The Challenge App

Legal

Privacy Policy

Effective 25 September 2026 · Version 2026-09-25 · Challenge App LLC

The Challenge App is operated by Challenge App LLC ("we", "us"). We decide what the app collects and why, and we are responsible for it.

Write to us at admin@challengeyourfaith.com about anything in this policy — a question, a correction, a copy of your data, or a deletion request.

You can also write to us on paper:

Challenge App LLC, 21049 Devonshire St., Chatsworth, CA 91311, United States. Online at challengeyourfaith.com.

This policy describes the app as it actually works. Where something is imperfect, we say so.

Who else is involved

The Challenge App is licensed to churches, which run programs inside it. Freedom Church is a program partner, not the operator. When you register with a church's code, that church receives your registration record — your name, email, phone number and which group you joined — because it is the church that placed you in the program and organises your group. The church is responsible for what it does with that information. We are responsible for the app.

Who may use the app

You must be 13 or older. The Challenge App is not directed to children under 13 and we do not knowingly collect information from them. We ask for your date of birth at registration to enforce this. An account one of our system administrators creates by hand is the exception: they may enter a date of birth and they may leave it blank, so for those accounts the check is the administrator's judgement rather than a date we hold. We create those accounts for group leaders we already know. If you believe a child under 13 has an account, email admin@challengeyourfaith.com and we will delete it.

What we collect

Things you give us when you register — or that an administrator enters for you

Most people type all of that in themselves. Group leaders are often set up before a program starts: one of our system administrators enters those details, sets a first password, and hands it over. If that is how your account was made, replace that password — our Support page says how, and why signing out first matters.

Things you create by using the app

Things your device gives us

Things about your access

What we do not collect

No location data. The app requests no location permission and contains no location code. No contacts. No audio recording. No browsing or search history. No advertising identifier.

We do not currently strip embedded metadata from the photos, GIFs, videos and files you share in group chat before they upload: the app uploads each one as your device hands it over. If a file you share already contains location data in its own metadata, that data travels with the file to your group. Remove it before sharing anything you would rather not disclose. We intend to fix this.

A profile photo is not uploaded as the original file — the app uploads the new copy it makes on your device, as described above. We have not yet confirmed whether that copy keeps any of the original's embedded metadata, so do not rely on it to remove location data either.

What we do not do

The one exception worth naming honestly: the Stripe payments library is compiled into the app on every platform and reports its own product-interaction telemetry to Stripe. That is Stripe's own processing for fraud prevention and service operation, not ours, and it is not used for advertising.

Who can see what, inside the app

Those last four protections are about what another account can read. They are not protection against somebody who knows your password, because to the app that is simply you signing in. They are not protection against somebody who can change the address on your account either, because the code that sets a new password follows that address. If an administrator set your account up and chose your first password, replace it — and to end a session somebody else may already be holding, sign out first and then use Forgot password? Changing it from inside the app while you are signed in leaves other sessions alone, deliberately, so that changing your password does not sign you out of the phone in your hand. Our Support page walks through both. That route only works while the address on your account is one you can open, because that is where the code goes — and correcting a wrong address ends no session, so putting the right address back does not remove somebody who is already signed in.

Group chat is private to the group. It is not public, not indexed, and not readable by people outside the group, with one exception: a message someone has reported can be read by our administrators and by church staff we authorise, even if they are not in the group — the message itself while a report on it is open, and the report's frozen copy of it after that. Please still treat it as you would any group conversation — anyone in the room can screenshot it.

Companies that process data for us

We use a small number of service providers. Each receives only what its job requires.

We do not permit any of these providers to use your information for their own advertising.

Where data is held

Our database, storage and functions run in the United States. If you use the app from elsewhere, your information is processed in the United States.

How long we keep things

While your account exists, we keep your profile, your profile photo if you have added one, your messages and media, your check-ins, your reading progress, your Bible highlights, your notifications and your subscription record, because they are the app. Removing a highlight deletes it, and removing your profile photo deletes it from storage.

Registration records — the seat your church issued, the audit trail of your registration attempts, and a record of any correction we made to the email address on it — are kept for the life of the program and afterwards as a record that the seat was used. We do not currently run an automated purge of old registration verification records; if you want yours removed, write to us.

Every spiritual gifts assessment you complete is kept as a dated record for as long as your account exists. Taking it again adds a new result rather than replacing the old one — that is deliberate, so you can see how your answers change over time. Answers to an assessment you have not finished are working notes and are cleared when you start again; nothing is lost when they are, because each completed result keeps its own copy of the answers it was worked out from.

Server logs held by Supabase and Expo are retained according to those providers' own schedules.

Deleting your account

You can delete your account from inside the app: Me → Delete Account. It is immediate and it cannot be undone. Here is exactly what happens, stated plainly:

Two things survive on purpose, and you should know about them:

Anything already saved or screenshotted by another member of your group is outside our control.

Your rights

You may ask us to:

Deletion is available in the app at Me → Delete Account. For everything else, email admin@challengeyourfaith.com. We will answer within 30 days. We may need to confirm you control the account's email address before we act.

There is one request that cannot work that way, and it is the one people need most: correcting the email address itself. You cannot write to us from an address that never reached you, and there is no way to change it yourself in the app — only a system administrator can. So for that one request we ask for something else: something from the registration record your church gave us, such as the phone number on it, or word from the church that issued your code. Be clear about what that is worth. Your name and the group you are in can already be read by other members of the app, so what we are doing is weighing up whether your story holds together, not proving it. It is a system administrator's judgement and we will refuse when it does not add up. We hold to the stricter check for anything we cannot undo — a deletion carried out for the wrong person cannot be reversed — so if the address on your account is wrong and you want the account deleted, write from an address you can open, tell us so, tell us how else to reach you, and expect us to take longer over it.

Depending on where you live you may have additional rights, including the right to complain to a data protection authority. Write to us first and we will try to sort it out.

Security

Access to your data is enforced at the database level, per row, per account — not just in the app's screens. Chat media lives in a private bucket that only members of the relevant group can read, except that while a message has an open report, our administrators and church staff we authorise can also read that message's photos, videos and files. Profile photos live in a separate private bucket, where another signed-in member can read only a member's current photo, and not across a block in either direction; the app shows each one through a link that stops working within an hour. Passwords are hashed. Traffic is encrypted in transit.

No system is perfect, and we will not pretend otherwise. If we become aware of a breach affecting your information, we will tell you.

Changes to this policy

If we change this policy in a way that matters, we will update the version and effective date at the top and show you the new version in the app. Continuing to use The Challenge App after that means you accept the updated policy.

Effective 25 September 2026.

Questions: admin@challengeyourfaith.com