Skip to content
FireRoom

Legal

Privacy Policy

Last updated October 2026

FireRoom exists to help you grow in faith with people you trust. What you share here is deeply personal, so we treat your data as sacred: we collect only what we need, protect it carefully, and never sell it. This page explains what we collect, why, and the choices you have.

The short version

  • Your data is never sold, rented or used for advertising.
  • You decide what each accountability partner can see, and you can change it at any time.
  • Community confessions are anonymous. Other members never see who wrote them.
  • You can export all of your data or delete your account whenever you like.

What we collect

  • Account details: your first name or a nickname (a last name is optional), email address, password (stored only as a strong one-way hash), timezone, and optional profile photo, bio and country.
  • Why we ask: your name is shown only to the partners and groups you choose, never on confessions. Your email lets you sign in, confirm your account and recover it, and brings important account and safety notices. It is never shown to other members, sold, or used for marketing without your permission.
  • Spiritual activity you choose to record: habits and check-ins, notes, journal entries, prayer requests, partner messages, group messages and weekly reports.
  • Community content: confessions and responses you post, and the prayers and “me too”s you give.
  • Technical data: basic logs (such as IP address, device type and timestamps) used to keep the service secure, prevent abuse and fix problems.

How we use it

We use your information only to run FireRoom for you: showing your habits and streaks, delivering notifications and prayer requests to your partners, generating your weekly reports, moderating community content, and keeping your account secure. We do not build advertising profiles and we do not rank or compare you with other people.

Analytics

We measure how FireRoom is used so we can make it better, and we do it in the most private way we know.

  • First-party and cookieless: our own servers collect page views and page speed. We set no analytics cookies and use no third-party trackers, advertising pixels or analytics services.
  • No IP addresses stored: to count unique visitors per day we use a one-way hash that rotates daily and cannot be reversed or linked across days.
  • Approximate location only: we record a country, taken from our hosting provider's network header or your browser's time zone. Never a city or precise location.
  • Your signals are respected: if your browser sends Do Not Track or Global Privacy Control, we collect no analytics at all.
  • Short retention: raw analytics events are deleted after 90 days.

How we protect it

  • All traffic is encrypted in transit with TLS, and sensitive data is encrypted at rest.
  • Passwords are hashed; we can never see them.
  • Sessions use short-lived access tokens and a secure, HttpOnly refresh cookie that scripts cannot read.
  • You can turn on two-factor authentication (2FA) for an extra layer of protection.
  • Access to data inside our team is limited, logged and granted only when needed to support you.
  • We rate-limit sensitive actions and continuously monitor for suspicious activity.

Who can see what

  • Accountability partners see only what your visibility setting allows (full, habits only, or minimal). You can change this per partner or end a partnership at any time.
  • Prayer requests made with the "Pray for Me" button go only to your accepted partners (and, if a request goes unanswered, to leaders of groups you belong to).
  • Community confessions are shown without your name, photo or profile. Moderators review posts for safety, but your identity is never revealed to other members.
  • Group leaders see only aggregate progress (such as weekly completion), never your private notes, journal or messages.
  • Service providers (hosting, email delivery, push notifications and automated content screening) process data on our behalf under strict confidentiality and only to provide the service.

Moderation

To keep the community safe, confessions are screened automatically and, when needed, reviewed by trained human moderators before they appear. Content that is harmful, explicit, or identifies other people may be declined. You can report any post or response you believe breaks our guidelines.

Your rights and choices

  • Export: download a copy of all your data at any time from Settings → Privacy.
  • Delete: delete your account from Settings → Privacy. Your personal information is removed and any community content is fully anonymised.
  • Correct: update your profile details whenever you like.
  • Control notifications: choose which notifications you receive, by which channel, and set quiet hours.

Depending on where you live (for example under the GDPR or CCPA), you may have additional rights. We honour them for everyone, wherever you are.

How long we keep data

We keep your data for as long as your account is active. When you delete your account, personal data is removed or anonymised promptly, and residual copies in encrypted backups expire on a rolling schedule. Security logs are kept for a limited period to protect the service.

Children

FireRoom is not intended for children under 13, and we do not knowingly collect their information. If you believe a child has created an account, please contact us and we will remove it.

Questions

If you have questions about your privacy, contact us at privacy@fireroom.app. See also our Terms of Service.