Stake Admin App
Stake Admin App ("we," "our," or "us") is a mobile application designed to help Latter-day Saint stake leadership manage callings, meetings, and organizational tasks. This Privacy Policy explains how we collect, use, and protect your personal information when you use our app.
Stake Admin is an independent tool for local leadership coordination. It is not officially affiliated with, endorsed by, or sponsored by The Church of Jesus Christ of Latter-day Saints.
When you create an account, we collect:
To enable stake administration features, we collect:
Because ward or branch membership, callings, priesthood ordination records, and leadership assignments can reveal religious affiliation or beliefs, we classify this organizational data as Sensitive Information for app-store privacy disclosures.
Calling & Release Workflow: Names of individuals being called or released, calling details and workflow status, sustaining votes from authorized leaders, extension and set-apart records.
Priesthood Ordination Tracking: Ordination candidate information, interview assignments and completion records, and ordination ceremony details.
Meetings & Assignments: Meeting schedules and attendance, speaking and prayer assignments, action items and follow-up tasks.
Unit Directory and Directions: Stake Admin stores unit meeting locations, building addresses, and any building-photo URL entered by an authorized leader. Stake Admin does not automatically send unit addresses to Google Maps or another map provider to find building photos. If you choose Directions, Stake Admin passes that address to your device's maps app or the map website you select; that provider handles the request under its own privacy policy.
Search: Search text you submit is transmitted to our authorized search service to return app records and meeting passages you are permitted to access. First-party global-search analytics records query length and result metadata, not the search text itself; previous-meeting search does not intentionally retain the search text, and B.O.B. questions are handled as described below.
Recordings, Transcripts, and AI Features: If you choose to record a meeting or use an AI-assisted feature, we collect the audio or prompt you provide, meeting and recording metadata, transcripts, and generated summaries, topics, decisions, action items, speaker labels, or other notes. We use this information to provide recording playback, transcription, review, search, and meeting follow-up. Only the content needed for the feature is sent to the service that performs it. Recording transcription may use Groq, Deepgram with a per-request model-improvement opt-out, or OpenAI Whisper, depending on the configured path and fallback; Google Gemini may perform recording analysis, speaker resolution, and embedding work. AssemblyAI is disabled unless optional speaker-diarization processing is separately configured under a verified account/plan no-training or model-improvement opt-out bound to the exact deployed API key. Meeting analysis, retrieval, and B.O.B. may send the transcript, your question, and the authorized meeting, handbook, or app context needed to answer it to Google Gemini, OpenAI, or Groq. Talk-preparation coaching sends the coaching conversation and topic you provide to Anthropic Claude. Production user requests are not sent to DeepSeek. These providers are not all used for every feature or request.
Calendar: We store calendar and appointment information created in Stake Admin, such as titles, dates, times, locations, descriptions, organizers, participants, visibility, and calendar-feed subscriptions. If you choose to add an event to a device calendar, Stake Admin reads available writable calendars and sends the selected event to your device operating system or calendar provider. A calendar subscription URL contains a private bearer token. Anyone who obtains that URL can request the read-only feed without signing in to Stake Admin, so treat it like a password. Regenerating the link immediately invalidates the old token; you must update any connected calendar app. Calendar providers may cache the feed URL or event copies under their own policies, so regenerating or deleting a Stake Admin feed cannot remove copies already imported into another calendar.
Bug Reports and Screenshots: A report may include its title and description, the current screen or route, account, stake and role context, reporter email, comments, and technical metadata. The report flow may prepare a screenshot of the current app screen for you to review before submission, and you may choose another screenshot or photo from your device. Submitted screenshots are stored privately and shown through short-lived authorized links to the reporter where applicable and to approved support administrators.
Usage and Diagnostics: We collect first-party usage and reliability events linked to your account or stake, such as your user ID, stake ID, calling or role, permission level, screens visited, session timing, feature and workflow usage, load timing, repeated taps, recording-upload health, and limited B.O.B. question text and response metadata. First-party crash and performance diagnostics may include device, operating-system and app-version information, routes, stack traces, and performance data. Current builds restrict Sentry to sanitized JavaScript exception types, source filenames and line numbers, and static platform/app-version metadata. Sentry does not receive exception messages, request data, breadcrumbs, attachments, dynamic routes, account identifiers, email, stake, unit, calling, role, permission level, native crash envelopes, sessions, replay, or performance traces. Older app builds may have attached account, stake, and role context until they receive the privacy update.
Scripture Study Progress: Verses you choose to memorize, practice attempts, and mastery levels.
Push Notifications: Device push notification tokens and notification preferences.
We use collected information to:
Your organizational information is visible to authorized stake leaders based on role-based permissions. For example:
Supabase (Database & Authentication): Stores the app's core database records, authentication data, and selected files, and manages user authentication.
Google Cloud (Recording Processing and Storage): Cloud Run processes configured recording and analysis jobs. Google Cloud Storage may store authorized recording archive or playback copies.
Resend (Email Delivery): Delivers account, workflow, support, reminder, and other transactional emails. It receives the recipient email address, name when used in the message, and the message content needed for delivery.
Expo (Push Notifications): Delivers push notifications to your device.
OAuth Providers: Google Sign-In and Apple Sign-In handle authentication. We receive only your email and name from these services.
Sentry (Crash Monitoring): Processes sanitized JavaScript exception types and source locations plus static platform/app-version metadata so we can diagnose failures; current builds exclude user content, organizational data, native crash envelopes, sessions, replay, and performance traces.
Transcription and AI Providers: When you use recording, transcription, B.O.B., or another AI-assisted feature, only the audio, transcript, prompt, or related context needed for that feature may be processed by the configured provider for that request. No one provider receives all of your app data, and these providers are not all used for every feature. Google Gemini: recording analysis, speaker resolution, and retrieval or embedding work for meeting and app-help features. Groq, Deepgram, and OpenAI Whisper: active recording transcription paths and fallbacks, as configured for the recording pipeline; Deepgram requests include a per-request model-improvement opt-out. AssemblyAI: optional speaker diarization only when that separate processing path is configured under a verified account-level no-training or model-improvement opt-out; otherwise the integration remains disabled. OpenAI: B.O.B. generation when the configured OpenAI model is selected, and the OpenAI Whisper transcription fallback described above. Anthropic (Claude): talk-preparation coaching messages and the topic you provide to that coaching feature. DeepSeek: production user requests are not sent to DeepSeek. Provider retention and handling are governed by the applicable provider terms and policies; shared meeting records and transcripts remain subject to the retention rules below.
We do use first-party product analytics and the service providers described above to operate, secure, troubleshoot, and improve Stake Admin.
We implement security measures including:
Account and user-scoped operational data are retained while your account is active and are removed or detached as described below when account deletion completes.
Shared or stake-owned organizational records may remain after an account is deleted, including meeting agendas and history, attendance, calling or ordination history, action items, calendar events, recordings, transcripts, AI-generated notes, and support records. Account references are detached or anonymized where supported. These shared records remain until an authorized user deletes them or they are no longer needed to provide the service, preserve the shared record, address security or support issues, or meet legal obligations.
Source audio used to process a recording is generally scheduled for deletion approximately 10 days after creation. Authorized playback or archive copies, transcripts, and generated notes may remain with the shared meeting record until that record is deleted or no longer needed. Crash, support, and security records are retained only as long as reasonably needed to diagnose, resolve, and document the related issue. Provider backups and caches may clear on their own retention schedules. Calendar feed tokens remain active until you disable or regenerate the feed. Regeneration invalidates the old bearer URL, but it cannot erase copies already cached or imported by an outside calendar provider.
Access and Correction: You can view and update your profile information through the app's settings screen.
Push Notifications: You can disable push notifications through the app's notification preferences or your device's system settings.
Calendar: You can deny or revoke calendar access in your device settings. Events already added to another calendar must be managed through that calendar provider.
Account Deletion: In the app, sign in, open More, select Delete My Account, review the notice, enter DELETE, and select Delete Account. If you are the only active administrator for a stake, the app may require another active administrator to be assigned first.
If you cannot complete the in-app process, visit Delete your Stake Admin account or email support@stakeadmin.app. Do not send your password. We may request information reasonably needed to verify that the account belongs to you. Deleting the app from your device does not delete your account.
Stake Admin is intended for adult leadership use. The app is not intended for anyone under 18 years of age, and we do not knowingly collect personal information from minors.
None. We do not track users across apps or websites.
None declared. A crash or performance diagnostic captured before sign-in may lack Stake Admin account, stake, or role context, but it can still include device or network details. We therefore conservatively classify diagnostics as linked to you for App Store privacy-label purposes.
For questions about this Privacy Policy or to exercise your data rights, contact:
Email: support@stakeadmin.app