Privacy Policy for Ministry (미니스토리)





Effective date: August 13, 2026


App name: Ministry (미니스토리)


Android package name: com.devjian.ministry


iOS bundle identifier: com.devjian.ministry.ios


Developer: devjian


Contact: rlawldks3753@gmail.com





This Privacy Policy explains how Ministry (“the App”, “we”, “us”, or “our”) accesses, uses, stores, shares, retains, and deletes data.





SUMMARY





Ministry stores ministry or service records locally on the device by default. Google sign-in, Firebase server backup, friend sharing, contact-based friend discovery, maps, advertising, remote configuration, and purchases are optional network features. This policy explains what those features process and how users can delete an account and server data.





1. DATA STORED LOCALLY





The App helps users manage ministry or service activity, time, goals, schedules, notes, interested-person records, return visits, studies, custom fields, reports, stopwatch history, maps, routes, and media.





These records are stored in the App's private local database and storage by default. The App may access location when a user starts a location or route feature, contacts when a user opens optional contact-based friend discovery, and files or media selected by the user.





Local data remains until the user deletes individual records, uses the reset function, clears the App's storage, or uninstalls the App. Files exported or shared by the user remain at the destination selected by the user.





Users are responsible for entering and managing information about other individuals appropriately and for respecting their privacy.





2. OPTIONAL GOOGLE OR APPLE SIGN-IN AND FIREBASE FEATURES





On Android, a user may choose Google sign-in. On iOS, a user may choose Google sign-in or Sign in with Apple. These optional sign-in methods enable Firebase server backup and friend-sharing features. Signing in is not required to use local record features.





When a user signs in, Firebase Authentication may process the Firebase user ID, Google account email, display name, profile image, authentication tokens, and sign-in metadata.





If a signed-in user enables server backup or friend sharing, Firebase Cloud Firestore may store:





• Firebase user ID, display name, profile image or user-selected profile image, profile color, friend code, and hashed account email;


• friend and follower relationships, selected badge identifiers, route-distance summaries, and daily distance totals;


• up to three encrypted server backups. The App encrypts backups using AES-GCM before upload, and server backups do not include attached media;


• hashed email or phone values used for optional contact-based friend discovery.





For contact-based friend discovery, the App reads contacts only after permission is granted, normalizes email addresses or phone numbers, and hashes them on the device. The lookup sends hashes to Firebase. Raw contact names, email addresses, and phone numbers from the address book are not uploaded.





3. ADVERTISING





The Android App uses Google Mobile Ads SDK to show one adaptive banner in a dedicated area above the People screen. The iOS App shows one adaptive banner at the top of the Interested Ones screen only and does not request ads on Settings or other screens. Both apps disable publisher ad personalization and send non-personalized ad requests. Where required, Google's User Messaging Platform obtains or manages consent before ads are requested. The iOS App updates consent information on each launch, waits until UMP allows ad requests, and provides a privacy-options entry point in Settings > Data when required. The iOS App does not call ATTrackingManager and does not show an App Tracking Transparency prompt.





Google Mobile Ads may process IP address, device or advertising identifiers, ad interactions, App interactions, and diagnostic information for ad delivery, measurement, security, and fraud prevention under Google's policies.





Ministry records, interested-person records, notes, routes, contacts, and backup contents are not supplied to the advertising SDK for targeting.





4. OTHER SERVICES





Maps and geocoding


When a user uses map, location, tile, or geocoding features, service providers may receive network information and the map, coordinate, or address request needed to provide the feature.





Google Play Billing and Apple In-App Purchase


Optional purchases are processed by Google Play or Apple. The App receives purchase status needed to provide the support or tip experience and may retain local purchase-count or support state. We do not receive full payment card details.





Remote configuration


The App may contact a Cloudflare Worker to check minimum-version, notice, and update information. Cloudflare may process IP address, request time, and normal network metadata. Ministry records, interested-person records, notes, media, routes, and backup contents are not sent in this request.





User-directed export and sharing


When a user exports or shares data, it is sent only to the destination selected by the user, such as a file provider, email, messaging app, or cloud storage service.





5. PURPOSES AND SHARING





Data is used to provide requested App features, authenticate the user, create and restore backups, support friend sharing and discovery, display maps and non-personalized ads, process optional purchases, prevent abuse, troubleshoot failures, and respond to support requests.





We do not sell personal data. Data is shared only with processors needed for a feature selected or used by the user, including Google Firebase, Google Mobile Ads and UMP, Google Play, Apple, map or geocoding providers, Cloudflare, and destinations selected by the user.





6. RETENTION AND SECURITY





Firebase retains the account and associated server data while the account exists. The App automatically limits server backups to the three newest backups.





Account deletion removes the Firebase Authentication identity, server backups, profile, friend-sharing relationships, contact index hashes, badge identifiers, and route-distance summaries controlled by the App.





Support and deletion-request correspondence may be retained for up to one year after resolution. Limited records may be retained longer where required for legal obligations, dispute resolution, security, or fraud prevention.





Copies exported, shared, or stored by third parties are governed by the destination and cannot be deleted by the App.





Network requests use encrypted HTTPS transport. Server backup archives are encrypted by the App before upload. No security method can guarantee absolute protection, so users should protect their devices and exported files.





7. ACCOUNT AND DATA DELETION





Delete the Firebase account and server data inside the App





Open:


Settings > Data > Server Backup > Delete account and server data


설정 > 데이터 > 서버 백업 > 계정 및 서버 데이터 삭제





Confirm the warning. The App permanently deletes the Firebase Authentication account and the associated server data, then signs out on the device. This action cannot be undone. It does not delete records stored locally on the device.





Request deletion without the App





1. Email rlawldks3753@gmail.com with the subject “Ministry account deletion”.


2. Send the request from the email address used for Google or Apple sign-in, or include that account email in the message.


3. We may request a limited verification step to protect the account. Verified requests are completed within 30 days.





The following data is deleted:





• Firebase Authentication account and Firebase user ID;


• encrypted server backups and backup metadata;


• profile name, email hash, profile image, profile color, and friend code;


• friend and follower relationships, contact index hashes, badge identifiers, route-distance summaries, and daily route-distance data.





Local records remain on the device so that deleting an online account does not unexpectedly erase offline ministry records.





Delete local data





Open:


Settings > Data > Reset All Data


설정 > 데이터 > 모든 데이터 초기화





Users can also delete individual records, clear Ministry's storage in Android settings where available, reset local data in the App, or uninstall the App. Original gallery media and exported, emailed, shared, or third-party copies must be deleted from their own locations.





8. PERMISSIONS





Location permission is used only for user-selected current-location, map, address selection, and route tracking features.





Contacts permission is used only when the user opens optional contact-based friend discovery. Raw address-book data is not uploaded.





Notification permission is used for user-enabled reminders, stopwatch notifications, and route-tracking foreground service notifications.





File and media access is used when the user selects media, imports or exports files, or shares data.





Internet and network access is used for optional Firebase features, maps, advertising, purchases, and remote configuration.





On Android, advertising identifier permissions may be used by Google Mobile Ads. On iOS, the App does not request App Tracking Transparency permission; however, Google Mobile Ads may process device or advertising identifiers under Google's policies for non-personalized ad delivery, measurement, security, and fraud prevention.





9. CHILDREN, INTERNATIONAL PROCESSING, AND CHANGES





The App is not directed to children, and we do not knowingly collect children's personal information. If you believe a child has provided personal information, contact us so that we can address the request.





Service providers may process data in other countries under their terms and applicable safeguards.





We may update this policy when App behavior or legal requirements change. The effective date above identifies the current version.





10. CONTACT





Questions, privacy requests, and deletion requests may be sent to:





rlawldks3753@gmail.com