Privacy Policy

Last updated 11 September 2026 · covers Thread Bible Study, Emberside, and this site

One policy, two apps, and this website

Thread Bible Study and Emberside are made by Wayfarers Digital LLC, which is responsible for everything described here. They share one sign-in, so one account works in both. This page covers both apps and the Wayfarers Digital website, and replaces the separate policies the apps used to carry. Where something is true of only one app, it says so.

Plain English, because a policy nobody reads protects nobody. There is no advertising, no advertising identifier, no tracking pixel, and no cross-app tracking. Nothing is sold, and nothing is shared for anyone else’s marketing.

What the apps collect

WhatWhyWhich app
Email addressIt is your account, your sign-in, and how you get back inBoth
Display nameSo people you study and pray with see a name rather than an addressBoth
Lesson progress, days present, review scheduleThe product itself: keeping your place and knowing what is dueThread
Reflections you writeKept so they survive a lost phone and follow your accountThread
Highlights, verse notes, bookmarks, chapters finishedWhat you marked, so it is there on your next deviceThread
Prayer requests and their updatesThe group prays for them; that is what they are forEmberside
Group chat and private threadsWhat you send to your group, or to one person in itEmberside
Pictures you send, and a gathering’s photoShown to that group only, and deleted after five yearsEmberside
Gatherings, your reply to one, and files you pinThe calendar and the vaultEmberside
Which groups and which church you belong toWho can see what, and which seats a church is usingEmberside
Six signals, for the drift viewAttendance a leader marked, your reply to a gathering, asking for prayer, praying for someone, posting an update, and posting in chatEmberside
When you last opened the appOne date, so a church paying for seats can see whether one has gone unused for ninety daysEmberside
A notification token for your deviceOnly if you allow notifications, so your phone can be toldBoth
Whether your church holds a planIt is what unlocks the full library for the people it coversBoth
Product analyticsWhich screens are used, so we can tell where the app loses people. Never what you wroteThread only, and you can switch it off
Crash reportsThe error and the stack trace when something fails, so it can be fixedBoth

The thirteen events Thread’s analytics sends

This is the complete list — every event the app is capable of sending. They carry lesson and course identifiers and your position in a lesson, and nothing else. No reflection text, no email address and no name is ever sent, and events are tied to your account by its random identifier only. Emberside sends none of this; it has no product analytics at all.

  • A lesson opened lesson_opened
  • A card in a lesson viewed lesson_card_viewed
  • A lesson left, and which card you were on lesson_left
  • A lesson completed lesson_completed
  • A review card graded review_graded
  • A verse revealed on a recall card verse_peeked
  • A course downloaded to read offline course_downloaded
  • An offline course removed course_download_removed
  • The screen that explains the plan was shown paywall_viewed
  • A plan became active on the account purchase_completed
  • A feature explainer shown tour_started
  • A feature explainer read to the end tour_completed
  • A feature explainer waved off tour_dismissed

Two of those will look odd in a product that sells nothing inside the app, and they are named here rather than quietly dropped. paywall_viewed fires on the screen that explains what a church’s plan covers, and purchase_completed fires when a plan becomes active on an account — bought by a church on the web, never in the app.

What you write is private, and it is not encrypted

This is the most important paragraph on the page, and it applies to reflections in Thread and to prayer requests and messages in Emberside.

They are never scored, never used to train anything, never shown to anyone outside the group you wrote them for, and never read by us except where you explicitly send one to support. But they are stored as ordinary text in the database, which means anyone with database, backup or export access could read them. Today that is one person: the developer.

That is a deliberate choice, and you should know the reasoning so you can decide what to write. Encrypting them properly means the key lives on your device and nowhere else — otherwise the server holds the key, can still read the text, and nothing has been protected. A key that lives only on your device has worse consequences than the problem: lose the phone and the writing is gone permanently, a password reset cannot recover it, and reading it on a second device means carrying a recovery phrase around.

Losing somebody their writing is a worse outcome than the risk encryption would remove here. So instead the exposure is kept small, and this page says plainly what the situation is. If that is not good enough for something you want to write down, write it somewhere else. That is a reasonable decision, and this page exists so you can make it.

Who can see what

In Thread, nothing you write is shown to another reader. Reflections, highlights and notes are yours alone.

In Emberside, people in your group see what you post to that group. A private thread between two people is read by those two and nobody else — not even the group’s leader. Your leader sees a view of who is drifting, built from the six signals above and never shown to the group or ranked publicly.

A church administrator sees numbers about people and never words. How many belong, how many are drifting, who holds a seat, and whether a member has not opened Emberside in ninety days. They cannot read a prayer request, a chat message, or another church’s roster. That is enforced by the database, row by row, rather than by a setting anyone can change.

What is never collected

Your location, at any precision. Your contacts, your device calendar, your photo library, or your files. How long you spent in the app, or what you read inside a page. Whether you opened a message. Advertising identifiers, and any cross-app tracking. The text of anything you write never appears in analytics or in a crash report.

Notifications

Both apps ask before sending anything, and both keep working if you say no.

Thread sends one reminder a day, at a time you choose. Emberside tells you about new chat, prayer requests and gatherings in your groups. You can set quiet hours so nothing arrives overnight, and mute one group’s chat for up to eight hours. A prayer request’s words are never in a notification — only that one was added. You can revoke the permission in your device settings at any time.

Who processes it

We do not sell your information, and we share it with nobody except the providers below, each only to run the service. They process it on our instructions and for no purpose of their own. If a provider is added or replaced, this page changes before the change ships.

ServiceWhat it doesWhat it sees
SupabaseYour account, the database and file storageYour account and everything you write. Access is enforced row by row, so one account cannot read another’s
Sentry (United States)Crash and error reportsThe error, the stack trace, and your account’s random identifier. Not your email, not your name
PostHog (United States)Product analytics, in Thread, if you have not turned them offWhich screens were used, tied to a random identifier. Never what you wrote
SanityThe lessons themselves, in ThreadContent only. It receives nothing about you
StripePayment, when a church buys a plan on the webThe billing details the person buying types in. We never see or store a card number
Google (Firebase Cloud Messaging)Delivers notifications to your phoneA device token, and each notification’s text — a name and a chat preview, or that a prayer request or gathering was added. Kept only long enough to deliver
Google and MicrosoftSign-in, only if you choose one of themYour email address and, where they supply it, your name. Nothing else, and never your password
NetlifyHosts these websitesNothing from either app. There is no analytics or tracking on these pages

These providers store data in the United States. If you are outside the US, your information is transferred and processed there.

Paying for it

Nothing is sold inside either app. A church buys one plan covering both apps, on the web, by card through Stripe. We never see a card number. A person covered by their church’s plan buys nothing and gives us no payment details at all.

How long it is kept

Until you delete your account, with two exceptions worth naming. Pictures sent in Emberside are deleted after five years, and the message they were attached to says so where they were the whole message. A group that the last person leaves is deleted with everything in it, because a room nobody is in is one nobody can get back into.

Analytics events and crash reports are held by PostHog and Sentry under their own retention windows, tied to your account’s random identifier rather than to anything that names you.

Deleting your account

In Thread: You → Delete my account. In Emberside: Settings → Leaving, which offers both deleting your Emberside data and deleting everything. Either way it asks you to confirm, then removes the account and everything attached to it, in both apps, immediately.

Without the app installed, use the deletion request page for Thread or for Emberside.

Deletion is immediate and cannot be undone. Two things about it are worth knowing. Your own words go and the shape of the conversation stays: a prayer request you wrote is emptied and left as a marker, so the replies other people wrote underneath it do not vanish from their history. And if you are the only leader of a group with other people still in it, the app asks you to name another leader first, rather than leaving them with a group nobody can run.

Children

Both apps are written for adults. Emberside asks whether you are sixteen or over before you can use it, and neither app is directed at children under 13 or knowingly collects their data. Emberside carries a way to report a child-safety concern from inside the app, and what happens then is set out on the child safety page.

Security

All traffic is encrypted in transit. Your session is held in the device’s secure storage rather than ordinary app storage. Access to your data is enforced by the database itself, row by row, rather than by an app asking politely. Pictures live in a private store and are reached through links that expire. The code is scanned continuously for vulnerabilities, exposed secrets and risky dependencies.

This website

Everything above is about the apps. This site — wayfarersdigital.com — collects far less.

If you email us, request a demo, volunteer for early testing, or ask to support our work, we receive what you put in your message: your name, your email address, and what you wrote. We use it to reply and to talk to you about your request, and nothing else.

The site also receives the basic technical information any browser sends, such as your IP address, browser type and the pages you visited. It is used to run and secure the site. There is no analytics and no tracking on these pages.

Changes, and how to reach us

If this policy changes in a way that affects what is collected or who processes it, the apps will say so before the change takes effect. Any update is posted here with a revised date.

A request about your data — a copy of it, a correction, or deletion — goes to privacy@wayfarersdigital.com. For anything else, including help with either app, support@wayfarersdigital.com reaches us faster. We may keep limited information where the law requires it.

Wayfarers Digital LLC · wayfarersdigital.com