Fire Over Africa – Privacy Policy
Last Updated: September 12, 2026
Welcome to Fire Over Africa, This Privacy Policy explains how Fire Over Africa, a California nonprofit corporation ("we," "us," or "our"), collects, uses, shares, and protects your personal information when you use the Fire Over Africa web platform or the marketing website at gowithjesus.org (collectively, the "Services").
By creating an account, you affirmatively consent to the collection, use, and sharing of your information as described in this Privacy Policy. If you do not agree to this Privacy Policy, you may not create an account or use the Services.
Contact Us: For privacy-related inquiries, please contact us at: support@fireoverafrica.org or Fire Over Africa, 3341 Walnut Blvd., Suite 304, Brentwood, California.
1. Your Consent
a. How We Obtain Your Consent
We obtain your consent to this Privacy Policy at the time you create your account. During registration — whether by email and password or through Sign in with Google — you are required to affirmatively check a box confirming that you have read and agree to this Privacy Policy and our Terms of Use before your account can be created. The checkbox is not pre-checked; you must actively select it. We record the date, time, method, and version of the Privacy Policy to which you consented.
If you register through Sign in with Google, the consent step is presented after Google authentication but before your account is created. You must still affirmatively agree to this Privacy Policy before proceeding.
b. Changes to This Privacy Policy and Re-Consent
We may update this Privacy Policy from time to time. When we make material changes — such as introducing new categories of data collection, new data-sharing arrangements, or changes to how your data is processed — we will:
Revise the "Last Updated" date at the top of this page;
Notify you by email at the address associated with your account;
Display an in-app notice (banner or modal) the next time you open the app or log in, linking to the revised Privacy Policy; and
For material changes, require you to affirmatively re-accept the updated Privacy Policy before you can continue using the Services.
Your continued use of the Services after non-material changes constitutes your acceptance of the updated Privacy Policy. If you do not agree to a material change, you may delete your account as described in Section 9.
c. Withdrawing Your Consent
You may withdraw your consent to data processing at any time by deleting your account (see Section 9). Please note that withdrawing consent does not affect the lawfulness of processing carried out before withdrawal, and certain data (payment records and certificates) will be retained as described in Section 6.
2. Information We Collect
a. Information You Provide
Account Information. When you register, we collect your name, email address, password, country, preferred language, and, optionally, a profile photo and short bio.
Age Confirmation. During registration, you are required to confirm that you are at least 13 years of age (or such higher age as may be required by applicable law in your jurisdiction). We record this confirmation but do not collect your date of birth.
Sign in with Google. If you choose to sign in with Google (when available), Google will receive your name and email address, and we will store your Google account identifier to link your account.
Learning Data. As you use the Services, we collect your course enrollments, lesson completion records, quiz answers and scores, and any private notes you create.
Certificates. Upon completion of a certificate program, we generate and store a certificate containing your name, email address, the program name, and the date of completion.
Membership and Payment Information. When you subscribe to a paid plan, we collect your plan selection, active/inactive status, and Stripe customer and subscription identifiers. We also store invoice amounts, dates, and payment statuses as returned by Stripe. Card details are entered directly into Stripe and never pass through or rest on our servers.
b. Information Collected Automatically
Server Logs. Our hosting providers collect standard HTTP request logs when you access the Services.
Session Cookie. The web platform sets one first-party session cookie (an httpOnly cookie containing your session JWT). No other first-party cookies are set by the platform.
On-Device Session Storage. On iOS, your session token is stored in the iOS Keychain. On Android, it is stored in Android Keystore-backed encrypted storage.
IP-Derived Country. We read your IP-derived country from Vercel's request headers to determine whether you qualify for the country-gated free tier and to display country-specific pricing. This value is used for that single request and then discarded — it is not stored in the database or associated with your account.
Crash and Diagnostic Data (Mobile Apps Only). Our mobile applications use Sentry for crash and error reporting. Sentry collects the error type, location in code, application version, device model, and operating system version. No personally identifiable information (name, email, or account identifier) is included in crash reports, and reports are not associated with your account. Crash data is retained for 30 days and then automatically deleted.
Over-the-Air Update Checks. The mobile applications periodically contact Expo's servers to check for application updates, which transmits your device's IP address.
c. Information Collected by Third Parties on the Marketing Website
Our marketing website at gowithjesus.org uses Google Analytics (GA4) and Google Tag Manager for visitor and usage analytics. The marketing website also uses advertising measurement tags (Meta pixel, Google Ads conversion tags, and the X pixel) deployed through Google Tag Manager, which collect visitor page views, conversion events, and ad-interaction data. Google Fonts are served from Google's servers on the marketing website, which transmits each visitor's IP address to Google. A Google Translate widget on the marketing website sends page content and the visitor's IP address to Google when a visitor selects a language.
The mobile applications do not currently use analytics or measurement tools, do not use the Apple advertising identifier (IDFA), and do not contain any advertising SDK.
3. How We Use Your Information
We use the information we collect for the following purposes:
Providing and operating the Services: To create and manage your account, deliver courses, track your learning progress, issue certificates, and process membership payments.
Communication: To send you transactional emails regarding your account, membership, and certificates via our email provider, Resend.
Country-based pricing and access: To determine your country at request time for the purpose of displaying appropriate pricing and determining free-tier eligibility.
Crash reporting and app improvement: To identify and fix errors in our mobile applications through Sentry crash reports, which contain no personally identifiable information.
Marketing (marketing website only): To measure and optimize our advertising campaigns through the analytics and advertising tags on our marketing website.
We do not sell your personal information. We do not track you across other companies' apps or websites. No AI or large language model service is called at runtime; nothing member-facing contacts any AI model provider.
4. How We Share Your Information
We share your information only with the following categories of third-party service providers ("sub-processors"), each of which receives only the data necessary for its function:
| Provider | Function | Data Received |
|---|---|---|
| Vercel | Hosting and edge delivery for the web platform | Standard HTTP request logs; approximate country derived from IP address |
| Neon | Managed PostgreSQL database | All stored personal data |
| Amazon Web Services (S3) | Storage of course files and uploaded images | Course documents, images, and profile photos |
| Stripe | Payment, subscription, and donation processing | Cardholder name, email address, and card details (entered directly into Stripe) |
| Vimeo | Lesson video hosting and delivery | Video playback requests; Vimeo may set its own cookies |
| Resend | Transactional email delivery | Recipient name, email address, and message body |
| Google Cloud Translation | Machine translation of course material (admin-time only) | Course text only — no member data |
| Sentry | Crash and error reporting (mobile apps) | Technical error data only — no PII |
| Expo | Build service and over-the-air updates | Device IP address during update checks |
| Apple / Google Play | App distribution | App Store/Play Store account, download, and diagnostic data under their own terms |
Planned Services (Not Yet Active):
OneSignal — push notification delivery, which would process device push tokens, platform/device identifiers, and notification delivery and open events.
Mailchimp or Kit — marketing email campaigns, which would process subscriber names and email addresses and embed open- and click-tracking.
We will update this Privacy Policy and, where required, obtain your re-consent before activating any planned service that materially changes how your data is collected, used, or shared.
1. Data Residency
All personal data stored by the platform is stored and processed in the United States, regardless of where you live. Our database (Neon) is hosted in AWS US East (N. Virginia), our file storage (AWS S3) is in US East (N. Virginia), and our compute (Vercel) is in US East (Washington, D.C.). Vercel's edge network may terminate requests worldwide, but application compute and all data storage remain in the United States.
By creating an account and consenting to this Privacy Policy, you acknowledge and consent to the transfer, storage, and processing of your personal data in the United States, even if you are located outside the United States.
2. Data Retention
Account data, learning data, and notes: Retained for as long as your account is active. Deleted when you delete your account (see Section 9 below).
Payment and invoice records: Retained after account deletion for legal and accounting purposes.
Certificates: Retained indefinitely — including after account deletion — so that a previously issued certificate can be verified as genuine.
Crash reports (Sentry): Retained for 30 days and then automatically deleted.
Server logs: Retained by hosting providers in accordance with their own retention policies.
Consent records: Retained for as long as necessary to demonstrate compliance with applicable law.
3. Cookies and Tracking Technologies
The web platform sets one first-party cookie: a session cookie used to keep you logged in. This cookie is strictly necessary for the platform to function and does not require separate consent. Vimeo may set its own cookies when a lesson video loads.
On the marketing website, Google Analytics, Google Tag Manager, and advertising tags (Meta pixel, Google Ads conversion tags, X pixel) set their own cookies and identifiers. Where required by applicable law, a cookie consent banner is presented on the marketing website before non-essential cookies are set.
The mobile applications do not use tracking cookies, analytics SDKs, or the Apple advertising identifier (IDFA).
4. Device Permissions (Mobile Applications)
The mobile applications request device permissions only at the moment you take the related action, and only with your express consent at that moment. Photo-library access is requested only when you choose to upload a profile photo. Notification permission would be requested only if and when push notifications are enabled. No other permissions are requested. Location, contacts, camera, and microphone access are never requested. You may revoke any granted permission at any time through your device's settings.
5. Account Deletion
You may delete your account at any time through the web platform (account settings) or through the mobile application (Profile > Delete account). No support request or manual approval is required. You must type your email address to confirm; the action is irreversible. If you have an active paid membership, the platform will require you to cancel it before deletion proceeds.
Upon deletion:
Deleted: Your account record, course progress, quiz attempts, and private notes.
Deleted from device: Your session token.
Retained: Payment and invoice records, issued certificates (which retain the name and email address they were issued to for verification purposes), and consent records.
Not removed from device: Lesson files you previously downloaded to your device's local storage. You must delete these manually.
Deleting your account constitutes a withdrawal of your consent to future data processing, except for the limited categories of data retained as described above.
6. Children's Privacy
The Services are a ministry-training platform directed to adults and are not directed to children under the age of 13 (or such higher age as may be required by applicable law). During account registration, users are required to confirm that they are at least 13 years old. We do not knowingly collect personal information from children under 13. If we learn that we have collected personal information from a child under 13, we will take steps to delete that information and the associated account promptly. If you believe a child under 13 has provided us with personal information, please contact us at support@fireoverafrica.org.
7. California Privacy Rights
Because Fire Over Africa is a California-based organization, California residents may have additional rights under the California Consumer Privacy Act ("CCPA"), as amended by the California Privacy Rights Act ("CPRA"), including:
Right to Know. You have the right to request that we disclose the categories and specific pieces of personal information we have collected about you, the categories of sources from which your personal information was collected, the business purpose for collecting your personal information, and the categories of third parties with whom we share your personal information.
Right to Delete. You have the right to request the deletion of your personal information, subject to certain exceptions. You may exercise this right at any time by deleting your account as described in Section 9, or by contacting us.
Right to Correct. You have the right to request the correction of inaccurate personal information.
Right to Opt Out of the Sale or Sharing of Personal Information. We do not sell your personal information. We do not share your personal information for cross-context behavioral advertising purposes within the meaning of the CCPA/CPRA.
Right to Non-Discrimination. We will not discriminate against you for exercising any of your privacy rights.
To exercise any of these rights, please contact us at support@fireoverafrica.org. We will verify your identity before responding to your request and will respond within 45 days, as required by law.
8. Security
We implement reasonable technical and organizational measures to protect your information, including:
Passwords are hashed and are not recoverable in readable form.
All traffic between your device and the platform is served over TLS (encryption in transit).
Session tokens are stored in secure, platform-specific storage (httpOnly cookies on the web; iOS Keychain on iOS; Android Keystore-backed encrypted storage on Android).
Course files on paid plans are authorized against your membership before the file is served.
Card details are entered directly into Stripe and never pass through or rest on our servers.
No method of electronic storage or transmission is 100% secure. While we strive to protect your personal information, we cannot guarantee its absolute security.
9. Your Rights
Depending on your jurisdiction, you may have certain rights regarding your personal information, including the right to:
Access the personal data we hold about you;
Correct inaccurate or incomplete data;
Delete your data (by deleting your account as described in Section 9, or by contacting us);
Port your data to another service;
Withdraw consent to data processing (by deleting your account);
Object to or restrict certain processing; and
Lodge a complaint with a supervisory authority in your jurisdiction.
California residents: please also see Section 11 above for your specific rights under California law.
To exercise any of these rights, please contact us at support@fireoverafrica.org. We will respond to your request within 30 days (or 45 days for California-specific requests, as required by law).
10. International Users
All personal data is stored and processed in the United States. If you access the Services from outside the United States, your information will be transferred to, stored, and processed in the United States. By creating an account and affirmatively consenting to this Privacy Policy during registration, you consent to the transfer and processing of your information in the United States.
11. Accessibility of This Privacy Policy
This Privacy Policy is accessible at all times from:
Within the mobile application (Profile or Settings screen);
On the web platform (footer of every page);
On the marketing website at gowithjesus.org (footer);
In the Apple App Store and Google Play Store listings.
12. Contact Us
If you have questions or concerns about this Privacy Policy or our data practices, please contact us at:
support@fireoverafrica.org or Fire Over Africa, 3341 Walnut Blvd., Suite 304, Brentwood, California.