Skip to main content

Privacy notice

What we collect, why, how long we keep it, where it goes, and the choices you have — written to be read, not skimmed.

Version 2026-08-25

Who we are

Hope After Loss Project is run by [legal entity name to be confirmed]. You can reach us about anything in this notice at [contact email to be confirmed].

This notice covers the website at https://hopeafterlossproject.com and the member platform behind it. It does not cover other websites we link to, including the 988 Lifeline.

The short version

We collect what we need to run a grief programme and nothing we do not. Your private writing stays private — no staff member, no analytics, and no AI ever reads your reflections. We do not sell data, we do not run advertising, and we do not use third-party tracking. You can download everything we hold about you, and you can delete your account, at any time, from your own settings.

What we collect, and why

Most of what we hold is what you give us. Here it is, grouped by how sensitive it is.

  • Your private writing — reflections inside lessons, assessment answers, and your story. This is the most sensitive thing on the platform, and it is held for one purpose: so you can come back to it. Reflections and assessment answers are readable by you alone. Your story is readable by others only to the extent you choose in your own settings, which default to private.
  • Messages you send to other members. These are visible to the people in the conversation. They are not monitored in real time. If someone reports a message, staff can see the quoted context the reporter supplied, and that viewing is recorded.
  • Your account — email address, display name, sign-in method, and which version of these documents you accepted and when.
  • Your profile, if you fill it in — pronouns, a short bio, a location label, a note about faith, a photo. All optional, all private by default, all yours to change.
  • Private details you give us for a specific purpose — a legal name for a certificate, a phone number if you offer one. Only the owner and administrators can see these.
  • Course progress — which lessons you have opened and finished, quiz scores on facilitator training. Scores, not your answers.
  • Orders — what you bought, when, for how much, and the identifiers Stripe gives us. We never see or store your card number.
  • Security records — the device and network address you signed in from, kept for 30 days so you can see your own active sessions and sign out of any of them.
  • Support tickets you open, and reports you make about other members.

What we deliberately do not collect

There are no advertising cookies and no third-party analytics trackers on this site. We do not record how you move around the pages. The only cookie set is the one that keeps you signed in, and it cannot be read by any other site.

Our own usage counts — how many people finished a course, how many enrolled — are counts. They contain no writing and cannot be traced back to what any one person wrote.

Where your data goes

Three outside services handle some of your data, each for one purpose. There are no others.

  • Stripe processes payments. It receives your email address and the amount. Card details go to Stripe directly and never touch us. Stripe's own privacy policy applies to what it holds.
  • Google Cloud hosts the platform and stores the data described here. Your photo, if you upload one, is stored privately with its location and device metadata removed first, and is only ever shown through a short-lived private link.
  • OpenAI powers a writing assistant used by the programme's author to draft course material. Your writing never reaches it. The assistant sees only the author's own manuscript text, and we send it with storage switched off.

How long we keep things

Most of what you give us is kept until you delete it or delete your account. A few things expire on their own:

  • Sign-in session records: 30 days.
  • A story you delete can be recovered by you for 30 days, then it is gone.
  • Technical error records and AI usage records (which hold no text): 60 to 90 days.
  • Payment-provider event receipts used to prevent duplicates: 90 days.
  • Notifications you have read: 90 days.

What happens when you delete your account

You can delete your account yourself, from your settings. There is a short waiting period in which you can change your mind; after it, deletion is carried out automatically and cannot be undone.

What goes: your sign-in, your profile, your story, your reflections, your assessment answers, your private details, your badges, your session records, your notifications, and every file you uploaded.

What stays, and why: the record of which policies you agreed to and when (a legal record); orders (a financial record); messages you sent to other people, because deleting them would remove the other person's side of a conversation they may need — your name is detached from them; the audit trail of staff actions; and any certificate issued to you, because you may hold a copy and we must be able to explain it. Your account record itself is kept with all personal fields blanked, so that nothing else in the system points at a person who no longer exists.

You see this exact list before you confirm.

Your rights and how to use them

Whatever the law in your state or country calls them, here is what you can do, and where:

  • See and download everything we hold about you — including your reflections — from your settings. It arrives as a file; we do not keep a copy of the export.
  • Correct anything in your profile yourself, at any time.
  • Delete your account yourself, as described above.
  • Withdraw your agreement to these documents by deleting your account. You cannot use the platform without agreeing to them, because they describe how it works.
  • Ask us anything about your data, or complain, at [contact email to be confirmed]. We will answer. If you are not satisfied, you may complain to the data-protection or consumer-protection authority where you live.

Children

You must be at least 18 to hold an account. We do not knowingly collect information from anyone younger. If you believe someone under 18 has an account, tell us at [contact email to be confirmed] and we will remove it.

Security

Data is encrypted in transit and at rest. Staff accounts require a second factor to sign in. Every staff action that touches a member's information is recorded. Access rules are written so that nothing is readable unless a rule specifically allows it. No system is perfectly secure, and if a breach ever affects your data we will tell you what happened and what we are doing about it.

Changes to this notice

If we change this notice in a way that matters, we will publish a new dated version and ask you to read and accept it the next time you sign in. We will not quietly widen what we collect or where it goes.

Privacy notice — Hope After Loss Project