Threshold

Privacy

Threshold is in active development. A complete privacy policy will land here before the product opens to paid use. The notes below summarize current behavior. They are not yet a binding legal document.

What Threshold collects

  • Your email address (for sign-in via magic link).
  • Information you enter about your church: name, type, location, attendance averages, ministry owners, assessment answers, tasks, meetings, decisions, retrospectives, and pastoral notes.
  • Files you upload to the Facility area: building plans and documents such as contractor quotes, permits, and photos. A building plan, or a quote you explicitly choose to read with AI, is sent to Anthropic's Claude API (see below). Other documents are stored privately and not sent anywhere.
  • Standard server logs (IP address, user agent) for the duration required by the hosting provider.

Where it's stored

  • Application data: Supabase (managed Postgres, encrypted at rest).
  • Authentication: Supabase Auth (encrypted at rest, sessions issued as signed JWTs).
  • Facility documents (building plans, contractor quotes, permits, photos): stored privately in Supabase Storage, readable only by your church's members through short-lived signed links. When you read a building plan or a quote with AI, that file is streamed through the Threshold server to Anthropic's Claude API. Anthropic does not train on API submissions but may hold them up to 30 days for abuse monitoring per their data policy.

Who can see it

Each church's data is restricted to members of that church via Postgres row-level security. Threshold operators can access data through the Supabase dashboard for support and debugging. Data is never sold or shared with third parties beyond the infrastructure providers above.

Deleting your data

You can delete an individual church (and all of its data) from the church's settings. You can delete your entire account from Settings. Account deletion removes your sign-in record, your church memberships, and any pastoral notes you authored.

Records deleted inside a church work differently. When a leader deletes a record from your church (a person, a goal, a task), that record can be restored by the church for 30 days. After 30 days it is removed permanently. The window exists so an accidental deletion is not final.

Deleting a church and deleting your account are not covered by that window. Both remove the data straight away, with nothing held back for recovery.

If you want a record about you removed immediately instead of waiting out the 30 days, write to support@threshold.vision and we will erase it on request.

Questions

Until a final policy is published, contact the operator directly with privacy questions.