Skip to the document
Thrive Church
Contents

Thrive Church App: Privacy Policy

Last updated 最後更新:2026-09-13 Version 版本:1.3

Applies to: the Thrive Church member app (iOS and Android) and the staff web admin. 適用範圍: Thrive Church 成員 App(iOS 與 Android),以及同工使用的後台網站。

Languages. This policy is published in English and Traditional Chinese. The two versions are meant to say the same thing. If they ever differ, the English version governs.

語言。 本政策以英文與繁體中文發布。兩個版本的內容應為一致。若兩者有任何歧異,以英文版為準。

1. About this policy

This policy explains what personal data the Thrive Church app collects, why we collect it, who can see it, how long we keep it, and what you can ask us to do about it.

Taiwan's Personal Data Protection Act (the PDPA) is the law that governs how we handle your data.

2. Who we are, and how to reach us

社團法人興世代教會 (Thrive Church) ("we", "us") is responsible for the personal data in this app. Under the PDPA we are the non-government agency collecting and using your data.

  • Registered address: 4th Floor, No. 98, Section 3, Xinsheng South Road, Da'an District, Taipei City
  • Website: https://www.thrivetaipei.com/
  • Anything about your data, including all the rights in section 11: app@thrivetaipei.com
  • Safety concerns, reports, or anything involving a child: patrick.ng@thrivetaipei.com
  • Giving, receipts, and your ID number: finance@thrivetaipei.com

We answer requests to see or copy your data within 15 days, and requests to correct, complete, or delete it within 30 days. If we need longer, the law lets us extend each of those once by the same amount again, and we will write and tell you if we do.

3. What we collect, and why

3.1 Your account and profile

To create an account we collect your email address and a password. Passwords are handled by our login provider and we never see them. We record when you accepted this policy.

A short onboarding form then asks for your name in English, Chinese, or both, how you would like your name printed on a name tag, your gender, and optionally your phone number and LINE ID. It also asks whether you are in a family group or would like to join one, and whether you are a member or would like to know more. Your answers to those last two are used to flag you for staff follow-up; saying you are a member does not make you one in our records, as staff confirm that separately.

We use this to know who you are, to let other members find you, to let leaders reach you, and, in the case of gender, to decide which gendered family group rooms and prayer walls you can see.

You can skip the onboarding form, and if you do, none of it is collected. Gender cannot be answered separately from the rest of the form, and the later "Update my info" screen does not include it, so if you skip the form or want your gender, family group, or membership answer changed, email app@thrivetaipei.com and a staff member will set it for you.

Profile photos. If you choose a picture, we store it. It is kept in a private area of our hosting provider's file storage and shown to signed-in members alongside your name. An earlier version of this policy said we stored no profile photo for anyone and promised to update this policy first if that changed. This is that update.

Language and appearance. Your choice of English or Chinese, and light or dark mode, are saved on your own device only and never sent to us.

Staff record, about you rather than by you: whether your account is approved, whether you are an attendee or a member, your role, and which family group you are placed in.

Whether you are married. Staff record this for one purpose only: deciding whether the option to see giving combined with a spouse is available to you. It is a yes or no, not a marital history, because that single question is all the feature needs. Other members never see it. If it is wrong, ask any staff member to change it.

Your birthday, if you choose to give one. It is optional everywhere it is asked, and nothing in the app requires it. You can give the day and month only: the year is a separate choice, because the year is your age and the birthday list does not need it. It is visible to you, to staff, and to the leaders of your family group, so they know when to wish you happy birthday. It is not shown to the congregation. Leave it blank and you simply do not appear on that list, and you can remove it at any time from Profile, then My Info.

3.2 Your family group

If you join a family group we store your membership of that group and your role in it.

Your leader can record attendance at each meeting, optionally with a reason and a note. This is recorded by your leader about you. Repeated absence shows up in a staff list so someone can check in on you.

We also store photos uploaded to your family group with their captions, and the meeting location, which is often somebody's home and may include access details such as a door code.

3.3 Messages

The app has several kinds of messaging and they are not protected the same way. Section 6 explains the differences, and it is worth reading.

  • Direct messages, group chats you create, and family group rooms. We store the message and any attachment, who sent it, when, what it replies to, and reactions.
  • Messages to the staff team. A separate conversation between you and the staff team as a whole.
  • Unsent messages. You have a short window to withdraw a message you sent. Section 6.1 explains what withdrawing does and does not do.

Some messaging features have been written but are not switched on, and nothing is being recorded for them. We will update this policy before any feature that collects new data goes live.

3.4 Prayer

We store prayer wall posts, church-wide and family group, including whether you chose to post anonymously; who prayed for a post and their reactions; and any blocks you place on another poster. Posts drop off the wall after about a week, but the record is kept. See section 9.

3.5 Your private study material

Sermon notes, your prayer journal, reading plan progress, reflections, saved verses and highlights, memorised verses, and bookmarks.

Nobody else can read any of it: not other members, not your family group leader, not staff, and not the safeguarding officer.

One exception: reading progress inside a family group is shared with that group, so everyone in your group can see who has finished which chapters.

3.6 Forms you fill in

Connection cards, membership class and baptism interest, retreat signups, sermon response forms, and similar. Between them these collect your name and contact details, your answers to the questions asked, and anything you write in your own words. A connection card can be submitted by a visitor who has never signed up.

Family group signups are the exception, and they are not on this list. That form is a Google Form, not a screen in the app, so what you write in it goes to Google and staff read it in the response sheet. It is not held in our database and the retention rules in section 9 do not reach it. See section 7.

Staff also record follow-up attempts based on these forms: who contacted you, when, how, what happened, and a note.

3.7 Care and benevolence requests

If you ask the church for help we store the type of need you selected, your description in your own words, how urgent it is, how you want us to contact you, and whether you agreed to share it with your family group leader.

Staff then keep a contact log about your case, including their own notes.

Requests cannot be submitted anonymously. Your name is always attached.

3.8 Giving and tax receipts

If you record a donation we store the date, amount, currency, purpose, and the last few digits of your bank account.

If you want a Taiwanese tax receipt filed on your behalf, we ask for your name for the receipt, mailing address, contact details, and your national ID or ARC number. This is entirely optional and used only for that purpose.

We also import a spreadsheet exported from the church's accounting software and match transactions to members. That file may contain donors who do not use the app.

3.9 Notifications

If you allow notifications we store a token for your device, your device model, the platform, and your notification preferences and quiet hours.

3.10 Safety and administrative records

  • An audit log of administrative actions: who did what, to what, and when. It does not record message content.
  • A rate limit log: a timestamp each time you send a message, file a report, or post a prayer request.
  • Reports you file about a message, which include a frozen copy of that message.
  • Safeguarding flags and preservation holds. See section 6.6.

3.11 What we do not collect

These are real and deliberate choices, so we want to be specific:

  • No analytics, no tracking, and no crash reporting. There is nothing of that kind anywhere in the app. We do not measure which screens you visit or how long you stay.
  • We do not log your IP address in the app. One exception is in section 7: our web host logs staff IPs for the admin site.
  • No advertising, no data selling, and no data sharing for marketing.
  • No location tracking.
  • No access to your contacts or calendar.
  • Your photo library is read only when you open the attachment sheet, and only if you allow it. Thrive adds a photo to your library only when you tap Save.

4. Why we are allowed to hold this

Under the PDPA we rely on the following, depending on the data:

  • Your consent. You accept this policy when you sign up and we record the timestamp. Filling in an optional field is itself a choice to give us that information.
  • Our relationship with you. Running a church you belong to requires a member record, a family group list, and a way to contact you.
  • A specific legal duty. Donation and tax receipt records exist because tax law requires them.
  • Protecting someone's life, body, freedom, or property. This is the basis for keeping safety records and preservation holds, even when you have asked us to delete your account.

Health information gets a higher standard. The PDPA treats medical and health data as special category data. In this app that means the medical parts of a care request, a "sick" reason on an attendance record, and any children's medical notes. We rely on your explicit choice to tell us, and only ever in the context of you asking for help. You never have to give us health information to use the app.

A note on religious belief. Taiwan's PDPA does not classify religious belief as special category data, so under Taiwanese law most of what is in this app is ordinary personal data. We recognize that in practice nearly everything here is a record of your faith and your private spiritual life, and we treat it as sensitive regardless of what the law requires. If you live in the EU or the UK, tell us at app@thrivetaipei.com and we will handle your data to the stricter standard those laws expect.

5. Who can see your data inside the church

5.1 The roles

RoleWhat it is
YouYour own account.
Approved membersAnyone the church has approved. They see the member directory.
Family group leadersThe leader and co-leader of a group, for their own group only. Helpers are not included. A helper assists with running a group and is given the group's leaders' chat room; they see no more of your data than any other member does.
StaffChurch staff accounts. The broadest everyday access.
Safeguarding officerOne or more named people who handle reports and safety matters. This permission cannot be granted from the admin website at all, so no staff member can give it to themselves.
Super adminThe small number of people who decide who has access to what, including who can see giving. A super admin can grant that access to anyone, themselves included, and every grant and removal is written to the audit log. The app refuses to remove the last remaining super admin.
Database administratorWhoever holds the keys to our database account.

5.2 What each role can see

Swipe sideways to see every column.

Your dataYouOther membersYour FG leaderStaffSafeguarding officer
NameYesYesYesYesYes
Phone, LINE ID, emailYesHidden by defaultHidden by defaultYes, alwaysYes
GenderYesNoYes, in your groupYesYes
Role, membership status, family groupYesYesYesYesYes
Whether you are recorded as marriedYesNoNoYesYes
Private chats and DMsYesOnly people in the chatNoNoOnly via a report or an audited retrieval
Messages to the staff teamYesNoNoYes, all staffYes
Prayer wall posts (named)YesYesYesYesYes
Prayer wall posts (anonymous)YesHiddenHiddenHiddenCan unmask
Notes, prayer journal, highlightsYesNoNoNoNo
Reading progressYesNoYesYesYes
Family group attendanceYesNoYesYesYes
Sermon responses, connection cards, signup formsYesNoNoYes, all staffYes
Care and benevolence requestsYesNoOnly if you agreedYes, all staffYes
Staff notes about your care caseNoNoNoYesYes
Giving records, bank digits, national IDYesNoNoNoNo
Reports you fileNoNoNoNoYes
Event RSVPsYes, your ownOnly the totalOnly the totalYes, individuallyYes

Giving is the exception to this table. Nobody in it can see your donation records or your ID number, including staff and the safeguarding officer. Only accounts a super admin has given finance access to can, and section 6.5 explains how that is handled.

5.3 Things that commonly surprise people

  • Your contact details are hidden from other members by default. Your name appears in the directory; your phone, LINE ID, and email do not. There is currently no switch for this in the app, so email app@thrivetaipei.com if you want them shown, or want to be sure they are hidden.
  • Staff see your profile in full, including the contact details hidden from other members, and staff can edit it.
  • Poll votes are not secret. Everyone in the chat can see how you voted.
  • Event RSVPs look anonymous, and are not. Other members only see a total, but every staff account can see exactly who said going, maybe, or cannot make it.
  • You cannot read back a report you filed. It goes to the safeguarding officer and only they can open it, including the reason you typed. This is deliberate, so that nothing about a report can be used to work out who filed it. Keep your own note first if you want a record.
  • Reading progress in your family group is a shared list.
  • Your family group leader can see and record your attendance, including a reason and a note.

6. The sensitive parts, explained plainly

6.1 Private messages between members

Staff cannot read your direct messages, your group chats, or your family group rooms. This is enforced by the database itself, not by the app being polite.

There are exactly four exceptions:

  1. The safeguarding officer can retrieve a full transcript of conversations you were part of, if there is a safety reason to. This includes messages you unsent and messages hidden by our retention schedule. Every retrieval is written to the audit log.
  2. Anyone in a conversation can report a message. Reporting freezes a copy and sends it to the safeguarding officer. This is the intended route for private content to reach someone who can act on it.
  3. A staff member who is in the chat reads it like everybody else in it. Being staff gives no extra access; being in the room does.
  4. Whoever administers our database can technically read anything. We restrict who holds those keys, but no software rule can prevent it. Your messages are not end-to-end encrypted.

When you unsend a message, others see only a note that a message was withdrawn, and the text is hidden from everyone including you. It is not erased: the record stays for the retention period in section 9, and the safeguarding officer can still retrieve it. A notification that has already reached someone's phone cannot be recalled.

A reported message can be removed. When you report a message, the safeguarding officer or a staff member can take it down from the chat room. That is the whole point of the report button, and it is the only route to it: there is no browse-and-delete tool, and nobody can remove a message they have not been shown by a report. Removal hides the message from everyone; it does not erase it, and the record stays for the retention period in section 9. Every removal is written to the audit log with who did it and why.

6.2 Messages to the staff team

This is a separate conversation from your chats with other members, and it is not private in the same way.

Every staff account can read every message in it. It is a shared inbox by design, so that no single person is the sole holder of a difficult conversation and so that someone always replies. That is a deliberate accountability decision, but it means when you write to "the staff team", you are writing to all of them. If you need to tell one specific person something in confidence, please speak to them directly.

When staff reply, the notification on your phone deliberately shows no preview.

6.3 Prayer requests, including the anonymous option

Anonymous means anonymous to people, not to the system.

When you post anonymously, your name is hidden from other members, from family group leaders, and from ordinary staff, and that hiding is enforced by the database. But your name is stored on the post, and the safeguarding officer can see it. We keep the link because a prayer request is sometimes how someone tells us they are in danger, and we need to be able to reach that person.

So, honestly: anonymous prayer is a good way to share something you would rather other members did not attach to your face. It is not a way to say something you need nobody to ever trace back to you. If you need that, please talk to someone in person.

If you block an anonymous poster, we do the blocking on our side so you never learn who it was.

6.4 Care and benevolence requests

These are among the most sensitive things in the app. If you tell us about an illness, a job loss, a debt, or a family crisis, that text is stored.

  • Every staff account can read your request in full, including the free text.
  • Your family group leader can read it only if you ticked the box to share it with them. That box is a real control and it works.
  • Staff keep a contact log about your case that you cannot currently read. We think you should be able to see notes about yourself, and that is on our list to change. In the meantime, ask us at app@thrivetaipei.com.
  • There is no self-service way to delete a care request. Email us and a staff member will handle it, subject to section 9.
  • Requests cannot be anonymous.

6.5 Giving, bank digits, and your ID number

This is the one area where ordinary staff have no access at all. Donation records can only be seen by an account a super admin has granted finance access to. Holding finance access does not let that person grant it to anyone else, and every grant and removal is recorded in the audit log.

Your national ID or ARC number gets the strongest handling in the app:

  • It is only collected if you ask for a tax receipt to be filed on your behalf.
  • It is encrypted before it is stored, using a key kept separately, so it is not readable even in a copy of the database.
  • Every time it is decrypted, that is written to the audit log with who did it and when.
  • If you withdraw your consent, the number is erased immediately, not just marked inactive.

Tax receipt documents are stored privately, where you can only ever reach files in your own folder. They may contain your ID number.

6.6 Safeguarding reports, flags, and preservation holds

Anyone can report a message. When you do:

  • A copy of the message is frozen at that moment, so an edit or an unsend cannot change the evidence.
  • The report goes only to the safeguarding officer. Ordinary staff cannot see reports, and neither can you, after you send it. Filing one does not give you a copy or a status page.
  • A preservation hold is placed on the person who wrote the message, which stops anything they were part of being deleted until the hold is lifted.
  • The person reported is not told, and the app deliberately gives them no way to find out. That protects you as the reporter.

If you are under a preservation hold and you ask us to delete your account, we will refuse and keep the data, under the PDPA exception for protecting someone's life, body, freedom, or property. We may not be able to tell you why, because doing so could identify a reporter.

Dismissing a report never automatically lifts a hold. Lifting one is always a separate, deliberate, logged decision by the officer.

7. Who outside the church receives your data

We do not sell your data and we never share it for marketing. These are the only companies that receive any of it.

WhoWhat they receiveWhere they are
Our hosting and database providerEverything. Our database, login system, file storage, and server functions.Singapore
Our notification service, and Apple and GoogleYour device token, the sender's name, and a short preview of the message, every time you get a notification.United States and elsewhere
GIPHYWhat you typed, when you search for a GIF. The search is sent from our server, not from your phone, so your IP address is not shared. Once a GIF has been sent, anyone who scrolls past it loads the image from GIPHY, which does reveal their IP address to GIPHY in the same way any image on the internet does.United States
Crossway (ESV)The Bible passage reference only. No account, no device, and no identifying information. Most requests never reach them because we cache the text.United States
Our web hostStandard web logs (IP, browser, and page) for staff using the admin website. Member data does not pass through it; the admin site talks to our database directly from the staff member's browser.United States
Google Workspace (Drive)The files and photos you send in a chat, and the full-size photos added to a family group album. They go from your phone straight to the church's own Google Drive and are never stored by our hosting provider. Google receives the file itself; it does not receive your name, your message, or who else is in the conversation.United States and elsewhere
Google FormsYour answers to the family group signup form, which is a Google Form rather than a screen in the app. That is your name, your contact details, and whatever you write in the form's own boxes. It goes to Google, not to us, and staff read it in the response sheet.United States and elsewhere
Our code host (backups)A nightly backup of the whole database, encrypted before it leaves us and readable only with a key the church holds. It is kept for 90 days and then deleted automatically. Nobody at that company can read it.United States
Apple App Store and Google PlayStandard app distribution and crash information collected by the stores themselves.United States and elsewhere

Read this before you decide about notifications. When someone sends you a direct message, the first part of what they wrote, together with their name, is sent to Apple or Google so it can appear on your lock screen. Those companies handle it outside Taiwan. So a piece of the real message leaves our systems every time you are notified, and anyone who can see your locked phone can read it.

There are two ways to stop that. Turn off message previews in your phone's own notification settings, and you will still be told a message arrived but not what it says. Or turn off message notifications in the app, and nothing is sent at all.

Replies from staff never carry a preview, whatever your settings.

About files and photos in chat. When you attach a document or send a photo in a chat, the file goes from your phone directly to the church's own Google Drive. It does not pass through our hosting provider at any point. This keeps large files off a service we pay for by the gigabyte, and it means the file sits in an account the church controls rather than one a third party controls on our behalf. Small previews of photos stay with our hosting provider so conversations load quickly.

Practically: Google can see the file, because it is holding it. Google is not told who sent it, what was said around it, or who else is in the room. When a file is removed from a chat, its link stops working within ten minutes and the file itself is deleted from the Drive.

Things we are sometimes assumed to use, and do not. The church uses accounting software, but the app is not connected to it; a person exports a spreadsheet and uploads it by hand. There is no analytics or advertising service of any kind.

If we ever add a new recipient, or start sending an existing one something new, we will update this policy and tell you in the app before it takes effect.

8. Where your data is stored, and transfers outside Taiwan

Your data is stored outside Taiwan. Our database provider does not operate a data center in Taiwan, so our project runs in Singapore. That provider is a company incorporated in the United States, which means United States legal process could in principle reach it.

This is an international transfer of personal data out of Taiwan, and the PDPA requires us to tell you so rather than leave it implied. By using the app you are agreeing to your data being held in Singapore and, for notifications, passing through the United States. Three other things also leave Taiwan, and section 7 says what each one is: photos and files go to the church's Google Drive, family group signup answers go to Google Forms, and an encrypted nightly backup of the database is held by our code host for 90 days.

We have no way to keep this data inside Taiwan while using this software. If that is not acceptable to you, please contact us at app@thrivetaipei.com before creating an account.

9. How long we keep things

A job runs every night and deletes whatever has reached the end of its period. The periods are settings the church can change, so if one of these numbers matters to you, ask and we will tell you what it is set to today.

DataHow long
Chat and staff team messagesHidden from everyone at 12 months, destroyed at 36
Photos in chats and family groupsDestroyed together with the message or photo record they belong to
Care and benevolence requests3 years after the case is closed. An open request is never deleted while it is still open
Connection cards and signup forms held by us2 years
Sermon responses2 years
Family group attendance3 years
Prayer wall posts, your notes, reading records, and saved versesFor as long as you have an account. Posts leave the wall after about a week, you can delete your own at any time, and all of this is destroyed when you delete your account
Push tokens and notification settingsUntil you sign out, ask for deletion, or remove the app
The log of when you sent messages or postedShort-term, and only to enforce rate limits

Between month 12 and month 36 a message is invisible to you, to other members, and to staff. Only the safeguarding officer can retrieve it, and only with an audit record.

What we keep for longer, and why

Three things outlive the schedule above, deliberately:

  • Giving and tax records: 7 years. Tax law requires it.
  • The audit log: permanently. It is the record of who did what as an administrator, it holds no message content, and nobody, including a super admin, can edit or delete an entry.
  • Safeguarding reports, flags, and anything under a preservation hold: for as long as they are needed. Harm is often disclosed years after it happened, and evidence that expires on a timer is no use to the person who has to act on it. A hold is released only by a specific, logged decision.

A hold stops everything. If anyone involved is under a preservation hold, or content has been flagged or reported, none of the periods above apply to it and nothing is deleted until the hold is lifted.

If you want something specific deleted sooner, ask us at app@thrivetaipei.com. A person will do it by hand.

10. How we protect your data

  • Every table carries its own access rules, checked by the database on every single query. The app cannot ask for data you are not allowed to see, even if a bug tried to.
  • Encryption in transit. All traffic between the app and our servers is encrypted.
  • Your national ID is encrypted at rest with a key stored separately from the data, and every decryption is logged.
  • Private file storage. Tax receipts, and the small preview images for chat and family group photos, are in private storage, with rules tied to your membership of that chat, group, or account. The full-size photos and chat files are not there at all: they go from your phone straight to the church's own Google Drive, and a link to one stops working within ten minutes of being opened. See section 7.
  • Split permissions. An ordinary staff account cannot promote itself to anything. Access to giving, and super admin itself, can only be granted by an existing super admin, and every grant and removal is logged. Safeguarding officer is the only permission that cannot be granted from the admin website at all, so nobody can hand themselves the ability to read reports and unmask anonymous prayer.
  • An audit log that nobody can edit. Administrative actions are recorded permanently, and no account, including a super admin, can change or delete an entry.
  • Report details are kept from ordinary staff, so that filing a report cannot expose the person who filed it.
  • No third-party analytics, so there is no extra copy of your behavior anywhere else.

What we cannot promise

  • Messages are not end-to-end encrypted. Anyone with our database keys can read them. We limit who has those keys.
  • One storage area is public: images published by staff for the whole church. Do not treat that one as private. Chat photos, family group photos, and tax receipts are all private.
  • Notification previews leave our systems, as explained in sections 7 and 8.
  • Anyone with access to a screen can copy or photograph what is on it. No software rule stops that, which is why staff access is limited by role and why administrative actions are logged.

11. Your rights, and how to use each one

Under PDPA Article 3 you have five rights. Here is how each works today, including which ones need a person rather than a button.

To ask what we hold, to see it, and to get a copy

Email app@thrivetaipei.com. There is no self-service export in the app, so a staff member assembles your data by hand. We will tell you within 15 days whether we can do it, extendable once by a further 15 days if the request is complicated, in which case we will write and tell you. We provide it in a readable format, and may charge a reasonable fee for the work, as the PDPA permits.

To correct or complete your data

Some of this you can do yourself. In the app, go to Profile, then Update my info, where you can change your names, how your name is printed on a name tag, your LINE ID, and your phone number.

These need a staff member: your email address (it is your login), your gender, your family group, your membership status, and your role. Email app@thrivetaipei.com and we will correct them.

To stop us collecting, processing, or using your data

Several controls exist in the app and genuinely work:

  • Notification preferences and quiet hours, in Settings.
  • Block another member. This hides their messages from you everywhere and stops direct messages in both directions.
  • Tax receipt consent. Withdraw it and your ID number is erased immediately.
  • Sharing a care request with your family group leader. A per-request choice.
  • Posting a prayer request anonymously. With the honest limits in section 6.3.

There is no general "withdraw my consent but keep my account" switch: consent is recorded once at sign-up, and the complete way to stop us processing your data is to delete your account. To stop one specific use of your data, email app@thrivetaipei.com and we will handle it as a manual request.

To have your data deleted

In the app: Settings, then Account, then Delete my account.

WhenWhat happens
The moment you tap deleteYour account switches off. You disappear from the directory, member features stop, and notifications stop. Nothing is erased.
The next 30 daysA cooling-off period. Sign back in and cancel, or ask a staff member to cancel for you. Everything comes back exactly as it was.
Day 30Permanent deletion runs. Your profile is scrubbed, your account is removed, and everything attached to it is destroyed.

What is destroyed on day 30: your chat messages, prayer wall posts, personal notes, prayer journal, reading records, saved verses, giving profile including any encrypted ID number, push tokens, and notification settings.

What survives, and why. Please read this part, because "deleted" does not mean every trace of your name is gone.

Deletion scrubs one place: your profile. Your name, email, phone, and LINE ID are overwritten there and your login is destroyed. Everywhere else, records that pointed at your profile simply stop pointing at it. Any text in those records that contains your name was typed or copied in as plain text, and cutting the link does not touch plain text. In practice:

  • Forms you submitted keep a snapshot of the name and contact details you entered at the time, along with everything you wrote. The snapshot exists so a form does not go stale when someone later changes their details, which is exactly why deleting your profile does not remove it.
  • Sermon responses keep your name and LINE ID as you typed them, with your reflection and prayer request.
  • Financial records imported from the church's accounting software keep the donor name as the accounting software recorded it. Your own donation entries keep the amount, date, and bank digits, no longer attached to you.
  • Safety reports and flags keep the frozen copy of the reported message and the reason the reporter typed. Safety evidence has to outlive the accounts involved, or it would be useless to the person who has to act on it.
  • The audit log keeps its entries permanently, and your account's internal id can still appear in an entry where you were the subject of an action.
  • Everything, if you are under a preservation hold. The deletion is refused and waits until the hold is lifted.

If this matters to you, ask us. Email app@thrivetaipei.com and a staff member can remove your name from the surviving records by hand, except from anything held for safety or tax reasons. That is a manual job, and we would rather do it than have you find out later.

Before you tap delete:

  • If anything blocks the deletion, your account is still switched off on day one, and we keep retrying every night until it completes. Email app@thrivetaipei.com if you want confirmation that it has.
  • If you are a parent with a child recorded in the children's ministry, deleting your account would also delete your child's record. Please talk to us first.

If you are not happy with how we handled it

Contact us first at app@thrivetaipei.com. If we do not resolve it, you can complain to the relevant Taiwanese authority for personal data protection, or seek a remedy in court under the PDPA.

There is no privacy contact form inside the app. Messages in the app go to the staff team, which is not a privacy channel and is itself covered by the retention schedule, so please use email.

12. Children and young people

We need to be straightforward here.

The app cannot tell whether an account belongs to a minor. It asks for a birthday, but only as an optional field, and the year is optional on top of that, so most people give a day and month and nothing more. There is no age check anywhere, and nothing is limited by age. This matters because our community includes first-year university students, some of whom are under 18.

In practice: someone under 18 can sign up in exactly the same way as an adult and consents to this policy on their own behalf, no feature is limited by age, and we have no parental or guardian consent process in the app.

If you are under 18, please talk with your parent or guardian about using the app, and tell us at app@thrivetaipei.com so we can handle your data with extra care and answer their questions.

If you are a parent or guardian and you want to see, correct, or delete data about your child under 18, email app@thrivetaipei.com and we will treat it as a priority.

Children's ministry check-in. The system contains an unused design for children's check-in, covering things like allergies, medical notes, authorized pickup, and emergency contacts. It is not switched on, no part of the app writes to it, and no child's record exists in it. We will update this policy and ask parents for consent properly before it is ever turned on.

Reporting a concern about a child. Contact patrick.ng@thrivetaipei.com immediately. Our approach to child safety, mandatory reporting, and preserving evidence is set out in our separate Safeguarding and Retention Policy.

13. Changes to this policy

If we change this policy we will update the date at the top and publish the new version in the app, under Profile.

If a change materially affects you, for example if we start collecting a new kind of data or send data somewhere new, we will tell you in the app before it takes effect.

The app does not currently ask you to re-accept an updated policy; your consent is recorded once, at sign-up. Until that changes, we will announce material changes in the app and give you time to ask questions or to leave.

14. Questions

Anything at all: app@thrivetaipei.com.

We would rather answer an awkward question than have you assume the worst, or the best.