Privacy Policy
Last updated August 18, 2026.
DOST ("Dialogue for Outreach, Service and Togetherness," "we," "us") operates this website and mobile app to support our community's programs, events, membership, volunteering, and donations. This policy describes, accurately and completely, what information we collect through the app, why, and what choices you have — not a generic template.
Information we collect
Account information. When you register, we collect your name, email address, and a password. Your password is never stored in plain text — it is hashed with Argon2id, a modern, deliberately slow hashing algorithm designed to resist password-cracking attempts, before it ever touches our database.
Profile information you choose to add. Bio, photo, city, professional field, interests, skills, languages, and volunteer interests, all optional and editable by you. A private phone number field exists but is never shown in the public member directory under any visibility setting.
Household and family information. If you set up a household, we store the names and (for dependents, typically children) dates of birth of the people in it, so the app can apply the right safety rules — for example, requiring a guardian's consent before a minor is registered for an activity that needs it. A minor's date of birth is the only source we use to determine they're a minor; see "Children's privacy" below for the full picture.
Membership, volunteering, and event data. Membership applications, event/program registrations and their guardian-consent status, and volunteer hours and service project participation.
Donation information. If you donate, we collect the donor name, email, and amount associated with the gift. We do not store full payment card details ourselves — card processing, once enabled, is handled entirely by our payment processor (Stripe), which never shares full card numbers with us.
Messages. If you use DOST's chat, we store the messages you send (including voice messages, if you record one), who they're sent to, and delivery/read receipts, so conversations work the way you'd expect from a messaging feature. Voice messages are stored as audio files in private object storage, never made publicly accessible, and only ever served back to you via a short-lived, expiring link.
Device and push notification information. If you enable push notifications on the mobile app, we store a device token so we can deliver them — nothing else about your device.
Security and audit logs. We keep a real, internal record of security-relevant account events (like sign-ins, lockouts, and two-factor authentication changes) and of certain administrative actions staff take, so we can detect and investigate misuse. These logs are never sold, shared, or used for advertising.
What we don't do
We do not sell your personal information. We do not use third-party advertising trackers, and there is no third-party analytics SDK anywhere in this app collecting your behavior for us or anyone else. We do not share your information with third parties except the limited, necessary cases below.
Who we share information with
Our infrastructure (database, real-time messaging, file storage) is self-hosted, not run by a third-party cloud data broker. The only third parties who ever see any of your information are ones directly involved in providing the service to you: our payment processor (Stripe) for donations, once enabled, and our transactional email provider for account verification and notification emails, once enabled. Neither is configured to use your information for their own marketing purposes.
Children's privacy
DOST is built for a whole community, including families, and some members are minors added to a household by a parent or guardian. A minor is never able to register for an activity that requires guardian consent, or start a direct message with an adult who isn't a real, recorded guardian, without that consent being given first — enforced by the app itself, not just policy. We do not knowingly collect information directly from a child through their own independent signup outside of this guardian-managed household structure. If you believe a child has provided us information outside of this structure, contact us using the details below and we will remove it.
Your choices and rights
You can review and edit your profile information at any time from your account settings. You can enable or disable two-factor authentication at any time. You can permanently delete your account from your account settings, at any time, with no need to contact anyone — deletion removes your account, profile, and personal session data immediately and permanently. A small set of records — donation records (for our own financial and legal recordkeeping as a nonprofit) and messages you sent to others — are retained after deletion the way any nonprofit or messaging service retains them, but your name and account are disassociated from them; they show as coming from a deleted account, not from you by name.
Data retention
We keep your account information for as long as your account is active. If you delete your account, the data described above is removed immediately, with the limited financial/message-history exceptions described above kept in an anonymized, disassociated form.
Security
Passwords are hashed with Argon2id. Sessions use short-lived access tokens paired with rotating refresh tokens that detect and shut down reuse of a stolen token. Two-factor authentication (TOTP) is available on every account. All traffic to this site and app is encrypted in transit (HTTPS/TLS). No security measure is perfect, but we treat this seriously and keep a real, internal record of how it's implemented, publicly documented in our own engineering repository.
Changes to this policy
If we make a material change to this policy, we'll update the date at the top of this page and, where required by law, notify you more directly.
Contact us
Questions about this policy or your data, or a request to access or delete your information without using the in-app option, can be sent to [email protected].