---
title: "Privacy Policy"
canonical: https://www.boldmen.org/privacy
type: WebPage
updated: 2026-08-08T03:03:13.052125+00:00
publisher: "B.O.L.D. (Brothers Overcoming Lustful Desires)"
organization: "B.O.L.D. (Brothers Overcoming Lustful Desires)"
organizationUrl: https://www.boldmen.org/
contactEmail: bryan@boldmen.org
---

# Privacy Policy

Last updated: **August 2, 2026**

This policy explains what data B.O.L.D. and the Watchman app collect, how we use it, and what control you have.

## What we collect

**Account: **your email address, display name, and optional profile picture.

**Community activity: **your daily check-ins, prayer requests you submit to your team, and group chat messages within your team.

**Aggregate Watchman counters: **if you have a Watchman+ subscription and opt into a team, the number of times Watchman+ blocked content on your device, and a timestamp. We do NOT see page content, search queries, or your general browsing history.

**Blocked domain (Watchman+ dispute log): **for Watchman+ members, when the DNS filter or Screen Time blocks a site, we also record the plain domain (e.g. `example.com`) and a device label (e.g. "Jarrod's iPhone"). This is domain-only by construction — the filter itself never sees a path, query string, or page content, only a hostname, so that's all there ever is to record. It exists solely so a real dispute about what was accessed has an answer. It is visible only to B.O.L.D. platform administrators, never to your team, leader, or spouse — they continue to see only the block count and timestamp described above.

**Subscription state: **whether your Watchman+ subscription is active, when it renews. Payment data is handled by Apple or Google — we never see your card.

## Location

**What and when:** If you choose to turn on location sharing with your linked spouse, the Watchman app collects your device's precise (GPS) location. While the app is open it updates as you move; if you grant the "Allow all the time" permission, it also sends your location in the background roughly every 15–30 minutes.

**Why:** Location is used for one feature only — letting your linked spouse see your recent location as a point of accountability. It is off by default and requires a separate in-app consent step, an active spouse link, and a Watchman+ subscription to turn on.

**Who can see it:** Only your linked spouse, and only while sharing is turned on. Your team, your group leader, and B.O.L.D. staff never see your location, and it is never used for advertising.

**Your control:** You can stop sharing at any time from your Profile. Stopping immediately ends new collection and cuts off your spouse's access to your location. Deleting your account removes your stored location along with the rest of your data.

## What we do NOT collect

Full URLs, page paths, or query strings. Page content. Search queries. General browsing history. Contacts. Photos (other than the profile picture you choose to upload). Health data. Microphone. Camera (other than for the profile picture you choose to upload). Screenshots are never taken or transmitted.

## Where data lives

On Supabase (Postgres + Storage) in US data centers. Encrypted in transit (TLS 1.3) and at rest (AES-256). Row-level security ensures you only see your own data and what your team has explicitly shared. The blocked-domain dispute log described above is additionally locked at the database column level so it cannot be read outside the platform-admin tool, even by someone with row access to your other alert data.

## Who can see your data

**You: **everything you've created.

**Your team (if you've joined one): **your check-ins, prayer requests, group chat messages, and Watchman+ block counters. They do not see content you posted before joining, and they do not see the blocked-domain dispute log.

**B.O.L.D. staff: **only when you explicitly contact support, or to investigate a safety report. Staff access is logged. Platform administrators additionally have access to the blocked-domain dispute log described above, for resolving disputes about what was accessed.

**Service providers: **Supabase (database, auth, storage), Vercel (web hosting), Apple/Google (payments and push), Postmark (transactional email), Sentry (crash and error diagnostics). They process data only to provide their services to us.

## Children

The Service is not directed at children under 13. We do not knowingly collect data from children.

## Your rights

You can: download a copy of your data, delete your account, leave a team. Email us to make any of these requests.



## Onboarding conversations (new members)

When you first join and haven't yet been placed on a pack, you can chat privately with our leadership to help them get to know you and place you well. For that conversation:

- **We capture, with each message,** the message content, the sender's email address, the originating IP address, and the date and time. This is retained on our servers and used only for safety and to resolve disputes.
- **Who sees the conversation:** only you and the leaders involved, while it is active. The originating IP address and email captured for safety are visible only to B.O.L.D. platform administrators — never to a leader or another member.
- **When you're placed on a pack,** the conversation is closed immediately — you and the leaders lose access to it right away — and it is retained on our servers for **30 days**, then permanently deleted.
- **Illegal activity.** If a leader flags a message as disclosing illegal activity, that message and its captured details are retained beyond the 30-day window (a legal hold) until a platform administrator releases it, so it can be preserved and, where appropriate, reported to authorities.

## Device identifiers and notifications

**Device identifier: **To link your notifications and the app's security heartbeat to your device, the app reads a per-install device identifier — on Android the system Android ID, on iOS the vendor identifier (identifierForVendor). It is treated as an opaque value and is never used for advertising or to track you across other apps or companies.

**Push notifications: **To send check-in reminders and team alerts, we register a push token with Apple's and Google's push services and store it on our server. You can turn notifications off at any time in your device settings.

**Diagnostics: **When the app crashes or hits an error, we send a diagnostic report (through Sentry, our diagnostics provider) that includes device information and an app/device identifier so we can find and fix the problem. These reports never include your messages, prayers, browsing, or location.

## Changes to this policy

If we change this policy in a way that materially affects what we collect or who can see it, we'll notify you in the app or by email at least 14 days before the change takes effect.

## Contact

Questions: **boldmen.org/contact**

Source: https://www.boldmen.org/privacy
