1stHour Back to 1stHour

Privacy policy

What 1stHour holds, and what it does with it.

Effective 1 October 2026. Operated by 1stHour LLC.

1stHour is a planning tool for a ward bishopric. It holds the records a bishopric keeps anyway, it publishes only the part a ward is meant to see, and it is not funded by advertising. Nothing in it is sold.

Who this applies to

Two groups of people appear in 1stHour, and they are treated differently.

  • Bishopric users. The people who sign in and plan: the bishop, his counselors, the ward clerk and executive secretary, and anyone a ward gives a bulletin editing role to.
  • Ward members recorded by a bishopric. People who do not sign in, but whose names a bishopric enters in order to plan, such as a speaker to invite or a position to fill. These records are created by the ward, not by the member.

A ward bishopric decides what goes in. 1stHour stores it for them and makes it useful. Wards are kept separate from each other by design: every record carries the ward it belongs to, and a sign-in only reaches its own ward.

What a ward puts into 1stHour

Depending on which parts of the app the ward switches on, that can include:

  • People a bishopric can ask to speak. A display name, whether they are youth, whether they have asked not to be called on, whether they have moved out, a free text note, the dates they have spoken, and the dates they declined.
  • Sacrament meeting plans. Speakers, hymns, prayers, ward and stake business, the conducting script, and the announcements that become the bulletin.
  • Assignments raised by any part of the app, with who owns them and when they are due.
  • Callings, if switched on: the position, the person proposed, and where it has reached between proposed and set apart.
  • Interviews, if switched on: who is being seen, when, for how long, and the reason in general terms.
  • Bishopric meeting agendas and notes, if switched on.
  • The ward's recurring events, if switched on, with owners and notes.
  • Images a ward uploads, such as a flyer on an announcement or a photo at the top of a Sunday. These are stored privately and served only at addresses that cannot be guessed.

What is deliberately not there

The speaker list holds no phone numbers, no email addresses and no home addresses for ward members. 1stHour does not import a membership record, and it is not connected to any Church system. Nothing in it is an official record of The Church of Jesus Christ of Latter-day Saints.

1stHour is not the place for confidential interview content. An interview record holds who is being seen, by whom, when and for how long. There is no field for what was said in it.

1stHour does not message ward members

The only email 1stHour sends goes to the people who sign in, and it is the sign-in link itself. Ward members recorded by a bishopric are never emailed or texted by the app. When a bishopric offers interview times, it copies a link and sends that link itself, through whatever it already uses. No member contact details are needed for that, and none are stored for it.

What the ward can see

One part of 1stHour is public by design: the page a ward opens on Sunday. It shows the program, the announcements, and the bishopric contact details the ward chooses to publish. It does not require a sign-in, so treat anything published there as public.

Planning stays private. A speaker who has only been asked, or who declined, is never shown on the public program. Interviews, callings in progress, bishopric meeting notes and assignments are visible only to the ward's signed-in bishopric.

Google Calendar

1stHour offers an optional connection to Google Calendar, so that interview times are not offered when the interviewer is already busy, and so a booked interview appears on their calendar. It is off unless somebody turns it on, and it is one connection per interviewer: connecting the bishop’s calendar does not touch a counselor’s.

An interviewer can connect their own calendar. So can the bishop or the executive secretary, who already set other people’s availability, which covers the ordinary case of a secretary managing a calendar the bishop has shared with them. 1stHour records which Google account granted the connection and who set it up.

The scopes requested

Four, asked for together at the first connection so that nobody has to reconnect later:

  • openid and email, to know which Google account granted the connection. This is not how anyone signs in to 1stHour.
  • calendar.calendarlist.readonly, to list the calendars on the account so the right one can be picked.
  • calendar.freebusy, which returns whether a block of time is busy or free and nothing about what is in it.
  • calendar.events, to put a booked interview on the calendar, move it when it moves, and take it off when it is cancelled. This scope can read and write events, which is what putting something on a calendar requires.

What it is used for

Two visible purposes, and nothing else: subtracting busy blocks from the interview times a bishopric can offer, and keeping the interviews 1stHour itself created in step on the connected calendar. 1stHour does not read other people’s events to show them to anyone, does not use calendar contents for advertising or profiling, and does not train any machine learning model on them.

Tokens

The authorization Google issues is stored encrypted at rest, with AES-256-GCM or a key held in AWS KMS. It is used only to make the calls described above.

The use of information received from Google Workspace scopes will adhere to the Google User Data Policy, including the Limited Use requirements.

Disconnecting

Turning the setting off in 1stHour stops the connection and discards the stored authorization token. Access can also be revoked at any time from Google Account permissions, which works whether or not 1stHour is open.

[CONFIRM ON MERGE: this section was written from the Google Calendar branch (docs/google-calendar.md), which is not yet in main. Re-read it against the shipped code, and check what disconnecting does with the stored token and whether free/busy results are cached.]

Signing in

Signing in identifies a person by an email address and the ward and role attached to it. 1stHour stores that email address, the ward, and the role.

1stHour has no passwords. Signing in means asking for a link, which arrives by email and signs that person in when they open it. Nothing about a password is stored, because none is ever set.

Sign-in does not use a Google account. Connecting a Google Calendar is a separate, optional thing, described below; it tells 1stHour the email address of the account that granted it, and nothing else about that account. 1stHour never receives a Google contact list or Gmail content.

Where the data lives

1stHour runs on Amazon Web Services in the United States, in the Oregon region (us-west-2). Records are held in DynamoDB and uploaded images in a private S3 bucket. Traffic is served over HTTPS. Storage buckets are not publicly listable, and uploaded files are reachable only through the content delivery network at unguessable addresses.

Youth and children

1stHour is used by adult members of a bishopric, and is not directed to children. It can, however, hold information about people under 18, because a bishopric plans youth speakers and youth interviews. That information is entered by the ward, not by the young person, and it is limited to what planning needs: a name, that they are youth, and the dates involved.

A parent or guardian who wants a young person's record removed should ask the ward bishopric, who can remove it directly, or contact 1stHour at the address below.

Diagnostics

1stHour records operational logs and traces so that failures can be found and fixed. These hold request paths, timings, error details, and the ward and role that made the request. They expire automatically, currently after 14 days. They are not used to profile anyone and are not shared for advertising.

The waitlist

The email address entered on the 1stHour home page is collected through a Google Form and used for one thing: telling that person when 1stHour opens to more wards. It is not sold and not passed to anyone else.

Email 1stHour sends

Two kinds, both to people who sign in, never to ward members:

  • Sign-in links. Sent when somebody asks to sign in. This is how 1stHour works without passwords.
  • Reminders about a ward's own work, such as a speaker still waiting on an answer. This is planned rather than built, and it will be something a ward can switch off.

1stHour does not send marketing email, and a sign-in address is not added to any mailing list.

Sharing

1stHour does not sell personal information and does not share it for advertising. It is shared only with the infrastructure providers that run the service, currently Amazon Web Services and Google (for the waitlist form and, where a user connects it, Google Calendar), and where the law requires it.

Keeping and deleting

Ward records are kept while the ward uses 1stHour, because a bishopric's value in it comes from history: who spoke last spring, who was asked, what happened last year.

A bishopric can delete most records from inside the app, including meetings, business items, templates and a person's access. Someone on the speaker list is marked as moved out rather than deleted, so that the ward's history of who spoke stays intact.

To have a ward's entire data removed, or one person's records removed outright, write to the address below. Requests are answered within 45 days. Removal covers the live records and the uploaded images. Operational logs expire on their own schedule, currently 14 days.

Changes

When this policy changes, the effective date at the top changes with it. A change to how Google user data is used will be described here before it takes effect.

Contact

Questions, deletion requests and anything else about privacy: support@1sthour.app.