Introduction
Good Joseph ("we", "us", "our") provides financial education content through the Good Joseph Android app, and the website at goodjoseph.com.
This Privacy Policy explains what personal information we collect, why we collect it, who we share it with, and the choices you have. By using our services, you agree to the practices described here.
Android app
When you use the Good Joseph Android app, we may collect and process the following information:
Account information: your mobile phone number and a password you choose. Passwords are stored on our servers using one-way hashing; we never store your password in plain text.
Profile information: your first and last name, if you provide them or if they are supplied by M-Pesa payment confirmations. You can edit your name in the app after signing in.
Payment information: when you pay via M-Pesa STK Push, we send your phone number and payment amount to Safaricom to trigger the PIN prompt. We store transaction references, receipt numbers, amounts, and related purchase records to unlock paid guides and topics. We do not receive or store your M-Pesa PIN.
Purchase and entitlement history: records of guides and coaching topics you have purchased or subscribed to, so we can grant access to paid content.
Push notification token: if you are signed in and allow notifications, we collect a Firebase Cloud Messaging (FCM) device token and store it on our servers so we can notify you when new lessons or guides are published.
Session data: access and refresh tokens are stored locally on your device (Android DataStore) to keep you signed in. Android backup is disabled for the app because these tokens are sensitive.
App preferences: theme mode and navigation layout choices are stored locally on your device only and are not sent to our servers.
The app requests Internet access to communicate with our API and notification permission (Android 13+) if you want push alerts. The app does not access your location, contacts, camera, microphone, or photo library.
Website (goodjoseph.com)
When you use our website, we may additionally collect:
Google sign-in: if you sign in with Google, we receive your Google account ID, email address, name, and profile picture URL from Google and store them in your Good Joseph account.
Stripe billing: if you subscribe or pay by card, payment processing is handled by Stripe. We store Stripe customer and subscription identifiers and billing status; card details are handled directly by Stripe and are not stored on our servers.
M-Pesa on the website: similar to the app, we use your phone number and payment details to process M-Pesa payments and record entitlements.
Contact form: if you submit our contact form, we collect your name, email address, topic, priority, and message to respond to your enquiry.
Book orders: if you purchase books on the website, we collect order and payment information needed to fulfil the purchase.
Session cookies: the website uses session cookies managed by NextAuth to keep you signed in when you use Google login. We do not use advertising or third-party analytics cookies on the website.
How we use your information
We use the information we collect to:
Create and manage your account and authenticate you.
Process M-Pesa and card payments and unlock paid content you have purchased.
Send optional push notifications about new guides and lessons (app only, with your permission).
Respond to contact form messages and support requests.
Operate, maintain, and improve our services.
Prevent fraud and enforce our Terms of Service.
Comply with legal obligations and resolve disputes.
What we do not collect
The Good Joseph Android app does not collect precise location, contacts, photos, health data, browsing history outside the app, or advertising identifiers.
We do not sell your personal information. We do not use Firebase Analytics or in-app advertising in the Android app.
Third-party services
We use trusted third parties to operate our services. They process data only as needed to provide their service:
Safaricom (M-Pesa / Daraja API): processes mobile payments. Your phone number and payment instructions are sent to Safaricom when you pay via M-Pesa STK Push (Lipa na M-Pesa Till).
Google Firebase Cloud Messaging: delivers push notifications to the Android app. FCM device tokens are shared with Google for message delivery.
Google Sign-In: authenticates website users who choose "Continue with Google".
Stripe: processes card payments and subscriptions on the website.
Hosting providers: our API and website are hosted on infrastructure we control (including servers in the EU). Data is transmitted to these servers over encrypted connections.
Each third party has its own privacy policy. We encourage you to review Safaricom, Google, and Stripe policies if you use those features.
Storage and security
Data is transmitted between your device and our API over HTTPS (TLS encryption in transit).
Passwords are hashed before storage. Refresh tokens are stored as hashes on our servers.
Sensitive auth tokens on the Android app are kept in DataStore with Android backup disabled.
Access to production systems is restricted to authorised personnel. Admin actions may be logged, including IP addresses, for security and audit purposes.
No method of transmission or storage is completely secure. We work to protect your information but cannot guarantee absolute security.
How long we keep data
We retain account and purchase records for as long as your account is active and as needed to provide services, comply with law, resolve disputes, and enforce our agreements.
Payment and transaction records may be kept for accounting and legal compliance even after account closure.
FCM device tokens are deactivated when you sign out or uninstall the app, or when we detect they are no longer valid.
Contact form messages are retained as long as needed to handle your enquiry and for reasonable record-keeping.
Your choices
Push notifications: you can allow or deny notification permission in your device settings. You can also open notification settings from the Good Joseph app (You → Settings).
Profile: signed-in members can update their name in the app.
Sign out: signing out clears session tokens from your device. Refresh tokens on our servers are revoked on logout.
Website sign-in: you can sign out of the website at any time.
Access, correction, and deletion
You may request access to, correction of, or deletion of your personal information by emailing us at hello@goodjoseph.com. Include the phone number or email associated with your account so we can verify your request.
We do not currently offer an in-app account deletion button. We will process deletion requests manually within a reasonable timeframe, subject to legal retention requirements (for example, payment records we must keep for tax or audit purposes).
If you are in a jurisdiction with additional privacy rights (such as the EU/UK GDPR), you may also have the right to object to or restrict certain processing, or to lodge a complaint with a supervisory authority.
Children
Good Joseph is not directed at children under 13. We do not knowingly collect personal information from children under 13. If you believe a child has provided us with personal information, contact us at hello@goodjoseph.com and we will take steps to delete it.
Changes to this policy
We may update this Privacy Policy from time to time. We will post the revised policy on this page and update the "Last updated" date. Continued use of our services after changes take effect constitutes acceptance of the updated policy.
Contact us
For privacy questions or requests, contact Good Joseph at hello@goodjoseph.com.
Related policies: Terms of Service (Terms of Service) and Refund Policy (Refund Policy).