Privacy Policy

Last updated: May 29, 2026

Version: 2026-05-29

This Privacy Policy explains how Arship ("Arship", "we", "our", or "us") collects, uses, discloses, and safeguards information when you use the Arship mobile application (the "App") and any related services. By using the App, you agree to the practices described here. If you do not agree, please do not use the App.

Contents

  1. Information We Collect
  2. How We Use Your Information
  3. Legal Bases for Processing (GDPR / UK GDPR)
  4. How We Share Your Information
  5. Service Providers (Sub-Processors)
  6. Data Retention
  7. Security
  8. International Data Transfers
  9. Your Rights
  10. California Residents (CCPA / CPRA)
  11. EU / UK Residents (GDPR / UK GDPR)
  12. Children's Privacy (COPPA)
  13. Voice Recordings and Biometric Information
  14. Push Notifications
  15. Changes to This Policy
  16. How to Contact Us

1. Information We Collect

We collect only the information needed to run the App and the features you use. The categories below mirror the information actually stored by the App's backend systems.

1.1 Account & profile information

1.2 Team and content data

1.3 Technical identifiers used to operate the App

1.4 Information collected when a parent creates a child account

1.5 What we do not collect

2. How We Use Your Information

We use the categories above to:

If you are located in the European Economic Area or the United Kingdom, we rely on the following legal bases under Article 6 of the GDPR / UK GDPR:

4. How We Share Your Information

We share information only as needed to run the App. We do not sell your information, do not share it for cross-context behavioral advertising, and do not transfer it for any unrelated commercial purpose.

5. Service Providers (Sub-Processors)

The following providers process information on our behalf:

ProviderPurposeData categories
Google LLC — Firebase & Google Cloud (Authentication, Cloud Firestore, Cloud Storage, Cloud Functions, Cloud Messaging)Account hosting, app data storage, audio storage, server-side logic, push notification delivery, basic loggingAll categories listed in Section 1, including audio recordings, chat content, identifiers, IP addresses
Apple Inc. — Sign in with Apple, Apple Push Notification serviceAuthentication (if you choose Apple), push notification delivery to iOS devicesEmail (sometimes relayed via Apple's private-relay), push token, basic device identifiers
Google LLC — Google Sign-InAuthentication (if you choose Google)Email, display name, profile photo (if you provide one)
Resend, Inc.Transactional email delivery (account verification, parental notices, consent confirmations, age-out notices, account deletion confirmations)Email address, message content (which may include your or your child's display name and account state)

We do not use advertising networks, analytics SDKs, or trackers in the App.

6. Data Retention

We keep information only as long as is reasonably necessary for the purposes described above, or as required by law.

7. Security

We use industry-standard security measures provided by Google Firebase, including TLS encryption in transit, encryption at rest, server-side access rules, custom claim–based role enforcement, and abuse-detection (App Check) in our production environment. We restrict server-side access to the smallest necessary set of operators. Despite reasonable safeguards, no system is perfectly secure; we encourage you to use a strong unique password and to enable platform-level account protections.

If we become aware of a security incident that affects your information, we will notify you and any required regulators consistent with applicable law.

8. International Data Transfers

The App is operated from the United States. If you access the App from outside the United States, your information will be transferred to, stored in, and processed in the United States and other jurisdictions where our service providers operate. Where required, we rely on the European Commission's Standard Contractual Clauses (or the UK International Data Transfer Addendum) as a transfer mechanism.

9. Your Rights

Subject to applicable law, you (or, for a child account, the supervising parent) have the right to:

To exercise rights other than those directly available in-app, contact us at support@arship.app. We aim to respond within 30 days, and in any event no later than 45 days where a longer period is permitted.

10. California Residents (CCPA / CPRA)

If you are a California resident, you have the rights described in Section 9 above (Right to Know, Right to Correct, Right to Delete, Right to Data Portability), plus the right to opt out of the sale or sharing of your personal information. Arship does not sell personal information and does not share personal information for cross-context behavioral advertising. For children under 16, California law requires affirmative opt-in for any sale; because we do not sell information, no opt-in is required, and we will not begin selling without first asking.

Categories of personal information collected, by CCPA category: identifiers (email, display name, user ID, device ID, push token, IP address); commercial information (account type / status); audio and other electronic information (voice recordings, chat messages); user content (songs, setlists, notes, attachments); sensitive personal information limited to date of birth (used solely to determine adult / minor status). We disclose categories of personal information to the service providers listed in Section 5 strictly for the business purposes described in Section 2.

We do not knowingly use or share sensitive personal information for purposes other than those identified in California Civil Code §1798.121(a). To exercise a California right, email support@arship.app; you may also use an authorized agent (we will verify the authorization).

11. EU / UK Residents (GDPR / UK GDPR)

The data controller for the App is Arship (contact details below). The legal bases for our processing are described in Section 3. You have the rights described in Section 9, including the right to lodge a complaint with your local supervisory authority (in the UK, the Information Commissioner's Office).

12. Children's Privacy (COPPA)

Arship may be used by children under 13 only when a parent or legal guardian creates the account on the child's behalf, with verifiable parental consent under the U.S. Children's Online Privacy Protection Act ("COPPA") and accompanying FTC rule (16 C.F.R. Part 312).

12.1 Personal information collected from children

12.2 How a parent provides consent

The parent must first create their own adult Arship account, verify their email, and complete a recent-reauthentication step. Within the App, the parent reviews:

Each of these documents is versioned; we record which version the parent accepted, when, and a one-way hashed reference to the parent's email for audit purposes. The parent is rate-limited to a small number of child-account creations per day to deter misuse.

12.3 Disclosure of a child's information

A child's recordings, chat messages, and contribution records are visible to other current members of the child's worship team (whom the parent has consented to). They are not shared publicly, are not used for advertising, and are not sold. Our service providers (Section 5) process this information on our behalf under written agreements.

12.4 Parent's rights at any time

Use Parent Controls in the App for the most direct path, or email support@arship.app.

12.5 Automatic transition at age 13

When a child reaches their 13th birthday, the account is automatically migrated to a standard account: parental controls relax, password sign-in is enabled, and the parent is notified by email. Records of the parental-consent period are retained as described in Section 6.

12.6 If we learn we have collected information from a child without consent

If we discover that a child under 13 has created an account without verifiable parental consent, we will promptly delete that account and its associated personal information.

13. Voice Recordings and Biometric Information

We do not use voice recordings to identify or authenticate users. Voice recordings are used solely for the team-rehearsal purpose for which you created them, and are visible only to current members of the team you placed them in. We do not run voice-print extraction, speaker identification, voice cloning, or voice-based behavioral profiling on your recordings, and we do not allow third parties to do so on our behalf.

Voice recordings are retained until you delete them, leave the team, or delete your account; see Section 6.

14. Push Notifications

The App requests permission before sending push notifications. You can revoke notification permission at any time from your device's system settings; in addition, the App's settings allow you to disable specific notification categories. When you allow notifications, your device's push token (FCM / APNs) is stored against your account so that the notification can be delivered to that device.

15. Changes to This Policy

We may update this Privacy Policy from time to time. We will update the "Last updated" and "Version" dates at the top of this page and, for material changes that affect how we collect or share information from a child account, we will notify the supervising parent by email and require renewed consent before continuing the affected processing.

16. How to Contact Us

If you have any questions, requests, or concerns about this Privacy Policy or our handling of your information, please contact us at:

Email: support@arship.app