One policy, two apps, and this website
Thread Bible Study and Emberside are made by Wayfarers Digital LLC, which is responsible for everything described here. They share one sign-in, so one account works in both. This page covers both apps and the Wayfarers Digital website, and replaces the separate policies the apps used to carry. Where something is true of only one app, it says so.
Plain English, because a policy nobody reads protects nobody. There is no advertising, no advertising identifier, no tracking pixel, and no cross-app tracking. Nothing is sold, and nothing is shared for anyone else’s marketing.
What the apps collect
| What | Why | Which app |
|---|---|---|
| Email address | It is your account, your sign-in, and how you get back in | Both |
| Display name | So people you study and pray with see a name rather than an address | Both |
| Lesson progress, days present, review schedule | The product itself: keeping your place and knowing what is due | Thread |
| Reflections you write | Kept so they survive a lost phone and follow your account | Thread |
| Highlights, verse notes, bookmarks, chapters finished | What you marked, so it is there on your next device | Thread |
| Prayer requests and their updates | The group prays for them; that is what they are for | Emberside |
| Group chat and private threads | What you send to your group, or to one person in it | Emberside |
| Pictures you send, and a gathering’s photo | Shown to that group only, and deleted after five years | Emberside |
| Gatherings, your reply to one, and files you pin | The calendar and the vault | Emberside |
| Which groups and which church you belong to | Who can see what, and which seats a church is using | Emberside |
| Six signals, for the drift view | Attendance a leader marked, your reply to a gathering, asking for prayer, praying for someone, posting an update, and posting in chat | Emberside |
| When you last opened the app | One date, so a church paying for seats can see whether one has gone unused for ninety days | Emberside |
| A notification token for your device | Only if you allow notifications, so your phone can be told | Both |
| Whether your church holds a plan | It is what unlocks the full library for the people it covers | Both |
| Product analytics | Which screens are used, so we can tell where the app loses people. Never what you wrote | Thread only, and you can switch it off |
| Crash reports | The error and the stack trace when something fails, so it can be fixed | Both |
The thirteen events Thread’s analytics sends
This is the complete list — every event the app is capable of sending. They carry lesson and course identifiers and your position in a lesson, and nothing else. No reflection text, no email address and no name is ever sent, and events are tied to your account by its random identifier only. Emberside sends none of this; it has no product analytics at all.
- A lesson opened
lesson_opened - A card in a lesson viewed
lesson_card_viewed - A lesson left, and which card you were on
lesson_left - A lesson completed
lesson_completed - A review card graded
review_graded - A verse revealed on a recall card
verse_peeked - A course downloaded to read offline
course_downloaded - An offline course removed
course_download_removed - The screen that explains the plan was shown
paywall_viewed - A plan became active on the account
purchase_completed - A feature explainer shown
tour_started - A feature explainer read to the end
tour_completed - A feature explainer waved off
tour_dismissed
Two of those will look odd in a product that sells nothing inside the app, and they are named here rather than quietly dropped. paywall_viewed fires on the screen that explains what a church’s plan covers, and purchase_completed fires when a plan becomes active on an account — bought by a church on the web, never in the app.
What you write is private, and it is not encrypted
This is the most important paragraph on the page, and it applies to reflections in Thread and to prayer requests and messages in Emberside.
They are never scored, never used to train anything, never shown to anyone outside the group you wrote them for, and never read by us except where you explicitly send one to support. But they are stored as ordinary text in the database, which means anyone with database, backup or export access could read them. Today that is one person: the developer.
That is a deliberate choice, and you should know the reasoning so you can decide what to write. Encrypting them properly means the key lives on your device and nowhere else — otherwise the server holds the key, can still read the text, and nothing has been protected. A key that lives only on your device has worse consequences than the problem: lose the phone and the writing is gone permanently, a password reset cannot recover it, and reading it on a second device means carrying a recovery phrase around.
Losing somebody their writing is a worse outcome than the risk encryption would remove here. So instead the exposure is kept small, and this page says plainly what the situation is. If that is not good enough for something you want to write down, write it somewhere else. That is a reasonable decision, and this page exists so you can make it.
Who can see what
In Thread, nothing you write is shown to another reader. Reflections, highlights and notes are yours alone.
In Emberside, people in your group see what you post to that group. A private thread between two people is read by those two and nobody else — not even the group’s leader. Your leader sees a view of who is drifting, built from the six signals above and never shown to the group or ranked publicly.
A church administrator sees numbers about people and never words. How many belong, how many are drifting, who holds a seat, and whether a member has not opened Emberside in ninety days. They cannot read a prayer request, a chat message, or another church’s roster. That is enforced by the database, row by row, rather than by a setting anyone can change.
What is never collected
Your location, at any precision. Your contacts, your device calendar, your photo library, or your files. How long you spent in the app, or what you read inside a page. Whether you opened a message. Advertising identifiers, and any cross-app tracking. The text of anything you write never appears in analytics or in a crash report.
Notifications
Both apps ask before sending anything, and both keep working if you say no.
Thread sends one reminder a day, at a time you choose. Emberside tells you about new chat, prayer requests and gatherings in your groups. You can set quiet hours so nothing arrives overnight, and mute one group’s chat for up to eight hours. A prayer request’s words are never in a notification — only that one was added. You can revoke the permission in your device settings at any time.
Who processes it
We do not sell your information, and we share it with nobody except the providers below, each only to run the service. They process it on our instructions and for no purpose of their own. If a provider is added or replaced, this page changes before the change ships.
| Service | What it does | What it sees |
|---|---|---|
| Supabase | Your account, the database and file storage | Your account and everything you write. Access is enforced row by row, so one account cannot read another’s |
| Sentry (United States) | Crash and error reports | The error, the stack trace, and your account’s random identifier. Not your email, not your name |
| PostHog (United States) | Product analytics, in Thread, if you have not turned them off | Which screens were used, tied to a random identifier. Never what you wrote |
| Sanity | The lessons themselves, in Thread | Content only. It receives nothing about you |
| Stripe | Payment, when a church buys a plan on the web | The billing details the person buying types in. We never see or store a card number |
| Google (Firebase Cloud Messaging) | Delivers notifications to your phone | A device token, and each notification’s text — a name and a chat preview, or that a prayer request or gathering was added. Kept only long enough to deliver |
| Google and Microsoft | Sign-in, only if you choose one of them | Your email address and, where they supply it, your name. Nothing else, and never your password |
| Netlify | Hosts these websites | Nothing from either app. There is no analytics or tracking on these pages |
These providers store data in the United States. If you are outside the US, your information is transferred and processed there.
Paying for it
Nothing is sold inside either app. A church buys one plan covering both apps, on the web, by card through Stripe. We never see a card number. A person covered by their church’s plan buys nothing and gives us no payment details at all.
How long it is kept
Until you delete your account, with two exceptions worth naming. Pictures sent in Emberside are deleted after five years, and the message they were attached to says so where they were the whole message. A group that the last person leaves is deleted with everything in it, because a room nobody is in is one nobody can get back into.
Analytics events and crash reports are held by PostHog and Sentry under their own retention windows, tied to your account’s random identifier rather than to anything that names you.
Deleting your account
In Thread: You → Delete my account. In Emberside: Settings → Leaving, which offers both deleting your Emberside data and deleting everything. Either way it asks you to confirm, then removes the account and everything attached to it, in both apps, immediately.
Without the app installed, use the deletion request page for Thread or for Emberside.
Deletion is immediate and cannot be undone. Two things about it are worth knowing. Your own words go and the shape of the conversation stays: a prayer request you wrote is emptied and left as a marker, so the replies other people wrote underneath it do not vanish from their history. And if you are the only leader of a group with other people still in it, the app asks you to name another leader first, rather than leaving them with a group nobody can run.
Children
Both apps are written for adults. Emberside asks whether you are sixteen or over before you can use it, and neither app is directed at children under 13 or knowingly collects their data. Emberside carries a way to report a child-safety concern from inside the app, and what happens then is set out on the child safety page.
Security
All traffic is encrypted in transit. Your session is held in the device’s secure storage rather than ordinary app storage. Access to your data is enforced by the database itself, row by row, rather than by an app asking politely. Pictures live in a private store and are reached through links that expire. The code is scanned continuously for vulnerabilities, exposed secrets and risky dependencies.
This website
Everything above is about the apps. This site — wayfarersdigital.com — collects far less.
If you email us, request a demo, volunteer for early testing, or ask to support our work, we receive what you put in your message: your name, your email address, and what you wrote. We use it to reply and to talk to you about your request, and nothing else.
The site also receives the basic technical information any browser sends, such as your IP address, browser type and the pages you visited. It is used to run and secure the site. There is no analytics and no tracking on these pages.
Changes, and how to reach us
If this policy changes in a way that affects what is collected or who processes it, the apps will say so before the change takes effect. Any update is posted here with a revised date.
A request about your data — a copy of it, a correction, or deletion — goes to privacy@wayfarersdigital.com. For anything else, including help with either app, support@wayfarersdigital.com reaches us faster. We may keep limited information where the law requires it.
Wayfarers Digital LLC · wayfarersdigital.com