Privacy Policy
How Koinonia handles information
Koinonia uses information needed to provide secure phone sign-in, community profiles, posts and media, saved posts, notifications, moderation, support, and account administration.
Information collected
- Your verified mobile phone number and account identifier.
- Your first and last name, community membership, role, and account status.
- An optional profile photo.
- For authorized publishers and administrators: post titles, text, categories, images, videos, audio, and supported YouTube links.
- Your saved-post records, reports, block relationships, related moderation status, and records of the Terms and Community Standards versions accepted by authorized publishers.
- If notifications are enabled, an Expo push token, device platform, notification language, and the device name reported by the operating system. A device name can contain a person’s name.
- Security records such as sign-in attempts, timestamps, and protected digests of phone numbers and request network addresses used to prevent abuse.
- If production diagnostics are enabled, crash and performance information, an account identifier, community identifier, app release information, and technical device information. Koinonia’s diagnostics code is configured to remove phone numbers, authentication tokens, post bodies, and signed media URLs.
Community membership and prayer or faith content may reveal religious beliefs. Koinonia treats that information as sensitive.
Information stored on your device
The app stores its authentication session, language and text-size preferences, notification choices, and a user-scoped cache of recent feed content on your device. Account deletion clears the persisted session and account-scoped feed cache. Other local app data can be removed by uninstalling the app or clearing its storage through the device operating system.
How information is used
- Authenticate accounts and manage community access.
- Display profiles, posts, media, preferences, and saved content.
- Deliver optional post notifications.
- Receive reports, apply blocks, moderate content, and maintain safety records.
- Respond to support, privacy, safety, and deletion requests.
- Protect the service against fraud, abuse, and unauthorized access.
- Diagnose reliability and performance problems when diagnostics are enabled.
Visibility inside a community
Names and optional profile photos can be visible to active members of the same community. Posts and attached media are visible to active members unless a member blocks the author. Reports and block relationships are not shown to the reported or blocked user. Authorized administrators retain the access needed to review reports and moderate their community.
Service providers
Koinonia uses Supabase for authentication, database, file storage, and server functions; Supabase Auth’s configured SMS provider, Twilio Verify, for one-time verification codes; Expo Push Service and, depending on the device, Apple Push Notification service or Firebase Cloud Messaging for optional notifications; YouTube for embedded video playback; and YouVersion for verse content. Sentry receives technical diagnostic information only when a Sentry DSN is enabled in the installed release. Embedded services may also process device and network information under their own privacy terms.
Sale and tracking
Koinonia does not sell personal information and does not use personal information to track users across other companies’ apps or websites for advertising.
Retention
Account and content data is kept while an account is active. Data is deleted or retained only for as long as reasonably necessary to provide the service, protect users, meet security and moderation needs, comply with applicable obligations, and maintain provider backups.
- Moderation records. Some moderation decisions and audit entries may remain for safety and accountability after an account is deleted. User references are removed or set to null where the database deletion rules require it.
- Security and service logs. Sign-in, abuse-prevention, server, and diagnostic records are retained according to operational need and the applicable provider’s retention settings.
- Backups. Deleted data may remain temporarily in encrypted provider backups until those backups expire or are overwritten on the provider’s schedule.
Deleting your account
You can delete your account in the app from Profile → Account → Delete Account, or start a request on the account deletion page without installing the app. Deletion removes the authentication account, profile, community memberships, saved posts, push tokens, block relationships, authored posts, and uploaded profile/post media from active systems. Related report and moderation records follow the database deletion and de-identification rules described above. A final active community administrator must transfer or add another administrator before deleting the account.
Deleting an account does not create a permanent ban on the verified phone number. Subject to normal enrollment and community-access rules, the same verified phone number may be used to register again later.
Children
Koinonia is intended for users aged 13 and older and is not directed to children under 13.
Your choices and contact
You can update your profile in the app, disable notifications in device settings, manage blocked users under Profile → Privacy & Safety, and delete your account under Profile → Account. To ask what is held about you, request a correction, or raise a privacy concern, email Koinonia.support@gmail.com.