Skip to main content

How we protect your data.

You sign up. We create an encryption key just for you. Every conversation you have with your coach, every check-in, every note gets encrypted with that key before it hits the database. Nobody else's key works on your data.

By default, your coach can use your history to give you better advice. That's data sharing. It's on from the start because that's the whole point.

If you want more control, add a passkey. That's your fingerprint or Face ID. Once you add one, a toggle appears in the app. Three options:

Always On. Coach always remembers you.

Always Off. Coach starts fresh every time.

Auto. Sharing is off until you scan your fingerprint when you log in.

Without a passkey, there's no toggle. Data sharing stays on. Your coach just works.

Your data is encrypted. Your fingerprint controls access. Nobody at FaithGrind is reading your conversations.


Want the specifics? Keep reading.

How it works step by step

1

You sign up. Your vault is created.

We generate a unique encryption key just for you. Every conversation, check-in, and note gets encrypted with that key before it touches the database. We never store your data in plain text.

2

Your coach uses your history to help you.

Data sharing is on by default. Your coach remembers past conversations and tailors advice to where you are. It gets better the more you use it.

3

Want more control? Add a passkey.

A passkey ties data sharing to your fingerprint or Face ID. Once added, you get a toggle with three modes: Always On, Always Off, or Auto.


Three modes. You decide.

Always On

Your coach remembers everything. Best responses. No friction.

Always Off

Data stays encrypted. Coach starts fresh every time. Flip it back on whenever you want.

Auto

Sharing is off by default. When you log in, the app asks for your fingerprint. If you pass, sharing turns on for that session.


Under the hood

AES-256-GCM encryption. Each user gets their own key.

Zero plain text storage. Encrypted before it hits the database.

WebAuthn passkeys. Industry standard. Your fingerprint never leaves your device.

Envelope encryption. Your key is wrapped by a master key. Even if someone got the database, they could not read your data.

Sign-in security log. At sign-in and sign-up we log a hashed and truncated version of your IP address (never the raw IP) plus your device user-agent, for account security and fraud prevention. Retained for 90 days, then deleted.


Your story is yours. We just help you write the next chapter.

Get Started