Ministry Assistant 2

Privacy Policy

Effective date: September 27, 2026

1. Who we be

Ministry Assistant de help publishers plan and record their preaching work, keep notes, and — where congregation de use am — prepare meeting programs, field service meetings, the schedule for public witnessing, substitutes and field service reports. Data controller for the account and cloud features: Codivine Sp. z o.o., e-mail: fluttercodivine@gmail.com. Most of wetin you enter no de leave your phone. This policy explain exactly wetin de leave am, when, to who, and for how long.

2. Wetin de stay for the device and wetin de go cloud

Everything wey you enter — hours, notes, territories, people wey you de study with, goals — dem de first write am for database for your device. E de leave the device only when you turn something on: • an account (e-mail, name, and if you like phone number — dem need am to sign in, so friends fit find you, and for subscription), • synchronisation between your devices (you choose the provider: your Ministry Assistant account, Google Drive or iCloud), • backup copy, • to share something with friend or send link (for example invitation to service), • to join congregation. The "Account (encrypted)" synchronisation option de encrypt your records for the device with key wey come from your encryption password. We no fit read them. The plain "Firebase" option no de do am — dem label am so for the app.

3. Congregation

Dem encrypt congregation from end to end. Names, meeting programs, assignments, the schedule of field service meetings with places and online meeting details, meeting broadcast details, the schedule for public witnessing, lists of people wey dem approve for assignments, requests for substitutes, attendance and reports dey encrypted for phone with congregation key wey only members get. Our server de keep ciphertext and e no fit read any of am. The server de see technical metadata wey permissions and notifications no go fit work without am: which account belong to which congregation and its permissions; when dem submit report and to which field service group; who sign up for cart shift; which accounts de conduct field service meeting; which accounts receive request for substitute, who accept am and which date e concern; the speaker account for outgoing talk; the settings of the congregation website. The talk number and title wey speaker from another congregation pick for the invitation page no dey encrypted — dem come from the public list of outlines. Members of the same congregation de automatically become friends for the app (dem go see wetin friends de see — see section 4). You fit turn this off for privacy settings; friends wey you add by yourself go stay. Dem de send field service reports only when you clearly agree, and you fit take back the agreement. E de go to your group overseer and im assistant, and group summary de go to the secretary. Dem no de ever send report automatically without that consent. When dem remove member, dem de change the congregation key so that the person wey don leave no go fit read new content again. Administrators of the congregation and people wey get the right permissions de enter the congregation content. If you get questions about data for congregation (for example entry for the list of people), first contact the elders of your congregation — we no get access to that content.

4. To share with other people

Friends: friend de see your name and profile photo. Your surname, phone number, e-mail, congregation, role and dates, each one get separate switch for your profile. Territories and interested persons wey you send to friend de land for that friend inbox as copy. You and the person wey receive am fit delete am, and e de disappear by itself after 30 days if nobody do anything with am. Anybody wey get the link fit open links (congregation assignment, program for one week, invitation for speaker, task, invitation to service, request for substitute) — na for that reason dem de exist. The decryption key dey the part of the address wey browsers no de ever send to server; links de expire and dem fit cancel them any time. Our server de keep the answer to link ("I accept" / "I can't"). Dem encrypt the name of person wey join open service invitation or accept request for substitute with the link key — only the person wey invite or make the request fit read am.

5. The congregation website

Congregation fit make the schedule for public witnessing, form to request publications, the information board, report form and the schedule of field service meetings available for browser — for people wey no get the app or only for members wey don sign in. Dem encrypt the content of that kind page with the key wey dey the link, so the server no fit read am. Anybody wey get the link fit see the page — na why names (for example of people wey dey shifts or of conductors) de show for there only if the congregation turn them on. Administrator of the congregation fit turn off particular pages, require sign in, or turn off browser access completely for settings. When person wey no get account sign up for shift or ask for publications, dem de encrypt the name, phone number and notes wey the person enter for the browser with the congregation key — only the coordinator fit read them for the app. The browser de remember for local which shifts dem send request for; that information no de reach us. Analytics for this website de run only if you agree and e no de ever receive the content of requests or keys from links.

6. People wey no de use the app

The app de let you write down people wey you de visit, their addresses and notes, and congregation members wey no get account. Those people no be our users and dem no agree to anything with us — you (and, for congregation, its administrators) de decide wetin to write down and you de responsible for am. For that reason: dem records de stay for your device unless you turn on synchronisation or sharing; for congregation dem dey encrypted from end to end; their names de show for the congregation website only if the congregation turn names on; and the settings de let you switch off whole sections (for example addresses wey nobody dey house, or interested persons) for countries wey no allow that kind records. If one of those people ask make you remove am, delete the record for the app — e go disappear from your device, from your copies for cloud and, after the retention period wey dey below, from our servers. You fit write us too and we go help.

7. Permissions

Contacts (no be must) — to show which of your contacts de use the app already. Your address book no de ever leave the phone: only fingerprints (hashes) of e-mail addresses and phone numbers wey no fit reverse de go, and we no de keep anything from them. Location (no be must) — to show your position for the territory map and to suggest the nearest territory. We no de receive the position. You de set the pin for meeting place or cart location by hand for the map, no be from your position. Notifications (no be must) — reminders and congregation notifications. Congregation notifications no de ever carry the content of assignment or any names. Dem de keep their title and short description for the notification list for your account too, so none of them no go lost. Photos and files (no be must) — photos for territory card, photo of person, attachments for the information board, backups.

8. Service providers

Google / Firebase (Ireland, USA) — sign-in, database, file storage, server functions, push notifications, crash reports (Firebase Crashlytics), usage statistics for the app (Firebase Analytics, only if you agree — see section 9) and, for this website, Google Analytics, wey no de start until you agree. RevenueCat (USA) — to handle subscription. E de receive your account identifier and, to support you, the name, e-mail address and phone number from your account. Apple and Google — to process payment for subscriptions. We no de ever see your card details. OpenStreetMap — map tiles. When you open map, e de send your IP address and the map area wey dey show to their servers. Google Maps (or another maps app) — only when you tap "Directions" or "Map" na then the address or point de open for that app. Zoom and other online meeting services — the link de open for their app or website; we no de pass any data to them. E-mail delivery of service messages — technical data, no records from the app.

9. Usage statistics and crash reports for the app

Usage statistics (Firebase Analytics) dey off until you agree. The app de ask one time; you fit change your mind any time for Settings → Privacy → Personal data → Usage statistics. When you take back consent, collection go stop sharp-sharp and the statistics identifier for the device go reset. With your consent the app (for phones, tablets and for browser) de send pseudonymous events about which features dem de use — for example "dem add entry", "dem create backup", "dem sign up for shift" — with general details like the source of entry, yes/no flags, rounded numbers of people and how long service entry be. Google de record the app version, the device model and operating system, the language and the country wey e fit be (dem work am out from the IP address, wey Google no de keep). Dem de link events to random identifier of the app installation and, when you don sign in, to the pseudonymous identifier of your account, so that your phone and tablet go count as one user. Dem de add three segments too: your role for preaching work (for example publisher or regular pioneer), if you get PRO, and your level of access for congregation (none, member, with permissions, administrator, owner). We no de ever send the content of wetin you enter: no names, addresses, notes, reports, names of congregation or any other congregation data, e-mail addresses or phone numbers. We de use the statistics only to understand which features de help and which one need to improve. Advertising features and Google signals dey switched off: dem no de collect advertising identifier and dem no de use the data for advertising or ad personalisation. Dem de keep statistics for 14 months and then dem de delete them automatically. Legal basis: your consent (art. 6(1)(a) and art. 9(2)(a) GDPR). The processor na Google Ireland Limited; dem fit transfer data to Google LLC for USA under the EU–US Data Privacy Framework and standard contractual clauses. Test versions of the app no de ever send statistics. Dem de send crash reports (Firebase Crashlytics, for phones and tablets only) no matter the statistics setting, because without them we no go fit fix errors wey de break the app. Report get the error and the place for the code where e happen, the app version, the device model, the operating system and random installation identifier. Dem no link am to your account and e no include your records. Legal basis: our legitimate interest for app wey de work and dey secure (art. 6(1)(f) GDPR); you fit object by writing to us. Dem de keep crash reports for 90 days. The processor na Google Ireland Limited, as e dey above.

10. How long dem de keep data

• Records wey dem synchronise to your account: as long as the account active. After subscription end dem de keep them for one year, with warning 30 days before dem delete. • Deletion markers wey synchronisation de use: 180 days. • Field service reports (even the ones wey dem send through the website) and the group summaries for the secretary: 2 years from the end of the month wey dem cover — when you send report you agree to this. After that dem de delete them automatically. For the app the person wey write the report fit delete am early, but no be inside 60 days after e send am (so that nobody no go fit take report back from the overseer the next day). • Requests from the congregation website (cart shift, publications) wey the coordinator no accept: 30 days. • Requests for substitute: up to 2 days after the date of the assignment. • The notification list: 60 days. • Announcements for the information board of the congregation: until the expiry date wey the congregation set, or until dem delete am. • Invitation and sharing links: up to 120 days, most of them de shorter pass that; task invitations and copies wey dem send to friends: 30 days. • Account deletion: dem de delete everything wey dey described above — your account document with all records and keys, the two sides of every friendship, congregation membership, reports, invitations, notifications, files. Congregation wey you own go pass to another administrator, or dem go delete am if nobody dey. • Congregation wey no get congregation plan: 12 months after the plan end (6 months if e only ever get the free period); dem de notify the owner and administrators 30 days before dem delete am together with its files. • Congregation cart shifts and sign-ups: 13 months; absences: until the end date wey dem enter with them; requests for publications wey dem don give out: 90 days.

11. Security

Dem de encrypt connections as data de move. Congregation content, encrypted synchronisation and backups dey encrypted again for the device, with key wey come from your encryption password. This mean say we no fit recover that password for you. Keep the recovery code wey dem show you when you set the password — without the password or the code, nobody fit read encrypted data, including us.

12. Your rights

You get right to access your data, to correct am, to delete am, to restrict or object to processing, and to receive copy. Most of this one you fit do by yourself for the app: edit or delete records, switch off wetin you no want share, or delete the account (Settings → account), wey de remove the data wey dey listed above from our servers too. You fit write fluttercodivine@gmail.com too. If you believe say we de handle your data wrong, you fit lodge complaint with the President of the Personal Data Protection Office (Urząd Ochrony Danych Osobowych) for Poland.

13. Changes and contact

Dem fit update this policy. Dem go announce important changes for the update notes of the app and for this page, with new effective date. Data controller: Codivine Sp. z o.o. E-mail: fluttercodivine@gmail.com