Pray With Me

Consumer Health Data Privacy Policy

Version v1-2026-09-18 · Effective 2026-09-18

1. What "consumer health data" means here

Pray With Me composes a prayer from what you share and prays it with you. It is not a health app. It asks you nothing about your health, keeps no health record, and offers no health guidance. But prayer often names what hurts, and a person who brings a diagnosis, a treatment, grief, a struggle with a substance, or the state of their mind to prayer has shared health-related information, incidentally, in their own words. Where that happens, IRJG treats what was shared as consumer health data under one or more of the Washington My Health My Data Act ("MHMDA"), Nevada SB 370, the Connecticut Data Privacy Act ("CTDPA"), and the Maryland Online Data Privacy Act ("MODPA"), and this Policy governs it.

This Policy governs consumer health data processed through the Pray With Me service (the "Service"). The public website at trypraywithme.com collects no consumer health data: it hosts no form, sets no cookie, and loads no third-party script or tag; its only processing is the ordinary request logging of its hosting provider. If IRJG ever collects information on the website that is linked or linkable to a person's health, IRJG will voluntarily treat it as consumer health data with the protections of this Policy, and will update this section before that collection begins.

For purposes of this Policy, IRJG voluntarily applies a single broad definition of consumer health data, regardless of which state's narrower statutory definition would apply to a given user. This is a unilateral commitment to higher protection, not a description of statutory overlap. Specifically, where you share it in the conversation, in an intention, or in anything else you bring to prayer, Pray With Me treats the following as consumer health data:

Religious belief is a separate category. The tradition you choose and the fact that you bring something to prayer are religious-belief data, protected under the Privacy Policy (§§ 5, 6, 18 and 19) with their own explicit consent; they are not consumer health data and are not governed by this Policy.

A note on HIPAA and clinical confidentiality. Pray With Me is a devotional product, not a healthcare provider, and IRJG is not a HIPAA covered entity or business associate. The federal Health Insurance Portability and Accountability Act (HIPAA) therefore does not apply to anything you share with Pray With Me, and telling Pray With Me something is not the same as telling a doctor or therapist bound by HIPAA, or a member of the clergy bound by a rule of confession. This does not mean your data is unprotected: IRJG protects it under this Policy and the state consumer health data laws described here, including its commitments not to sell it, never to use it for third-party or targeted advertising, and to obtain your consent before collecting it.

2. How Pray With Me collects consumer health data

Pray With Me collects consumer health data:

Pray With Me does not infer health data from your IP address, browsing history, location, or other indirect signals. Its consumer health data comes only from what you choose to tell it. The only automated reading Pray With Me makes of what you tell it is the safety review described in § 3, which looks for expressions of a crisis, and the memory described in § 1, which carries forward what you brought in the writer's own paraphrase and records the few facts you state plainly about yourself. The facts card holds only what you state outright; Pray With Me infers nothing into it.

3. How Pray With Me uses consumer health data

Pray With Me uses your consumer health data only to:

Pray With Me does not use consumer health data:

A specific note on AI training. IRJG does not train its own AI models on your consumer health data. Pray With Me's AI service providers process your data under each vendor's applicable, operator-verified terms; whether and how each provider may use inputs for model improvement is governed by that vendor's terms, not by IRJG. § 4 of this Policy describes the per-vendor posture, including Anthropic's default-terms commitment not to train on API inputs and outputs (no opt-out required), and IRJG's affirmative opt-out election from ElevenLabs' default training use.

A specific note on MODPA's standard for sensitive data. Maryland's MODPA treats consumer health data as sensitive data and prohibits its collection or processing except where strictly necessary to provide or maintain the specific product or service the consumer has requested; consent does not authorize processing beyond that standard. Each purpose listed in § 3 is, in IRJG's assessment, strictly necessary to provide and maintain Pray With Me for you, including the bounded 90-day diagnostic-artifact purpose (coach-conversation transcripts and generation records), which exists to verify and maintain the quality and safety of the contracted service, with a window sized to the operational review cadence and to investigating a reported issue with a specific prayer after the report arrives. IRJG documents its reasoning for processing decisions involving consumer health data in its internal data-protection assessment, which the Maryland Attorney General may request during an investigation under MODPA § 14-4710.

4. How Pray With Me shares consumer health data

Pray With Me does not sell your consumer health data. Pray With Me does not share consumer health data with any third party for cross-context behavioral advertising, targeted advertising, or any other advertising purpose. Pray With Me does not use location data, geofencing, or proximity tracking; the Washington, Nevada, and Connecticut prohibitions on geofencing near health care facilities (2,000 feet under Washington law; 1,750 feet under Nevada and Connecticut law) are satisfied by absence of the practice.

A specific note on MODPA's absolute prohibition on sensitive-data sale. Maryland's MODPA prohibits the sale of sensitive personal data, which includes consumer health data, regardless of whether the consumer consents. This is stricter than the CTDPA, MHMDA, or Nevada SB 370, each of which permits sale with consent (or with separate written authorization in the case of MHMDA). Pray With Me's no-sale commitment in this section satisfies MODPA's stricter standard.

Pray With Me shares consumer health data only with the service providers listed in § 4 of the Privacy Policy, and only to the extent strictly necessary for each provider to perform the service IRJG has contracted them to provide. IRJG has no affiliates and shares consumer health data with none. Correspondence you choose to email to IRJG's contact addresses transits IRJG's email-infrastructure providers (Cloudflare for inbound routing and Google Workspace for the operator's mailbox) under the same contractual protections; see § 4 of the Privacy Policy. Each provider is bound by a written contract (a Data Processing Addendum and, where applicable, EU Standard Contractual Clauses) that requires the provider to:

The providers that may process your consumer health data, and the specific data each receives, are:

Pray With Me may also disclose consumer health data:

5. Consent, and what is not required

Under each of the four laws referenced in § 1, where applicable to Pray With Me, IRJG generally must obtain your consent before collecting, using, or sharing your consumer health data for purposes beyond what is strictly necessary to provide the Service you have requested.

You provide that consent during onboarding through a separate consent step, a distinct affirmative act, separate from your acceptance of the Terms of Service and separate from the religious-belief consent described in § 5 of the Privacy Policy, that states the categories of consumer health data collected, how they are used, who receives them, and how to withdraw, and that covers this Policy and the Privacy Policy. That consent covers:

A separate written authorization is not required, because Pray With Me does not sell your consumer health data. Under MHMDA RCW 19.373.070, a separate "valid authorization" with specific statutory elements (expiration date, identified recipient, statement of right to revoke, etc.) is required only for the sale of consumer health data. Pray With Me does not sell consumer health data, to anyone, for any consideration, so the authorization regime does not apply.

You may withdraw your consent at any time, and you may do it two ways.

In the app. Settings contains a Consent & Policies screen listing each consent you gave, with a control to turn any of them off. This is the same kind of act, through the same interface, as giving the consent in the first place. Because what you bring to prayer is the material every prayer is composed from, turning off the consumer health data consent pauses your use of Pray With Me: the conversation, new prayers, and the prayers already in your archive all become unavailable. Your data is not deleted. It is retained, and remains unavailable to you, until either you turn the consent back on (which restores your access, including to your existing prayers) or you delete your data. Deletion is offered on the same screen you are returned to, and is described in § 9 of the Privacy Policy.

By email. You may instead withdraw by emailing privacy@trypraywithme.com. When you withdraw by email, IRJG will treat the withdrawal as a request for account deletion (see § 9 of the Privacy Policy) unless you specify otherwise.

Withdrawal does not affect the lawfulness of processing conducted before withdrawal. Whichever route you use, you may request deletion of your consumer health data at any time under § 6.

If Pray With Me's practices change such that consumer health data may be sold (in jurisdictions where sale is permissible with authorization), IRJG will obtain a separate signed authorization meeting the statutory requirements of each applicable state law before any sale. In Maryland, however, the sale of sensitive personal data, including consumer health data, is prohibited under MODPA regardless of consent or authorization, and no future change to Pray With Me's practices would permit sale of Maryland residents' consumer health data.

Pray With Me is for adults only. The children's privacy rule appears in § 11 of the Privacy Policy.

6. Your rights as a Washington, Nevada, Connecticut, or Maryland resident

If you are a resident of Washington, Nevada, Connecticut, or Maryland, you have the rights described below.

A note on voluntary scope. The CTDPA and MODPA each have entity-applicability thresholds. The CTDPA's thresholds changed on July 1, 2026: the general threshold is now 35,000 Connecticut consumers, with no-threshold triggers for processing of sensitive data and for the sale of personal data; MODPA has its own separate thresholds. IRJG extends Connecticut-style and Maryland-style rights to Connecticut and Maryland residents regardless of whether any CTDPA or MODPA entity-applicability threshold is met for Pray With Me in any given year. Where this is a higher standard than required, it is a voluntary commitment, not a description of compelled compliance.

Rights available to all WA, NV, CT, and MD residents

Additional rights for Washington residents (MHMDA)

Additional rights for Connecticut residents (CTDPA)

Additional rights for Maryland residents (MODPA)

MODPA data-minimization standard. MODPA prohibits the collection or processing of sensitive personal data, including consumer health data, except where strictly necessary to provide or maintain the specific product or service you have requested. § 3 of this Policy is intended to comply with this standard. If you believe IRJG is processing more consumer health data than is reasonably necessary, you may exercise the opt-out described above and, if dissatisfied, appeal under § 8.

Note on universal opt-out signals. MODPA requires controllers to recognize universal opt-out preference signals such as Global Privacy Control. Pray With Me honors GPC where applicable law requires (see § 21 of the Privacy Policy).

7. How to exercise your rights

To exercise any right described in § 6, email privacy@trypraywithme.com from the email address tied to your Pray With Me account. If you do not have access to that email address, you may submit a written request to IRJG at the address in § 1 of the Privacy Policy.

IRJG may request one round of clarifying information to verify your identity. IRJG will respond to your verified request within 45 days (extendable by an additional 45 days where reasonably necessary, with notice).

This 45-day commitment is uniform across all four states covered by this Policy.

Where verification is not possible, IRJG may deny the request and explain why.

You may use an authorized agent to submit a request. IRJG may require proof of your authorization (a signed authorization from you naming the agent, plus identity verification of you directly).

Pray With Me does not charge a fee to process a verifiable consumer-health-data request unless the request is excessive, repetitive, or clearly unfounded. If IRJG determines a fee applies, IRJG will notify you and provide a cost estimate before completing the request.

8. Appeals

If IRJG denies your request, you have the right to appeal. The first-step appeal path is the same across all four states; the second-step regulator differs by state.

First step (all four states)

Reply to the denial email within a reasonable period to request reconsideration. Within 45 days of receipt of an appeal, IRJG will inform you in writing of any action taken or not taken, including an explanation of the reasons for the decision.

Second step: state-specific regulators

9. Retention of consumer health data

Pray With Me may retain the following data, which may be considered consumer health data, only as long as needed to provide the Service to you and to meet the obligations described below. Specifically:

When you delete your account, vendor-side deletion follows the mechanism each provider actually offers, under the contracts described in § 4. ElevenLabs' speech-generation history is erased by the automated purge described above on its rolling cycle, so your prayer text does not wait for any request at all. Where a provider's standard service tier offers no per-user deletion channel, the contracted retention limit is itself the deletion mechanism: Anthropic's standard API terms delete inputs and outputs within 30 days, and they are never used for training. That mechanism has one limit worth stating plainly rather than leaving to the vendor's terms: where content is flagged under Anthropic's usage policy the window extends to up to two years for the inputs and outputs, and up to seven years for the trust-and-safety scores derived from them. In that case deletion of your Pray With Me account does not shorten the vendor-side window, because IRJG has no per-user deletion channel on that tier. Where any other provider offers deletion of stored content on request, IRJG initiates it promptly, and in any event within the rights-request response windows in § 7. The vendor step is not part of the synchronous app-side deletion endpoint; IRJG confirms completion within the response windows in § 7.

10. Security of consumer health data

IRJG protects consumer health data with the technical and organizational safeguards described in § 12 of the Privacy Policy, including encryption in transit and at rest, need-to-know access controls, a server-logging configuration that does not write what you bring to prayer to request logs, and an error-monitoring configuration verified to scrub consumer health data from error events before transmission (§ 14 of the Privacy Policy). If IRJG determines that a breach affecting consumer health data has occurred and that it triggers a notification obligation under applicable law, IRJG will notify you as described in § 17 of the Privacy Policy.

11. AI processing and consumer health data

Pray With Me's prayers are composed by AI providers operating under each vendor's terms and applicable Data Processing Addenda (see § 4 above and § 4.1 of the Privacy Policy). Prayers and the conversation are AI-generated and not reviewed by any person before delivery; that disclosure, and what the Service is not, are stated in § 13 of the Privacy Policy and § 2 of the Terms of Service. One point bears directly on consumer health data and is named here:

IRJG does not train its own models on your consumer health data; § 3 states that commitment and § 4 records each provider's posture, including the ElevenLabs training opt-out.

Crisis resources. Pray With Me is not monitored in real time. If you are in crisis, please reach out to one of the resources below immediately.

In the United States:

Outside the United States, call your local emergency number, and see https://findahelpline.com/ for a crisis line in your country.

12. Changes to this Policy

If this Policy changes in a material way, IRJG will update the version and effective date and may require renewed consent. Non-material updates (clarifying language, formatting, additional explanation) are reflected as a version bump without renewed consent.

A change in Pray With Me's practices that would result in (a) the sale of consumer health data, (b) the sharing of consumer health data for advertising, (c) the use of consumer health data to train IRJG's own AI models, (d) the reversal of the ElevenLabs training opt-out, or (e) the introduction of any new vendor whose default terms permit broader use of consumer health data than the vendors named in § 4, would be a material change requiring renewed consent and, in the case of sale, a separate signed authorization meeting the statutory requirements of each applicable state law (subject to MODPA's absolute prohibition on the sale of Maryland residents' sensitive personal data).

13. Contact

For any question about this Policy, including to exercise a right or appeal a denial:

14. Effective date and version

Effective date: 2026-09-18 Version: v1-2026-09-18