Privacy policy

Your information, your choices and our responsibilities.

This policy explains what AfterTheChurch processes, why it is needed, who can receive it and how you can exercise your rights. It applies to public browsing, private contributor sessions, story submissions, uploaded media, moderation and communications.

Effective: 5 August 2026Last reviewed: 5 August 2026Read the Terms of Use

Privacy at a glance

No sale of personal dataWe do not sell personal information or run targeted advertising.
Private by defaultNew submissions remain private until moderation is complete and publication is approved.
Choice of public identityContributors choose which name and organisation details appear publicly.
Deletion controlsContributors can unpublish, request changes and delete submissions from the same browser without an account.

1. Data controller and contact

AfterTheChurch is a survivor-led project operated from Norway. Until a separate legal entity is identified on this website, Ian Shammah, operating AfterTheChurch, is the data controller for the processing described here.

Privacy, legal and takedown contactsha2mmah@gmail.comUse “Privacy request” or “Legal notice” in the subject line.

AfterTheChurch is not a confidential crisis, medical, legal or safeguarding service. Do not use this email for emergencies. Use the Safety and Urgent Help page instead.

2. Information we process and why

We aim to collect only information needed to receive and moderate stories, protect the service and honour contributors’ choices. You do not need an account or sign-in to read, submit or use any public feature.

Private contributor session

Examples: A random technical identifier, browser session token and session dates. Public contributors are not asked to create an account or password.

Purpose: Keep a submission and its private management controls connected to the browser used to submit it.

Legal basis: Performance of the Terms of Use; legitimate interests in secure access and preventing unauthorised changes.

Moderator authentication

Examples: Administrator email address, password hash, session token and password-reset records.

Purpose: Restrict the private moderation queue to specifically authorised administrators.

Legal basis: Legitimate interests in safeguarding, confidentiality and service security.

Story submission and moderation

Examples: Title, summary, story text, chosen identity, named organisation, privacy level, categories, content notices, region, religious background, images, audio, video, moderation notes and change requests.

Purpose: Privately receive, review, edit, publish, manage or delete a submission according to the contributor’s choices.

Legal basis: Consent; explicit consent where a contributor includes special-category information; legitimate interests in safe editorial review and legal claims.

Security and technical records

Examples: IP address and browser information used to create a one-way rate-limit fingerprint, timestamps, request records, security logs and error information.

Purpose: Prevent spam, abuse and unauthorised access; diagnose faults; protect contributors and the service.

Legal basis: Legitimate interests in security, service integrity and abuse prevention; legal obligations where applicable.

Published material

Examples: The approved story, selected identity fields, media, content notices, categories and publication metadata.

Purpose: Make the contributor’s approved story available to readers under the selected privacy setting.

Legal basis: Consent and the publication licence in the Terms of Use.

When processing is required by law, necessary to protect vital interests or needed to establish, exercise or defend legal claims, a different lawful basis may apply. We will explain that basis when reasonably possible.

3. Survivor stories may contain sensitive information

A submission can reveal religious or philosophical beliefs, health, sexuality, ethnic background, trauma or alleged offences. Some of this is “special-category” personal data under the GDPR. Do not include it unless it is necessary to your story and you want us to process it under the privacy level you selected.

The story form asks for explicit consent before submission. Consent can be withdrawn by unpublishing or deleting the submission, or by contacting us. Withdrawal does not make earlier lawful processing unlawful and cannot reliably remove copies already made by readers, search engines, archives or other third parties.

Do not upload private medical records, government identifiers, passwords, verification codes, private addresses or another person’s confidential material. Where a story identifies another person, we may limit, redact or refuse publication to protect privacy, safety and legal rights.

4. Who receives information

  • Authorised moderators can access private submissions only where needed for review, safety, support requests or administration.
  • Supabase provides anonymous contributor sessions, administrator authentication, database services and private file storage as a data processor.
  • Vercel provides website hosting, delivery, security and operational logging as a data processor.
  • Email infrastructure delivers password-reset messages for authorised administrators only.
  • Authorities or advisers may receive limited information where required by law, necessary to protect life or safety, or reasonably needed for legal claims.

We do not give unpublished stories or contributor identities to donors, churches, ministries or advertisers. Service providers may process information outside Norway or the EEA subject to their contractual safeguards and lawful transfer mechanisms. Their current terms and subprocessor arrangements govern those transfers.

5. Publication, privacy levels and limits of anonymity

Fully Public: the chosen name and church or organisation name are displayed.

Anonymous Church: the chosen name is displayed and the organisation appears as “Church Name Withheld.”

Anonymous Author: “Anonymous Author” is displayed and the church or organisation name is shown.

Fully Anonymous: “Anonymous Author” and “Church Name Withheld” are displayed.

These settings control what AfterTheChurch intentionally displays. They cannot guarantee that a person will remain unidentified. Writing style, dates, events, locations, images, voices and details may allow others to infer identity. Public pages may be copied, photographed, cached, indexed or archived beyond our control.

Moderation reduces risk but does not independently verify every claim or guarantee that published material is complete, accurate or lawful. People identified or affected by content can request review, correction, restriction or removal using the contact above.

6. Retention and deletion

  • Rate-limit fingerprints are automatically removed after approximately 24 hours.
  • Anonymous technical session identifiers are retained as needed to connect private submission controls, prevent abuse and meet legal obligations.
  • Administrator authentication records are retained while moderation access is authorised and for the limited period needed for security or legal obligations.
  • Pending submissions are retained while review or requested changes remain active.
  • Approved stories remain until withdrawn, deleted or removed through moderation.
  • Rejected and withdrawn submissions are scheduled for deletion after 30 days, unless the contributor deletes them sooner or a lawful preservation need applies.
  • Current uploaded media is removed with a permanent submission deletion. Provider backups or security logs may retain encrypted or isolated copies for a limited period under provider schedules.

We may preserve specific records when reasonably necessary for safety, fraud prevention, a legal obligation or the establishment, exercise or defence of legal claims. Access will be restricted and the material deleted when the preservation purpose ends.

7. Cookies, local storage and public browsing

When a visitor submits or manages a story, the site stores an essential anonymous session token in that browser. It contains no public account email or password and exists so another visitor cannot change the submission. Clearing site data or changing device may remove access to those private controls. Administrator sessions and content-warning choices may also be stored in the browser.

The site does not currently use advertising or third-party behavioural analytics. Essential hosting and security logs may still be generated. If non-essential analytics, marketing cookies or similar technologies are introduced, the notice and consent controls must be updated before activation where the law requires it.

8. Security and breach response

Measures include private media storage, signed short-lived media links, authenticated server routes, restricted administrator access, input validation, rate limiting and limited collection. Access should be granted only to people who need it for an authorised purpose.

No internet service can guarantee absolute security or uninterrupted availability. If a breach creates a risk to people’s rights and freedoms, we will assess notification duties and notify the relevant authority and affected people where required.

9. Your data-protection rights

Depending on the circumstances, you may request access, correction, deletion, restriction, portability, withdrawal of consent or objection to processing based on legitimate interests. You also have the right not to be subject to a solely automated decision that produces legal or similarly significant effects.

Send requests to sha2mmah@gmail.com. We may ask for proportionate information to verify your identity or authority. Do not email identity documents unless specifically requested through a safe method. We aim to respond without undue delay and normally within one month where the GDPR applies.

If the issue is not resolved, you may complain to the Norwegian Data Protection Authority (Datatilsynet) or the supervisory authority where you live or work.

10. Children and young people

Public educational material can be read without an account. Story submissions are intended for people aged 18 or over. A person under 18 must not submit a story unless a parent or legal guardian has provided verifiable consent and the operator has agreed in writing beforehand.

If we learn that a child’s information was submitted without an appropriate basis, we may restrict access and delete it. Immediate child safety concerns should be directed to emergency or specialist services, not the story form.

11. Changes to this policy

We may update this policy when the service, providers or law changes. The effective date will be changed and material changes affecting contributors will be communicated through a reasonable channel where possible. New uses requiring consent will not be applied merely by rewriting this policy.

Conclusion

Privacy is a continuing responsibility.

The purpose of this policy is not to remove every risk. It is to set clear limits, collect less, keep unpublished stories restricted, make publication a deliberate choice and give contributors workable routes to change or remove their information.