🔒 What's private, and what isn't
The short version, before the detail. If you are exploring faith quietly, these are the facts that matter most:
- There is no end-to-end encryption. Your posts, prayer requests, journal entries, direct messages and ORA conversations are stored in our database as ordinary text. We do not encrypt them in the app before they leave your device.
- Your church can read what you post in its community. Posts, comments and any prayer request you did not mark private are visible to every member of that community, pastors and church admins included. Pastors and moderators can also pin a post or hide it from the feed.
- Your journal is yours by default. SOAP journal entries are visible only to you unless you deliberately mark one public and share it to a community. On iPhone that sharing toggle exists; on Android and the web there is no way to publish a journal entry at all.
- Prayer requests are visible to your community by default. Mark a request private and only you can see it.
- ORA conversations stay in your account. Other members, your church and its admins cannot read them. To answer you, your message is sent to the AI providers listed in section 4.
- On the explorer path, analytics aren't linked to you. The iPhone app never ties usage events to an explorer account. Versions up to 1.19.19 still send Mixpanel anonymous app-open and session counts; later versions send Mixpanel nothing once an explorer is signed in (section 2).
- You choose what you join. Nothing joins a community on your behalf, and a group marked private is invite-only and stays out of search.
- Profile Visible (iPhone app: Me, then Edit Profile) hides you from strangers, not from your communities. With it off, people outside your communities and conversations can't find or open your profile. Members of the communities you join still can, and anyone who can see your profile can get every field on it, including a phone number (section 4). Explorer accounts created on iPhone start with it off; the Android and web apps don't have the switch yet.
- If your safety depends on privacy: use a display name that isn't your real name, don't add a phone number, prefer private (invite-only) groups, and turn off notification previews on your lock screen (section 5).
- Your data is stored in the United States, in Northern Virginia, and some of your words go to AI companies: every journal entry you save is sent to OpenAI to build journal search, and what you ask ORA is sent to Anthropic (section 4).
- Photos have public links. Anyone who has the link to your profile photo, or to a photo in a post or message, can open it.
1. Who We Are
SoapBox Super App ("SoapBox," "we," "us," "our") is a faith community platform founded in 2023. We can be reached at support@soapboxsuperapp.com.
This Privacy Policy applies to the SoapBox mobile apps for iOS and Android, the web app, and the website at soapboxsuperapp.com. Where the platforms behave differently, this policy says so.
2. What We Collect
Information you provide
- Account registration: name, email address, optional phone number for verification
- Profile information: display name, photo, bio, faith journey details (all optional)
- Content you create: prayer requests, journal entries, community posts, messages
- Church-related data (for pastors): member information, giving records, event data
Information collected automatically
- Device information: device type, operating system version, app version — sent with error reports, and stored alongside your account id
- Usage analytics on iPhone and iPad only: which features you use and when — for example that you posted a prayer, created a journal entry, or sent a message to ORA. We record that the event happened, not what you wrote. These events go to Mixpanel, a US analytics company, and are tied to your account id; they are not anonymous, and there is no in-app opt-out today. Some events name what was used, such as a Bible reference or a community's id. iPhone app versions up to 1.19.19 also send your display name and the words you type when searching for a church, and let Mixpanel estimate your city from your internet address; later versions send none of these, and remove the name from your analytics record the next time you open the app signed in. The iPhone app never links events to an explorer account; up to 1.19.19 it still sends anonymous app-open and session counts, and later versions send nothing once an explorer is signed in. The Android and web apps send no product analytics.
- Activity we store in your own account: which sermons you listened to and how far you got, verse audio you played, resources you downloaded, event check-ins, and memory-verse reviews. These rows are keyed to your account, not anonymous.
- Error and crash reports, which include your account id, the failing screen or endpoint, and your device and app version
- Location, on iPhone and iPad only: when you search for nearby churches and grant permission, your approximate coordinates are sent to our server to run that one search. We do not save them to your profile and we keep no location history. The Android app never asks for location — its "near you" search is a text directory filter. The city in your profile is whatever you typed there.
- Contacts, only if you turn on contact matching: phone numbers are hashed on your device and only the hashes are sent, so we never hold your contacts' numbers
- Push notification tokens (for notifications you opt into). iPhone and iPad register a token with Apple; the Android app uses reminders scheduled on your own device instead.
What we do NOT do
- We do not sell your data. There is no advertising SDK in either app.
- We do not build advertising profiles.
- We do not read your ORA conversations for marketing purposes.
- We do not show your journal entries to other members, to your church, or to its admins — unless you publish one yourself.
- We do not record the text of your prayers, journal entries or ORA messages in our analytics. The analytics event says "a journal entry was created," never what it said.
3. How We Use Your Information
- To provide the service: Authenticate your account, deliver features, sync your data across devices
- To personalize your experience: Show relevant communities, verses, and content based on your preferences. If you read SoapBox in a language other than the one a post was written in, that post’s text is sent to a translation provider (section 4) and the translation is cached on our servers.
- To power journal search: each time you save a journal entry, its Scripture reference, observation, application and prayer are sent to OpenAI to turn it into a search vector, and so are your journal searches.
- To communicate with you: Send push notifications you opt into (prayer reminders, community activity)
- To power ORA: Your message is sent to Anthropic to generate the answer. If your church has a sermon library, your message is also sent to OpenAI to turn it into a search vector, so ORA can quote the right sermon back to you. On the Disciple plan, ORA also sends Anthropic passages from your own past journal entries that relate to your question. What those providers may do with it is governed by their own API terms. We keep your ORA history in your account so you can reread it; only you can read it, and you can delete it.
- To improve the app: We count feature usage and watch error rates. Our server-side metrics are aggregate only — a function name, an hour, a count, with no user named. The in-app analytics described in section 2 are not aggregate: they are tied to your account.
- For security: Detect and prevent fraud, abuse, and unauthorized access
4. Sharing Your Information
We do not sell your personal information. We share data only in these limited circumstances:
- Service providers. SoapBox runs on Supabase — database, sign-in and file storage — hosted on Amazon Web Services in the United States (Northern Virginia). Depending on which features you and your church use, data also reaches: Stripe and MTN MoMo (payments); Apple, for push notifications to iPhone and iPad, and Google Firebase Cloud Messaging, the path our server uses for Android push tokens; Resend (email); Twilio (SMS one-time codes); Anthropic (ORA answers) and OpenAI (the search index behind journal search, sermon search and ORA grounding); Google Cloud Translation, Sunbird AI and Replicate (translating posts and answers); Google Cloud Text-to-Speech, ElevenLabs, Fish Audio and Replicate (audio narration); Groq (sermon transcription); Gelato (printing and shipping physical orders); Coinbase and the Base network (payments made in USDC); and Vercel, which hosts this website and records page visits on it. If your church connects a social or YouTube channel, content it publishes goes to that platform too. Anthropic and OpenAI say that, by default, they don't train their models on data sent through their business APIs; OpenAI says it keeps that data for up to 30 days to monitor for abuse.
- Your church's SMS provider. A church can connect its own SMS provider account (for example DARSMS) to SoapBox. When it does, and a pastor or admin sends a text message, SoapBox passes the phone numbers of the people that church has recorded as agreeing to receive SMS, together with the message text the church wrote, to that provider on the church's instruction. The provider is the church's own, under the church's agreement with it; SoapBox does not send SMS from its own account, does not sell or resell SMS, and holds no SMS credit. The church's provider key is stored encrypted and is never shown in full to anyone after it is saved; church staff see only its last four characters.
- Your profile. With Profile Visible on (the default), any signed-in SoapBox user can find your profile and open it. With it off, only these people can: you; people in a conversation you started or have written in; people who belong to a community you belong to (a pending invitation or a one-time visit doesn't count, for them or for you); and staff who manage people for a church or group you belong to or have given to. SoapBox's search and Find Friends skip you, and where someone who can't see your profile sees one of your posts, it shows a placeholder instead of your name. The switch is in the iPhone app (Me, then Edit Profile); the Android and web apps don't have it yet.
- Every field on your profile. Anyone who can see your profile can get every field on it through our systems, not only what the app displays. That includes your phone number, if you added one. The Show Email, Show Location and Show Activity switches don't limit this.
- Find Friends and church invitations. If Profile Visible is on and someone who has your phone number in their contacts uses Find Friends, SoapBox can show them your profile, and a pastor can do the same to invite people to a church. With Profile Visible off, neither finds you.
- Photos. Profile photos and photos in posts and direct messages are stored at web addresses that don't require signing in. Anyone who has a photo's link can open it.
- Your church, its admins, and the other members. If you join a church or group on SoapBox, its pastor and admins see your membership and your profile, and they can read everything you post inside that community — posts, comments, and any prayer request you did not mark private. So can every other member of that community. Pastors and moderators can pin a post, or hide it from the feed (a reversible act we record); only you or a SoapBox administrator can delete a post you wrote. Church admins also see event check-ins and the donations made to their church, where a gift you marked anonymous shows as "Anonymous donor" with no name attached. They cannot read your journal entries, your direct messages, or your ORA conversations.
- Legal requests. We don't build or allow any government access to church or member data, for any country, and we don't report church data to any government. We release data only in response to valid legal process from a court of competent jurisdiction, and then only the narrowest set of records that process requires. If a request concerns a church's data, we tell that church, unless the law forbids us to. SoapBox is a US company that stores data in the United States, so US courts can issue such orders.
- Business transfers: In the event of a merger or acquisition, your data would transfer subject to the same privacy protections.
5. Data Security
What we do:
- TLS encryption for everything travelling between your device and our servers.
- Row-level security in the database, so the app can only read the rows your signed-in account is entitled to. Your journal entries, direct messages and ORA conversations are restricted to you; community content is restricted to the members of that community.
- The OAuth tokens a church gives us when it connects a social or YouTube channel, and the Google tokens a pastor gives us to import sermons from YouTube, are encrypted in the database with a key kept in a separate vault.
- For contact matching, your contacts' phone numbers are hashed on your device before they are sent, and our server hashes them again with a secret key, so the raw numbers never reach us.
- Access controls on our own systems, and security reviews of the database’s access rules.
What we do not do — stated plainly, because the opposite is often assumed:
- No end-to-end encryption. Nothing in the app encrypts your content before it is sent. Your posts, prayers, journal entries, messages and ORA conversations sit in our database as ordinary text.
- No application-level encryption at rest. Our database host, Supabase, says it encrypts all customer data at rest with AES-256. That protects against stolen hardware. It does nothing to stop someone who can query the database from reading what you wrote.
- Our own people can read your content. The service keys our backend uses bypass row-level security, so SoapBox engineers with production database access can read posts, prayers, journal entries, direct messages and ORA conversations. We limit who holds that access; we will not pretend it is impossible.
Your data is stored in the United States, in Northern Virginia.
Notifications show your content. A new direct message's notification shows the sender's name and the start of the message (up to 100 characters), and a prayer notification can show a person's name and the first 60 characters of the prayer request. Apple and Google deliver them, so their systems handle that text, and your phone shows it on the lock screen unless you change that in your phone's settings (on iPhone: Settings, then Notifications, then Show Previews). A copy of each notification is also kept with your account for the app's notification list.
No system is 100% secure. If you believe your account has been compromised, contact us immediately at support@soapboxsuperapp.com.
6. Your Rights & Choices
- Access: You can view the content you created — journal, prayers, posts, ORA history — within the app at any time
- Correction: Update your profile and preferences from the Me tab → Settings
- Deletion: You can delete your account in the app at Settings → Delete Account. It takes effect immediately and cannot be undone: your profile, journal entries, prayer requests, community posts, messages and memberships go with it. Your ORA conversations and notifications go too. Some things stay, and you should know about them: gift and purchase records (amount, date, and the church or item), kept for tax and accounting and no longer linked to your account; a church's own member record of you (for example the name, email and phone number the church entered), until the church deletes it; content you created for a church as a pastor or staff member, such as sermons, clips, reading plans, events and groups; messages other people sent you, in their conversations; error reports, feedback you sent us and download counts, no longer linked to your account; any backup copies our database host holds, which expire on its schedule; and records held by the companies in section 4 under their own rules. In particular, the iPhone usage events already sent to Mixpanel are held under your account id there; deleting your SoapBox account does not delete them — write to us if you want them removed.
- Deleting a single journal entry: today this removes the entry from your screen but not from our servers. Deleting your account does remove your journal entries. We are fixing this; until then, write to us if you need an entry removed.
- Profile Visible: in the iPhone app, Me, then Edit Profile. It works as section 4 describes. The Android and web apps don't have this switch yet.
- Phone number: to remove a phone number already on your account, email support@soapboxsuperapp.com.
- Notifications: Manage notification preferences in the app or your device settings
- Location: On iPhone and iPad, location access can be revoked in Settings → SoapBox → Location. The Android app never requests it.
- What others see: you choose which communities to join, which prayer requests are private, and whether a group you create is invite-only. You can delete your own posts and ORA history at any time. No setting hides your profile from the members of a community you have joined.
- Data export: To request a copy of your personal data, email support@soapboxsuperapp.com
In accordance with Apple App Store requirements, you may delete your account at any time from within the SoapBox app without needing to contact us.
7. Children's Privacy
SoapBox is designed for users 13 and older. We do not knowingly collect personal information from children under 13. If you believe a child under 13 has created an account, please contact us at support@soapboxsuperapp.com and we will promptly delete the account.
8. Developer API, MCP Server & AI Agents
SoapBox offers a public developer API (the "Faith Content API") and a remote Model Context Protocol (MCP) server so third-party AI agents and developers can use SoapBox faith tools. This section explains the data involved.
What agents send and receive. Agents may send queries such as scripture quotes, study questions, search terms, and approximate location coordinates (to find nearby churches). They receive public-domain Scripture, study answers, public church-directory data, and — only where a creator has opted in — purchasable sermon content.
API keys & usage. Developers self-serve API keys; we store only a hashed form of each key and meter per-call usage (including an anonymized IP hash for key-less calls) for rate-limiting, abuse prevention, and billing.
Acting on your behalf (consent tokens). An agent can take an action for you — post a prayer, make a donation, or read your "faith context" — only with an explicit, scoped, revocable consent token you generate in the SoapBox app. Tokens are bound to a specific agent and enforce per-transaction and monthly limits. The faith context an agent may read is limited to your name, denomination, preferred language, faith-journey stage, and ministry interests — it does not include your prayers or journal entries. You can revoke a token at any time in the app.
Cryptocurrency (USDC) payments. Some purchases may be paid in USDC on the Base network. To verify a payment we process the on-chain transaction hash, wallet address, and amount. SoapBox does not custody your funds; where a hosted crypto checkout is used, Coinbase Commerce processes the payment under its own policy.
Content marketplace. Pastors and creators may opt their content in for sale to people and AI agents; purchases are metered per key or account, and creators receive the majority of net proceeds. Donations are separate from content sales and are always passed through to the church.
Third-party agent handling. Data you allow an agent to access is also governed by that agent operator's own privacy policy. We instruct agents not to store or reuse your data beyond what you have permitted.
Retention & developer contact. API usage logs are kept for security, rate-limiting and billing; we do not currently delete them on a schedule. Consent tokens persist until they expire or you revoke them. Developer or security questions: support@soapboxsuperapp.com.
9. YouTube and Google Account Data
SoapBox uses YouTube API Services. This section applies only to churches and ministries whose staff choose to connect a YouTube channel to SoapBox. Nothing here applies to members or to anyone who never connects YouTube.
Publishing to your channel (Amplify). When a church connects its YouTube channel for publishing, SoapBox asks Google for permission to upload videos. At connection we read the channel's ID and name, so we know which channel you connected and can show it to you. After that, SoapBox uploads a video only when an authorized member of your staff has approved that specific video, with the title and description they approved. We upload it to the channel your church connected and nowhere else. We do not read, edit, or delete any other videos, playlists, comments, or channel settings.
Importing sermons from your channel. If a pastor chooses to import sermons from YouTube, SoapBox asks Google for read-only access. We read the channel's list of uploaded videos and, for each one, its title, description, thumbnail, publish date, and length. SoapBox does not download YouTube captions or video files. These become draft sermons in your church's SoapBox library, which your staff review before anything is published and can edit or delete at any time.
How we store and use it. We use YouTube data only to provide these features to your church. We do not sell it, use it for advertising, or share it with anyone except the service providers who host SoapBox. Google access tokens are stored on our servers, encrypted at rest with a key kept in a separate vault, where only our backend services can reach them. SoapBox's use of information received from Google APIs adheres to the Google API Services User Data Policy.
How long we keep it.
- Google access tokens. When you disconnect YouTube in SoapBox, or your church's community is deleted, we delete the stored tokens immediately. When you delete your SoapBox account, we do the same for your sermon-import connections and for the YouTube channels you connected for publishing; a publishing channel connected before this update stays with the church until it is disconnected in Amplify, which anyone who manages Amplify for the church can do, or you can ask us to remove it. We then ask Google to revoke SoapBox's access, normally within minutes. Until Google answers, we keep an encrypted copy of the token for that purpose only, and never for more than 24 hours. We don't ask Google to revoke when the same YouTube channel is still connected to SoapBox through another connection, because revoking would cut that connection off too, and if the request can't be completed, we stop trying within 24 hours. Our copy is deleted either way. If Google tells us your access was revoked, we delete the tokens at once. If Google refuses to refresh a token for 7 days, we delete it within the following day and ask Google to revoke it.
- Cached YouTube information, such as thumbnails, publish dates, and channel names, is refreshed from YouTube every day. Anything we could not refresh within 30 days is deleted. A video or channel that YouTube no longer returns is cleared at the next daily refresh.
Disconnecting and revoking access. You can disconnect your channel inside SoapBox at any time, which immediately stops all uploads, and you can ask us to delete the data described here through the deletion options in Section 6. In addition to those procedures, you can revoke SoapBox's access to your data through Google's security settings page at https://myaccount.google.com/permissions.
Google's terms. By connecting a YouTube channel, you agree to be bound by the YouTube Terms of Service. Google's handling of your data is described in the Google Privacy Policy.
10. Changes to This Policy
We may update this Privacy Policy from time to time. When we do, the "last updated" date at the top of this page changes, and anything material is written up in our product updates. We do not currently have a way to push a policy notice into the app, so this page is the record. Continued use of SoapBox after changes constitutes acceptance of the updated policy.