Legal
Privacy Policy
- Version
- Version v1.0
- Effective
- Effective July 16, 2026
- Locale
- Locale en-US
Privacy Policy
Working draft — pending Legal review. ARM-010 ships this scaffold so the consent ledger and read endpoints have something to point at; the canonical text lands at ARM-010-FUP1.
Effective: the date this version was published. Version: 1.0
What this is
This page tells you, in plain English, what ARMOUR24-7 collects, why we collect it, and how long we keep it. There is a separate Pastoral Note below that translates the same content into the way we'd talk about it from the pulpit.
What we collect
- Account information you give us when you sign up: email, optional display name, your selected language and country, the faith tradition you choose to share. You can change or remove any of this from Watchpost → Account.
- Activity inside the app: which prayers you opened, which paths you started, your covenant streak. We use this to render Today and to recommend paths.
- Journal entries are encrypted on your device with a key derived from a passphrase only you know. Even ARMOUR24-7 staff cannot read them.
- Subscription information from Apple, Google, Stripe, or PayMongo when you subscribe. We never see your full card number.
- Diagnostic information — crashes, performance issues, failed requests — with personally identifying information stripped before it leaves your device.
What we don't do
- We do not sell your data.
- We do not show third-party advertising in ARMOUR24-7.
- We do not share your journal contents with anyone, including us.
- We do not profile you for advertising or share your data with data brokers.
Where your data lives
ARMOUR24-7 runs on cloud infrastructure in regional data centers. EU residents' data is stored in the EU; users in the Philippines are stored in the APAC region; everyone else defaults to the US region. The full sub-processor list is at armour24-7.com/legal/subprocessors.
Your rights
You can export, correct, or delete your data at any time from Watchpost → Privacy. Deletion is processed within 30 days; some financial records (per tax law) are retained 7 years. We respond to GDPR / CCPA / Philippines Data Privacy Act / LGPD / POPIA requests within the timeline each law requires.
How long we keep things
- Account data: until you delete your account.
- Journal entries: until you delete them, or your account.
- Audit logs: 2 years (general) or 7 years (financial).
- Diagnostic telemetry: 90 days hot, 1 year cold; never tied to you personally.
Contact
Email privacy@armour24-7.com. Our Data Protection Officer is named in the published sub-processor list.