Legal
Privacy Policy
What we collect, why, and what you can ask us to do about it.
1. Who is responsible
The controller for the processing described here is: Mosaikkirche Berlin e.V. Clayallee 228 14195 Berlin, Germany Email: hallo@mosaikberlin.com We have not appointed a data protection officer; we are not required to. Write to the address above with any question about your data and a person will answer it.
2. What this covers
This policy covers two things: the website at mosaik.berlin, and the Mosaik Berlin app for iPhone, Android and the web. They share an account system and some of the same data, so they are described together and the differences are called out where they matter. It does not cover ChurchTools, the church's membership database, when you use it directly. ChurchTools has its own privacy notice.
3. Using the website or the app without an account
You can read almost all of the app and all of the website without an account. Sermons, service times, events, the small group map and the noticeboard are open to everyone. When you do, we do not know who you are. Our servers record the ordinary technical information any web server records — the page requested, the time, an IP address, the browser or app version — for security and to keep the service working. On the app's own API these logs are kept by Cloudflare; for the website they are kept by Vercel. The small group map deliberately shows a guest NO street address and NO map coordinates for any group. Those are people's homes. Signed-in members see an approximate area; members of that group see the exact location.
4. Creating an account
There are three ways to sign in, and they give us different things. ChurchTools — you sign in with your existing ChurchTools username and password. We send them to ChurchTools once, over an encrypted connection, to check them. We never store your ChurchTools password. If your account has two-factor authentication, the intermediate session is held encrypted on our server for at most five minutes and then destroyed. From ChurchTools we then read your name, email address, campus, membership status, date of first contact, birthday, profile photo and your group and team memberships. Google — we receive your name, email address and profile picture from Google. Nothing else. Apple — we receive your name and email address, or Apple's private relay address if you choose to hide it. Apple only sends your name the very first time you sign in. A Google or Apple account is NOT automatically connected to a ChurchTools membership, even if the email address matches. Connecting them is a deliberate step you take yourself while signed in. This is on purpose: an email address on its own is not proof of who you are, and a church membership carries real permissions.
5. What the app stores about you
Your profile: name, email address, profile photo if you set one, the campus or campuses you follow, your language, your time zone, and your notification preferences. What you write: noticeboard posts and replies, small group and camp chat messages, and your personal sermon notes and highlights. Message and prayer-post text is encrypted at rest on our servers. What you respond to: event and meeting RSVPs, camp attendance, sermon bookmarks, and which announcements you have read. Your devices: a push notification token for each device you allow notifications on. Your sermon notes are yours. They are shown to nobody else, ever.
6. Photos
If you upload a photo — a profile picture, a noticeboard post or a chat message — it is stored on Cloudflare R2 and served back through our own server, so the storage location itself is not publicly guessable. Your ChurchTools profile photo is only shown in the app if you switch it on in Settings. That setting exists because a ChurchTools photo URL is public and permanent once it has been handed out, so we do not hand it out unless you say so.
7. Location
The app asks for your location in exactly one place: the camp site map, to show a dot for where you are standing. It is asked for only while the app is open, never in the background, and it is never sent to our servers or stored. Refusing it leaves every other part of the app working normally.
8. Notifications
If you allow notifications, we store a push token for that device and send messages through Expo's push service, which passes them to Apple or Google to deliver. You can turn off any category in Settings. We send at most two notifications a day, and none between 22:00 and 08:00 in your own time zone.
9. Analytics and error reporting
Sentry records technical errors and crashes so we can fix them. PostHog records which screens are used, hosted in the European Union. Both identify you by an internal app user id and nothing else — never your name, your email address or your ChurchTools person id. Neither is used for advertising. There is no advertising SDK in the app and no data is sold or shared with data brokers.
10. Forms on the website
When you send a contact card, a small group request, or any other form, what you write is emailed to the relevant church address through Mailchimp Transactional, and where the form is a ChurchTools sign-up it is also written into ChurchTools. The contact card works without an account. It is rate-limited per IP address to stop abuse.
11. Embedded and linked content
Sermon pages embed YouTube and link to Spotify and Apple Podcasts. The homepage can show an Instagram feed. Giving links out to an external payment provider. When you play an embedded video or follow one of these links, that provider receives your request and applies its own privacy policy. We do not send them anything about you beyond what your browser or device sends by making the request.
12. Who processes data for us
Vercel — website hosting. Cloudflare — the app's API, database and file storage. Sanity — the content management system behind the website and app content. ChurchTools — the church's membership database, and one of the sign-in options. Google and Apple — sign-in, when you choose them. Expo — delivering push notifications. Sentry — error reporting. PostHog — product analytics, EU-hosted. Mailchimp Transactional (Mandrill) — sending form submissions by email. Some of these are based outside the European Union. Where that is so, transfers rely on the European Commission's standard contractual clauses or an adequacy decision.
13. Legal basis
Where you are a member or a regular participant and we process your data to run church life — your group, your serving rota, announcements — the basis is our legitimate interest in operating as a church community, and in most cases your membership relationship (Art. 6(1)(b) and (f) GDPR). Where you choose something — notifications, showing your ChurchTools photo, writing on the noticeboard — the basis is your consent (Art. 6(1)(a)), and you can withdraw it at any time by changing the setting or deleting what you wrote. Because we are a religious association, the fact that you are in our database may itself say something about your religious belief. We handle that under Art. 9(2)(d) GDPR, which permits a religious body to process the data of its members and of people in regular contact with it, and we do not disclose it outside the church.
14. How long we keep things
Your account and profile: until you delete your account. Noticeboard posts and chat messages: until you or a moderator delete them, or until the church retires the group they belong to. Sermon notes and bookmarks: until you delete them or your account. Push tokens: until the device unregisters or the token stops working. Server logs: short-lived, and kept only for security and diagnosis. A record removed by a moderator is hidden rather than destroyed immediately, so that an appeal is possible.
15. Your rights
You have the right to ask what we hold about you, to have it corrected, to have it deleted, to restrict or object to how we use it, and to receive it in a portable form. Where we rely on consent, you can withdraw it at any time. You can delete your Mosaik account yourself, in the app: Settings → Account → Delete account. That removes your account and the content attached to it. It does NOT remove your record from the church's ChurchTools database, which the church keeps separately as its membership register — ask us if you want that removed too. You also have the right to complain to a supervisory authority. For us that is the Berlin Commissioner for Data Protection and Freedom of Information.
16. Children
The app is intended for people aged 16 and over, or younger with a parent's involvement. We do not knowingly create accounts for children under 16 without that. If you believe a child has an account they should not have, write to us and we will remove it.
17. Changes
We will update this policy when what we do changes — for instance if we add a service to the list above. The date below is when it last changed. Questions about any of this: hallo@mosaikberlin.com
Last updated 8 September 2026. If anything here is unclear or out of date, write to hallo@mosaikberlin.com and a person will answer.