The short version
- MoNomo is a community for people who have left, are leaving, or are questioning the LDS church. Just having an account here can say something about your religious beliefs, so we treat everything you give us as sensitive.
- We do not sell your data. We do not run ads, use ad trackers, use analytics tools, or work with data brokers.
- We collect what the app needs to work: your account details, the profile you choose to fill out, your messages and social activity, your photos, your journal backups, and basic technical logs.
- During this private test, your data is stored on a server that Knight Developers runs in Utah, reached through Cloudflare. Your journal is backed up to that server and is not end-to-end encrypted yet. We do not read journals, except where the law requires it or to investigate a credible threat to someone's safety.
- Your device location for the "Near me" map stays on your device. We never receive it. Photos are stripped of hidden location data before they are uploaded.
- You can ask to see, correct, export, or delete your data at any time by emailing us. We answer within 45 days.
- You must be 18 or older to use MoNomo.
1. Who we are
MoNomo is operated by Knight Developers, a small software studio based in Utah, USA. In this policy, "MoNomo," "we," "us," and "our" mean Knight Developers and the MoNomo service. "You" means anyone who visits the website or uses the app.
This policy covers the MoNomo website at monomo.knightdevelopers.com and the MoNomo apps for iOS and Android when they are released. It does not cover other websites you reach by following a link from MoNomo.
MoNomo is currently a private test. Anyone can sign up, but an administrator reviews and approves each account before it becomes active. Features, and the way we handle data, may change during the test. When they change in a way that affects your privacy, we will update this policy first.
2. What we collect
Account information
When you sign up, we collect your email address, a password, and a display name. Your password is stored only as a salted hash, a one-way scrambled form. We never store it in plain text and cannot see it. We also keep your account status (for example, pending approval, active, or suspended) and your role (for example, member or administrator).
Age confirmation
At signup you enter your birthdate so we can confirm you are 18 or older. We do not store your birthdate. We keep only a flag saying your age was confirmed as adult, and the date that confirmation happened.
Profile information (optional)
Everything in your profile beyond your display name is optional, and you decide what to add. Profile fields can include:
- your name and pronouns;
- your city (a city only, never a street address; we do not look it up, map it, or geolocate it);
- the year you left the church ("out since"), which you can hide;
- the mission you served and the years you served;
- a bio, hobbies, interests, what you are "looking for," and answers to profile prompts;
- a profile photo;
- your resignation anniversary date, which is shared with your friends only if you allow it.
Social activity
To run the community features, we store:
- friend requests you send and receive, and your friends list;
- people you have blocked;
- direct messages you send and receive;
- groups you join, events you RSVP to, and comments you post;
- reports you file about other users or content;
- your activity feed, which shows public actions such as RSVPs, group joins, comments, and badges.
Private journal
MoNomo includes a private journal. Your entries are backed up to our server so they are not lost if you change or lose your device. In the app, your journal is visible only to you. During the private test, journal backups are not end-to-end encrypted. That means the people who administer our server could technically access stored journal data. We commit not to read your journal entries except where the law requires us to, or where we need to investigate a credible threat to someone's safety.
Photos
When you upload a photo, the app re-encodes it on your device before it is sent to us. This removes embedded metadata, such as the GPS location where the photo was taken and camera details. We store the cleaned image. Anything visible in the picture itself (a face, a street sign, a house) is still visible, so please choose photos with that in mind.
Settings and preferences
We store your app settings, such as privacy choices for your profile and notification preferences, so the app works the way you set it up.
Technical information
When your device connects to MoNomo, our server and Cloudflare (our network provider, described below) receive your IP address and basic request information, such as the time of the request, the page or feature requested, and your browser or app version. We keep this in short-lived logs to keep the service running, troubleshoot problems, and protect against abuse. We also issue session tokens so you stay signed in.
Location
The map tab has a "Near me" button. If you use it, your device asks for permission to use its location, and that location is used only on your device to center the map. It is never sent to us and we never store it. We do not track your location in any other way. Your IP address can suggest a rough area, but we do not use it to locate you.
3. What we do not collect
- We do not show ads, and we do not use advertising trackers or pixels.
- We do not use third-party analytics tools or analytics SDKs.
- We do not buy data about you from data brokers, and we do not sell data to anyone.
- We do not "sell" or "share" personal information as those terms are defined in California law, which includes sharing for cross-context behavioral advertising, and we do not use your data for targeted advertising as defined in other state laws.
- We do not store your birthdate, your street address, or your device location.
If any of this ever changes, we will update this policy before the change takes effect, and where the law requires your consent, we will ask for it first.
4. How we use your information
We use your information only to run MoNomo and keep it safe. Specifically, we use it to:
- create your account, confirm you are an adult, and review your signup during the private test;
- show your profile, posts, comments, and activity to the people you have chosen to show them to;
- deliver your messages, friend requests, group activity, and event RSVPs;
- back up and restore your journal for you;
- remember your settings;
- keep you signed in and keep accounts secure;
- review reports, enforce our Terms and Community Guidelines, and protect users from harassment, fraud, spam, and threats;
- fix bugs and keep the service working;
- send you messages about your account, the test, or changes to our policies;
- comply with the law.
We do not use your information to build advertising profiles, and we do not make decisions about you that have legal or similarly significant effects using automated processing.
5. Sensitive information
Many privacy laws give extra protection to "sensitive" personal data, which includes information revealing religious or philosophical beliefs, sexual orientation, sex life, health, and racial or ethnic origin. California, Colorado, Connecticut, Oregon, Texas, Utah, Virginia, and other states define it this way, and the EU and UK GDPR treat it as a "special category."
On MoNomo, sensitive information is unavoidable. Simply having an account on a community for people who have left or are questioning the LDS church can reveal something about your religious beliefs. Your profile, messages, comments, and journal may also contain information about your sexual orientation, gender identity, mental or physical health, family situation, or other sensitive topics, if you choose to share it.
Here is how we handle it:
- Purpose. We process sensitive information only to provide the service you asked for: your account, your profile, your conversations, your journal, and the community features you use.
- No sale, no ads. We never sell sensitive information, never use it for advertising, and never use it to infer things about you.
- Your choice and consent. You decide what to put on MoNomo. By creating an account and using the service, you are choosing to provide this information to us for these purposes. Where a law requires consent to process sensitive data, you give that consent when you create your account and through the choices you make in the app, such as filling in a profile field or sending a message. You can withdraw consent at any time by removing information, changing your settings, or deleting your account. Because MoNomo cannot work without processing the fact that you are a member, withdrawing consent for that means closing your account.
- Opting out. If you live in a state that gives you a right to opt out of the processing of sensitive data (for example, Utah), you can exercise it the same way: remove the information, or ask us to delete your account. Email us if you want help.
6. What other users can see, and outing risk
For many people, being seen on MoNomo carries real risk. Family members, ward members, employers, or others could react badly to learning that you have left or are questioning the church. We want you to understand plainly what other people can see.
- Other approved members can see your display name and the parts of your profile your settings allow. Your public activity (such as RSVPs, group joins, comments, and badges) can appear in activity feeds.
- Friends may see more, depending on your settings, such as your resignation anniversary if you allow it.
- Messages are seen by the people you send them to. They can screenshot or share what you send, and we cannot stop that.
- Your journal is not shown to any other user.
Anyone who is approved can join MoNomo, including people you know in real life. Someone could join in bad faith. We review signups during the test, but we cannot guarantee that every member has good intentions.
Things you can do to lower your risk:
- use a display name and photo that do not identify you;
- set your profile to friends-only;
- hide optional fields such as your "out since" year, or leave fields blank;
- use an email address that is not tied to your real name;
- block anyone you do not want contacting you or seeing your activity;
- report anyone who threatens to out you, harasses you, or seems to be there to watch members.
7. Services that receive data
We do not sell or rent your information. A small number of outside services receive some data in the normal course of using MoNomo:
- Cloudflare. Cloudflare serves the MoNomo website files (Cloudflare Pages) and carries traffic between your device and our server (Cloudflare CDN and Cloudflare Tunnel). Cloudflare sees your IP address and request information, and data passing to and from our server travels through its network. Cloudflare acts as our service provider. Its handling of data is described in its own privacy policy.
- Map tiles and the map library. When you open the map tab, your device loads map images from OpenStreetMap tile servers and loads the Leaflet map library from cdnjs. Those requests come directly from your device, so those services see your IP address and the area of the map being loaded. They do not receive your account information from us.
- Links you choose to open. MoNomo links to outside sites, such as Google Maps or Apple Maps for event directions, news articles, and resources. When you open one, that site receives whatever your browser or device normally sends (such as your IP address and browser details), and its own privacy policy applies.
- App stores. When the iOS and Android apps launch, Apple and Google will handle app downloads and updates and will collect information under their own policies. We will update this policy if we add any app store service that sends us data, such as crash reports.
We may also disclose information:
- when required by law, as described in Law enforcement and legal requests;
- when we believe in good faith that it is necessary to prevent imminent physical harm to someone;
- if Knight Developers or MoNomo is sold, merged, or reorganized, to the new owner, who would be bound by this policy for the information it receives. We would tell you before that happened.
8. Where your data is stored
During the private test, your account data, messages, images, and journal backups are stored on a server computer that Knight Developers operates in Utah, in the United States. People reach that server through Cloudflare. The website files themselves are served by Cloudflare Pages.
This setup may change. We may move to a cloud hosting provider as MoNomo grows. If we do, we will update this policy to name the provider and describe where data is kept, before or at the time of the move.
If you use MoNomo from outside the United States, your information will be transferred to and stored in the United States, where privacy laws may differ from those where you live.
9. How long we keep data
- Account and profile data, messages, social activity, photos, and journal backups are kept while your account is active.
- When you delete your account (or ask us to), we delete your personal information within 30 days, except where the law requires us to keep something longer, or where we must keep a limited record to resolve a dispute, investigate a safety report, or enforce our Terms. Messages you sent to others may remain in the recipient's own copy if they saved or screenshotted them.
- Server and request logs are kept for up to 30 days, then deleted.
- Reports you file and records of moderation actions may be kept for as long as needed to keep the community safe, then deleted.
- The private test. Data from the test may be wiped when the test ends. We will tell testers before that happens, so you can export anything you want to keep, including your journal.
10. Security
We use reasonable measures to protect your information, including salted password hashing, encrypted connections (HTTPS) between your device and MoNomo, access limited to the people who run the service, and stripping location metadata from photos before upload.
To be honest about the limits: MoNomo is a private test run by a small studio, and no system is perfectly secure. As noted above, journal backups and other stored data are not end-to-end encrypted during the test. Please think carefully about what you store here, especially anything that would hurt you if it were exposed.
If a security breach affects your personal information, we will notify affected users and any authorities as required by law, and we will tell you what happened and what you can do.
You can help by using a strong password you do not use anywhere else, and by signing out on shared devices.
11. Your rights and how to use them
Wherever you live, you can ask us to:
- Access the personal information we hold about you, and learn how we use it;
- Correct information that is inaccurate (much of it you can also edit yourself in the app);
- Delete your account and personal information;
- Export your information in a portable, commonly used format (portability);
- Opt out of the sale of your data, targeted advertising, and profiling. We do none of these, so there is nothing to opt out of, but you are welcome to ask and we will confirm it in writing;
- Withdraw consent or opt out of the processing of sensitive information, as described in Sensitive information.
How to make a request
During the private test, email us at privacy@knightdevelopers.com from the email address on your account, and tell us what you would like us to do. Once in-app account deletion is available, you will also be able to delete your account from the app's settings.
To protect you, we will verify that the request comes from the account owner, usually by confirming it came from your account email address or asking you to confirm through the app. We will not ask for more information than we need to verify you. You may use an authorized agent where your state's law allows. We may ask the agent for proof that you authorized them, and may ask you to confirm your identity directly.
How fast we respond
We will respond within 45 days. If we need more time, we may extend that by up to another 45 days where the law allows, and we will tell you why within the first 45 days. Requests are free. We may decline requests that are manifestly unfounded or excessive, and will tell you why.
Appeals
If we decline your request, in whole or in part, we will explain why. You can appeal by replying to our decision or emailing us with "Privacy appeal" in the subject line. We will respond to your appeal in writing within the time your state's law requires (generally 45 to 60 days) and explain our decision. If you are not satisfied, you can contact the attorney general of your state.
No discrimination
We will not deny you service, change the quality of service, or treat you differently for exercising your privacy rights. The only exception is the obvious one: if you ask us to delete your account, we can no longer provide the service to you.
12. California residents
This section supplements the rest of this policy for California residents and is our notice at collection under the California Consumer Privacy Act, as amended by the California Privacy Rights Act (together, the "CCPA"). Some of these laws apply only to businesses above certain size thresholds. We provide the rights in this section to California users whether or not the CCPA applies to us.
Categories of personal information we collect
| Category (CCPA) | What it means on MoNomo | Source | Purpose | Disclosed to | Retention |
|---|---|---|---|---|---|
| Identifiers | Email, display name, name (optional), IP address, session tokens, account ID | You; your device | Running and securing your account | Cloudflare (service provider) | While your account is active; IP logs up to 30 days |
| Personal information described in Cal. Civ. Code 1798.80(e) | Name and photo, if you provide them | You | Showing your profile | Other users you allow; Cloudflare | While your account is active |
| Characteristics of protected classifications | Religious affiliation or beliefs (implied by membership), adult status, and anything you share about gender, sexual orientation, or similar topics | You | Providing the community you joined | Other users you allow; Cloudflare | While your account is active |
| Internet or other electronic network activity | Request logs; your activity within MoNomo (RSVPs, groups, comments) | Your device; you | Running the service, security, abuse prevention | Cloudflare; other users (public activity only) | Logs up to 30 days; activity while your account is active |
| Audio, electronic, or visual information | Photos you upload (with metadata removed) | You | Showing your photos | Other users you allow; Cloudflare | While your account is active |
| Geolocation data | Not collected. "Near me" location stays on your device. City is free text you type. | Not applicable | Not applicable | Not applicable | Not applicable |
| Inferences | Not created. We do not build profiles about you. | Not applicable | Not applicable | Not applicable | Not applicable |
| Sensitive personal information | Account login (email and password); religious or philosophical beliefs; sexual orientation or health information you choose to share; contents of your messages and journal | You | Only to provide the service you requested | Other users only as you choose (journal: no one); Cloudflare transmits it | While your account is active; deleted within 30 days of account deletion |
Sale, sharing, and sensitive information
In the past 12 months we have not sold or shared (for cross-context behavioral advertising) any personal information, and we have no actual knowledge of selling or sharing personal information of anyone under 16. We use sensitive personal information only for purposes the CCPA permits without a right to limit, such as providing the service you requested and keeping it secure. For that reason we do not offer a "Limit the Use of My Sensitive Personal Information" link, but you can always ask us to delete it.
Your California rights
You have the right to know what personal information we collect, use, and disclose; to access a copy of it; to correct it; to delete it; to opt out of sale or sharing; to limit the use of sensitive personal information; and not to be discriminated against for using these rights. See Your rights for how to make a request.
Shine the Light
California Civil Code 1798.83 lets California residents ask which personal information a business disclosed to third parties for their direct marketing purposes. We do not disclose personal information to anyone for their direct marketing.
13. Residents of other US states
A growing number of states have comprehensive privacy laws, including Colorado, Connecticut, Delaware, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah, and Virginia. Depending on your state, these laws give you the right to confirm whether we process your data, and to access, correct, delete, and obtain a portable copy of it; to opt out of sale, targeted advertising, and profiling; to consent to (or opt out of) the processing of sensitive data; and to appeal our decisions. Some states also let you request a list of the specific third parties that received your data. We honor these rights for all US users, whether or not a particular law applies to us, using the process in Your rights. If you share health-related information on MoNomo, we treat it as sensitive and handle it as described in this policy.
14. Users in the EU, EEA, or UK
MoNomo is built for and offered to people in the United States. We do not target the European Union, the European Economic Area, or the United Kingdom. If you use MoNomo from there anyway, the following applies. Knight Developers is the controller of your personal data. We rely on these legal bases: performance of our contract with you (providing the service), our legitimate interests (security, abuse prevention, and fixing problems, balanced against your rights), legal obligations, and your consent. Because membership can reveal religious or philosophical beliefs and you may share other special category data, we process that data based on your explicit consent, given when you create your account and when you choose to add the information; you can withdraw it at any time by removing the information or deleting your account. You have the rights of access, rectification, erasure, restriction, portability, and objection, and the right to complain to your local data protection authority. Your data is transferred to and stored in the United States.
15. Children
MoNomo is for adults only. You must be 18 or older to create an account. We do not knowingly collect personal information from anyone under 18. If we learn that an account belongs to someone under 18, we will delete it and its data. If you believe a minor has an account, please tell us at the contact address below.
16. Law enforcement and legal requests
We disclose user information to government or law enforcement only when we are legally required to, such as by a valid subpoena, court order, or warrant, and we review each request to make sure it is lawful and no broader than necessary. We will try to notify affected users before disclosing their information, unless the law prohibits it or there is an emergency involving a risk of death or serious physical injury. We do not hand over information to any religious organization, and we do not respond to informal requests from anyone seeking to identify members.
17. Do Not Track and Global Privacy Control
Because we do not sell or share personal information, run ads, or track you across other websites, there is nothing for a "Do Not Track" or Global Privacy Control (GPC) signal to turn off. If your browser sends a GPC signal, we treat it as a valid request to opt out of sale and sharing, which is already how we operate.
18. Changes to this policy
We will update this policy when our practices change, including when we change hosting providers, add a service that receives your data, or leave the private test. The "Last updated" date at the top shows when it last changed. If we make a material change, we will tell you in the app or by email before it takes effect. We will not use information we already have in a materially different way without your consent where the law requires it.
19. Contact us
For privacy questions, requests, or appeals, email privacy@knightdevelopers.com.
Knight Developers, Utah, USA