Home Ward Privacy Policy
1. Who we are
Home Ward is operated by ASTON VENTURES L.L.C., 354 N 360 E, Vineyard, Utah 84059. Contact us at legal@home-ward.com.
Home Ward is available in the United States only and is for adults 18 and over.
2. What we collect
Account and identity
- Your email address — held by our identity provider and in our own database.
- Your password — held only by our identity provider. No Home Ward database contains your password or a hash of it.
- Your date of birth — collected once at sign-up to decide whether you are 18 or over. ⚠️ We keep it after that decision, and it is never shown back to you or to anyone else. We also record when you were admitted and on what basis.
Profile
- Your display name, exactly as you typed it, and your bio.
- Your @handle, which we generate from your display name. It is public and cannot be changed.
- Your profile photo and the order you arrange your photos in.
- ⚠️ Sensitive information. If you answer the optional onboarding question, we store whether you say you are a member of the Church. If you add a ward, we store it — and a ward is both a religious affiliation and a geographic area. We never infer your location from your network or your device; a ward is stored only because you told us. Who can see these is controlled by your privacy settings.
What you create
- The text of your posts and replies, when you wrote them, and whether you edited them.
- Your photos, plus a display copy we generate.
- ⚠️ The description read aloud to screen-reader users for your photo is written by an AI model, not by you.
- Your likes, friendships and requests, blocks and mutes, and any reports you file, including the note you write.
Device and technical
- A push token for your device, if you allow notifications.
- ⚠️ We do not store your IP address — no Home Ward database or log holds one. It is, however, processed in passing: our gateway passes it to our services, where it is converted through a one-way function into a counter used for abuse limits. That counter cannot be turned back into an address, but we would rather say the address is handled than claim it never touches our systems.
- We do not collect a hardware or advertising identifier, and we do not record your browser or device user-agent.
3. Why we use it
- To run your account and show you the feed.
- To review content for safety before it is published (see below).
- To enforce the Community Guidelines.
- To limit abuse — rate limits and spam controls.
- To keep the service working, and to fix it when it breaks.
- To meet legal obligations, including child-safety reporting.
4. Automated safety review, and third-party AI
Everything you submit is checked before it appears. Some of that check happens at Anthropic, a separate company outside our cloud provider. Because that means sharing your content with a third party, we ask for that permission separately from the Terms, and you can decline it or withdraw it later in Settings.
| What is sent | To whom |
|---|---|
| A resized, re-encoded copy of your photo (about 512 pixels). The original never leaves our private storage, and the re-encode strips all embedded metadata, including any GPS location. | Amazon Rekognition (inside our AWS account) and Anthropic (outside it) |
| The text of your posts and replies. | Amazon Comprehend (inside our AWS account). Text detected as English is additionally sent to Anthropic; text detected as another language is not. |
| Your display name and profile text. | The same automated review as posts. |
The photo we send carries no name, email, account identifier or device information alongside it. Profile photos go through exactly the same review as post photos. Anthropic also writes the accessibility description for your photo on that same call.
If a photo matches a hash of known child sexual abuse material it is blocked and preserved without being sent to Rekognition or Anthropic, and the match is reported to the National Center for Missing & Exploited Children.
Names and details of other people that you write into a post go to these providers along with the rest of your text. Please think about that before writing about someone else.
5. Who else receives your information
| Recipient | What they get |
|---|---|
| Amazon Web Services | Hosting, storage, database, identity, queues, logs. Almost everything runs here. |
| Anthropic | Photo copies and English post text, for safety review. This is where your content leaves AWS. |
| Apple | Your device push token and one opaque identifier, when we send a notification. Push notifications carry fixed wording only — no sender name, no message text, no counts. |
| Datadog (US5) | Server performance traces and metrics, designed to carry no member content and no IP address. |
| Google Workspace | Our email is hosted with Google, so if you write to us — or we contact you after a safety concern — that correspondence and your email address pass through Google. |
| PhotoDNA / Thorn, and NCMEC | Photo hashes for child-safety matching, and reports of confirmed matches. |
| Law enforcement or regulators | Where we are legally required to respond, or where there is a risk to someone's life. |
You can stop every transmission to Apple's push service by declining the notification permission, or turning notifications off later in iOS Settings.
6. What we do not do
- We do not sell your personal information.
- We share nothing with advertisers, ad networks, data brokers or attribution vendors.
- We do not track you across other companies' apps or websites, and we show no App Tracking Transparency prompt because we have nothing to ask for.
- home-ward.com carries no analytics, advertising or tracking scripts of any kind.
7. Photos are served from public addresses
⚠️ This one deserves its own section. A photo that passes review is served from a public web address that anyone holding the link can open without signing in. The link is not signed, not time-limited and not restricted to your account, and the address contains your account identifier and the photo's identifier.
Deleting a post withdraws its photo from public delivery, and so does a ban.
8. How long we keep things, and what survives deletion
You can delete your account from inside the app. That removes your identity record, your data rows and your media. Some things deliberately survive, because deleting them would defeat a safety or legal purpose:
- Reports you filed and reports filed about you.
- Moderation and enforcement decisions, including the reason recorded.
- Preserved child-safety evidence, where the law requires it.
- A record that a banned account may not return, held as a one-way digest.
- Your acceptance of these documents — which version, and when. An acceptance record deleted exactly when it might matter proves nothing.
Records that survive are kept for the purpose that justified keeping them, not indefinitely for general use.
9. What we cannot yet do
Most privacy policies do not have a section like this. We would rather write one than imply capabilities we do not have.
- ⚠️ You cannot download or export a copy of your data. There is no export feature and none is planned before launch.
- ⚠️ Deleting your account does not erase every copy immediately. Our database backups keep restorable copies for the length of the backup window. That residue is not reachable through the product, but it is not zero.
- ⚠️ A few places deletion cannot reach. Notification entries naming you in other members' inboxes remain until they expire, up to 90 days. If a post or reply repeatedly fails safety processing, the message carrying it — including your text — sits in an internal error queue for up to 14 days. If you retry a request, we hold a copy of the answer we already gave you for 24 hours, which for sign-up includes your email address.
- ⚠️ Content sent to Anthropic may be retained by them for up to 30 days. We do not currently have a zero-retention arrangement in place.
- ⚠️ Amazon's service terms permit AWS to use content sent to some Comprehend features to improve those services. The personal-data-detection feature is excluded from that; language and toxicity detection are not.
- ⚠️ People who are not members. If someone appears in the background of a photo you upload, their image goes to our safety providers with the rest of the picture. They have no Home Ward account through which to ask us to erase anything, and we have no way to find them in our systems.
10. Your choices
- Change your display name, bio, and church-membership answer at any time.
- Control who sees your Friends list, your ward, and your church-membership answer.
- Block or mute another member.
- Grant, decline, or later withdraw the third-party-AI permission.
- Turn notifications off.
- Delete your account.
- Ask us about your information at legal@home-ward.com.
⚠️ Your @handle cannot be changed, and your date of birth cannot be edited after sign-up.
11. Children
Home Ward is for adults 18 and over. We do not knowingly allow anyone under 18 to hold an account, and we rely on the date of birth you give us — we do not verify it. If we learn an account holder is under 18 we will restrict or close the account. If you believe a child has an account, write to legal@home-ward.com.
12. Security
What we can say accurately:
- Connections between the app and our servers use HTTPS, and photos are delivered over HTTPS.
- Our database, uploaded files, cache and queues are encrypted while stored.
- Storage buckets block public access at the bucket level; none is browsable or listable.
- Database credentials are generated and rotated by AWS and fetched at run time — never written into our source code.
- Every API request must carry a valid sign-in token, checked at the gateway and again in the service that answers it. Our databases sit in a private network unreachable from the internet.
- Every moderation decision is written to a write-once record store, and every human decision is recorded against the reviewer who made it.
- Access to the cloud account holding member data requires a second factor at every sign-in.
- ⚠️ Home Ward is operated by one person. Only that operator, and the automated systems he configures, can reach member data. There is no larger staff to restrict access from — and equally, no separation of duties.
No service can promise it will never be breached, and we do not.
13. Changes
When this policy changes we publish a new version with a new effective date; we do not edit a version you have already been shown. Material changes are brought to you before you carry on using Home Ward.
14. Contact
legal@home-ward.com · ASTON VENTURES L.L.C., 354 N 360 E, Vineyard, Utah 84059.