Kingdom Perspective, LLC, operating My Purpose Plan Effective 19 August 2026 · Published on the Company's website and provided to customers on request; referenced by the Data Processing Agreement, Exhibit C
1. Purpose
This register identifies every third party that receives personal data in connection with the My Purpose Plan application and related services (the "Services"), states what each receives and on what basis, and records the retention and deletion terms under which each holds it.
It exists to answer four questions:
- Who receives personal data, and what exactly do they receive?
- On what footing — as the Company's service provider, or as a recipient the customer or the user directed data to?
- How long does each hold it, and what happens when a user deletes their account?
- Who is contacted, and within what period, if one of them suffers a security incident?
A recipient's absence from this register is a positive claim, not an omission: Section 9 records what was considered and excluded, and why, so that a reversal is a visible change rather than a silent one.
2. How to read this register
Third parties fall into three classes, and the distinction is legal rather than presentational. A reader who treats all three as "vendors" will reach the wrong conclusion about who is accountable for the data.
| Class | Definition | Company's obligations | Section |
|---|---|---|---|
| Subprocessor | Processes personal data on the Company's documented instructions, for the Company's purposes, under contract | Contractual data protection terms; deletion on instruction; change notice to customers; listed in the Data Processing Agreement, Exhibit C | 3 |
| Customer-directed destination | Receives data at a business customer's instruction, into an account that customer owns and governs | None after receipt — the customer is the controller of the receiving account. The Company transmits only while the connection is active | 5 |
| User-directed disclosure | Receives data because an individual user chose to send it there, as the purpose of the feature | None after receipt — the recipient is the controller of what it receives. The Company discloses the recipient and transmits only at the user's request | 6 |
Deletion-instruction stage. When a user requests account deletion, deletion runs in two stages: the first at the request, the second at the close of the fourteen-day reversal window. A provider's stage follows one test:
Does acting on the first day destroy something a user who cancels on the twelfth day could not get back?
Where it does, the instruction waits for the second stage, because issuing it immediately would impose exactly the penalty the reversal window exists to prevent. Where it does not — the act touches only a credential the Company holds locally, or the provider holds nothing a returning user would want back — it runs at the first stage. The second stage is the default; the first requires a written basis recording that no recoverable state is destroyed, given in the table below.
3. Subprocessors
Every subprocessor is a United States company, and the Company transmits personal data to no recipient outside the United States. Each processes personal data only on the Company's documented instructions, under contractual data protection terms no less protective than those the Company owes its own customers.
| # | Provider | Function | Personal data received | Deletion instruction | Retention at the provider |
|---|---|---|---|---|---|
| 1 | Google Cloud Platform / Firebase (Google LLC) | Hosting, database, authentication, file storage, push messaging, crash reporting, product analytics | All application data, as the platform on which the Services run | Not applicable — disposal within the platform is performed by the Company's own deletion process rather than by instruction to a provider | Held under the Company's own configuration, for the periods in the Data Retention Schedule. Crash reporting and analytics are configured separately and are stated in Section 4 |
| 2 | OpenAI, L.P. | Generation of a user's purpose statement and daily check-in content; translation between English and Spanish | Content the user authors, submitted for generation | None required — the provider holds no per-user record that an instruction could name | Submitted content is not used to train models. Content may be retained up to thirty (30) days solely to monitor misuse of the service, and is then deleted, except where the provider is required by law to retain it longer |
| 3 | Google LLC (Gemini API) | The same generation and translation functions, as a failover provider | Content the user authors, submitted for generation | None required — as above | As above |
| 4 | Stripe, Inc. | Payment processing for subscriptions billed directly by the Company | Billing information and payment identifiers for paid accounts. Card numbers are collected by the provider on its own hosted pages and do not transit Company systems | Second stage. Deleting the customer record at the provider is irreversible and takes the saved payment method with it. A separate, reversible instruction halting future billing runs at the first stage and deletes nothing | Transaction records are retained by the provider as its own financial-record obligations require, independently of the customer record |
| 5 | RevenueCat, Inc. | In-app subscription management for mobile purchases | Application user identifier and email address for every signed-in mobile user, whether or not a purchase is made; purchase and subscription history | Second stage | Subscriber records are retained until deleted on the Company's instruction |
| 6 | Twilio SendGrid, Inc. | Transactional and notification email delivery | Email address and name | Second stage | Contact records are retained until deleted on the Company's instruction |
| 7 | Google Maps Platform (Google LLC) | Converting coordinates to a place name for volunteer search ("Connect"); map display in the browser version of the Services | Coordinates supplied at the moment of a search, which the Company does not store. The browser version loads the mapping library on each page, which discloses the visitor's network address, browser type, and page address to the provider whether or not a search is performed | None required — the provider holds no per-user record | Request-level logging under the provider's own terms; no Company-held store |
Notes on the table.
- Row 1 covers several distinct services whose retention is configured separately and is therefore stated in Section 4 rather than collapsed into one cell.
- Rows 2 and 3 have no deletion instruction to issue. Neither provider holds a per-user record that an instruction could name. The protections are the retention limit and the commitment against training, both of which are terms rather than actions.
- Row 4 is the worked example for the staging test in Section 2: the same provider takes a reversible action at the first stage and an irreversible one at the second.
- Row 7 is listed separately from row 1 deliberately. Both are the same corporate provider, and the information adds nothing new in kind, since the visitor's network address already reaches that provider through the platform in row 1. What differs is the footing: row 1 is the provider acting as the Company's processor on the Company's instructions, while the mapping platform operates under its own terms as an independent controller. A disclosure covering the first does not reach the second, so combining the rows would misstate the position.
- Rows 5, 6, and 7 create no Company-held store, so none has a row in the Data Retention Schedule. Their counterpart there is the single entry covering deletion instructions to subprocessors, together with this register.
4. Platform retention settings
Row 1 above is the platform on which the Services run, so its retention is largely the Company's own configuration rather than a provider commitment. Stated separately because these periods are asked about individually, and because most are Company-set values governed by the change procedure in the Data Retention Policy.
| Service | Data held | Period | Set by |
|---|---|---|---|
| Cloud Firestore and Cloud Storage | Application data | Per the Data Retention Schedule | Company |
| Database backups | Point-in-time recovery and scheduled snapshots | 7 days continuous; 30 days snapshots | Company |
| Cloud Logging | Service logs | 30 days | Company |
| Firebase Analytics | Device and usage events | 14 months; user-level records deleted at the second stage of an account deletion, via the provider's deletion interface | Company |
| Firebase Crashlytics | Crash reports: device model, operating system version, and an installation identifier. No content a user authors is attached to a crash report | 90 days | Provider |
| Firebase Cloud Messaging | Device push tokens | Until sign-out; deleted at the first stage on a deletion request | Company |
5. Customer-directed destinations
These are not subprocessors. The receiving account belongs to the business customer, is governed by that customer's own agreement with the provider, and no term of the Company's Data Processing Agreement attaches to data once it arrives there. There is no Company retention term to state, because there is no Company–provider relationship.
| Destination | Directed by | What the Company transmits | While |
|---|---|---|---|
| Notion — the customer's own workspace | The business customer's administrator, who supplies the integration credential | Tasks on collaborative tiles (title, notes, schedule, completion status, points), the tiles they belong to, and each contributing person's name, email address, role, and organization identifier. Tasks on a user's own private tiles are never transmitted | The connection is active |
Consequences that follow from the customer being the controller of the destination:
- The Company cannot revoke the credential on the customer's behalf, and cannot delete from the customer's workspace. That provider's interface offers no permanent-delete capability; where a person leaves the organization, the Company archives that person's page and assigned task pages, and permanent removal is the customer's own action as controller.
- Disconnecting stops any further transfer. Data already delivered is governed by the customer's agreement with the provider.
- The Company's local copy of the credential is purged at the first stage of a deletion request. Purging it has no effect at the destination and is restored at cancellation by re-supplying the same credential, which is why it takes the first-stage branch of the test in Section 2 rather than the second-stage default. Everything the Company derives from the connection — synchronization queues, job records, and the identifiers linking tasks to workspace pages — is ordinary derived data and is purged at the second stage.
6. User-directed disclosures
These are not subprocessors either, and they are distinct from Section 5: the individual user, not a business customer, chooses the recipient, and transmission is the purpose of the feature rather than a background synchronization.
| Recipient | Directed by | What the Company transmits | When |
|---|---|---|---|
| Idealist, and through it the organization that posted the opportunity | The individual user, by submitting a volunteer application | First name, last name, email address, and any file the user attaches, such as a résumé | Only at the moment the user submits an application |
Notes.
- The Company retains no copy of the attachments. The application form is presented within the application, and its contents pass through Company systems in transit only: attachments are forwarded to the recipient's upload endpoint and are written to no Company store. The destination is restricted to the recipient's own upload locations, so the mechanism cannot be directed elsewhere.
- The Company does record that an application was made — the user identifier, the opportunity's identifier, title, organization name and address, the number of attachments, and the date, and never the application's content. It is retained for 24 months and purged at fourteen days on account deletion, per the Data Retention Schedule. Its only operating purpose is to prevent a duplicate application to the same opportunity.
- The Company separately retrieves volunteer listings from this recipient. That direction of flow carries no personal data.
7. Deletion instructions on account deletion
Consolidated view of what is issued and when.
| Provider | At the request | At fourteen days |
|---|---|---|
| Google Cloud / Firebase | Disposal of the immediate categories by the Company's own deletion process | Disposal of remaining categories; deletion of the sign-in credential; user-level analytics deletion instruction |
| OpenAI | — | — (no per-user record) |
| Google (Gemini API) | — | — (no per-user record) |
| Stripe | Future billing halted, reversibly, without ending the current billing period | Customer-record deletion instruction |
| RevenueCat | — | Subscriber-deletion instruction |
| SendGrid | — | Contact-deletion instruction |
| Google Maps Platform | — | — (no per-user record) |
| Notion (customer-directed) | The Company's local copy of the customer's credential is purged | Derived queues, job records, and identifier maps are purged |
| Idealist (user-directed) | — | — (the recipient holds an application the user chose to submit; the Company's own application record is purged at this stage) |
Subscriptions billed through the Apple App Store or Google Play cannot be cancelled by the Company under any circumstances. The account-deletion confirmation screen directs those subscribers to cancel in their own store account settings.
8. Security incidents involving a subprocessor
Each subprocessor is bound by contractual terms requiring it to notify the Company of a security incident affecting personal data without undue delay, and to provide the information the Company needs to meet its own notification obligations.
The Company maintains a current security contact for each provider in this register as part of its incident-response preparations, reviewed on the cadence in Section 10. A subprocessor's notice is treated as the opening input to the Company's own incident procedure rather than as the end of the matter: the Company assesses the incident against its own obligations, notifies affected business customers without undue delay after becoming aware and within 72 hours of confirmation as its Data Processing Agreement requires, and notifies individuals and regulators as applicable law requires. A provider's own notification period does not extend the Company's.
9. Considered and excluded, with reasons
Recorded so that a future reader need not re-derive why an apparently obvious candidate is absent, and so that a reversal is a visible change rather than a silent one.
| Party | Why it is not listed |
|---|---|
| Meta (Facebook) | The Services transmit nothing to this provider. An analytics library from this provider was previously present in the mobile application and has been removed in its entirety, together with its configuration on both platforms and the associated advertising-identifier permission. The Company's statement that it does not share personal information for cross-context behavioral advertising rests on that library's absence rather than on a configuration setting, and an automated check fails the Company's build if any part of it returns |
| Vimeo | A video player library from this provider was previously loaded by the web application and has been removed. The Services no longer include video |
| Stripe.js | A browser payment library was previously loaded by the web application and has been removed; nothing in the Services used it, as payment and subscription management run entirely as provider-hosted pages the application links to. The payment provider itself remains a subprocessor at row 4 |
| Nylas | No code path reaches this provider. The dependency and its associated code have been removed. A similarly named calendar function retained in the Company's codebase performs Google authentication under a legacy name and involves this provider in no way |
| Apple App Store / Google Play | Independent controllers for in-app purchases made through their stores, not the Company's service providers. Card details are collected by the store and never transit Company systems |
| Device speech recognition | Voice-to-text dictation is performed by the device's own speech recognition. Audio does not reach Company systems and is transmitted by the Company to no third party |
| Device geocoding | Where the application resolves a location on the device itself, it uses the platform's own geocoder. This is distinct from the server-side lookup at row 7 |
| Calendar providers (Apple, Google, Microsoft) | Where a user creates a calendar subscription link, the user's own calendar application fetches it. The Company transmits to no provider; it publishes a feed that the user's chosen application reads. The provider operating that application will read the feed, which the Services disclose to the user at the point of creation |
| Inbound calendar synchronization (Google, Microsoft) | The feature is deactivated and its stored credentials are purged. Were it reactivated, each provider would become an entry in Section 3 |
10. Change control
A change to this register is a change to the Company's data governance programme, and follows the procedure in the Data Retention Policy, which controls.
- Adding or replacing a subprocessor requires the approval of the programme owner, entry in this register with every column completed, and propagation to the Privacy Policy, the Data Governance Overview, and the Data Processing Agreement's subprocessor exhibit.
- Customers receive notice at least 30 days before a new subprocessor begins processing their personal data, during which a customer may object on reasonable data-protection grounds. This register as published is that notice mechanism.
- Moving a party between Sections 3, 5, and 6 is a change of legal footing rather than a presentational edit, and requires the same approval and propagation as an addition.
- A change to a deletion stage in Section 7 is a change to the Company's deletion process and requires the written basis described in Section 2 before a provider may move from the second stage to the first.
- Adding a third-party library to the application is a change to this register, whether or not any Company code calls it. A library that transmits on its own initiative is a recipient of personal data on the same terms as one the Company invokes deliberately.
- This register is reviewed annually, and on any addition of a third party, any change to what an existing party receives, or any incident implicating one.
11. Ownership
This register is owned by the Privacy Officer, who approves every change under Section 10.
Kingdom Perspective, LLC, doing business as My Purpose Plan privacy@mypurposeplan.com