Skip to content

Security and privacy

Homeward holds two kinds of information about you: what you choose to publish, and what you enter for practical reasons — a passport number, a child’s date of birth, a billing address. This page explains where each kind lives, who can read it, and the settings that shrink it.

Every field on your profile carries one of three visibility classes. In the profile editor each row shows a small eye icon telling you which one applies:

  • Public field — shown on your public profile to anyone your visibility setting allows, including people who are not signed in.
  • Masked field — only the general area is shown publicly. For an address that means the city or locality; the street, postal code, and map pin stay private.
  • Private field — never shown on your public profile at all.

The eye icon reflects how the field behaves, not a setting you can change field by field. If a row says it is private, no toggle will make it public.

The broadest control is on your profile: Public, Protected, or Private. It decides who reaches your profile at all, and therefore who sees every public field on it. See Visibility, connections, and profile managers.

Two rules surprise people: your date of birth limits which options you can choose (see Children on the platform), and a profile that has ever been Public or Protected cannot be made Private again.

Card numbers never reach Homeward’s servers. When you save a card in your wallet, the card fields are hosted by our card vault, and the saved value is a secure token — not the number. When you pay without saving a card, the payment fields are hosted by our payment processor instead.

The card security code is never stored anywhere, even when the card itself is saved. You are asked for it again on each gift.

Messaging never exposes your email address or other contact details. Who can message you follows exactly who can see your profile.

Deletion and expiry are real. When a message is deleted it is destroyed, not hidden — the content and any attachments are removed from Homeward’s storage, and both sides see “This message was deleted” in its place. Messages also expire on their own schedule. See Messages.

Some of the most sensitive information on the platform is private by design and cannot be made public:

  • Travel documents, health and dietary details, and emergency contacts — held on the Personal Travel tab of your profile, and used mainly for Homeward events.
  • Date of birth, gender, and nationality.
  • Phone numbers — always private, with no toggle.
  • Residence and native-home addresses — masked: the public profile shows a general area at most. Your Mailing and Ministry addresses are public fields, so only add as much detail as you want visitors to read.

The homepage Letters edition can be personalized using the ministry areas and regions you choose in your preferences. Homeward’s own description of that feature is the promise: turning personalization off “show[s] the same edition as signed-out visitors. Homeward does not use your giving, browsing, private profile data, or connections to choose these stories.”

Personalization only reorders stories within the same public edition. It does not add stories you would not otherwise be able to read.

These controls live on the security page (Dashboard → Account → Security):

  • Password — set one even if you normally sign in with Google, Apple, Facebook, or an email code. Two-step verification requires it.
  • Passkeys — a passkey signs you in without a password and is bound to the device it was created on. Each one can be renamed or removed.
  • Two-step verification — requires a 6-digit code from an authenticator app on every sign-in, including email login codes. Save the backup codes when you enrol; each works once if you lose your authenticator, and they are not shown in full again.
  • Connected accounts — shows Google, Facebook, and Apple, when each was linked, and an Unlink button.
  • Active sessions — every signed-in device, with its IP address, last activity, and expiry. Sign out ends that session immediately.

Review the sessions list whenever a device you do not recognise appears in it. Sessions expire on their own, but revoking one is immediate — nothing waits for the expiry date shown in the table.

Homeward staff can, in a support situation, view Homeward as you. They act as the owner of your profile in read-only mode: no password is revealed and they cannot change your data. Every impersonation session shows a standing banner on the staff member’s screen, and it ends when they return to their own account.

If a field is wrong, see Fixing something that is wrong. If an endorsement about you or anyone else breaks the community rules, report it — see Endorsements. For anything else, use Support in the dashboard top bar.

Related: Your individual profile, Visibility, connections, and profile managers, Signing in.