Privacy Policy
Last updated 17 September 2026
Under legal review. Awaiting review by a qualified lawyer. Every fact we have not yet confirmed is shown as a visible marker rather than filled with a plausible-looking value, because a privacy policy naming the wrong legal entity is worse than one that visibly has a gap in it.
These documents are published in English only. The rest of this site is bilingual; these pages are not, because machine-assisted translation of a legal document is worse than none — a mistranslated legal basis is a liability rather than a courtesy. A reviewed Swedish translation will follow.
The short version. The assessments on this site do not send us your answers. They run entirely in your browser. We use no analytics, no advertising trackers and no profiling cookies. There are exactly two ways we come to hold personal data about you: you email us, or you open a group reading and give us your own contact details so we can reach you about it. Answering somebody else's group reading is not one of them — your answers are encrypted before they leave your browser, and we do not hold the key.
Who we are
Kingdom Vanguard is operated by [[LEGAL ENTITY NAME — Daniel]], [[COMPANY FORM AND REGISTRATION NUMBER — Daniel]], of [[REGISTERED ADDRESS — Daniel]]. For questions about this policy or about your data, write to [[CONTACT EMAIL — Daniel]].
We are the data controller for the personal data described below.
Answering on your own: we receive nothing
The Church Health Index and the Leadership Health Assessment are computed in your browser using code delivered with the page. Your answers, your dimension scores, your band and your report exist only on your device. No answer, score or report is sent to us or to anyone else.
This is a deliberate design decision, not a feature we have not built yet. It means a church leader can answer honestly — including the questions about leadership health and congregational trust that are hardest to answer honestly — without any possibility that the answers reach us, a denomination, or an employer.
Group readings: what changes, and what does not
A group reading lets a church put the same instrument to its leaders and its congregation and see where the two accounts differ. That needs somewhere to collect responses, so unlike answering on your own, it does involve a server. Here is precisely what that server sees.
Your answers are encrypted in your browser before they are sent. The key is generated in the facilitator's browser and carried in the fragment of the invitation link — the part after the `#`. A fragment is never transmitted in a web request. So the key does not reach our server, is not in its logs, and is not in any backup. What the server stores is a block of ciphertext, the initialisation vector needed to decrypt it, which respondent group it belongs to, and the minute it arrived.
We cannot read your responses. Not "we choose not to": we do not have the key, and we cannot obtain it. If you send us the code for a reading and ask us what it says, we cannot tell you.
Nothing stored beside a response says who wrote it. No name, no email, no IP address, no browser fingerprint, no account, no per-respondent identifier. There is no field that records who answered, so there is no query anyone could write — us, a court, or an attacker with the whole disk — that would establish it.
Two categorical questions are asked, and they travel inside the encryption. Your part in the church, and how long you have been there. They exist so a report can tell the accounts apart instead of averaging them, they are not scored, and a group smaller than eight is never reported separately, because role and tenure together can identify a person in a small church even without a name.
Below the anonymity threshold, the server does not hand the responses over at all. Not to us, and not to the person who opened the reading. Suppression is not a rule the report politely applies at the end; below the line there is nothing to decrypt.
Contributing to a European reference set: a second, separate decision
Every church-health instrument in this field compares a congregation to American churches, and none of them says so. There is no European reference set, because nobody has built one. We would like to, and we will not do it by quietly repurposing readings people ran for their own churches.
So it is a separate consent, it belongs to the person who opened the reading, and it is off unless they turn it on. Agreeing to look at your own church is not agreeing to become a data point in somebody else's research, and the interface offers refusal as the first of two equally visible options rather than as an unticked box.
- What would be kept: when a reading is destroyed, one row — the dimension scores, the country, the size band and the tradition given when it was opened.
- What would not: no responses, no church name, no contact details, no code, nothing that identifies a congregation or anyone in it. A row that cannot be traced to a church cannot be traced to a person in one.
- When anything would be published: not until there are enough churches that no single one is visible in the result, and we will publish that number before we publish anything drawn from it.
Nothing has been contributed yet, because nothing has been built yet. The choice is recorded now so that a reference set, if it ever exists, can only be built from readings whose facilitator agreed at the time — rather than from readings fitted afterwards with a consent nobody gave. Anyone holding a reading's code can see which way it is set.
If you open a group reading, we hold your details
The person who opens a reading gives their name, email, church and position, and optionally the church's size, tradition and country. This is the one place on this site where we deliberately collect personal data, and we are stating it plainly rather than leaving it to be discovered.
- What it is for: so we can reach the person responsible for a reading, and so we know which church a reading belongs to. Nothing else. It is not used for marketing, it is not shared, and it is not sold.
- Legal basis: Article 6(1)(b) GDPR where you are asking us for the service, and otherwise Article 6(1)(f) — our legitimate interest in being able to contact the person who opened a reading on our infrastructure.
- Who can see it: us. It is deliberately never returned by the part of the service that hands out a reading, because everyone you invite holds the reading's code, so anything returned there would be returned to all of them.
- How long: a reading stops accepting responses after 120 days, and everything in it — every response and your own details — is destroyed 180 days after you opened it, whether or not anyone ever built the report.
- Why a fixed window rather than "deleted once you are finished": the report is built in your browser under a key our server does not have, so the server cannot tell when you are finished. It can keep a promise about a date, and that is the promise we make. The window is enforced by the code that serves the reading, and the number you are reading here is served by that same code rather than typed into this page.
- Deleting it sooner: there is a delete control in your own facilitator console. It destroys every response and your contact details together, immediately, without asking us. You can also write to [[CONTACT EMAIL — Daniel]] and we will do it.
- Taking a copy: there is an export control beside it, which hands you everything we hold for that reading as a file. The responses come out as the ciphertext they are, so you can give the export to your own data protection officer without giving them your congregation's answers.
A word about sensitivity. Your name and church, recorded alongside a set of answers about a church's spiritual life, is data revealing religious belief — special-category data under Article 9 GDPR. This is why the responses are encrypted with a key we do not hold unless you hand it to us, why no respondent is named, and why the facilitator record is deliberately separated from the responses rather than joined to them. We would rather over-explain this than have a denominational data protection officer discover it for themselves.
What is stored on your device
The site writes a small amount of information to your browser's local storage. None of it is sent to us.
| What | Why | How long |
|---|
| Your assessment answers and results | So you can leave and come back without starting over, and so your report can be displayed | Until you clear your browser data |
| Your language choice | So the site opens in the language you chose | Until you clear your browser data |
| A group reading you have opened or joined: its code, its encryption key, and — if you opened it — the token that lets you delete it | So you can return to a reading without the link, and so the report can be decrypted on your device | Until you clear your browser data, or use "forget this reading" |
Because everything we store is strictly necessary to provide a service you have explicitly requested, no consent is required for it and we do not show a consent banner. See the Cookie and Local Storage Notice.
If you email us
The contact links on this site open your own email program. If you write to us, we keep your message and your address so we can answer.
- Legal basis: Article 6(1)(f) GDPR — our legitimate interest in responding to people who contact us.
- How long: 24 months from last contact
- Where: our mail is handled by Microsoft 365 (Microsoft Ireland Operations Limited), processing in the European Union.
Please keep email to logistics when you first write. Do not describe a pastoral situation, a safeguarding concern, or a person in your congregation in a first message. Email is not a confidential channel. Tell us you would like to talk, and we will talk.
Server logs
Our hosting provider records standard technical information when a page is requested: IP address, time, page requested, browser type. This is used to keep the site running and secure, and for nothing else. We do not read these logs to build a picture of who is visiting.
- Legal basis: Article 6(1)(f) GDPR — our legitimate interest in the security and availability of the site.
- How long: [[HOSTING LOG RETENTION — one email to the host]]
Processors
| Processor | Purpose | Location |
|---|
| GoDaddy.com, LLC | Serving this website | United States |
| GoDaddy.com, LLC | Storing encrypted group-reading responses and facilitator records | United States |
| Microsoft 365 (Microsoft Ireland Operations Limited) | Receiving and sending correspondence | European Union |
That is the complete list. There is no analytics provider, no scheduling provider, no payment provider and no AI provider on this site, because none of those features are built yet. When one is added it will appear in this table before it goes live, not after.
The group-reading store runs on the same hosting as the site; there is no separate database service and no third party involved in it. Our host can see the ciphertext we store, which is what it is: our host cannot read a response any more than we can.
A note on our hosting. GoDaddy.com, LLC processes in the United States. For transfers out of the European Economic Area it relies on the EU-US Data Privacy Framework and Standard Contractual Clauses. We are naming this plainly rather than burying it: the strongest privacy claim on this site is that your assessment answers never leave your browser, and that claim is unaffected by where the pages are served from — but your IP address does reach our host, and you are entitled to know that.
What we do not do
We do not use Google Analytics or any other analytics service. We do not use advertising or remarketing pixels. We do not embed social media trackers or fonts loaded from third parties. We do not fingerprint your browser. We do not build a profile of you. We do not sell, rent or share personal data.
Your rights
Under the GDPR you may ask us for a copy of the personal data we hold about you; have it corrected if it is wrong; have it deleted; restrict or object to how we use it; and receive it in a portable format. Where we rely on consent, you may withdraw it at any time.
To exercise any of these, write to [[CONTACT EMAIL — Daniel]]. We will respond within one month.
You may also complain to a supervisory authority. In Sweden this is Integritetsskyddsmyndigheten (IMY), imy.se. If you live in another EU or EEA country you may complain to your own national authority instead.
A note on the assessments. If you have only used an assessment on your own, or answered somebody else's group reading, and have never contacted us, we hold no personal data about you at all, and a request for access will return nothing. This is not evasion. It is the point of the design, and it is why we cannot delete an individual response from a group reading on request: we cannot tell which one is yours, and neither can anyone else. The whole reading can be deleted, by the person who opened it or by us.
If you have opened a group reading, we hold the details you gave, and you can see, correct or destroy them. The fastest route is the delete control in your own facilitator console.
Children
This site is intended for church leaders and is not directed at children. We do not knowingly collect personal data from anyone under 13.
Changes
If we change this policy we will update the date at the top and, where the change is material, say so on the site.