FAITH40

Privacy Policy

How Faith40 handles your data

Plain terms, no legal filler: what we collect, why, who (if anyone) sees it, and how to make us delete it.

Effective August 18, 2026Applies to the Faith40 iOS & Android appContact byniclee@gmail.com

01 What we collect

Faith40 collects only what's needed to run a 40-day challenge tied to your own account. Nothing here is collected for advertising, and nothing is collected passively in the background.

DataWhere it comes fromWhy we need it
Email addressYou, when you create an accountSign-in, password resets
PasswordYou, when you create an accountSign-in — stored as a salted hash, never in readable form (see §4)
Device timezoneYour device, automaticallyLine up your daily checklist with your actual midnight, not a server's
Challenge progressYou, as you use the appChecklist completion, current day, fast commitment, streak/grace/restart history
Reflection textYou, if you choose to write itShown back to you in the app — this is optional, and only you can read it

We do not collect your location, contacts, photos, or device identifiers, and the app contains no analytics or advertising SDKs of any kind.

02 How we use it

Every piece of data above exists to make the app itself work:

  • Authenticate you and keep your session signed in
  • Show the correct day of your challenge, on your own local calendar day
  • Save your checklist, reflections, and settings so they're there next time you open the app
  • Send you a password-reset email if you request one

We do not use your data to train any model, build an advertising profile, or make decisions about you beyond running the app you're using.

03 Who sees it

No one, by default. We don't sell data, share it with advertisers, or hand it to data brokers. There is exactly one third party involved, and it's infrastructure, not a partner with its own use of your data:

Supabase — our backend provider, hosting the database, authentication, and server functions Faith40 runs on. Supabase processes data solely on our instruction, under its own security and privacy commitments (supabase.com/privacy).

We'll only disclose data beyond that if legally compelled to (e.g. a valid court order) — that has never happened and we hope it never does.

04 Storage & security

  • All traffic between the app and our servers is encrypted in transit (HTTPS/TLS).
  • Passwords are hashed before storage — we cannot see or recover your actual password, ever.
  • Database access is locked down with row-level security: your data is only ever readable by your own signed-in account, enforced at the database layer, not just in the app's UI.

05 Retention & deletion

Your data is kept for as long as your account exists. You can permanently delete your account, and everything tied to it, at any time from inside the app:

Account → Delete account. This immediately and permanently removes your account, your full challenge history, and everything you've written — there's no recovery window and no need to contact us first.

06 Your rights

Wherever you're located, you have the right to:

  • Access what we hold on you — everything is already visible inside the app itself (your challenge history, reflections, and settings).
  • Correct it — edit your settings, reflections, and password directly in the app at any time.
  • Delete it — see §5 above.
  • Ask questions about any of this — email us, see §9.

07 Children

Faith40 is not directed at children under 13, and we don't knowingly collect data from them. If you believe a child has created an account, email us and we'll delete it.

08 Changes to this policy

If this policy changes in a way that matters, we'll update the effective date above. Meaningful changes — new categories of data, new third parties — will also be reflected here before they take effect.

09 Contact

Questions, concerns, or a data request that isn't covered by the in-app tools above: byniclee@gmail.com.