Legal
Privacy Policy
Effective September 25, 2026. Supersedes the version dated September 20, 2026.
Cordline is a communication platform for missionaries, ministry organizations, and the people who support them. This policy explains what we collect, why we collect it, who else sees it, and what you can do about it.
We have tried to write it plainly, and to describe what our software actually does rather than what a policy template usually says. Where something is unusual — the writing assistant, the security tiers, the information we hold about people who never signed up — we have said so rather than leaving it implied.
1. Who we are
Cordline Inc. — referred to below as “Cordline”, “we” and “us” — of 12636 High Bluff Drive, Suite 400 - 7024, San Diego, CA 92130. You can reach us at support@cordline.app.
Cordline Inc. is the company responsible for the information described in this policy. It is a for-profit company, not a charity.
2. Information you give us
Account information. Your name and email address, and — if you turn on text notifications — your mobile phone number. Signing in is handled by Clerk. If you sign in with Google, we receive your name, email address, and profile image from Google. If you sign in with Apple, we receive your name and email address from Apple — and if you take Apple’s option to keep your address private, what reaches us is a forwarding address Apple creates for you rather than your own. Apple does not give us your real address, and that is the address your account carries.
Ministry profile, if you are a missionary or an organization. A display name, a written biography, a location description you type yourself, an organization affiliation, a family photograph, milestones and posting goals, and a link to your own giving page.
Content you create. Posts, photographs and videos, prayer requests, direct messages, comments, and reactions.
Information that reveals religious or philosophical belief. Cordline exists to connect missionaries and ministry organizations with the people who support them, so a great deal of what it holds is about faith — prayer requests, posts about the work, and the simple fact of which missions a person follows. We would rather name that as a kind of information we collect than leave it implied inside “content you create”. Collecting it is required, not optional. Following a ministry creates a record that you support that ministry, and without one you cannot read that ministry’s updates at all. You can look through ministries before you follow any — what the record unlocks is the thing Cordline is actually for. For a missionary or an organization it is the substance of what they publish.
Family details, if you choose to add them. The names, relationships, and birthdays of family members you list on your ministry profile. This is optional, and you can remove it at any time.
Support conversations. Crisp powers our support chat on the web and in the mobile app. When the chat loads in your browser or the app — and, when you send a message, as part of the conversation — Crisp receives your IP address and browser or device information, from which an approximate, city-level location can be derived. If you are signed in, we also share your name, email address, and account role, so the conversation starts with context.
Reports. If you report a post, a comment or a message as objectionable, we store which piece of content you reported, the category you chose, anything you write in the description, and the fact that the report came from you.
Requests you send from this website. If you ask for a demo or write to us through our contact form, we store the name, email address, phone number, organization, and message you submit, and we email a copy of it to ourselves. You do not need an account to do this, and we do not create one for you.
3. Information we generate
Usage and engagement. Which posts you have opened, when you last viewed your feed, and activity records used to build it. We also calculate engagement scores — a numerical summary of how recently and how often an account has been active — on a nightly schedule. They are used inside the product to decide which prompts and suggestions to show you.
Device and diagnostic information. Device model, operating system version, app version, and — when something goes wrong — an error report. Error reports are handled by Sentry and can include the account identifier of whoever hit the error.
Delivery records. Whether an email, text message, or push notification was sent, delivered, or failed.
4. What we do not collect
We do not collect your device location. The Cordline apps never ask for location permission and contain no location-tracking code. The only location information we hold is the location description a missionary or organization types into their own profile — a city and country, for example — which is something they wrote, not something their phone reported. Separately, some tools we embed from other companies — for example, our support chat — receive your IP address, from which an approximate, city-level location can be derived; that is different from your device reporting its precise location, which we never collect.
We remove location metadata from photographs and videos. Cameras often record the exact coordinates of a photograph inside the image file itself. Photographs are stripped of that metadata before they leave your device or browser, and videos are re-packaged on your phone to remove it before upload. This matters most for missionaries and organizations whose safety depends on their location not being published, so it is applied to everyone rather than offered as a setting.
We do not recognize faces. Our photo tool can find that a face is present in a picture so you can blur it before posting. That detection runs on your own phone or in your own browser. No face template, geometry, measurement, or other face identifier is calculated, stored, or sent anywhere. The location of a box on the image is sent to our server so the blur can be applied to the stored copy, and it is not kept as face data. The tool can tell that a face is there. It cannot tell whose face it is, and we hold nothing that could be used to work that out later.
We do not track you across the web, and we run no analytics. We use no advertising cookies, no cross-site trackers, and no analytics service of any kind — not on this website and not in the app. The only cookies we set are the ones that sign you in and keep the site working. Because we set nothing else, there is no cookie banner to click. If that ever changes we will update this section first.
We do not sell your information. We have never sold personal information and we do not disclose it to anyone for their own advertising or marketing. The companies listed in section 9 process information on our instructions, for the purposes described there, and for nothing else.
5. Information about people who are not our users
Some information in Cordline describes people who do not have accounts and never agreed to anything. We would rather name that plainly than leave it implied.
Children and family members. A missionary may list family members — including children — with names, relationships, and birthdays, and may post photographs of them. It is shown to that missionary’s approved supporters at the visibility level they have chosen. A missionary who would rather not share family details should simply not add them; the feature is optional and can be cleared at any time.
People you invite. When you invite someone to follow a ministry, we hold the email address and any phone number you gave us. Until they accept, that person has no account and no relationship with us. An invitation that is accepted, or withdrawn, stays in that ministry’s record of who it invited rather than disappearing — write to us if you want yours removed.
People who appear in content. Someone may be named in a post or a prayer request, or appear in a photograph. We do not identify people in photographs, and we provide the blurring tool described in section 4 so faces can be obscured before posting.
People named in a report. A report about objectionable content is written by one person about another, and its description can name someone who has no account at all. It is held as part of our record of what was reported and what we did about it.
People who write to us. A demo or contact request from this website is information about someone who is not a user.
If you believe Cordline holds information about you and you do not have an account, write to support@cordline.app and we will find it and remove it.
6. How we use information
To run the platform and show each person the content they are entitled to see. To send the notifications you have asked for. To provide the writing assistance described in section 7. To screen posts, comments, messages and prayer requests for prohibited terms before they are published, and to review reports and act on them. To find and fix faults. To protect accounts and content from unauthorized access. To meet our legal obligations.
7. Phoebe, our writing assistant, and what it sees
Cordline includes a writing assistant called Phoebe. We want to be specific about it, because it is the part of the product where your content leaves our own systems.
What it does. Phoebe helps draft posts, suggests updates when something notable is coming up, summarizes recent activity, and answers questions about your ministry.
Turning it on. Phoebe and the other AI features are off until you turn them on. Nothing you write is sent to Anthropic unless you have switched AI on; the setting is enforced on our servers, not just hidden in the app, and you can switch it back off at any time in your settings.
Where the processing happens. Phoebe is built on Anthropic’s Claude API — Anthropic is the company that makes Claude, and the API is how our software asks it for a draft. To answer, we send Anthropic the context needed for that particular request. Depending on the feature, that can include your posts, your ministry profile and biography, your milestones and posting goals, the names and dates of family members you have listed, and the recent history of your conversation with Phoebe. We send it so that Anthropic can produce the response, and we ask nothing else of them. Our agreement with Anthropic does not permit them to train their models on it. We have also not opted into the arrangements that would allow it: the option to share conversations as feedback is switched off, and we are not part of their development-partner programme. Anthropic keeps its own copy of what we send for a limited period, so that it can watch for misuse of its service, and then deletes that copy. That is Anthropic’s retention, not ours — how long Cordline keeps your conversations with Phoebe is in section 12, and the two are not the same.
Your writing style. Cordline builds a description of how you write, from your own posts and from any writing samples you upload, and refreshes it on a weekly schedule. It is stored in our own database — not Anthropic’s — and is included with your requests so that drafts sound like you. It is used for your ministry alone and never for anyone else.
Whose writing it draws on. The description is built only from the writing of people who have AI turned on. Each weekly update draws on posts by members who have turned it on; a co-manager who has not turned AI on has their posts left out, and any writing samples you upload yourself count only if your own AI is on. If you turn AI off, the writing description Phoebe has learned is reset for every ministry you help manage, and rebuilt from scratch using only the writing of people who still have AI on.
Whose choice it is. Each person controls AI for their own account: whether your posts and messages are sent to Phoebe depends on your choice, not anyone else’s. In a ministry managed by more than one person, a co-manager who has not turned AI on has their own posts and messages left out, even when others have turned it on — Phoebe only processes content whose author has agreed to it. Separately, on a ministry at our highest security tier Phoebe is unavailable to everyone: enforced on our servers, the assistant refuses to run and the weekly writing-style job skips the ministry.
Automatic screening of what you upload. To keep prohibited material off Cordline, images you upload — and the first frame of any video you upload — are automatically checked by an image-screening service (Amazon Rekognition) the moment you post, and a post can be refused if it fails that check. Full-length video is not screened frame by frame. This check runs on everyone’s uploads and is not something you turn on or off. If a post is wrongly refused, write to support@cordline.app.
What we do not do. We do not use your content to train our own models, and we do not sell it to anyone.
8. Security tiers, and who can see what
Some missionaries and organizations serve where being publicly identified is dangerous. Several parts of this product exist for them, and it is worth understanding how visibility works before you post.
Security tiers. A ministry can be set to a higher security tier, which changes whether it can be discovered by people who are not already supporters, how much of it is visible outside the approved circle, and which features are available — including turning Phoebe off entirely. If this matters for where you serve, set it when you create your profile rather than afterwards.
Who sees a post. Posts go to a ministry’s approved supporters, or to a group of them if the author chose one. Supporters see posts from before they joined only within a limited window. Co-managers of a ministry see what the ministry sees.
Your sending organization. If your sending organization partners with Cordline, the people it designates as administrators can see information about the ministries affiliated with it. There are two levels. Senior leadership sees organization-wide totals only, and nothing about any individual. A care-team administrator sees, for each ministry:
- Your name and your co-manager’s name, your ministry’s display name, and the location you typed into your own profile. If you have not given us a name, what they see is the part of your email address before the @.
- Your security tier.
- When you joined, when you last posted, and how many posts you have published in each of the last twelve weeks.
- How many prayers and comments your posts received, how many supporters you have, and how many of them have been active recently.
- Notes their own staff write about supporting you. Those notes belong to them, not to you — there is nowhere in Cordline where you can read them.
This applies at every security tier, including the highest. We would rather say that plainly than let you discover it. A higher tier changes who outside your organization can find you or see your work; it does not hide you from the organization that sent you. That organization arranged your placement and chose where you serve — it already holds your name and your location. Cordline is not disclosing anything to it that it does not already have, and the tier is still doing its job everywhere else.
What your organization cannot see. Not the content of your posts. Not who your supporters are — we count them without ever resolving a name or an address. Not your family details, your posting goals, your milestones, or anything from your conversations with Phoebe. None of that is available at any tier, and there is no way for an administrator to send you a message through Cordline.
One ordinary exception: if someone at your organization is also a supporter you invited yourself, they see your posts the way any supporter does — through the invitation you sent them, not through the organization’s dashboard.
Comments and prayer requests. When you comment on a post or send a prayer request, it goes to the missionary or organization whose post it is, and to anyone who co-manages that ministry. Other supporters do not see it: each supporter’s conversation on a post is their own thread, and the ministry sees them all.
Reports and blocks. A report is private. The person you report is not told that you reported them, nothing on the content shows that it was reported, and you cannot see anyone else’s reports. If a ministry blocks a supporter, any direct-message conversation between them closes for both of them — neither can open it again — though we keep it, and our staff can still read it if a report or a dispute requires it.
Cordline’s own staff. We can reach your information when running the service requires it — investigating a fault, looking into a report of abuse, or complying with the law. That includes being able to view the app as you see it, which is how we diagnose a problem that appears on one account and nowhere else. Access is limited to the people who need it for those purposes, and it is not a licence to read private messages out of interest.
Photographs and videos. Media is delivered from a content-delivery network by direct file address. Anyone who is given that address can open the file, whether or not they are a supporter — so a photograph forwarded outside the circle is outside it for good. This is the same as most of the web, and it is the reason a higher security tier is a better protection than any single setting.
9. Who else receives information
We use the following companies to run Cordline. Each receives only what it needs, processes it on our instructions, and is not permitted to use it for its own purposes.
| Company | What it does for us | What it receives |
|---|---|---|
| Supabase | Our database and file storage | All stored platform data |
| Clerk | Signing in and account security | Name, email address, phone number, sign-in activity |
| Cloudinary | Photograph and video storage and delivery | Uploaded photographs and videos |
| Amazon Web Services | Automatic screening of uploaded images and video first frames for prohibited content | Uploaded images, and the first-frame image of uploaded videos |
| Anthropic | Phoebe, the writing assistant | The content described in section 7 |
| Resend | Email delivery | Recipient address, message content, and any images in a post digest |
| Twilio | Text message delivery | Phone number and message text |
| Sentry | Error and crash reporting | Device and diagnostic information, account identifier |
| Crisp | Support chat on the web and in the mobile app | Conversation content, name, email address, account role; and — like any embedded web tool — IP address, approximate (city-level) location, and browser/device information |
| Sign-in with Google, and Android push notifications | Sign-in identity; device push token and notification content | |
| Apple | Sign in with Apple, and iOS push notifications | Sign-in identity; device push token and notification content |
| Expo | Building the mobile app and relaying notifications | Push tokens and notification content |
| Vercel | Hosting our website and application | All requests to our services |
| Stripe | Payments, where someone contributes to Cordline — see section 10 | Payment details, handled by Stripe directly |
A push notification can contain the beginning of a post or a message, so the companies that deliver notifications can see that text in transit.
We also disclose information when the law requires it. If Cordline Inc. is ever acquired or merged, we will tell you before your information moves.
10. Giving
Gifts to a ministry do not pass through Cordline. When you choose to give, we send you to that ministry’s own giving page, run by them or by their organization. We do not see, hold, or handle that money, we are not told what you gave, and no payment information reaches us.
Contributions to Cordline itself are a separate thing. Cordline is free for missionaries, organizations, and supporters. We also provide a way to support the platform itself, which we may open or close at different times. If you use it, that payment is processed by Stripe: Stripe handles your card details rather than us, and we hold only a record that the contribution was made.
We make no representation about tax deductibility. Cordline Inc. is a for-profit company. Whether a gift to a ministry is deductible depends entirely on that ministry’s own status — ask them, or ask your tax advisor.
11. Text messages
If you turn on text notifications, you are agreeing to receive text messages from Cordline at the number you gave us. Message frequency varies, and message and data rates may apply. Reply STOP to any message to opt out, or turn text messages off in your settings. Reply HELP for help.
These are the text-message terms for both this policy and our Terms of Service — the terms do not restate them.
12. How long we keep information
We keep information for as long as it is needed for the purpose we collected it for, and then we delete it. Your account and the content you create are kept while your account is open.
Records we keep only for a while. Notifications, records of which posts you have viewed, activity records used to build your feed, and delivery records for email and text messages are all cleared automatically on a routine schedule — they are useful for a limited period and then they are not.
Photographs and videos. Media you delete is removed from storage automatically. When you use the face-blurring tool, the unblurred original is removed once the blurred version exists.
Two things we currently keep indefinitely. Draft suggestions from Phoebe that you neither used nor dismissed, and your conversation history with Phoebe, have no set expiry today. We would rather tell you that than imply one that does not exist.
Product feedback. If you report a problem to us, we keep your message and any screenshots you attach so we can investigate and fix it. These can outlive your account, because a screenshot is often what lets us reproduce the problem.
Safety records. Reports, our record of what we did about them, and the record of any content our staff removed are kept without a set expiry, because they are how we answer a later question about a decision we made. The record of a removal holds what was removed and when — not a copy of the content itself.
Demo and contact requests. A request you send us from this website is kept until we no longer need it for the conversation you started. Ask us and we will delete it.
When you close your account. Your profile and personal details are removed. What you wrote — posts, comments, prayer requests and messages — stays where it is with your name removed, because it is part of other people’s record too: deleting your side of a conversation would tear a hole in theirs. If you were the only person managing a ministry, the ministry and its posts are removed with your account; if someone else manages it too, they keep it and it carries on without you. If a ministry has blocked you, that record is kept so the block continues to hold. If you sent us feedback about a problem, your message and any screenshots you attached are kept too, so we can still fix what you reported.
13. Your choices and rights
You can see and change most of your information in your account settings, on the web and in the app.
A copy of your data. You can download a copy of your data from your account settings, as a file, without asking us. If you run a ministry it includes the ministry’s content as well as your own.
Changing your email address. You can change it in your account settings, on the web and in the app. We send a verification code to the new address first, so an address you cannot reach cannot become the key to your account. If you are locked out of both addresses, write to support@cordline.app.
Closing your account. You can close your account yourself in settings, and our account-deletion page explains what that removes and what stays. If you cannot sign in, write to support@cordline.app and we will do it for you. Section 12 describes what happens to your content either way.
Depending on where you live, you may also have rights to see, correct, delete, or receive a portable copy of your information, and to object to some processing. Write to support@cordline.app and we will respond within the time the law allows. We will not treat you differently for asking.
14. Children
Cordline is not intended for anyone under 13, and we do not knowingly create accounts for them. Section 5 describes the information about children that an adult may add about their own family.
15. International users
Cordline is operated from the United States by Cordline Inc. Information is stored and processed there, and by the companies listed in section 9. Missionaries and organizations using Cordline often serve outside the United States: if you use Cordline from another country, your information will be handled in the United States, where the laws are not the same as your own.
16. Changes to this policy
When we change this policy we post the new version here, update the effective date, and record what changed in the list at the end of this page. If a change materially affects how we use your information, we will tell you by email or in the app before it takes effect.
17. Contact
Write to support@cordline.app, or to Cordline Inc., 12636 High Bluff Drive, Suite 400 - 7024, San Diego, CA 92130.
Version history
This document is version-controlled. Each version records what changed from the one before it.
September 25, 2026
- Said in section 7 that Phoebe and the other AI features are off until you turn them on, and that this is enforced on our servers rather than only in the app.
- Said in section 7 that AI consent is per person: whether your own posts and messages are sent to Phoebe follows your choice, and in a ministry managed by more than one person a co-manager who has not turned AI on has their own content left out. This replaces the earlier statement that there was no separate per-account switch.
- Said in section 7 that the writing-style description is built only from the writing of people who have AI turned on, and that turning AI off resets that description for every ministry you help manage, which is then rebuilt from the writing of people who still have AI on.
- Described in section 7 the automatic screening of uploaded images and video first frames for prohibited content, and named the provider (Amazon Web Services) in the list of companies in section 9.
- Said in section 12 that feedback you send us about a problem, and any screenshots you attach, are kept to investigate and fix it, and can outlive your account.
September 20, 2026
- Corrected how we describe Crisp, our support-chat provider: it powers chat on the web as well as in the mobile app, and — like any embedded web tool — it receives your IP address and browser or device information, from which an approximate, city-level location can be derived.
September 1, 2026
- Rewritten in full against an enumeration of the codebase rather than from memory.
- Named every company that receives information — thirteen, where the previous version named five.
- Added section 7, describing the Phoebe writing assistant, what is sent to Anthropic, and how the writing-style profile is built.
- Added section 5, on information about people who do not have accounts, including family members and children.
- Added section 8, describing security tiers, who can see a post, how private a comment or prayer request is, and how photographs are delivered.
- Said in section 8 exactly what a sending organization’s administrators can see about a ministry affiliated with them, that it applies at every security tier, and what they cannot see.
- Said plainly in section 8 that Cordline staff can reach your information when running the service requires it, including viewing the app as you see it.
- Covered reporting, blocking and automatic screening of content, and what each of them records.
- Said which content stays when an account closes — comments, prayer requests and messages as well as posts — rather than naming posts alone.
- Named signing in with Apple alongside Google, and what Apple’s keep-my-address-private option means for the address we hold.
- Named information that reveals religious or philosophical belief as a kind of information we collect, and said plainly that collecting it is required rather than optional: without a record that you follow a ministry, you cannot read that ministry’s updates.
- Said in section 7 that our agreement with Anthropic does not permit them to train their models on what we send, and that the training-adjacent options are switched off.
- Replaced "as long as your account is active" with what we keep, why we keep it, and that we delete it when it is no longer needed for that purpose.
- Separated gifts to a ministry from contributions to Cordline, which are processed differently and are not tax-deductible.
- Said that we run no analytics at all, replacing a claim that we used privacy-friendly analytics — we use none.
- Removed the claim of "regular security reviews".
- Described what is done about location metadata in photographs and videos.
- Covered demo and contact requests sent from this website.
- Named the contracting party consistently as Cordline Inc., defined once and referred to as Cordline thereafter.
July 6, 2026
- First published version.