Skip to main content

Persona: Karen — Privacy Paranoid

non-critical   Property: ChurchWiseAI   Category: Security Tier: anonymous Persona: karen-privacy-paranoid Touchpoint: /pricing, /security, legal pages

Preconditions

  • Visitor is concerned about data privacy and congregation surveillance
  • Worried about ChatGPT-like data harvesting
  • Will not buy without strong privacy guarantees

Steps

#ActionExpected Result
1Land on homepageNo mention of training AI on church data. Privacy commitment prominent ('Your data is yours').
2Look for privacy policyPrivacy policy link accessible in footer. Clearly states ChurchWiseAI does not train on customer data.
3Check data ownership languageTerms explicitly state: 'You own your data. We don't sell or use it for AI training.'
4Look for GDPR/compliance badgesGDPR compliant and/or SOC 2 Type II mentioned. Links to compliance documentation if available.
5Search for data encryption infoData encrypted in transit (TLS/HTTPS) and at rest (AES-256 or similar). Clearly documented.
6Check data locationWhere is data stored? On-premise, US-only, EU-friendly explicitly stated. No 'stored globally' vagueness.
7Verify no cross-border data sharingReassurance that visitor data stays in jurisdiction (US, EU, etc). Not sold to third parties.
8Check data retention policyHow long is data kept? What happens when subscription ends (exported/deleted)? Clear answer.
9Look for 'right to deletion' infoFAQ clarifies that church/visitors can request data deletion. Process documented.

Known Failure Modes

  • Privacy policy missing or vague — Karen bounces immediately
  • Data used for AI training — Karen sees this as breach of trust
  • No mention of encryption — Karen assumes unprotected
  • Data stored in multiple countries — GDPR-compliant churches concerned
  • No deletion policy — Karen worried data retained forever

References

Notes

Karen is privacy-conscious (often church data officer or compliance person). Wants: data ownership guarantee, no AI training on her data, strong encryption, clear deletion policy, GDPR compliance, no cross-border sharing. A single vague sentence about data handling loses her. Honesty and transparency required.