Privacy
Last updated 18 August 2026
Huddle is built around one rule: it stores the commitment, not the confidence. It records who is doing what by when. It is not a case file, and it is not designed to become one.
Huddle is a private tool for a ward's weekly coordination meeting, operated independently. It is not a product of, endorsed by, or affiliated with The Church of Jesus Christ of Latter-day Saints, and it does not connect to any official Church system.
What Huddle stores
Your account
An email address, and nothing else that identifies you. There is no password: signing in sends a one-time numeric code to your email, and typing it back is what proves the mailbox is yours. Huddle also records which ward you serve in and in what calling, because that is what decides which information you are allowed to see.
What leaders type in
Leaders enter coordination details about people the ward is actively helping: names, assignments, dates, who owns an item, when somebody was last reached, and a short next step.
Nothing is imported. There is no roster import and no membership sync. Every name in Huddle was typed by a leader, by hand, because that person is being actively coordinated — which keeps the list to the few people it concerns rather than to everybody on a ward roll.
On your device
Huddle keeps a copy of your ward's current data in your browser's local storage so it works in a building with no signal. Clearing your browser's site data for this domain removes that local copy.
Who can see it
Every read and write is enforced by row-level security in the database, not by what the app chooses to display. A leader sees their own ward. Stake leadership sees rhythm only — whether a huddle happened, how many items are open, how old they are — with no names and no notes.
Access ends with the calling. Membership records carry an end date, and a released leader loses access automatically on that date. There is no cleanup step for somebody to forget.
What leaves Huddle, and what never does
Some coordination has to reach people outside the app — full-time missionaries work from a Google Sheet, and some items go out by text message. Anything that crosses that line is outside Huddle's protection: it can be read by whoever holds the phone or the link, and it persists after a transfer.
So a single, deliberately narrow projection decides what may cross. It is an allowlist — data does not leave unless it has been explicitly named as permitted, so adding a field to Huddle cannot quietly widen what gets shared.
May leave
- Names of people the meeting has agreed to share with that audience
- Assignments and commitments — the task, its owner, its date
Never leaves, under any circumstances
- The next-step note on a person
- The meeting's read on how a family is doing, and its history
- The record of when and how somebody was reached out to
- Anything about why a person is on the list at all
Google data
When a ward chooses to share a workbook with its missionaries, Huddle acts on a single Google account belonging to the operator of this service. It uses that account's Google Drive, Docs and Forms access to create the workbook, the printed page and the response form, to share them with the missionaries' area address, and to read back the responses that come in.
Huddle's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Data obtained through Google APIs is used only to provide the sharing features described above. It is never sold, never transferred to anyone else except as needed to provide those features, never used for advertising, and never read by humans except with your consent, for security purposes, or where required by law.
Sharing is reversible. When a ward revokes a shared workbook, access is withdrawn from the address it was shared with.
Services Huddle relies on
- Supabase — the database and sign-in codes
- Vercel — hosting for the app itself
- Google — only for wards that turn on missionary sharing
There is no analytics, no advertising, no tracking pixel, and no third-party font. Nothing about your ward is sold or shared for marketing, ever.
Keeping and deleting
Coordination data is kept while the ward is using Huddle. You can ask for your account or your ward's data to be deleted by writing to the address below, and it will be removed from the database. Anything already exported to a Google Sheet or sent as a text message lives outside Huddle and has to be deleted where it now is.
Children
Huddle accounts are for adult ward leaders. Children do not sign in. A leader may record a young person's name as part of coordinating help for a family, under the same narrow rules as any other name.
Changes
If this policy changes in a way that affects what is collected or where it goes, the date at the top changes with it.
Contact
Questions about this policy, or a request to delete data: jamesonblds@gmail.com