Selah Space Privacy Policy
Operator: Workbird LLC
Effective date: September 22, 2026
Policy version: 2026-09-22-v1
1. Who we are and what this policy covers
Workbird LLC operates Selah Space, also presented as Selah, at tryselahspace.com. In this policy, “Workbird,” “Selah,” “we,” and “us” refer to Workbird LLC. This policy explains how we handle information when you visit our website, create an account, explore pastors, purchase a membership, exchange messages, book a conversation, submit a review, or participate as a pastor.
We determine how personal information is used to operate Selah. A pastor may also have responsibilities for information they receive or create in their own ministry. Zoom, Stripe, and other providers have their own responsibilities for services they provide directly to you. This policy describes our practices; it does not replace those providers’ notices.
Selah facilitates pastoral conversation and spiritual support. It is not an emergency service or a medical-record system. Calling information “pastoral” does not make every communication legally privileged or remove privacy obligations that otherwise apply.
For privacy questions or requests, contact support@workbird.co. Please identify Selah Space in your correspondence.
2. Information we collect
Account and sign-in information
We collect your name, email address, account type, internal account identifiers, and account status. We use email sign-in links rather than asking you to choose a password. Sign-in requests generate short-lived tokens, delivery information, and records used to prevent misuse. Our database stores hashed sign-in and session tokens rather than the usable tokens themselves. We record the version and time of your agreement, your adult and U.S. eligibility affirmations, applicable pastor fee acceptance, sensitive-information choices and changes, and the recurring-payment disclosure you authorize.
Launch waitlist
If you join the launch waitlist, we store your email address, whether you joined from the member or pastor landing page, the launch-notification consent version, and the signup time. The form also uses an empty-field check to help reject automated submissions. Joining saves your request to receive an email when Selah launches; it does not create an account, purchase a membership, or subscribe you to an unrelated newsletter. The current signup flow shows confirmation on screen and does not automatically send a confirmation email.
You can withdraw the launch-notification request by contacting support@workbird.co. If we send commercial email, it will include an appropriate way to stop further marketing messages. We will honour covered marketing opt-outs within ten business days. Necessary account and transaction emails are separate from optional marketing. We may retain limited suppression information to avoid sending messages you have declined.
Preferences and profile information
You may provide a display name, faith tradition, openness to different traditions, conversation topics, intentions, preferred teaching or conversation style, examples that resonate with you, appointment preferences, and time zone. We save onboarding progress and completed answers. Topics may include relationships, family, grief, prayer, and life transitions.
Pastors also provide a public introduction, denomination or tradition, areas of conversation, profile title, availability, and profile information. An uploaded profile photograph is processed into a smaller display image. We do not use profile photos to create facial-recognition identifiers.
Conversations, bookings, and messages
We store appointment dates, times, duration, participants, booking status, cancellation information, updated scheduling information, and notes a member chooses to add to a booking. We store messages exchanged through Selah. A pastor can create private notes associated with a session; these are separate from member-provided booking notes.
These materials can reveal religious beliefs, relationships, health concerns, sexual orientation, or other sensitive circumstances even when the service does not ask specifically for that information. Share only what is useful for the conversation. Avoid including another person’s identifying details unless you have an appropriate reason and authority to do so.
Memberships and payments
We store the selected plan, associated pastor, subscription status, session allowance, billing period, cancellation status, and payment-provider identifiers and event records. Stripe processes payment details through its hosted services. The Selah payment flow does not ask you to enter a complete card number or card security code into a Selah-hosted form.
Pastors supply payout and identity-verification information through Stripe Connect. Stripe may collect bank, tax, identity, and business information for its own onboarding and compliance processes. Selah stores the connected-account identifier and information needed to determine whether payments and payouts are enabled. Do not send card numbers, bank credentials, government identifiers, or tax documents through Selah messages.
Zoom connection information
When a pastor authorizes the integration, we receive Zoom access and refresh tokens and their expiration information. We store these tokens in encrypted form. We also process Zoom meeting identifiers, meeting times, participant join links, and host links needed for booked sessions.
When creating a meeting, Selah sends scheduling information, a generic conversation title and agenda, a generated passcode, and meeting settings to Zoom. Selah does not include private booking notes, pastoral notes, or private messages in the meeting-creation payload.
Public reviews and saved choices
We store saved pastors and reviews you submit. A published review displays the member’s first name, rating, review text, and date with the pastor’s profile. Text you put in a review may identify you or another person even if we display only your first name.
Device, security, and support information
Requests to the service involve an IP address, browser and request information, timestamps, and technical error information. Hosting providers may maintain service and security logs. Selah uses a hashed identifier derived from connection information for request limiting. We may also receive correspondence and evidence you provide when asking for help, reporting conduct, disputing a charge, or exercising privacy rights.
We do not need access to your contacts, precise device location, or general browsing history to provide the current service.
3. Where information comes from
Information comes from you, from the browser or device making a request, from the member or pastor participating in a conversation with you, from reviews or reports submitted to us, and from service providers returning authorization, payment, subscription, or delivery information. A pastor’s private notes are supplied by that pastor. We do not purchase profiles from data brokers to generate pastor suggestions.
4. Why we use information
We use information to maintain the launch waitlist and send the requested launch notice; establish and authenticate accounts; save preferences; show and manage profiles; suggest and filter pastors; administer appointments, subscriptions, credits, and payouts; exchange messages; create and manage Zoom meetings; deliver account emails; display reviews; respond to requests; diagnose failures; prevent fraud and abuse; investigate reports; comply with applicable obligations; and resolve disputes.
Pastor suggestions compare the preferences you select with pastor profile information and availability. The current matching feature uses rules and weighted comparisons. It does not diagnose you, assess your mental health, or promise that a suggested pastor is suitable. You decide whom to contact or book and can change your preferences.
We do not use private conversations, messages, or pastoral notes to train a general-purpose artificial-intelligence model. The current Selah service does not generate session transcripts or automated spiritual or clinical assessments.
5. Sensitive information and your choices
Faith preferences and the content of personal conversations deserve particular care. We use them for the specific features you request, such as matching, messaging, and pastoral conversations, and for permitted safety, support, and legal purposes. We do not use them to build advertising audiences.
Where consent is required for sensitive processing, we will ask for a specific, affirmative choice before that processing begins. Acceptance of general terms or this policy is not a substitute for a separate consent that the law requires. You may withdraw a consent by contacting support@workbird.co or using an available consent control. We will explain which features depend on the information and stop consent-based processing within the applicable legal deadline. For covered Delaware processing, that deadline is no later than 15 days after receipt of the withdrawal.
You can avoid putting sensitive details in booking notes or messages. You can choose “Still exploring” where offered instead of selecting a particular faith tradition. Members can continue without personalization instead of supplying religious preferences. If you enable personalization, its setup asks for the fields needed by that feature; it does not require you to claim a belief you do not hold. Withdrawing preference consent removes sensitive information from the active preference profile and stops personalized matching. For pastors, it also unpublishes the public pastoral profile; existing appointments and subscriptions require separate attention.
Manage these choices in Privacy & account. Conversation consent is separate from matching preferences. Withdrawing it disables new sensitive conversation submissions; contact us for review or deletion of retained records and any processing that must cease under an applicable right. Withdrawal does not automatically cancel your membership.
Where consumer-health-data law applies, the separate Consumer Health Data Privacy Notice provides additional information. A reference to spiritual support does not exclude health information from protections that apply to it.
6. Who can see information
Other participants and the public
A member and their pastor receive the information needed to manage their relationship and appointments, including participant names, scheduling information, messages exchanged with each other, and member-provided booking notes. The current application does not publish a member’s private onboarding answers as a public profile.
Approved pastor profiles, their public descriptions and photographs, review summaries, and available appointment information can be seen by visitors or members. Public material can be copied or indexed by others. Avoid placing private contact, health, or third-party information in a public profile or review.
The current photo-access feature limits an ordinary member’s uploaded profile image to their own authenticated account. Approved pastors’ profile photographs are public. Different visibility for additional photo features would be explained before those features are introduced.
Pastor-created private notes are not available through the member-facing notes interface and are not included in Selah’s Zoom meeting requests. “Private notes” describes ordinary account access, not a guarantee that an authorized administrator, service provider, or legally entitled requester could never obtain them. Applicable privacy rights, other people’s rights, and privileges must be considered when handling a request involving those notes.
Service providers
We use Netlify for website hosting, server functions, and the application database; Stripe for checkout, subscriptions, billing, and connected-account payouts; Zoom for authorized meeting operations and video conversations; and Resend for sign-in email delivery. They receive information needed for the services they provide. The active services may depend on which features you use.
Zoom processes meeting audio, video, and related information when you use Zoom. Stripe processes information entered on its payment and account-verification pages. Their own terms, settings, and privacy notices also apply to those activities. Their policies are available at Zoom, Stripe, Netlify, and Resend.
Support, safety, legal processes, and business changes
Personnel and service providers may access information when reasonably needed for their authorized work, such as investigating a delivery problem, security incident, billing dispute, or misconduct report. We do not promise continuous human monitoring of conversations or messages.
We may preserve or disclose information when required by law, valid legal process, or a reporting obligation, or when reasonably necessary and legally permitted to address fraud, a serious safety concern, or a dispute. We consider the request’s authority, scope, and applicable confidentiality protections. We may notify you when lawful and appropriate; some circumstances prohibit or make advance notice unsafe.
If Workbird undergoes a merger, acquisition, financing, reorganization, or asset transfer, relevant information may be reviewed or transferred subject to appropriate confidentiality and legal requirements. A business transfer does not itself authorize using sensitive information for an unrelated purpose without any notice or consent required by law.
7. Sales, advertising, cookies, and browser signals
We do not sell personal information or share it for cross-context behavioral advertising. The current Selah application does not include third-party advertising pixels or advertising-audience tracking. These commitments do not prevent necessary service-provider processing or disclosures you request as described above.
Selah uses a first-party selah_session cookie to keep you signed in. It is HTTP-only, uses the SameSite=Lax setting, and is marked Secure on the HTTPS production configuration. It expires after seven days unless removed earlier. Signing out removes the active session. Your browser may also store selah:welcome-hidden, a preference for whether to display the welcome card; that value persists until changed or browser storage is cleared.
The waitlist uses selah:waitlist-dismissed in session storage to remember dismissal during the tab's browsing session, and selah:waitlist-joined in local storage to avoid repeating the invitation after signup. These values are flags, not stored copies of your email address. The joined flag persists until browser storage is cleared. Clearing a flag does not delete the email saved on the server.
Necessary cookies support account security and requested features. Blocking them may prevent sign-in. You can clear local browser storage through your browser settings. Payment and meeting providers may use their own technologies when you visit or use their services, under their own notices.
The current application does not change its behavior in response to the older “Do Not Track” header. It does not use that fact as permission to track you across unrelated websites. A legally recognized opt-out preference signal, such as Global Privacy Control where applicable, expresses a choice against covered sale or targeted advertising; our no-sale and no-targeted-advertising practice applies whether or not such a signal is present. We will not introduce covered processing without providing required notices, choices, and signal handling.
8. Audio, video, recording, and confidentiality
Calls take place through Zoom. Selah does not operate the audio/video transport or store a recording or transcript through the current integration. Meetings created by the integration have automatic recording disabled. That setting cannot guarantee that another participant will not use a device, account setting, or outside tool to record.
Our Community Standards prohibit recording, screenshots of private content, transcription bots, or sharing private communications without appropriate permission and a lawful basis. Tell the other participant promptly if an unexpected recording indicator or third party appears, and end the session if necessary.
We do not represent Selah as a HIPAA-certified service or promise that every conversation is covered by medical or clergy privilege. Whether a legal privilege or reporting duty applies depends on the facts, the participants’ roles, and applicable law. A report of abuse or a safety concern can require action even when shared during a spiritual conversation.
9. Retention and deletion
We retain information for the purposes described in this policy, taking account of the sensitivity of the information, active services, unresolved disputes, legal requirements, and legitimate security needs. We do not assign the same retention period to payment records and intimate conversation content.
Account and preference information supports an active account. Waitlist information supports the requested launch notification and should be removed or limited when that purpose ends, subject to a withdrawal, deletion request, or justified suppression or legal record. Messages, bookings, and pastoral notes support the relationship and appointment history, subject to a valid deletion request and lawful retention exceptions. Public reviews remain associated with a profile unless removed or otherwise handled through the applicable process. Payment and dispute records may need to be retained after membership ends; this does not justify retaining every private message or note.
Sign-in links expire after 15 minutes, sessions after seven days, and Zoom authorization state after ten minutes. Expiration prevents further authorized use; it is not a promise that every related security or provider log is erased at exactly that moment. Expired authentication records are cleaned up as part of the application’s authentication and request processes.
You can remove your uploaded photo through the profile-photo control. Clearing a pastoral note replaces the note content in the application; backups and records held for a justified legal purpose may be treated separately. Account closure, deletion of personal data, cancellation of a membership, and removal of a Zoom authorization are different requests. Tell us which actions you want. We will explain the consequences and any information we must retain, and will not require you to leave a paid subscription renewing merely to exercise a privacy right.
When deletion is required, we address active systems and instruct applicable processors as required. Backup copies may remain until their scheduled replacement or deletion, subject to applicable deadlines and restrictions on use. We do not promise a fixed backup-deletion period that has not been established for the relevant provider. Information another participant legitimately retains, public copies made by others, and information a provider holds for its own legal purposes may require a separate request to that recipient.
10. Security
We use account authentication, role and ownership checks, request limiting, encrypted storage of Zoom credentials, and other measures intended to protect information. The protection applied to Zoom tokens does not mean all database content is encrypted separately at the application layer. Stored Selah messages and pastoral notes are not end-to-end encrypted.
No service can guarantee that every loss, unauthorized access, or disclosure will be prevented. Protect your email account, do not share sign-in or host links, use a private device where possible, and report suspected unauthorized access to support@workbird.co. If an incident requires notice, we will provide notice under the applicable law rather than rely on this policy to excuse that obligation.
11. Your requests and privacy rights
You can use available profile controls to update preferences and your photograph. Privacy & account provides consent controls and a download of your account information and authored content. The download is not a final determination of every record available under a legal access right; information involving another person's privacy or a legal privilege may require individual review. For additional access, correction, deletion, account closure, a portable copy, withdrawal of consent, information about disclosures, or another applicable privacy right, email support@workbird.co. Describe your request and the email used for your account. You do not need to create a new account to make a request. Closure, deletion, reports, and appeals are reviewed email processes, not an automatic erasure or case-management dashboard.
We may reasonably verify identity or an agent’s authority before releasing or changing private information. We avoid asking for unnecessary sensitive verification material. Tell us if you cannot use your account email so we can consider another method. We do not require identity verification for an opt-out where the applicable law forbids that requirement.
Rights depend on the applicable law and its coverage. Where the Delaware Personal Data Privacy Act applies, rights include access, correction, deletion, portability, information about categories of third-party recipients, and opting out of covered sales, targeted advertising, and certain significant automated decisions. We do not retaliate for exercising an applicable right.
For covered Delaware requests, we respond within 45 days, with a permitted additional 45 days when necessary and explained within the original period. If we decline a request, we explain why and how to appeal. Email the same privacy contact with “Privacy appeal” and the original request details. We respond to a Delaware appeal within 60 days. You may also complain through the Delaware Department of Justice privacy portal. A shorter or different mandatory deadline under another applicable law controls where required.
Requests are generally free. We charge or decline repetitive or excessive requests only where permitted and with an explanation. We may limit a response to protect another person’s information, a legally recognized privilege, security, or other lawful interests. A restriction in the account interface does not, by itself, decide the legal scope of an access or deletion right.
12. Age, location, and international visitors
Selah is intended for adults age 18 or older using the service in the United States. We do not offer child accounts or a parent-managed account program. Do not create an account for a child or let a child take over an adult account. If you believe a child’s information has been submitted improperly, contact support@workbird.co so we can investigate and take appropriate action.
The service and its providers may process information in the United States and other locations where their infrastructure and personnel operate. We do not promise that all data remains in Delaware or that every provider has the same processing location. Visiting from elsewhere does not waive mandatory privacy protections that apply to you. Expansion into additional supported countries requires corresponding notices and operating arrangements.
13. Changes and contact
We will publish an updated effective date when this policy changes. For a material change, we will provide a notice appropriate to the change, such as a prominent website/account notice or email. Where a new purpose or category of sensitive processing requires consent, a policy update alone will not supply that consent.
Privacy: support@workbird.co
Account and safety support: support@workbird.co
Workbird LLC · Effective September 22, 2026 · support@workbird.co