PrayApp

Privacy Policy

Effective date: September 15, 2026 · Last updated: September 15, 2026

Not legal advice. This is a starter template written so PrayApp can complete App Store, Google Play, and Google sign-in forms. Muaad Hasan Kholi (Mark Kholi) is not a lawyer. Please have a qualified person review this before you treat it as final.

This policy explains how PrayApp (“we”, “us”) handles information when you use the iOS app (com.mkholi.prayapp, listed as “PrayApp - Together”) and the Android app (com.prayapp.mobile). Operator: Muaad Hasan Kholi. Contact: mkholi23@gmail.com.

1. In short

2. Information we collect

Account and profile

Sign-in providers

You can create or open an account with email and password, Google, or Sign in with Apple (iOS).

Prayers and community content

Other people can see this content only according to the audience you pick and our access rules (for example a 1:1 prayer is for that friend; a group prayer is for members). Anonymous posts still hide your name from other users; we keep the real author internally so reports and safety tools can work.

Contacts (optional)

If you allow Contacts, the app reads your address book on the device to show which of your people already have PrayApp, and to help you invite others using your own Messages or Mail composer.

Photos

If you pick a profile photo or a group cover, we store the image file so others who can see that profile or group can load it. Photo-library access is optional and used only for that purpose.

Notifications

If you allow notifications, we store a push token for your device (via Expo) and whether the device is iOS or Android, so we can send alerts such as a new prayer or friend request. Idle tokens may be removed after a period of inactivity. You can turn notifications off in system settings.

Device and session

3. How we use information

4. How we share information

We share information only as needed to run PrayApp:

Who Why
Supabase Authentication, database, file storage, and (when used) edge functions for delete-account, notifications, and moderation.
Google Google Sign-In, and Android push delivery through Firebase Cloud Messaging when push is enabled.
Apple Sign in with Apple; iOS push through Apple Push Notification service when push is enabled.
Expo / EAS App builds and Expo’s push pipeline that hands notifications to Apple or Google.
Email SMTP (planned) Confirmation and password-reset mail (for example via a transactional provider such as Resend). We do not use this to email your friends for you.

Invites to people who are not on PrayApp go through your phone’s SMS or mail composer. We do not send bulk email or SMS on your behalf.

Other users see what you share with them (name, photo, prayers, and so on) under your audience settings. Moderators who are allow-listed can review reports and suspend accounts.

We may disclose information if required by law, or to protect someone’s safety. If the project is transferred (for example a successor operator), this policy would still apply until you are told otherwise.

5. Google user data (Limited Use)

PrayApp’s use of information received from Google APIs adheres to the Limited Use requirements. We use Google identity data only to authenticate you and populate your account. We do not sell it, we do not use it for advertising, and we do not allow unrelated human access except as needed for security, legal compliance, or with your request (for example account support).

6. Retention

7. Your choices

If a privacy law where you live gives you extra rights (access, correction, export, or objection), email mkholi23@gmail.com and we will do our best to help.

8. Children

PrayApp is not directed at children under 13. We do not knowingly collect personal information from children under 13 and we do not try to comply with COPPA for that age group. If you are under 13, do not use the app. If you believe a child under 13 created an account, email us and we will delete it. You must be at least 13 (or older if your country requires it) to use PrayApp. See also our Terms of Service.

9. International transfers

We are a small personal project. Servers and vendors (Supabase, Google, Apple, Expo, email) may process data in the United States and other countries. If you use PrayApp from another country, you understand that your information may be transferred to those locations, which may have different privacy laws than your own.

10. Security

We use HTTPS, signed-in access rules on the database, hashed contact matching instead of raw address books, and device secure storage for session tokens. No method is perfect. Please use a strong password if you sign in with email, and contact us if you think your account was misused.

11. Changes

If this policy changes in a meaningful way, we will update the date above and post the new version at this URL. Continued use after an update means you accept the new policy, except where the law requires extra notice or consent.

12. Contact

Muaad Hasan Kholi (Mark Kholi)
mkholi23@gmail.com