Privacy Policy
Not legal advice. This is a starter template written so PrayApp can complete App Store, Google Play, and Google sign-in forms. Muaad Hasan Kholi (Mark Kholi) is not a lawyer. Please have a qualified person review this before you treat it as final.
This policy explains how PrayApp (“we”, “us”) handles information when you
use the iOS app (com.mkholi.prayapp, listed as “PrayApp - Together”) and the
Android app (com.prayapp.mobile). Operator: Muaad Hasan Kholi.
Contact: mkholi23@gmail.com.
1. In short
- We collect what you need to run an account, pray with people you choose, and keep the community safe.
- We do not sell your data. We do not show ads. We do not run a public prayer feed.
- Your address book is optional. Raw names, emails, and numbers from contacts stay on your phone. We only compare scrambled codes (hashes).
- You can delete your account in the app. You choose what happens to prayers you already sent.
2. Information we collect
Account and profile
- Email address and a password (stored by our auth provider as a hash, not as plain text).
- Display name, username, optional bio, optional profile photo.
- Privacy choices (for example whether friends can find you, who may send you prayers, default anonymity).
- Optional verified phone number, if you add one, used only so opted-in people can find you by that number.
- A unique account id created when you sign up.
Sign-in providers
You can create or open an account with email and password, Google, or Sign in with Apple (iOS).
- Google. We receive an ID token and basic profile information the Google account shares with the app — typically email, name, and profile photo URL. We use this only to sign you in and to fill your PrayApp profile. We do not use Google data for ads, and we do not sell it. See also Google API Services User Data Policy (Limited Use).
-
Apple. We receive an identity token. Apple may share your name the first
time you allow the app, and either your email or a Hide My Email relay address
(
@privaterelay.appleid.com). - Email confirmation (a code or link sent to your inbox) is planned. When it is on, we process confirmation and password-reset mail through our email sender.
Prayers and community content
- Prayer text and prayer requests you write.
- Blessings (short replies) and reactions such as “I prayed”.
- Who a prayer is for: a person, your friends, or a group.
- Optional Bible verse references you attach (book, chapter, verses — not a copy of the whole Bible stored as your content).
- Group names, descriptions, optional cover photos, and membership.
- Friend requests, friendships, blocks, and reports you file (reason and optional details).
Other people can see this content only according to the audience you pick and our access rules (for example a 1:1 prayer is for that friend; a group prayer is for members). Anonymous posts still hide your name from other users; we keep the real author internally so reports and safety tools can work.
Contacts (optional)
If you allow Contacts, the app reads your address book on the device to show which of your people already have PrayApp, and to help you invite others using your own Messages or Mail composer.
- We do not upload your raw contact list.
- Emails and phone numbers are normalized on the device, then turned into a one-way scrambled code (SHA-256 hash with a public app pepper). Those codes are sent for a match against people who opted in to be findable.
- Contact names stay on your device so we can label a match. They are not sent as the match payload.
- Matching is stateless: we do not store your friends’ address-book hashes after the lookup.
- Your own confirmed email (and verified phone, if you added one) is stored as a hash so someone who already has that address can find you when you allow it.
Photos
If you pick a profile photo or a group cover, we store the image file so others who can see that profile or group can load it. Photo-library access is optional and used only for that purpose.
Notifications
If you allow notifications, we store a push token for your device (via Expo) and whether the device is iOS or Android, so we can send alerts such as a new prayer or friend request. Idle tokens may be removed after a period of inactivity. You can turn notifications off in system settings.
Device and session
- Sign-in session tokens stored in the device’s secure storage so you stay signed in.
- Platform (iOS or Android) with the push token.
- We do not use third-party advertising SDKs or sell analytics about you.
3. How we use information
- Create and secure your account, including linking Google or Apple to the same email when the provider allows it.
- Show prayers, threads, groups, and profiles to the people who are allowed to see them.
- Send optional push notifications you asked for.
- Help you find friends who already use PrayApp, using the privacy settings you choose.
- Review reports, block abusive accounts, and suspend accounts that break the rules.
- Operate, debug, and improve the service (for example fixing sign-in or delivery failures).
- Comply with law and protect people from harm.
4. How we share information
We share information only as needed to run PrayApp:
| Who | Why |
|---|---|
| Supabase | Authentication, database, file storage, and (when used) edge functions for delete-account, notifications, and moderation. |
| Google Sign-In, and Android push delivery through Firebase Cloud Messaging when push is enabled. | |
| Apple | Sign in with Apple; iOS push through Apple Push Notification service when push is enabled. |
| Expo / EAS | App builds and Expo’s push pipeline that hands notifications to Apple or Google. |
| Email SMTP (planned) | Confirmation and password-reset mail (for example via a transactional provider such as Resend). We do not use this to email your friends for you. |
Invites to people who are not on PrayApp go through your phone’s SMS or mail composer. We do not send bulk email or SMS on your behalf.
Other users see what you share with them (name, photo, prayers, and so on) under your audience settings. Moderators who are allow-listed can review reports and suspend accounts.
We may disclose information if required by law, or to protect someone’s safety. If the project is transferred (for example a successor operator), this policy would still apply until you are told otherwise.
5. Google user data (Limited Use)
PrayApp’s use of information received from Google APIs adheres to the Limited Use requirements. We use Google identity data only to authenticate you and populate your account. We do not sell it, we do not use it for advertising, and we do not allow unrelated human access except as needed for security, legal compliance, or with your request (for example account support).
6. Retention
- Account, profile, and content stay until you delete the account, except as described below.
- When you delete, you choose one of three prayer options: keep prayers without your name; keep only direct 1:1 prayers (anonymized); or remove everything you wrote. Details: Delete your account.
- Your profile, photo files, friends list, group memberships, contact hashes, and push tokens are always removed on deletion.
- Reports you filed may be kept without your name, for safety records.
- Your username is reserved for about 90 days so someone else cannot immediately impersonate you.
- Idle push tokens may be pruned (about 90 days without use).
- Backups of our database, if any, expire on the host’s normal backup cycle.
7. Your choices
- Change privacy settings in Profile.
- Turn discoverability off so people cannot find you by name, username, email, or phone.
- Decline Contacts, Photos, or Notifications in the system prompt; the rest of the app still works.
- Block someone so they cannot find you or send you prayers.
- Report abuse in the app or by email (see Support).
- Delete your account in the app, or email us from the address on the account. We will verify it is you before we delete.
- Disconnect Google or Apple from the device’s account settings. That does not by itself delete your PrayApp account — use in-app deletion for that.
If a privacy law where you live gives you extra rights (access, correction, export, or objection), email mkholi23@gmail.com and we will do our best to help.
8. Children
PrayApp is not directed at children under 13. We do not knowingly collect personal information from children under 13 and we do not try to comply with COPPA for that age group. If you are under 13, do not use the app. If you believe a child under 13 created an account, email us and we will delete it. You must be at least 13 (or older if your country requires it) to use PrayApp. See also our Terms of Service.
9. International transfers
We are a small personal project. Servers and vendors (Supabase, Google, Apple, Expo, email) may process data in the United States and other countries. If you use PrayApp from another country, you understand that your information may be transferred to those locations, which may have different privacy laws than your own.
10. Security
We use HTTPS, signed-in access rules on the database, hashed contact matching instead of raw address books, and device secure storage for session tokens. No method is perfect. Please use a strong password if you sign in with email, and contact us if you think your account was misused.
11. Changes
If this policy changes in a meaningful way, we will update the date above and post the new version at this URL. Continued use after an update means you accept the new policy, except where the law requires extra notice or consent.
12. Contact
Muaad Hasan Kholi (Mark Kholi)
mkholi23@gmail.com