Privacy Policy
Effective date: September 27, 2026
1. Who we are
Ministry Assistant help publishers to plan and write their field ministry, keep notes, and — where a congregation using it — prepare meeting programs, meetings for field service, the schedule for public witnessing, substitutes and field service reports. Data controller for the account and the cloud features: Codivine Sp. z o.o., e-mail: fluttercodivine@gmail.com. Most of the things you put inside never leave your phone. This policy explain exactly wetin leave it, when, to who, and for how long.
2. Wetin stay on the device and wetin go to the cloud
Everything you put inside — hours, notes, territories, people you study with, goals — first na write inside one database on your device. It leave the device only when you turn something on: • an account (e-mail, name, phone number if you want — we need it to sign in, so friends can find you, and for subscription), • synchronization between your devices (you choose the provider: your Ministry Assistant account, Google Drive or iCloud), • a backup copy, • to share something with one friend or send one link (for example an invitation to field service), • to join a congregation. The "Account (encrypted)" synchronization option encrypt your records on the device with a key da come from your encryption password. We can't read them. The plain "Firebase" option not do this — the app say so clearly.
3. Congregation
A congregation is encrypted end to end. Names, meeting programs, assignments, the schedule of meetings for field service with places and online meeting details, details of meeting broadcast, the schedule for public witnessing, lists of people da approve for assignments, requests for substitutes, attendance and reports are encrypted on the phone with one congregation key da only the members have. Our server keep ciphertext and can't read any of it. The server can see technical metadata da we need so permissions and notifications can work: which account belong to which congregation and its permissions; when somebody submit a report and to which field service group; who sign up for one cart shift; which accounts conduct one meeting for field service; which accounts get one request for substitute, who accept it and which date it is about; the account of the speaker for one talk outside; the settings of the congregation website. The talk number and title da one speaker from another congregation choose on the invitation page not encrypted — they come from the public list of outlines. Members of the same congregation become friends inside the app automatically (they see wetin friends see — see section 4). You can turn this off inside the privacy settings; the friends you add by yourself will stay. Field service reports go only when you agree clearly, and you can take back the agreement. They go to your group overseer and his assistant, and one summary of the group go to the secretary. We never send a report automatically without this agreement. When we remove one member, we change the congregation key so da the person can't read the new content again. The administrators of the congregation and the people da get the right permissions put the congregation content. For questions about information inside one congregation (for example one entry on the list of people), first talk to the elders of your congregation — we not get access to that content.
4. Sharing with other people
Friends: one friend can see your name and profile photo. Your surname, phone number, e-mail, congregation, role and dates, each one get its own switch inside your profile. Territories and interested persons da you send to one friend go inside the inbox of that friend as copy. You and the person da receive it can delete it, and it will disappear by itself after 30 days if nobody do anything with it. Anybody da get the link can open links (a congregation assignment, the program for one week, an invitation for speaker, a task, an invitation to field service, a request for substitute) — that is why they are there. The key to decrypt is inside the part of the address da browsers never send to a server; links expire and you can cancel them any time. Our server keep the answer to one link ("I accept" / "I can't"). The name of the person da join one open invitation to field service or accept one request for substitute is encrypted with the key of the link — only the person da invite or ask can read it.
5. The congregation website
One congregation can put the schedule for public witnessing, one form for requests for publications, the information board, one form for reports and the schedule of meetings for field service inside a browser — for people without the app or only for members da sign in. The content of this kind of page is encrypted with the key inside the link, so the server can't read it. Anybody da get the link can see the page — that is why names (for example of the people on shifts or of conductors) show on it only if the congregation turn them on. One administrator of the congregation can turn off single pages, ask people to sign in, or turn off access from the browser completely inside the settings. When somebody without account sign up for one shift or ask for publications, the name, phone number and notes da the person put are encrypted inside the browser with the congregation key — only the coordinator can read them inside the app. The browser remember on the phone itself which shifts the person send request for; this information not come to us. Analytics on this website run only with your agreement and never get the content of requests or the keys from links.
6. People da not using the app
The app let you write down the people you visit, their addresses and notes, and members of the congregation da not get account. These people are not our users and they not agree to anything with us — you (and, inside one congregation, its administrators) decide wetin to write down and you are responsible for it. For this reason: this kind of records stay on your device unless you turn on synchronization or sharing; inside one congregation they are encrypted end to end; their names show on the congregation website only if the congregation turn names on; and the settings let you turn off whole sections (for example addresses where nobody was home, or interested persons) inside countries where this kind of records are not allowed. If one of these people ask to take his name out, delete the record inside the app — it will disappear from your device, from your copies inside the cloud and, after the time we keep it below, from our servers. You can also write to us and we will help.
7. Permissions
Contacts (not must) — to show which of your contacts already using the app. Your address book never leave the phone: only fingerprints (hashes) of e-mail addresses and phone numbers da nobody can turn back are sent, and we not keep anything from them. Location (not must) — to show where you are on the territory map and to suggest the nearest territory. We not get the place where you are. You set the pin for the place of one meeting or the place of the cart by hand on the map, not from where you are. Notifications (not must) — reminders and congregation notifications. Congregation notifications never carry the content of one assignment or any names. Their title and short description are also kept on the list of notifications inside your account, so you not lose any of them. Photos and files (not must) — photos for territory cards, the photo of one person, attachments on the information board, backups.
8. Service providers
Google / Firebase (Ireland, USA) — sign-in, database, file storage, server functions, push notifications, crash reports (Firebase Crashlytics), statistics about use inside the app (Firebase Analytics, only with your agreement — see section 9) and, on this website, Google Analytics, da not start until you agree. RevenueCat (USA) — to handle subscriptions. It get the identifier of your account and, so it can help you, the name, e-mail address and phone number from your account. Apple and Google — to process payment for subscriptions. We never see the details of your card. OpenStreetMap — map tiles. When you open one map, your IP address and the part of the map da you can see go to their servers. Google Maps (or another maps app) — only when you tap "Directions" or "Map" the address or the point open inside that app. Zoom and other online meeting services — the link open inside their app or website; we not pass any information to them. E-mail delivery of service messages — technical information, no records from the app.
9. Usage statistics and crash reports inside the app
Statistics about use (Firebase Analytics) are off until you agree. The app ask one time; you can change your mind any time inside Settings → Privacy → Personal data → Usage statistics. When you take back your agreement, we stop to collect right away and we reset the statistics identifier on the device. With your agreement the app (on phones, tablets and inside the browser) send events without your name about which features people use — for example "one entry add", "one backup make", "sign up for one shift" — with general details like where one entry come from, yes/no flags, rounded numbers of people and how long one field service entry is. Google also record the version of the app, the model of the device and the operating system, the language and the country by estimate (they work it out from the IP address, da Google not keep). The events are tied to one random identifier of the installation of the app and, when you sign in, to the identifier of your account da not show your name, so your phone and tablet count as one user. We also add three segments: your role inside the ministry (for example publisher or regular pioneer), if you get PRO, and your level of access inside one congregation (none, member, with permissions, administrator, owner). We never send the content of wetin you put inside: no names, addresses, notes, reports, names of congregations or any other congregation information, e-mail addresses or phone numbers. We use the statistics only to understand which features help and which one need to be better. Features for advertising and Google signals are turn off: we not collect any advertising identifier and we not use the information for advertising or to make ads for you. We keep the statistics for 14 months and after that we delete them automatically. Legal basis: your agreement (art. 6(1)(a) and art. 9(2)(a) GDPR). The processor is Google Ireland Limited; information can go to Google LLC inside the USA under the EU–US Data Privacy Framework and standard contractual clauses. Test versions of the app never send statistics. Crash reports (Firebase Crashlytics, on phones and tablets only) go no matter wetin you set for statistics, because without them we can't fix the errors da break the app. One report get the error and the place inside the code where it happen, the version of the app, the model of the device, the operating system and one random identifier of the installation. It not tied to your account and not get your records. Legal basis: our legitimate interest to have app da work and is safe (art. 6(1)(f) GDPR); you can say no by writing to us. We keep crash reports for 90 days. The processor is Google Ireland Limited, like above.
10. How long we keep the information
• Records da synchronize to your account: as long as the account is active. After one subscription finish we keep them for one year, with warning 30 days before we delete. • Deletion markers da synchronization use: 180 days. • Field service reports (also the ones sent through the website) and the summaries of the groups for the secretary: 2 years from the end of the month da they cover — when you send one report you agree to this. After that we delete them automatically. Inside the app the person da write the report can delete it sooner, but not inside 60 days after he send it (so nobody can take back one report from the overseer the next day). • Requests from the congregation website (one cart shift, publications) da the coordinator not accept: 30 days. • Requests for substitute: up to 2 days after the date of the assignment. • The list of notifications: 60 days. • Announcements on the information board of the congregation: until the date da the congregation set for it to expire, or until somebody delete it. • Links for invitation and sharing: up to 120 days, most of them much shorter; invitations for tasks and copies da you send to friends: 30 days. • When you delete the account: we delete everything we describe above — the document of your account with all records and keys, both sides of every friendship, membership inside the congregation, reports, invitations, notifications, files. One congregation da you own will go to another administrator, or we delete it if nobody there. • One congregation without congregation plan: 12 months after the plan finish (6 months if it only get the free time); we tell the owner and the administrators 30 days before we delete it together with its files. • Cart shifts and sign-ups of the congregation: 13 months; absences: until the end date da somebody put with them; requests for publications da somebody already give out: 90 days.
11. Security
Connections are encrypted when the information is moving. Congregation content, encrypted synchronization and backups are also encrypted on the device, with a key da come from your encryption password. This mean we can't get that password back for you. Keep the recovery code da the app show when you set the password — without the password or the code, nobody can read encrypted information, including us.
12. Your rights
You get the right to see your information, to correct it, to delete it, to limit or say no to how we use it, and to get one copy. You can do most of this by yourself inside the app: edit or delete records, turn off the things you not want to share, or delete the account (Settings → account), da also remove the information we list above from our servers. You can also write to fluttercodivine@gmail.com. If you believe we not handle your information right, you can make complaint to the President of the Personal Data Protection Office (Urząd Ochrony Danych Osobowych) inside Poland.
13. Changes and contact
We can update this policy. We will announce big changes inside the update notes of the app and on this page, with new effective date. Data controller: Codivine Sp. z o.o. E-mail: fluttercodivine@gmail.com