Legal Document • Last Updated: July 23, 2026
Privacy Policy
This is what we collect, why we collect it, who we share it with, and what control you have. Plain English where possible. Formal legal language where required.
A Quick Note
This Privacy Policy explains how Strong Associations LLC, doing business as FaithGrind ("FaithGrind," "we," "us," or "our"), an Alabama limited liability company, handles your information when you use the FaithGrind mobile app, the website at faithgrind.com, and related services (the "Service"). It is not legal advice. If you have legal questions about your data or privacy rights, talk to a lawyer.
Recovery data like sober time, check-ins, urges, and coach conversations is consumer health data under laws such as Washington's My Health My Data Act. How we handle it, and the rights you have over it, are spelled out in our Consumer Health Privacy Policy.
1. Who We Are (Data Controller)
The data controller for your personal information is Strong Associations LLC, doing business as FaithGrind, an Alabama limited liability company headquartered in Brownsboro, Alabama, United States. We do not have an establishment in the European Union, the United Kingdom, or Switzerland and are not required to appoint an EU/UK representative under Article 27 GDPR at this time. If that changes, we will update this section.
For all privacy questions, data subject requests, or to exercise any right described in this policy, contact info [at] faithgrind.com.
2. Information We Collect
We only collect what we need to run the Service. Here is the full list:
Account Information
Email address, name, and account password (stored hashed, we never see it). Optional phone number if you opt in to SMS reminders.
Subscription and Purchase History
Records of in-app purchases and subscriptions through Apple StoreKit (iOS) and Stripe (web). We do not see or store your full payment card or Apple ID credentials. We receive transaction identifiers, plan, status, renewal date, and billing country.
AI Coach Messages
Text and voice transcripts of conversations with the AI Coach. These are sensitive because they may include mental health and recovery topics. These are encrypted at rest with a key tied to your account. Whether the AI Coach may read them back to personalize your coaching is controlled by your data sharing setting, which you can turn off at any time.
Coach Memories
Short notes the AI Coach saves from your conversations so it can coach you better over time: facts about your situation, commitments you make, breakthroughs, and preferences. Each memory is encrypted before it is stored. You can see every saved memory and delete any or all of them at any time. See Section 10.
Daily Check-Ins and Tracking
Mood entries, sobriety/clean-time tracking, daily reflection responses, streaks, and notes you submit. Sensitive by category.
Win Wall and Community Posts
Posts you submit to the public Win Wall (anonymous to other users by default), plus any private notes you keep to yourself, and Brothers/Mentors networking interactions.
Course and Lesson Progress
Which lessons you have started, completed, and where you left off.
Push Notification Token
If you allow notifications, your Apple Push Notification Service (APNs) token so we can send reminders and check-in prompts.
Basic Diagnostics
Crash reports, error logs, and minimal session timing so we can fix bugs. The mobile app and the website use Microsoft Clarity to help us understand how screens are used (touch heatmaps and session replays). Clarity capture is paused on every screen or page where you write or read personal recovery content, including check-ins, coach conversations, urge and crisis tools, your vault, sobriety settings, and onboarding, so that content is never recorded. We do not run third-party advertising SDKs.
Sign-In Security Log
At sign-in and sign-up we log a hashed and truncated version of your IP address (never the raw IP) plus your device user-agent, for account security and fraud prevention. These records are retained for 90 days and then automatically deleted.
Support and Communications
Emails you send to info@faithgrind.com or dmca@faithgrind.com, and our replies.
What we do NOT collect:
We do not collect your location, contacts, photos, browsing or search history, or biometric identifiers. Face ID and other on-device authentication stay on your device. We do not run third-party advertising SDKs and we do not sell or rent your personal information.
3. How We Use Your Information
We use your information to:
- ▸Run the Service: create and manage your account, deliver lessons, store check-ins, run the AI Coach, send notifications you opted into
- ▸Process subscriptions and purchases through Apple StoreKit (iOS) and Stripe (web)
- ▸Personalize your coaching context using your past check-ins and course progress when you have data sharing enabled
- ▸Send transactional emails (welcome, account, billing, password reset) and, only if you opted in, marketing emails through Brevo
- ▸Detect, debug, and fix problems
- ▸Comply with law, respond to lawful requests, and enforce our Terms of Use
Lawful Basis (for users in the EEA, UK, and Switzerland)
Where the GDPR or UK GDPR applies, we rely on the following lawful bases under Article 6:
- ▸Contract performance (Art. 6(1)(b)) — to provide the Service you signed up for, including running the AI Coach, storing your check-ins, and processing your subscription
- ▸Legitimate interests (Art. 6(1)(f)) — to keep the Service safe, prevent fraud, debug errors, and improve features. We balance this against your rights and you can object
- ▸Consent (Art. 6(1)(a)) — for marketing emails, optional SMS reminders, and any explicit data sharing toggles. You can withdraw consent at any time
- ▸Legal obligation (Art. 6(1)(c)) — to keep tax, accounting, and other records the law requires
Some of the data we process (mental health context, recovery status, religious belief inferred from use) is special category data under Article 9 GDPR. Where applicable, we process it on the basis of your explicit consent (Art. 9(2)(a)) given when you signed up for a faith-based recovery support service.
4. AI Coach and AI Training
The FaithGrind AI Coach is an AI-powered tool. It is not therapy, medical advice, or a crisis service. See our Terms of Use for the full disclaimer.
How It Works
When you message the AI Coach, your text is sent to OpenAI for real-time inference under its API business terms. If you have data sharing enabled, recent check-ins and course progress may be included in context so the response is personalized. Voice features are powered by ElevenLabs, which processes the text it converts to audio.
Coach Memory
To coach you well over time, the AI Coach saves short notes from your conversations: facts about your situation, commitments you make, breakthroughs, and preferences. These memories are encrypted before they are stored (AES-256-GCM, with an encryption key we hold separately from the database), and they exist for one purpose: personalizing your own coaching. They are never sold, never used for advertising or marketing, and never used to train third-party AI models. If you turn data sharing off in your vault settings, the coach cannot read your saved memories, check-ins, or conversation history. Some time-limited notes, like a commitment with a deadline, expire and are removed on their own. You can see every saved memory and delete any or all of them at any time (see Section 10), and all of them are permanently deleted when you delete your account.
We Do Not Use Your Private Data to Train Third-Party AI
We do not use your private AI Coach conversations, journal entries, vault contents, or check-ins to train third-party AI models. We may use anonymized, de-identified, or aggregated data to evaluate, debug, and improve the FaithGrind Service. Our LLM providers act as data processors and, under their business/API terms, do not train their foundation models on your inputs.
Automated Decision-Making
The AI Coach generates responses to help you reflect and stay accountable. It does not make legal or significant decisions about you within the meaning of Article 22 GDPR. You always stay in control of your own actions.
5. Encrypted Vault
FaithGrind offers a personal vault for sensitive content like AI Coach transcripts and journal entries.
- ▸Vault content is encrypted with a key tied to your account
- ▸On iOS, you can lock and unlock the vault with a passkey or Face ID. Face ID data stays on your device and never reaches our servers
- ▸Vault data is used only to deliver the Service to you, including personalizing AI Coach context when you choose to share
- ▸We do not sell, share, or use vault data for advertising
- ▸Deleting your account permanently removes vault data within 30 days of the deletion request
What this does and does not mean. The vault protects your content if a phone or a backup is lost or stolen, and it keeps your content out of ordinary staff view. It is not zero knowledge. Because the AI Coach has to read the content you choose to share in order to coach you, FaithGrind holds the key and can access that content to run the Service. Turn data sharing off and the coach stops reading it.
6. Third Parties We Work With
We use the following third-party processors to run the Service. Each one only gets the data it needs to do its job, and each one is bound by a written data protection agreement or equivalent contractual safeguards.
Apple (StoreKit, App Store, APNs)
Distributes the iOS app, processes in-app purchases and subscriptions, and delivers push notifications. Your Apple ID billing data is handled directly by Apple under Apple's privacy policy.
Stripe
Processes web subscription payments. Card details are entered directly into Stripe's PCI-compliant infrastructure. We never see or store full card numbers.
Supabase
Hosts our primary database (PostgreSQL), authentication, and file storage in the United States.
Vercel
Hosts faithgrind.com and the API. Vercel does not retain your coach messages.
OpenAI
Provides the language models that power the AI Coach. Your messages are sent to OpenAI's API, which processes them as a data processor under its API business terms and does not use API inputs to train its models.
ElevenLabs
Powers voice features for the AI Coach. Audio is processed in real time. Transcripts are stored by us, not by ElevenLabs.
Brevo
Sends transactional and (if you opted in) marketing emails, and SMS reminders if you opted in.
Cloudflare
Stores and serves images and course media (R2 object storage) and provides edge security.
Sentry
Captures error reports and minimal diagnostic data so we can fix bugs.
Google Analytics (via Google Tag Manager)
Measures aggregate website traffic on faithgrind.com so we understand which pages help people. We use IP anonymization where supported and we do not link analytics data to your account or use it for advertising. You can opt out of all analytics tools any time using the "Your Privacy Choices" link in the site footer or the cookie notice on your first visit. You can also install the Google Analytics Opt-Out Browser Add-on or block the relevant domains in your browser.
We do not sell, trade, or rent your personal information. We do not share data with advertising networks. We may disclose information if required by law, to enforce our Terms, to protect users, or in connection with a merger, acquisition, or sale of assets (in which case we will give you notice before your data becomes subject to a different policy).
People you invite. If you invite a mentor or an accountability partner, only the specific information you choose to share is shown to that person at your request. For a mentor that is your current streak, your last check in date, and your clean time. It never includes your coach conversations, your notes, or your urge logs. You can revoke a mentor's access at any time in your settings.
7. International Data Transfers
FaithGrind is operated from the United States. If you are in the European Economic Area, the United Kingdom, Switzerland, or anywhere else outside the United States, your data will be transferred to and processed in the United States, where data protection law differs from the law where you live.
Where the GDPR or UK GDPR applies, we rely on the following transfer mechanisms with our processors:
- ▸Standard Contractual Clauses (SCCs) approved by the European Commission, including the UK Addendum where applicable
- ▸EU-US Data Privacy Framework certification, where the recipient is certified
- ▸Your explicit consent for the specific transfer where no other mechanism applies
You can request a copy of the relevant transfer safeguards by emailing info@faithgrind.com.
8. Data Retention
We keep personal data only as long as we need it for the purposes described in this policy, or as long as the law requires.
Active Accounts
Account data, check-ins, AI Coach transcripts, coach memories, vault content, Win Wall posts, and course progress are kept while your account is active.
Account Deletion
When you delete your account from in-app settings or by emailing info@faithgrind.com, we delete your personal data from active systems within 30 days. Backups containing the data roll off within 90 days.
Inactive Accounts
If your account is inactive for 36 months, we may delete or anonymize your data after sending you an email notice.
Billing and Tax Records
Subscription receipts, invoices, and tax-related records are kept for at least 7 years after the transaction, as required by US tax and accounting rules.
Anonymous Win Wall Posts
Posts you made anonymously to the public Win Wall may remain visible after account deletion because the post is not tied to your identity, and removing it could erase context for other users. You can request takedown of any specific post by emailing info@faithgrind.com.
Diagnostic Logs
Crash and error logs are kept for up to 90 days, then automatically purged.
9. Data Security
We use reasonable technical and organizational measures to protect your data:
- ▸TLS encryption for data in transit between your device and our servers
- ▸Encryption at rest for the database, vault content, and stored files
- ▸Apple StoreKit and Stripe handle all card and Apple Pay details under PCI DSS
- ▸Role-based access control. Only personnel who need access for their job have it
- ▸Logging and monitoring through Sentry and Supabase audit logs
- ▸On-device passkey or Face ID for vault unlock. Biometrics never leave your device
No system is perfectly secure. If we ever discover a breach of your personal health information, we will notify you and the appropriate authorities within the timelines the law requires, including the Federal Trade Commission under the Health Breach Notification Rule, and, where it applies, GDPR Article 34.
10. Your Choices: See, Delete, and Export Your Data
You do not need to email us or live in a specific state or country to use these controls. They are built into the app for every user. On the web, go to faithgrind.com/app/privacy. In the mobile app, open Menu, then Privacy.
- ▸See what the coach remembers: view every memory the AI Coach has saved from your conversations
- ▸Forget any of it: delete a single memory, or delete all of them at once. Deletion is immediate and permanent
- ▸Export your data: download a copy of your personal data as a JSON file, including your profile, check-ins, wins, urge logs, AI Coach conversations, and coach memories
- ▸Turn off data sharing: in your vault settings, switch data sharing off and the coach stops reading your saved memories, check-ins, and conversation history
- ▸Delete your account: from in-app settings or by emailing info@faithgrind.com. See Section 8 for deletion timelines
11. Your Privacy Rights (EEA, UK, Switzerland)
If you are in the European Economic Area, the United Kingdom, or Switzerland, you have the following rights under the GDPR and UK GDPR:
- ▸Right of access — get a copy of the personal data we hold about you
- ▸Right to rectification — ask us to correct inaccurate or incomplete data
- ▸Right to erasure ("right to be forgotten") — ask us to delete your personal data
- ▸Right to restriction — ask us to pause processing in certain situations
- ▸Right to data portability — receive your data in a structured, machine-readable format
- ▸Right to object — object to processing based on our legitimate interests, including direct marketing
- ▸Right to withdraw consent — withdraw any consent you previously gave, at any time
- ▸Right not to be subject to automated decisions with legal effect — see Section 4
To exercise any of these rights, email info [at] faithgrind.com. We will respond within 30 days. If we need more time because of the complexity or number of requests, we will tell you within those 30 days.
You also have the right to lodge a complaint with your local data protection supervisory authority. In the EU, you can find your authority at edpb.europa.eu. In the UK, the relevant authority is the Information Commissioner's Office at ico.org.uk. We hope you talk to us first so we can fix things.
12. California Privacy Rights (CCPA/CPRA)
If you are a California resident, the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA) gives you specific rights regarding your personal information.
Categories of Personal Information We Collect
In the past 12 months we have collected the following categories from California consumers, sourced directly from you, your device, and our payment processors:
- ▸Identifiers (name, email, account ID, IP address, push token)
- ▸Customer records (subscription history, support correspondence)
- ▸Commercial information (purchases, plan, billing country)
- ▸Internet/network activity (basic diagnostics, error logs)
- ▸Geolocation (only the coarse country/region implied by your IP and billing — we do not collect precise GPS location)
- ▸Audio data (voice transcripts from AI Coach voice sessions)
- ▸Inferences drawn from check-ins and AI Coach activity to personalize the Service
- ▸Sensitive personal information: account credentials (hashed) and content concerning health and well-being (mental health, recovery context, religious belief inferred from a faith-based service)
How We Use Sensitive Personal Information
We use sensitive personal information only to deliver the Service you signed up for (the AI Coach, check-ins, vault, and course progress) and to keep the Service safe and lawful. We do not use sensitive personal information to infer characteristics about you for purposes other than providing the Service. You have the right to limit our use of sensitive personal information; because our use is already limited to providing the Service, you do not need to take additional action, but you may email info@faithgrind.com to confirm.
Categories of Third Parties We Share Personal Information With
Service providers and processors only, listed in Section 6 (payments, hosting, AI inference, voice, email/SMS, error tracking, file storage, app distribution). We do not share with advertising networks or data brokers.
No Sale or Sharing for Cross-Context Behavioral Advertising
We do not sell your personal information for money or other valuable consideration, and we do not share it for cross-context behavioral advertising as those terms are defined under the CCPA. We also do not knowingly sell or share the personal information of consumers under 16.
Your California Rights
- ▸Right to know what categories of personal information we have collected, used, disclosed, or sold/shared, and the specific pieces of personal information we hold
- ▸Right to delete your personal information
- ▸Right to correct inaccurate personal information
- ▸Right to opt out of sale or sharing for cross-context behavioral advertising — we already do not sell or share
- ▸Right to limit use of sensitive personal information — already limited as described above
- ▸Right to non-discrimination for exercising your rights
To exercise any California right, email info [at] faithgrind.com. We will verify your identity using information already in our records and respond within 45 days. You may use an authorized agent by sending us written, signed permission from you (and we may still need to verify your identity directly).
Notice of Financial Incentive
We do not offer financial incentives or price differences in exchange for personal information.
13. Children's Privacy
FaithGrind is built for adults. The Service is not directed to children. Our Terms of Use require users to be at least 18 years old.
United States (COPPA): We do not knowingly collect personal information from children under 13 in compliance with the Children's Online Privacy Protection Act. If we learn we have collected personal information from a child under 13, we will delete it.
EEA and UK: We do not knowingly process personal data of anyone under 16. If we learn that a person under 16 has given us personal data without verified parental consent, we will delete it.
If you believe a child has signed up, contact info [at] faithgrind.com and we will delete the account.
14. Cookies and Tracking Technologies
On faithgrind.com we use a small number of strictly necessary cookies and similar technologies to keep the site working:
- ▸Authentication and session cookies, so you stay logged in
- ▸Security tokens to prevent CSRF and abuse
- ▸Preference storage in localStorage for things like theme and last-visited section
We do not run third-party advertising cookies or cross-site-tracking pixels. The mobile app does not use cookies.
Do Not Track and Global Privacy Control: Because we do not engage in cross-context behavioral advertising and do not sell or share personal information, there is no advertising opt-out for us to honor. We go further with the Global Privacy Control (GPC): when your browser sends a GPC signal, faithgrind.com does not load our analytics tools at all, in addition to our default of never selling or sharing your personal information.
15. Email and SMS Communications
We send two kinds of messages:
- ▸Transactional emails: account confirmation, password reset, billing receipts, important changes to the Service. You cannot opt out of these while you have an account, because they are part of providing the Service
- ▸Marketing emails: tips, devotionals, product updates. We only send these if you opt in. Every marketing email has an unsubscribe link, and you can also email info@faithgrind.com
- ▸SMS reminders: only if you opted in by adding a phone number and confirming. Reply STOP to cancel. Standard message and data rates may apply
16. DMCA Copyright Takedowns
If you believe content on FaithGrind infringes your copyright, send a written DMCA notice to our designated agent. The notice must include all elements required by 17 U.S.C. § 512(c)(3), including your signature, identification of the copyrighted work, location of the alleged infringement, your contact information, and the required good-faith and accuracy statements.
DMCA Designated Agent: Thomas Azar, Strong Associations LLC, 2971 Elk Meadows Dr SE, Brownsboro, AL 35741, phone (334) 350-1385, email dmca [at] faithgrind.com. Registered with the U.S. Copyright Office under registration number DMCA-1072220.
17. Apple App Privacy Disclosures
For users of the iOS app, the data types declared on our App Store listing align with the categories described in this policy. Linked-to-you data includes: contact info (email, optional phone, name), purchase history, identifiers (account ID, device push token), user content (AI Coach transcripts, check-ins, journal entries, Win Wall posts, course progress), and diagnostics (crashes and basic performance data).
We do not collect data used for tracking across third-party apps or websites, and we do not run the App Tracking Transparency (ATT) prompt because we do not engage in tracking as Apple defines it.
18. Changes to This Policy
We may update this Privacy Policy from time to time. When we do, we will update the "Last Updated" date at the top. For material changes, we will give you notice by email or in-app before the change takes effect. Continued use of the Service after the effective date means you accept the updated policy.
19. Contact Information
Legal Entity: Strong Associations LLC, doing business as FaithGrind, an Alabama limited liability company.
Mailing Address: Brownsboro, AL 35741 (full street address available on request and registered with the U.S. Copyright Office under DMCA agent registration DMCA-1072220).
Privacy Email: info [at] faithgrind.com
DMCA Email: dmca [at] faithgrind.com
Contact Us
If you have any questions about this policy, please contact us at:
Address
Strong Associations LLC, dba FaithGrind
Brownsboro, AL 35741
United States