Home/Legal/Privacy Policy

Grace Unworthy Ministries, LLC


Privacy Policy


Effective Date: November 6, 2025

Last Updated: September 20, 2026

Document URL: https://graceunworthy.com/legal/privacy

Download PDF generates a letter-size Times document with page numbers. Print uses your browser's print dialog.

1. Introduction and Scope

Grace Unworthy Ministries, LLC is the data controller responsible for the personal information described in this Privacy Policy. This policy explains what we collect, why we collect it, who we share it with, how long we keep it, and the choices and rights available to you.

This Privacy Policy applies to all properties listed in our Covered Properties notice, to our mobile applications, and to offline interactions such as email, SMS, and support conversations. Your use of our services is also governed by our Terms of Service, and — if you use The Story Haven — by The Story Haven Community Guidelines.

Content and audience notice

Our services are intended for people aged 13 and older. Our faith-based educational content addresses mature subject matter, including sexuality, marriage, divorce, finances, abuse, grief, and trauma recovery.

For additional context about the nature of our content, see our Disclaimers page.

1.1 Data Protection Contact

Questions about this policy, requests to exercise your rights, and complaints about our handling of personal information should be directed to our data protection contact below. This is the same mailbox used for all privacy and data-rights requests.

Data Protection Contact

Data Protection Contact: Jeremy DeYoung

Email: [email protected]

Mailing Address:
Grace Unworthy Ministries, LLC
5753 Highway 85 N PMB 3496
Crestview, FL 32536

2. Information We Collect

The categories below describe everything we collect. Not all categories apply to every user — what we hold depends on which services you use.

2.1 Account Information

  • Name and email address
  • Username or display name
  • Password, stored only as a salted cryptographic hash — we never store or have access to your plaintext password
  • Profile photo, cover image, bio, and social links
  • Account settings, notification preferences, and language or display preferences
  • Records of your acceptance of our policies, including policy version and timestamp

2.2 Optional Profile Fields (Including Sensitive Categories)

Your profile may include optional fields such as birthday, location, occupation, interests, and church or religious affiliation. These fields are provided entirely at your discretion, and leaving them blank does not restrict your access to our services.

Special category data (GDPR Article 9)

Information about your religious or philosophical beliefs — including church affiliation, denominational identity, faith journey details you enter into your profile, and religious content you choose to share — is treated as a special category of personal data under Article 9 of the GDPR and as sensitive personal information under comparable laws.

Why we collect it: solely to operate community features — matching you with relevant groups, rooms, prayer circles, reading plans, and content recommendations within our faith-centered platforms.

Our legal basis: your explicit consent, given by voluntarily entering this information. Where you post religious beliefs publicly on our platforms, we also rely on Article 9(2)(e) (information manifestly made public by the data subject).

Withdrawing consent: you can clear these fields at any time in your profile settings, or email [email protected] to have them removed. Withdrawal does not affect processing that took place before you withdrew.

2.3 The Story Haven Community and Mobile App

When you use The Story Haven — on the web or in the mobile app — we collect the content you create and information about how you use the platform:

  • Posts and comments: text, formatting, attachments, reactions, bookmarks, and shares
  • Direct messages: the content of private messages you send and receive, including attachments
  • Images and media: photos, cover images, and other files you upload
  • Audio and voice notes: recordings you attach to posts, comments, or direct messages
  • Transcripts: automated text transcriptions of audio and voice notes
  • Prayer tags, reading plans, and saved verses: spiritual activity records tied to your account
  • Search queries: terms you enter in in-app search
  • Group, room, and follow activity: memberships, participation, follows, blocks, reports, and moderation actions affecting your account
  • Device and push data: push notification tokens, a generated device identifier (deviceId), platform type, and app version
  • Session analytics: sessions, screen views, feature usage, and engagement timing
  • Affinity scores: internal relevance scores derived from your activity that we use to order feeds, suggest people and groups, and rank content

Voice note transcription includes private messages

Audio and voice notes are sent to AssemblyAI, a third-party speech-to-text provider, to produce transcripts. This includes voice notes sent in private direct messages. Transcription is applied automatically to enable accessibility, search, and safety review, and there is currently no per-message setting to disable it. If you do not want a recording transcribed by a third party, do not send it as a voice note.

Content you post in public rooms, public groups, or on a public profile may be visible to other members and, in some cases, to the general public and search engines. See The Story Haven Community Guidelines for details on visibility and moderation.

2.4 AI Safety and Moderation Signals

Automated trauma and safety scoring

To keep a trauma-aware community safe, the text of posts and comments may be transmitted to OpenAI for automated review. This review produces internal safety and trauma sensitivity scores that are stored with the content.

These scores can affect how your content is handled — for example, whether a content warning is applied, whether the post is deprioritized or limited in distribution, whether crisis resources are surfaced, or whether the item is routed to a human moderator for review.

There is currently no per-user opt-out from this safety review. It applies to content submitted to our community platforms as a condition of using them. Automated scores inform, but do not solely determine, enforcement actions that significantly affect you; you may contest a moderation outcome by contacting [email protected].

2.5 Learning and Course Data

  • Course enrollments, progress, and completion status
  • Lesson, section, and step progression and time spent
  • Quiz and assessment answers, scores, and attempts
  • Notes, reflections, and free-text responses you submit
  • Certificates, achievements, and points earned
  • Course feedback and ratings

2.6 GuidedSteps and Journaling Content

If you use GuidedSteps or any journaling, reflection, or prayer journal feature, we store the entries you write, the prompts you respond to, your step and program progress, and any mood, gratitude, or spiritual practice entries you record. This content is frequently personal and may reveal religious beliefs or details about your mental and emotional health; we treat it with the same sensitivity described in Section 2.2 and use it only to deliver the feature to you.

2.7 Commerce and Payment Information

  • Billing name, billing address, and shipping addresses
  • Stripe customer, subscription, and payment identifiers — we do not receive or store full payment card numbers or CVV codes; card data is collected directly by Stripe
  • Order history, line items, coupons, credits, points, refunds, and invoices
  • Subscription status, renewal dates, and dunning history
  • Shipment tracking information for physical products, including carrier status updates

2.8 CRM, Email, and SMS Marketing Data

  • Contact records in our internal CRM, including name, email, phone number, tags, lists, and notes from your interactions with us
  • Email and SMS subscription status, opt-in source, opt-in timestamp, and opt-out records
  • Email engagement events — deliveries, opens, clicks, bounces, and complaints — including the IP address and user agent recorded when a message is opened or a link is clicked
  • Inbound messages you send us by email, SMS, WhatsApp, Facebook Messenger, or contact form, and our replies

Text message programs are described separately in our SMS & Text Messaging Terms.

2.9 Information Collected Automatically

  • IP address and approximate location derived from it
  • Browser type, user agent string, device type, and operating system
  • Referring URLs, pages viewed, and navigation paths
  • Timestamps, session duration, and error and crash diagnostics
  • Cookies, local storage, and similar technologies
  • A device fingerprint hash generated by FingerprintJS, which we use to cap how often the same device is shown a given advertisement or promotion and to detect abuse

2.10 Third-Party Sign-In (OAuth)

You may create or access an account using Google, Facebook, LinkedIn, Twitter/X, or Apple. When you do, we receive the identifier and basic profile fields that provider shares with us — typically name, email address, profile picture, and a provider user ID. Apple may supply a private relay email address instead of your real one. We use this information only to create and authenticate your account. We do not post to your social accounts, and we do not request access beyond what sign-in requires. What each provider shares is governed by your settings with that provider.

3. How We Use Your Information

  • Create, authenticate, and secure your account
  • Deliver the services you request, including courses, community features, journaling, and purchases
  • Process payments, subscriptions, refunds, shipping, and related recordkeeping
  • Track learning progress and issue certificates and achievements
  • Personalize feeds, recommendations, and content ordering using affinity scores and activity history
  • Operate safety and moderation systems, including automated trauma and safety scoring
  • Provide customer support and respond to your inquiries
  • Send transactional messages such as receipts, security alerts, and policy updates
  • Send marketing emails and text messages where you have opted in, and measure their performance
  • Measure advertising performance and limit repeat ad exposure on the same device
  • Detect, investigate, and prevent fraud, abuse, spam, and security incidents
  • Analyze usage to debug, maintain, and improve our services
  • Comply with legal obligations and enforce our agreements

3.1 Artificial Intelligence and Machine Learning

AI is embedded in several parts of our platform. We want to be specific about where your data is involved:

  • Safety and trauma scoring: post and comment text is sent to OpenAI to generate moderation and sensitivity scores, as described in Section 2.4.
  • Waitlist name inference: when you join The Story Haven waitlist, the given name you provide may be sent to OpenAI to estimate gender presentation so we can route you toward gender-specific rooms. The estimate is stored as a probability on the waitlist record and is not used as identity verification.
  • Image text recognition: images attached to Story Haven posts may be sent to OpenAI vision models to detect and extract Bible verse references for linking.
  • Support tickets and Storyteller compose: text you write in support tickets, and drafts Storytellers ask the compose or review tools to help with, may be sent to OpenAI to generate suggested copy. Ticket drafts are reviewed by staff; compose suggestions are shown to the Storyteller before publishing.
  • Voice transcription: audio and voice notes, including those sent in direct messages, are sent to AssemblyAI for speech-to-text conversion.
  • Assisted inbox replies (RAG): when our team responds to your support or contact messages, an AI system may draft a suggested reply by retrieving relevant prior content. Your message text may be processed by OpenAI as part of generating that draft. Replies are reviewed by a person before being sent.
  • Embeddings: vector embeddings generated from message and knowledge content are stored in our own MySQL database on infrastructure we control. We do not use a third-party vector database service for this data.
  • Course knowledge: course materials are indexed to power in-course search and question answering.
  • Content generation: podcast episodes and our own source material are used to draft blog posts and articles. This uses our content, not your personal data, and output is reviewed by our team before publication.

AI opt-out status

We do not currently offer a per-user opt-out from AI processing. Safety scoring, transcription, and retrieval-assisted replies are integral to how the platform operates today. If AI processing is not acceptable to you, the available choice is not to submit the content in question — for example, by not sending voice notes or not posting to community features.

We do not sell your content to AI companies, and we do not authorize our AI vendors to use your content to train their general-purpose models. Where a vendor offers a no-training-on-customer-data setting for the API tier we use, we rely on it.

4. Legal Bases for Processing (GDPR/UK GDPR)

If you are in the European Economic Area, the United Kingdom, or another jurisdiction with equivalent requirements, we rely on performance of a contract, consent (including explicit consent for special category data), legitimate interests, legal obligation, and — in rare safety emergencies — vital interests. The full Article 6 and Article 9 bases, with examples for each, are set out in our GDPR & UK GDPR Privacy Notice.

5. How We Share Information

We share personal information only in the circumstances described here. We do not sell personal information for money.

5.1 Service Providers and Subprocessors

We rely on the vendors below to operate our services. Each receives only the data needed for its function and is bound by contract to protect it. This list is current as of the Last Updated date shown at the top of this page and may change as our infrastructure evolves.

Payments and commerce

  • Stripe — payment processing, subscription billing, and fraud screening
  • EasyPost — shipping labels, rates, and package tracking for physical orders

Messaging and communications

  • Postmark — transactional and marketing email delivery and engagement tracking
  • Gmail API — synchronizing our staff inbox so email conversations with you appear in our CRM
  • Twilio — SMS and text message delivery
  • WhatsApp Business API — WhatsApp conversations where you initiate contact through that channel
  • Facebook Messenger API — Messenger conversations where you initiate contact through that channel
  • Expo / EAS Push and Web Push — delivery of push notifications to your devices

Artificial intelligence

  • OpenAI — safety and trauma scoring, embeddings, waitlist given-name gender inference, post-image verse recognition, assisted inbox replies, support-ticket drafts, Storyteller compose assistance, and content generation
  • AssemblyAI — speech-to-text transcription of audio and voice notes, including voice notes in direct messages

Hosting, media, and infrastructure

  • Cloudinary — image and media storage, transformation, and delivery
  • AWS S3 — file and document storage
  • Redis / BullMQ — job queues and short-lived caches, which may hold media URLs, job payloads, and hashed safety-score results for about an hour
  • Cloudflare — CDN, DDoS protection and web application firewall, Turnstile bot verification, and Cloudflare Web Analytics
  • Google Cloud Logging — application and infrastructure log storage
  • Sentry — error and crash reporting, including diagnostic context attached to an error

Media distribution

  • Castos — podcast hosting, distribution, and listener analytics
  • Vimeo — video hosting and playback analytics

Advertising, analytics, and product measurement

  • Meta — Meta Pixel and the Meta Conversions API, used for advertising measurement and audience building; the Conversions API transmits conversion events from our servers
  • Google Analytics, Google Tag Manager, and the GA4 Measurement Protocol — web and server-side analytics and tag deployment
  • TikTok Pixel — advertising measurement and conversion tracking
  • LogRocket — session replay and frontend diagnostics, which may capture interactions with pages you visit
  • FingerprintJS — device fingerprint hashing for advertising frequency capping and abuse detection
  • Vexo Analytics — mobile app product analytics
  • Firebase Analytics — mobile app usage analytics
  • Meta App Events — mobile app event reporting to Meta for advertising measurement
  • expo-observe — mobile app performance and startup metrics

Sharing with the advertising and analytics vendors above may constitute a "sale" or "sharing" of personal information under California law. See Section 9.2 and our Notice at Collection & Do Not Sell or Share for how to opt out.

5.2 Other Members and the Public

Content you post publicly — including posts, comments, profile fields, and reactions in public rooms and groups — is shared with other members and may be publicly accessible. Direct messages are shared with their recipients. Reported content and associated account information are shared with our moderation team.

5.3 Legal and Safety Disclosures

We may disclose information when we believe in good faith that it is required by law, valid legal process, or a government request, or when disclosure is necessary to protect the rights, property, or safety of our users, the public, or us — including reporting suspected child exploitation to the appropriate authorities. Our practices for subpoenas, warrants, and user notification are described in our Law Enforcement & Transparency Policy.

5.4 Business Transfers

If we are involved in a merger, acquisition, financing, reorganization, or sale of assets, personal information may be transferred as part of that transaction. We will notify you by email or prominent notice if such a transfer materially changes how your information is handled.

5.5 With Your Direction

We share information with other parties when you ask us to or otherwise direct us to do so.

6. Cookies and Similar Technologies

We use cookies, local storage, mobile SDK identifiers, and pixels for essential functionality, analytics, and advertising measurement. A full breakdown by category and provider is in our Cookie Policy.

Our current consent posture — plainly stated

We want to be candid rather than aspirational. Analytics and advertising technologies may load on our websites before you interact with a consent control, and our consent tooling is not uniformly deployed across every property and every page. We are actively working to tighten this.

Until that work is complete, the most reliable ways to limit non-essential tracking are to use the reject or opt-out control where it is presented, configure your browser to block third-party cookies, use tracking-prevention features or extensions, and — for mobile — disable ad personalization in your device settings.

We do not currently respond to browser-based Do Not Track signals, because no common standard governs how they should be honored. We do honor documented opt-out requests sent to [email protected].

7. Security

We use technical and organizational measures appropriate to our size and risk profile, including TLS encryption in transit, hashed password storage, role-based access controls for administrative functions, input validation, a web application firewall and DDoS protection at the edge, audit logging of sensitive administrative actions, and regular backups. Payment card data is handled by PCI-compliant processors and does not reach our servers.

What we do not claim

We are a small organization and we will not overstate our posture. We do not currently hold SOC 2, ISO 27001, or comparable third-party security certifications; we do not conduct scheduled independent penetration tests or formal external audits; we do not operate a formal, documented employee security training program; and we do not manage application-layer encryption keys through a dedicated key management service. No system is perfectly secure, and we cannot guarantee absolute security.

Our current practices, incident response approach, and vulnerability reporting process are described in our Security Policy. To report a suspected vulnerability, email [email protected].

8. Data Retention

Purchase and financial records are retained for legal and financial purposes

Orders, invoices, payments, refunds, subscription history, and related financial records are retained for as long as reasonably necessary for tax, accounting, audit, chargeback, fraud prevention, dispute resolution, and legal compliance — which may be many years and typically means these records are not deleted when you request account deletion. Where possible, we minimize the identifying detail retained alongside these records. See our Data Deletion & Retention Policy for the operational schedule.

For other categories, our general approach is:

  • Account and profile data: retained while your account is active and for a short wind-down period after deletion.
  • Community content: posts, comments, and media are removed or disassociated from your account on deletion; copies already delivered to other members, quoted, or shared may persist.
  • Direct messages: your copy is removed on deletion; recipients retain their copies of messages you sent them.
  • Voice notes and transcripts: retained with the associated message and removed with it.
  • Learning records: progress and certificates are retained while your account is active; enrollment records tied to a purchase follow the financial retention rule above.
  • Moderation and safety records: reports, enforcement actions, and ban records are retained after account deletion to enforce our policies and prevent ban evasion.
  • Marketing and suppression data: opt-out and unsubscribe records are retained indefinitely so we can continue to honor your opt-out.
  • Logs and diagnostics: typically retained for a limited operational window, then deleted or aggregated.
  • Analytics: aggregated and de-identified analytics may be retained indefinitely.

Encrypted backups are retained on a rolling schedule. Data deleted from live systems may persist in backups until those backups age out of rotation, after which it is overwritten. We do not restore deleted personal data from backups except to recover from a system failure.

Step-by-step deletion instructions and the full retention schedule are in our Data Deletion & Retention Policy.

9. Your Privacy Rights

9.1 GDPR and UK GDPR Rights

If you are in the EEA, the UK, or Switzerland, you have rights of access, rectification, erasure, restriction, portability, objection (including to direct marketing), withdrawal of consent, and — where applicable — not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects, with a right to request human review. You may also complain to your local supervisory authority or, in the UK, the Information Commissioner's Office. Full detail, including how to exercise these rights and our response times, is in our GDPR & UK GDPR Privacy Notice.

9.2 California Rights (CCPA/CPRA)

If you are a California resident, you have the right to know what personal information we collect and how we use and disclose it; to request deletion, subject to the exceptions in Section 8; to correct inaccurate personal information; to opt out of the sale or sharing of personal information; to limit the use and disclosure of sensitive personal information; and to be free from discrimination for exercising these rights.

Sale and sharing — our honest position

We do not exchange personal information for money. However, our use of advertising and analytics technologies — including the Meta Pixel and Conversions API, Google Analytics and the GA4 Measurement Protocol, TikTok Pixel, Meta App Events, and device fingerprinting for ad frequency capping — may constitute a "sale" or "sharing" of personal information for cross-context behavioral advertising under the CPRA. We treat it as such rather than claiming an exemption we cannot fully substantiate.

The categories potentially involved are identifiers, internet and electronic network activity information, commercial information, and inferences.

To opt out, do either or both of the following:

  • Select "Reject" on the cookie or consent control where it is presented, and block third-party cookies in your browser
  • Email [email protected] with the subject line "Do Not Sell or Share My Personal Information" — we will apply the opt-out to your account and to the identifiers you give us

Full details, including the categories collected and disclosed in the preceding twelve months, are in our Notice at Collection & Do Not Sell or Share.

Sensitive personal information. Religious affiliation and similar sensitive fields described in Section 2.2 are collected only with your consent and used only to provide community features. We do not use or disclose sensitive personal information for purposes that require offering a right to limit under the CPRA.

Authorized agents. You may designate an authorized agent to submit requests on your behalf. We will ask for written permission signed by you and may verify your identity directly.

9.3 How to Exercise Your Rights and Our Response Times

Submit requests to [email protected]. Deletion and related account requests are handled by email as described in our Data Deletion & Retention Policy — there is currently no in-app or web self-service delete-account button. Please tell us which right you are exercising and include the email address associated with your account. We will take reasonable steps to verify your identity before acting, and we may decline requests we cannot verify.

  • We aim to acknowledge requests promptly, usually within a few business days.
  • We aim to substantively respond to GDPR and UK GDPR requests within 30 days, extendable by up to two further months for complex requests, in which case we will tell you why.
  • We aim to substantively respond to CCPA/CPRA requests within 45 days, with one additional 45-day extension where permitted and with notice to you.

Exercising your rights is free. We may charge a reasonable fee or decline to act on requests that are manifestly unfounded, excessive, or repetitive, and we will explain our reasoning if we do.

9.4 Communication Preferences

You can unsubscribe from marketing email using the link in any marketing message or by emailing [email protected]. You can stop text messages by replying STOP, as described in our SMS & Text Messaging Terms. Push notifications can be disabled in your device or in-app settings. We will still send transactional messages related to your account, purchases, security, and legal notices.

10. Children's Privacy

Our services are not directed to children under 13, and you must be at least 13 years old to create an account. If you are between 13 and 18 years of age, you represent that you have permission from a parent or legal guardian to use our services.

No COPPA parental consent workflow

We do not knowingly collect personal information from anyone under 13. Our products do not include a verifiable parental consent mechanism under the Children's Online Privacy Protection Act, because they are not designed or intended for children under 13. Age is collected as a self-declared representation at registration; we do not perform documentary age verification.

If we learn that we have collected personal information from a child under 13, we will delete the account and associated data promptly. Parents and guardians who believe a child has provided us information should contact [email protected] and we will act on it.

For users between 13 and 17, we recommend parental involvement given the mature subject matter described in Section 1. A parent or guardian may request deletion of a minor's account by contacting [email protected].

11. International Data Transfers

We are based in the United States, and our infrastructure and most of our service providers are located in or process data in the United States. If you access our services from outside the United States, your personal information will be transferred to, stored in, and processed in the United States and in other countries where our providers operate. Data protection laws in those countries may differ from those in your jurisdiction.

For transfers of personal data out of the EEA, the UK, or Switzerland, we rely on Standard Contractual Clauses and the UK International Data Transfer Addendum with vendors that provide them, together with the safeguards described in Section 7. We have not yet finished confirming a documented transfer mechanism for every provider we use, and that review is ongoing; where a provider does not offer one, we work to put a mechanism in place or replace the provider. Details are in our GDPR & UK GDPR Privacy Notice. To ask which mechanism applies to a specific provider or to your own data, contact [email protected].

12. Third-Party Links, Apps, and Platforms

Our sites and apps link to third-party websites, embedded media, podcast platforms, and app stores that we do not control. Interacting with them may allow those parties to collect data about you under their own policies. This includes the OAuth providers listed in Section 2.10 and the app stores through which our mobile apps are distributed — use of our mobile apps is also subject to our End User License Agreement (EULA). We encourage you to review the privacy policies of any third party you interact with.

13. Changes to This Privacy Policy

We may update this Privacy Policy to reflect changes in our practices, technology, vendors, or legal obligations. When we do, we will revise the Last Updated date at the top of this page. For material changes — such as new categories of data, new purposes, or new sharing that meaningfully affects you — we will provide more prominent notice, which may include an in-product notice or an email to the address on your account. Continued use of our services after an update takes effect constitutes acceptance of the revised policy.

14. Contact Us

For privacy questions, rights requests, or complaints about how we handle personal information, contact us using the details below. Privacy matters should go to [email protected] rather than a personal mailbox, so that requests are tracked and answered within the timeframes in Section 9.3.

Privacy Contact

Privacy & Data Rights

Email: [email protected]

General Support: [email protected]

Mailing Address:
Grace Unworthy Ministries, LLC
5753 Highway 85 N PMB 3496
Crestview, FL 32536

End of Privacy Policy

Grace Unworthy Ministries, LLC

https://graceunworthy.com/legal/privacy