Version: 1.0 · Effective: 14 July 2026
1. Who we are and how to contact us
«Let's pray» is a free, non-commercial cross-confessional iOS app for coordinating
shared prayer, Ukrainian-first (Ukrainian primary; Russian and English supported). Website:
pray.dbau.org. App identifier: org.dbau.letspray.
Controller: the founder of the Lets Pray project - a single natural person, the sole data controller, established in Ukraine. (There is no EU adequacy decision for Ukraine - see Section 9 on international transfers.)
2. What data we process
A plain-language list of data categories. Special categories (GDPR Art.9) are flagged separately: 🔴 religion (denomination) and 🟠 health (prayer text). Some data is special by inference (🟣) - ordinary on its own, but revealing religion or health in combination.
Account data (ordinary)
- Email - login, password reset, transactional/verification mail. May be absent if you sign in with Apple Hide My Email (relay).
- Display name - public authorship; may be a pseudonym or "Anonymous".
- First / last name - optional; only if you deliberately enable name search (OFF by default). Apple supplies the name only on first authorization.
- "Find me by name" flag - OFF by default.
- Avatar - optional profile image.
- Language and timezone - to localize the UI and reminder copy.
- 16+ age confirmation - age gate (see Section 7).
- Federated-login data (Google / Apple / email): provider id, email-at-provider; password hash (Argon2id) - only for email login, never for OAuth.
🔴 Religion (special category, Art.9)
- Denomination - optional. Empty value = "Prefer not to say". Browsing never requires declaring a faith.
🟠 Health and prayer content (special category, Art.9)
- Prayer text (body) - the main, most sensitive element. May reveal your faith and health information, and frequently concerns another person's health (e.g., a sick relative).
- Title / theme - your chosen theme; can also reveal religion or a health context.
- Beneficiary label ("who is this for") - defaults to initials / relationship ("my mother") to avoid identifying a non-consenting third party. No structured name/diagnosis/hospital fields exist by design.
- Group update text - posts members are notified about; same sensitivity.
🟣 Data that is special by inference
- Group membership - joining reveals who you pray for (and so your religion and health interest). Membership lists are never shown publicly (only an aggregate count).
- Approximate group location - an administrative unit (village → country) for browse/filter. No GPS coordinates, latitude/longitude, or IP-based geolocation are stored. If you use "near me", the app uses iOS reduced accuracy, resolves it server-side, and discards it immediately.
- Prayer / reminder timing - tied to a sensitive group, so it inherits that sensitivity.
Technical and operational data
- APNs device token + device metadata (app/OS version, timezone, locale, push-enabled) - to deliver and correctly target notifications. This is not a tracking profile. (Routine reminders are scheduled locally on your device, not via server pushes.)
- Consent records - immutable proof that you gave explicit consent for special-category processing (and any withdrawal): consent type, policy version, granted/withdrawn timestamps, and a hashed IP (not the raw address).
- Reports and moderation - your reports on content, the moderation queue, and an immutable trail of decisions. A reporter's identity is never shown to the reported user.
- Notifications (outbox) - delivery log; the text may echo sensitive prayer content.
- Audit log + IP of sensitive/admin actions - for security and accountability; IP is truncated/hashed.
3. Why we process it, and the legal basis
| What | Why | Legal basis (GDPR) |
|---|---|---|
| Email, display name, avatar, locale/tz, login data, device token | Create account, sign in, deliver notifications | Art.6(1)(b) - performance of a contract |
| First/last name and name search; denomination | Optional features you enable yourself | Art.6(1)(a) - consent |
| 16+ age confirmation | Enforce the age gate (Art.8 GDPR) | Art.6(1)(c) - legal obligation |
| 🔴 Religion + 🟠 health (denomination, prayer text & title, beneficiary, updates, membership, location, timing) | The purpose of the app - shared prayer on a chosen theme | Art.9(2)(a) - EXPLICIT CONSENT (plus Art.6(1)(a); community display Art.6(1)(f)) |
| Showing public groups to the community | Let others join prayer at your chosen visibility | Art.6(1)(f) - legitimate interest |
| Reports and moderation | Safety, abuse prevention, Apple UGC duties | Art.6(1)(f) + 6(1)(c); for sensitive content Art.9(2)(a) as a backstop |
| Consent records + audit log | Demonstrate consent (Art.7(1)), security, defense of rights | Art.6(1)(c) + 6(1)(f) |
Explicit consent for special categories (Art.9(2)(a)). We collect consent for religion and health processing not at registration, but at the first sensitive action - via a separate, un-ticked, granular toggle that is not bundled into the Terms. You can withdraw it in settings as easily as it was given (Art.7(3)).
4. Who data is shared with
We do not sell your data and do not share it for advertising or tracking. Data is stored exclusively on our own server in Ukraine (see Section 9); there is no third-party storage. To operate the service, the following recipients / processors are involved:
| Recipient | Role | Data exposed | Where / transfer |
|---|---|---|---|
| Self-hosted PostgreSQL (Ukraine) | Storage (our own infrastructure) | All data | Ukraine |
| Apple APNs | Push notification delivery | Device token + notification title/body (may echo sensitive content) | Ukraine → Apple (US/global) |
| Apple and Google | Federated-login identity providers | Provider id, email-at-provider | Ukraine ↔ Apple/Google |
5. How long we keep data (retention)
| Data | Retention period |
|---|---|
| Account data (email, names, denomination, avatar, locale, age) | Until account deletion or 24 months of inactivity (then notice → deletion) |
| Login data (provider, password hash) | Deleted with the account (Apple token revoked) |
| Prayer content (text, title, beneficiary, updates, location) | Until the creator deletes it; past one-off prayers auto-archived after 90 days |
| Group membership | Deleted with the account (removes the inference) |
| APNs token + device metadata | On logout / deletion; 60 days if unused |
| Consent records + hashed IP | Deleted with the account (only an anonymized "account deleted at T" note kept) |
| Reports | 1 year after resolution; reporter id set to NULL on account deletion |
| Moderation / decision logs | 12 months; rejected content - 30 days (reason code kept) |
| Notifications (sent/failed) | 90 days |
| Past/completed prayer occurrences | 180 days |
| Audit log | 2 years, then the partition is dropped |
| IP addresses in security logs | 30-90 days, truncated/hashed |
| Backups | 30-35 day rotation; deletions propagate to backups within that window |
6. Your rights
Under GDPR and Ukrainian data-protection law you have the right to:
- access your data; rectify inaccurate data;
- erase your data ("right to be forgotten", Art.17) - including via in-app account deletion;
- restrict processing; port your data (Art.20);
- withdraw consent at any time (Art.7(3)) - in settings, as easily as it was given; this does not affect the lawfulness of processing before withdrawal;
- lodge a complaint with a data-protection supervisory authority (in your EU country, or the Ukrainian supervisory authority).
7. Children
The app is intended for people aged 16 and over. We ask you to confirm you are 16+ and do **not
8. No tracking, no ads
We show no advertising, perform no analytics profiling, and do no cross-app or cross-site tracking. "Used for tracking" = No for every data element. The app is therefore outside the scope of Apple App Tracking Transparency (ATT).
9. International data transfers
- Storage in Ukraine. All data is stored exclusively on our own PostgreSQL server in Ukraine. There is no EU adequacy decision for Ukraine. For EU users this means a transfer of personal (including special-category) data to a country without an adequacy decision; we provide
10. How to delete your account, and the no-account takedown form
- Account deletion. The app has a built-in account-deletion feature (the Apple token is revoked). This triggers a deletion cascade per the retention periods in Section 5.
- No-account takedown (Art.17). If you believe a prayer concerns you or someone close to you
without consent, you can request removal without creating an account - via the "Report a concern"
link on the group page:
https://pray.dbau.org/g/{id}/concern. A request never auto-removes content; it raises a high-priority human review.
11. Policy changes and versioning
Each revision of this policy carries a version number. Consents are tied to immutable policy versions
(the policy_version field in consent records). We will notify you in-app of material changes.
Sources of record (not part of the user-facing text):
docs/legal/privacy-facts.md,docs/legal/data-inventory.yaml,docs/legal/records-of-processing-art30.md. Every data category, legal basis, retention period, and recipient above is grounded in those files.