Privacy Policy
Effective July 18, 2026 · Last updated July 18, 2026
What Gods WURC is
Gods WURC (World Unified Religion Companion) is a spiritual and wisdom reflection product. You can journal what is on your mind, receive retrieved passages and a synthesized reflection anchored in a worldview you choose, and optionally listen to a spoken Voice Prayer reflection. The product does not claim divine authority and does not replace scripture, clergy, therapy, medical care, legal counsel, or emergency services.
You may use Begin Reflection as a guest without creating an account. Signing in enables private saved reflections and account preferences across devices.
Account sign-in
When you sign in, authentication is handled by Supabase Auth using one of these methods:
- Google Sign-In
- Facebook Login (when enabled)
- Email magic link (one-time sign-in link)
Gods WURC does not receive or store provider passwords. We never ask for your Google, Facebook, or email-account password.
Depending on the provider and what you allow, we may receive:
- Email address
- Provider name (for example Google or Facebook)
- Provider user identifier
- Basic profile information the provider supplies (such as a display name), when available
Facebook Login currently requests only public_profile and email. We do not request friends, pages, posts, messages, birthdays, photos, Instagram data, or advertising data.
If Facebook does not return a confirmed email, sign-in cannot be completed for that Facebook account. You can continue with Google or an email sign-in link instead.
What we store when you use the product
- Reflection / journal text you submit to Begin Reflection
- Generated responses and related request metadata needed to serve and improve the product
- Saved reflections / history when you are signed in and auto-save is on (default for signed-in users)
- Account preferences, including the auto-save setting and basic profile fields
- Voice Prayer source records and private audio objects generated for your account (per-user; not shared with other users)
- Feedback you choose to submit
- Technical, security, and operational diagnostics such as request identifiers, error classes, and limited operational events. Crisis-related audits are redacted where the product is designed to do so.
Guest use may still process journal text for that session without creating a lasting signed-in profile.
Processors and infrastructure
We use Supabase for authentication, database storage, and private object storage. When AI synthesis or speech generation is enabled, relevant text may be processed by OpenAI under OpenAI's terms. Hosting is provided through our production web host (currently Vercel).
These providers process data to deliver the service. We do not sell your journal text or account identity.
Privacy defaults and controls
Saved reflections on your account are private to your signed-in account by default. Auto-save of successful reflections is on by default for signed-in users; you can turn it off in Account.
You can:
- Delete individual saved reflections from Account
- Disable auto-save
- Delete your entire account (see Data deletion)
Retention
We keep account and saved-reflection data while your account exists, or until you delete specific items. After account deletion we remove account records, saved history, preferences, owned Voice Prayer sources and their private audio objects, and the Auth identity for that account, as described on the Data deletion page.
Limited anonymized or disassociated operational, safety, or backup records may remain for security, abuse prevention, or ordinary backup expiry. We do not promise instant erasure from every backup copy or every downstream processor cache.
Security
We use industry-standard hosting and access controls, including encrypted transport (HTTPS) and row-level access rules for user-owned data where the database is configured for them. No online service can guarantee perfect security. Protect your email and provider accounts, and sign out on shared devices.
Minors
Gods WURC is intended for adults. It is not directed at children under 13, and we do not knowingly create accounts for children under 13. If you believe a child has provided personal information, contact us using the method below so we can review deletion.
International processing
Infrastructure providers may process data in the United States or other countries where they operate. If you use the product from another region, your information may be processed outside your home country.
Policy updates
We may update this policy as the product changes. The last-updated date at the top of this page will change when we do. Continued use after an update means you have had a chance to review the revised policy.
Contact
For privacy questions, data-deletion help when you cannot sign in, or other account concerns, open a private-as-possible request via GitHub Issues. Include the email on the account (if known), the sign-in provider you used (Google, Facebook, or email), and approximate dates of use. Never include passwords, OAuth tokens, or Facebook credentials.

