iConfirm Privacy Policy — v2
Reviewed — effective 2026-08-31
Effective date: 2026-08-31
BIBS Specialty Services, Inc. ("BIBS," "iConfirm," "we," "us," or "our") provides iConfirm, a United States web application for church youth confirmation programs (the "Service"). This Privacy Policy explains how we collect, use, disclose, retain, and protect information through the Service.
Because iConfirm is used by students, including children under 13, Section 10 contains our children's privacy and COPPA disclosures. Parents should also read the separate Children's Privacy Notice and the direct notice displayed during enrollment.
1. Who operates iConfirm
BIBS Specialty Services, Inc.
735 Scanlan Avenue
St. Louis, Missouri 63139
Email: office@iconfirm.app
Telephone: 314-222-2777
iConfirm is offered for use in the United States. It is not currently designed for users outside the United States.
2. Account roles
- A Parent creates and authorizes a Student account, manages payment, can reset the Student's PIN, and may exercise rights concerning the Student's information while the Student is a minor.
- A Student uses lessons, records progress, answers surveys, and may write reflections. The Service is designed for students age 11 and older.
- A Church subscribes to a separate organization account and authorizes designated Leaders.
- A Leader can view attendance, lesson progress and completion, and content a Student deliberately marks as shared. Leaders cannot use the Service to view private reflections or private survey responses and cannot reset or obtain Student PINs.
3. Information we collect
Information from Parents
We collect:
- name and verified email address;
- account and authentication records;
- parent attestations and consent records;
- the Student information the Parent enters;
- subscription selection, billing status, transaction identifiers, discount information, and limited payment metadata received from Stripe; and
- communications, support requests, cancellation requests, and privacy requests.
Stripe processes payment-card details. iConfirm does not receive or store complete card numbers.
Information about Students
We collect:
- real name and nickname;
- an association with the Parent and participating Church;
- a hashed Student PIN;
- attendance, lesson progress, completion status, and activity timestamps;
- private and shared reflections, notebook entries, and survey responses;
- sharing selections; and
- export, consent, access, and deletion records.
We collect the Student's date of birth when the Parent creates the account. It is used only to check eligibility for the optional Discussion Board, which is limited to Students 13 and older; it is never shown to a Church Leader, never included in a roster or export, and not used for any other purpose. A Student enrolled before we began collecting it has none on file, and in that case the Parent supplies one only if they choose to opt that Student into the Board. The Parent also attests that the Student is within the intended audience and authorizes the account.
Photo upload features are disabled at launch. We will update the applicable notices and obtain any required consent before enabling a materially different photo feature.
Information from Churches and Leaders
We collect Church name and account details, Leader name and verified email, subscription information, role and access records, invitations, attendance and progress administration, shared-content activity, and communications with us.
Technical information
Our systems and service providers may automatically process IP address, browser and device type, operating system, request timestamps, authentication/session identifiers, and security or server logs. We use cookies or similar storage needed for sign-in, security, preferences, and operation of the Service. We do not currently use advertising cookies, social-media pixels, cross-site behavioral tracking, or third-party advertising analytics.
4. How we use information
We use information to:
- create and authenticate accounts;
- obtain and document parental authorization;
- provide lessons, save Student work, and display progress;
- keep private content separate from Church/Leader views;
- display content according to a Student's sharing selection;
- process subscriptions, discounts, renewals, cancellation, and account status;
- send account, consent, service, security, and transaction communications;
- respond to support, privacy, deletion, export, and legal requests;
- protect the Service, investigate misuse, and maintain tenant isolation;
- comply with law and enforce our agreements; and
- improve the Service using aggregated, deidentified, synthetic, or redacted information that does not contain real Student reflections or other Student-generated content.
We do not use real Student reflections, photos, or other Student-generated content to train artificial-intelligence or large-language models.
5. Who receives information
Parents and Students
Students can see their own content. A Student may choose to email or otherwise share particular entries with the Parent. A Parent may also request review, export, deletion, or cessation of collection by contacting us from the Parent's verified account email. We will verify and respond to the request as required by law.
How a review request is fulfilled. After we verify the requester is the Student's Parent using the Parent's account email, we provide the Parent the actual reflection content requested (a direct copy, not a summary or alternative), delivered through the same secure channel used for other account communications. We do not require the Student's separate consent to fulfill a Parent's COPPA review request, consistent with COPPA's parental-rights framework.
Churches and Leaders
Authorized Leaders receive the Student's name/nickname, attendance, progress and completion information, and content the Student deliberately marks as shared. Leaders do not receive private reflections, private survey responses, or Student credentials through the Service. We disclose this category of information to Leaders for the purpose of administering the confirmation program at the Parent's participating Church.
When a Student revokes a sharing selection, iConfirm stops future Leader access immediately and instructs the Church to delete prior exports where feasible. We cannot retrieve copies independently printed, photographed, or retained outside the Service.
Service providers
We use the following service providers to operate the Service:
- Supabase: database, authentication, and data storage;
- Vercel: hosting and delivery;
- Resend: transactional email; and
- Stripe: payments, subscriptions, discounts, and transaction records.
They receive information only as needed to provide their services to us, secure the Service, or comply with law. We require service providers handling children's personal information to maintain appropriate confidentiality, security, and integrity protections and limit their use of the information. [BUILD/FILE REQUIRED] We have not yet filed each provider's written data-processing assurance in our records — see launch board (memo finding F-6). All four publish a standard DPA; downloading and filing them is a paperwork task, not a drafting one.
We may update this list when service providers change. A material change affecting children's information will receive the notice and consent required by law.
Legal, safety, and business circumstances
We may disclose information when reasonably necessary to comply with valid legal process, protect rights and security, investigate misuse, respond to an emergency request as permitted by law, or complete a corporate transaction subject to appropriate confidentiality and continued legal obligations.
We do not sell or rent personal information. We do not disclose Student information for targeted advertising or another company's independent marketing.
6. Reflections and limits of privacy
The Service is designed so that Leaders do not receive private reflections or private survey responses. Privacy from Leaders is enforced by application permissions and query controls.
Reflections are protected by encryption in transit and the hosting/database provider's encryption at rest. They are not field-level or end-to-end encrypted. The Company's sole authorized operator can technically access plaintext records through privileged database access when necessary to provide verified parent rights, secure or troubleshoot the Service, respond to legal process, or address another documented operational need. We do not routinely read or monitor reflections.
iConfirm is not a confidential pastoral, counseling, mental-health, emergency, or clergy-penitent communication service. We do not promise that entries are legally privileged or immune from valid legal process.
7. Security
We use administrative, technical, and physical safeguards designed for the nature and sensitivity of the information, including TLS in transit, provider encryption at rest, role-based application access, hashed PINs, restricted privileged access, and tenant separation. No system is completely secure, and we cannot guarantee that unauthorized access will never occur.
8. Retention and deletion
What we retain, why, and for how long. We keep Student information only for as long as needed to run the program the Parent enrolled the Student in, and never merely because storage is inexpensive. Personal information collected from a Student is not retained indefinitely.
After paid access ends or nonpayment begins, the intended Student-content lifecycle is:
- by day 5, ordinary Student use is locked while download/export remains available;
- through day 90, the Student or verified Parent can retrieve the Student's information; and
- by day 90, Student content is deleted from active systems and applicable backups under our control.
We may retain the minimum consent evidence, transaction records, security logs, dispute records, and legal-hold information for longer when reasonably necessary to comply with law, establish consent or transactions, prevent fraud, resolve disputes, or enforce agreements. We segregate such records from Student content where feasible and delete them when their purpose expires. Complete details, including a full data-class-by-data-class schedule, are in our internal Data Retention and Deletion Policy, available on request.
These limited records are the one exception to "full deletion": consent evidence, transaction, and security-incident records are kept for at least 3 years, or 1 year after the account terminates, whichever is longer (the floor set by California B&P §17602(a)(6), applied here as our general standard). Everything else in the deletion lifecycle above is not subject to this carve-out.
Backups. The production database runs on a backup-capable hosting plan with automatic backups active. We have not yet independently verified multi-factor authentication on the hosting account or completed a restore test using synthetic data, so we do not represent that our restore capability has been tested.
9. Your choices and rights
Parents may contact us from their verified account email to:
- review the personal information collected from or about their child;
- request a secure export;
- request correction of inaccurate account information;
- request deletion;
- refuse further collection or use; or
- withdraw consent.
We may request information reasonably necessary to verify the requester and protect the Student. Withdrawing consent or requiring deletion may make continued use impossible.
Adults may also request access, correction, or deletion of their own account information, subject to applicable law and legitimate retention needs. We do not discriminate for exercising a legally protected privacy right.
10. Children's privacy and COPPA
iConfirm knowingly serves Students who may be under 13. We treat every Student enrollment as requiring Parent initiation and authorization, regardless of age.
Before activating a Student account, we provide the Parent direct notice of:
- the information we intend to collect from the Student;
- how we will use and disclose it;
- which information Leaders can and cannot see;
- our service providers;
- our retention practices; and
- the Parent's review, deletion, and refusal rights.
Resolved 2026-08-23. For a 100%-discounted enrollment, we do not rely on the checkout charge to verify the Parent — instead, our operator confirms consent directly with the Parent (currently in person or by phone) before the Student's enrollment code is issued, and records the verification event. For a paid seat, the Stripe payment-card process serves as verification, consistent with the card issuer's transaction notification to the Parent. The parent_consent_events record — verifier, Parent, Student, timestamp, method, notice version — is the complete documentation standard for the in-person/phone method; no additional written record is required beyond it.
Resolved. Consent records identify the Parent, Student, timestamp, notice/policy versions, consent scope, and verification method for every enrollment. The parent_consent_events table records this for both the paid-seat path (card verification) and the $0-discount path (operator's direct in-person/phone verification, per §10 above).
Parents may withdraw consent or exercise the rights listed in Section 9 by emailing office@iconfirm.app from the verified Parent account email. If we materially change the collection, use, or disclosure practices to which a Parent consented, we will provide a new direct notice and obtain new consent when required.
11. Student safety and requests for help
We do not routinely monitor private reflections for self-harm, abuse, danger, or pastoral concerns. A Student should not use a private reflection to request emergency help. Instead, the Service shows a static "Need help?" page: it tells a Student that private reflections are not monitored, directs them to a trusted adult, Parent, or Church representative, gives the 911 emergency number, and gives the 988 Suicide & Crisis Lifeline (call or text). That page does not collect any information, submit a request, send an email, or notify anyone — it is informational only.
Revised 2026-08-24, on counsel's recommendation. An earlier, interactive version of this feature — where a Student's request notified an authorized Leader and Parent — has been removed from the Student-facing app. Counsel's guidance: an active request-and-notify mechanism creates a mandated-reporter trigger under Missouri law today, and under every other state's law the moment a Church outside Missouri joins, and the burden of tracking each state's mandated-reporter statute for that mechanism is not sustainable at this stage. The underlying code is not deleted and may be reintroduced later. Each participating Church is independently responsible for telling its own Students how to seek pastoral help outside iConfirm. BIBS maintains a narrow internal procedure for the rare case where a disclosure reaches BIBS directly (for example, through customer-support email) rather than through a Leader.
If someone is in immediate danger, contact 911 or an appropriate emergency service.
12. Changes to this Policy
We may update this Policy as the Service changes. We will post the updated version with a new effective date. We will give at least 30 days' advance notice of material changes when reasonably practicable and obtain new parental consent when COPPA or another law requires it.
13. Contact us
Questions, complaints, cancellation notices, and privacy requests may be sent to:
BIBS Specialty Services, Inc.
735 Scanlan Avenue
St. Louis, Missouri 63139
office@iconfirm.app
314-222-2777
Resolved. The mailbox is active (CONTACT-01). MFA on the mailbox and a documented monitoring schedule are separate open items — see launch board.
