Data & Privacy Specifications

1. Do we collect data?

Yes — but only the data that a user deliberately provides.

This includes:

  • Account registration details (name, email)

  • Atonement step entries (the answers users write into the forms)

  • Login activity (standard WordPress log records)

  • Mutual acceptance connections (only yes/no status)

We do NOT collect:

  • Background tracking

  • Third-party behavioral data

  • Hidden analytics

  • Sensitive personal information unless the user intentionally writes it

HDOA only stores the minimal data needed to provide the Atonement Journey experience.

2. Who can see the conversations or entries?

No one other than the user.

The Atonement Steps are entirely private.

  • Admins cannot read users’ step entries.

  • Connections do not reveal personal notes or messages.

  • There is no open messaging system except mutual-acceptance-based communication, which users must opt into.

You (site owner) cannot see their notes, their reflections, or their internal journey logs.

The system is built with a “private journaling” model.

3. Can other members see my data?

No.

Other members only see what you explicitly share — example:

  • If you accept their invitation

  • If you manually send a message (only possible after mutual acceptance)

There is no browsing, no directory, and no ability to “look up” other users’ private content.

4. Does the website share or sell data?

Absolutely not.

HDOA does not sell, rent, trade, or share user information with any organization, including religious institutions, nonprofit entities, or government agencies.

5. Is anything public?

No.

  • All Atonement steps

  • User dashboard

  • Connection status

  • Certificates

    are private and only visible to the account holder.

The entire Atonement Journey is designed for self-reflection, not social networking.

6. How secure is the data?

HDOA uses industry-standard WordPress security:

  • SSL encryption (https)

  • Database encryption at the server level (handled by hosting platform)

  • Restricted admin roles

  • No external data processors except hosting + email provider

  • No third-party plugins that read content (Front End PM was removed entirely)

Your custom HDOA plugin stores reflections privately and does not include logging functions or admin-visible content.

7. Can HDOA staff read or monitor conversations?

No.

There is no backdoor, inbox viewer, or admin access to any user’s private notes.

The only things admins can see:

  • User account exists

  • Status of steps (completed vs not completed)

  • That two users are mutually connected (no message content)

 

8. What happens if someone deletes their account?

When a user deletes their account:

  • All personal entries

  • All Atonement reflections

  • All private notes are permanently removed and cannot be restored.