A priest’s duty to keep a secret is not an encryption algorithm. That distinction is the starting point for evaluating D.O.M., a Christian social and communications platform whose most intriguing privacy concept is to combine digital security with pastoral confidentiality.
Project materials describe a social feed, user and clergy profiles, comments, reactions, reposts, chats, calls, video conferences and a dedicated workspace for clergy. They also describe independent infrastructure controlled by the project.
What they do not yet establish is a cryptographic threat model. There is no documented end-to-end encryption in the supplied materials, no clear statement that servers cannot access plaintext and no published account of how keys are generated, stored, rotated or recovered.
That matters because Signal’s privacy claim is technical and testable: the service says messages and calls are end-to-end encrypted and that Signal cannot decrypt their content. If D.O.M. wants to make confidentiality a defining feature, it needs an equally precise description of what an attacker, administrator or compelled server operator can and cannot see.
The religious layer is different. Catholic canon law makes the sacramental seal inviolable. The confessor may not reveal the penitent by any means and may not use confession-derived knowledge to the person’s detriment. Canon 1386 also recognizes the digital threat explicitly by penalizing technical recording of a sacramental confession and malicious dissemination through communications media.
Orthodox rules also impose strong secrecy. The Orthodox Church in America’s 2023 clergy guidelines state that the secrecy of the Mystery of Penance remains binding even under strong external pressure.
These norms change the incentives and obligations of the recipient, but they do not secure the network. A compromised server, malware on a device or an improperly designed backup system will not be stopped by canon law.
The reverse is also true. Encryption does not create a sacramental or professional relationship. Catholic authorities do not recognize sacramental confession by phone, email or internet. A remote conversation can provide spiritual counsel, but software cannot turn it into sacramental absolution.
Secular privilege adds another conditional layer. Wyoming law protects certain confessions made to clergy in their professional character when church rules require secrecy. German criminal and civil procedure protect, in defined circumstances, information entrusted to clergy in their pastoral role. These statutes depend on facts and jurisdiction; they are not global properties of a packet traveling over the internet.
A technically serious D.O.M. would therefore separate threat classes.
Against network interception and platform access, end-to-end encryption is the relevant control. Against behavioral profiling, metadata minimization and strict data separation matter. Against long-term exposure, short retention and secure deletion matter. Against impersonation, clergy identity verification matters. Against misuse by the recipient, church discipline and professional rules matter. Against compelled testimony, applicable evidentiary law may matter.
A proposed Pastoral Confidential mode could make those controls coherent. It would begin only when a user intentionally selects a verified clergy account for spiritual care. Pastoral content would be excluded from advertising, recommendations and model training. Server logs would be minimized. Backups would need the same encryption properties as live messages. Retention would be explicit rather than indefinite.
Even then, some metadata may be difficult to eliminate. The service may need to route messages, manage abuse, synchronize devices or notify recipients. A public privacy design should therefore distinguish content confidentiality from traffic and account metadata instead of promising that “nothing is stored.”
European users add another constraint: GDPR treats data revealing religious beliefs as special-category personal data. That raises the cost of sloppy analytics and makes purpose limitation especially important for a platform where religious identity can be inferred from basic use patterns.
The most scientifically useful way to evaluate D.O.M. is not to ask whether church secrecy is “stronger” than encryption. They address different systems. Cryptography is a technical access-control mechanism. Clergy confidentiality is a normative rule applied to a human role. Legal privilege is a procedural rule applied by a jurisdiction.
The project becomes interesting when those systems are deliberately aligned. A user could gain message confidentiality from code, reduced data exposure from architecture, recipient restraint from church rules and, in some cases, testimonial protection from law.
But the first layer must still be engineering. Before D.O.M. can make a strong privacy claim, it needs to publish the cryptographic protocol, key custody, device-linking model, metadata policy, backup design, retention schedule and administrator-access rules. Church confidentiality can then become an additional control. It cannot be the patch for an undocumented security architecture.





