Skip to content
FaithSync Software

Trust & security

Security engineered into every product.

People bring real things to our apps — who they hope to build a life with, what they pray about, what their children are learning. Protecting that is an architectural decision, so this page says plainly what we do today and what we are still building.

Our commitments

Six things we hold ourselves to.

Encrypted in transit and at rest

Everything travels over TLS and everything stored is encrypted. Private messages and prayer requests are the next place we want end-to-end encryption, where only the people in the conversation hold the keys.

We do not train AI on your life

Your conversations, prayers, journal entries, and messages are never used as training data. This is how the products are built, not a setting you have to go and find.

Real people, verified

Profile photos are checked against a live capture before an account can reach other people, and every install is verified as a genuine, unmodified app.

Reports reach a person

When you report or block someone, it goes to a human who reviews it. Accounts that keep harming people are removed.

Children are handled differently

Anything made for children has no open-ended AI conversation, no advertising, and no way for strangers to reach them. A parent approves generated content before a child sees it.

Clear about your data

We are incorporated in Canada and handle personal information under PIPEDA, honouring GDPR rights for people in the EU and UK. Deleting your account deletes your profile and your content.

How it works

The details, in plain language.

You should not need a technical background to understand how your information is handled.

Signing in
You can sign in with email, Google, or Apple. We never store your password in a form anyone could read or recover.
App integrity
Our apps confirm that requests come from a genuine, unmodified install before they reach our servers, using Play Integrity on Android and App Attest on iOS.
Connections
Everything travels over HTTPS, and browsers are instructed to refuse anything less. Pages are locked down against being framed or having their content type guessed.
Payments
Your card details never touch our servers. Payments run through Google Play, Apple, and Braintree, each of which handles card data under its own certification.
Who can see what
Rules on our servers govern every single read and write. Access to live data by anyone on our side is limited and recorded.
Your data, on request
Deleting your account removes your profile and the content attached to it. If you would like a copy of your information or something corrected, email us and a person will handle it.

Where we are

What is done, and what is next.

Security is never finished. Here is an honest picture of both sides of that.

In place today

  • Encryption in transit and at rest across all products
  • Verified accounts and app integrity checks on mobile
  • Personal information handled under PIPEDA, with GDPR rights honoured
  • A published privacy policy and terms of service

What we are working on

  • End-to-end encryption for private messages and prayer requests
  • A published security contact and disclosure policy
  • A written incident response process
  • Beginning formal SOC 2 readiness work

Found a problem?

Tell us and we will fix it.

If you have found a security issue, we want to hear about it. Email us with what you found and how to reproduce it, and we will confirm we received it. We will not take action against anyone who reports something in good faith.