Last updated: August 19, 2026. The Moody Church · Chicago, Illinois.
This Privacy Policy explains how the Moody Church Connect mobile app handles your information. We've tried to write it in plain language. Where a term is unavoidable, we explain it the first time we use it.
This is the privacy policy for the Moody Church Connect app. It replaces, for the app, the website-only privacy policy previously published by The Moody Church.
1. Who We Are and What This Covers
Moody Church Connect is a mobile app for iPhone (iOS) and Android, built by The Moody Church in Chicago, Illinois, USA. The app helps members and attendees of The Moody Church stay connected with their groups, pray for one another, and engage with church life.
The Moody Church is the data controller — the organization responsible for the personal information described here. ("Personal information" means information that identifies you or could reasonably be linked to you.)
- Who controls your data: The Moody Church, Chicago, Illinois, USA
- How to contact us: info@moodychurch.org
- Governing law: Illinois, USA
This policy covers the Moody Church Connect app. The Moody Church's website has its own privacy policy; where that policy and this one disagree about the app, this policy governs the app.
We are based in the United States, and the information we collect is stored and processed in the United States (see Section 7).
Signing in is required to use the app, so the people who use the app are members and attendees of The Moody Church. The app is intended for adults (see Section 10).
2. Information We Collect
A note on sensitive information. Having an account in this app indicates that you are connected with The Moody Church, so your use of it reflects a religious affiliation. We disclose that to Apple and Google as sensitive information, because it is inherent to what the app is. We do not ask for, and the app has no field for, health information — though you are free to mention whatever you wish in a prayer request or a message, and anything you write there is treated as your content (Section 4).
(a) Account and identity information
When you sign in or register, we use information that comes from Ministry Platform (MP) — the church's management system, which holds a "Contact" record for every attendee (created when you register for an event). The identifiers we collect or use are:
- Your email address
- Your mobile phone number
- Your MP Contact ID (the church's internal record number for you)
- Your MP User GUID (a unique account identifier)
- Your display name (from MP)
- Your profile photo URL (from MP, when one is present)
To register a new account, we match you to your existing MP Contact record using your email or phone number plus your name. We do not use your date of birth to do this.
(b) Content you create
When you use the app, you may create content that we store in our database:
- Group chat messages and reactions
- Announcements (written by group leaders)
- Prayer requests and prayer responses (including "I prayed" activity)
- Personal sermon notes (private to you — only you can see them)
- Photos you attach to chat messages
(A separate photo-album feature exists in the app's code but is currently turned off.)
(c) Device and technical information
- A push notification token — a unique identifier for your device that lets us send you notifications. We treat this as personal information.
- A session token stored on your device in the operating system's secure storage (the iOS Keychain or Android Keystore) so you stay signed in. This stays on your device.
(d) Event registration information
When you register yourself or a member of your household for a church event through the app, the event may ask you to complete a registration form. What is collected depends on what that specific event's form asks — it can include information such as a date of birth, grade or age group, gender, allergies or medical notes, and emergency-contact details, along with the registration options you choose (for example, a session or a t-shirt size).
Because you can register the members of your household — including your children — for an event, this information may include a minor's information, provided by the parent or guardian who is registering them. (Signing in and using the app is still limited to adults; see Section 10.)
Event registration form answers are sent to and stored in Ministry Platform as part of the church's event records — the same place this information would go if you registered on the church's website. The form answers themselves are not stored in the app's own database. The app's database records only that a registration happened (who registered whom, for which event, and the options selected) so the app can show you your registrations.
(e) What we do NOT collect
- We do not collect or store any payment information. When you give, the app hands you off to OnlineGiving.org, which handles all payment details (see Section 5).
- We do not use any advertising or behavioral-analytics tracking tools (SDKs). The app does not track you for advertising.
3. How Sign-In Works and One-Time Codes
You can sign in to the app in a few ways:
- Passwordless sign-in with a one-time code: We send a 6-digit code to your email or mobile phone (your choice). You enter the code to sign in.
- "Sign in with my Moody Church account": Existing users can sign in using their Ministry Platform account.
About the one-time code (OTP): "OTP" means "one-time passcode" — a short code that works only once. We take care to protect it:
- The plain 6-digit code is sent to the delivery provider (email or SMS) and is never stored by us.
- On our servers, we keep only a scrambled, one-way fingerprint of the code (a "salted HMAC-SHA-256 hash" — a value that can be used to check your code but cannot be reversed back into the code).
- The code expires after 10 minutes, and we limit how many times it can be requested or tried.
About your session and church tokens: Your sign-in session token is stored on your device in secure storage. The keys that let our servers talk to Ministry Platform on your behalf (called access/refresh tokens) never reach your device — they stay on our servers only and are encrypted (scrambled so they can't be read if intercepted).
4. How We Use Your Information
We use your information to:
- Run the app — sign you in, show your groups, chat, announcements, prayer requests, sermon notes, and the calendar.
- Send push notifications — for example, when there's new activity in your group (see Section 5 for what prayer notifications contain).
- Keep the community safe — moderation tools, content reporting, and member blocking (see "Moderation and Safety" below).
We do not use your information for advertising, and we do not sell your information.
Moderation and Safety
To keep the app safe and respectful, the following tools are part of the app:
- Soft-delete: When content is removed, it simply disappears from member views with no placeholder shown. We keep an internal copy for leader and administrator review.
- Member reporting: Any member can report content; the group's leaders are notified.
- Member blocking: Any member can block another member, which hides the blocked person's messages, prayers, and responses across the app.
- Leader removal: Group leaders can remove members from their group.
- Escalation for concerning prayer content: Your group's leaders see every prayer request you share with that group — whether you share it with the whole group or with leaders only. If a leader sees something suggesting someone may be in danger or at risk of harm, the leader will raise it with the Church's Elders or pastoral staff, who respond as they judge appropriate.
5. How Information Is Shared and Who Can See It
We share your information only as described here. We do not sell it.
Within the app — who can see your content
- Group chat and announcements are visible to the members of the relevant group.
- Sermon notes are private to you.
- Prayer requests follow the visibility model below.
Prayer requests — please read carefully
Prayer is meant to be shared, so it's important you understand who can see what:
- A prayer request is group-scoped, and you may share one request with several of your groups at once.
- Each request has one of two visibility settings:
- Whole-group — all members of the linked group(s) can see it; or
- Leaders-only — only the leaders of the linked group(s) can see it.
- There is no anonymous option. Your name is always shown to anyone who is allowed to see your request.
- Church staff and administrators with database access can technically see all prayer content. This access is for operating and safeguarding the ministry.
- When someone taps "I prayed" on your request, you are notified — including the responder's name and an optional note they may add.
- New-prayer push notifications use a generic message (for example, "New prayer request in your group"). The text of your request is not put in the notification, so it does not appear on a lock screen.
Giving — handoff to OnlineGiving.org
When you use the Give tab, the app hands you off to OnlineGiving.org, the church's existing online-giving provider. All donations happen on OnlineGiving, not in the app.
- For a signed-in handoff, the app passes your MP User GUID and the church's Domain GUID as parameters in the link so you arrive already signed in on OnlineGiving.
- Once you're signed in there, OnlineGiving shows your saved payment methods and your giving history on OnlineGiving.
- If a signed-in handoff cannot be built, the app falls back to an anonymous giving link instead.
- Payment processing and storage are handled entirely by OnlineGiving and are governed by OnlineGiving's own privacy policy. The app does not see or store your payment details.
6. Service Providers (Sub-Processors)
We use the trusted service providers below to operate the app. Each may process some information on the church's behalf, limited to what's needed for its role. All of these providers are US-based.
| Provider | What it does |
|---|---|
| Supabase Cloud | Our database, sign-in (authentication), file storage, and server functions. Hosted in US East (Ohio), USA. |
| Expo | The Expo Push API (sends notifications), app builds, and over-the-air updates. USA. |
| Apple | Push delivery to iPhones (APNs) and the App Store. USA. |
| Push delivery to Android devices (Firebase Cloud Messaging) and Google Play. USA. | |
| Ministry Platform / Think Ministry | Identity and church records (your Contact and account information). USA. |
| Sanity | Content management. The app reads public, read-only published content from Sanity's content delivery network. No personal data flows from the app to Sanity. USA. |
| OnlineGiving.org | Donations, handled off-app (see Section 5). |
| Twilio | Optional — SMS delivery of one-time codes (the same Twilio account the church/MP uses). USA. |
| SendGrid | Optional — email delivery of one-time codes (reuses MP's SendGrid). USA. |
We do not use any third-party advertising or behavioral-analytics providers.
7. Where Your Data Lives and How We Protect It
Data location: Your information is stored and processed in the United States (our database is hosted in Supabase's US-East / Ohio region, and the other providers listed above are US-based).
Security measures we use:
- All traffic is encrypted in transit using HTTPS/TLS (the standard that protects data as it travels over the internet).
- Row-level security is enforced on every member-accessible table in our database, so people can only read the data they're entitled to.
- Secrets stay on our servers and are never placed in the app on your device.
- Ministry Platform tokens are encrypted at rest (scrambled while stored).
- Push tokens are treated as personal data and are not written into routine logs.
No system can be guaranteed perfectly secure, but we work to protect your information using the practices above.
8. How Long We Keep Your Data (Retention)
We keep information only as long as we need it to run the app and meet our recordkeeping and safety needs.
What you put in the app — your messages, prayer requests, responses, notes and photos — is kept while your account is active, and until you or we remove it. We do not delete it on a timer. When you remove something, or a group leader removes it, it stops being visible to other members and a copy is retained privately for a limited time so leaders and staff can review concerns and act consistently.
Two things do expire automatically:
- One-time sign-in codes are hashed, never stored in readable form, and expire after 10 minutes.
- Authentication tokens are removed when you sign out.
If the Church later adopts fixed time limits for chat or prayer content, we will state them here before they take effect.
9. Your Choices and Rights
You can:
- Access the information we hold about you.
- Correct information that is inaccurate.
- Delete your account from within the app (Settings → Delete Account).
What deleting your account does:
- Removes your login (authentication) record, your profile, your push notification tokens, and the server-side Ministry Platform token record tied to your account.
What deleting your account does NOT do:
- It does not delete your Ministry Platform church records — your membership, giving history, and attendance remain in Ministry Platform as church records.
- It does not erase what you posted — the content you authored (chat messages, prayer requests, responses, and photos) is kept, but disconnected from your name. Your authorship is reassigned to "Deleted User" so that conversations and prayer threads other members took part in stay readable and don't develop gaps. Nothing you posted remains attributed to you.
To ask a question or make a request about your information, contact info@moodychurch.org.
10. Children
The app is for adults. Accounts are for adults (18 or older). The app is not directed at children, we do not knowingly create accounts for them, and we do not knowingly collect personal information from them. Groups intended for children and youth are kept off the app.
**Registering a minor for an event is different from a minor using the app.** An adult may register their own children (household members) for a church event through the app, and doing so may submit that minor's registration information (see Section 2(d)). This is done by the parent or guardian, whose act of registering is the consent for that submission; a minor does not have their own app account and has no access to the app.
Age rating. Accounts are for adults. Each app store sets its own age rating from its own questionnaire, which we answer honestly — including that the app contains user-generated content and an in-app browser that can reach the open web. The rating shown on the App Store and the one shown on Google Play may differ, because the two questionnaires ask different questions.
11. Changes to This Policy
We may update this policy from time to time. When we make a material change, we will update the "Last updated" date at the top, post a notice in the app, and publish the updated policy on our website.
12. Contact Us
If you have questions about this policy or your information, contact us:
The Moody Church Chicago, Illinois, USA Email: info@moodychurch.org
This policy is published at app.moody.church/privacy and governs the Moody Church Connect app.