MormonGPT
Library Pricing Sign in
Try free
Contents 1. Who we are 2. What we collect 3. Questions about religion 4. How we use it 5. Who else sees it 6. Sharing a conversation 7. How long we keep it 8. Your choices 9. Your legal rights 10. Children 11. Security 12. Where data is processed 13. Changes 14. Contact us

Privacy

Privacy Policy

Effective 15 August 2026 Last updated 30 August 2026

The short version

  • We collect the email address you sign in with, the questions you ask, and the answers you get. That is most of it.
  • Your questions are sent to OpenAI to produce an answer. They are not sent anywhere else, and we do not sell them or use them for advertising.
  • Questions on this site are about religion. In much of the world that is legally sensitive information, so section 3 explains how we treat it.
  • A conversation is private to you unless you create a share link, which makes it readable by anyone who has the URL until you revoke it.
  • You can export or delete your account and its contents at any time by writing to [email protected].

This summary is for orientation only. The sections below are the policy.

1Who we are

MormonGPT is operated by Mcgurk Labs LLC (“we”, “us”, “our”), the controller of the personal information described here. You can reach us at [email protected].

MormonGPT is an independent research tool. It is not affiliated with, endorsed by, or connected to The Church of Jesus Christ of Latter-day Saints or any other religious organisation.

2What we collect

We collect only what the service needs to work. There is no advertising network here, no cross-site tracking, and no data broker relationship.

Account detailsWhen you sign in

Your email address, and — if you sign in with Google — your first and last name, profile photo URL, and Google account identifier. If you sign in with an emailed link or a passkey, we may hold only your email address. Passkeys are stored as public keys; we never receive your fingerprint, face, or device PIN.

Sign-in and device recordsSecurity

For each active session: a hashed session token, a device label derived at sign-in (for example “Chrome on macOS”), the browser user-agent string, and the IP address the sign-in came from. We keep a sign-in log so you can review and revoke devices in Settings. Requests for an emailed sign-in link also record the requesting IP address, to limit abuse of a form that anyone can submit.

Your research contentThe service itself

The questions you type, the answers generated for you, the sources cited in those answers, conversation titles (generated automatically from your first question), your default source-class preferences, and any feedback you leave on an answer — including the reasons you select and any note you write.

Declined questionsSafety

If the service declines to answer a question, we record the question text, the category of the refusal, and the account it came from, so we can tell a misuse attempt from a legitimate question wrongly refused and fix the latter.

Billing recordsIf you pay us

Your plan, purchases, credit grants and receipt links, plus the customer and subscription identifiers our payment processor assigns you. We never see or store your card number. Card details go directly to Stripe and are handled under their terms.

Usage and cost telemetryRunning the service

For each request to the language model: which model ran, how many tokens went in and out, how much of the input was served from cache, and what it cost. This is how we price the service and find performance problems.

How you found usIf you arrived from an ad or a link

If you reached us from a Google ad or a link on another site, we record which campaign or which site, and the first page of ours you landed on. We keep it on your account so we can tell whether the advertising we pay for reaches anyone. It is never sent back to Google or to anyone else, and it says nothing about you beyond how you arrived.

Push notificationsOnly if you turn them on

If you switch on notifications we store what your browser gives us to reach that device — a delivery address and its keys — plus a device label. We use it for one thing: telling you an answer you asked for has finished. There is no marketing push, and turning it off in Settings deletes the record.

Site analyticsAggregate only

We use Fathom Analytics, which is cookieless and does not build profiles of individual visitors or follow them across sites. It tells us page views and referrers in aggregate.

What we store on your device

Most of it is your browser’s local storage: your session token so you stay signed in, your appearance preference (light, dark, or system), your default source classes, and your text-size setting. Clearing your browser storage signs you out and resets those preferences.

We also set four small cookies, all of them our own. None of them is readable by another website, and none of them follows you off this one:

  • Signing in — two short-lived cookies that exist only for the seconds between clicking “sign in” and arriving back here. One ties a Google sign-in to the browser that started it, so somebody else cannot finish it for you. The other carries your new session token to the page. Both expire within two minutes.
  • How you found us — if you arrived from a Google ad or a link on another site, we record which one, along with the first page you landed on. It tells us whether the advertising we pay for is reaching anyone. It is not shared with Google or with any other website, it holds nothing about who you are, and it is deleted the moment you sign in. If you never do, it expires after 30 days.
  • A new account — a marker set for one page load so we can count how many people finish signing up. It is deleted the moment the page reads it.

We do not use cookies for advertising, we do not let anyone else set one here, and nothing on this site follows you to another.

3Questions about religion

This service exists to answer questions about a religion, so the questions you ask can reveal something about your own beliefs, doubts, or circumstances. Under the GDPR and similar laws, information revealing religious belief is a special category of personal data that gets extra protection. We treat your questions that way regardless of where you live.

In practice that means:

  • We process this content because you have explicitly asked us to by typing a question and submitting it. That consent is our legal basis, and you can withdraw it by deleting the conversation or your account.
  • We do not use your questions to build a profile of you, to infer your beliefs, or to target you with anything.
  • We do not sell this content, and we do not disclose it to any third party except the processors listed in section 5, who are contractually limited to running the service.
  • Staff access is limited to what is needed to operate the service — investigating a fault you report, reviewing feedback you submit, or reviewing a declined question. It is not browsed casually.

Please do not type information about other people that they would not want recorded. A question about a named living person’s worthiness, discipline, membership status or family situation puts their sensitive information into our systems, and you may not have the standing to consent on their behalf. Ask about the texts, not about identifiable individuals.

4How we use it

We use the information described above to:

  • Answer your questions, cite the sources those answers draw on, and keep your conversation history available to you.
  • Create and secure your account, keep you signed in, and let you review and revoke your own devices and passkeys.
  • Count and enforce your question allowance, take payment, and issue receipts.
  • Screen out misuse — attempts to extract our instructions, requests to fabricate a source, and similar.
  • Investigate faults, measure cost, and improve retrieval quality and answer accuracy.
  • Send you the transactional email the service requires: sign-in links and receipts. We do not send marketing email.
  • Send a push notification, if you have switched them on, when an answer you asked for has finished. That is the only thing we ever push, and you can turn it off in Settings.
  • Comply with law, and establish or defend legal claims.

We do not use your questions or conversations to train any AI model, ours or anyone else’s.

5Who else sees it

We do not sell personal information and we have never disclosed it for anyone’s advertising. We do rely on a small number of service providers, each of which processes data only on our instructions:

OpenAIGenerating answers

Your question, the conversation it belongs to, and the source passages retrieved for it are sent to OpenAI’s API to produce an answer, a title, and the safety screen. This is the one processor that sees the substance of what you ask.

GoogleSign-in

If you choose “Continue with Google”, Google authenticates you and returns your email address, name and profile photo. Google’s handling of that sign-in is governed by their own privacy policy.

StripePayments

Card details are collected by Stripe directly and never reach our servers. Stripe is an independent controller for the payment data it collects.

ResendEmail delivery

Sends sign-in links and receipts to your address.

CloudflareHosting and database

Hosts the site, runs the application, and stores the database. Your content is at rest in Cloudflare’s infrastructure.

SentryFault monitoring

When something breaks, the error and enough context to find it are sent to Sentry. That context is deliberately limited to internal identifiers — an account number, not an email address — along with the page the fault happened on and your browser version. It never carries the text of your questions.

Fathom AnalyticsAggregate statistics

Cookieless page-view counts. No individual profiles, no cross-site tracking.

We may also disclose information if we are legally required to, or where we believe in good faith that disclosure is necessary to protect someone’s safety, to investigate fraud, or to establish or defend a legal claim. If Mcgurk Labs LLC is ever acquired or merged, account information may transfer as part of that transaction; we will tell you before your information becomes subject to a different privacy policy.

6Sharing a conversation

You can create a share link for a conversation or a single answer. Doing so publishes that content at a public URL:

  • Anyone with the link can read it. No account is required.
  • The shared page shows the questions, the answers and the sources cited — not your name, email, or any of your other conversations.
  • Search engines and anyone the recipient forwards it to may reach it, and may cache or copy it.
  • You can revoke a link at any time from the share dialog or from Settings. Revocation stops the page being served, but we cannot un-publish copies other people have already made.

Only share a conversation you are comfortable being read by strangers.

7How long we keep it

  • Your account and conversations — for as long as your account is open.
  • Deleted conversations — marked deleted immediately and removed from the service, then permanently erased 30 days later. The short window exists so an accidental deletion can be reversed.
  • Deleted accounts — the same 30 days, after which your email address, your name, your photo, how you found us and every conversation are erased. Where a receipt has to point at something, a numbered shell of the account remains with nothing in it that identifies you.
  • Sign-in and device records — up to 12 months, for security investigations. A session you are still signed in on is not a record we expire; sign it out in Settings and it goes.
  • Requests for an emailed sign-in link — 30 days, then deleted with the IP address they recorded.
  • How you found us — for as long as your account is open, and erased with it. Before you have an account, 30 days.
  • Push notification records — until you turn notifications off for that device, or your account is erased.
  • Billing and tax records — as long as tax and accounting law requires, typically seven years. These survive account deletion because we are required to keep them.
  • Declined-question records — up to 12 months, after which the question text is erased and only the category and its cost remain.
  • Aggregate usage and cost statistics — indefinitely, in a form that is not linked to you.

These are not intentions. A job runs every night and applies each of the periods above; when it removes anything it says so, and if it stops running we are told.

8Your choices

  • Delete a conversation — from the ⋯ menu beside it in the sidebar.
  • Revoke a share link — from the share dialog, or Settings → Research → shared links.
  • Sign out a device or remove a passkey — Settings → Security.
  • Cancel a subscription — Settings → Plan & sharing. Questions you have already paid for stay available to the end of the period.
  • Export or delete everything — write to [email protected] from your account’s email address and we will action it within 30 days.

9Your legal rights

If you are in the UK, EEA or Switzerland

You have the right to access the personal data we hold about you, to have it corrected or erased, to restrict or object to how we use it, to receive it in a portable form, and to withdraw consent at any time (which does not affect processing already carried out). Our legal bases are: consent for the content of your questions and any special category data they reveal; performance of a contract for running your account and taking payment; legitimate interests for security, abuse prevention and service improvement; and legal obligation for tax and accounting records.

You may lodge a complaint with your local supervisory authority. We would appreciate the chance to resolve it first.

If you are in California

Under the CCPA as amended by the CPRA you have the right to know what personal information we collect and why, to request a copy of it, to request deletion or correction, and to be free from discrimination for exercising those rights. In the twelve months before the date above we collected the categories described in section 2, which include identifiers, commercial information, internet activity, and — because of what this service is for — information that may reveal religious beliefs.

We do not sell or share personal information as those terms are defined by the CCPA, and we do not use or disclose sensitive personal information for any purpose other than providing the service.

Everyone else

Wherever you live, you may ask us for a copy of your data or ask us to delete it, and we will honour the request. Write to [email protected]. We may need to verify that the request comes from you, which normally means replying from the address on the account.

10Children

MormonGPT is not intended for children under 13, and we do not knowingly collect personal information from them. If you are between 13 and 18, you may use MormonGPT only with the involvement of a parent or guardian. If you believe a child under 13 has given us personal information, write to [email protected] and we will delete it.

If you are in the EEA or UK and under the age at which you can consent for yourself (13 to 16 depending on the country), a parent or guardian must consent on your behalf.

11Security

Session tokens are stored hashed, never in plain text. The site is served over HTTPS only, with a strict content security policy. Payment card data never touches our servers. Passkeys are supported so you can sign in without a password at all, and you can see and revoke every active session from Settings.

No service can promise perfect security, and we will not pretend otherwise. If we discover a breach affecting your personal information we will notify you and the relevant regulator as the law requires.

12Where data is processed

Mcgurk Labs LLC is based in the United States, and our providers process data in the United States and other countries. If you are in the UK or EEA, this means your information is transferred outside your home jurisdiction. Where that happens we rely on the European Commission’s Standard Contractual Clauses or an equivalent transfer mechanism offered by the provider in question.

13Changes

If we change this policy we will update the date at the top. If a change materially affects how we handle your information — a new processor that sees the content of your questions, a new purpose, a longer retention period — we will tell you by email or in the app before it takes effect, and where the law requires consent we will ask for it rather than assume it.

14Contact us

Questions about this policy, requests about your data, or complaints:

Mcgurk Labs LLC
[email protected]

We aim to answer within a few days and, for formal data requests, within 30 days.

MormonGPT is an independent research tool. It is not affiliated with, or endorsed by, The Church of Jesus Christ of Latter-day Saints. All quoted texts remain the property of their publishers.

Read the Terms of Service →