Privacy, Terms and Refunds
This is a pre-legal-review draft. It describes how Veil actually operates today so you can make an informed decision. It does not mean a lawyer has reviewed it or that every statutory disclosure is final.
Privacy and personal records
Veil keeps account data and personal records (confessions, journals) separate by default. A personal record is not church data. A church administrator or pastor cannot read the text of your entries simply because you are a member of that church.
This is enforced by the database schema rather than by policy alone: the table used for reviewing flagged confessions has no user id column at all, so a reviewer cannot look up who wrote an entry even if they wanted to.
What we collect
| Data | Purpose and timing | How it is handled |
|---|---|---|
| Account identifiers | Sign-up, sign-in, sync across devices | Email, display name, auth identifier — minimum necessary |
| Adult status | Eligibility for the free public beta | We record only confirmation that you are 18 or older, not your full date of birth |
| Confessions, gratitude, quiet-time entries, journals | Only for features you chose to use and save | Encryption at rest and access control on the server is the product standard |
| Personalised-reflection input and response | When you run the on-device reflection | Processed on your device; only records you choose to save are sent to account storage |
| Consent and billing history | Proving what you chose, providing the subscription, resolving disputes | Version, timestamp, per-item choice, payment identifiers |
Storage, retention and deletion
- Local browser storage is used as an encrypted convenience cache only. It is not treated as the sole original store for your records.
- Free or paid, you must be able to view, export and delete your own past entries.
- The current in-app deletion control removes personal records from
user_dataand reading progress. It does not yet delete the Supabase Auth account, church membership, shared church content or provider backups. Full account deletion and a verified backup-deletion period remain launch work; request help by email in the meantime. - Veil does not store raw card numbers. Payment methods are tokenised by the payment provider.
Subprocessors
This is the complete list of external processors Veil relies on. Churches evaluating Veil may submit this table as-is.
| Processor | Purpose | Data shared | Location |
|---|---|---|---|
| Supabase | Authentication, sync and storage of saved records | Account identifiers, records you chose to save | United States |
| Vercel | Website and API hosting | IP address, request metadata | Global edge, primarily US |
| Google Sign-In (OAuth) | Account creation and sign-in when you choose it | Email, profile name, unique identifier | United States |
| Stripe | Subscription payment, tax calculation, invoicing | Email, billing address, tokenised payment method | United States, Ireland |
| getBible | Serving public-domain Scripture text | Only the book and chapter requested. No user identifiers | Outside Korea |
| Hugging Face | Serving the MIT-licensed local semantic-search model files | IP address and ordinary request metadata for model-file GETs. Confession, prayer, journal text and search queries are not included | United States and other locations |
| PostHog | Product analytics. Loaded only when both a key and optional service-improvement consent are present | Page views, clicks, and text-free reflection signals: document ID, locale, confidence band, selected fit and reason. Confession, prayer and journal text is never sent; session replay is disabled | United States |
Operator safety-monitoring boundary
The reflection and abuse-prevention log do not send confession text. The device derives only minimal self-harm, violence and abuse booleans, separated from identity; operators see those signals and encryption or processing state, not the original. Text you deliberately attach to a support request, or a separate legal obligation, follows that separate submission and audited-access scope.
Sign-up and consent
Required
- Processing the personal data needed to provide your account and the service.
- Storing and processing sensitive faith and counselling-related records.
Optional — off by default
- Using adult records and AI responses for quality evaluation and service improvement.
- Receiving marketing messages.
Optional items are unchecked by default and are stored separately from required items. Signing up with Google follows the same gate: you must confirm adult status and both required consents before the redirect happens. Social sign-in is not a way around consent.
Age
Account creation and use of the free public beta are limited to people aged 18 or older. We record only adult confirmation, not a full date of birth. Veil does not currently offer a minor church-invitation or guardian-consent flow.
Local personalised reflection and safety
The personalised reflection is produced on your device from a versioned corpus using BM25, an MIT-licensed multilingual-e5-small semantic model, structural reranking and fixed response composition. On first use the quantised model may be downloaded and cached; your writing is not included in that request and is not sent to an external model provider.
The English response library is an early draft. The Korean library is written and reviewed by people. The English one was drafted on 2026-08-09 and has not yet been reviewed by a pastor. Scripture in it is quoted from the World English Bible, which is in the public domain. Treat responses as a starting point for prayer, not as counsel, diagnosis or crisis support.
Veil is not a substitute for medical, psychological or emergency services. If you are in danger or considering harming yourself, contact your local emergency number or a crisis line immediately.
Terms of use
Nature of the service
Veil is a devotional tool in public beta. Features may change or be withdrawn. Veil does not represent any single denomination; its convictions are Reformed.
Your account
- Keep your credentials secure and do not share your account.
- Do not use Veil to harass others, to upload another person’s private information, or for anything unlawful.
- We may suspend an account for abuse, after which you may request your data under the rights section below.
Scripture text
Korean Scripture is quoted from the Korean Revised Version (개역한글판, 1961), whose economic copyright expired on 2011-12-31 and which is therefore in the public domain. English Scripture is quoted from the World English Bible, which is in the public domain. Veil does not reproduce translations that require a paid licence.
Payment, cancellation and refunds
Veil does not accept paid subscriptions during the free public beta. Plus, Community and Growth amounts shown on pricing pages are planned prices, not current offers. Before paid access opens, the payment-provider agreement, business registration, tax handling and final cancellation/refund terms must be completed and disclosed.
- Planned prices on English pages are shown in USD. Applicable VAT or sales tax and the final total must be disclosed before any future checkout.
- If a price cannot be charged in the currency shown, checkout fails with a clear message and you are not charged in a different currency.
- No recurring subscription or paid period is started by joining the current public beta.
- Billing period, amount, renewal date and the effect of cancelling are shown before checkout.
- If a payment is cancelled or fails, the subscription is not activated.
- Detailed withdrawal, partial refund and renewal-cancellation terms will be finalised and disclosed before checkout once the payment provider agreement and business registration are complete.
- Refund enquiries: support@veildaily.com
Your rights (access, correction, deletion, portability)
What Veil holds — confessions, prayers and records of faith — is information about religious belief. It is a special category of personal data under GDPR Article 9, dado sensível under Brazil’s LGPD, Sensitive Personal Information under California’s CPRA, and sensitive information under Korea’s PIPA. Veil processes it only on the basis of your explicit consent.
These rights are offered to every user, regardless of where you live.
- Access — request a copy of the records held for your account.
- Correction — ask us to correct inaccurate information.
- Deletion — the current control deletes personal records from
user_dataand reading progress. It does not yet delete your Auth account, church membership, shared church content or provider backups. Email us for a scoped request; we will not describe it as full account deletion until that path and the backup period are verified. - Portability — export in a machine-readable format.
- Withdraw consent — optional analytics and marketing consents can be changed in the Korean settings UI or by email. Withdrawal stops future optional processing and records the withdrawal time; it does not undo processing that already happened.
- Object or restrict — object to processing for a particular purpose.
- Automated decisions — Veil makes no automated decisions producing legal or similarly significant effects. An AI meditation is reference text generated because you asked for it; it is not counselling or a diagnosis.
Use the privacy and data-rights contact path. We aim to respond within 30 days. Please write from your account email so we can verify it is you.
International transfers
Veil’s infrastructure (Supabase, Vercel) and its AI and payment processors are located outside South Korea, primarily in the United States. Using the service transfers the data listed in the subprocessor table to those countries, for the purposes stated there.
Where data of EU or UK residents is transferred, Veil relies on the transfer mechanisms offered by each processor, such as Standard Contractual Clauses. Veil has not yet appointed an EU representative under GDPR Article 27. One will be appointed before Veil actively markets to EU users. We are disclosing this rather than leaving it unsaid.
If you would prefer that no transfer occur, you can use Veil without creating an account, or stop using it. Screens that work without an account do not send your writing to a server.
Data Processing Addendum for churches
Where a church determines the purposes and means of processing personal data through Veil, the church may act as controller and Veil as processor. We provide an English public-beta DPA template and a Korean draft for contract review.
The parties must complete their identities, scope, retention period and governing law and obtain appropriate legal review before signing. Publishing the template does not by itself form an agreement.