Legal
Privacy Policy
Last updated: September 13, 2026
Version: 2026-09-15
1. Who we are
WellDone GFS ("we," "us," "our") is a Scripture-centered daily-formation service operated by JoshuaOneNine LLC, a Florida limited liability company, at welldonegfs.io. For any privacy question, email support@welldonegfs.io with "Privacy" in the subject line. For applicable data-protection law, JoshuaOneNine LLC is the controller of the personal information described here.
2. The sensitive nature of what you share
The reflections, prayers, and related content you create may reveal your religious or spiritual beliefs and may express your emotional or mental-health state. Under laws such as the EU and UK GDPR, this is "special category" (sensitive) personal data receiving heightened protection. We process this sensitive content only to provide the Service to you, and we rely on your explicit consent — given when you create your account and accept this Policy — as the legal basis. You may withdraw consent by deleting the content or closing your account. We do not sell it, use it for advertising, or use it to train third-party advertising or foundation models.
3. Information we collect
You give us: account information (name, email, hashed password, optional avatar); date of birth (collected at sign-up to confirm you are 18+, stored privately and never shown to any other member); Your Content (reflections, prayers, journal entries, messages, voice/video, keepsakes); preferences (notification, rhythm, accessibility, location-sharing precision); consent records (the fact, time, and versions of your agreement); and, if you contribute, billing records from Stripe (name, email, billing address, amount, cadence, transaction identifiers — Stripe handles your card details directly; we never see or store them). We collect automatically: technical data (IP address, device and browser type, basic security logs). We have turned off general visitor/page analytics for this project.
A phone number, only if you apply for a role that needs one
Being a member of WellDone GFS never requires a phone number, and you can use everything on this platform without giving one. If you apply to hold a role where you will be trusted with something on another member’s behalf, we ask you to verify a phone number as part of that application. Verification is carried out by Google Identity Platform, the same service that handles sign-in; no new company is involved.
We are honest about why. It is not to prove who you are — a phone number does not do that. Email addresses are free and unlimited; phone numbers are not. Asking for one is simply the cheapest way to make it hard for one person to hold several of these permissions under different accounts.
The number is stored on its own, is never shown to another member, is included in the export of your data, and is deleted when your account is deleted. We do not text you for any other reason.
4. How we use your information
To provide the daily formation experience and generate Scripture-grounded responses; to deliver features you use (messages to their recipients, keepsakes you preserve); to confirm eligibility (18+) and operate the safety measures in Sections 5 and 8; to send the communications you have chosen; to secure the Service and detect abuse or fraud; and to keep records we are legally required to keep, such as billing and consent records. We do not use your reflections for advertising and do not sell your personal information.
5. Automated safety screening
Text you submit may be automatically screened for indications of crisis, self-harm, or harm to others, so supportive resources can be surfaced and accounts routed for human review where our procedures require. This screening is automated and used only for safety and integrity; never for advertising or commercial profiling. WellDone GFS is not a crisis or emergency service; if you are in danger, contact local emergency services or, in the U.S., call or text 988. Where safety screening or an age concern places an account on hold, related content is preserved rather than automatically deleted so a person can review it; the governing procedures are being finalized with counsel.
How the safety screening was built, and what nobody knows
Text you write here is checked for signs that you may be in danger, so that help can be put in front of you. The check runs in two passes: a fixed list of English phrases, and an AI service that reads the passage once and answers only whether it shows signs of crisis. It is used for nothing else.
The screening was built and reviewed by WellDone's owner, working with AI. Where AI was used, we say so rather than hide it. No independent clinical evaluation has been carried out. To the best of our abilities we judged it helpful and safe — and we are telling you how it was made so that you can decide for yourself whether to rely on it.
What nobody knows: it has never been measured against a set of scored examples. We cannot tell you how often it notices someone who is in danger, or how often it raises a notice for someone who is not. Those numbers do not exist. We would rather say that plainly than imply we have them.
One thing we did measure: the AI pass recognised a direct statement of intent to end one's life, in English and in each of the sixteen other languages we serve Scripture in. That was one sentence per language. It is not a measure of how the screening reads the way people actually write, and we are not offering it as one.
The phrase list is English only. When the AI pass cannot be reached and what you wrote is not in English, we cannot check it — so we show you the help notice rather than assume you are fine.
What it never does: it never deletes what you wrote, and it never refuses to save it. If you ask us to publish a prayer to the shared feed and the screening fires, we may decline to put those words on other people's screens. Your words remain yours and stay where you wrote them.
WellDone is not a crisis or emergency service. If you are in danger right now, contact your local emergency number, or in the U.S. call or text 988. Crisis lines are listed at /crisis-help, and you do not need an account to reach them.
6. The AnsweredPrayer globe — location by design
When a prayer joins the AnsweredPrayer globe, your device — not our servers — resolves your location to a centroid at the precision you choose in Settings (City, Region, Country, or None). Your precise coordinates are never sent, logged, or stored. Only the centroid, the region name your device produced, and the country reach us. Before the centroid is written, a small deterministic drift (about 2–5 km) derived from the prayer is added: stable across sessions, but the stored point sits near a place you know and never where you are. A city-level light stands alone only if at least two other prayers sit within about 10 km; otherwise it softens to the region tier, so no light identifies one person. We store only the centroid, region name, and country — we cannot expose what we never held.
7. AI processing and how your content is handled
Some features send the relevant text of Your Content to an AI service acting on our behalf — to generate your Scripture-grounded responses, to power the in-app guide, and to perform the safety screening in Section 5, for example. Features that read across reflections you have already written send extracts of those reflections again. That provider is contractually restricted from training on your content or using it for their own purposes, and we have switched off the caching that would otherwise hold inputs and outputs in its memory for up to twenty-four hours. It does not keep your content as a matter of course, with two exceptions you should know about. If Google's automated systems flag a request as possible abuse, Google may keep it for up to 90 days to review it; we have asked Google to exempt this platform from that, and we will say here what they answer. And when you ask the in-app guide to look something up on the web, Google keeps the search queries made from your question for up to three days.
This processing happens in the European Union. The safety screening described in Section 5 runs in Google's Frankfurt region, where Google commits to process your words within Germany — a narrower commitment than we could give before, when Google's only commitment was that they stayed somewhere in the EU. Our other AI requests are served from Google's Netherlands region and processed within the EU, through an endpoint we operate in Belgium, and speech synthesis uses Google's European endpoint. The text of your reflections is not transferred outside the EU for AI processing.
8. Where your data is stored and who processes it
We build and host WellDone GFS using third-party sub-processors. Your account data, your reflections, and the files you upload are stored in the European Union. The application itself, the AI processing described in Section 7, and transactional email are also served from European infrastructure. Payment processing is handled by Stripe (United States) under its policy at stripe.com/privacy; where you make a gift, the details you enter go to Stripe and cross to the United States.
In plain terms: your account, your reflections, and the AI processing of them rest in the EU. The one part of the Service that reaches the United States is payment. Where personal data does move between regions we treat it as an international transfer and rely on appropriate safeguards. Before public launch we will maintain a current, itemized list of sub-processors with their roles and locations.
9. How we share information
We share personal information only with the sub-processors above, acting on our behalf; with the specific people you choose to share content with inside the Service; and where legally required or necessary to protect a person's safety or the Service's integrity. We do not sell personal information and do not share it for advertising.
How your information reaches these companies
Nothing is disclosed in bulk. There is no scheduled export, no data feed, and no file of member information sent anywhere.
When you write a reflection and ask for a response, that single reflection is sent to Google's AI service as one request, and the answer comes back. When we send you an email, that one message and your address go to our mail provider. When you give, your payment details go from your browser to Stripe — they never reach our servers at all. And when you type a sentence to find your way, that sentence goes to the AI service to be matched and screened.
Each of these happens one at a time, at the moment it is needed, because of something you did. The one export we do produce is the copy of your own information you can ask for at any time, and if you turn on the yearly one — it is sent to you, and to nobody else.
10. International users and your rights
You can access, export, correct, or delete your information anytime from Settings → Privacy, or by email. EU/UK users have GDPR rights (access, rectification, erasure, restriction, portability, objection, withdrawal of consent, and complaint to a supervisory authority). California residents have CCPA/CPRA rights (know, delete, correct, opt out of "sale"/"sharing" — we do neither). We honor verified requests within the time required by law and, in any case, within 30 days where practicable.
11. Cookies
We use only essential cookies — authentication session, accessibility preferences, cookie-consent state, and the age-gate rate-limit marker. We do not use advertising or cross-site tracking cookies. See our Cookie Notice for details.
11a. Wayfinder conversations
A conversation you have with Wayfinder stays with your account, so you can pick it up on another device. We keep it for 90 days after your last message and then delete it. You can clear any conversation yourself from the panel, and erasing your account erases them with it.
12. Data retention and deletion
We keep Your Content while your account is active. When you delete specific content it is removed on our stated schedule; when you close your account, your personal content is deleted within 30 days, except (a) content another user has preserved through a feature that permits it, (b) records we are legally required to keep (billing and consent), and (c) short-lived backups and security logs, purged on a rolling schedule. Content preserved for a safety or age review is retained only as long as needed and then handled under the procedures referenced in Section 5.
Some counts do not include you, and cannot be undone
When something you write is flagged for crisis support, we record only that it happened, in what language, and on what day — never your words, never your name, and never anything that can be traced back to you. Because that record contains nothing about you, deleting your account cannot remove you from it: there is nothing there to remove. These counts exist so we can see where our safety checks are failing, and they are never shown publicly.
13. Security
We protect the Service with encryption in transit and at rest, database-level access controls (row-level security), and least-privilege access. No system is perfectly secure, but we design the Service to hold as little as we can and protect what we hold.
Who can reach your information
Two people run WellDone GFS, and both hold administrative access to the platform. Either of us can grant it; today it is held by the two of us and no one else. There is no support team, no contractor, and no third party with a login.
Between members, the database itself refuses access: a request made with your own sign-in can return only your own rows and what others have chosen to share with you. Much of what the site does for you runs on our server with a key those rules do not bind, and there our code checks that each row is yours before it answers.
Administrative access is wider than that, and this is how much wider. The two of us can read what you submit for other people to see — a remembrance, and the reflection you attach to it. We can read what you send us: a support message, a report about another member. We can read a question you asked Wayfinder that it could not answer, which is kept without your name attached. And we can see the ordinary record of an account: your email address, your sign-in history, which of our emails reached you, the fact and version of your agreement to these documents, and — only if you have applied to hold a role that requires it — that a phone number was verified for you. If something you write while composing a community prayer says you are under 18 — for example, by stating your age — we keep the words that matched and which check noticed them, with your account, for one of us to review. Nothing else you wrote is kept for that review. When another member reports an account as possibly belonging to someone under 18, we keep their note, with any numbers hidden.
When one of us opens a screen that reaches your information, that is recorded: who looked, which screen, and when. We can both read that record, including each other's — neither of us is invisible to the other. It records that a screen was opened, not which of your rows were on it, and it does not show whether anyone outside this account list has ever read anything.
Your own writing is different. Your reflections, prayers, Echoes reflections, memory stones, chapter notes, verse marks, season notes, your letters, your Sanctuary letters, your cornerstone, the answers you save, and your Wayfinder conversations carry no administrator rule at the database. That is not the same as impossible. The two of us also hold the accounts that run the database itself, and those accounts are not bound by that rule: either of us could, in principle, write a query that returned your writing, and the database provider’s own control panel, which we use to run WellDone GFS, can display any record it stores. Wayfinder conversations you have chosen to encrypt are the exception — they are locked with a passphrase we never receive, and we cannot read them.
Your information is encrypted in transit and at rest.
Your password
We never store your password. Sign-in is handled by Google Identity Platform, which stores it and checks it; when you sign in, your password goes from your browser straight to Google and does not touch our servers. There are two moments when it passes through us on its way to Google — when you first create your account, and if you ever use a backup code to get past two-factor authentication. On both it is forwarded and then discarded: never written to a table, never put in a log, never attached to an error message. If you sign in with Google, there is no password with us at all.
If something goes wrong
We keep a written procedure for the possibility that member information is exposed, and a record of every incident we assess — including the ones we conclude did not put anyone at risk. If a breach is likely to be a serious risk to you, we will tell you directly and in plain language: what happened, what of yours was involved, what we have done, and what you should do. Where the law sets a deadline we will meet it; where it does not, we will not wait for one.
14. Children
WellDone GFS is intended solely for adults aged 18 or older. We do not knowingly permit anyone under 18 to use the Service or collect personal information from anyone under 18. We use a date-of-birth age check at account creation and remove accounts we learn belong to a person under 18. If you believe someone under 18 has created an account, contact support@welldonegfs.io with "Privacy" in the subject line.
15. Changes to this Policy
We may update this Policy. When changes are material, we will notify you (by email or in-app) and, where the change concerns sensitive content, ask you to review and re-consent. Each version is identified.
16. Contact
Email support@welldonegfs.io with "Privacy" in the subject line.
God often works before we notice.