BuildSaints Inc. ("BuildSaints," "we," "us," or "our") respects your privacy. This Privacy Policy explains what information we collect, how we use and share it, how long we keep it, and the choices you have when you use the BuildSaints mobile applications for iOS and Android, the optional BuildSaints Mac Helper, the website buildsaints.com, and our related services (together, the "Services"). The BuildSaints applications were previously published under the name ExamenAI LLC (DBA BuildSaints); BuildSaints Inc. now provides them. For members of the investment advisory program, this policy also serves as our consumer privacy notice under Regulation S-P; we provide it when the program is activated and annually thereafter.
Several BuildSaints features are optional and connect to data sources that belong to you. Every such connection is off until you turn it on, and you can turn it off at any time as described in Section 6. By using the Services you agree to this policy; if you do not agree, please do not use the Services.
1. Information we collect
1.1 Information you provide
Account: your phone number (verified by a one-time code), a name if you choose to give one (shown beside what you share with your community only after you agree to share it), and an email address if you provide one.
Membership and billing: whether you hold a membership and its billing status. Payments are processed by Apple (App Store), Google (Google Play), or Stripe (buildsaints.com); we never receive or store your full card number.
Your content: reflections, answers, intentions, prayers you write, notes, photos you add, custom applications you build with the in-app agent, and anything else you create or share in the Services.
Communications: feedback, support requests, and other messages you send us.
1.2 Information collected automatically
Usage: features used, practices completed, in-app actions, frequency and duration of use, and feature-adoption patterns.
Device and diagnostics: device type and model, operating system and version, app version, unique device identifiers, mobile network information, push-notification token (if you enable notifications), performance data, crash reports, and logs needed to run and secure the Services.
1.3 Connected data — only what you connect, only for the feature you enabled
Location (approximate or precise, including background "Always" location if you grant it): used for optional, individually toggleable features — alerts for nearby Catholic Mass, Adoration, and Confession; notifications for nearby Catholic events you follow; walking-prayer prompts; pre-meeting prayer prompts before a connected calendar event; and the places program, in which location pings are clustered into visits to places you name or watch. Coordinates are used to evaluate proximity to locations you select, to detect motion state, and to build your own visit record. We do not sell location data, share it with advertisers, or use it for cross-app tracking.
Camera and photos: with your permission, the live camera feed is used to match artwork or statues you photograph in a church (the photo is compared with artwork images and kept for review of that feature), and photos you choose may be used as your profile photo.
Google Account — Gmail and Calendar (optional, "gmail.readonly" and "calendar.events" scopes): with your explicit consent through Google's OAuth screen, we access email metadata and content — sender, recipients, subject, body text, labels, and timestamps, primarily from the people you actively correspond with — and calendar event details — titles, times, locations, descriptions, and attendees. We use this to help you keep up with the people in your life: surfacing your most significant correspondence and meetings, building a per-contact relationship profile, offering reflective considerations and suggested follow-ups, and personalizing the app's formation content through that relationship context. Before this content is stored we automatically redact high-risk identifiers such as payment-card numbers, government identification numbers, passwords, and security keys. We never display your raw email or calendar content to other users, never sell it, never use it for advertising, and never use it to train generalized artificial-intelligence models.
Messages through the Mac Helper (optional macOS companion that you install and pair yourself): if you grant it Full Disk Access, it reads new messages from the Messages database on your own Mac and sends message events to our servers over an encrypted connection — sender phone number or email, sender name, group name and identifier, message text, timestamp, attachment metadata, and whether you sent the message. The iOS app never reads your Messages; all reading happens on your Mac. You can exclude specific contacts by marking them "sacred scope" and disconnect the Mac Helper at any time in Settings.
Bank accounts through Plaid (budgeting program): account balances and transactions under your own Plaid authorization.
Brokerage account through Charles Schwab (investment advisory program): account balances, positions, orders, and transactions through Schwab's interface under your own authorization, and the orders you place or authorize through the program.
ChatGPT / OpenAI connection (optional, for the in-app agent): the connection to your own ChatGPT or OpenAI account, used to run the agent tasks you request under that provider's terms.
Other integrations you connect through the application's connections catalog: only the data each integration needs for the feature you enabled.
1.4 AI-generated summaries and content
We use third-party AI services (Anthropic's Claude and OpenAI's models) to compose your personalized content and, for connected sources, to turn messages, emails, calendar events, transactions, and places into short derived summaries and per-contact or per-topic profiles. These derived summaries — not the underlying content — power the relationship summaries, suggested follow-ups, budgeting and places insights, and personalized formation content you see. Underlying content is sent to these providers only transiently to generate the results; under their commercial terms it is not used to train their models and is retained only for a limited period before deletion. Raw message, email, event, transaction, or brokerage content is never displayed to other users.
1.5 Google API Services — Limited Use
BuildSaints' use and transfer to any other app of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Data obtained from Google is used only to provide and improve the user-facing features described in this policy; it is not transferred to others except as necessary to provide those features, to comply with applicable law, or as part of a merger, acquisition, or sale of assets; it is not used for advertising; and humans do not read it except with your affirmative consent, for security purposes such as investigating abuse, to comply with applicable law, or where the data has been aggregated and anonymized.
2. How we use information
To provide and maintain the Services: create and manage your account, deliver the features you enabled, provide location-based features, and provide customer support.
To personalize your experience: your daily prayer, reading, examen, reflection, community, and program content, including AI-composed content generated from your data under our instructions.
For the investment advisory program: to provide advice, to place and execute the orders you authorized, and to keep the records the securities laws require. Scope separation: the budgeting, places, and intentions programs are not part of the investment advisory service, and we do not use their data to render investment advice.
To bill your membership and any usage-based charges, and to send receipts and billing notices.
To communicate with you: account and service notices, security alerts, responses to your requests, SMS messages for verification and, with your consent, updates; you can opt out of promotional messages at any time.
To improve the Services: analyze usage patterns, develop features, fix bugs, and improve performance and accuracy.
For legal and safety purposes: to secure the Services, prevent fraud and abuse, enforce our Terms of Use, and comply with legal obligations, including the books-and-records duties of an investment adviser.
We do not use information obtained from Google APIs for any purpose other than the user-facing features described above.
3. How we share information — and what we never do
We share personal information only:
With service providers that process it for us under contract and only as their function requires: Amazon Web Services (cloud hosting and storage in the United States), Anthropic and OpenAI (AI processing), Apple, Google, and Stripe (payments), Twilio (SMS delivery), Expo (push-notification delivery), and the providers behind the connections you initiated (Google, Plaid, Charles Schwab, OpenAI, and the integrations you connect through the connections catalog). Each provider is contractually required to protect your information.
With your community, only what a feature says it shares: a shared intention is labeled shared; answers to the day's shared question show your name only once you have shared it; reflections share presence only.
For legal and safety reasons: when required by law, regulation, court order, subpoena, or other valid process, or to protect the rights, property, and safety of our members, the public, or BuildSaints.
In a business transfer: to a successor in a merger, acquisition, or sale of assets, who will be bound by this policy.
As aggregated or de-identified information that cannot reasonably identify you.
We do not sell or rent personal information, we do not share it with third parties for their own marketing, and we do not use it for cross-app tracking or targeted advertising. Because we share nonpublic personal information only within the exceptions above, no Regulation S-P opt-out is required; if that ever changes we will provide one.
4. How we protect information
Data is stored on secure cloud servers in the United States. We use industry-standard encryption in transit (TLS) and at rest, with additional application-layer encryption of sensitive credentials such as access and refresh tokens; production databases are network-isolated; access to systems holding member data is restricted and logged; high-risk identifiers are redacted before storage; and we maintain a written security program and a written incident-response procedure. Account access uses phone verification by one-time code. If an incident involves unauthorized access to your sensitive information, we will notify you as required by law (for advisory-program members, within the timelines of Regulation S-P). No system is perfectly secure; keep control of your phone number and report anything suspicious to adrian@buildsaints.com.
5. Retention and deletion
We keep information while your account is active and as needed for the purposes above, to comply with legal obligations, to resolve disputes, and to enforce our agreements. Email and calendar content collected to generate summaries is kept only as needed for those features and is deleted when you disconnect the source or use "Remove My Data"; we do not keep a long-term archive of your inbox or calendar. Derived summaries are kept while your account is active. Records of the investment advisory program are retained as the securities laws require (generally five years or longer), even after you leave the program. Disconnecting a source stops new collection from it. When you delete your account, we delete or de-identify personal information that is not subject to a retention obligation.
While we take reasonable measures to protect and back up information, no method of transmission or storage is completely secure, and we cannot guarantee that data will never be lost, altered, or corrupted, including data synced from connected services. Keep your own copies of anything you consider important.
6. Your choices and rights
Access and update: view and update your account information in the app or by contacting us.
Delete your account: at any time in the app (Settings › Delete Account) or by emailing adrian@buildsaints.com. Deletion permanently erases your account and the personal information associated with it — including messages, email and calendar data, location data, bank and brokerage data, and derived summaries — and revokes any connected Google access, subject only to records the law requires us to keep.
Remove your data without closing your account: "Remove My Data" in Settings erases the data we have collected for you, including connected data and derived summaries, and revokes our access to your Google Account, while keeping your app session.
Disconnect a source: disconnect Google, Plaid, Schwab, or any other integration, disable location, or unpair the Mac Helper at any time in Settings; you can also revoke access from the provider's own security settings.
Notifications and sharing: control notification clocks, community participation, and whether your name is shown in the app's settings.
Communications: opt out of promotional messages by following the unsubscribe instructions, adjusting notification settings, or contacting us; service and security notices continue while you have an account.
Portability: request a copy of your information in a commonly used format.
State privacy rights: depending on where you live (including California under the CCPA/CPRA, and Virginia, Colorado, Connecticut, Utah, and other states with consumer privacy laws), you may have rights to know what personal information we collect and how we use and share it, to access, correct, delete, or port it, to opt out of sales or targeted advertising (we do neither), and to appeal a decision. To exercise these rights, contact adrian@buildsaints.com; we honor verified requests as the law provides and never discriminate against you for exercising them.
7. Children
The Services are intended for adults and are not directed to children. We do not knowingly collect personal information from anyone under 13, and our Terms of Use require users to be at least 18. If we learn we have collected information from a child under 13, we will delete it promptly.
8. Third-party services and links
We rely on the providers named in Section 3 to operate the Services; each processes information only to provide its service to us and is subject to its own terms and privacy commitments. We may use analytics and crash-reporting services to improve the Services. The Services may contain links to third-party websites or services whose privacy practices we do not control.
9. International users
The Services are operated from the United States and intended for U.S. members. If you use them from outside the United States, your information is transferred to and processed in the United States, where data-protection laws may differ from those in your country.
10. Changes to this policy
We may update this policy from time to time. We will notify you of material changes by posting the updated policy in the app and at buildsaints.com/legal/privacy-policy/, updating the effective date, and, for significant changes, notifying you in the app or by the contact details you provided. Your continued use after the effective date indicates acceptance of the updated policy.
11. App store notices
Apple App Store (iOS): we comply with the Apple Developer Program License Agreement; Apple is not responsible for our data practices; and this policy, not Apple's, governs the data the BuildSaints app collects. Concerns should be directed to us using the contact details below.
Google Play (Android): we comply with Google Play's Developer Program and User Data policies; the Data safety section of our Google Play listing reflects this policy; and Google is not responsible for our data practices. We will not require you to grant a permission the feature you are using does not need.
12. Contact
BuildSaints Inc. · 154 W 14th St, Floor 2, New York, NY 10011 · adrian@buildsaints.com · 650-690-2002. Questions about this policy or a privacy request can be sent to that address or email.