Grace Unworthy Ministries, LLC
Privacy Policy
Effective Date: November 6, 2025
Last Updated: September 20, 2026
Document URL: https://graceunworthy.com/legal/privacy
Download PDF generates a letter-size Times document with page numbers. Print uses your browser's print dialog.
1. Introduction and Scope
Grace Unworthy Ministries, LLC is the data controller responsible for the personal information described in this Privacy Policy. This policy explains what we collect, why we collect it, who we share it with, how long we keep it, and the choices and rights available to you.
This Privacy Policy applies to all properties listed in our Covered Properties notice, to our mobile applications, and to offline interactions such as email, SMS, and support conversations. Your use of our services is also governed by our Terms of Service, and — if you use The Story Haven — by The Story Haven Community Guidelines.
1.1 Data Protection Contact
Questions about this policy, requests to exercise your rights, and complaints about our handling of personal information should be directed to our data protection contact below. This is the same mailbox used for all privacy and data-rights requests.
Data Protection Contact
Data Protection Contact: Jeremy DeYoung
Email: [email protected]
Mailing Address:
Grace Unworthy Ministries, LLC
5753 Highway 85 N PMB 3496
Crestview, FL 32536
2. Information We Collect
The categories below describe everything we collect. Not all categories apply to every user — what we hold depends on which services you use.
2.1 Account Information
- Name and email address
- Username or display name
- Password, stored only as a salted cryptographic hash — we never store or have access to your plaintext password
- Profile photo, cover image, bio, and social links
- Account settings, notification preferences, and language or display preferences
- Records of your acceptance of our policies, including policy version and timestamp
2.2 Optional Profile Fields (Including Sensitive Categories)
Your profile may include optional fields such as birthday, location, occupation, interests, and church or religious affiliation. These fields are provided entirely at your discretion, and leaving them blank does not restrict your access to our services.
2.3 The Story Haven Community and Mobile App
When you use The Story Haven — on the web or in the mobile app — we collect the content you create and information about how you use the platform:
- Posts and comments: text, formatting, attachments, reactions, bookmarks, and shares
- Direct messages: the content of private messages you send and receive, including attachments
- Images and media: photos, cover images, and other files you upload
- Audio and voice notes: recordings you attach to posts, comments, or direct messages
- Transcripts: automated text transcriptions of audio and voice notes
- Prayer tags, reading plans, and saved verses: spiritual activity records tied to your account
- Search queries: terms you enter in in-app search
- Group, room, and follow activity: memberships, participation, follows, blocks, reports, and moderation actions affecting your account
- Device and push data: push notification tokens, a generated device identifier (deviceId), platform type, and app version
- Session analytics: sessions, screen views, feature usage, and engagement timing
- Affinity scores: internal relevance scores derived from your activity that we use to order feeds, suggest people and groups, and rank content
Content you post in public rooms, public groups, or on a public profile may be visible to other members and, in some cases, to the general public and search engines. See The Story Haven Community Guidelines for details on visibility and moderation.
2.4 AI Safety and Moderation Signals
2.5 Learning and Course Data
- Course enrollments, progress, and completion status
- Lesson, section, and step progression and time spent
- Quiz and assessment answers, scores, and attempts
- Notes, reflections, and free-text responses you submit
- Certificates, achievements, and points earned
- Course feedback and ratings
2.6 GuidedSteps and Journaling Content
If you use GuidedSteps or any journaling, reflection, or prayer journal feature, we store the entries you write, the prompts you respond to, your step and program progress, and any mood, gratitude, or spiritual practice entries you record. This content is frequently personal and may reveal religious beliefs or details about your mental and emotional health; we treat it with the same sensitivity described in Section 2.2 and use it only to deliver the feature to you.
2.7 Commerce and Payment Information
- Billing name, billing address, and shipping addresses
- Stripe customer, subscription, and payment identifiers — we do not receive or store full payment card numbers or CVV codes; card data is collected directly by Stripe
- Order history, line items, coupons, credits, points, refunds, and invoices
- Subscription status, renewal dates, and dunning history
- Shipment tracking information for physical products, including carrier status updates
2.8 CRM, Email, and SMS Marketing Data
- Contact records in our internal CRM, including name, email, phone number, tags, lists, and notes from your interactions with us
- Email and SMS subscription status, opt-in source, opt-in timestamp, and opt-out records
- Email engagement events — deliveries, opens, clicks, bounces, and complaints — including the IP address and user agent recorded when a message is opened or a link is clicked
- Inbound messages you send us by email, SMS, WhatsApp, Facebook Messenger, or contact form, and our replies
Text message programs are described separately in our SMS & Text Messaging Terms.
2.9 Information Collected Automatically
- IP address and approximate location derived from it
- Browser type, user agent string, device type, and operating system
- Referring URLs, pages viewed, and navigation paths
- Timestamps, session duration, and error and crash diagnostics
- Cookies, local storage, and similar technologies
- A device fingerprint hash generated by FingerprintJS, which we use to cap how often the same device is shown a given advertisement or promotion and to detect abuse
2.10 Third-Party Sign-In (OAuth)
You may create or access an account using Google, Facebook, LinkedIn, Twitter/X, or Apple. When you do, we receive the identifier and basic profile fields that provider shares with us — typically name, email address, profile picture, and a provider user ID. Apple may supply a private relay email address instead of your real one. We use this information only to create and authenticate your account. We do not post to your social accounts, and we do not request access beyond what sign-in requires. What each provider shares is governed by your settings with that provider.
3. How We Use Your Information
- Create, authenticate, and secure your account
- Deliver the services you request, including courses, community features, journaling, and purchases
- Process payments, subscriptions, refunds, shipping, and related recordkeeping
- Track learning progress and issue certificates and achievements
- Personalize feeds, recommendations, and content ordering using affinity scores and activity history
- Operate safety and moderation systems, including automated trauma and safety scoring
- Provide customer support and respond to your inquiries
- Send transactional messages such as receipts, security alerts, and policy updates
- Send marketing emails and text messages where you have opted in, and measure their performance
- Measure advertising performance and limit repeat ad exposure on the same device
- Detect, investigate, and prevent fraud, abuse, spam, and security incidents
- Analyze usage to debug, maintain, and improve our services
- Comply with legal obligations and enforce our agreements
3.1 Artificial Intelligence and Machine Learning
AI is embedded in several parts of our platform. We want to be specific about where your data is involved:
- Safety and trauma scoring: post and comment text is sent to OpenAI to generate moderation and sensitivity scores, as described in Section 2.4.
- Waitlist name inference: when you join The Story Haven waitlist, the given name you provide may be sent to OpenAI to estimate gender presentation so we can route you toward gender-specific rooms. The estimate is stored as a probability on the waitlist record and is not used as identity verification.
- Image text recognition: images attached to Story Haven posts may be sent to OpenAI vision models to detect and extract Bible verse references for linking.
- Support tickets and Storyteller compose: text you write in support tickets, and drafts Storytellers ask the compose or review tools to help with, may be sent to OpenAI to generate suggested copy. Ticket drafts are reviewed by staff; compose suggestions are shown to the Storyteller before publishing.
- Voice transcription: audio and voice notes, including those sent in direct messages, are sent to AssemblyAI for speech-to-text conversion.
- Assisted inbox replies (RAG): when our team responds to your support or contact messages, an AI system may draft a suggested reply by retrieving relevant prior content. Your message text may be processed by OpenAI as part of generating that draft. Replies are reviewed by a person before being sent.
- Embeddings: vector embeddings generated from message and knowledge content are stored in our own MySQL database on infrastructure we control. We do not use a third-party vector database service for this data.
- Course knowledge: course materials are indexed to power in-course search and question answering.
- Content generation: podcast episodes and our own source material are used to draft blog posts and articles. This uses our content, not your personal data, and output is reviewed by our team before publication.
4. Legal Bases for Processing (GDPR/UK GDPR)
If you are in the European Economic Area, the United Kingdom, or another jurisdiction with equivalent requirements, we rely on performance of a contract, consent (including explicit consent for special category data), legitimate interests, legal obligation, and — in rare safety emergencies — vital interests. The full Article 6 and Article 9 bases, with examples for each, are set out in our GDPR & UK GDPR Privacy Notice.
5. How We Share Information
We share personal information only in the circumstances described here. We do not sell personal information for money.
5.1 Service Providers and Subprocessors
We rely on the vendors below to operate our services. Each receives only the data needed for its function and is bound by contract to protect it. This list is current as of the Last Updated date shown at the top of this page and may change as our infrastructure evolves.
Sharing with the advertising and analytics vendors above may constitute a "sale" or "sharing" of personal information under California law. See Section 9.2 and our Notice at Collection & Do Not Sell or Share for how to opt out.
5.2 Other Members and the Public
Content you post publicly — including posts, comments, profile fields, and reactions in public rooms and groups — is shared with other members and may be publicly accessible. Direct messages are shared with their recipients. Reported content and associated account information are shared with our moderation team.
5.3 Legal and Safety Disclosures
We may disclose information when we believe in good faith that it is required by law, valid legal process, or a government request, or when disclosure is necessary to protect the rights, property, or safety of our users, the public, or us — including reporting suspected child exploitation to the appropriate authorities. Our practices for subpoenas, warrants, and user notification are described in our Law Enforcement & Transparency Policy.
5.4 Business Transfers
If we are involved in a merger, acquisition, financing, reorganization, or sale of assets, personal information may be transferred as part of that transaction. We will notify you by email or prominent notice if such a transfer materially changes how your information is handled.
5.5 With Your Direction
We share information with other parties when you ask us to or otherwise direct us to do so.
6. Cookies and Similar Technologies
We use cookies, local storage, mobile SDK identifiers, and pixels for essential functionality, analytics, and advertising measurement. A full breakdown by category and provider is in our Cookie Policy.
7. Security
We use technical and organizational measures appropriate to our size and risk profile, including TLS encryption in transit, hashed password storage, role-based access controls for administrative functions, input validation, a web application firewall and DDoS protection at the edge, audit logging of sensitive administrative actions, and regular backups. Payment card data is handled by PCI-compliant processors and does not reach our servers.
Our current practices, incident response approach, and vulnerability reporting process are described in our Security Policy. To report a suspected vulnerability, email [email protected].
8. Data Retention
For other categories, our general approach is:
- Account and profile data: retained while your account is active and for a short wind-down period after deletion.
- Community content: posts, comments, and media are removed or disassociated from your account on deletion; copies already delivered to other members, quoted, or shared may persist.
- Direct messages: your copy is removed on deletion; recipients retain their copies of messages you sent them.
- Voice notes and transcripts: retained with the associated message and removed with it.
- Learning records: progress and certificates are retained while your account is active; enrollment records tied to a purchase follow the financial retention rule above.
- Moderation and safety records: reports, enforcement actions, and ban records are retained after account deletion to enforce our policies and prevent ban evasion.
- Marketing and suppression data: opt-out and unsubscribe records are retained indefinitely so we can continue to honor your opt-out.
- Logs and diagnostics: typically retained for a limited operational window, then deleted or aggregated.
- Analytics: aggregated and de-identified analytics may be retained indefinitely.
Encrypted backups are retained on a rolling schedule. Data deleted from live systems may persist in backups until those backups age out of rotation, after which it is overwritten. We do not restore deleted personal data from backups except to recover from a system failure.
Step-by-step deletion instructions and the full retention schedule are in our Data Deletion & Retention Policy.
9. Your Privacy Rights
9.1 GDPR and UK GDPR Rights
If you are in the EEA, the UK, or Switzerland, you have rights of access, rectification, erasure, restriction, portability, objection (including to direct marketing), withdrawal of consent, and — where applicable — not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects, with a right to request human review. You may also complain to your local supervisory authority or, in the UK, the Information Commissioner's Office. Full detail, including how to exercise these rights and our response times, is in our GDPR & UK GDPR Privacy Notice.
9.2 California Rights (CCPA/CPRA)
If you are a California resident, you have the right to know what personal information we collect and how we use and disclose it; to request deletion, subject to the exceptions in Section 8; to correct inaccurate personal information; to opt out of the sale or sharing of personal information; to limit the use and disclosure of sensitive personal information; and to be free from discrimination for exercising these rights.
Sensitive personal information. Religious affiliation and similar sensitive fields described in Section 2.2 are collected only with your consent and used only to provide community features. We do not use or disclose sensitive personal information for purposes that require offering a right to limit under the CPRA.
Authorized agents. You may designate an authorized agent to submit requests on your behalf. We will ask for written permission signed by you and may verify your identity directly.
9.3 How to Exercise Your Rights and Our Response Times
Submit requests to [email protected]. Deletion and related account requests are handled by email as described in our Data Deletion & Retention Policy — there is currently no in-app or web self-service delete-account button. Please tell us which right you are exercising and include the email address associated with your account. We will take reasonable steps to verify your identity before acting, and we may decline requests we cannot verify.
- We aim to acknowledge requests promptly, usually within a few business days.
- We aim to substantively respond to GDPR and UK GDPR requests within 30 days, extendable by up to two further months for complex requests, in which case we will tell you why.
- We aim to substantively respond to CCPA/CPRA requests within 45 days, with one additional 45-day extension where permitted and with notice to you.
Exercising your rights is free. We may charge a reasonable fee or decline to act on requests that are manifestly unfounded, excessive, or repetitive, and we will explain our reasoning if we do.
9.4 Communication Preferences
You can unsubscribe from marketing email using the link in any marketing message or by emailing [email protected]. You can stop text messages by replying STOP, as described in our SMS & Text Messaging Terms. Push notifications can be disabled in your device or in-app settings. We will still send transactional messages related to your account, purchases, security, and legal notices.
10. Children's Privacy
Our services are not directed to children under 13, and you must be at least 13 years old to create an account. If you are between 13 and 18 years of age, you represent that you have permission from a parent or legal guardian to use our services.
For users between 13 and 17, we recommend parental involvement given the mature subject matter described in Section 1. A parent or guardian may request deletion of a minor's account by contacting [email protected].
11. International Data Transfers
We are based in the United States, and our infrastructure and most of our service providers are located in or process data in the United States. If you access our services from outside the United States, your personal information will be transferred to, stored in, and processed in the United States and in other countries where our providers operate. Data protection laws in those countries may differ from those in your jurisdiction.
For transfers of personal data out of the EEA, the UK, or Switzerland, we rely on Standard Contractual Clauses and the UK International Data Transfer Addendum with vendors that provide them, together with the safeguards described in Section 7. We have not yet finished confirming a documented transfer mechanism for every provider we use, and that review is ongoing; where a provider does not offer one, we work to put a mechanism in place or replace the provider. Details are in our GDPR & UK GDPR Privacy Notice. To ask which mechanism applies to a specific provider or to your own data, contact [email protected].
12. Third-Party Links, Apps, and Platforms
Our sites and apps link to third-party websites, embedded media, podcast platforms, and app stores that we do not control. Interacting with them may allow those parties to collect data about you under their own policies. This includes the OAuth providers listed in Section 2.10 and the app stores through which our mobile apps are distributed — use of our mobile apps is also subject to our End User License Agreement (EULA). We encourage you to review the privacy policies of any third party you interact with.
13. Changes to This Privacy Policy
We may update this Privacy Policy to reflect changes in our practices, technology, vendors, or legal obligations. When we do, we will revise the Last Updated date at the top of this page. For material changes — such as new categories of data, new purposes, or new sharing that meaningfully affects you — we will provide more prominent notice, which may include an in-product notice or an email to the address on your account. Continued use of our services after an update takes effect constitutes acceptance of the revised policy.
14. Contact Us
For privacy questions, rights requests, or complaints about how we handle personal information, contact us using the details below. Privacy matters should go to [email protected] rather than a personal mailbox, so that requests are tracked and answered within the timeframes in Section 9.3.
Privacy Contact
Privacy & Data Rights
Email: [email protected]
General Support: [email protected]
Mailing Address:
Grace Unworthy Ministries, LLC
5753 Highway 85 N PMB 3496
Crestview, FL 32536