Privacy Policy
Last updated August 1, 2026
Trellis — Privacy Policy
Effective date: August 1, 2026 Last updated: August 1, 2026
This Privacy Policy explains how Douglas Tech LLC, an Indiana limited liability company doing business as Trellis ("Trellis," "we," "us"), collects, uses, shares, and protects personal information when you use the Trellis app and related services (the "Service"). By using the Service, you agree to this Policy. If you do not agree, do not use the Service.
1. Who we are and how to reach us
Trellis provides software to campus ministries and their members. For privacy questions or requests, contact support@douglas-tech.com or Douglas Tech LLC, 11807 Allisonville Rd, Unit #1234, Fishers, IN 46038.
2. Information we collect
You provide:
- Account information — name, email address, and (optionally) phone number.
- Age information — your date of birth, collected once at sign-up to confirm you're old enough to use Trellis. We retain your date of birth to keep your eligibility and age-appropriate settings current (for example, whether you are under 18); we use it only for eligibility and safety, never display it to others, and remove it if you delete your account.
- Sign-in details — if you sign in with Apple or Google, we receive basic account details from that provider (such as your name and email address).
- Profile information — any details you add to your profile.
- Your content — the messages, images, and files you send in direct messages and group channels; content you post or share; event RSVPs; and similar activity.
- Organization membership — the campus ministry and groups you belong to and your role.
- Safety reports — if you submit a report or are the subject of one, we keep the report, a snapshot of the reported content and its context, and records of how it was handled.
Collected automatically:
- Device & push information — device identifiers and push notification tokens (via Firebase Cloud Messaging) so we can deliver notifications.
- Server logs & diagnostics — basic technical logs generated when the app communicates with our servers (such as IP address, timestamps, and error information), used to keep the Service working. We do not currently use third-party analytics or crash-reporting tools; if that changes, we will update this Policy first.
- Age signals from your app store — where required by law (for example, for minors in certain U.S. states), Apple or Google may provide us an age category and parental-consent status for your account. We use these signals only to provide age-appropriate access as required by those laws.
We do not intentionally collect special categories of data beyond what you choose to share in your messages or profile. Because messages may contain anything you type, treat message content as potentially sensitive.
3. How we use information
- To provide and operate the Service — authentication, messaging delivery, group and event features.
- To send notifications you've enabled (push via Firebase). If we later offer SMS notifications, we will update this Policy and obtain any required consent first.
- To keep the Service safe — moderation, investigating reports, preventing abuse and fraud, and meeting our legal and child-safety obligations.
- To improve and maintain the Service.
- To communicate with you about the Service.
4. How messages are stored and who can access them
- Your messages are stored on our servers so the Service can deliver and display them. They are not end-to-end encrypted. We made this choice deliberately so we can act on abuse reports and meet our child-safety obligations.
- Your Organization's leaders cannot read your private messages.
- Authorized Trellis personnel may access message content only in limited circumstances: to investigate a report you or another user submits, to comply with the law or legal process, or to meet our child-safety reporting duties. Such access is restricted and logged. You consent to this limited access as part of our Terms of Service.
- We do not monitor or scan your private messages for content.
5. How we share information
We share personal information only as described here. We do not sell your personal information, and we do not share it for cross-context behavioral advertising.
With your Organization. Your Organization's leaders can see your profile information (such as your name and email address), your group memberships and role, your event RSVPs and attendance, and anything you post in group channels or other shared spaces they have access to. They cannot read your direct messages (see Section 4).
We use trusted service providers ("processors") who handle data on our behalf and are bound to protect it:
- Hosting & database — Supabase, Railway;
- Web hosting — Vercel;
- Push notifications — Firebase (Google).
If we add new service providers (for example, an SMS provider), we will update this list.
We may also disclose information: to comply with the law or valid legal process; to NCMEC and law enforcement in connection with child-safety reporting; to protect the rights, safety, or property of Trellis, our users, or others, including where we believe in good faith that disclosure is necessary to prevent an emergency involving danger of death or serious physical injury; and in connection with a merger, acquisition, or sale of assets (with notice where required).
6. Your privacy rights
Depending on where you live (for example, California and other U.S. states with privacy laws), you may have the right to:
- Know / access the personal information we hold about you;
- Delete your personal information;
- Correct inaccurate information;
- Obtain a copy (portability) of your information;
- Opt out of sale or sharing for targeted advertising — note: we do none of these;
- Limit the use of sensitive information.
To exercise these rights, contact support@douglas-tech.com, or use the in-app account-deletion control for deletion. We will verify your request and respond within a reasonable time, as required by any applicable law. If we deny a request, you may appeal by contacting support@douglas-tech.com with "Appeal" in the subject line. We will not discriminate against you for exercising any of these rights.
7. Data retention and account deletion
- We keep personal information only as long as needed for the purposes in this Policy, unless a longer period is required by law or for safety/recordkeeping.
- You can delete your account at any time from within the app (Profile → Delete account).
- What deletion does: we permanently disable sign-in and remove personal identifiers — we delete your sign-in identities, and replace your name with a generic label such as "Former member," and remove your email and phone number and push tokens.
- What we retain (anonymize-not-purge): for child-safety, moderation-integrity, group-recordkeeping, and legal reasons, the messages you sent and your group/attendance records are retained, disconnected from your account and identity — your name is replaced with a generic label and your account identifiers are removed. The text of a message you wrote may still contain information you chose to include in it. We do not attempt to re-link retained records to you. Retained records are kept for up to 3 years after account deletion, unless we are required to keep specific records longer (for example, content preserved for a child-safety report, which federal law requires us to keep for at least one year).
- Content you reported or that was reported about you, and related records, may be retained as needed to meet legal obligations (including child-safety evidence-preservation requirements).
8. Security
We use reasonable administrative and technical measures to protect personal information, including encryption in transit (TLS) for connections between the app and our servers. (At-rest encryption posture to be confirmed and stated here — see topic 033 Phase B3.) No system is perfectly secure; we cannot guarantee absolute security. If a security breach affecting your personal information occurs, we will notify you and the relevant authorities as required by law.
9. Children's privacy
- The minimum age to use Trellis is 14. The Service is not directed to and not intended for children under 13, and we do not knowingly collect personal information from anyone under 13.
- If you are a parent or guardian and believe a child under 13 has provided us information, contact support@douglas-tech.com and we will delete it.
- For users aged 14–17, see our Terms of Service regarding parental/guardian consent.
10. International users
The Service is operated in the United States and intended for use in the United States. We do not target users in the European Union; if you access the Service from outside the U.S., you do so on your own initiative and your information will be processed in the U.S.
11. California notice at collection
At or before collection, we collect the categories described in Section 2 (identifiers, customer records, internet/network activity, and the content you provide) for the purposes in Section 3. We do not sell or share personal information. Our Service does not respond to browser "Do Not Track" signals. Retention periods for these categories are described in Section 7. For California rights and how to exercise them, see Section 6.
12. Changes to this Policy
We may update this Policy. If we make material changes, we will provide notice (for example, in-app or by email) and update the "Last updated" date. Your continued use after changes take effect means you accept the updated Policy.
13. Contact
support@douglas-tech.com · Douglas Tech LLC, 11807 Allisonville Rd, Unit #1234, Fishers, IN 46038
Appendix — store-submission privacy artifacts (internal checklist, not part of the published policy)
Apple App Privacy ("nutrition label"): Contact Info (name, email, phone), User Content (messages, attachments, safety reports), Identifiers (user ID, FCM token), Other Data (age bracket) → all Data Linked to You. Do not declare Usage Data/Diagnostics unless analytics/crash tooling actually ships. No tracking (no third-party ad/data-broker sharing → no ATT prompt). Privacy-policy URL in App Store Connect and in-app. In-app account deletion (5.1.1(v)) + retained-data disclosure (Section 7). Age rating under Apple's current tier scheme (4+/9+/13+/16+/18+, mandatory new questionnaire since 2026-01-31): unrestricted user-to-user chat lands 16+ or 18+ — answer the questionnaire honestly and let it assign; not Kids Category.
Google Play Data Safety: declare data types actually collected/shared (no SMS, no analytics unless shipped), purposes, "encrypted in transit = yes" (TLS), "users can request deletion = yes (partial retention disclosed)." Privacy-policy URL must match this document. In-app deletion and a web deletion-request URL entered in Play Console. Target audience set to teen/adult bands only; not Designed-for-Families.
State app-store age laws (evaluate at Phase B age-gate design): TX SB 2420 (live) and LA Act 481 (live 2026-07-01, no developer safe harbor) require developers to consume store-provided age-category/parental-consent signals for those states' minors; UT follows 2027-05-06. Apple's Declared Age Range API and Google's Play Age Signals API are the mechanisms — see 033-02 §7 item 3.