Nlarj

Privacy

Privacy Policy

Version v2.4.0 — Effective 2026-07-01

Privacy Policy

Version: v2.4.0 Effective Date: July 1, 2026 Last Updated: July 1, 2026

What changed in v2.4.0 (July 1, 2026): Added §3.5 "Customer-Directed AI Integration (Third-Party AI Assistant Access)" describing the optional Kingdom-plan connector that lets a church admin connect an external AI assistant (such as Claude or ChatGPT) to their own church's data, the data-controller / data-conduit / data-processor roles that apply, and the admin-facing consent and revocation controls; added a matching row to the §3.1 sharing table and to the §4.1 legal-basis table; added an "AI Connector Consent & Audit Records" row to §6 Data Retention (retained for 3 years as proof of consent under the DPDP Act, 2023, and kept even after account deletion on that legal basis). Full terms live in the AI Assistant Integration Terms.

What changed in v2.3.0 (May 21, 2026): Rewrote §9.1 to make the adults-only platform-account rule explicit (children appear only as parent-managed dependent profiles under §9.4); added a "Verifiability of parental consent" paragraph to §9.4(a) defining the in-app consent mechanism; named the Children's Data Protection Officer, the POCSO Reporting Officer, and the IT Rules 2021 Rule 3(2) Grievance Officer in §16. The "Children" line in the summary table was rewritten to match.

What changed in v2.1.0 (May 3, 2026): Added Section 9.4 "Kids Programs (My Family)" covering child profile creation, co-guardian linking, photo consent, QR pickup verification, and a minimal 90-day check-in/pickup audit log. Updated Sections 1.1 and 3.1 with the new child-data fields and the limited disclosure to your church's Kids Program organizers.

Nlarj ("we," "us," or "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your personal information when you use our membership-based software platform and related services (the "Platform").

About Nlarj: We are a technology company that provides software tools for faith-based communities. We offer a marketplace that connects clients with independent biblical guides. We do NOT provide guidance services directly.

This policy complies with:

  • EU: General Data Protection Regulation (GDPR) 2016/679
  • India: Digital Personal Data Protection Act, 2023 (DPDP Act) and Information Technology Act, 2000
  • USA: California Consumer Privacy Act (CCPA) and applicable state laws

Data Controller / Contact

The data controller (and "Data Fiduciary" under the DPDP Act, 2023) responsible for your personal information under this Privacy Policy is:

Promised Land Labs Private Limited (trading as "Nlarj") CIN: U94910AP2026PTC126073 Registered office: 6/1019, Guntakal, Anantapur District, Andhra Pradesh, India — PIN 515801 Data Protection Officer / privacy queries: privacy@promisedlandlabs.com

References in this Privacy Policy to "Nlarj," "we," "us," or "our" mean Promised Land Labs Private Limited, a private limited company incorporated under the Companies Act, 2013 of India, trading under the brand name "Nlarj."


Table of Contents

  1. Information We Collect
  2. How We Use Your Information
  3. Information Sharing
  4. Legal Basis for Processing (GDPR)
  5. Data Storage and Security
  6. Data Retention
  7. Your Rights
  8. Cookies and Tracking
  9. Children's Privacy
  10. International Data Transfers
  11. Content Moderation & Community Standards
  12. No Proselytization or Ideological Enforcement
  13. Voluntary Participation Affirmation (India)
  14. Third-Party Services
  15. Changes to This Policy
  16. Contact Us

1. Information We Collect

1.1 Information You Provide

Data TypeExamplesPurpose
Account InformationName, email, phone number, passwordAccount creation and authentication
Profile InformationProfile picture, bio, locationPersonalization and community features
Prayer RequestsPrayer content, prayer categoriesCore platform functionality
Church MembershipChurch affiliations, membership statusConnecting you with churches
Guidance Booking DataSession bookings, biblical guide preferencesPlatform scheduling features
Membership/SubscriptionPlan type, billing cycle, feature accessSoftware access management
Payment InformationBilling address, payment method (via Razorpay/Stripe)Processing transactions
CommunicationsMessages, support requestsPlatform communication
AI ConversationsChat messages, prompts, AI responsesAI-powered biblical guidance and study
Bible Study DataReading progress, daily study completions, Bible plan selectionsBible Plans and Daily Study features
AI Language PreferencePreferred language for AI responsesMulti-language AI response delivery
Sermon Planner DataSermon titles, notes, transcripts, AI-generated content (outlines, summaries, hashtags)Church Admin sermon preparation tools
AI-Generated ImagesVerse card designs, quote card imagesVerse Card Creator feature
Child / Dependent Profile Data (if you register a child via "My Family")Child's full name and nickname, date of birth, gender, allergies, medical notes, emergency contact name and phone, optional photoEnrolling your child in a church Kids Program (Sunday School, music class, kids' Bible study), check-in / pickup verification, and emergency response — see Section 9.4
Kids Program Activity (if your child is enrolled)Program enrollment records, check-in / check-out timestamps, pickup-by user, photo-consent flagOperating the program and producing the audit trail required for child safety
Co-Guardian Links (if you accept or initiate a guardian link)Parent/guardian relationship between two member accounts and a child profileLetting both parents see, edit, and pick up the same child without re-entering data

1.2 Information Collected Automatically

Data TypeExamplesPurpose
Device InformationDevice type, OS version, device IDApp optimization and security
Usage DataFeatures used, time spent, clicksImproving user experience
Location DataApproximate location (with consent)Prayer map, nearby churches
Log DataIP address, access times, errorsSecurity and troubleshooting

1.3 Information from Third Parties

  • Social Login: If you sign in via Google or Apple, we receive your name and email
  • Church Administrators: May add you to their church roster
  • Payment Processors: Transaction confirmations

2. How We Use Your Information

We use your information to:

2.1 Provide Our Services

  • Create and manage your account
  • Display and share prayer requests
  • Facilitate church membership
  • Enable guidance sessions
  • Process payments for platform subscriptions and guidance bookings
  • Display church-provided giving/payment information (Note: For UPI/direct giving, we do NOT process payments - see Section 3.4)

2.2 Improve Our Platform

  • Analyze usage patterns
  • Develop new features
  • Fix bugs and optimize performance
  • Conduct research (anonymized data only)

2.3 Communicate With You

  • Send service notifications
  • Respond to your inquiries
  • Provide customer support
  • Send optional promotional content (with consent)

2.4 Ensure Safety and Security

  • Detect and prevent fraud
  • Enforce our Terms of Service
  • Protect users and the platform

2.5 AI-Powered Features

Nlarj provides AI-powered features for faith exploration, Bible study, and church administration. Here is how we handle AI-related data:

Member App AI Features

FeatureData ProcessedHow Data Is Used
AI Biblical Guidance (Chat)Your chat messages and promptsSent to third-party LLM providers to generate responses; NOT stored permanently unless you save them
Bible SearchYour search queriesProcessed by AI to find relevant verses and explanations
Bible StoriesSelected stories and topicsAI generates narrative summaries of biblical stories
Daily StudyReading selections and reflectionsAI creates personalized study reflections
Bible PlansPlan creation preferences, completion progressAI generates customized Bible study plans
Verse Card CreatorSelected verses, design preferencesAI generates shareable verse card images
AI GreetingApproximate location (with your consent)Provides contextual, location-aware greetings
Language SelectionYour preferred AI response languageStored locally on your device; AI responses generated in your chosen language

Church Admin App AI Features

FeatureData ProcessedHow Data Is Used
Sermon PlannerSermon titles, notes, context, speaker nameAI generates sermon outlines, summaries, hashtags, discussion questions, recap emails, and quote/verse cards
Sermon TranscriptionSermon audio/video filesTranscribed locally on your device using an on-device transcription engine - audio is NEVER sent to external servers
AI Image GenerationText prompts from sermon/verse contentGenerates images for verse cards and quote cards
Local RestreamingStream keys for YouTube, Facebook, or custom streaming destinationsRuns locally on your device using local media processing tools - video data is sent directly from your device to your configured destinations (YouTube, Facebook, etc.) and NEVER passes through Nlarj servers
Local RecordingSermon/stream video recordingsStored locally on your device only

Key AI Data Practices

  • Conversations are NOT used to train AI models: We opt out of all third-party AI provider training programs
  • Sermon transcription is 100% local: Audio processing happens on your device - no audio data leaves your device
  • AI prompts are routed through our backend: Your prompts pass through our backend AI service, which may log anonymized usage analytics via a self-hosted analytics platform for quality monitoring
  • AI responses are ephemeral: Unless you explicitly save or export AI-generated content, it is not permanently stored on our servers
  • BYOK (Bring Your Own Key): Church Admins may configure their own OpenRouter API keys for AI features - we store these keys securely and encrypted

3. Information Sharing

3.1 We DO Share Information With:

RecipientWhat We ShareWhy
Other UsersPublic profile, public prayersPlatform functionality
Church AdministratorsMember informationChurch management
Kids Program Organizers (your church's Ministry Leader / Youth Leader roles)Your child's name, age, allergies, medical notes, emergency contact, photo (only if you opted in), and check-in / pickup eventsRunning the program safely — these fields are visible only to organizers of the specific church and program your child is enrolled in
Biblical Guides (Independent)Session booking, client requestsBiblical Guides deliver their services
Payment ProcessorsTransaction detailsPayment processing
Cloud ProvidersAll data (encrypted)Infrastructure
AI Providers (Google AI, OpenAI, OpenRouter)AI prompts and conversation context (anonymized where possible)Generating AI responses for biblical guidance, Bible search, sermon content, and study features
Church-Directed AI Assistants (only if your Kingdom-plan church admin connects one — e.g. Claude, ChatGPT, or another MCP-compatible tool)The church data the admin queries through the connector — which can include member names, contact details, event registrations, prayer requests, group and kids-program rosters, giving configuration, and analyticsAnswering the admin's own natural-language questions about their church. The admin chooses the AI provider; the data is then governed by that provider's own policies. See §3.5.
Legal AuthoritiesAs required by lawLegal compliance

3.2 We DO NOT:

  • Sell your personal data
  • Share data for third-party advertising
  • Provide data to data brokers
  • Use your prayers or conversations for AI model training
  • Send sermon audio to external servers for transcription (transcription is 100% local)
  • Share your BYOK (Bring Your Own Key) API keys with any third party

3.3 Guidance Session Data

IMPORTANT: Session content and communications during guidance are between you and the independent biblical guide. Nlarj does NOT access, monitor, or store the content of guidance sessions. Video sessions use end-to-end encryption. Any notes or records are managed by the biblical guide under their own privacy practices.

3.4 UPI/Direct Church Giving Data

IMPORTANT: NO PAYMENT DATA FOR DIRECT GIVING

For Church Giving features where we display UPI IDs, bank details, or other payment information:

Data TypeWhat We StoreWhat We Do NOT Store
Church Payment InfoUPI IDs, bank names (provided by churches)Your payment transaction details
User Giving DataNOTHINGAmount donated, payment status, transaction IDs
Payment ConfirmationNOTHINGAny proof of payment

You acknowledge:

  • When you pay via UPI or direct bank transfer to a church, that transaction is between you and the church - we have NO involvement
  • We do NOT receive, process, or verify any payment made via displayed UPI IDs
  • We have NO record of whether you donated, how much, or when
  • For donation receipts or tax documents, contact your church directly
  • We CANNOT assist with payment disputes for direct giving - contact your bank or church

3.5 Customer-Directed AI Integration (Third-Party AI Assistant Access)

Nlarj offers an optional Kingdom-plan feature that lets an authorized church admin connect an external AI assistant of their own choosing — such as Claude (Anthropic), ChatGPT (OpenAI), or any other tool that speaks the Model Context Protocol — to their own church's data, through our connector at mcp.nlarj.app. This feature is off by default and can only be enabled by a church administrator; members, counselors, and guests cannot enable it.

What data leaves Nlarj, and where it goes. When an admin enables the feature and asks the connected AI a question, the church data responsive to that question is transmitted out of Nlarj to the AI provider the admin selected. Depending on what the admin asks, that data can include member names, email addresses, phone numbers and addresses, event registrations, group and kids-program rosters, giving configuration, announcements, analytics, and prayer requests (which can reveal religious beliefs, health, or other sensitive information). Once that data reaches the admin's chosen AI provider, it is held in the admin's own account with that provider and is governed by that provider's terms and privacy policy — not this Privacy Policy. How long the provider keeps it, whether it is used to train models, and where in the world it is processed are all determined by the admin's agreement with that provider. We do not control those choices.

Who is responsible for what. For any data routed through the connector:

  • The church (acting through its admin) is the data controller / Data Fiduciary — it decides what to ask, which provider to use, and what to do with the answer, and is responsible for establishing a lawful basis and giving its members any notice their local law requires before routing their data to an external AI.
  • Nlarj acts only as a data conduit — we authenticate the request, enforce security controls (scoped access, per-connection audit logging of metadata, revocation), and pass the data through at the admin's instruction. We do not read the substance of the questions or answers, we do not decide what data is routed where, and we are not a party to the admin's relationship with the AI provider.
  • The AI provider (Anthropic, OpenAI, or whichever the admin connects) is the church's own processor, not a sub-processor of Nlarj, and does not appear on our Subprocessor List.

Your consent and control. Connecting an AI assistant requires an explicit in-app approval by the admin — they scan a QR code or paste a one-time code and then confirm on a screen that names the app requesting access. An admin can view and revoke any connection at any time from the admin app; revoking a connection stops further access by that AI assistant.

Consent record. So that we and the church can demonstrate that a connection was authorized (and later revoked), we keep an append-only record of each connect and revoke event — including the admin's user ID and email, the church, the name of the connecting app, the versions of the Terms and this Privacy Policy in force at the time, the source IP address, and the timestamp. This record is retained as described in §6 and is kept even after account deletion, as our lawful basis for keeping it is proof of consent, not the delivery of the service. It is not shared with the AI provider and is not used for marketing.

Full terms for this feature — including the church admin's own consent obligations to members — are set out in the AI Assistant Integration Terms, which form part of your agreement with us when the feature is enabled.


For users in the EU and those subject to GDPR, we process your personal data on the following legal bases:

Processing PurposeLegal BasisJustification
Account Creation & AuthenticationContractual NecessityNecessary to provide our services under the user agreement
Service DeliveryContractual NecessityProviding prayer requests, church management, guidance sessions, and AI features as promised
Payment ProcessingContractual Necessity & Legal ObligationRequired to process payments and comply with financial/tax laws
Safety & SecurityLegitimate InterestFraud prevention, system security, and protection of our platform and users
Improvement & AnalyticsLegitimate InterestUnderstanding usage patterns to improve the platform (with proper safeguards)
CommunicationsConsent & Legitimate InterestSending service updates (legitimate) and promotional content (consent-based)
Legal ComplianceLegal ObligationResponding to legal requests, regulatory inquiries, and law enforcement
AI-Powered FeaturesConsent & Contractual NecessityYou consent to send data to AI providers when you use these features; it's also contractually necessary to deliver the service
Customer-Directed AI Integration (admin-enabled connector — §3.5)Controller's Instruction & Legitimate InterestWhere an admin connects an external AI assistant, the church is the controller and establishes its own lawful basis for the underlying member data; Nlarj processes the connection metadata to authenticate, secure, and audit the connection
AI Connector Consent RecordsLegal Obligation & Legitimate InterestKeeping proof that a connection was authorized (and revoked) to meet our and the church's consent-record accountability obligations under the DPDP Act, 2023, and to establish or defend legal claims

For processing based on consent (such as promotional emails or analytics), you may withdraw consent at any time by:

Withdrawal does not affect the lawfulness of processing before withdrawal.


5. Data Storage and Security

5.1 Where We Store Data

Primary Storage (India-First):

  • User data is primarily stored on servers located in India
  • We use secure cloud providers with data centers in India and Singapore

For US Users:

  • Some data may be processed on US-based servers
  • All transfers comply with applicable data protection laws

5.2 Security Measures

We implement industry-standard security practices:

MeasureImplementation
Encryption in TransitTLS 1.3 for all connections
Encryption at RestAES-256 encryption for stored data
End-to-End EncryptionPrivate messages and guidance sessions
Access ControlsRole-based access, multi-factor authentication
Regular AuditsSecurity assessments and penetration testing
Secure PaymentsPCI-DSS compliant payment processing

5.3 Breach Notification

In the event of a data breach affecting your personal data:

  • India: We will notify CERT-In and affected users within 72 hours
  • USA: We will notify affected users as required by state laws

6. Data Retention

Data TypeRetention Period
Account InformationUntil account deletion + 30 days
Prayer RequestsUntil deleted by user or 2 years of inactivity
MessagesUntil deleted by user or 1 year after last activity
Guidance Records7 years (legal requirement)
Payment Records7 years (financial/tax compliance)
AI Connector Consent & Audit Records (§3.5)3 years from the connect or revoke event — retained even after account deletion, because the lawful basis for keeping it is proof of consent and the establishment/defence of legal claims, not delivery of the service
Log Data90 days
Deleted Account DataPermanently deleted within 90 days

7. Your Rights

7.1 Rights for All Users

You have the right to:

RightDescription
AccessRequest a copy of your personal data
CorrectionUpdate or correct inaccurate data
DeletionRequest deletion of your data
PortabilityReceive your data in a portable format
Withdraw ConsentOpt-out of optional data processing
ObjectObject to certain processing activities

7.2 Additional Rights for India Users (DPDP Act)

Under the Digital Personal Data Protection Act, 2023:

  • Right to access and correct your data through our Data Fiduciary
  • Right to grievance redressal
  • Right to nominate another person to exercise rights on your behalf

Data Fiduciary Contact: privacy@promisedlandlabs.com

7.3 Additional Rights for California Users (CCPA)

Under the California Consumer Privacy Act:

  • Right to know what personal information is collected
  • Right to delete personal information
  • Right to opt-out of sale of personal information (we do NOT sell data)
  • Right to non-discrimination for exercising your rights

To Exercise CCPA Rights: privacy@promisedlandlabs.com or call [Phone Number TBD]

7.4 How to Exercise Your Rights

  1. In-App: Settings -> Privacy -> Manage My Data
  2. Email: privacy@promisedlandlabs.com
  3. Support: Through our customer support channels

We will respond to requests within:

  • India: 30 days
  • USA/California: 45 days

8. Cookies and Tracking

8.1 Mobile App

Our mobile app uses:

  • Analytics SDKs: To understand app usage (can be disabled)
  • Crash Reporting: To fix bugs and improve stability
  • Push Notifications: With your explicit consent

8.2 Website (if applicable)

Our website may use:

Cookie TypePurposeRequired
EssentialSite functionalityYes
AnalyticsUsage statisticsNo (opt-in)
PreferencesRemember your settingsNo (opt-in)

8.3 Managing Cookies/Tracking

  • Mobile: Device settings or in-app privacy controls
  • Website: Cookie consent banner and browser settings

9. Children's Privacy

9.1 Adults-only platform accounts

Nlarj platform accounts are restricted to adults aged 18 and over. Children under 18 are present on the Platform only as parent-managed dependent profiles under Section 9.4 of this Privacy Policy. A child does not hold an independent account, login, or platform presence; all data about a child is processed under the parent/guardian's verifiable consent.

9.2 Parental Controls

Parents/guardians can:

  • Review their child's dependent-profile information
  • Request deletion of their child's data
  • Manage privacy settings on the child's behalf

9.3 COPPA Compliance (USA)

We do not operate child-facing accounts. For dependent profiles under §9.4 that pertain to a child resident in the United States, we obtain verifiable parental consent in line with the Children's Online Privacy Protection Act before any data about the child is processed.

If you believe a child has had personal information processed without a parent/guardian's verifiable consent, contact us immediately at privacy@promisedlandlabs.com.

9.4 Kids Programs ("My Family")

Nlarj lets a parent or legal guardian register a child as a dependent profile under their own member account, so the child can be enrolled in church-run Kids Programs (Sunday School, music class, kids' Bible study, etc.). The child does not have their own login, account, or independent presence on the Platform — the profile exists solely as data managed by the consenting parent/guardian.

(a) Lawful basis. We process child data only after the parent or legal guardian gives verifiable, age-appropriate consent in-app. Under the Indian DPDP Act 2023, processing of a child's personal data (under 18) is permitted only with the consent of the parent or lawful guardian; we treat this consent as a non-waivable precondition to creating the child profile.

Verifiability of parental consent. Verifiable parental consent under DPDP §9 is established by: (i) the parent/guardian holding a pre-authenticated adult member account at the church (government-ID or church-membership-verified at registration); (ii) an in-app explicit consent affirmation, timestamped and logged for the duration of the dependent profile plus 90 days; and (iii) a confirmation email or SMS to the parent/guardian's verified contact channel before the dependent profile becomes active. The Church confirms parent/guardian status at the point of dependent-profile creation through its own membership records; the Company relies on this Church-side attestation as the relationship-proof layer under DPDP §9, in addition to the three identity/affirmation/confirmation factors above.

(b) Data we collect about the child. Only what is necessary to safely run the program:

FieldRequired?Why
Full name + nicknameRequiredRoll call, badge printing, pickup verification
Date of birthRequiredAge-appropriate program assignment
GenderOptionalRestroom / dorm grouping where applicable
AllergiesRecommendedSnack safety
Medical notesOptionalEmergency response (e.g. asthma inhaler location)
Emergency contact name + phoneRequiredReaching a guardian if the parent is unavailable
Last 4 digits of emergency phoneRequiredPickup-override secret if the parent's QR is unavailable
Photo of the childOpt-in onlyVisual identification at pickup; you can decline and the program still works

We do not collect biometric data, location, device identifiers, or behavioural analytics from child profiles.

(c) Who sees this data.

  • You (the parent/guardian who created the profile) — full read/write.
  • Any co-guardian you have explicitly linked (mother + father pattern). Either guardian can edit the profile, generate pickup QR codes, or remove themselves at any time.
  • Kids Program organizers at your specific church (users granted the ch_ministry_leader or ch_youth_leader role by the church admin) — read access for the kids enrolled in programs they run, plus the ability to record check-in/check-out events.
  • Nobody else. Your church's regular members, other churches, and Nlarj staff do not see child data in the normal course of operating the Platform.

(d) Photo consent is granular. Photo upload is a separate opt-in switch from the data-processing consent. You can keep the child profile but refuse photo storage, and you can withdraw photo consent later — we will delete the stored photo within 7 days.

(e) QR codes and pickup. When a child is enrolled, we generate a one-time-rotating QR code that the parent or co-guardian scans at pickup. The QR encodes only an opaque token (a SHA-256 hash) — no child data travels in the QR itself. If a parent loses their device, organizers can verify identity using the last 4 digits of the emergency phone as a fallback secret; this fallback is logged in the audit trail.

(f) Audit log. Every guardian-link change, every check-in/check-out, and every pickup-override event is recorded in an immutable audit log retained for 90 days, then deleted. This is the minimum window needed to answer routine parent queries ("who picked him up three Sundays ago?") and reconcile a program quarter — we deliberately do not retain beyond that. If a safeguarding incident is reported, the relevant records are placed under legal hold and preserved separately for the duration of the investigation.

(g) Your rights as the parent/guardian. You may at any time:

  • View, export, or correct any field on the child profile;
  • Withdraw the child from a program (immediate);
  • Delete the child profile (soft-delete, scrubbed within 30 days; audit log purged on its 90-day rolling window);
  • Remove a co-guardian, or remove yourself if a co-guardian remains;
  • Withdraw photo consent (photo deleted within 7 days).

(h) Data minimisation when a child ages out. When a registered child reaches 18, the dependent profile is automatically frozen — they may then create their own member account if they wish, and we will not migrate program-history data to that account without their fresh adult consent.

(i) No advertising, no profiling, no AI training. Child profile data is never used to train AI models, generate recommendations, target ads, or for any purpose outside the specific Kids Program(s) you enrolled the child into.


10. International Data Transfers

10.1 For India Users

Your data is primarily stored and processed in India. If transferred internationally:

  • We use Standard Contractual Clauses
  • We ensure equivalent data protection standards

10.2 For USA Users

Data may be processed in India, Singapore, or the USA depending on service requirements. All transfers comply with applicable US data protection laws.

10.3 Safeguards

All international transfers are protected by:

  • Encryption in transit and at rest
  • Contractual protections with service providers
  • Regular security assessments

11. Content Moderation & Community Standards

11.1 Content Moderation Policy

Nlarj maintains community standards to ensure a respectful and safe platform for all users, regardless of their faith background or beliefs.

Prohibited Content:

  • Hate speech, discrimination, or harassment based on religion, ethnicity, gender, or other protected characteristics
  • Sexual exploitation, abuse, or unsafe content
  • Spam, misinformation, or conspiracy theories
  • Threats of violence or self-harm
  • Illegal activity or incitement to illegal acts
  • Child exploitation in any form

Moderation Process:

  1. User reports are reviewed by our moderation team within 24-48 hours
  2. Context and intent are considered in determining violations
  3. Violations result in warnings, content removal, or account suspension
  4. Appeals can be submitted within 30 days of moderation action

11.2 Who Can Moderate?

  • Platform Moderators: Nlarj team members trained in community standards
  • Church Administrators: May moderate content within their church community
  • Users: Can report inappropriate content through in-app reporting tools

11.3 Religious Diversity & Respect

Nlarj is a platform for faith-based communities. We respect and protect:

  • Users of all Christian denominations and faith traditions
  • Diverse theological perspectives and biblical interpretations
  • Individual conscience and religious freedom

We DO NOT discriminate based on religious denomination, theological position, or worship style.


12. No Proselytization or Ideological Enforcement

12.1 Our Commitment

Nlarj is a faith community platform, not a religious conversion or recruitment tool. We explicitly prohibit:

Prohibited ActivityWhat This Means
Coercive ProselytizationPressuring users to change their faith or beliefs
Deceptive RecruitmentMisrepresenting services to recruit users into a specific ideology
Ideological EnforcementRequiring users to adopt specific theological positions to use our platform
Exclusionary PracticesDenying platform access based on religious beliefs or denomination
Manipulation via AIUsing AI features to manipulate users toward a particular faith outcome

12.2 Freedom of Conscience

Users retain complete freedom to:

  • Explore their faith at their own pace
  • Hold differing theological views within their church
  • Leave the platform or church community at any time without penalty
  • Discuss, question, or debate theological topics respectfully

12.3 Church Administrator Accountability

Church administrators using Nlarj must:

  • Maintain a welcoming environment for members of all theological perspectives
  • Not use platform tools to coerce faith decisions
  • Respect members' right to leave the church community
  • Comply with local laws regarding religious association

Violation: Church administrators engaging in coercive proselytization may face account suspension and removal from the platform.


13. Voluntary Participation Affirmation (India)

Under Indian law, including the Digital Personal Data Protection Act, 2023, and the Information Technology Act, 2000, religious or faith-based service participation MUST be voluntary.

13.2 Your Voluntary Participation

By using Nlarj, you affirm:

  • You are a willing participant in faith-based activities offered through this platform
  • Your participation is voluntary and not coerced, pressured, or mandated by any employer, institution, or authority
  • You may withdraw at any time without penalty, legal consequence, or loss of access to non-faith services
  • You have not been deceived about the nature of services offered
  • You retain freedom of conscience to question, discuss, or modify your faith at any time

13.3 If Your Participation Is NOT Voluntary

If you have been coerced, pressured, or mandated to join Nlarj by:

  • An employer requiring participation as a condition of employment
  • A family member or guardian forcing participation against your will
  • An institution threatening consequences for non-participation
  • Deceptive marketing or false representation of services

You have the right to:

  1. Immediately stop using the platform with no penalty
  2. Request complete data deletion (Section 7 - Your Rights)
  3. Report coercion to privacy@promisedlandlabs.com or relevant authorities
  4. Seek legal remedies if you have been harmed

13.4 Nlarj's Responsibility

We are committed to:

  • Never requiring participation in religious activities to access platform features
  • Clearly disclosing the faith-based nature of our platform before account creation
  • Protecting data privacy even if users face external pressure
  • Investigating reports of coercion and taking action against violators

14. Third-Party Services

Our Platform integrates with:

10.1 Infrastructure & Authentication

ServicePurposePrivacy Policy
RazorpayPayment processing (India)razorpay.com/privacy
Google Sign-InAuthenticationgoogle.com/privacy
Apple Sign-InAuthenticationapple.com/privacy
FirebasePush notifications, analyticsfirebase.google.com/support/privacy
CloudflareSecurity, CDNcloudflare.com/privacypolicy

14.2 AI & Machine Learning Providers

ServicePurposeData SharedPrivacy Policy
Google AI (Gemini)AI response generation for biblical guidance, Bible search, study featuresUser prompts and conversation contextpolicies.google.com/privacy
OpenAIAI response generation (alternative provider)User prompts and conversation contextopenai.com/privacy
OpenRouterAPI routing layer for LLM requests (used by Church Admin BYOK)User prompts routed to selected model provideropenrouter.ai/privacy
Self-Hosted AnalyticsPrompt management, AI quality analyticsAnonymized prompt/response metadata - hosted on OUR infrastructure, no external data sharingN/A (self-hosted)

Important AI Provider Note: When your prompts are processed by Google AI or OpenAI, they are subject to those providers' terms of service and privacy policies. We have agreements with these providers to opt out of training data programs. However, we recommend reviewing their policies directly.

This is different from the Customer-Directed AI Integration in §3.5. The AI features described in this section are operated by Nlarj — we route your prompts to our chosen providers to generate a response for you, and we opt out of their training programs. The connector in §3.5 is the opposite: your church admin connects their own AI assistant, under their own provider account and provider terms, and we do not control that provider's training or retention. If your church has enabled the connector, read §3.5.

14.3 Local Processing (No External Sharing)

TechnologyPurposeData Handling
On-Device Transcription EngineSermon audio transcriptionRuns 100% locally on your device - NO audio data sent externally
Local Media Processing ToolsAudio extraction for transcription; local streaming pipelineRuns locally on your device
Local RestreamingMulti-destination streaming to YouTube, Facebook, and other platformsRuns 100% locally - video stream goes directly from your device to your configured destinations; Nlarj servers are NOT involved in the video pipeline
Local RecordingSermon/stream recordingStored locally on your device only

We recommend reviewing their privacy policies to understand how they handle your data.


15. Changes to This Policy

We may update this Privacy Policy from time to time. When we do:

  • We will update the "Last Updated" date
  • For material changes, we will notify you via:
    • Email (if you've provided one)
    • In-app notification
    • Website banner (if applicable)
  • Continued use after changes constitutes acceptance

16. Contact Us

For Privacy Inquiries

Nlarj Privacy Team

  • Email: privacy@promisedlandlabs.com
  • Address: 6/1019, Guntakal, Anantapur District, Andhra Pradesh, India — PIN 515801
  • Phone: [Phone Number TBD]

For India Users (DPDP Act)

Data Protection Officer / Data Fiduciary — Ruth Sumanchupalli

Children's Data Protection Officer

For DPDP §9 children's-data complaints, special-category processing, and any matter relating to dependent profiles, contact the Children's Data Protection Officer at privacy@promisedlandlabs.com. The Children's DPO is the same Data Protection Officer designated above, with explicit responsibility for children's-data oversight.

POCSO Reporting Officer

Nlarj's POCSO Reporting Officer is Ruth Sumanchupalli, reachable at posco@promisedlandlabs.com. Credible reports of CSAM, grooming, or abuse are escalated to SJPU/local police under POCSO §19 within 24 hours of disclosure.

Grievance Officer (IT Rules 2021 Rule 3(2))

Name: Ruth Sumanchupalli, Grievance Officer, Promised Land Labs Private Limited. Email: legal@promisedlandlabs.com. Physical address: 6/1019, Guntakal, Anantapur District, Andhra Pradesh, India — PIN 515801. Acknowledgement within 24 hours; resolution within 15 days per Rule 3(2)(c).

Child Complaints Officer (voluntary). Nlarj does not meet the Significant Social Media Intermediary threshold under IT Rules 2021 Rule 2(1)(v) and does not accept SSMI obligations. As a voluntary additional channel, complaints involving children may also be addressed to the Children's Data Protection Officer at privacy@promisedlandlabs.com.

For USA Users (CCPA)

Privacy Rights Requests

For General Support


Summary of Key Points

TopicOur Practice
Data CollectionOnly what's needed for our services
Data SellingWe NEVER sell your data
AI DataPrompts are NOT used for AI model training; sermon transcription is 100% local
Data SecurityIndustry-standard encryption
Your RightsFull access, correction, deletion rights
Data StoragePrimarily in India
ChildrenAdults-only accounts (18+); under-18s only as parent-managed dependent profiles under §9.4 with verifiable parental consent
ChangesWe'll notify you of material changes

This Privacy Policy is designed to be transparent and easy to understand. If you have any questions, please don't hesitate to contact us.