Privacy Policy

Last updated: 15 August 2026

What we collect

  • Account data: email address and password (stored by AWS Cognito).
  • Profile data you provide: name, birthdate, gender, denomination, church, city, bio, faith statement, photos, and optional signup attribution.
  • Event activity: registrations, check-ins, and QR connections you make.
  • Messages you send to your connections.
  • Reports and blocks you submit.
  • Payment metadata for self-sold ticket purchases, processed by Stripe, Inc. We store identifiers such as stripePaymentIntentId, stripeCheckoutSessionId, ticket amounts, and refund timestamps. Eventbrite cities process payment on Eventbrite. We do not store card numbers, CVV codes, or bank account numbers.
  • Device push tokens, if you enable notifications on a phone.

How we use it

  • To run the service: show events near you, issue tickets, and power chat.
  • To keep the community safe: moderation, report review, and enforcement.
  • To communicate with you about your account and events you joined.
  • To collect self-sold ticket payments, handle refunds, and keep accounting records.

We do not sell your personal data. We do not show your birthdate to other members — only your age. Your email is never shared with other members.

What others see

Other members see your public profile: name, age, gender, denomination, church, city, bio, faith statement, and photos. Event hosts additionally see your check-in status for their events. Messages are visible only to you and your connection.

Payments and Stripe

Stripe, Inc. is our payment processor for self-sold ticket checkout. When you buy a ticket in a self-sold city, Stripe handles the card details. We receive and store only the payment identifiers listed above — never the card number itself. Stripe processes that data under its own privacy policy at stripe.com/privacy. Eventbrite cities process payment under Eventbrite's privacy policy.

Where data lives

Data is stored on Amazon Web Services (Cognito, DynamoDB, S3) in the region shown in your app. Photos are stored privately and served through short-lived signed URLs. Payment processing runs on Stripe.

Your choices

  • Edit or remove profile fields and photos at any time in Settings.
  • Block members to stop all contact.
  • Delete your account in Settings → Account. Deletion is described in the next section.
  • Request a copy of the personal data we hold about you by emailing privacy@kingdomsingles.app. There is no in-app export button. We aim to respond within 30 days.

What happens when you delete your account

Deletion deactivates your login and hides your profile from other members immediately. There is no scheduled purge job that later wipes every leftover row.

Removed right away

  • Your ability to sign in (the Cognito account is disabled).
  • Profile fields other members can see: name, birthdate, gender, denomination, church, city, bio, faith statement, and photo references. Your profile page returns nothing.
  • Photos and other files under your private storage prefix are deleted from S3.
  • Push-notification device records.
  • Messages in your conversations, both sides of each connection, and the conversation record.
  • Free-text on host applications (motivation, experience, organization, proposed city). The application row itself is kept as an anonymized audit record.

Kept on purpose

  • A deactivated profile stub: your user id, email, and deletion timestamp. This lets us match tickets and keep the disabled login from being treated as a live member.
  • Ticket records (including stripePaymentIntentId when you paid in-app) for 7 years, for accounting, tax, refund, and fraud obligations.
  • Reports, blocks, and admin member notes for 2 years, for safety and abuse prevention.

After those named periods we may remove the retained rows. Removal is a manual operator process — we do not run an automated daily purge. You cannot undo deletion.

Contact

Privacy questions, data-access requests, and deletion follow-ups: privacy@kingdomsingles.app.