Privacy, Terms and Refunds
This is a pre-legal-review draft. It describes how Veil actually operates today so you can make an informed decision. It does not mean a lawyer has reviewed it or that every statutory disclosure is final.
Privacy and personal records
Veil keeps account data and personal records (confessions, journals) separate by default. A personal record is not church data. A church administrator or pastor cannot read the text of your entries simply because you are a member of that church.
This is enforced by the database schema rather than by policy alone: the table used for reviewing flagged confessions has no user id column at all, so a reviewer cannot look up who wrote an entry even if they wanted to.
What we collect
| Data | Purpose and timing | How it is handled |
|---|---|---|
| Account identifiers | Sign-up, sign-in, sync across devices | Email, display name, auth identifier — minimum necessary |
| Adult status | Eligibility for the free public beta | We record only confirmation that you are 18 or older, not your full date of birth |
| Confessions, gratitude, quiet-time entries, journals | Only for features you chose to use and save | Encryption at rest and access control on the server is the product standard |
| Personalised-reflection input and response | When you run the on-device reflection | Processed on your device; only records you choose to save are sent to account storage |
| Consent and billing history | Proving what you chose, providing the subscription, resolving disputes | Version, timestamp, per-item choice, payment identifiers |
Storage, retention and deletion
- Local browser storage is used as a convenience cache only. That cache is not encrypted, so please clear your records when you finish on a shared device. It is not treated as the sole original store for your records.
- Free or paid, you must be able to view, export and delete your own past entries.
- The current in-app deletion control removes personal records from
user_dataand reading progress. It does not yet delete the Supabase Auth account, church membership, shared church content or provider backups. Full account deletion and a verified backup-deletion period remain launch work; request help by email in the meantime. - Veil does not store raw card numbers. Payment methods are tokenised by the payment provider.
Subprocessors
This is the complete list of external processors Veil relies on. Churches evaluating Veil may submit this table as-is.
| Processor | Purpose | Data shared | Location |
|---|---|---|---|
| Supabase | Authentication, sync and storage of saved records, anonymous counting of response-rating buttons | Account identifiers, records you chose to save. The rating count stores no account identifier — only which button and reason you pressed, the document ID, locale, confidence band, and whether you were signed in. What you wrote is never included | United States |
| Cloudflare | Website and API hosting (Workers), visit statistics (Web Analytics) | IP address, request metadata. Visit statistics set no cookies and do not identify visitors; only page path, referrer and performance metrics are recorded. Confession, prayer and journal text is never included | Global edge, primarily US |
| Google Sign-In (OAuth) | Account creation and sign-in when you choose it | Email, profile name, unique identifier | United States |
| Stripe | Subscription payment, tax calculation, invoicing | Email, billing address, tokenised payment method | United States, Ireland |
| getBible | Serving public-domain Scripture text | Only the book and chapter requested. No user identifiers | Outside Korea |
| Hugging Face | Serving the MIT-licensed local semantic-search model files | IP address and ordinary request metadata for model-file GETs. Confession, prayer, journal text and search queries are not included | United States and other locations |
| PostHog | Product analytics. Loaded only when both a key and optional service-improvement consent are present | Page views, clicks, and text-free reflection signals: document ID, locale, confidence band, selected fit and reason. Confession, prayer and journal text is never sent; session replay is disabled | United States |
| Google Gemini | Paid personalised reflection and prayer composition (api/meditate.js, api/prayer.js) | Input sent only when VEIL_GEMINI_PAID_TIER is set to 'true'. Default-deny guard active. Confession and gratitude text not sent before guard is lifted | United States |
Operator safety-monitoring boundary
The reflection and abuse-prevention log do not send confession text. The device derives only minimal self-harm, violence and abuse booleans, separated from identity. Entries you choose to save, however, are stored on our server under your account, and operators can open that original for limited reasons: a safety concern, an outage investigation, a support request, or a legal obligation. They are not opened otherwise.
Sign-up and consent
Required
- Processing the personal data needed to provide your account and the service.
- Storing and processing sensitive faith and counselling-related records.
Optional — off by default
- Using adult records and AI responses for quality evaluation and service improvement.
- Receiving marketing messages.
Optional items are unchecked by default and are stored separately from required items. Signing up with Google follows the same gate: you must confirm adult status and both required consents before the redirect happens. Social sign-in is not a way around consent.
Age
Account creation and use of the free public beta are limited to people aged 18 or older. We record only adult confirmation, not a full date of birth. Veil does not currently offer a minor church-invitation or guardian-consent flow.
Local personalised reflection and safety
The personalised reflection is produced on your device from a versioned corpus using BM25, a semantic model we fine-tuned from the MIT-licensed multilingual-e5-small, structural reranking and fixed response composition. On first use the quantised model is downloaded from veildaily.com and cached; no request goes to a third-party model host, and your writing is not included in that request or sent to an external model provider.
The English response library is an early draft. The Korean library is written and reviewed by people. The English one was drafted on 2026-08-09 and has not yet been reviewed by a pastor. Scripture in it is quoted from the World English Bible, which is in the public domain. Treat responses as a starting point for prayer, not as counsel, diagnosis or crisis support.
Veil is not a substitute for medical, psychological or emergency services. If you are in danger or considering harming yourself, contact your local emergency number or a crisis line immediately.
Terms of use
Who provides this service
Veil is operated and provided by Hyeonsu Hwang, an individual based in the Republic of Korea, who is responsible for the service and its contents. When paid subscriptions open, the Merchant of Record for those subscriptions is Paddle.com Market Ltd (30 Old Bailey, London, EC4M 7AU, United Kingdom). Paddle handles payment, tax collection and receipts, and Paddle appears on your card statement.
Nature of the service
Veil is a devotional tool in public beta. Features may change or be withdrawn. Veil does not represent any single denomination; its convictions are Reformed.
Your account
- Keep your credentials secure and do not share your account.
- Do not use Veil to harass others, to upload another person’s private information, or for anything unlawful.
- We may suspend an account for abuse, after which you may request your data under the rights section below.
Scripture text
Korean Scripture is quoted from the Korean Revised Version (개역한글판, 1961), whose economic copyright expired on 2011-12-31 and which is therefore in the public domain. English Scripture is quoted from the World English Bible, which is in the public domain. Veil does not reproduce translations that require a paid licence.
Payment, cancellation and refunds
Veil does not accept paid subscriptions during the free public beta. Joining today does not start a recurring subscription or a paid period. The terms below apply as written from the moment paid access opens.
Seller and supplier
- The Merchant of Record for paid subscriptions is Paddle.com Market Ltd; the supplier of the service is Hyeonsu Hwang.
- Paddle appears on your card statement and on your receipt.
- Paddle calculates, collects and remits VAT and other applicable sales tax. Tax and the final total are shown separately at checkout before you pay.
- If a price cannot be charged in the currency shown, checkout fails with a clear message and you are not charged in a different currency.
Cancellation
- You can cancel at any time from your account. You do not need to contact us.
- Cancelling keeps your access until the end of the period you already paid for.
- After cancelling, no further payment is taken.
Refunds
- Within 7 days of a charge we refund it in full, whether or not you used the service. Nothing is deducted.
- After 7 days we refund what you paid minus the amount for the days you had access, counted up to the day you ask to cancel, and minus 10% of the amount charged. This follows the Korea Fair Trade Commission’s Consumer Dispute Resolution Standards for internet content services. A refund is never less than zero.
- That 10% already includes the payment processing cost we actually incur. Nothing else is deducted.
- Monthly subscriptions keep your access to the end of the period you paid for and only stop the next charge, so there is no remaining period to refund. If you would rather stop immediately and be refunded, we apply the rule above.
- Before we refund, we tell you the expected amount and each deduction, and we wait for your agreement.
- If you were charged twice, or you cancel because of a fault or outage on our side, we refund the full amount with nothing deducted.
- Refunds are returned to the original payment method and can take 5–10 business days depending on your provider.
Failed payments and price changes
- If a payment fails we retry it over the following days. Plus features may be locked during that time.
- If the payment ultimately fails, free features and everything you have written remain intact.
- If we change a price, we email you at least 30 days before your next renewal. You can cancel before then if you do not accept it.
- Refund and billing enquiries: support@veildaily.com. We reply within 3 business days.
Your rights (access, correction, deletion, portability)
What Veil holds — confessions, prayers and records of faith — is information about religious belief. It is a special category of personal data under GDPR Article 9, dado sensível under Brazil’s LGPD, Sensitive Personal Information under California’s CPRA, and sensitive information under Korea’s PIPA. Veil processes it only on the basis of your explicit consent.
These rights are offered to every user, regardless of where you live.
- Access — request a copy of the records held for your account.
- Correction — ask us to correct inaccurate information.
- Deletion — the current control deletes personal records from
user_dataand reading progress. It does not yet delete your Auth account, church membership, shared church content or provider backups. Email us for a scoped request; we will not describe it as full account deletion until that path and the backup period are verified. - Portability — export in a machine-readable format.
- Withdraw consent — optional analytics and marketing consents can be withdrawn at any time by emailing support@veildaily.com (we will act on your request within 30 days). Korean users may also change these in the settings UI. Withdrawal stops future optional processing and records the withdrawal time; it does not undo processing that already happened.
- Object or restrict — object to processing for a particular purpose.
- Automated decisions — Veil makes no automated decisions producing legal or similarly significant effects. An AI meditation is reference text generated because you asked for it; it is not counselling or a diagnosis.
Use the privacy and data-rights contact path. We aim to respond within 30 days. Please write from your account email so we can verify it is you.
International transfers
Veil’s infrastructure (Supabase, Cloudflare) and its AI and payment processors are located outside South Korea, primarily in the United States. Using the service transfers the data listed in the subprocessor table to those countries, for the purposes stated there.
Where data of EU or UK residents is transferred, Veil relies on the transfer mechanisms offered by each processor, such as Standard Contractual Clauses. Veil has not yet appointed an EU representative under GDPR Article 27. One will be appointed before Veil actively markets to EU users. We are disclosing this rather than leaving it unsaid.
If you would prefer that no transfer occur, you can use Veil without creating an account, or stop using it. Screens that work without an account do not send your writing to a server.
Data Processing Addendum for churches
Where a church determines the purposes and means of processing personal data through Veil, the church may act as controller and Veil as processor. We provide an English public-beta DPA template and a Korean draft for contract review.
The parties must complete their identities, scope, retention period and governing law and obtain appropriate legal review before signing. Publishing the template does not by itself form an agreement.