Use the platform with care
- Use data only when your organisation has authority and a lawful, clearly explained purpose.
- Never use communications, payments, AI, or integrations to deceive, exploit, harass, or cause harm.
- Children, vulnerable people, pastoral records, and safeguarding information require heightened care.
- Plan allowances are enforced; attempts to evade them or degrade the Service are prohibited.
This Acceptable Use Policy (AUP) forms part of the Terms of Service and applies to every use of TheFaithApp, including church administration, member and public experiences, communications, giving, AI-assisted tools, uploads, APIs, webhooks, and integrations.
1. Scope and responsibility
You are responsible for your users, content, recipients, integrations, and activity. You must use the Service only for lawful purposes, follow applicable provider rules, and maintain the permissions, consents, notices, safeguards, and professional oversight appropriate to your organisation and jurisdiction.
If a connected provider’s rules are stricter, you must comply with them as well. If you cannot satisfy both sets of requirements, do not use that provider through TheFaithApp.
2. Prohibited activities and content
You must not use the Service to create, store, publish, send, facilitate, fund, or promote:
- illegal activity, fraud, scams, deception, money laundering, sanctions evasion, or terrorist financing;
- sexual exploitation or abuse, child sexual abuse material, grooming, trafficking, or content that endangers a child or vulnerable person;
- credible threats, incitement to violence, targeted harassment, stalking, coercion, or hateful conduct against people based on protected characteristics;
- malware, ransomware, credential theft, phishing, malicious redirects, or instructions intended to compromise systems or people;
- content or activity that infringes intellectual-property, privacy, publicity, confidentiality, or other rights;
- false impersonation, fabricated authority, misleading fundraising, manipulated receipts, or deliberate misrepresentation of a church, charity, campaign, beneficiary, or use of funds;
- regulated goods, gambling, weapons, controlled substances, adult services, or other restricted activity unless it is lawful, relevant to legitimate ministry operations, accepted by every connected provider, and approved by us in writing where requested; or
- any activity designed to exploit, intimidate, shame, discriminate against, or improperly profile a member, donor, volunteer, visitor, employee, or beneficiary.
3. Data protection and confidential records
- Collect only data you need for a defined and explained purpose.
- Do not import purchased, scraped, unlawfully obtained, or unauthorised lists.
- Do not expose pastoral care, prayer, safeguarding, health, giving, child, credential, or private formation records to people without a need and permission to see them.
- Use the designated restricted workflows for sensitive records rather than general notes, public pages, campaigns, or unrestricted chat.
- Honour access, correction, deletion, objection, consent withdrawal, retention, and legal-hold requirements that apply to you.
- Do not use TheFaithApp as the sole record or response mechanism for an emergency, safeguarding investigation, medical need, or other situation requiring specialist systems or immediate professional action.
4. Security and technical abuse
You must not:
- access another account, tenant, record, endpoint, or secret without authorisation;
- probe, scan, penetration-test, reverse engineer, bypass controls, or exploit a vulnerability without our prior written permission;
- interfere with availability, overwhelm infrastructure, distribute denial-of-service traffic, or run abusive automated workloads;
- scrape, harvest, mirror, or bulk-extract content or personal data except through authorised export or API functions for a lawful organisational purpose;
- share credentials, publish tokens, disable security controls, conceal malicious origins, or knowingly connect a compromised integration;
- upload malicious files or use the Service to distribute code that is deceptive, destructive, or unauthorised; or
- circumvent permissions, moderation, safety controls, metering, product access, or plan allowances.
Report suspected vulnerabilities through the contact in our security.txt. Do not access or retain personal data beyond what is needed to demonstrate the issue safely.
5. Email, SMS, WhatsApp, push, voice, and messaging
Before sending a communication, you must have the authority and consent or other lawful basis required for that recipient, channel, content, and jurisdiction. You must:
- identify the sender honestly and avoid deceptive subjects, caller identity, links, or content;
- respect channel preferences, quiet hours, opt-outs, unsubscribe requests, STOP requests, and suppression lists promptly;
- avoid spam, excessive frequency, list bombing, cold outreach to purchased contacts, and messages likely to cause harm or distress;
- use approved templates, sender identities, registrations, and provider routes where required;
- protect confidential content and use a safer channel when ordinary email, SMS, or notification previews are inappropriate; and
- comply with applicable electronic-marketing, telecommunications, and campaign laws.
6. Children, youth, and safeguarding
Features can support—but do not replace—your safeguarding policy, trained leaders, background checks, reporting duties, emergency procedures, or local professional advice. When minors or vulnerable people are involved, you must:
- record and verify guardian authority or another lawful basis where required;
- limit access to approved people and keep roles, training, and safeguarding status current;
- use supervised group communication and never try to bypass restrictions on one-to-one or disappearing messages involving minors;
- use verified check-in, pickup, emergency, and incident processes appropriate to the setting;
- avoid publishing identifying, location, health, family, or safety information without proper authority; and
- contact emergency services or the relevant safeguarding authority when a real-world risk requires it.
7. Giving, fundraising, registrations, and payments
You may use connected payment services only for lawful activity your organisation is authorised to conduct. You must:
- describe the organisation, campaign, beneficiary, restrictions, and intended use of funds accurately;
- keep appropriate records and provide receipts, cancellation information, refunds, or disclosures required by law;
- never use a donor’s payment method beyond the permission given or manipulate recurring-giving authority;
- respond to disputes, chargebacks, fraud reviews, know-your-customer requests, and provider enquiries honestly and promptly;
- comply with charity, tax, fundraising, anti-money-laundering, sanctions, consumer, and payment rules that apply to you; and
- follow the current prohibited and restricted activity rules of Stripe, PayPal, Flutterwave, banks, and any other connected provider.
8. AI, transcription, analytics, and automation
You must provide human review and must not use an AI-assisted, scoring, analytics, or automated feature to:
- make a final safeguarding, employment, eligibility, discipline, medical, mental-health, legal, financial, or similarly high-impact decision about a person;
- diagnose, rank, shame, manipulate, or infer sensitive traits about members or communities;
- generate impersonation, deceptive media, fabricated testimony, false evidence, or content presented as fact without review;
- submit data you are not permitted to disclose to the configured provider; or
- remove source context, required warnings, review steps, or privacy boundaries built into the feature.
9. Fair use, limits, and platform integrity
Use must stay within the product access and numeric allowances attached to your plan and add-ons. You must not inflate activity, create fake members, split one church across accounts, rotate identities, script repetitive actions, or use other means to avoid a limit. We may rate-limit, queue, pause, or require coordination for unusual workloads that threaten reliability, security, provider rules, or other customers.
10. Investigation and enforcement
We may investigate suspected violations and preserve relevant evidence. Depending on seriousness and urgency, we may warn the account owner, require remediation, remove or restrict content, disable a feature or integration, rate-limit activity, suspend users or the account, terminate service, notify a connected provider, or report conduct where the law requires or permits it.
Where doing so would not increase risk or conflict with law, we will give notice and a reasonable opportunity to respond. We consider context, severity, repetition, intent, impact, and remediation. You may ask support to review an enforcement decision.
11. Reporting concerns
Report suspected abuse, unsafe content, fraud, or a policy violation to support@thefaithapp.com. Include the relevant church, URL or record, date, and enough context to investigate, but do not email unnecessary sensitive information.
12. Changes to this AUP
We may update this AUP as the Service, risks, provider requirements, or law change. We will update the date above and give reasonable notice of a material change. Continued use after the effective date is governed by the updated AUP.