On this pageStart with a question, not an SDKSeparate the purposesA smaller event can still answer the questionReview chat with an explicit boundarySession replay and hidden collectionRegional and evidential boundariesMeasure usefulness without scoring the soulInterface optionsSources and limits

8-minute guide · Editorial guidance

Learn without surveilling spiritual life

Choose useful metrics while protecting chats, prayers and reading histories.

A useful starting point

Collect the least sensitive evidence that can inform a specific product decision.

Ask: What is the least sensitive evidence that could answer the question?

Start with a question, not an SDK

“Where does playback fail?” is a product question. “What does this person confess?” is a very different collection. Define the decision, minimum data, access, retention and deletion before enabling automatic capture.

Prayer text and conversations may contain religious beliefs, health information, sexuality, family circumstances or third-party details. Reading searches, group membership, recordings and annotations also deserve scrutiny. A pseudonymous identifier does not make a history anonymous.

Separate the purposes

Scroll the comparison sideways to see all options.

Proposed collection defaults; review the actual implementation and jurisdiction
PurposePreferKeep separate or exclude
ReliabilityError category, app version, latency bucket and a short-lived diagnostic identifierPrompt bodies, transcripts, tokens, keys, raw URLs and private notes in error logs
UsabilityMinimal events tied to a defined question; coarse or aggregate results where sufficientAutomatic collection of every tap, field, passage and persistent identity
Answer-quality reviewA user-selected excerpt with preview, clear purpose and restricted accessAll conversations flowing into a general analytics dashboard
Safety operationsA separately governed process with access, retention and escalation rulesReusing safety flags for conversion, advertising or faith scoring
Model improvementA distinct decision with truthful explanation of use and available choicesTreating ordinary chat use or product analytics consent as blanket training permission
MarketingDeclared channel preferences and campaign-level reporting where appropriateTargeting offers from inferred vulnerability, confessions or private spiritual doubts

A smaller event can still answer the question

Illustrative event design

Question: does the new player reduce failed starts?

Candidate data: playback-start result, error category, app version and network class. Aggregate promptly; set a justified short retention window.

Exclude: prayer text, chat message, named user, precise location and passage history unless separately necessary and justified.

Even this minimal schema is not automatically anonymous or exempt from consent requirements. Inspect SDK enrichment, IP handling, device identifiers, crash attachments and vendor onward use. A privacy label is only credible if the actual payload matches it.

Review chat with an explicit boundary

  1. A person chooses “Report this answer”; show the specific messages and attachments to be included.
  2. Offer removal of personal details and explain who reviews the report, why, and for how long.
  3. Keep content-quality review distinct from a request for urgent help. Do not imply a report is continuously monitored.
  4. Restrict staff access and audit access to sensitive content. Plan deletion across application storage, logs, vendors, backups and derived datasets as applicable.
  5. Explain what deletion can and cannot achieve, including any lawful retention and limitations of already-used training data. Do not promise instant erasure you cannot perform.

Redaction can miss indirect identifiers, quotations and third-party details. Prefer synthetic test conversations for routine development and evaluation. If real samples are necessary, establish a separate justified process instead of quietly widening the analytics stream.

Session replay and hidden collection

Disable replay on chat, prayer journals, pastoral support, payment details and credential entry by default. Verify masking of rendered answers as well as inputs, clipboard content, accessibility labels, network requests and error attachments. A vendor’s default masking needs testing.

CNIL’s February 2026 consultation identifies privacy risks in session replay. The reviewed document is a draft consultation, not a verified final rule. The conservative defaults here are this library’s design proposals.

Regional and evidential boundaries

ICO guidance identifies religious beliefs and health as special-category data and explains when intended inferences or differential treatment trigger that classification. Not every Bible-page visit automatically establishes a belief, but inferred “faith stage” or vulnerability profiles need particular scrutiny. UK requirements are not interchangeable with every jurisdiction.

ICO guidance also treats email tracking pixels separately from permission to send the email. Apply the regional research to the whole data flow: app, analytics vendor, model provider, support tooling and exports.

Measure usefulness without scoring the soul

Combine task success, reliability and voluntary interviews. Ask about understanding and pressure without demanding intimate testimony. Report uncertainty and include people who decline research. A completed prayer, positive sentiment or longer chat is not a validated measure of spiritual maturity.

Review question: can the team answer its next decision with less data, a shorter retention period or participant-led research?

Sources, review scope and limits

Take this into a product decision

Write down the intended benefit, the chosen option, who carries the burden, and what evidence would change your mind.

Use the decision worksheet · Explore another guide