On this page
Start with a question, not an SDKSeparate the purposesA smaller event can still answer the questionReview chat with an explicit boundarySession replay and hidden collectionRegional and evidential boundariesMeasure usefulness without scoring the soulInterface optionsSources and limits8-minute guide · Editorial guidance
Learn without surveilling spiritual life
Choose useful metrics while protecting chats, prayers and reading histories.
A useful starting point
Collect the least sensitive evidence that can inform a specific product decision.
Ask: What is the least sensitive evidence that could answer the question?
Start with a question, not an SDK
“Where does playback fail?” is a product question. “What does this person confess?” is a very different collection. Define the decision, minimum data, access, retention and deletion before enabling automatic capture.
Prayer text and conversations may contain religious beliefs, health information, sexuality, family circumstances or third-party details. Reading searches, group membership, recordings and annotations also deserve scrutiny. A pseudonymous identifier does not make a history anonymous.
Separate the purposes
Scroll the comparison sideways to see all options.
| Purpose | Prefer | Keep separate or exclude |
|---|---|---|
| Reliability | Error category, app version, latency bucket and a short-lived diagnostic identifier | Prompt bodies, transcripts, tokens, keys, raw URLs and private notes in error logs |
| Usability | Minimal events tied to a defined question; coarse or aggregate results where sufficient | Automatic collection of every tap, field, passage and persistent identity |
| Answer-quality review | A user-selected excerpt with preview, clear purpose and restricted access | All conversations flowing into a general analytics dashboard |
| Safety operations | A separately governed process with access, retention and escalation rules | Reusing safety flags for conversion, advertising or faith scoring |
| Model improvement | A distinct decision with truthful explanation of use and available choices | Treating ordinary chat use or product analytics consent as blanket training permission |
| Marketing | Declared channel preferences and campaign-level reporting where appropriate | Targeting offers from inferred vulnerability, confessions or private spiritual doubts |
A smaller event can still answer the question
Illustrative event design
Question: does the new player reduce failed starts?
Candidate data: playback-start result, error category, app version and network class. Aggregate promptly; set a justified short retention window.
Exclude: prayer text, chat message, named user, precise location and passage history unless separately necessary and justified.
Even this minimal schema is not automatically anonymous or exempt from consent requirements. Inspect SDK enrichment, IP handling, device identifiers, crash attachments and vendor onward use. A privacy label is only credible if the actual payload matches it.
Review chat with an explicit boundary
- A person chooses “Report this answer”; show the specific messages and attachments to be included.
- Offer removal of personal details and explain who reviews the report, why, and for how long.
- Keep content-quality review distinct from a request for urgent help. Do not imply a report is continuously monitored.
- Restrict staff access and audit access to sensitive content. Plan deletion across application storage, logs, vendors, backups and derived datasets as applicable.
- Explain what deletion can and cannot achieve, including any lawful retention and limitations of already-used training data. Do not promise instant erasure you cannot perform.
Redaction can miss indirect identifiers, quotations and third-party details. Prefer synthetic test conversations for routine development and evaluation. If real samples are necessary, establish a separate justified process instead of quietly widening the analytics stream.
Session replay and hidden collection
Disable replay on chat, prayer journals, pastoral support, payment details and credential entry by default. Verify masking of rendered answers as well as inputs, clipboard content, accessibility labels, network requests and error attachments. A vendor’s default masking needs testing.
CNIL’s February 2026 consultation identifies privacy risks in session replay. The reviewed document is a draft consultation, not a verified final rule. The conservative defaults here are this library’s design proposals.
Regional and evidential boundaries
ICO guidance identifies religious beliefs and health as special-category data and explains when intended inferences or differential treatment trigger that classification. Not every Bible-page visit automatically establishes a belief, but inferred “faith stage” or vulnerability profiles need particular scrutiny. UK requirements are not interchangeable with every jurisdiction.
ICO guidance also treats email tracking pixels separately from permission to send the email. Apply the regional research to the whole data flow: app, analytics vendor, model provider, support tooling and exports.
Measure usefulness without scoring the soul
Combine task success, reliability and voluntary interviews. Ask about understanding and pressure without demanding intimate testimony. Report uncertainty and include people who decline research. A completed prayer, positive sentiment or longer chat is not a validated measure of spiritual maturity.
Review question: can the team answer its next decision with less data, a shorter retention period or participant-led research?
Sources, review scope and limits
- What is special category data?Categories and inference guidance reviewed · Context and processing intent matter; not every Bible-page visit automatically establishes a belief.
- Session replay: consultation on a draft recommendationConsultation overview reviewed · Draft consultation, now closed; final adoption was not established by this review.
- Electronic mail: data protection and tracking pixelsData protection, vulnerability and pixel sections reviewed · UK guidance; consent to email is not a universal answer to analytics requirements.
- Digital Spiritual Formation: The Aperto Vision · selected Draft 4 reviewSelected sections on reading, engagement, multimodal and communal formation, incentives and honest assessment reviewed 5 October 2026 · Not an effectiveness study. Full bibliography and manuscript are not published or comprehensively reviewed here.
Take this into a product decision
Write down the intended benefit, the chosen option, who carries the burden, and what evidence would change your mind.
Use the decision worksheet · Explore another guide