Effective July 30, 2026

Privacy Policy

Clear information about what we collect, why we use it, who processes it, and the choices available to you.

Who operates this service

Sacramento Men's Group is an independently organized Christian men's group serving the Sacramento area. Privacy, security, and account requests should be sent to contact@sacramentomensgroup.com.

Information we collect

Public visitors may provide a name, email address, optional phone number, and message when requesting information. Public surveys store the selected answer and a keyed, pseudonymous voter identifier so a browser can change its vote without exposing raw device identifiers. We do not require an account for public surveys.

When public visit analytics are enabled, we use signed first-party visitor and 30-minute session identifiers and record the approved public-page category, time, broad traffic-source category, and whether a campaign tag was present. Analytics identifiers are keyed and pseudonymous. The aggregation queue temporarily holds those hashes, then erases them when processing completes; historical rollups retain only counts and probabilistic estimates. We do not store raw IP addresses, exact locations, detailed referrer URLs, or campaign names in analytics. Browser and request signals may be evaluated briefly to reject obvious automation and abuse, but are not copied into analytics records.

Invited members provide authentication and profile information and may create private meeting minutes, tasks, discussions, reactions, files, and notification preferences. If a member enables phone notifications, we store the device's push-service endpoint, public encryption keys, a random app device identifier, and limited device class. Message text appears in a phone notification only when that member explicitly enables message previews; otherwise the alert identifies only the discussion. Administrators can view member and operational records needed to run the group, but browser clients cannot read stored push endpoints or encryption keys.

How we use information

  • Respond to requests to join or learn about gatherings.
  • Understand aggregate public-site reach, useful pages, broad traffic sources, and successful interest-request conversion.
  • Authenticate invited members and enforce role- and meeting-based access.
  • Operate meetings, assignments, discussions, surveys, files, and notifications.
  • Protect the service from abuse, duplicate requests, and unauthorized access.
  • Diagnose failures and maintain reliable operations without intentionally logging private meeting content or secrets.

Every active workspace member may view the aggregate public-site dashboard. Small source and page groups are withheld. The dashboard does not contain contact details, private workspace activity, or visitor-level histories.

AI-assisted task suggestions

An administrator may explicitly choose to send the current meeting-minute text to OpenAI to generate structured task suggestions. Suggestions are validated and must be reviewed by an administrator. AI cannot automatically assign tasks, publish minutes, change existing work, or send notifications. Unrelated member information is not intentionally included.

Service providers

Firebase and Google Cloud provide hosting, authentication, databases, file storage, abuse protection, background processing, logs, and backups. SendGrid delivers application email. OpenAI processes meeting text only when an administrator starts task extraction. reCAPTCHA Enterprise and Firebase App Check help distinguish legitimate application requests from abuse. These providers process data under their own applicable terms and security controls.

Cookies, local storage, and PWA behavior

The private application uses a secure session cookie and Firebase Authentication persistence. Public surveys store a random browser identifier locally so a vote can be updated. First-party public analytics use an HttpOnly visitor cookie for up to 365 days and a session cookie for 30 minutes after the latest measured page view. The installable web app may cache public images, fonts, styles, and a non-private offline screen for performance; private pages and API responses are excluded from the service-worker cache.

On a device that a member explicitly marks as trusted, Firebase may maintain its protected browser cache and the app may retain message drafts, failed-send retry records, and unsynced meeting-minute drafts. Those app-retained private records use per-member, non-exportable Web Crypto AES-GCM keys and authenticated encryption before they are written to browser storage. Trusted-device storage is off by default; its encryption keys and records are destroyed when the member turns it off or signs out. On an untrusted device, private drafts remain only on the open screen. The installed app may use the operating system's unread icon badge. Members can disable message notifications in Profile or in device settings.

Google Analytics and advertising trackers are not enabled. Analytics are first-party and stored in the same Firebase and Google Cloud environment already used to operate the site. We honor supported Global Privacy Control and Do Not Track signals. You may also turn public visit analytics off for this browser below. A successfully submitted interest request still contributes one aggregate reach-out count, but it is not linked to a measured visit when analytics are off.

Loading analytics choice…

Disclosure and sale

We do not sell personal information or use it for targeted advertising. Information may be disclosed to the service providers described above, to approved administrators who need it to operate the group, when required by law, or when reasonably necessary to protect people and the service.

Retention

Join-interest submissions are scheduled for deletion after 24 months. Analytics queue records expire after 90 days, and their pseudonymous visitor/session hashes are erased as soon as aggregation completes. Non-identifying hourly, daily, monthly, and all-time rollups may remain as service history. Abuse-prevention identifiers expire after 48 hours. In-app notifications are retained for 12 months, email delivery records for 13 months, successful message-push outbox records for 30 days, push delivery records for 60 days, and push subscriptions that have not been used for 180 days are removed. AI operational metadata is retained for 90 days, idempotency records for 30 days, and raw survey vote records for 12 months after a survey closes. Aggregate survey results may remain as community history.

Active account and meeting records are retained while operationally needed. Archived meeting history, tasks, and audit records may be retained for up to seven years to preserve accountability and continuity. Approved deletion requests are applied to live systems, subject to security, legal, and legitimate historical-record needs; separately expiring backups may contain older copies temporarily.

Security

We use server-side authorization, deny-by-default database and storage rules, App Check integration, input validation, restricted service credentials, encrypted managed services, protected file paths, and audit records. No internet service can guarantee absolute security. Please report suspected misuse promptly to contact@sacramentomensgroup.com.

Your choices and requests

You may ask to access, correct, export, or delete information associated with you, or withdraw from future public-group correspondence. Email contact@sacramentomensgroup.com from the address connected to the request. We may need to verify identity before disclosing or changing private records.

Children

This service is intended for adult men and is not directed to children under 13. Do not submit a child's information through the public form or private workspace. Contact us if you believe a child's information was submitted.

Changes

We will update the effective date when this policy materially changes. This policy is a best-practice working policy based on the current system and has not been reviewed by an attorney.