Privacy, Terms and Refunds

Public beta · Last updated 2026-08-09 · Contact and support · 한국어

Who operates Veil. Veil is a public beta run by Hyeonsu Hwang, an individual based in the Republic of Korea. It is not an incorporated company or a registered business. Business registration details (trade name, representative, registration number) will be published on this page when paid access opens.

This is a pre-legal-review draft. It describes how Veil actually operates today so you can make an informed decision. It does not mean a lawyer has reviewed it or that every statutory disclosure is final.

Privacy and personal records

Veil keeps account data and personal records (confessions, journals) separate by default. A personal record is not church data. A church administrator or pastor cannot read the text of your entries simply because you are a member of that church.

This is enforced by the database schema rather than by policy alone: the table used for reviewing flagged confessions has no user id column at all, so a reviewer cannot look up who wrote an entry even if they wanted to.

What we collect

DataPurpose and timingHow it is handled
Account identifiersSign-up, sign-in, sync across devicesEmail, display name, auth identifier — minimum necessary
Adult statusEligibility for the free public betaWe record only confirmation that you are 18 or older, not your full date of birth
Confessions, gratitude, quiet-time entries, journalsOnly for features you chose to use and saveEncryption at rest and access control on the server is the product standard
Personalised-reflection input and responseWhen you run the on-device reflectionProcessed on your device; only records you choose to save are sent to account storage
Consent and billing historyProving what you chose, providing the subscription, resolving disputesVersion, timestamp, per-item choice, payment identifiers

Storage, retention and deletion

Subprocessors

This is the complete list of external processors Veil relies on. Churches evaluating Veil may submit this table as-is.

ProcessorPurposeData sharedLocation
SupabaseAuthentication, sync and storage of saved records, anonymous counting of response-rating buttonsAccount identifiers, records you chose to save. The rating count stores no account identifier — only which button and reason you pressed, the document ID, locale, confidence band, and whether you were signed in. What you wrote is never includedUnited States
CloudflareWebsite and API hosting (Workers), visit statistics (Web Analytics)IP address, request metadata. Visit statistics set no cookies and do not identify visitors; only page path, referrer and performance metrics are recorded. Confession, prayer and journal text is never includedGlobal edge, primarily US
Google Sign-In (OAuth)Account creation and sign-in when you choose itEmail, profile name, unique identifierUnited States
StripeSubscription payment, tax calculation, invoicingEmail, billing address, tokenised payment methodUnited States, Ireland
getBibleServing public-domain Scripture textOnly the book and chapter requested. No user identifiersOutside Korea
Hugging FaceServing the MIT-licensed local semantic-search model filesIP address and ordinary request metadata for model-file GETs. Confession, prayer, journal text and search queries are not includedUnited States and other locations
PostHogProduct analytics. Loaded only when both a key and optional service-improvement consent are presentPage views, clicks, and text-free reflection signals: document ID, locale, confidence band, selected fit and reason. Confession, prayer and journal text is never sent; session replay is disabledUnited States
Google GeminiPaid personalised reflection and prayer composition (api/meditate.js, api/prayer.js)Input sent only when VEIL_GEMINI_PAID_TIER is set to 'true'. Default-deny guard active. Confession and gratitude text not sent before guard is liftedUnited States
The current personalised reflection does not call an external generative AI. Retrieval, reranking and response assembly run on your device. The paid personalised reflection and prayer composition endpoints (api/meditate.js, api/prayer.js) use Google Gemini but are guarded by a default-deny privacy guard unless VEIL_GEMINI_PAID_TIER is set to 'true'. A dormant experimental server path is not linked from the public interface.

Operator safety-monitoring boundary

The reflection and abuse-prevention log do not send confession text. The device derives only minimal self-harm, violence and abuse booleans, separated from identity. Entries you choose to save, however, are stored on our server under your account, and operators can open that original for limited reasons: a safety concern, an outage investigation, a support request, or a legal obligation. They are not opened otherwise.

Veil does not offer encryption that locks entries on your device so that operators cannot read them (end-to-end encryption). A journal-encryption setting used to appear in the app but never actually worked; that entry point was removed in September 2026. Storage is protected by TLS in transit, provider-managed encryption at rest, and row-level access control.

Local personalised reflection and safety

The personalised reflection is produced on your device from a versioned corpus using BM25, a semantic model we fine-tuned from the MIT-licensed multilingual-e5-small, structural reranking and fixed response composition. On first use the quantised model is downloaded from veildaily.com and cached; no request goes to a third-party model host, and your writing is not included in that request or sent to an external model provider.

The English response library is an early draft. The Korean library is written and reviewed by people. The English one was drafted on 2026-08-09 and has not yet been reviewed by a pastor. Scripture in it is quoted from the World English Bible, which is in the public domain. Treat responses as a starting point for prayer, not as counsel, diagnosis or crisis support.

Veil is not a substitute for medical, psychological or emergency services. If you are in danger or considering harming yourself, contact your local emergency number or a crisis line immediately.

Church sharing and care requests

The current public beta does not accept in-app pastoral-care requests or send contact information to a church. Before opening that feature, Veil will implement explicit recipient and data confirmation, consent, and delivery and access audit records, then update this policy.

Confessions, journals and AI responses are not automatically disclosed to a church or a guardian.

Terms of use

Who provides this service

Veil is operated and provided by Hyeonsu Hwang, an individual based in the Republic of Korea, who is responsible for the service and its contents. When paid subscriptions open, the Merchant of Record for those subscriptions is Paddle.com Market Ltd (30 Old Bailey, London, EC4M 7AU, United Kingdom). Paddle handles payment, tax collection and receipts, and Paddle appears on your card statement.

Nature of the service

Veil is a devotional tool in public beta. Features may change or be withdrawn. Veil does not represent any single denomination; its convictions are Reformed.

Your account

Scripture text

Korean Scripture is quoted from the Korean Revised Version (개역한글판, 1961), whose economic copyright expired on 2011-12-31 and which is therefore in the public domain. English Scripture is quoted from the World English Bible, which is in the public domain. Veil does not reproduce translations that require a paid licence.

Payment, cancellation and refunds

Veil does not accept paid subscriptions during the free public beta. Joining today does not start a recurring subscription or a paid period. The terms below apply as written from the moment paid access opens.

Seller and supplier

Cancellation

Refunds

Failed payments and price changes

Supporting Veil is a separate item that funds Veil’s operation and development. It is not presented as a church offering or as a tax-deductible donation, and Veil does not collect offerings on behalf of a church before that church’s contract and settlement structure exists.

Cookies and local storage

Veil does not use third-party advertising or tracking cookies. This is the complete list of what is actually stored.

NameTypePurposeNecessity
veil.themelocalStorageRemembers light/dark themeFunctional
veil.beta.consentlocalStorage and account storageRecords consent choices and consent or withdrawal timesRequired
veil.rot.*, streak recordslocalStorageAvoids repeating the same response; counts consecutive days on-deviceFunctional
Encrypted cachelocalStorageConvenience cache of your entries. Not the sole original storeFunctional
Auth sessionSupabase cookie/storageKeeps you signed inRequired
PostHog identifierCookie + localStorageProduct analytics. Not created unless an analytics key is configured, and not collected if your browser sends Do Not TrackOptional
veil.feedback.anon-consentlocalStorageRemembers your answer to the anonymous rating opt-in shown when you use Veil without an account. It is a yes/no flag, not an identifier, and we neither ask nor collect if your browser sends Do Not TrackOptional

Clearing this storage in your browser signs you out and removes the on-device cache. To delete records held on the server, use the process below.

Your rights (access, correction, deletion, portability)

What Veil holds — confessions, prayers and records of faith — is information about religious belief. It is a special category of personal data under GDPR Article 9, dado sensível under Brazil’s LGPD, Sensitive Personal Information under California’s CPRA, and sensitive information under Korea’s PIPA. Veil processes it only on the basis of your explicit consent.

These rights are offered to every user, regardless of where you live.

Use the privacy and data-rights contact path. We aim to respond within 30 days. Please write from your account email so we can verify it is you.

Veil does not sell personal records and does not share behavioural data for advertising. No processing that would constitute a “sale” or “share” under CPRA takes place.

International transfers

Veil’s infrastructure (Supabase, Cloudflare) and its AI and payment processors are located outside South Korea, primarily in the United States. Using the service transfers the data listed in the subprocessor table to those countries, for the purposes stated there.

Where data of EU or UK residents is transferred, Veil relies on the transfer mechanisms offered by each processor, such as Standard Contractual Clauses. Veil has not yet appointed an EU representative under GDPR Article 27. One will be appointed before Veil actively markets to EU users. We are disclosing this rather than leaving it unsaid.

If you would prefer that no transfer occur, you can use Veil without creating an account, or stop using it. Screens that work without an account do not send your writing to a server.

Data Processing Addendum for churches

Where a church determines the purposes and means of processing personal data through Veil, the church may act as controller and Veil as processor. We provide an English public-beta DPA template and a Korean draft for contract review.

The parties must complete their identities, scope, retention period and governing law and obtain appropriate legal review before signing. Publishing the template does not by itself form an agreement.