Praize Privacy Policy

Effective date: 2026-05-16 Controller: Joshua Katigbak, operating Praize ("Praize", "we", "us") Privacy contact: privacy@praize.faith Supervisory authority (Estonia): Andmekaitse Inspektsioon (Estonian Data Protection Inspectorate), https://www.aki.ee

1. Overview

Praize is a prayer community app where users can anchor prayers, praises, and reflections to Bible verses. If you create an account and post content, your prayers may reveal religious beliefs, which is treated as sensitive (special category) data under EU data protection law.

This policy explains what we collect, why, how long we keep it, and your rights.

2. How You Can Use Praize

2.1 Viewer Mode (no account required)

You can browse public Scripture and prayers without creating an account. In viewer mode we process only basic technical data (IP address, device info) to operate and secure the service. We do not store personal content for viewers.

2.2 Account Mode

When you create an account, you can post prayers, give and receive intercessions, join groups, participate in vigils, and use voice features. Creating an account and posting prayer content involves processing data that may reveal religious beliefs.

2.3 Guest Accounts

You may initially use Praize with a guest account for limited functionality. If you later sign up with email or a social provider, your guest activity may be migrated to your new account. Guest activity is pseudonymous, not fully anonymous, while it can still be linked to the same device or later account.

3. What We Collect

3.1 Account data

3.2 Prayer and community content

3.3 Audio and transcripts (optional)

If you use voice features:

3.4 Location (optional)

If you enable location-based prayer alerts:

3.5 Groups, vigils, and invites

3.6 Safety and security data

3.7 Error monitoring

We use Sentry for crash and error reporting. Sentry receives:

3.8 Analytics (optional)

If you consent to analytics:

3.9 Payments (optional, future)

If you use paid features or sponsorship:

4. Why We Use Your Data

PurposeWhat dataLegal basis
Provide the service (accounts, prayer posting, delivery)Account data, prayer contentContract (Art. 6(1)(b)) + Explicit consent for religious content (Art. 9(2)(a))
Voice prayers and transcriptionAudio, transcriptsContract (Art. 6(1)(b)) where needed to provide the feature + explicit consent for religious content (Art. 9(2)(a)); separate opt-in for voice
Translation for cross-language deliveryTranscripts, translationsContract (Art. 6(1)(b)) where translation is enabled for delivery + explicit consent for religious content (Art. 9(2)(a))
Location-based prayer alertsCoarse locationSeparate optional consent (Art. 6(1)(a))
AnalyticsAnonymized usage eventsConsent (Art. 6(1)(a))
Community safety and moderationContent metadata, flags, reports, transcripts (for moderation)Legitimate interest (Art. 6(1)(f)) + explicit consent for religious content where special-category content is processed (Art. 9(2)(a)) — see our LIA: Safety & Abuse Prevention
Security, fraud prevention, rate limitingIP, device info, auth eventsLegitimate interest (Art. 6(1)(f)) — see our LIA: Security Logging
Backups and disaster recoveryDatabase snapshots, including special-category content where presentLegitimate interest (Art. 6(1)(f)) + explicit consent for religious content where special-category content remains in backups (Art. 9(2)(a)) — see our LIA: Backups & DR
PaymentsTransaction referencesContract (Art. 6(1)(b))
Legal/tax obligationsPayment recordsLegal obligation (Art. 6(1)(c))

5. Religious Content (Special Category Data)

Prayer content may reveal religious beliefs. In account mode, we process this based on your explicit consent to operate the service you request.

You can withdraw consent at any time in Settings > Privacy & Data. Withdrawing consent:

Consent withdrawal is not a punishment. Viewer mode provides meaningful access to the service.

6. Automated Processing

6.1 Transcription and translation

If you use audio features, we may auto-transcribe your voice prayers. Translation is used only where enabled for cross-language delivery or otherwise selected in the product.

6.2 Privacy filter

We apply automated checks to detect high-risk personal information in posts (e.g., phone numbers, email addresses, physical addresses, identifying details about minors). If detected:

6.3 New user safety period

During the first 14 days after account creation, we may apply additional safety checks to protect the community (e.g., enhanced moderation review of audio content). You are informed about this during onboarding.

7. Third-Party Data in Prayers

Prayers naturally mention other people. Please:

If you believe someone has posted your personal information without consent, you can report the content for review.

8. Who We Share Data With

8.1 Other users

Based on your visibility settings, your content may be visible to:

8.2 Service providers (processors)

We use the following categories of service providers to operate Praize:

ProviderServiceLocationSafeguard
CloudflareAudio storage (R2), CDN, upload workersEU region for core storage; global edge network for CDN/securityDPA/SCC or equivalent contractual safeguards
OpenAIAudio transcription/translation where enabledMay process outside the EU depending on service configurationDPA/SCC or equivalent contractual safeguards
DeepgramTranscription fallback where enabledMay process outside the EU depending on service configurationDPA/SCC or equivalent contractual safeguards
AppleOAuth authenticationUSPlatform DPF/SCCs
GoogleOAuth authenticationUSPlatform DPF/SCCs
FacebookOAuth authenticationUSPlatform DPF/SCCs
SentryError monitoringUSDPA/SCC or equivalent contractual safeguards
Proton MailEmail hosting for support and privacy requestsSwitzerland / EU-region infrastructure depending on service routingAdequacy/SCC or equivalent contractual safeguards
Apple, Google, ExpoPush notification delivery where enabledMay process outside the EU depending on platform routingPlatform terms and contractual safeguards
Payment providerPayment processingNot enabled for this beta releaseNot applicable until paid features launch

We configure providers to minimize retention and require appropriate contractual protections before production use. Provider retention, region, DPA, SCC/DPF, and transfer-impact status is tracked in our vendor register.

8.3 We do not sell your data

We do not sell, rent, or trade personal data to third parties for advertising or marketing.

9. International Data Transfers

We process and store core user data (database, audio, backups) in the European Union as our baseline for all users, regardless of your location.

Some service providers (OAuth, push notifications, email, error monitoring) may process limited data outside the EU under their own infrastructure. Where Praize initiates transfers via processors, we use appropriate safeguards such as Standard Contractual Clauses (SCCs) or rely on adequacy decisions.

10. How Long We Keep Data

Data typeRetentionNotes
Account data and contentUntil you delete it or request account deletionYou control your data lifecycle
Audio filesUntil you delete them or request account deletionDeleted from storage within 24 hours of request
Deleted content in backupsUp to 30 days after deletionBackups expire automatically; deletion re-applied after any restore
Security logs7-30 days (detailed); up to 90 days (aggregated/pseudonymized)IP addresses pseudonymized after 7 days
Moderation artifacts`transcript_raw`: 24h (7d if flagged); flags: with content lifecycleRaw transcripts are ephemeral
Payment records7 yearsLegal/tax requirement; anonymized on account deletion where possible
Security audit logsUp to 1 yearUsing pseudonymized identifiers

11. Your Rights

Depending on your location, you may have rights including:

RightHow to exerciseResponse time
Access (Art. 15)Settings > Privacy & Data > Export, or email usUp to 30 days
Rectification (Art. 16)Edit your profile or content directly in the appImmediate
Erasure (Art. 17)Settings > Privacy & Data > Delete Account7-day grace period, then deletion + 30-day backup expiry
Restriction (Art. 18)Withdraw consent > revert to viewer modeImmediate
Portability (Art. 20)Data export in machine-readable format (JSON/ZIP), including audioUp to 30 days
Object (Art. 21)Analytics opt-out in Settings; email us for other objectionsImmediate for opt-outs
Withdraw consentSettings > Privacy & DataImmediate; does not affect prior lawful processing
ComplainEstonian Data Protection Inspectorate (https://www.aki.ee) or your local authorityN/A

Account deletion details

When you request account deletion: 1. 7-day grace period: You can cancel the deletion during this time 2. Day 7: Hard delete from live database; audio files deleted from storage within 24 hours 3. Day 37: Oldest backup containing your data expires (30-day backup retention)

Public content options at deletion:

> Important: "Detach" removes your account link but is pseudonymization, not true anonymization. If your prayer text includes identifying information (your name, location, etc.), it may still be identifiable. We recommend reviewing and editing content before detaching.

12. Security

We use appropriate technical and organizational measures to protect personal data, including:

13. Children

Praize is not intended for children under 16. We do not knowingly collect data from anyone under 16. If we learn a user is underage, we will delete the account and related data.

14. Cookies and Local Storage

The Praize mobile app uses:

The Praize website (praize.faith) may use:

15. Changes to This Policy

We may update this policy. If changes are material (new processing purposes, new processors, changes to your rights), we will notify you via the app or email before the changes take effect.

16. Contact

Change Log

DateChangeWhyRemaining blocker
2026-05-16Removed public draft placeholders, set the release effective date, updated controller/contact details, and replaced unresolved vendor placeholders with current beta-release posture.Makes the public policy suitable for TestFlight/App Store review links while preserving accurate external-state caveats.Final legal review and store-console App Privacy confirmation remain required before production submission.
2026-04-28Marked draft, replaced guest-account anonymity wording, added Article 6 + Article 9 pairings, corrected consent-withdrawal wording, and softened unverified processor retention/DPA claims.Aligns public policy with GDPR design and vendor register.Superseded by 2026-05-16 release update.

Related Documents (Internal)

DocumentPurpose
RoPAFull register of processing activities (Art. 30)
DPIAData Protection Impact Assessment (Art. 35)
LIA: Security LoggingLegitimate interests assessment
LIA: Backups & DRLegitimate interests assessment
LIA: Safety & Abuse PreventionLegitimate interests assessment
Back to Praize