Privacy Policy

Last updated September 8, 2026

Missionary Legacy (missionarylegacy.com) is operated by Missionary Legacy LLC, a Tennessee limited liability company, 2104 Carroll Creek Rd, Johnson City, TN 37615. In this policy "we", "us" and "Missionary Legacy" mean that company. "You" means whoever is reading this — a family member with an account, a missionary, a follower, a guest at a call opening, or someone who appears in a family's archive.

Missionary Legacy is independent of The Church of Jesus Christ of Latter-day Saints. The Church does not sponsor, endorse or have access to anything described here.

1. Who this policy covers

Missionary Legacy gathers a missionary's letters, family video calls, chats, photos and videos during a mission, helps the family compose a biography from them, prints it, and preserves the archive afterward. Several different kinds of people touch that process, and most of them never create an account. This policy is written for all of them.

If you hold an account

A parent or guardian creates the family's archive and becomes its account owner. The owner invites others — grandparents, siblings, close friends — by email or by a six-character code sent by text. Each member is given a role: account owner, parent, sibling or member. Every role can read the shared archive and write to the missionary; owners and parents can also edit it and manage people, and only the owner manages billing. Section 6 sets out exactly who can see what. One person may belong to more than one family's archive, and each archive's owner controls that archive.

You sign in with an email address and password. Authentication is provided by Supabase; your password is stored in hashed form, never in plain text.

If you are the missionary

The missionary is an adult, 18 or older, and in most families never logs in. You do not need an account for the archive to exist. Your family creates it, and it is built from what you already do: emailing home, chatting, calling. Even so, the archive is about you, so you have your own protections built in:

  • Your own capture addresses. Each missionary gets private email addresses at our domain. Letters sent or forwarded to them land in your archive and nowhere else.
  • A private journal. You can record voice memos or write entries to a journal address sealed behind a passcode you choose. Your family does not read sealed entries in ordinary use, and an entry goes into the book only when shared from behind the passcode. The exception is a forgotten passcode: an owner or parent can reset it from the family's settings once one exists, and whoever performs the reset then knows the new passcode and can read what is sealed. Every reset, by a family admin or by the emailed link, is emailed to you and shown in a passcode history on the journal page, and so is any change to your recovery or personal address.
  • Personal chats that stay personal. A one-to-one chat between you and one family member is private from everyone else, including your parents, and its words stay out of the book unless the two of you choose otherwise. A parent can see that a personal chat exists and can switch personal chat off entirely, but cannot read it. Photos are the exception: a photo sent in any chat joins the family's photo archive, where everyone in the archive can see it.
  • A biographer that asks, not assumes. About once a week, on your preparation day, the archive's biographer sends you one question over chat. You choose whether to answer.
  • Your own login, when you want it. An account is reserved for you from the start. You can claim it, set a password, and see everything the family sees plus your sealed journal.

Because your family provides your information, we rely on them to tell you the archive exists and how it works.

If you follow a missionary by email

Families can share a follow link. If you use it, you give us your email address, and a name if you like, and we email you the missionary's letters as they arrive. You do not have an account. Every letter carries a one-click unsubscribe.

A follow link works for anyone who has it, so families should share it only with people they want reading the letters. Letters sent to followers may include photos and the names of people the missionary writes about; followers are expected to keep them within the circle the family intended.

If you are a guest at a call opening

Families can host a mission-call opening on a public page that needs no account. As a guest, you give a name and your guess of where the missionary will serve. You may also give an email address if you want letters later; that address goes on a waiting list. The page is marked so search engines do not index it, and the missionary appears only as a first name and last initial.

If you buy a gift

You give us your name and email and pay through Stripe. We email you the gift code and a printable card and, if you ask, tell you when it is redeemed. We keep your purchase record as described in Section 2.10.

If you are an affiliate or referral partner

We keep your name, contact details, social handle, your code, the activations attributed to it, commissions owed and paid, and your tax forms, which are collected through Stripe Connect. Your affiliate agreement governs the program; this policy governs your data.

If you appear in a family's archive but never use Missionary Legacy

Letters, transcripts, chats and photos naturally mention other people: companions, mission presidents, members, investigators, converts, friends, relatives. If that is you, the family who uploaded or forwarded the content is responsible for it. We do not publish any family's archive to the public. The printed book goes only to the people the family orders it for. The demonstration archive shown on our site is entirely simulated; no real person appears in it. If you have a concern about how you appear in a family's archive, contact us at support@missionarylegacy.com and we will follow the complaints procedure in the Terms.

Children

Missionaries are adults. An account holder must be 18 or older (Terms, Section 2), so nobody under 18 signs in, and we do not knowingly collect personal information from anyone under 13 through an account.

Children do still appear in an archive — in photographs, in letters, in the family call — because a parent put them there. That content is uploaded and controlled by the parent, who decides what goes in and can remove it. A younger sibling reads over a parent's shoulder rather than through a login of their own.

Setting accounts at 18+ also settles something the earlier draft could not: a personal one-to-one chat with the missionary belongs to an account, so no child has one, and the conflict between a private sibling chat and a parent's right to review a child's information does not arise.

If you are a parent and want to see or delete what is held about your child, write to support@missionarylegacy.com.

2. Information we collect

We collect information in three ways: you give it to us, your family or a device gives it to us on your behalf, or it is generated when you use the service.

2.1 Account and family information

  • Your name, email address and password (stored hashed).
  • Your relationship to the missionary and your role in the archive.
  • Your birthday, if you or a parent enters it, used to date letters and show birthdays on the mission timeline. For a minor sibling, a parent enters it.
  • A contact phone number and mailing address, if you provide them, used for your account and for shipping books.
  • Invitations you send: the email addresses or codes you issue, and who accepted them.
  • Your acceptance of our Terms and this Privacy Policy: which version you accepted, when, and on which screen. When the documents change, you are asked to accept the new version.
  • Settings and preferences, such as which missionary's archive you last viewed and whether you turned on notifications.

2.2 The missionary's profile

The family enters the missionary's name, birthday, mission, start and expected end dates, the Church-issued missionary email address, and an optional personal email address that will still work after the mission ends. The family may add a photo. Over the mission, the archive fills in areas served, transfers, companions and other facts (Section 2.9).

2.3 Letters and email

Inbound letters. Each missionary has private capture addresses at our domain. Mail sent to them is received by Amazon Web Services (Simple Email Service), written as a raw message to an Amazon S3 bucket, then parsed into the archive. We keep the message: sender and recipient addresses, date, subject, body and attachments. Families typically have the missionary add a capture address as a recipient, or forward the missionary's weekly email to it.

Letters home from the family. Letters the family writes to the missionary through Missionary Legacy are kept in the archive too.

Imports. A family can upload a Gmail export (.mbox) to rescue older letters. We read it, keep only messages from the missionary, and delete the uploaded file when the import finishes. A family can also upload Google Takeout archives to import photos.

The Church account. Missionaries write from a Church-provided account that the Church deletes within months after the mission ends. Everything in the archive is our copy, held for the family; we have no access to the Church account itself.

2.4 Chats

Families chat with the missionary through a relay we operate on Google Chat:

  • Family members write in Missionary Legacy. Our relay posts each message into a Google Chat space under our app's identity, with the writer's name at the start of the message. The missionary's replies come back through the same relay and are stored in the archive.
  • Photos travel in both directions and are filed in the archive.
  • Reactions are stored per member.
  • If the missionary writes in another language, we may translate the message with an AI model and keep the translation with the original so it is not re-translated each time.
  • There are three kinds of thread: the family thread everyone in the archive can read; personal threads between the missionary and one member, which only those two can read and which stay out of the book unless they choose otherwise; and the biographer thread, where the archive asks the missionary questions, visible to the owner and parents.

The missionary's side of the chat lives in their Google account and is subject to Google's terms.

2.5 Calls and recordings

The family's video call room. We host a permanent Google Meet room for each missionary, owned by a service identity we control whose Google Workspace licence carries recording and transcription rights.

How a call is recorded. Every archive is given a permanent Meet room, and whenever anyone is in that room a recording participant from Recall.ai joins it automatically, appearing in the participant list as "Missionary Legacy" so everyone on the call can see it. A family admin can switch the room to unrecorded from the Calls page: the recording participant is not sent in, Google's own recording of the room is switched off, and nothing from the room is imported while the switch is on. For family calls it records audio only, delivered to us as a single mixed audio file. We do not keep video of family calls. Google Meet may also record and transcribe the call natively through our service identity; when it does, Google shows its own recording indicator, and the recording, transcript and any "Notes by Gemini" document land in that identity's Google Drive, from which we import them. Families who prefer not to use the recorder can use the in-app recorder, which records audio through your device's microphone on speakerphone and uploads it. The person who turns on call capture is responsible for telling everyone on the call that it is being recorded (Section 7 of the Terms, Call recording and consent).

What we keep from a call. The audio; the date and duration; who was on the call; the transcript; the moments the family keeps; and a note of whether the family approved or set aside each moment. The transcript is visible only to the account owner and parents. The call's summary goes into the book by default, and owners and parents can switch any call out of it.

Transcription and speaker identification. Audio is transcribed by Deepgram with speaker separation, which tells voices apart acoustically so that a family sharing one speakerphone is not collapsed into one voice. If Deepgram is unavailable we fall back to OpenAI's Whisper. We then try to put names on the separated voices using only what the archive already knows: the roster of family members, the names the family declared for that call, and what is said. A name is applied only above a confidence floor; when we are not confident the label stays generic. We would rather leave a voice unnamed than put the wrong name in a printed book. We do not build, store or compare voiceprints of anyone.

Moments. An AI model reads each transcript and proposes moments: a short summary plus verbatim excerpts worth keeping. The family reviews each one — keep it, set it aside or mark it private. Kept moments can print in the book beside a QR code, which anyone holding the book can scan; see Section 6, "Printed QR codes are bearer links". Media behind a printed code is never sealed (Section 7).

2.6 Call openings

A host creates a call-opening event by giving their name, email address, the missionary's name (we display first name and last initial only), the opening date and time, and an optional meeting link. The host's email is added to our waiting list and receives our messages about the event. Guests give a name, a guess, and optionally an email address; guests who give an email receive a receipt of their guess and the reveal. A guess can be changed until the opening. The event page is public but marked no-index. Other people who open the event page can see the names and guesses that have been posted, so use the name you are comfortable showing. If a referral code brought the host to us, it is attached to the event.

The opening may be recorded on video by our recorder — the one recording in the product we keep as video. If the family never starts an archive, the recording is kept for three months and then removed. During that time we remind the host that it is theirs to download free, at about 30, 7 and 1 days before removal, and nothing is removed until at least two reminders have been delivered. If the family starts an archive, the recording is claimed into it and never expires.

2.7 Photos and videos

Where they come from. A shared Google Photos album — you give us the public share link and we check it hourly for new items; we do not sign in to your Google account — a shared Google Drive folder, files you upload, email attachments, chat photos, and Google Takeout archives.

What we extract and keep. The image or video file; its embedded metadata, including the date it was taken and, if the camera recorded it, the GPS coordinates of where it was taken, which we use to file the photo to the right place and time; pixel dimensions; a content hash and a perceptual hash so we can recognise duplicates and near-duplicates; a caption and category produced by a vision model from OpenAI so photos are searchable and can be placed in the book; and derived versions such as thumbnails and poster frames. Videos are kept up to 200 MB per clip or the limit our storage plan allows, whichever is smaller — 50 MB today. A clip over the limit is refused rather than partly saved. Videos are kept for every archive today.

2.8 Voice journals

The missionary can email voice memos to journal addresses. We store the audio, transcribe it, and file the entry. Entries sent to the sealed journal are protected by a passcode the missionary sets; we store the passcode only as a salted hash and set a short-lived unlock cookie on whichever device enters the correct passcode. Sealed entries are transcribed so the missionary can read them, but they are not shown to the family and are not used in the book unless the missionary shares them.

2.9 Mission facts and locations

As the mission unfolds, the family and the archive record areas served and transfer dates; companions; baptisms and other milestones; the mission president; and "connections" — people who mattered in the missionary's story. For each connection the family may record a name, role, notes, a photo, a birthday, a phone number, a street address and a map location. We ask families to record contact details only when the person gave them to the missionary for the family to keep, and never for people the missionary is teaching unless they agreed.

Locations can include the address of an apartment or area so it can be pinned on the mission map. When you type an address or place into the archive, your browser sends the text to Mapbox, which returns coordinates; the mission map itself is drawn by Mapbox, so your browser also requests map imagery from Mapbox while you view it. We store the coordinates, the address as you confirmed it, and how precise the match was.

2.10 Payments, orders and codes

Payments are processed by Stripe. You enter card details on Stripe's checkout page; we never see or store card numbers. We store the Stripe customer and subscription identifiers, what you bought, amounts, dates, any promo, referral, affiliate or gift code used, and credits earned or applied. For a printed book we store the edition, volumes, and the recipient's name, shipping address and phone number, which we pass to our printer.

2.11 Server logs, cookies, analytics, notifications and error reports

Server logs. Like every website, our servers and hosting provider record each request: your IP address, browser and device type, the page requested, and the time. We use these logs to keep the service running and secure and to investigate abuse. We also keep the time of your last sign-in.

Cookies. We use a small number of first-party cookies. None are advertising cookies.

CookieWhat it doesHow long
Authentication cookiesKeep you signed inSession, as set by our authentication provider
ml_attrRecords how you first arrived, so we know which of our own efforts brought you; stamped on the family record at sign-up and then deleted30 days, or until used
ml_refHolds a referral or join code so the referring family gets credit; deleted when used30 days, or until used
ml_promoHolds a promo code you arrived with; deleted when used30 days, or until used
ml_founders_optinRemembers that you opted into the founding-families program while you finish signing up1 day
ml_selected_missionaryRemembers which missionary's archive you last viewed1 year
mljrnl_…Unlocks the missionary's sealed journal on their own device after they enter their passcode12 hours, and reset when the passcode changes

Analytics. We use Vercel Analytics and Speed Insights to count page views and measure how fast pages load. We also run our own visit counter, which is cookieless by construction: for each page view, your browser sends the page path with identifiers stripped and the referring site's hostname; our server computes a one-way hash of your IP address, browser signature, the day and a secret, and stores only that hash. The hash changes every day at midnight UTC and cannot be reversed, so we can count how many people visited without knowing who they were. We do not store your IP address in this counter. Known bots and our own admin pages are excluded.

Notifications. If you turn on browser push notifications, your browser gives us a push endpoint and encryption keys, which we store with your membership. Notifications are encrypted to your browser and delivered through your browser maker's push service.

Error reporting. We use Sentry to learn when something breaks. Error reports include the error, a stack trace, the page, and browser and device type. Sentry is configured not to send personal information by default — no IP addresses or user identifiers — and we sample a small share of requests for performance timing.

2.12 Support and communications

When you email support@missionarylegacy.com, or reply to one of our emails, we keep the correspondence. We send email through Resend: account and billing messages, letter deliveries to followers, reminders, and event emails to call-opening hosts and guests. We keep a suppression list of addresses that have unsubscribed or bounced so we do not email them again; the unsubscribe link is signed to your address so no one else can unsubscribe you. Feedback you give us in the app may be summarised by an AI model for our team. We do not use pixel-based open tracking in letters.

2.13 Information others provide about you

Most of what is in an archive is placed there by the family, not by the person it describes. If you are the missionary or someone who appears in the content, the family is the source, and the account owner controls it.

3. How we use your information

To build and keep the archive. Receive letters, chats, calls, photos and journals; date and file them to the right part of the mission; detect duplicates; extract metadata; back them up. Originals are never edited.

To compose the book. AI models draft chapters from the archive's letters, transcripts, chat, journal entries the missionary has shared, and mission facts. A second pass checks every claim against the sources and removes anything the sources do not support; a further pass flags places where a figure of speech may have been taken literally. The family can review, edit and approve every chapter; we print the book as it stands when the order is placed, approved or not.

To transcribe calls and journals and label who spoke. As described in 2.5 and 2.8. Names are applied only when confident; otherwise the speaker stays unnamed.

To propose and preserve moments. Suggest excerpts from calls for the family to keep, set aside or mark private; generate the codes that play kept moments from the recording.

To host and record calls. Provide the Meet room; dispatch the recorder automatically whenever someone is in it, unless the family has switched the room to unrecorded; import Google's recording, transcript or notes when they exist and the room is not switched off; deliver the in-app recorder's audio.

To run the call-opening event. Show the page; collect guesses; email hosts and guests about the event; record the opening if asked; keep, remind about, and remove or claim the recording on the schedule in 2.6.

To deliver letters to followers. Email the missionary's letters to people who followed by link, with one-click unsubscribe.

To relay chat. Post family messages into the Google Chat space and bring replies back; translate when needed; enforce the privacy of personal threads.

To print and ship books. Render the approved book to PDF, send it with the shipping details to our printer, and track the order.

To bill you. Charge setup fees, subscriptions, passes, gifts, vaults and books through Stripe; apply codes and credits; send receipts and billing reminders.

To keep the service safe and working. Authenticate you; enforce roles and thread privacy; sign links so they cannot be forged; detect abuse; monitor errors; keep backups.

To understand usage in aggregate. Count visits and measure performance without identifying individuals.

To attribute referrals and honour codes. Credit the family or affiliate who referred you; apply promo and gift codes; run the founding-families program.

To communicate with you about the service. Onboarding, reminders — for example the date media will seal without a vault, or that a recording will be removed — changes to these documents, and replies to support requests.

To communicate with call-opening guests, narrowly. Guests who asked for letters get letters. Before departure, guests may receive one note inviting them to write words for the missionary's book. At the end of the mission, guests may receive one or two emails about a journal of their own. We do not otherwise market to a family's guest list; it is theirs.

To comply with law and protect rights. Respond to lawful requests, enforce our Terms, and protect the safety of families, missionaries and the public.

What we do not do. We do not sell personal information. We do not use archive content for advertising. We do not publish any archive. We do not use your content to train AI models, and our AI providers may not either.

4. AI processing

AI is how a shoebox of letters becomes a book. This section says which providers we use, what they receive, and what they may not do with it.

ProviderWhat it doesWhat it receives
Anthropic (Claude models)Drafting and reviewing book text, summaries, chat translation, and the pass that checks for figurative misreadsLetters, chat messages, transcripts, journal entries the missionary shared, mission facts, and our instructions
OpenAI (GPT models; Whisper)Drafting book text and fact-checking, moment extraction, photo captions and categories, translation; Whisper is the fallback for speech-to-textText as above; photos for captioning; audio when Whisper is used
DeepgramSpeech-to-text with speaker separation for calls and voice journalsAudio of calls and voice journals
Google (Meet transcription, Gemini notes)When a licensed account is on a call, Google may transcribe it and produce meeting notes, which we importCall audio and video while the call runs; it produces the transcript and notes we import

Which model handles a given step can change as models improve, and we will update this policy if we add a provider.

What is not sent to AI providers

Passwords, payment information and sign-in tokens are never sent to an AI provider. Sealed journal entries are transcribed so the missionary can read them but are not used in composition unless the missionary shares them. Personal chat threads are not used in the book unless the two participants choose otherwise. Google's transcription and notes are produced inside Google Meet under Google's terms rather than sent by us; we import the result.

No training on your content

We use each provider through its business API terms, under which customer content is not used to train or improve the provider's public models.

How we keep AI honest

  • Sources first. The chapters that tell your missionary's story are built from your archive, not from the model's general knowledge, and a fact-check pass removes claims the sources do not support. The background Parts on the country and its cities are the exception: they are written from a public encyclopaedia entry about that place. To fetch it we send the place name and nothing else — never your archive, and nothing about you.
  • A second opinion. Where we can, a model from a different provider reviews the drafter's work, so one model's habits do not go unchecked.
  • Refusal to guess. Speaker names, dates and places are applied only above confidence thresholds; otherwise they are left blank or generic rather than invented.
  • You decide. A moment reaches the story only when someone keeps it, and every chapter can be reviewed, edited and approved before you order. We print the book as it stands at the moment you order, so the reading is yours to do.
  • Nothing is overwritten. Originals are never edited by AI or by us.

What we record about AI use

For each archive we log how much AI processing was used — which model, token counts, estimated cost and the kind of task. This is a usage ledger for cost control; it does not contain your content.

Automated decisions

We do not use AI to make decisions about you that have legal or similarly significant effects. No pricing, eligibility or account decisions are automated in that sense. The book and speaker labels are drafts subject to your review.

5. Sharing and subprocessors

We share information only in the ways listed here.

With the people you choose

  • Family members read the shared archive; owners and parents can also edit it and manage members. Call recordings and transcripts are visible only to owners and parents. Personal chat threads are visible only to their two participants. Sealed journal entries are visible only to whoever holds the passcode — normally the missionary alone; the journal section below describes the reset exception.
  • The missionary receives the family's chat messages and letters through the relay and their email.
  • Followers receive the missionary's letters by email because the family shared the follow link.
  • Call-opening guests see the event page and receive the event emails they signed up for.
  • Holders of the printed book can scan any printed code and play the recording behind it. Treat a book like the keepsake it is.

With service providers

These companies process information on our behalf, under contracts that limit them to providing their service to us.

ProviderServiceWhat it receives
SupabaseDatabase, file storage, authenticationEverything in the archive; account data; hashed passwords
VercelHosting the application; Analytics and Speed InsightsWeb requests, including IP addresses in ordinary server logs; page-view and performance data
Amazon Web ServicesInbound email; storage of raw inbound messages and media backupsInbound letters and attachments; copies of media
ResendSending emailRecipient addresses and the content of the emails we send, including letters delivered to followers
Stripe (including Stripe Connect for affiliate payouts and tax forms)PaymentsName, email, billing details, card data entered on Stripe's pages, purchase history
Lulu, and the print facilities and shipping carriers it uses, which may be in the destination countryPrinting and shipping booksThe book PDF, including the names, words and photos it contains, and the recipient's name, shipping address and phone
Recall.aiRecording participant for calls and call openingsThe meeting link, the recorder's display name, the audio — or video, for call openings — and participant display names. Recall keeps its own copy of the recording.
Google (Workspace APIs)Chat relay; Meet rooms, native recordings, transcripts and Gemini notes; Drive folder reading; Google Photos shared albumsChat messages and photos relayed into the Chat space; call audio and video while a Meet call runs; Google-made recordings, transcripts and notes stored in our service identity's Drive; the public album and folder links you give us
DeepgramSpeech-to-text and speaker separationCall and voice-journal audio
OpenAILanguage models, vision captioning, fallback transcriptionText from the archive; photos for captioning; audio when Whisper is used
AnthropicLanguage modelsText from the archive
MapboxAddress and place lookup; mission map imageryThe address or place text you type; your browser's IP address and the map area you view, since requests go directly from your browser
SentryError monitoringError reports and sampled performance data, configured without default personal information
Browser push servicesDelivering notifications you opted intoAn encrypted notification addressed to your browser's push endpoint

We will update this list when it changes.

Within our team

See "Our team" in Section 6.

When the law requires it

We may disclose information to comply with a subpoena, court order or other legal process, or when we believe in good faith that disclosure is necessary to protect the safety of a missionary, a family, our users or the public, or to enforce our Terms. Where the law allows, we will tell the account owner before we disclose.

If our business changes hands

If Missionary Legacy is acquired, merges or transfers substantially all of its assets, the archives and the information in this policy may be transferred to the successor, who must honour this policy for the information collected under it until you are notified of a change. Nothing in a transfer alters the promise that archive originals are never edited, that written archives and books stay readable free, and that printed codes never seal.

What we never do

We do not sell personal information, do not share it with advertisers or data brokers, do not share it with the Church, and do not publish any archive.

6. Who can see what inside an archive

An archive is private to the people the family lets in. Nothing in it is ever published publicly by us.

Family accounts

The person who creates an archive is its account owner. Owners invite others by email or with a short join code, and they decide who is in and what role each person has. One person can belong to several archives and sees each one separately.

  • Account owner — everything, including billing. One per archive.
  • Parent — everything an owner can do except billing: settings, members, and editing the archive's contents.
  • Sibling — reads the shared archive, writes to the missionary, and is on the call and chat lists by default.
  • Member (aunts, uncles, cousins, grandparents) — reads the shared archive and writes to the missionary, but is off the call and chat lists unless a parent or owner switches them on.

Reading the shared archive is not rationed by role: every account reads the same letters, photos, chats and book drafts, so an aunt reads what a mother reads. Call recordings and transcripts are the one exception — only the account owner and parents can open them, and the rest of the family sees only the moments those two roles choose to keep. What else differs by role is who can change things and who can manage people and billing. Owners and parents can also set per-person switches: whether someone joins calls, is in the family chat, has a personal chat with the missionary, and whether letters they write appear in the book.

An archive whose subscription has lapsed becomes read-only, not locked: everyone can still read it, but capture and AI work pause. The public demo archive is read-only for everyone and entirely simulated.

The missionary's private journal

The missionary can keep a sealed journal that the family does not read in ordinary use. It is protected by a passcode that only the missionary sets: we email a one-time setup link to the missionary's own address, and the family cannot set that first passcode for them. The passcode is stored as a one-way hash; we never email it and cannot see it.

If the passcode is forgotten, a one-time reset link valid for 60 minutes can be emailed to the missionary's recovery address. An owner or parent can also trigger a reset from the family's settings once a passcode exists, and a reset immediately locks every open session. Whoever performs a reset knows the new passcode. The emailed setup link is no safer: an owner or parent also controls which address is on file as the recovery address, so a family that points it at their own inbox can complete a reset themselves. Every reset, by either route, sends the missionary an email saying it happened, and the reset and any change to an address those notices go to are written, with who performed them, into a passcode history shown on the journal page to the whole family, the missionary included.

A sealed entry moves into the printed book only from behind the passcode — normally by the missionary. A family admin who has reset the passcode could also do it, which is one more reason every reset is disclosed. When they do, the entry prints as text in the family book, labelled as shared by them; its recording, and any code that plays it, stays out of the family book and lives only in the missionary's own sealed volume.

Personal chats are private from parents

The family chat is a shared room that everyone with an account can read. A personal chat between one family member and the missionary belongs to those two people only. A parent or owner can see that a personal thread exists and can switch the personal-chat channel off for a member, but cannot read it. The words of a personal thread are left out of the book by default; only the people in a thread can choose to keep something from it for the book. Photos are not thread-scoped: a photo sent in a personal chat joins the family's photo archive like any other, and everyone in the archive can see it.

The biographer thread is visible to the owner and parents, because its purpose is improving the book.

Followers

A follower receives the missionary's letters by email through a follow link the family shares. Followers have no account, no login, and no way into the archive. They receive only what the family sends out to the list, and every email carries a one-click unsubscribe.

Call-opening guests

A mission-call opening page is a public, unlisted event page. Guests give a name and a guess, and an email address only if they want to hear where the missionary is going or to receive letters later. The page is marked so search engines do not index it, and it shows a first name and last initial only. Guests never see the archive.

Kept call moments, and journal entries or videos chosen for the book, print with a QR code. Scanning it plays that story from the recording. Each code is a signed, unguessable link that opens exactly one item; knowing or guessing an identifier grants nothing.

The player starts at the story and stops when it ends, but the listener can choose to keep listening into the rest of that call. Anyone who holds the book can scan its codes, and can therefore hear the whole recording behind any kept moment. A printed code is a bearer link, like a key in the book's pages. It does not require a login, and we cannot tell who scanned it. Only moments the family marked "keep" ever get a code; moments set aside or marked private do not. Choose what you print with that in mind.

Our team

Our operator console shows account-level information — names, email addresses, roles, counts, order status, last sign-in — and never the text of letters, journals, chats or transcripts. When we send a data export, it goes to the person it is about, not to our screen. Engineers who maintain the database and storage could technically reach content; we do so only to fix a specific problem you have reported, with your permission, or when the law requires it.

7. How long we keep things, and how they are deleted

Raw is sacred

We never edit an original. Letters, recordings, photos and chats are stored as they arrived; summaries, transcripts, captions and book chapters are created alongside them, never over them. If the missionary later deletes a message in Google Chat, our archived copy is not deleted with it.

When we say nothing is ever deleted, we mean by us, for non-payment. A family may still ask us to delete its archive, and an unclaimed call-opening recording is removed after three months.

The written record

Letters, chats, transcripts, call summaries, journal text and the book itself stay readable to the family, free, for as long as Missionary Legacy operates. Nothing is deleted because a subscription ended or a bill went unpaid.

Photos, audio and video

Photos, audio and video stay live through the mission and for six months after the mission end date recorded in the archive, at no charge. If no end date is recorded, nothing seals. After that, one of two things happens:

  • If the family has a storage plan, media stays live. No such plan is on sale yet, and nothing has been sealed: today photos, audio and video stay live for every archive at no charge.
  • If not, photos, audio and video may be sealed, moved out of the live archive into cold storage. Sealed is not deleted. Sealed media is restorable on request. If restoring carries a fee, we will name it in the notices we send before anything seals, never only at the moment you ask.

Before anything seals, we will tell you, with the dates, and you can ask for a full export of your media first at no charge.

Founding families' media never seals.

Printed codes never seal

Whatever the family's storage status, media that a printed code points at is never sealed. Kept call moments, journal recordings and videos chosen for the book keep playing from the page for the life of the book. The rest of the archive — the full photo library, calls without a kept moment, videos not chosen for the book — follows the rule above. This is enforced in our software, not only promised here.

Call-opening recordings that were never claimed

If you record a mission-call opening and never start an archive, we keep the recording for three months, and it is yours to download free the whole time. We email reminders 30 days, 7 days and 1 day before it comes down. Nothing is removed unless we sent at least two reminders and our email provider accepted them; if a send failed, the deadline extends instead. The moment your family starts an archive, the recording is claimed into it and never expires. This is the one place in the product where media is removed rather than sealed.

Imports and relays

When you import a Gmail export or Google Takeout, we keep only the missionary's messages and delete the raw upload once the import finishes. Recordings made by our recorder are fetched from the recording vendor into our storage as audio; family-call video is not kept, the call-opening video being the exception.

Backups

Photos and videos are copied to an off-site backup bucket we control as they arrive. Call recordings and voice-journal audio are not mirrored today; they exist only in our primary storage. Because of the backup, something you delete may persist there for a period before it ages out.

Everything else

WhatHow long
Closed loginsKept while the archives you belonged to keep your contributions attributed to you
Support emailKept as part of our correspondence with you
Call-opening events where no archive was createdThe recording is removed after three months; guest names, guesses and emails are kept with the event
Waiting listUntil you ask to be removed
Follower addressesUntil you unsubscribe, then on the suppression list only
Raw inbound email in storageKept after the letter is parsed into the archive
Push subscriptionsUntil you disable them, or after repeated delivery failures
Error reportsKept by our error-monitoring provider under its own schedule
AI-usage ledgerContains no content; kept for accounting

Deletion and export today

There is no self-serve delete or export button yet. Both are done on request: email us from the address on your account and we will act on it.

  • Export of your own information — we email you what we hold about you as a person: your profile, the letters you wrote, the photos you added, and your orders. It does not include letters other people wrote; those belong to them.
  • Export of a whole archive — the account owner can request it.
  • Deletion of a whole archive — the account owner can request it. It is permanent. Printed books cannot be recalled, and copies other people downloaded or received by email are outside our control.
  • Payment records — we keep the Stripe customer and subscription identifiers and order history as long as needed for tax, accounting and dispute purposes. We never hold card numbers.

When an account or subscription ends

  • If you close your account, we revoke your login and suspend your memberships, but your contributions stay in the archives you belonged to, attributed to you. Removing them would erase your name from letters you wrote and destroy your personal chat with the missionary — history that also belongs to the missionary and the family. If you want your contributions removed as well, tell us and we will talk it through.
  • If your subscription lapses, the archive becomes read-only. Capture and AI work pause; every written word and the book stay readable. No one is locked out.
  • Accounts that never joined an archive and have not signed in for a long period may be closed. Closing such an account changes nothing in any archive.
  • Followers who unsubscribe stop receiving email immediately. We keep the address on a suppression list so we do not email it again; ask us if you want it removed entirely.
  • The missionary's Church account is deleted by the Church within months after release. Our copy of what was forwarded to us is independent of that and stays in the archive.

8. Security

We protect your family's record with care, but no system is perfectly secure, and we do not promise that it is.

  • In transit: every connection to our service, and between our service and our providers, is encrypted.
  • At rest: our storage and database providers encrypt stored data.
  • Access controls: database row-level security keeps each family's rows separate; roles and per-person switches decide what each account can do. Photos, audio and video are served through short-lived signed links, not public URLs.
  • Unguessable addresses and links: capture email addresses are private and unique per missionary. Links that grant access — photo permalinks, listen links, unsubscribe links — are cryptographically signed so identifiers cannot be enumerated.
  • Passcodes: the missionary's journal passcode is stored as a one-way hash and never emailed; reset links expire in 60 minutes and work once.
  • Our tools: the operator console never displays content, and data exports go to the person they are about. Our error-monitoring service is configured not to attach personal information to error reports. Our traffic counter uses a hashed identifier that rotates daily and cannot be reversed.
  • Recording is visible: our recording participant joins under its own name, and Google Meet shows its own recording indicator when Google records.
  • Inbound mail: capture addresses are unguessable, but anything mailed to one is filed to the archive. If a stray message arrives, an owner or parent can set it aside. Keep capture addresses within the family.

Your part. Keep your password and the missionary's passcode private. Share join codes and follow links only with people you mean to admit. Anyone holding a printed book can play its codes.

If something goes wrong. If we learn of a security incident affecting your personal information, we will notify you by email at the address on your account, without undue delay and within the time the law requires, and tell you what happened and what we are doing. To report a vulnerability, email security@missionarylegacy.com.

9. Your rights and choices

Access and correction

While signed in you can read, add to and, as an owner or parent, correct the archive, and update your own name and email. Owners and parents manage who is in the archive.

Export

Ask us and we will email you what we hold about you. Account owners can request a full-archive export.

Deletion

Ask us and we will delete your account, your personal information, or a whole archive you own, subject to the limits described above — backups, printed books, other people's copies, and records we must keep for tax, accounting or legal reasons.

Email

  • Follower letters — every email has a one-click unsubscribe.
  • Reminders, digests and onboarding emails — every email has an unsubscribe link; using it adds you to our suppression list.
  • Transactional emails — receipts, security notices, sign-in links, export deliveries — are part of running your account and cannot be turned off while you have one.

Push notifications

Push is opt-in through your browser. Turn it off in your browser's settings at any time, or use the per-channel switches in your family settings. If a device stops accepting pushes we disable, rather than delete, its record so a returning device picks up again.

Cookies

Required sign-in cookies keep you logged in; the first-party preference cookies and analytics are listed in Section 2.11. We do not use advertising cookies and we do not sell your information. Most browsers let you block or delete cookies; blocking the required ones will sign you out.

If you live in California or another state with a privacy law

We do not sell personal information and do not share it for cross-context behavioural advertising. Depending on where you live, you may have the right to know what we collect and why, to access it, to correct it, to delete it, to obtain a portable copy, to opt out of sale or sharing (we do none), to limit the use of sensitive personal information, and not to be discriminated against for exercising these rights. Exercise them by emailing us; we verify your request using the email on your account and respond within the time the law allows. You may use an authorised agent with written permission.

Three things about this product deserve counsel's specific attention: the record is by its nature about religious service, a sensitive category under several laws; our transcription labels speakers by matching voices and names against the family roster, which may be regulated as voice or biometric identification in some states; and we store precise locations — GPS coordinates embedded in photos and geocoded addresses of areas, apartments and connections — which several state laws treat as sensitive personal information.

If you are in the European Union, United Kingdom, or another place with similar laws

Where we sell, and whose data we hold. We sell to account holders resident in the United States only (Terms, Section 2). That is not the same as only holding data about Americans, and we would rather be plain about the difference: your missionary is almost certainly serving abroad, family and friends who follow along may live anywhere, and people they meet in the field appear in letters and photographs. We process that information wherever those people are.

If the data-protection laws of your country apply to you, you have the rights to access, rectify, erase, restrict, port and object described in this policy, whether or not you are the person paying us. Write to support@missionarylegacy.com.

Verifying requests, agents and appeals

We verify requests by confirming control of the email address on the account. Requests about a shared archive must come from its owner. If we decline a request, you may ask us to reconsider by replying to our decision, and we will respond in writing.

10. Where your information is stored and moves

Missionary Legacy is operated from the United States, and your information is stored there: our database, file storage, inbound mail and backups run in US regions. Our providers may process information in the United States and in other countries where they operate.

Because the missionary serves abroad, their letters, voice and photos are sent to us from wherever they are and processed in the United States. Family members and followers outside the United States send us their information the same way. A book may be printed at a facility near its destination, so the book file and shipping details may be processed in that country. If you are in the EU, UK, Switzerland or another country with data-transfer rules, we rely on for those transfers.

Recording laws differ by country and state. The family member who turns on call capture is responsible for telling participants, including the missionary, that the call is recorded.

11. Changes to this policy

Each version of this policy carries a date, and we record which version you accepted and when. Material changes take effect no sooner than 30 days after we email the address on your account and show a notice in the app, and you will be asked to accept the new version the next time you sign in. Smaller changes take effect when posted.

12. How to contact us

Questions, requests and concerns about your privacy: support@missionarylegacy.com. Security reports: security@missionarylegacy.com. We read every message and reply personally.

Missionary Legacy is an independent service, not affiliated with, sponsored by, or endorsed by The Church of Jesus Christ of Latter-day Saints.

See also the Terms of Service. Questions: support@missionarylegacy.com.