← Home

Privacy Policy

Updated: 14 July 2026 · Українська версія →

Version: 1.0 · Effective: 14 July 2026

1. Who we are and how to contact us

«Let's pray» is a free, non-commercial cross-confessional iOS app for coordinating shared prayer, Ukrainian-first (Ukrainian primary; Russian and English supported). Website: pray.dbau.org. App identifier: org.dbau.letspray.

Controller: the founder of the Lets Pray project - a single natural person, the sole data controller, established in Ukraine. (There is no EU adequacy decision for Ukraine - see Section 9 on international transfers.)

2. What data we process

A plain-language list of data categories. Special categories (GDPR Art.9) are flagged separately: 🔴 religion (denomination) and 🟠 health (prayer text). Some data is special by inference (🟣) - ordinary on its own, but revealing religion or health in combination.

Account data (ordinary)

🔴 Religion (special category, Art.9)

🟠 Health and prayer content (special category, Art.9)

🟣 Data that is special by inference

Technical and operational data

3. Why we process it, and the legal basis

What Why Legal basis (GDPR)
Email, display name, avatar, locale/tz, login data, device token Create account, sign in, deliver notifications Art.6(1)(b) - performance of a contract
First/last name and name search; denomination Optional features you enable yourself Art.6(1)(a) - consent
16+ age confirmation Enforce the age gate (Art.8 GDPR) Art.6(1)(c) - legal obligation
🔴 Religion + 🟠 health (denomination, prayer text & title, beneficiary, updates, membership, location, timing) The purpose of the app - shared prayer on a chosen theme Art.9(2)(a) - EXPLICIT CONSENT (plus Art.6(1)(a); community display Art.6(1)(f))
Showing public groups to the community Let others join prayer at your chosen visibility Art.6(1)(f) - legitimate interest
Reports and moderation Safety, abuse prevention, Apple UGC duties Art.6(1)(f) + 6(1)(c); for sensitive content Art.9(2)(a) as a backstop
Consent records + audit log Demonstrate consent (Art.7(1)), security, defense of rights Art.6(1)(c) + 6(1)(f)

Explicit consent for special categories (Art.9(2)(a)). We collect consent for religion and health processing not at registration, but at the first sensitive action - via a separate, un-ticked, granular toggle that is not bundled into the Terms. You can withdraw it in settings as easily as it was given (Art.7(3)).

4. Who data is shared with

We do not sell your data and do not share it for advertising or tracking. Data is stored exclusively on our own server in Ukraine (see Section 9); there is no third-party storage. To operate the service, the following recipients / processors are involved:

Recipient Role Data exposed Where / transfer
Self-hosted PostgreSQL (Ukraine) Storage (our own infrastructure) All data Ukraine
Apple APNs Push notification delivery Device token + notification title/body (may echo sensitive content) Ukraine → Apple (US/global)
Apple and Google Federated-login identity providers Provider id, email-at-provider Ukraine ↔ Apple/Google

5. How long we keep data (retention)

Data Retention period
Account data (email, names, denomination, avatar, locale, age) Until account deletion or 24 months of inactivity (then notice → deletion)
Login data (provider, password hash) Deleted with the account (Apple token revoked)
Prayer content (text, title, beneficiary, updates, location) Until the creator deletes it; past one-off prayers auto-archived after 90 days
Group membership Deleted with the account (removes the inference)
APNs token + device metadata On logout / deletion; 60 days if unused
Consent records + hashed IP Deleted with the account (only an anonymized "account deleted at T" note kept)
Reports 1 year after resolution; reporter id set to NULL on account deletion
Moderation / decision logs 12 months; rejected content - 30 days (reason code kept)
Notifications (sent/failed) 90 days
Past/completed prayer occurrences 180 days
Audit log 2 years, then the partition is dropped
IP addresses in security logs 30-90 days, truncated/hashed
Backups 30-35 day rotation; deletions propagate to backups within that window

6. Your rights

Under GDPR and Ukrainian data-protection law you have the right to:

7. Children

The app is intended for people aged 16 and over. We ask you to confirm you are 16+ and do **not

8. No tracking, no ads

We show no advertising, perform no analytics profiling, and do no cross-app or cross-site tracking. "Used for tracking" = No for every data element. The app is therefore outside the scope of Apple App Tracking Transparency (ATT).

9. International data transfers

10. How to delete your account, and the no-account takedown form

11. Policy changes and versioning

Each revision of this policy carries a version number. Consents are tied to immutable policy versions (the policy_version field in consent records). We will notify you in-app of material changes.


Sources of record (not part of the user-facing text): docs/legal/privacy-facts.md, docs/legal/data-inventory.yaml, docs/legal/records-of-processing-art30.md. Every data category, legal basis, retention period, and recipient above is grounded in those files.

Data deletion request

Received.

Thank you. We read every message and answer as soon as we can.