account, so whoever sets that address can ask for that code, read it, set a password, and then be you inside the app — posting in your group under your display name, reading anything the account can read, and permanently deleting it, because the password is also what confirms a deletion. Church staff cannot do this either; only a system administrator can. Correcting an address signs nobody out: anybody already signed in to that account stays signed in, and correcting it is not a way to remove them. It moves the address on your account and on the registration record your church holds, for every program you are registered in, all of them or none. It changes nothing held by Stripe — a payment record keeps the address the payment was made with. We record every change, holding the old and the new address masked rather than written out. And this is the part the bullet above cannot promise you: an administrator who can move where a new password is sent never needs to read the old one.
- Church staff we authorise can see every report and the reported content too. A church staff account is one we have given that role; only we can give it. The role is not tied to a church: a staff account can see reports from every group in the app.
- An administrator or church staff member who is not in your group can see a reported message itself, including its photos, videos and files, only while a report on it is open. Once every report on it is resolved, the app stops opening the message and its media to them — though a link to a photo, video or file that was already opened keeps working for up to an hour after that. They can still read the report and the frozen copy of the message it keeps, and so can your group's leaders. The reported message's text also reaches our moderation inbox by email the moment the report is filed, and we keep that email as the record of the report — see "Our email provider" below.
- The person who made a report can read the note left on it when it is resolved.
- Who filed a report is hidden from the person that report is about. If someone reports you and you are one of the people who review reports — a group leader, an administrator or authorised church staff — the review screen on your phone and in the web console does not show you who filed it, and it withholds what they typed in the report's description box as well, because that description is their own words about you and would often identify them. It withholds two more fields for the same reason: the note written when the report is closed, and the name of whoever closed it — because the person who reviews a report may be the person who filed it, and then that note is the reporter's own words about you too. You still see the reason, the frozen copy of your own message, the status and the time the report was closed; if you closed it yourself, you also see your own note. The database enforces all of this, per row: the report table itself will not hand your own account a report somebody else filed about you, and the review screens read it through a routine that removes those fields first. The alert that tells a moderator a report has been filed records no account as its author, so it adds nothing about who filed the report to what that moderator can already read in the report itself, on a screen or otherwise. Another moderator, reviewing that same report, sees it whole. The alert email described under "Our email provider" below withholds the first two of those fields as well, on every report and from every reader: the line that would name the person who filed it reads the same on every one of those emails, and what they typed is not in the email at all — it is not even read out of the database to write it. An administrator who reads that inbox does not find the reporter's name or description there. What that email does still tell whoever opens it about the person who filed it, and we would rather name that than imply nothing is left: that a report exists, which group it is in, the reason chosen and the time it was filed. Those are the same facts the review screen already gives the person a report is about, and in a group of four to ten they can narrow who is likely to have filed it. Being church staff does not put an account on any report notification list — no push, no alert in the app, and that email goes to our own inbox rather than to staff; staff find reports in the web console. Our administrators are notified of every report, including one about themselves, so that a report about a leader always reaches somebody. If you do not review reports, none of this reaches you: you are never shown a report filed about you, or the note that closes it.
- Other signed-in members of the app can currently read basic profile fields — your first name, last name, display name and which group you are active in — even if they are not in your group. This is wider than it should be and we are narrowing it to your own church and group in a future release. We are telling you now rather than after.
- Your profile photo, if you have added one, can be seen by every signed-in member of the app, whether or not they are in your group — in the app on a phone or tablet, and on the website. That is the reach your display name has today, and the narrowing promised in the bullet above covers those profile fields, not your photo. The one exception is blocking: if you have blocked another member, or they have blocked you, neither of you is shown the other's photo, and each of you sees the other's initial instead — though a photo already loaded on the other person's device, or on another device of yours, can stay on screen for up to an hour after the block. The app gives nobody else a control to change or remove your photo. As with anything on your account, an administrator who can sign in as you (described above) could; and, as our Terms of Use say, we may remove a photo that breaks them, or the account that posted it.
- Your date of birth is never readable by another user. It is held in a separate, owner-only table that no other account can query — not by your group, not by your group leader, and not by an administrator. That stays true of an account an administrator created — but if they entered a date of birth when they set it up, they know it, because they typed it.
- Your phone number is not visible to other members. The copy we hold in that same owner-only table is readable by nobody but you — though an administrator who set your account up knows any phone number they entered for it, and that field is optional. Separately, the phone number you typed on your church's registration form is part of the registration record that church receives, described under "Who else is involved" above, and our administrators and the church staff we authorise can see it on the screen they use to organise groups — a role that, as the bullet above says, is not tied to one church. Your group and your group leader cannot see it. If you did not give a phone number when you registered, there is nothing there for them to see.
- Your spiritual gifts assessment is yours alone. Your answers and your results are readable only by your own account. This is one place where "your group leader sees everything the group sees" does not apply: your group does not see it, your group leader does not see it, and there is no administrator or church staff screen that reads it — not your answers, not your results, and not how many assessments you have completed. The database itself enforces that, per row: no group, leader, administrator or staff path to those rows exists.
- Your Bible highlights are yours alone. Which verses you have highlighted is readable only by your own account. No other member sees them, your group leader does not see them, and there is no administrator or church staff screen that reads them — not which verses, and not how many. The database itself enforces that, per row: no group, leader, administrator or staff path to those rows exists.
Those last four protections are about what another account can read. They are not protection against somebody who knows your password, because to the app that is simply you signing in. They are not protection against somebody who can change the address on your account either, because the code that sets a new password follows that address. If an administrator set your account up and chose your first password, replace it — and to end a session somebody else may already be holding, sign out first and then use Forgot password? Changing it from inside the app while you are signed in leaves other sessions alone, deliberately, so that changing your password does not sign you out of the phone in your hand. Our Support page walks through both. That route only works while the address on your account is one you can open, because that is where the code goes — and correcting a wrong address ends no session, so putting the right address back does not remove somebody who is already signed in.
Group chat is private to the group. It is not public, not indexed, and not readable by people outside the group, with one exception: a message someone has reported can be read by our administrators and by church staff we authorise, even if they are not in the group — the message itself while a report on it is open, and the report's frozen copy of it after that. Please still treat it as you would any group conversation — anyone in the room can screenshot it.
Companies that process data for us
We use a small number of service providers. Each receives only what its job requires.
- Supabase — our database, authentication and file storage provider. Supabase holds everything above: your account, your profile and any profile photo, your private details, your chat and its media, your check-ins and your subscription record. Its infrastructure logs also record request metadata including IP addresses.
- Stripe — payments. Stripe receives your email address and your user id, and holds the subscription or purchase record. Card details are entered into Stripe's own screens and go to Stripe directly; they never reach our servers. If we later correct the email address on your account, the address already at Stripe is not changed: a payment record keeps the address the payment was made with.
- Expo — push notifications. To deliver a notification, Expo's push service receives your push token plus the notification itself, which for a chat notification is the sender's display name and up to 140 characters of the message text.
- Apple (APNs) — the same notification payload, downstream of Expo, so that it can reach your device.
- Cloudflare (Turnstile) — the "are you human?" check on the registration form. Cloudflare receives your raw IP address, the challenge token and information about your browser or in-app web view. We keep only a truncated hash.
- Expo (EAS Hosting) — that human check loads a page we host with Expo, so Expo's hosting sees your IP address and user agent at that moment. On the web version, Expo's hosting also serves the app's own files, so if you read a Bible translation other than the World English Bible it can see that your browser downloaded that translation's text — a single file holding the whole translation, so the download itself never says which book or chapter you read.
- AudioTreasure (audiotreasure.com) — the source of the World English Bible audio, which is what plays for every translation except the Berean Standard Bible. When you press play while reading any other translation, that host receives your IP address, your user agent and which chapter you are playing. Nothing else about you is sent.
- Open Bible (openbible.com) — the source of the Berean Standard Bible audio. When you press play while reading the Berean Standard Bible, that host receives your IP address, your user agent and which chapter you are playing. Nothing else about you is sent.
- Our email provider — the email service configured on our Supabase project. It delivers the confirmation code sent during registration, so it receives your email address and name. It also delivers our moderation alert when a message is reported, which carries the reported message's text and caption, the reason that was chosen, the report's own reference, the group it was posted in, the time it was filed, the display name and account id of the person who posted the reported message, and the name and storage path of any photo, video or file attached to it. It does not carry the name or the account id of the person who filed the report, and it does not carry what they typed about it.
We do not permit any of these providers to use your information for their own advertising.
Where data is held
Our database, storage and functions run in the United States. If you use the app from elsewhere, your information is processed in the United States.
How long we keep things
While your account exists, we keep your profile, your profile photo if you have added one, your messages and media, your check-ins, your reading progress, your Bible highlights, your notifications and your subscription record, because they are the app. Removing a highlight deletes it, and removing your profile photo deletes it from storage.
Registration records — the seat your church issued, the audit trail of your registration attempts, and a record of any correction we made to the email address on it — are kept for the life of the program and afterwards as a record that the seat was used. We do not currently run an automated purge of old registration verification records; if you want yours removed, write to us.
Every spiritual gifts assessment you complete is kept as a dated record for as long as your account exists. Taking it again adds a new result rather than replacing the old one — that is deliberate, so you can see how your answers change over time. Answers to an assessment you have not finished are working notes and are cleared when you start again; nothing is lost when they are, because each completed result keeps its own copy of the answers it was worked out from.
Server logs held by Supabase and Expo are retained according to those providers' own schedules.
Deleting your account
You can delete your account from inside the app: Me → Delete Account. It is immediate and it cannot be undone. Here is exactly what happens, stated plainly:
- Your profile, your streak and every check-in you have logged are deleted.
- Every message you have sent is deleted, and the photos, videos and files you uploaded are removed from storage.
- Your profile photo, if you added one, is removed from storage.
- Your notifications, your notification preferences and every device's push registration are deleted.
- Your private details — phone number and date of birth — are deleted.
- Your spiritual gifts assessment goes with your profile: your answers and every completed result, including every earlier attempt, are deleted.
- Your library reading progress and your Bible highlights are deleted.
- Your name, email, phone number and date of birth are erased from the church registration record.
- If you lead a group, leadership passes to another member. If nobody else is in it and it belongs to a church program, the group stays in place, without a leader, for the church to reassign. If it is a personal group with nobody left in it, it is deleted.
- If you have an older subscription with us, deleting your account may not stop it. We changed payment processors after those were sold, so write to admin@challengeyourfaith.com and we will cancel it by hand and confirm. The remainder of the period is not refunded.
- Your church registration seat stays used up. This is deliberate: erasing an account does not mint a free seat. If you want to come back, your church has to issue you a new code.
Two things survive on purpose, and you should know about them:
- A short system line in your former group noting that you left. It carries the display name you were using. It is part of the group's record and cannot be removed by the app.
- An audit record that a deletion happened, identified by an account id that no longer maps to a person. We keep it so that we can show a deletion was performed.
Anything already saved or screenshotted by another member of your group is outside our control.
Your rights
You may ask us to:
- give you a copy of the personal information we hold about you;
- correct anything that is wrong;
- delete your account and its data.
Deletion is available in the app at Me → Delete Account. For everything else, email admin@challengeyourfaith.com. We will answer within 30 days. We may need to confirm you control the account's email address before we act.
There is one request that cannot work that way, and it is the one people need most: correcting the email address itself. You cannot write to us from an address that never reached you, and there is no way to change it yourself in the app — only a system administrator can. So for that one request we ask for something else: something from the registration record your church gave us, such as the phone number on it, or word from the church that issued your code. Be clear about what that is worth. Your name and the group you are in can already be read by other members of the app, so what we are doing is weighing up whether your story holds together, not proving it. It is a system administrator's judgement and we will refuse when it does not add up. We hold to the stricter check for anything we cannot undo — a deletion carried out for the wrong person cannot be reversed — so if the address on your account is wrong and you want the account deleted, write from an address you can open, tell us so, tell us how else to reach you, and expect us to take longer over it.
Depending on where you live you may have additional rights, including the right to complain to a data protection authority. Write to us first and we will try to sort it out.
Security
Access to your data is enforced at the database level, per row, per account — not just in the app's screens. Chat media lives in a private bucket that only members of the relevant group can read, except that while a message has an open report, our administrators and church staff we authorise can also read that message's photos, videos and files. Profile photos live in a separate private bucket, where another signed-in member can read only a member's current photo, and not across a block in either direction; the app shows each one through a link that stops working within an hour. Passwords are hashed. Traffic is encrypted in transit.
No system is perfect, and we will not pretend otherwise. If we become aware of a breach affecting your information, we will tell you.
Changes to this policy
If we change this policy in a way that matters, we will update the version and effective date at the top and show you the new version in the app. Continuing to use The Challenge App after that means you accept the updated policy.
Effective 25 September 2026.
Questions: admin@challengeyourfaith.com