Privacy Policy
Effective June 21, 2026
The YMYW App (“the App”) is a private communication and coordination tool used by leaders, parents, youth, and others affiliated with a specific Aaronic Priesthood quorum or Young Women class of The Church of Jesus Christ of Latter-day Saints. This policy explains what information we collect, why we collect it, and how it is handled. The App is operated by an individual volunteer (not by the Church) for the benefit of the participating ward.
What we collect
- Account information you provide when an administrator creates your account or you complete sign-up: name, phone number, email address, role (e.g., parent, youth, leader), and quorum or class affiliation.
- Authentication data: a hashed password (we never store the plaintext password), session cookies, and, if you opt in, biometric authentication state stored only on your device.
- Chat messages and photos you send within the App, along with associated metadata (timestamp, sender, thread, read-receipts).
- Activity participation data: RSVPs, attendance records, appointment bookings, and assignment status that administrators or you record within the App.
- Device push tokens issued by Apple Push Notification service or Google Firebase Cloud Messaging when you grant notification permission to the mobile app. These tokens identify your device for delivery of notifications and contain no personal information themselves.
- Basic usage diagnostics: pages visited, login timestamps, and error logs. This is used to see whether members are connected and to improve reliability, and is associated with your user account. We do not record your IP address or device type against your account, and these diagnostic records are automatically deleted after a limited retention period.
What we do NOT collect
- We do not sell, rent, or share data with advertisers.
- We do not collect precise device GPS location in the background.
- We do not collect health, financial, or biometric identifiers.
- We do not run third-party advertising or analytics SDKs (no Google Analytics, Meta SDK, etc.).
How we use your information
- To authenticate you and keep your session secure.
- To show you the activities, announcements, assignments, chat threads, and other content authorized for your role within your quorum or class.
- To deliver notifications to your device about new messages, announcements, reminders, and other events relevant to you.
- To allow leaders and other authorized adults to coordinate their work (e.g., view attendance, manage appointments).
- To diagnose errors and improve the App's reliability.
Third-party services
The App uses a small set of third-party services strictly necessary to function:
- Apple Push Notification service (APNs) and Google Firebase Cloud Messaging (FCM) — to deliver push notifications to your device. We send a notification title, short preview, and badge count.
- Expo Push Service (operated by 650 Industries, Inc.) — acts as a proxy to deliver our notifications to APNs and FCM. Notification content briefly transits Expo's infrastructure.
- Web hosting provider — the application is hosted on a dedicated virtual private server. Server access logs (IP address, request path, timestamp) are retained for a short period for security and debugging.
- Email and SMS delivery providers — used to send account-related notifications (password resets, reminders, invitations) when you have opted in.
We do not authorize these providers to use your data for their own marketing.
Children's privacy
The App is intended for use by ward members, including youth ages 11–18 with parental or guardian permission. We collect only the information necessary to operate the App, and we do not sell personal information or use it for advertising.
For youth accounts, a parent or guardian provides consent from their own logged-in account on the Family privacy & consent page. A parent or guardian can, at any time, from that same page:
- Review what consent is on file for each linked child.
- Revoke their consent.
- Request deletion of all of their child's data; a ward leader reviews and permanently removes the account.
You can also reach us at the address below for any request. Activity photos are automatically deleted after two and a half years (sooner on request).
How long we keep your data
We retain account, chat, and activity data for as long as you have an active account in the App, or as needed to comply with legal or recordkeeping obligations. Diagnostic records (login timestamps, error logs, and notification/email delivery logs) are automatically purged on a rolling retention schedule rather than kept indefinitely. When an account is deleted, associated personal data is removed from the active database within a reasonable period.
Your rights
You may:
- Request a copy of the personal data we hold about you.
- Request correction of inaccurate data.
- Request deletion of your account and associated data.
- Revoke notification permissions at any time via your device settings, or sign out of the App at any time.
For day-to-day questions, please contact your local ward administrator (your bishop, YM/YW president, or whoever holds the relevant calling) — that's usually the fastest path. For formal data requests under this policy, send a message to For privacy and other queries, take the second word of this sentence, then the at-symbol, then the domain markj, then a period and the country code us, to form the contact address..
Security
Data in transit is protected by TLS. Passwords are stored as bcrypt hashes. Access to administrative features is restricted by role. However, no system is perfectly secure; please use a strong password and notify us promptly if you suspect your account has been compromised.
Changes to this policy
We may update this policy as the App evolves. Material changes will be communicated in-App or via the email address on file. The “effective” date at the top of this page reflects the most recent revision.
Contact
For day-to-day questions, contact your ward administrator (your bishop, YM/YW president, or whoever holds the relevant calling). Formal data requests under this policy may be sent to For privacy and other queries, take the second word of this sentence, then the at-symbol, then the domain markj, then a period and the country code us, to form the contact address..