Privacy
Dokimos exists so a man can stand approved, unashamed. That purpose sets the privacy posture: your practice room is yours. This page says plainly what is collected, where it lives, and what will never be done with it.
Last updated: 27 July 2026.
Who runs Dokimos
Dokimos is operated by Mike Boland. Questions about anything on this page go to mike.boland@me.com.
What we collect
Your account
- Your name and email address.
- If you sign up with a password, a one-way bcrypt hash of it. We never store your password itself and cannot recover it.
- If you sign in with Google, we request only
openid email profile— your email address, name, and Google account identifier. We do not request or receive access to your Gmail, Drive, Calendar, contacts, or any other Google data. - A session cookie (
pca_session) so you stay signed in. It is HTTP-only, so page scripts cannot read it. It is used for authentication only — not advertising, and not tracking you across other sites.
Your study record
This is the substance of the product, and it is generated by you as you use it:
- Every answer you record — the item, your self-grade, the confidence you committed, how long you took, and when.
- The scheduling and mastery state derived from those answers, so the app knows what to bring back and when.
- Mock exams, floor sessions, and committee sittings — including the verdicts they produce.
- Flashcard and catechism progress.
- Study plans, goals, and exam dates you set.
- Anything you write when preparing a stated difference with the Westminster Standards — the text of your exception paper, the one-sentence statement you file, and every drill answer you record against it.
Exception papers you upload
When you upload an exception paper, Dokimos reads the text out of the file and keeps the text. The file itself is never stored. It exists only for the moment it takes to extract the words from it, and is gone when the page finishes loading. There is no copy on our servers, in a storage bucket, or in a backup.
Your paper is yours. It lives on your machine, it goes to your presbytery by whatever route your presbytery already uses, and Dokimos is not in that path. The extracted text is part of your study record: you can read it, export it, and delete it, and it is covered by the visibility covenant below.
Your Anthropic API key, if you provide one
You may add your own Anthropic API key in Settings. It is encrypted at rest with AES-256-GCM before being stored, and it is used only to make the AI calls you trigger. It is never displayed back to you in full and never sent anywhere except Anthropic.
If you have not added a key, AI features may run on Dokimos’s own key instead. The same rate limits and the same payload rules below apply either way.
What we do not collect
- No advertising or third-party analytics trackers.
- No audio. Dokimos asks you to answer aloud; it does not listen.
- No payment card details. Dokimos has no billing today; if that changes, this page will name the payment processor before any card is entered.
Where it is stored
- Neon — the PostgreSQL database holding your account and study record.
- Vercel — application hosting and delivery. Vercel processes ordinary web request logs (IP address, user agent, requested path) as part of serving the site.
- Vercel Blob — private, access-controlled storage holding the papers filed with a presbytery. Filed papers are part of the court’s record; see “Keeping and deleting your data”.
- Anthropic — only when you use an AI feature, and only the content described immediately below.
What is sent to Anthropic, and when
AI features are the only thing that sends content outside Dokimos, and each runs only when you trigger it. Nothing is sent in the background. Depending on the feature, the request contains:
- The question and its model answer.
- What you did with it — your self-grade, your stated confidence, and your response time.
- The name and definition of the doctrine under examination.
- When you ask for written-answer grading, the answer you wrote — grading it is the point.
- When you ask the tutor a question, the question you typed and the study material on screen.
- In the exceptions module, the statement you filed, because pressure-testing it is the point of that feature.
Your name and email are never included in these requests. Anthropic processes these requests as our API provider under its own API terms. We have not yet confirmed the retention configuration on the Anthropic account, so this page makes no claim about retention or training on Anthropic’s side; when that is confirmed, it will be stated here.
Your answers belong to you
Everything you write and record in Dokimos — your answers, your self-grades, your drafted exceptions, and any future reflections — is yours. We claim no ownership of it. We do not sell it, rent it, or share it with advertisers or data brokers. We do not use it to train models.
The visibility covenant
Dokimos is built to be sold to presbyteries, and candidates under care will get access through them. That creates an obvious temptation, so the boundary is stated here as a commitment rather than left to a settings screen:
Your practice room is private. Individual study sessions, your self-grades, your stated confidence, the answers you got wrong while feeling sure, your floor verdicts and your committee sittings are visible to you and to nobody else. They are never shown to a committee, a chairman, or a presbytery — not as a record, not as a summary, and not as a rate or a trend.
A committee sees only what you publish. When the committee-facing features exist, what a committee can see is limited to readiness summaries you choose to publish, your assignment status, and the outcomes of exams that are meant to be assessed. Joining a presbytery does not expose anything you did before joining.
Practising a stated difference is practice. Your exception paper and the statement you file are yours, and you decide who reads them. But every drill you run against them — the questions, your confidence, your self-grades, the debrief — is practice-room data and stays on your side of the line. A man cannot rehearse defending an exception if he is being marked on how badly the rehearsal went.
This is enforced structurally, not by policy alone: the practice-room tables carry no link to any presbytery, and the committee-facing view is being built so that a query for private data cannot be written against it.
Security
- All traffic is served over HTTPS.
- Passwords are stored only as bcrypt hashes.
- Any Anthropic API key you supply is encrypted at rest.
- The session cookie is HTTP-only.
No system is perfect, and we will tell you promptly if something happens that affects your data.
Keeping and deleting your data
Your study record is kept for as long as your account exists, because the whole value of spaced repetition is the history behind it — deleting last month’s answers would damage next month’s schedule.
You can ask us to delete your account at any time, and we will delete it along with your study record, your practice sessions and reflections, your drafted exceptions, any readiness snapshot you published, and any stored API key. Write to mike.boland@me.com; deletion is done promptly and confirmed to you when it is complete.
Two things are not ours to delete, and both belong to a presbytery.
What a presbytery recorded that it did. If a presbytery has minuted an action about you — received you under care, licensed you, sustained your trials — that entry, its date, and your name stay in that presbytery’s record. Those minutes belong to the court rather than to us, and a presbytery that cannot say what it did about a man has lost something it is required to keep.
And the papers you filed with it. A thesis, an exegetical paper, a sermon, a testimonial — once you file it with a presbytery it is the paper that court examined, and it stays in that court’s record with the minutes that refer to it. A court that cannot produce what it examined has lost your papers, not only its own. This is why the app tells you so at the moment you file, rather than here.
Everything else goes. Your account, your practice room, your study history, your reflections, your drafted exceptions, your profile — none of it survives, and none of it is kept for us.
You can remove your Anthropic API key yourself at any time in Settings, which stops all AI features immediately.
Rights
Depending on where you live you may have rights to access, correct, export, or delete your personal data. Write to mike.boland@me.com and we will help.
Children
Dokimos is built for adults preparing for ordained ministry and is not directed at children. It is not intended for anyone under 18.
Changes
If this policy changes in a way that matters, we will say so here and date it. The date at the top always reflects the current version.