CBMC, Inc. · CBMC One

CBMC One conference app

Effective: September 15, 2026

CBMC One is a companion application for CBMC conferences and events. This addendum explains app-specific data practices and supplements the CBMC Privacy Policy. If this addendum conflicts with the general policy for CBMC One, this addendum describes the app's current technical behavior.

Information used by the app

CBMC One uses the email address associated with an event registration to confirm eligibility and deliver a one-time sign-in code. After sign-in, the app may display registration profile information such as name, organization, title, city, and profile photo.

The app stores attendee choices needed to provide its features, including saved schedule items, notification preferences, directory visibility, breakout registration state, assigned activity-ticket names, quantities and statuses, and push-notification device registrations. Activity checkout takes place on the registration website; the mobile app does not receive payment-card details. If enabled for an event, attendees may upload a profile photo or submit prayer and praise text and replies, react to posts, report content, or block authors. Prayer content may reflect religious or philosophical beliefs. Content marked anonymous is hidden from other attendees, but remains associated internally with the submitting attendee for security, rate limiting, and moderation.

CBMC One also records when the app is opened, the names of screens visited, app/device characteristics, and crash and sampled performance diagnostics. These records are associated with the signed-in member ID, name, and email so authorized support staff can understand feature use and investigate problems. Dynamic attendee, session, and speaker identifiers, touch interactions, screen contents, query parameters, notes, and prayer text are not included in mobile analytics or crash-reporting events.

How information is used

CBMC uses this information only to operate the event app: authenticate eligible attendees, present event and attendee information, remember app preferences, support event participation, deliver requested conference notifications, protect the service, and respond to support or privacy requests. CBMC One does not use app data for third-party advertising or cross-app tracking. CBMC uses limited product analytics to improve the app and diagnostic data to find and fix crashes, errors, and performance problems.

Service providers

CBMC uses service providers to operate CBMC One, including AnyRegistration for event registration and event content, Cloudflare for API and database hosting, Postmark for transactional one-time-code email, Expo for push-notification brokerage, Apple Push Notification service for iOS delivery, and Firebase Cloud Messaging for Android delivery. CBMC also uses PostHog for product analytics and Sentry for crash reporting and sampled performance diagnostics. Providers process information only as needed to provide these functions and under their applicable agreements with CBMC.

When automated Prayer Wall review is enabled, the broker sends submitted prayer or reply text to OpenAI to check for unsafe content and correct clear spelling, punctuation, and capitalization mistakes. It also sends a hashed attendee safety identifier. The submitted text can itself contain personal or sensitive information. The app requests that Responses API results not be stored; this does not mean that the provider retains no data for security or abuse monitoring. Authorized conference administrators also review reports and moderate contributions.

Directory, contributions, and photos

Attendees are hidden from the in-app directory by default and must choose to be visible. A visible attendee can turn directory visibility off. Directory profiles may show name, organization, title, city, and an approved profile photo to other eligible event attendees.

Prayer and praise submissions may be shown to other eligible attendees. An anonymous option hides the attendee's public name but does not remove the internal linkage needed for safety and moderation. Attendees should not submit confidential information about themselves or another person.

Profile-photo selection uses the device photo picker. CBMC One accepts only the selected image and does not scan the attendee's photo library.

Push notifications

If an attendee allows notifications, CBMC One registers an app-specific push token and device model so CBMC can deliver conference announcements, program changes, and session reminders according to the attendee's preferences. The attendee can change notification permission in device settings and change conference notification preferences in the app.

Information kept only on the device

General notes and session notes are stored only on the attendee's device and are not uploaded to CBMC. The app warns the attendee to export notes before sign-out because sign-out removes them from that device. Downloaded conference files and offline caches also remain on the device until removed by the user, the app, or the operating system.

Retention and choices

CBMC retains app information only as long as needed to operate the event, protect the service, meet legal obligations, and handle support requests. Attendees can hide their directory profile, adjust notification preferences, remove a profile photo when the feature is available, and contact CBMC to ask about access, correction, or deletion.

Account and data deletion

To request deletion of your CBMC One account and associated personal data, open Profile → Delete Account & Data in the app, or use the public deletion request page. You do not need to reinstall the app or send a separate email to start a request. CBMC verifies ownership of the email address for requests submitted through the public website.

CBMC support completes verified requests within 30 days and emails a confirmation when finished. Deletion includes associated profile information, schedule and notification preferences, registered devices, and Prayer Wall contributions. CBMC coordinates fulfillment with AnyRegistration and applicable app service providers. Records required by law, such as transaction records, may be retained; support explains applicable exceptions. Requesting account deletion does not automatically cancel or refund conference tickets. Privacy request records are used to verify, fulfill, and document the request and are kept only as necessary for that purpose and applicable legal obligations.

Export any on-device notes you wish to keep before signing out or uninstalling. For privacy questions, contact support@cbmc.com. The CBMC Privacy Policy also applies.

Questions? support@cbmc.com · CBMC Privacy Policy