← nTer

nTer

Privacy Policy

Version 1.5 • effective 30 July 2026 • first published 3 August 2026

Launch verification: before first publication, confirm Cloudflare's product-specific retention configuration and complete the final production cookie and device-storage scan.

This policy explains what personal information nTer collects, how it is obtained, why it is used, where it is processed, how long it is kept, when it is disclosed and the rights and choices available to you. nTer is a daily Christian devotional service operated by Matt White International (Pty) Ltd. This policy is designed to meet the transparency requirements of the Protection of Personal Information Act, 2013 (South Africa) and other privacy laws that apply where nTer deliberately offers the service.

In brief

  • We collect only the information needed to operate, secure and support nTer.

  • Your Whisper Journal is encrypted before storage. We do not routinely inspect, analyse or use its content.

  • We do not sell personal information, disclose it for targeted advertising, or use journal content to train artificial-intelligence models.

  • We use a limited group of service providers to operate the platform, as described below.

  • You can access, export, correct or delete your information and withdraw optional consents.

  • You must be 18 or older to create an nTer account.

This summary helps you navigate. The full policy governs.

What this policy covers

1 Who we are and how to reach us

2 Scope and how we collect information

3 The information we hold, why we hold it and how long we keep it

4 Your use of nTer, the Whisper Journal and sensitive information

5 How we disclose personal information

6 How we protect personal information

7 Where personal information is processed

8 Retention, deletion and backups

9 Cookies, analytics and on-device storage

10 Email and other messages

11 Your rights and choices

12 Children, automated decisions and profiling

13 Regional information

14 Changes, questions and complaints

1. Who we are and how to reach us

nTer is a service of Matt White International (Pty) Ltd, a private company incorporated in the Republic of South Africa under the Companies Act 71 of 2008, registration number 2017/378663/07. Physical business address and address for service: 34 2nd Avenue, Linden, Johannesburg, 2196, South Africa. Postal address: Suite 8, Private Bag X1, Greenside, Johannesburg, 2034, South Africa.

For matters relating to personal information, including requests and complaints, contact our registered Information Officer, Matthys Johannes Kruger-Nel, at info@mattwhiteinternational.com or +27 82 869 6163. For ordinary nTer service support, contact support@nter.life.

In this policy, “we”, “us”, “our” and “nTer” mean Matt White International (Pty) Ltd. Under POPIA, we are the responsible party for personal information used for nTer. nTer is offered from South Africa and is not made available for Account creation to people located in the European Economic Area or the United Kingdom at the point of sign-up, so the EU and UK GDPR do not ordinarily apply to our processing. Where any data-protection law applies to a particular person or processing activity, we comply with it. “You” and “your” mean the person using or communicating with nTer.

The relevant Paddle group company identified at checkout or on your receipt is nTer’s authorised reseller and Merchant of Record. Depending on your location, this may be Paddle.com Inc., Paddle.com (Canada) Ltd. or Paddle.com Market Limited. Paddle independently determines how it handles checkout, payment, tax, invoicing, fraud prevention and related billing information. Paddle’s own privacy notice governs that processing. nTer receives only the limited subscription and transaction information needed to provide and support the service.

2. Scope and how we collect information

This policy applies to the nTer website, installable web application, account, Whisper Journal, daily reading, email delivery, support interactions and subscription administration. It does not govern a third party’s website or service merely because nTer links to it.

Territorial availability. At launch, nTer is not offered to, and does not knowingly accept sign-ups or Subscriptions from, people located in the European Economic Area or the United Kingdom at the point of sign-up. Reasonable location controls operate before an Account is created or any Whisper Journal content is accepted, and may include IP-based geolocation and other location indicators. The Terms of Service explain this restriction. Nationality alone does not determine whether it applies.

We collect information in four ways:

We do not purchase personal information from data brokers. We do not collect your legal name, residential address or identity document for an ordinary nTer account unless a particular legal, billing, support or fraud-prevention need requires it and you are told at the time.

Where information is required, we explain the consequence of not providing it. Without an email address and adult-status confirmation, nTer cannot create an account. Journal use, reminders and marketing communications remain optional.

3. The information we hold, why we hold it and how long we keep it

The table describes the principal categories of personal information processed by nTer. “Contract” means processing needed to provide the service you request. “Legitimate interests” means a necessary business or security purpose that we assess against your rights. Because nTer is expressly a Christian devotional service, creating an account, subscribing or using the service may reveal or permit an inference about religious beliefs. Where applicable law treats that information as special-category or sensitive information, we rely on explicit consent collected separately from acceptance of the Terms, in addition to the ordinary lawful basis shown in the table. We also request separate explicit consent for sensitive Whisper Journal content. Consent is not bundled with marketing consent.

Information Source and purpose Required and lawful basis Retention
Account identifiers and authentication data Your email address, an internal user identifier, sign-in records, magic-link events and related authentication information. We use these to create and secure your account and let you sign in. Email and adult-status confirmation are required. Contract; legitimate interests in account security and preventing misuse; legal obligations where applicable. Account identifiers remain while the account is active. Authentication and security logs are normally kept for a limited period under sections 6 and 8.
SoulName A display name you choose. It need not be your legal or real name. It is shown within your account and service experience. Required for the account experience, but you may use a pseudonym. Contract. While your account is active, then deleted under section 8.
Adult age confirmation You provide your date of birth once. nTer checks whether you are 18 or older, immediately discards the date itself and keeps only the result and date of verification. Required. Contract; legitimate interests in maintaining an adults-only service; legal obligations where applicable. The yes/no result and verification date remain while the account is active. The date of birth itself is not intentionally stored.
Whisper Journal entries The private reflections you choose to write. We use them only to store them securely and return them to your authenticated account. Optional. Contract for the journal function, plus explicit consent where entries reveal special-category or sensitive information. While your account remains active, subject to deletion, withdrawal and dormancy rules in section 8.
Candle activity and devotional progress A record that you lit a candle, completed a reading or used a related feature, so the service can remember the state you selected. Optional feature data. Contract. While your account is active, then deleted under section 8.
Timezone, reminders and preferences Timezone may be detected from your browser and can be changed by you. We use it with your reminder and email choices to deliver messages at the intended local time. Timezone and reminders are optional. Contract for requested functionality; consent for optional electronic communications where required. While your account is active or until you change or withdraw the preference.
Consent and policy records Records of the consents, withdrawals and policy or terms versions associated with your account. We use these to honour your choices and demonstrate compliance. Generated automatically. Legal obligations and legitimate interests in accountability. For as long as needed to demonstrate compliance, normally for the life of the account and a reasonable period afterwards.
Subscription and transaction information Information received from Paddle, such as subscription status, plan, customer or transaction reference, purchase date, currency, country, tax status and limited billing or contact details Paddle makes available to us. nTer does not receive your complete card number. Required for paid access. Contract and financial, tax, accounting and fraud-prevention obligations. Subscription status while relevant to the account. Transaction and accounting records for the period required by applicable law, generally at least five years.
Email-delivery information Message type, delivery status, bounce, complaint and suppression information generated by Resend or another mail provider. We use this to deliver requested messages, protect sender reputation and stop sending where required. Generated when email is sent. Contract; legitimate interests in reliable delivery and security; consent for marketing where required. Operational delivery records are kept only as long as needed. Opt-out and suppression records may be retained longer so we do not contact you against your choice.
Support correspondence Messages, attachments and account information you provide when contacting support. We use these to answer the request, investigate faults and maintain an appropriate service record. Optional unless needed to resolve a request. Contract; legitimate interests in support, service quality and dispute management; legal obligations where applicable. Normally for up to 24 months after the matter is closed, unless a longer period is needed for legal, security or dispute reasons.
Technical, device and security data IP address, dates and times, browser or user-agent information, device and operating-system information, requested pages or functions, error records, rate-limit events and security signals generated when nTer is used. Generated automatically and necessary to operate the service safely. Legitimate interests in security, reliability, fraud prevention and fault diagnosis. nTer-controlled operational logs are normally retained for no longer than 90 days. Records connected to a security incident, legal claim or abuse investigation may be kept longer.
Privacy-rights, complaint and incident records Requests to access, correct, export, restrict or delete information, identity-verification evidence, complaint correspondence and breach-assessment records. Generated when needed. Legal obligations and legitimate interests in accountability and legal defence. For the period required by applicable law and normally up to five years after the matter closes, unless a longer period is justified.

We may keep a smaller amount of information for longer where necessary to comply with law, enforce rights, investigate a security incident, maintain an opt-out or establish, exercise or defend a legal claim. We do not retain information merely because storage is available.

4. Your use of nTer, the Whisper Journal and sensitive information

nTer is a Christian devotional service. Creating an account, subscribing, receiving an nTer Moment or using devotional features may reveal or permit an inference about religious or philosophical beliefs. What you choose to write in the Whisper Journal may reveal those beliefs and may also reveal other sensitive or special-category information, such as information about health, political opinions, racial or ethnic origin, relationships or sex life. nTer does not require you to include any of these details in the journal.

We process account and service information to provide nTer under our contract with you and, where required, on the basis of explicit consent for information revealing religious or other special-category information. We process journal content to provide the optional journal function under our contract with you and rely on the separate explicit journal consent requested during account setup where the content is sensitive. These consents are not bundled with acceptance of the Terms or with marketing consent.

You may withdraw an applicable sensitive-information consent at any time. Withdrawal does not make earlier lawful processing unlawful. If the withdrawn consent is necessary for us to provide the account, devotional service or Whisper Journal, we may need to stop the affected processing, disable the relevant feature or close the account after giving you an opportunity to export or delete journal content, subject to the technical and legal retention rules in section 8.

Journal entries are encrypted in transit and encrypted by an application-level server function before they reach the Supabase database. Supabase stores the journal body as ciphertext only. The encryption key is held in Cloudflare's secret store, separately from the database, and each entry carries a key-version tag so keys can be rotated. nTer does not routinely inspect, analyse, classify or use journal content. Journal content is not used for advertising, profiling or training artificial-intelligence models.

This is server-managed encryption, not end-to-end or zero-knowledge encryption, because nTer holds the encryption key. Decryption occurs inside the server function when an authenticated account holder requests the relevant entry. There is no ordinary administrative journal-reading function. Journal content is not written to application logs; export records contain only the channel and number of entries, not their contents.

Please avoid recording identifiable personal information about another person unless you have a proper and lawful reason to do so. The journal is not an emergency, medical, counselling or crisis-response service, and nTer does not monitor journal entries for requests for help.

5. How we disclose personal information

We do not sell personal information. We do not disclose personal information for cross-context behavioural or targeted advertising. We disclose only what is reasonably necessary in the following circumstances:

We require processors and operators to act on documented instructions, maintain confidentiality and security, assist with rights and breach obligations, and delete or return information when the relationship ends, subject to lawful retention.

6. How we protect personal information

We use technical and organisational safeguards proportionate to the sensitivity of the information and the risks presented by the service. These include:

No internet transmission, device or storage system is completely secure. If a personal-information breach occurs, we investigate and assess it under each applicable law. We notify the relevant regulator and affected people when, in the manner and within the period required by that law.

7. Where personal information is processed

nTer is operated from South Africa and uses a limited group of providers. Some providers process information outside South Africa and outside the country where a user is located. The principal providers at the date of this policy are listed below.

Provider Role and data involved Principal processing locations and role
Supabase Database and authentication. Stores account information, authentication records and encrypted journal entries. Processes technical and security logs. Primary database region: Frankfurt, Germany. Other support, security and operational processing may occur internationally. Processor/operator.
Cloudflare Website delivery, edge security, performance, limited cookieless analytics and the secret-management infrastructure used by nTer. Global edge network, including the United States and other countries where Cloudflare operates. Processor/operator for customer data; may act independently for limited service and security data under its own notice.
Resend / Plus Five Five, Inc. Sends account, service and daily-reading emails. Processes recipient address, message content and delivery, bounce, complaint and suppression information. United States and locations used by its subprocessors. Processor/operator for email customer data; independent controller for its own account and usage information.
Relevant Paddle group company Authorised reseller and Merchant of Record. Handles checkout, payment, tax, invoicing, fraud prevention, refunds and billing support. nTer receives limited transaction and subscription information. The contracting entity depends on the buyer’s location and may be in the United States, Canada or the United Kingdom. Processing may also occur in the European Union and other locations described in Paddle’s privacy information. Independent controller for payment and billing information.
Tristar Technologies CC Hosts the support@nter.life mailbox and processes sender and recipient details, message content, attachments, delivery information and mailbox administration records. South Africa. Operator/processor for hosted email services, subject to its contractual terms.

We maintain a current provider and subprocessor list on nTer’s legal page. A provider may change its infrastructure or subprocessors. We review material changes and update the list or this policy where appropriate.

For transfers from South Africa, we use a mechanism permitted by section 72 of POPIA, including contractual protections, an adequate legal framework, consent where appropriate or another permitted ground.

You may ask which safeguard applies to a particular transfer and request information about it by contacting info@mattwhiteinternational.com. We may provide a summary or a redacted copy where confidentiality or security requires it.

8. Retention, deletion and backups

We retain personal information for the shortest period reasonably needed for the purpose described in this policy, including legal, accounting, security and dispute-management requirements.

When you delete your account, deletion cascades through the live database records linked to the account, including the profile, journal, candles, consents, subscription state, export tokens and export-event records. At launch, Supabase Pro daily backups are retained for approximately seven days and point-in-time recovery is not enabled. Deleted information may remain only as encrypted residual data in those backups until the backup cycle expires. nTer maintains no separate journal exports or additional backup location. Backups are used only for disaster recovery or service continuity.

Deletion may not remove records that nTer or an independent controller must retain by law, or information necessary to maintain an unsubscribe, defend a legal claim, prevent fraud or document that a request was completed. Such information is restricted to the remaining purpose.

9. Cookies, analytics and on-device storage

At the date of this policy, nTer does not use advertising cookies or third-party behavioural tracking. The service uses only limited technologies needed to operate, secure and understand the service:

When offline journal text reaches nTer, it is encrypted and stored as described above. The app is designed to clear the temporary local copy after successful synchronisation and to clear nTer-controlled on-device account information when you sign out or delete the account. Browser, operating-system, backup or device behaviour outside nTer’s control may affect complete local erasure.

If nTer introduces a non-essential cookie, advertising technology or materially different analytics tool, we will update this policy and request consent where applicable law requires it.

10. Email and other messages

nTer sends different kinds of communications for different purposes:

nTer does not intentionally use open pixels or click tracking to create profiles of recipients. Our mail provider still processes technical delivery, bounce, complaint, abuse-prevention and suppression information needed to operate email safely and reliably.

11. Your rights and choices

Depending on the law that applies, you may have some or all of the following rights. nTer makes the core choices available to every account holder where reasonably possible:

You can carry out common actions such as changing preferences, exporting writing and deleting the account through the service where those controls are available. For any other privacy or PAIA request, email info@mattwhiteinternational.com. We use proportionate verification and do not ask for more identity information than reasonably necessary.

We respond without undue delay and within the period required by applicable law. Requests are usually free. We may charge a reasonable or prescribed fee, request clarification, extend a response period or refuse a request only where applicable law permits it, and we will explain the decision and complaint route.

Some rights are subject to exemptions. A request may also affect information concerning another person. In that case, we balance the applicable rights and may redact or withhold information where the law requires or permits it.

12. Children, automated decisions and profiling

Children

nTer is intended only for people aged 18 or older. The service is not designed for or directed to children. We check adult status at sign-up and intentionally retain only the result, not the date of birth. If we reasonably determine that an account belongs to a person under 18, we close the account and delete the associated personal information, subject to any limited record needed to document the action or comply with law.

Automated decisions and profiling

nTer does not use personal information to make solely automated decisions that produce legal or similarly significant effects. The adult-status check is a simple rule used to enforce eligibility. We do not profile journal content, infer characteristics for advertising or carry out targeted advertising.

13. Regional information

The general protections above apply to everyone. The following provisions add information required or appropriate for particular regions. Where a regional provision conflicts with the general policy, the regional provision governs for the person and processing covered by that law.

South Africa - POPIA and PAIA

Matt White International (Pty) Ltd is the responsible party. Our registered Information Officer is Matthys Johannes Kruger-Nel, Information Regulator registration number 2026-063369, at info@mattwhiteinternational.com or +27 82 869 6163. MWI's PAIA Manual and prescribed access information are made available through https://mattwhiteinternational.com, the nTer legal page where relevant, and on request.

You may request access to or correction of personal information, object to qualifying processing, request deletion or destruction where the legal requirements are met, withdraw consent and complain to the Information Regulator. Cross-border transfers are managed under section 72 of POPIA. Direct marketing is managed under POPIA and other applicable electronic-communications and consumer law.

European Economic Area and United Kingdom

nTer is not offered to, and does not knowingly accept sign-ups or Subscriptions from, people located in the European Economic Area or the United Kingdom at the point of sign-up. Access from these regions is restricted before an Account is created or any Whisper Journal content is accepted. We therefore do not ordinarily process personal information as a controller subject to the EU or UK GDPR, and we have not appointed a representative under Article 27. If we later choose to serve these regions, we will update this policy with the applicable lawful bases, rights and representative details before doing so. Where the EU or UK GDPR nevertheless applies to a particular processing activity, we comply with it.

United States

Where a United States state privacy law applies to nTer, a resident has the rights provided by that law. Depending on the state, those rights may include access, correction, deletion, portability, appeal and freedom from discriminatory treatment for exercising privacy rights. Regardless of whether a particular state law applies, nTer voluntarily provides the core account rights described in section 11 where reasonably possible.

nTer does not sell personal information, use journal content to infer characteristics for advertising, or process personal information for targeted advertising. If a future practice creates a legally defined sale, sharing or targeted-advertising activity, nTer will provide the required notice and opt-out mechanism before that practice begins.

Australia

Where the Privacy Act 1988 and Australian Privacy Principles apply to nTer, we handle personal information consistently with the APPs, including transparency, access, correction, security, complaint handling and cross-border-disclosure requirements. SoulName allows a pseudonym within the service, although an email address and adult-status confirmation remain necessary for an account.

Personal information may be disclosed to recipients in Germany, the United States, the United Kingdom and other countries used by the providers identified in section 7. We take reasonable steps appropriate to the relationship and risks to require overseas recipients to protect the information. Eligible data breaches are notified as required by the Notifiable Data Breaches scheme. You may complain to the Office of the Australian Information Commissioner after raising the concern with us.

Other countries

Additional national or regional privacy laws may apply depending on where you are located and whether nTer deliberately offers the Service there. We provide additional collection notices, consent choices, grievance details and rights processes where required. Naming a law in this policy does not limit rights you have under another law that applies to you.

14. Changes, questions and complaints

Changes to this policy

We update this policy when nTer, our providers, our processing or applicable law changes. We change the version number and effective date and retain earlier versions as required or on request. We notify you before a material change takes effect where appropriate. If a new use requires consent, we obtain that consent before the new use begins. Continued use is not treated as consent where the law requires an affirmative choice.

Questions and complaints

Contact info@mattwhiteinternational.com with a privacy or PAIA question, request or complaint. Contact support@nter.life for ordinary product support. We assess privacy concerns, gather the relevant facts and respond without undue delay. You are not required to complain to us before approaching a regulator where the law allows direct contact.

South Africa: Information Regulator, Woodmead North Office Park, 54 Maxwell Drive, Woodmead, Johannesburg; PO Box 31533, Braamfontein, Johannesburg, 2017; enquiries@inforegulator.org.za; Information Regulator eServices portal.

Australia: Office of the Australian Information Commissioner.

Elsewhere: Your applicable national or regional privacy authority.