Ministry Assistant 2

Privacy Policy

Effective date: September 27, 2026

1. Who we are

Ministry Assistant helps publishers plan and record their field ministry, keep notes, and — where a congregation uses it — prepare meeting programs, meetings for field service, the public witnessing schedule, substitutes and field service reports. Data controller for the account and cloud features: Codivine Sp. z o.o., e-mail: fluttercodivine@gmail.com. Most of what you enter never leaves your phone. This policy explains exactly what does leave it, when, to whom, and for how long.

2. What stays on the device and what goes to the cloud

Everything you enter — hours, notes, territories, people you study with, goals — is first written to a database on your device. It leaves the device only when you turn something on: • an account (e-mail, name, optionally a phone number — needed to sign in, to be found by friends, and for a subscription), • synchronisation between your devices (you choose the provider: your Ministry Assistant account, Google Drive or iCloud), • a backup copy, • sharing something with a friend or sending a link (for example an invitation to service), • joining a congregation. The "Account (encrypted)" synchronisation option encrypts your records on the device with a key derived from your encryption password. We cannot read them. The plain "Firebase" option does not — it is labelled as such in the app.

3. Congregation

A congregation is end-to-end encrypted. Names, meeting programs, assignments, the schedule of meetings for field service with places and online meeting details, meeting broadcast details, the public witnessing schedule, lists of those approved for assignments, requests for substitutes, attendance and reports are encrypted on the phone with a congregation key that only members hold. Our server stores ciphertext and cannot read any of it. The server does see technical metadata without which permissions and notifications would not work: which account belongs to which congregation and its permissions; when a report was submitted and to which service group; who signed up for a cart shift; which accounts conduct a meeting for field service; which accounts received a request for a substitute, who accepted it and which date it concerns; the speaker's account for an outgoing talk; the congregation's website settings. The talk number and title that a speaker from another congregation picks on the invitation page are not encrypted — they come from the public list of outlines. Members of the same congregation automatically become friends in the app (they see what friends see — see section 4). You can turn this off in the privacy settings; friends you added yourself stay. Field service reports are sent only when you explicitly agree, and the agreement can be withdrawn. They go to your group overseer and his assistant, and a group summary goes to the secretary. A report is never sent automatically without that consent. When a member is removed, the congregation key is replaced so that past member can no longer read new content. Congregation content is entered by its administrators and by those with the relevant permissions. For questions about data in a congregation (for example an entry on the list of people), first contact the elders of your congregation — we have no access to that content.

4. Sharing with other people

Friends: a friend sees your name and profile photo. Your surname, phone number, e-mail, congregation, role and dates are each governed by a separate switch in your profile. Territories and interested persons sent to a friend land in that friend's inbox as a copy. Both you and the recipient can delete it, and it disappears by itself after 30 days if nobody acts on it. Links (a congregation assignment, a week's program, a speaker invitation, a task, an invitation to service, a substitute request) can be opened by anyone who has the link — that is what they are for. The decryption key is in the part of the address that browsers never send to a server; links expire and can be revoked at any time. The answer to a link ("I accept" / "I can't") is stored by our server. The name of a person who joins an open service invitation or accepts a substitute request is encrypted with the link key — only the inviter or requester can read it.

5. The congregation website

A congregation can make the public witnessing schedule, a literature request form, the information board, a report form and the schedule of meetings for field service available in a browser — to people without the app or only to signed-in members. The content of such a page is encrypted with the key in the link, so the server cannot read it. Anyone with the link can see the page — that is why names (for example of those on shifts or of conductors) appear on it only if the congregation turns them on. A congregation administrator can turn off individual pages, require signing in, or turn off browser access altogether in the settings. When someone without an account signs up for a shift or asks for literature, the name, phone number and notes they enter are encrypted in the browser with the congregation key — only the coordinator can read them in the app. The browser remembers locally which shifts a request was sent for; that information does not reach us. Analytics on this website run only with your consent and never receive the contents of requests or keys from links.

6. People who do not use the app

The app lets you write down people you visit, their addresses and notes, and congregation members who have no account. Those people are not our users and did not agree to anything with us — you (and, in a congregation, its administrators) decide what to write down and are responsible for it. For that reason: such records stay on your device unless you turn on synchronisation or sharing; in a congregation they are end-to-end encrypted; their names appear on the congregation website only if the congregation turns names on; and the settings let you switch off entire sections (for example addresses where nobody was home, or interested persons) in countries where such records are not permitted. If one of those people asks to be removed, delete the record in the app — it disappears from your device, from your copies in the cloud and, after the retention period below, from our servers. You can also write to us and we will help.

7. Permissions

Contacts (optional) — to show which of your contacts already use the app. Your address book never leaves the phone: only irreversible fingerprints (hashes) of e-mail addresses and phone numbers are sent, and nothing is stored from them. Location (optional) — to show your position on the territory map and to suggest the nearest territory. The position is not sent to us. The pin for a meeting place or a cart location is set by hand on the map, not from your position. Notifications (optional) — reminders and congregation notifications. Congregation notifications never carry the content of an assignment or any names. Their title and short description are also kept on the notification list in your account, so none of them gets lost. Photos and files (optional) — territory card photos, a person's photo, attachments on the information board, backups.

8. Service providers

Google / Firebase (Ireland, USA) — sign-in, database, file storage, server functions, push notifications, crash reports (Firebase Crashlytics), usage statistics in the app (Firebase Analytics, only with your consent — see section 9) and, on this website, Google Analytics, which does not start until you agree to it. RevenueCat (USA) — subscription handling. It receives your account identifier and, to support you, the name, e-mail address and phone number from your account. Apple and Google — payment processing for subscriptions. We never see your card details. OpenStreetMap — map tiles. Opening a map sends your IP address and the visible map area to their servers. Google Maps (or another maps app) — only when you tap "Directions" or "Map" does the address or point open in that app. Zoom and other online meeting services — the link opens in their app or website; we pass no data to them. E-mail delivery of service messages — technical data, no records from the app.

9. Usage statistics and crash reports in the app

Usage statistics (Firebase Analytics) are off until you agree to them. The app asks once; you can change your mind at any time in Settings → Privacy → Personal data → Usage statistics. Withdrawing consent stops collection immediately and resets the statistics identifier on the device. With your consent the app (on phones, tablets and in the browser) sends pseudonymous events about which features are used — for example "an entry was added", "a backup was created", "signed up for a shift" — with general details such as the source of an entry, yes/no flags, rounded numbers of people and the length of a service entry. Google also records the app version, the device model and operating system, the language and the approximate country (worked out from the IP address, which Google does not store). Events are linked to a random identifier of the app installation and, when you are signed in, to the pseudonymous identifier of your account, so that your phone and tablet count as one user. Three segments are added as well: your role in the ministry (for example publisher or regular pioneer), whether you have PRO, and your level of access in a congregation (none, member, with permissions, administrator, owner). We never send the content of what you enter: no names, addresses, notes, reports, congregation names or any other congregation data, e-mail addresses or phone numbers. We use the statistics only to understand which features help and which need improving. Advertising features and Google signals are switched off: no advertising identifier is collected and the data is not used for advertising or ad personalisation. Statistics are kept for 14 months and then deleted automatically. Legal basis: your consent (art. 6(1)(a) and art. 9(2)(a) GDPR). The processor is Google Ireland Limited; data may be transferred to Google LLC in the USA under the EU–US Data Privacy Framework and standard contractual clauses. Test versions of the app never send statistics. Crash reports (Firebase Crashlytics, on phones and tablets only) are sent regardless of the statistics setting, because without them we could not fix errors that break the app. A report contains the error and the place in the code where it happened, the app version, the device model, the operating system and a random installation identifier. It is not linked to your account and does not include your records. Legal basis: our legitimate interest in an app that works and is secure (art. 6(1)(f) GDPR); you can object by writing to us. Crash reports are kept for 90 days. The processor is Google Ireland Limited, as above.

10. How long data is kept

• Records synchronised to your account: as long as the account is active. After a subscription ends they are kept for a year, with a warning 30 days before deletion. • Deletion markers used by synchronisation: 180 days. • Field service reports (also those sent through the website) and the group summaries for the secretary: 2 years from the end of the month they cover — by sending a report you agree to this. After that they are deleted automatically. In the app the author can delete their report sooner, but not within 60 days of sending (so that a report cannot be withdrawn from the overseer the next day). • Requests from the congregation website (a cart shift, literature) that the coordinator did not accept: 30 days. • Requests for a substitute: up to 2 days after the date of the assignment. • The notification list: 60 days. • Announcements on the congregation's information board: until the expiry date set by the congregation, or until deleted. • Invitation and sharing links: up to 120 days, most of them much shorter; task invitations and copies sent to friends: 30 days. • Account deletion: everything described above is deleted — your account document with all records and keys, both sides of every friendship, congregation membership, reports, invitations, notifications, files. A congregation you owned passes to another administrator, or is deleted if there is none. • A congregation without a congregation plan: 12 months after the plan ended (6 months if it only ever had the free period); the owner and administrators are notified 30 days before it is deleted together with its files. • Congregation cart shifts and sign-ups: 13 months; absences: until the end date entered with them; handed-out literature requests: 90 days.

11. Security

Connections are encrypted in transit. Congregation content, encrypted synchronisation and backups are additionally encrypted on the device, with a key derived from your encryption password. This means we cannot recover that password for you. Keep the recovery code shown when you set the password — without the password or the code, encrypted data cannot be read by anyone, including us.

12. Your rights

You have the right to access your data, to correct it, to delete it, to restrict or object to processing, and to receive a copy. Most of this you can do yourself in the app: edit or delete records, switch off what you do not want to share, or delete the account (Settings → account), which also removes the data listed above from our servers. You may also write to fluttercodivine@gmail.com. If you believe we handle your data incorrectly, you can lodge a complaint with the President of the Personal Data Protection Office (Urząd Ochrony Danych Osobowych) in Poland.

13. Changes and contact

This policy may be updated. Significant changes will be announced in the app's update notes and on this page, with a new effective date. Data controller: Codivine Sp. z o.o. E-mail: fluttercodivine@gmail.com