Legal

Privacy Notice

Version and last updated: July 22, 2026

This Notice explains how SDA Church App processes personal data. The App provides private Church workspaces for membership, attendance, meetings, voting, communications, treasury, and related administration. Elie Zedeck, based in Madagascar, operates the App and can be contacted at (enable JavaScript to see the email address).

A Privacy Notice describes processing; it is not a request for blanket consent. Essential crash and error diagnostics are always enabled while you use the App. Optional usage analytics has its own choice in the App and can be declined without losing access.

1. Who controls Church records

Elie Zedeck determines how account, security, service-operation, essential diagnostic, and optional analytics data is handled for the App. For records entered and managed inside a Church workspace, the relevant Church organization or authorized Church leadership generally decides why the records are kept and who may use them. The App provides the technical service.

Questions about a particular membership, attendance, voting, treasury, or other Church record should normally go first to the Church that manages that workspace. You may also contact the App operator using the address above.

2. Data processed

2.1 Account and profile

  • Firebase Authentication UID and Google or Apple provider identifier
  • Email address, display name, profile photo, and language preference when provided
  • Terms and Privacy Notice versions accepted, acceptance time, and optional usage Analytics choice
  • Security, session, notification-token, and device-related information needed to operate the App

2.2 Church-book and operational records

  • Names, nicknames, gender, phone numbers, photos, Church membership, status, roles, transfers, and exit information
  • Attendance, meetings, propositions, remarks, polls, and voting records linked to member identifiers
  • Donations, receipts, payment modes, accounts, deposits, balances, expenses, and transaction history
  • Administrative actions and audit/history records showing what happened and, when required, who acted

Church membership and similar records can reveal religious belief and may be legally protected as sensitive or special-category data. Authorized Church users must have a valid basis and authority to enter and manage this information.

2.3 Essential diagnostics and optional analytics

In installed release builds, the App keeps essential crash and unexpected-error reporting enabled and sends a diagnostic report when one of those failures is recorded. Firebase Crashlytics receives these reports so security, startup, reliability, and account-specific failures can be investigated. Firebase automatically supplies crash traces, App and device details, and installation or session identifiers used to process and group reports. The App also attaches the Firebase Authentication UID when signed in. This essential reporting is a condition of using the App and cannot be disabled with the optional Analytics switch.

When optional Analytics is off, App-added Crashlytics context is limited to the Firebase Authentication UID and non-identifying technical facts such as build mode, failure category, status or error code, security provider, timing, counts, and a bounded journey stage. Free-form messages and other App-domain identifiers are excluded. If you opt in, the App may send bounded feature-use events to Firebase Analytics and may attach detailed context to Crashlytics, including operation or request references; Church, member, person, media, receipt, transaction, or upload identifiers; rehearsal device names and local-network addresses; bounded error messages; and the App state relevant to the failure. Passwords and authentication tokens are not intended diagnostic fields.

You can withdraw the optional choice under Privacy choices. Withdrawal stops future Analytics collection and new detailed App-added Crashlytics context, but it cannot rewrite reports already uploaded or clear every log already held in the current Crashlytics session. Essential diagnostics continue in the restricted form described above. You may stop using the App and request account deletion, but reports already uploaded remain subject to Firebase retention and deletion processes.

3. Why data is used

  • Authenticate accounts and provide private, tenant-separated Church workspaces
  • Maintain Church books and perform membership, attendance, voting, financial, communication, and administrative functions
  • Preserve transaction integrity, security, permissions, auditability, and historical continuity
  • Send requested service messages and push notifications
  • Comply with applicable law and respond to valid rights or security requests
  • Maintain security and reliability through essential crash and error diagnostics
  • Improve App journeys through optional usage Analytics when you opt in

Depending on the record and jurisdiction, processing may be necessary to provide the service, maintain its security and reliability, support legitimate Church and service-administration interests, meet legal duties, establish or defend legal claims, or rely on another basis available to the relevant Church. Essential diagnostics are part of providing and supporting the App. Consent is used for optional usage Analytics, not as a blanket basis for every Church record.

4. Services and locations

  • SpacetimeDB Maincloud: hosts and processes operational App data. The App's Maincloud deployment is currently in the United States.
  • Google Firebase: provides authentication, remaining Firestore-backed data, file storage, messaging, Remote Config, essential Crashlytics diagnostics, and optional Analytics.
  • Cloudflare Workers: processes authenticated supporting APIs, notifications, media, and service operations.
  • Your device: stores preferences and encrypted or provider-managed offline caches needed for App operation.

Provider information: SpacetimeDB Privacy Policy, SpacetimeDB Terms, Firebase privacy information, and Cloudflare Privacy Policy.

These links explain provider practices but do not replace any data-processing or international-transfer agreement required between the relevant parties. Processing in the United States may be an international transfer for users elsewhere. Where transfer rules apply, an appropriate legal transfer mechanism must be available. A Church requiring specific residency or contractual safeguards should contact the App operator before placing records in the service.

5. Access and security

Church workspaces are separated by tenant and protected through authentication, role-based authorization, and server-scoped data access. Data is encrypted in transit using provider-supported HTTPS/TLS, and hosted providers apply their available storage protections. No internet service can promise absolute security.

Users must protect their provider account, use only authorized Church workspaces, grant the minimum necessary roles, and promptly report suspected unauthorized access.

6. Retention, account deletion, and historical traces

App account data and Church records have different lifecycles. When account deletion completes, the App deletes the account's identity links, user profile, legal-acceptance row, and—when no other account owns it—the linked person and phone records. Pending membership requests are removed. Non-pending Church membership rows are de-identified in the current system by removing their profile link and replacing direct profile fields with a deleted-user label.

Account deletion does not erase every Church-owned or transaction record. Attendance, department participation, voting, financial transactions, transfers, administrative actions, and other historical traces may remain when needed to preserve the Church book, audit trail, transaction integrity, legal claims, or the rights and records of other people. A retained record may still be personal data if a Church can link it to a person through other information; it is not described as anonymous unless it truly cannot be re-identified.

We and the relevant Church should remove or de-identify unnecessary personal fields where reasonably possible without making the remaining record false or breaking required history. Different record types may be kept for different periods based on purpose, Church policy, legal duties, disputes, backups, and technical integrity. Uploaded essential diagnostics and optional Analytics events follow the applicable Firebase retention configuration and may remain in aggregated reports.

7. Your choices and rights

  • View or correct profile and Church information where your role permits
  • Decline or withdraw optional usage Analytics
  • Stop using the App if you do not accept essential crash and error diagnostics
  • Request access, correction, deletion, restriction, objection, or portability where applicable
  • Delete your App account using the in-App account deletion flow
  • Complain to an applicable data-protection authority

Rights are not absolute. A deletion request may not require removal of a Church-book or transaction record that must be retained for a valid purpose, but unnecessary personal fields should still be reviewed. Contact the managing Church first for Church-controlled records, or contact the App operator for account/service data. Identity verification may be required before a request is fulfilled.

8. Records about minors

App accounts are intended for adults or people legally authorized to administer Church data. Church workspaces may contain records about people under 18, entered and managed by authorized adults. The relevant Church and the user entering the record are responsible for having appropriate authority, providing any required notice, limiting access, and following local child-data rules. Contact the Church or App operator promptly if a minor's information appears without proper authority.

9. Changes

This Notice may change as the App, providers, or legal requirements change. The updated version and date will appear here. When a material new version requires acknowledgment, the App may ask signed-in users to review it before continuing.

10. Contact

Elie Zedeck — SDA Church App operator

Madagascar

(enable JavaScript to see the email address)

You can also use the contact page.

SDA Church App iconSDA Church App

Private, secure Church administration for Seventh-day Adventist congregations — from the membership book to the treasury.

© 2017-2026 Elie Zedeck. All rights reserved.

Seventh-day Adventist and the flame logo are trademarks of the General Conference of Seventh-day Adventists.