Kingdom Perspective, LLC, operating My Purpose Plan Effective 19 August 2026 · Published on the Company's website · Prepared for customer security and privacy review


1. Purpose and Scope

This document describes the data governance programme of Kingdom Perspective, LLC (the "Company") for the My Purpose Plan application and related services (the "Services"). It is intended for customer security, privacy, and procurement review, and summarizes: the governance structure; data inventory, retention, and disposal; the handling of data subject requests; protections applicable to employee users; artificial-intelligence processing; hosting and security; and subprocessor management.

The Services are directed to users in the United States. Personal data is stored in the United States, every service provider receiving it is a United States company, and the Company transmits it to no recipient outside the United States.

2. Governance Structure

  • Accountable owner. The data governance programme is owned by the Company's Privacy Officer, a role held by a designated officer of the Company. The Privacy Officer approves any change to a retention period, reviews the programme annually, and is the escalation point for data protection matters.
  • Review cadence. The retention schedule and this overview are reviewed annually, and upon any change to the data model, the addition of a subprocessor, or a material change in applicable law.
  • Document register. The programme comprises: this overview; the published Privacy Policy; the Data Retention Schedule; the internal Data Retention Policy (shareable with customers on request); the Data Processing Agreement offered to business customers; the subprocessor register; the incident-response procedure described in §12; and the data protection assessment described in §13.
  • Change control. Documents are the specification: a change to a retention commitment is made in the Data Retention Schedule first, then propagated to the enforcement registry and its automated tests, then to the published Privacy Policy and every other rendering. The full procedure and its ordering are stated once, in the Data Retention Policy, §4, which controls. Code is conformed to documents, not the reverse.

3. Data Inventory and Classification

Every data store in the Services carries a machine-readable retention classification recording the category of data held, the identifier it is keyed on, its retention period, and its disposal action. This registry is maintained in source control alongside the schema it describes.

A continuous-integration test fails the build when any data store lacks a classification. New collections therefore cannot reach production without a declared retention rule. This mechanism is the Company's primary safeguard against governance decay as the product evolves.

4. Retention and Disposal

Retention periods for every category are stated in the Data Retention Schedule and rendered publicly in the Privacy Policy. Summary of the principal commitments:

Commitment Period
User content (statements, plans) Duration of the account
Check-in entries, reflections, messages 24 months rolling
Employment and billing records Employment: duration of employment, then 7 years; billing: 7 years (legal obligation)
Service logs / analytics 30 days / 14 months
Full deletion after account closure 14 days (live systems); 44 days including backup expiry. Crash diagnostics, service logs, and payment/integration records expire on their own shorter periods; identity-linked analytics is deleted, aggregated measurements retained

Enforcement. A scheduled daily process disposes of records exceeding their period and logs disposal counts per category, producing an audit trail that disposal occurred on schedule. Disposal actions are purge (irrecoverable deletion) and pseudonymization (removal of identifying fields where a record concerns more than one person). Exceptions are limited to legal obligation and legal hold; no discretionary exception exists.

5. Data Subject Requests

The Company honors access, correction, deletion, portability, and sensitive-data limitation requests for all users irrespective of state of residence.

  • Intake: in-application (Settings) or by email to privacy@mypurposeplan.com.
  • Verification: against the authenticated account or account email; authorized agents are verified as to both authority and identity.
  • Response: within forty-five (45) days, extendable once by forty-five (45) days with notice.
  • Appeals: denials state their reasons and may be appealed; appeals are answered within forty-five (45) days.
  • Export: portable copies are produced by an automated export assembled from the same retention registry that drives disposal, ensuring the export and the deletion cascade cover an identical data surface.

6. Account Deletion and Employee Off-Boarding

Account deletion operates in two stages: immediate closure (the account is marked deletion-pending and unusable for anything but cancelling; images, notification tokens, and reminders deleted), followed at fourteen (14) days by complete purge or pseudonymization of remaining data, deletion of the sign-in credential, and the issuance of deletion instructions to subprocessors. The intervening period permits reversal by the user without penalty; signing in during the window reaches a cancel-only screen rather than the ordinary application. Deleted data expires from backups within forty-four (44) days of the request; backups are not selectively modified, and disaster-recovery restoration re-runs outstanding deletions against a deletion register retained for this purpose before return to service.

Where a business customer removes an employee, or terminates its relationship with the Company, only that employee's employer-linked content — check-ins, recognition sent to colleagues, monthly workplace survey responses, AI-generated daily check-in content, reminders, job role and work area, and organization feed posts — is disposed of within fourteen (14) days. The employee's own account, purpose statement, purpose tiles, messages, images, and consent records are unaffected and continue under that individual's own account, without requiring action by the individual. Employment and billing records are retained solely under their stated legal-obligation periods.

Deletion is verified: after a purge, the automated export must return no records from purge-classified categories, no residual identifiers from pseudonymize-classified categories, and only retain-with-basis categories, each carrying its written basis; this check forms part of the programme's test suite.

7. Employee Data Protections

The Services are used by employees of business customers to record personal reflections. The Company enforces the following as architectural guarantees at the database layer, verified by automated test, rather than as policy commitments:

  1. An employer cannot read an individual employee's purpose statement, reflections, or check-in content.
  2. Employer-facing reporting is aggregated and attributes reflections to job role only; it contains no names or direct identifiers, and a role is included only where at least three distinct employees contributed in the reporting period. An AI-generated summary included in that reporting (§9) is produced under the same role-level, threshold-gated aggregation.
  3. An employer cannot observe whether an individual employee participates in check-ins or reflections, or with what frequency. This restriction does not extend to features that identify participants to their team by design: team recognition ("shout-outs"), which an Employee User enters by choosing to send one, and the task-completion leaderboard, which ranks completion of assigned team tasks and is visible to the employer.
  4. Tasks on a collaborative tile — a tile shared between an employee and colleagues — are visible to that tile's team by design, and where the employer has connected a workspace integration (§11) those tasks, including their notes, are copied into that workspace. Tasks on an employee's own private tiles are not shared and are not copied; a second, independently tested gate prevents them from ever reaching a connected workspace.
  5. Consent decisions (§8) are likewise invisible to employers, individually and in aggregate.

These guarantees rest on a role distinction the Data Processing Agreement makes explicit: employer-linked content (check-ins, recognition, feed posts, survey responses, and derived daily content) is processed as the customer's service provider, while personal-scope content (the purpose statement, tiles, messages, and images) is processed by the Company in its own right, under its published Privacy Policy, and is not the customer's data.

Internal Company access to user content is restricted to a limited number of engineering personnel under a dedicated access grant, separate from general administrative access, for support and fault diagnosis only.

8. Sensitive Data and Consent

User-authored content may reveal information classified as sensitive under applicable state law (including religious beliefs and mental or physical health). The Company obtains opt-in consent before processing such content: a consent request is presented, in plain language, before a user's purpose statement is created, covering storage and artificial-intelligence processing of authored content, including daily reflections. Consent may be withdrawn at any time; upon withdrawal, artificial-intelligence processing of authored content stops in full, belief-related selections are removed, and collection of free-text check-in answers stops, while check-ins themselves remain available. The user elects retention of their statement (visible only to the user) or its deletion, without effect on account standing or accrued benefits.

Consent events are recorded (identifier, timestamp, copy version, and scope — never content) and retained for the life of the account and seven (7) years thereafter to evidence that consent was obtained. California residents are additionally offered the statutory control to limit the use of sensitive personal information.

9. Artificial-Intelligence Processing

User-authored content is transmitted to the Company's artificial-intelligence providers (OpenAI, and Google's Gemini API as a failover provider) to generate the user's own statement and daily content and to translate between English and Spanish. Output is produced solely for the authoring user, with one disclosed exception: where content is generated through an employer relationship, a short AI-generated summary of themes across employees' reflections may appear in the aggregated, role-attributed employer reporting described in §7, under the same anonymization threshold. Customer and employee data is not used to train artificial-intelligence models, by either provider, under each provider's contractual paid-API commitment. A provider may retain submitted content up to thirty (30) days solely to monitor misuse of its service, after which it is deleted, except where the provider is required by law to retain it longer; it is used for no other purpose during that period.

10. Hosting and Security

The Services are hosted on Google Cloud Platform (Firebase) in the United States, region us-central1. Data is encrypted in transit and at rest. Access within the Company is role-based; access to user content is further restricted per §7. Payments are processed by Stripe (web) and by the Apple App Store or Google Play for mobile in-app purchases; card data does not transit Company systems.

11. Subprocessors

Provider Function Data received Retention at the provider
Google Cloud / Firebase Hosting, database, authentication, storage, push messaging, analytics, crash reporting Application data Held under the Company's own configuration, for the periods in the Data Retention Schedule
OpenAI AI generation and translation User-authored content Not used for model training. Up to 30 days for misuse monitoring only, then deleted
Google (Gemini API) AI generation and translation, failover provider User-authored content As above
Stripe Payment processing Billing information Transaction records retained under the provider's own financial-record obligations
RevenueCat In-app subscription management (mobile) Application user identifier and email address for every signed-in mobile user, whether or not a purchase is made; purchase and subscription history Until deleted on the Company's instruction
SendGrid Email delivery Email address, name Until deleted on the Company's instruction
Google Maps Coordinate-to-place-name lookup for volunteer search ("Connect"), user-initiated; map display in the browser version Coordinates at time of request, not stored. The browser version loads the mapping library per page, disclosing network address, browser type and page address to the provider independently of any search Request-level logging under the provider's own terms; no Company-held store

Subprocessors process personal data under contract and on the Company's instructions. On account deletion, deletion instructions are issued to subprocessors as described in §6. Additions are reflected here and reviewed under §2. Each subprocessor is contractually required to notify the Company of a security incident without undue delay, and the Company maintains a current security contact for each as part of its incident-response preparations.

Customer-directed integrations. Where a business customer connects a Notion workspace, the Company transmits selected task and identity data to that workspace on the connecting administrator's instruction (§7, item 4), and receives task information from that workspace at the customer's direction, to populate the corresponding collaborative tiles. This is not a subprocessor relationship: the receiving workspace belongs to the customer and is governed by the customer's own agreement with Notion, so no Company retention term attaches to the data once it arrives, and the retention column above does not apply to it. The Company is not a party to that agreement, does not determine the workspace's retention, and cannot revoke the connecting credential on the customer's behalf. Transmission stops on disconnect and on account deletion.

User-directed disclosures. Where an individual user applies to a volunteer opportunity through the "Connect" feature, the Company transmits that user's first name, last name, email address, and any attachment they supply to Idealist, and through it to the organization that posted the opportunity. This is a third class again: the individual user selects the recipient, and transmission is the purpose of the feature. The recipient is the controller of the application it receives, no Company retention term attaches to it, and the retention column above does not apply. The Company retains no copy of attachments — only a record that an application was made, under the period in the Data Retention Schedule.

A complete account of all three classes, with per-provider deletion timing, is maintained in the Company's subprocessor register, published on the Company's website and available on request.

12. Incident Response

The Company maintains an incident-response procedure covering detection, containment, assessment, and notification. Where a security incident involves personal information, the Company notifies affected business customers without undue delay after becoming aware and no later than 72 hours after confirming the incident, as its Data Processing Agreement provides, and notifies individuals and regulators as applicable breach notification statutes require. The procedure names an incident lead, requires counsel's involvement before any external notification, and treats a subprocessor's breach notice as an incident of the Company's own; the subprocessor register carries each provider's security contact and breach-notice terms for that purpose.

13. Regulatory Posture

The Company aligns its practices to the comprehensive United States state privacy laws in force, including category-level retention disclosure, opt-in consent for sensitive data, data subject rights with appeal, and non-discrimination. A data protection assessment covering the processing of sensitive data is maintained and available to customers under non-disclosure terms. The Services are not directed to users in the European Union or United Kingdom; the programme is structured so that EU/UK obligations can be adopted without architectural change should that posture change.

14. Contact

The Privacy Officer · Kingdom Perspective, LLC · privacy@mypurposeplan.com

The Company will review this programme, including the underlying retention registry and its enforcement tests, with customer security or privacy teams upon request.