Privacy Policy
Privacy isn’t just a legal page to us — it’s the trust at the foundation of everything we do. The moms in our community share their hardest stories, their unspoken prayers, and their honest feedback. We protect that trust with real safeguards, not just promises. The full details are below; if anything is unclear, write to us.
This Privacy Policy explains what data we collect across the entire Catholic Mom Calm experience — our website, our courses and digital products, our memberships, our coaching calls, the Catholic Mom Calm and Calm Catholic Kids mobile apps, our community Slack, our email lists, our podcast, our affiliate links, and our in-person events — how we use it, who we share it with, and your rights over it. We’ve written it to be readable. If anything is unclear, email [email protected] and we’ll explain.
Catholic Mom Calm and Calm Catholic Kids are brands of Made for Greatness, LLC (“we”, “us”, “our”), the data controller for the information described below.
1. Services this policy covers
This Privacy Policy applies to all of the following:
- Our websites — catholicmomcalm.com, you.catholicmomcalm.com, madeforgreatness.co, and any related subdomains.
- Email lists and newsletters — including welcome sequences, course communications, and broadcast emails.
- Digital products and courses — including Mary’s Heart, Martha’s Order, Healing Wounds, Motherhood Sparkle, and any other course, workbook, or digital resource we sell or include with a membership.
- Memberships — the Catholic Mom Calm community and its associated benefits.
- Coaching calls — group calls and one-on-one coaching sessions delivered by video conference.
- The Catholic Mom Calm App — our iOS and Android mobile application (the “App”).
- The Calm Catholic Kids App — our iOS and Android mobile application for children ages 4–6, where parents purchase audio packs on our website and unlock them inside the App. The Calm Catholic Kids App is built so the parent is the only account holder — see Section 15 for the children’s-privacy protections that apply.
- Slack workspace — the community Slack workspace available to qualifying paid members.
- Podcast — the Catholic Mom Calm podcast.
- In-person events — including the Mother / Daughter Pilgrimage and any other live retreat or gathering we host.
- Affiliate links — links from our content to third-party retailers where we may earn commission on qualifying purchases.
Where a section below applies only to a specific service, we say so plainly.
2. Information we collect
We collect only what we need to deliver the services above. The exact set depends on what you use.
2.1 Account and contact information
When you create an account on our website, in the App, or in the community, we collect your name and email address. If you choose to sign in with Apple, Google, or another single-sign-on provider, we receive the basic profile information that provider chooses to share with us (typically name and email). If you book a coaching session, we collect any intake-form responses you provide.
2.2 Subscription and payment information
When you purchase a product, course, membership, or app subscription, we record what you bought, the price, the date, and your renewal or cancellation status. Card numbers are processed by our payment processors (Stripe, Ontraport, Apple, and Google Play). We do not see, store, or have access to your full payment card numbers. Our payment processors send us a token, the last four digits of the card, and the cardholder name for receipts and reconciliation.
2.3 Content you create or share
- Posts, comments, replies, and reactions in the App’s Wins feed.
- Messages, posts, reactions, and files you share in our Slack workspace.
- Replies to email broadcasts, including unsubscribe choices.
- Worksheet responses, quiz answers, and other content you save inside courses.
- Questions submitted before, during, or after coaching calls.
- Wins, prayers, photos, or stories you submit for sharing in newsletters or marketing — only when you opt in to that sharing.
- The journal text you write inside the App’s Daily Pray & Plan flow — see Section 8 for the special protections that apply to journal entries.
2.4 Coaching session content
Group coaching sessions are delivered through Zoom and recorded. Recordings include audio, video, and the public chat. They are stored in our course platform (Membership.io) and made available to qualifying members as replays. By joining a recorded group session, you consent to being recorded and to your recording being shown to other members of that program. One-on-one coaching sessions are not routinely recorded; see Section 6 for details on both formats and your opt-out options.
2.5 In-person event information
For in-person events such as the Mother / Daughter Pilgrimage, we collect what travel and safety require: legal name as it appears on your passport, date of birth, passport number and expiration, citizenship, dietary restrictions and food allergies, accessibility needs, emergency contact, and any medical or health information you choose to share with us. Some of this information is shared with our travel partners (the booking agency, the airline, the hotels and tour providers) only to the extent strictly necessary to complete the booking and protect your safety. We do not retain passport scans after the event ends.
2.6 Behavioral and device information
When you use our website, the App, or open our emails, our service providers collect standard technical and behavioral data on our behalf — IP address, device type and operating system, browser, the pages you visit, the links you click, the buttons you tap inside the App, and the dates and times of your activity. On the App we also collect crash reports and error diagnostics. Section 5 describes the cookies and pixels we use to collect this on the website.
2.7 Marketing preferences and segmentation
Your subscription status to our marketing emails, your tag-based segments inside our CRM (e.g., “completed Mary’s Heart, Martha’s Order”), and any preferences or interests you’ve declared in surveys or signup forms.
3. How we use your information
We use the information described in Section 2 to:
- Deliver what you bought — fulfill course access, membership benefits, App features, coaching sessions, and event registrations.
- Send you the communications you signed up for — receipts, course notifications, newsletters, and event details. You can unsubscribe from marketing communications at any time without losing access to anything you’ve paid for.
- Provide customer support — answer your questions, process refunds, and troubleshoot access issues.
- Improve our products — understand which courses are completed, which App features are used, which lessons resonate, and where moms get stuck. This is done in aggregate; we do not read individual journal entries.
- Run our business operations — billing, accounting, fraud prevention, and security monitoring.
- Show relevant marketing — run ads on Meta and Google about our products and retarget visitors who showed interest. Section 5 covers this in detail.
- Comply with legal obligations — respond to lawful requests, enforce our Terms of Service, and protect our community and ourselves from fraud or abuse.
4. Service providers we share with
We share specific data only with service providers who need it to deliver the services in Section 1. Each is bound by data processing terms that limit their use of your data to providing services to us. We do not sell your personal information.
- Ontraport
- Email marketing, marketing automation, customer relationship management (CRM), website forms, and order processing. Receives: name, email, purchase history, marketing tags, behavioral signals from our website. ontraport.com/privacy
- Stripe
- Payment processing for purchases on our website. Receives: name, billing address, email, payment card details (which Stripe processes; we do not see them), and transaction amount. stripe.com/privacy
- Apple App Store and Google Play
- Distribution of the App and processing of in-app purchases on iOS and Android. Subject to Apple’s and Google’s privacy policies. apple.com/legal/privacy · policies.google.com/privacy
- RevenueCat
- Subscription management and receipt validation for the App. Receives: anonymous user identifier, subscription state, device platform. revenuecat.com/privacy
- Google Firebase
- Account authentication, database storage, and backend services for the App. Receives: account email, all App-stored data including journal entries (encrypted at rest), planning history, and behavioral activity inside the App. firebase.google.com/support/privacy
- Membership.io
- Course hosting and storage of coaching call replays. Receives: name, email, course progress, video viewing history, and Zoom recordings of group and 1-1 coaching calls. membership.io/privacy
- Zoom
- Video conferencing for coaching calls and live events. Receives: name, email, IP address, audio/video stream during sessions, chat messages. Recordings are downloaded from Zoom and stored in Membership.io. zoom.us/privacy
- Acuity Scheduling (Squarespace)
- Booking and calendar management for one-on-one coaching sessions. Receives: name, email, booking time, intake form responses. squarespace.com/privacy
- Slack
- Hosts our community workspace. Receives: name, email, profile photo, all messages and files you share inside the workspace. slack.com/trust/privacy/privacy-policy
- HelloAudio
- Hosts and delivers the audio recordings inside the App (prayers, daily sessions, meditations). Receives: device IP and request logs when audio plays. helloaudio.fm/privacy
- Expo Push Notifications
- Relays push notifications you have enabled inside the App to your device. Receives: device push token (an anonymous device identifier).
- Google Analytics
- Website usage analytics. Receives: IP address (truncated where supported), pages visited, referrer, device and browser information. We do not use Google Analytics inside the App. policies.google.com/privacy
- Meta (Facebook) Pixel
- Website conversion tracking and ad audience building. Receives: events such as page view, product view, and purchase, along with hashed identifiers used to match website visitors to Meta accounts. We use this to run ads to people who have visited our site or look similar to our customers. facebook.com/policy
- Sentry
- Crash and error reporting for the App. Receives: anonymized device identifier, App version, error stack traces, and limited diagnostic context. We do not transmit journal entries or other user content to Sentry. sentry.io/privacy
- Podcast hosts and platforms
- Our podcast is distributed through standard podcast platforms (e.g., Apple Podcasts, Spotify, Amazon Music, Google Podcasts). Listening data is collected by those platforms under their own privacy policies; we receive only aggregate, anonymized download counts.
- Travel partners (in-person events only)
- For pilgrimages and retreats, we share necessary registration data with the booking agency, airline, lodging provider, and ground transport operator(s) for the specific event. The exact partners are disclosed at the time of registration.
- Affiliate retailers
- If you click an affiliate link from our content (for example, an Amazon Associates link), the destination retailer sets cookies on your browser to credit the referral. We see only aggregate referral counts; we do not see what you purchase.
We may also disclose information when required by law (subpoena, court order, lawful government request) and to professional advisors (accountants, lawyers, auditors) bound by confidentiality. If we are ever involved in a merger, acquisition, or sale of business assets, your information may be transferred as part of that transaction; we will notify you and any successor will be bound by this policy or one materially equivalent.
5. Cookies, analytics, and advertising
Our websites use cookies and similar technologies. Cookies are small text files stored by your browser that let websites remember you and let analytics and advertising tools function.
5.1 What we use cookies for
- Strictly necessary — keeping you signed in, remembering your shopping cart, security tokens. These cannot be turned off without breaking the site.
- Analytics (Google Analytics) — measuring how many people visit our pages, which posts are popular, and where visitors come from. Used in aggregate.
- Advertising (Meta Pixel) — tracking which website actions led to purchases, building audiences for ad targeting on Facebook and Instagram, and retargeting visitors who showed interest.
- Affiliate tracking — third-party retailers may set their own cookies when you click an affiliate link.
5.2 Your choices
You can manage cookies in your browser settings — most browsers let you block third-party cookies, clear cookies on exit, or block specific domains. You can also opt out of personalized advertising at:
- Meta (Facebook / Instagram): facebook.com/adpreferences
- Google: adssettings.google.com
- Industry-wide opt-out: aboutads.info/choices (US) or youronlinechoices.eu (EU)
The App itself does not use Google Analytics, Meta Pixel, or any third-party advertising tracker. Advertising tracking applies only to our websites.
6. Coaching call recordings
Group and one-on-one coaching sessions delivered by video conference are recorded. Recordings include the audio, the video feeds of all on-screen participants, and the public chat. We use the recordings to make replays available to qualifying members.
Notice and consent. The recording status is announced at the start of each session, and a recording indicator is visible inside Zoom. By joining a session that is being recorded, you consent to being recorded and to your recording being shown to other members of the program for which the call was conducted.
If you would prefer not to appear in the recording:
- Mute your microphone.
- Turn off your video.
- Avoid posting in the public chat — chat is included in the recording.
- Send any private questions to [email protected] instead of asking them live.
Where recordings are stored. Recordings are downloaded from Zoom and uploaded to our course platform (Membership.io). Access is restricted to qualifying members of the program for which the call was conducted. We do not publish coaching call recordings publicly on YouTube, social media, or our website.
One-on-one coaching. One-on-one coaching sessions are not routinely recorded. When a recording is made — for example, at your request, or as part of an ongoing coaching package — it is shared only with you and your coach, and is never made available to other members. If you would prefer your one-on-one session not be recorded, tell your coach at the start of the session and we will turn recording off.
7. In-person events
For events involving travel — most importantly the Mother / Daughter Pilgrimage — we collect sensitive information that is not collected anywhere else in our services: passport details, date of birth, citizenship, and any medical, dietary, or accessibility information you choose to share with us.
This data is used solely to:
- Book your travel and lodging.
- Meet airline and tour-operator regulatory requirements.
- Plan meals, transport, and accessibility on the ground.
- Reach your emergency contact in case of a medical event.
Travel partners (booking agency, airline, hotel, tour operators) receive only the fields they require to complete their part of the trip. We delete passport-number records and passport-image scans within 90 days of the event’s conclusion. Dietary, medical, and emergency-contact information is retained only while the event is active.
8. Special protections for App journal entries
Your App journal entries are subject to stronger protections than the rest of your data. (This section applies only to the Catholic Mom Calm App. The Calm Catholic Kids App contains no journaling feature; the protections for that App are described in Section 15.2.) The text you type into the Daily Pray & Plan journal includes your most private prayers — about marriages, children, doubt, fear, hope. We protect these with the safeguards listed below.
- Encrypted at rest — journal entries are stored in Google Firebase, where they are encrypted at rest by Google’s standard infrastructure. Direct database access does not yield readable entries.
- Encrypted in transit — TLS / HTTPS for everything moving between your device and our backend.
- Owner-only access — Firebase Security Rules restrict reads and writes on the journal collection to your authenticated account only. There is no admin tool inside our company that lets the Catholic Mom Calm team read your journal entries. Sterling cannot read them. The team cannot read them. The developer cannot read them.
- Never used to train AI — we will never use journal entries to train any AI model, ours or anyone else’s. See Section 9.
- Not transmitted to crash reporting — Sentry, our error reporting tool, never receives journal entry contents.
- Export anytime — you can download your full journal as a plain-text file from the App: Settings → Help → Privacy & your data → Export my journal.
- Delete anytime — when you delete your App account, all journal entries are permanently removed from our database within seconds. See Section 13 for the 90-day grace period that applies to subscription cancellation (separate from account deletion).
9. Artificial intelligence
We currently use AI tools only for internal analysis — for example, summarizing aggregate, anonymized customer feedback or analyzing coaching call themes that we have already collected. These tools do not have access to your App journal, your direct messages, or any individually identifiable user content beyond what we explicitly choose to feed them, and they are never used to make consequential decisions about you.
What we do not currently do:
- We do not run an AI chatbot inside the App, the website, or our community.
- We do not train any AI model on your journal entries, coaching session transcripts, or any other personal content.
- We do not share your data with third-party AI providers for them to train their models.
Coming changes. We are planning to introduce an AI-powered chatbot in a future release. Before that feature ships, we will update this policy to disclose what data the chatbot has access to, how prompts are processed, and your options to opt in or out. You will receive notice of that change before it goes live.
10. Things we never do
- We do not sell your personal information. Not to advertisers, not to data brokers, not to anyone.
- We do not read your App journal entries. No employee, contractor, or partner has a tool that exposes journal text. The data is encrypted in storage and locked to your account.
- We do not train AI on your content. See Section 9.
- We do not allow third-party advertising trackers inside the App. No Meta Pixel, no Google Ads conversion tracking, no third-party SDKs that profile users.
- We do not contact you outside the channels you signed up for. Buying a course does not opt you into the broader newsletter; subscribing to the newsletter does not give us permission to call your phone.
11. Marketing emails and opt-out
We send marketing emails about our courses, programs, and events to people who have signed up for our list, made a purchase, or registered for a free resource. Every marketing email includes an unsubscribe link in the footer. Clicking it removes you from marketing communications immediately.
You will continue to receive transactional messages (receipts, course access notifications, password resets, account alerts) regardless of marketing email preferences, because those are necessary to operate your account.
To stop all email contact entirely, unsubscribe and then email [email protected] asking us to delete your account.
12. Your rights
You have rights over your data. Most of these rights apply regardless of where you live; some are specific to your jurisdiction.
12.1 Rights available to everyone
- Access — request a copy of the data we hold about you.
- Correction — ask us to correct inaccurate data.
- Deletion — ask us to delete your account and the data associated with it (subject to limited exceptions where we’re legally required to retain something, such as financial records).
- Export — for App journal entries, use the in-App export tool. For other data, email us.
- Unsubscribe — opt out of marketing emails at any time.
12.2 European Economic Area, United Kingdom, and Switzerland (GDPR / UK GDPR)
If you are in the EEA, the UK, or Switzerland, you also have the right to:
- Restrict or object to specific processing.
- Receive your data in a portable, machine-readable format.
- Withdraw consent at any time (where processing is based on consent).
- Lodge a complaint with your local data protection authority. We would prefer the chance to address your concern first — please contact us before filing.
Our legal bases for processing under GDPR are: contract (delivering the products you bought), legitimate interest (operating and improving our business, fraud prevention), consent (marketing emails, certain cookies), and legal obligation (tax and accounting).
12.3 California (CCPA / CPRA), Virginia, Colorado, Connecticut, Utah, and other US state privacy laws
If you are a resident of a US state with a comprehensive privacy law, you have the right to:
- Know what categories of personal information we collect, the sources, and the purposes.
- Access the specific pieces of personal information we hold about you.
- Delete your personal information.
- Correct inaccurate personal information.
- Opt out of the “sale” or “sharing” of personal information for cross-context behavioral advertising. We do not sell personal information for money. Our use of Meta Pixel may qualify as “sharing” under California law for cross-context behavioral advertising; you can opt out of this sharing by emailing us or by using the cookie management options in Section 5.
- Limit the use and disclosure of “sensitive personal information.” We do not use the limited categories of data we collect for purposes beyond what is described in this policy.
- Be free from retaliation for exercising any of these rights.
You may also designate an authorized agent to exercise these rights on your behalf, with proof of authorization.
12.4 How to exercise these rights
For the App journal, use the in-App export and delete tools. For all other rights, email [email protected] with the subject line “Privacy Request” and tell us what you’d like to do. We may need to verify your identity (typically by confirming you control the email address on file). We respond within 30 days for GDPR / UK requests and within 45 days for US state law requests.
13. How long we keep your data
We retain different categories of data for different periods, based on what’s necessary to operate the service and what the law requires.
- Active accounts — we retain account and content data for as long as your account is active.
- Cancelled App subscriptions (account not deleted) — if you cancel your App subscription but do not delete your account, we hold your journal entries and planning history for 90 days after the cancellation date in case you want to come back. After 90 days, we permanently delete this data. Account email and subscription record remain for billing reconciliation.
- Account deletion — when you delete your account, we delete your user record and all associated content within a few seconds, including journal entries, planning history, habit data, reflections, protocols, systems, and Wins posts. This is non-recoverable.
- Course and membership purchase history — retained for as long as your account exists; tax and accounting records retained for the period required by US tax law (typically 7 years).
- Coaching call recordings — group program recordings are typically retained for at least 12 months after the program ends, so members can re-watch the full series; specific programs may keep recordings longer at our discretion. One-on-one coaching sessions are generally not retained beyond the engagement. If a one-on-one is recorded at your request, the recording is held only as long as needed to share it with you and is then deleted.
- In-person event data — passport numbers and scans are deleted within 90 days of event conclusion; dietary, medical, and emergency-contact information is deleted at event conclusion.
- Email marketing data — retained until you unsubscribe and request deletion. Unsubscribe alone removes you from sending lists; deletion removes the underlying record.
- Slack messages — retained according to Slack’s standard retention; we do not impose an additional retention period inside the workspace.
- Website analytics and ad-event data — retained according to the default settings of Google Analytics (currently 14 months) and Meta (currently up to 24 months for ad events).
14. International data transfers
We are based in the United States. The service providers we rely on are also primarily based in the United States. If you are accessing our services from outside the US, your data will be transferred to and processed in the US (and potentially other countries where our service providers operate).
For transfers from the EEA, UK, and Switzerland, we rely on Standard Contractual Clauses approved by the European Commission and the UK Information Commissioner’s Office, and on the data processing terms our service providers commit to. We have evaluated the protections offered by our processors and consider them adequate.
15. Children’s privacy
15.1 Adult services
Most of our services — the Catholic Mom Calm App, courses, memberships, coaching, the podcast, the website, in-person events, and our community Slack — are intended for adults (18 and over). We do not knowingly collect personal information from minors using these adult services. If you believe a minor has created an account on any of these adult services, please email [email protected] and we will delete the account.
15.2 The Calm Catholic Kids App
The Calm Catholic Kids App is intended to be listened to by children ages 4–6, but the parent is the account holder and the customer. The child does not log in, does not enter any information, does not appear inside the App as a user, and has no surface on which to communicate with anyone — there is no chat, no comments, no profiles, no social features.
Specifically, in the Calm Catholic Kids App:
- We do not ask for, store, or transmit a child’s name, age, photo, voice, or any other personal information.
- We do not track which audio tracks a child plays, how often, or how long.
- We use no third-party analytics SDKs, no advertising SDKs, no behavioral profiling tools — Firebase Analytics is disabled.
- There are no ads of any kind.
- There is no in-app browser. The few external links that exist (to the website checkout, the privacy policy, and support email) are placed behind a parental gate in the Settings screen and open in the system browser.
- We do not request access to the device’s location, microphone, camera, contacts, photos, or health data.
- Sign-in uses email and password only; we do not offer “Sign in with Google”, “Sign in with Apple”, or any other social-identity provider.
Where a child has selected a story, the App may save the playback position on the device so they can resume — that information never leaves the device and is not linked to any account or identifier we hold.
This design is intended to satisfy the U.S. Children’s Online Privacy Protection Act (“COPPA”), Apple’s “Kids” category requirements (Guideline 1.3 and 5.1.4), and Google Play’s “Designed for Families” program. If you believe a child’s information has somehow been collected by us through the Calm Catholic Kids App, contact [email protected] and we will investigate and delete any such data.
15.3 Mother / Daughter Pilgrimage
When a parent registers a daughter under 18 for the pilgrimage, the parent is the one providing consent and information. We collect only what is required to complete the booking and protect the child’s safety, and we apply the retention rules in Section 13 to that data.
16. Security
We protect your data using industry-standard practices: TLS / HTTPS for all data in transit, encryption at rest in our backend storage, role-based access controls inside our team, and regular review of who has access to what. The App’s journal is locked to your account by Firebase Security Rules — the strongest level of access control Firebase offers.
No system is perfectly secure. If we ever experience a data breach that affects your information, we will notify you in accordance with applicable law.
17. Changes to this policy
If we change this Privacy Policy, we will post the new version at this URL and update the effective date at the top. Material changes — those that affect how we handle your existing data, expand the categories of data we collect, or introduce new third-party processors — will be announced by email and, where appropriate, by an in-App or in-website notice that you must read before continuing.
18. Contact
Questions, concerns, or requests about your data — including data export, account deletion outside the App, formal data-subject requests under GDPR, UK GDPR, or US state law, and complaints — go to:
[email protected]
Made for Greatness, LLC
206 Ironwood Dr. #1096
Coeur d’Alene, ID 83814
United States