Pray With Me
Consumer Health Data Privacy Policy
Version v1-2026-09-18 · Effective 2026-09-18
1. What "consumer health data" means here
Pray With Me composes a prayer from what you share and prays it with you. It is not a health app. It asks you nothing about your health, keeps no health record, and offers no health guidance. But prayer often names what hurts, and a person who brings a diagnosis, a treatment, grief, a struggle with a substance, or the state of their mind to prayer has shared health-related information, incidentally, in their own words. Where that happens, IRJG treats what was shared as consumer health data under one or more of the Washington My Health My Data Act ("MHMDA"), Nevada SB 370, the Connecticut Data Privacy Act ("CTDPA"), and the Maryland Online Data Privacy Act ("MODPA"), and this Policy governs it.
This Policy governs consumer health data processed through the Pray With Me service (the "Service"). The public website at trypraywithme.com collects no consumer health data: it hosts no form, sets no cookie, and loads no third-party script or tag; its only processing is the ordinary request logging of its hosting provider. If IRJG ever collects information on the website that is linked or linkable to a person's health, IRJG will voluntarily treat it as consumer health data with the protections of this Policy, and will update this section before that collection begins.
For purposes of this Policy, IRJG voluntarily applies a single broad definition of consumer health data, regardless of which state's narrower statutory definition would apply to a given user. This is a unilateral commitment to higher protection, not a description of statutory overlap. Specifically, where you share it in the conversation, in an intention, or in anything else you bring to prayer, Pray With Me treats the following as consumer health data:
- information about your mental and emotional state (mood, stress, anxiety, grief, motivation, sleep);
- information about a physical or mental-health condition, a diagnosis, a symptom, a treatment, a medication, or a hospital stay, whether yours or that of someone you name;
- information about substance use or a pattern of behavior you are struggling with;
- information about pregnancy, fertility, or reproductive health;
- the memory, including the passage you may write about yourself, and the prayers composed from any of the above, to the extent they carry it forward; and
- account-linked records of your use of the Service, on a precautionary basis, where they are linked to content of the kinds above.
Religious belief is a separate category. The tradition you choose and the fact that you bring something to prayer are religious-belief data, protected under the Privacy Policy (§§ 5, 6, 18 and 19) with their own explicit consent; they are not consumer health data and are not governed by this Policy.
A note on HIPAA and clinical confidentiality. Pray With Me is a devotional product, not a healthcare provider, and IRJG is not a HIPAA covered entity or business associate. The federal Health Insurance Portability and Accountability Act (HIPAA) therefore does not apply to anything you share with Pray With Me, and telling Pray With Me something is not the same as telling a doctor or therapist bound by HIPAA, or a member of the clergy bound by a rule of confession. This does not mean your data is unprotected: IRJG protects it under this Policy and the state consumer health data laws described here, including its commitments not to sell it, never to use it for third-party or targeted advertising, and to obtain your consent before collecting it.
2. How Pray With Me collects consumer health data
Pray With Me collects consumer health data:
- Directly from you, and only where you choose to share it: in the conversation with the app (the app captures the transcript of the conversation, and writes into the memory, after each session that ends in a prayer, one entry holding the date, a short summary of what you brought and the intention your prayer was composed from), in the intention you set before a prayer, in the passage you may write about yourself on the memory's screen, and in any feedback you give.
- Automatically from your device in the form of usage logs, timestamps, and technical/security data linked to your account. This data is not health data in itself, but becomes consumer health data when linked to content of the kinds described in § 1.
- From third parties: none. Pray With Me does not receive consumer health data from third-party data brokers, advertising platforms, electronic health record systems, employer wellness programs, or any other third party, and reads nothing from the health features of your device.
Pray With Me does not infer health data from your IP address, browsing history, location, or other indirect signals. Its consumer health data comes only from what you choose to tell it. The only automated reading Pray With Me makes of what you tell it is the safety review described in § 3, which looks for expressions of a crisis, and the memory described in § 1, which carries forward what you brought in the writer's own paraphrase and records the few facts you state plainly about yourself. The facts card holds only what you state outright; Pray With Me infers nothing into it.
3. How Pray With Me uses consumer health data
Pray With Me uses your consumer health data only to:
- compose and speak your prayers, including by transmitting the necessary content to its AI service providers (Anthropic for language-model processing; ElevenLabs for voice synthesis), as described in §§ 4 and 4.1 of the Privacy Policy and § 4 of this Policy;
- maintain the memory, so that a later conversation and a later prayer can know what you brought before, and let you forget one session or erase all of it at once;
- support the processing purposes described in § 3 of the Privacy Policy;
- respond to your support and rights-request communications;
- document consent and maintain a legal audit trail;
- operate, secure, diagnose, and maintain the Service, including through AI-assisted operational tooling processed by Anthropic under the contractual protections described in § 4 of this Policy and § 4.1 of the Privacy Policy;
- retain and review coach-conversation transcripts and generation records (the assembled generation prompt built from your conversation, intention, summary and preferences, together with the prayer text it produced) for a bounded period (no more than 90 days; see § 9) to diagnose product issues, investigate reported safety issues with a specific prayer, evaluate and improve the quality of the conversation and the prayers composed from it, and verify that the Service's safety and personalization features behave as intended. This purpose never includes training AI models on your consumer health data (see the AI-training note below);
- screen what you type, and review each prayer before its audio is produced, for expressions of a crisis, so that Pray With Me can show crisis resources in place of its normal response when that is the right response. This automated safety screening is part of providing the Service safely; it is described in full on the published safety page, and the record it keeps for the required annual count holds no names, no account identifiers, and no message content;
- measure how the Service and its subscription flow are used, through first-party event records (for example: a prayer was composed, a subscription offer was shown or declined, a purchase was attempted or activated) that are never handed to an advertising platform, never used to advertise to you, and never contain what you brought to prayer;
- protect the Service against fraud, abuse, and security incidents;
- comply with legal obligations.
Pray With Me does not use consumer health data:
- for cross-context behavioral advertising, targeted advertising, interest-based advertising, profiling for advertising, or any advertising delivered by or through a third party, and sends no marketing message about using the Service. Pray With Me sends exactly one kind of reminder, and only to a person who has turned it on: one notification a day, at the local time that person chose, saying that it is their time to pray. The notification carries no consumer health data at all: no intention, no summary, nothing you brought to prayer, and nothing from which any of it could be inferred. Turning the reminder off under Reminder in the app's Settings stops it and removes the notification token for every device on your account;
- to train IRJG's own AI models;
- for profiling that produces legal or similarly significant effects on you;
- to make any decision about you that has employment, credit, insurance, housing, or similar real-world consequences;
- for any purpose unrelated to providing Pray With Me to you.
A specific note on AI training. IRJG does not train its own AI models on your consumer health data. Pray With Me's AI service providers process your data under each vendor's applicable, operator-verified terms; whether and how each provider may use inputs for model improvement is governed by that vendor's terms, not by IRJG. § 4 of this Policy describes the per-vendor posture, including Anthropic's default-terms commitment not to train on API inputs and outputs (no opt-out required), and IRJG's affirmative opt-out election from ElevenLabs' default training use.
A specific note on MODPA's standard for sensitive data. Maryland's MODPA treats consumer health data as sensitive data and prohibits its collection or processing except where strictly necessary to provide or maintain the specific product or service the consumer has requested; consent does not authorize processing beyond that standard. Each purpose listed in § 3 is, in IRJG's assessment, strictly necessary to provide and maintain Pray With Me for you, including the bounded 90-day diagnostic-artifact purpose (coach-conversation transcripts and generation records), which exists to verify and maintain the quality and safety of the contracted service, with a window sized to the operational review cadence and to investigating a reported issue with a specific prayer after the report arrives. IRJG documents its reasoning for processing decisions involving consumer health data in its internal data-protection assessment, which the Maryland Attorney General may request during an investigation under MODPA § 14-4710.
4. How Pray With Me shares consumer health data
Pray With Me does not sell your consumer health data. Pray With Me does not share consumer health data with any third party for cross-context behavioral advertising, targeted advertising, or any other advertising purpose. Pray With Me does not use location data, geofencing, or proximity tracking; the Washington, Nevada, and Connecticut prohibitions on geofencing near health care facilities (2,000 feet under Washington law; 1,750 feet under Nevada and Connecticut law) are satisfied by absence of the practice.
A specific note on MODPA's absolute prohibition on sensitive-data sale. Maryland's MODPA prohibits the sale of sensitive personal data, which includes consumer health data, regardless of whether the consumer consents. This is stricter than the CTDPA, MHMDA, or Nevada SB 370, each of which permits sale with consent (or with separate written authorization in the case of MHMDA). Pray With Me's no-sale commitment in this section satisfies MODPA's stricter standard.
Pray With Me shares consumer health data only with the service providers listed in § 4 of the Privacy Policy, and only to the extent strictly necessary for each provider to perform the service IRJG has contracted them to provide. IRJG has no affiliates and shares consumer health data with none. Correspondence you choose to email to IRJG's contact addresses transits IRJG's email-infrastructure providers (Cloudflare for inbound routing and Google Workspace for the operator's mailbox) under the same contractual protections; see § 4 of the Privacy Policy. Each provider is bound by a written contract (a Data Processing Addendum and, where applicable, EU Standard Contractual Clauses) that requires the provider to:
- use your data only for the purposes IRJG directs;
- not sell or further share your data;
- not use your data for advertising or marketing;
- protect your data with appropriate technical and organizational safeguards;
- delete or return your data at the end of the engagement, or on IRJG's instruction.
The providers that may process your consumer health data, and the specific data each receives, are:
- Anthropic receives the conversation, the intention, the memory, and your preferences, used to carry the conversation, compose your prayer, write the session's one entry into the memory, and review the finished prayer for safety. The memory is transmitted both to carry the conversation and to compose the prayer: the conversation and the prayer read the same memory; and, where AI-assisted tooling administers, troubleshoots, or maintains the Service, the specific stored records retrieved for that task, which can include the same categories of consumer health data Pray With Me stores on your behalf, as well as correspondence you send to IRJG's contact addresses where the tooling triages it and drafts responses. Each operational session is limited to the data reasonably necessary for the task. Under Anthropic's default API terms, Anthropic does not use API inputs or outputs to train its models, and deletes them from its systems within 30 days, except where content is flagged under Anthropic's usage policy, in which case the inputs and outputs may be retained for up to two years and the trust-and-safety scores derived from them for up to seven years. Operational sessions run under the Anthropic terms governing the operator's tooling account, which the operator verifies before use: those terms do not permit training on these inputs or outputs, and vendor-side retention follows that account's verified terms.
- ElevenLabs receives only the prayer text produced by Anthropic, not the conversation. ElevenLabs converts that text to audio in the voice you chose. The prayer text itself may contain consumer health data, because it is composed from what you brought. Under ElevenLabs' default Terms of Service, ElevenLabs would otherwise be permitted to use inputs to improve its models, including for training. IRJG has elected to opt out of ElevenLabs' training use on its account, using the "Data use" setting in the "Terms and Privacy" section of the ElevenLabs account dashboard. Once that opt-out has been processed by ElevenLabs, the prayer text Pray With Me sends to ElevenLabs is not used to improve ElevenLabs' models. ElevenLabs may retain generation history per its default policy at IRJG's tier; this history is not user-configurable. IRJG deletes ElevenLabs speech-generation history, the surface that holds prayer text, through ElevenLabs' history-deletion controls, on an automated schedule covering all accounts: at least monthly as this Policy's commitment, and daily by design. Note also that ElevenLabs reserves rights under its Terms of Service to use operational and personal data (such as account data) for its own business purposes, including service improvement and R&D, a posture distinct from training on inputs and not affected by the training opt-out.
- Supabase provides at-rest storage of your account data, the conversation transcripts, the memory, your preferences, prayer text and audio, and consent-log records. Supabase is contractually prohibited from using your data for any purpose other than providing storage and authentication services to IRJG.
- Railway hosts the Service's server. The server is configured not to write what you bring to prayer to request logs; see § 7 of the Privacy Policy.
- Vercel hosts the public website. Consumer health data is not stored at Vercel and does not pass through Vercel compute: the Pray With Me app talks directly to the server at Railway.
- Sentry receives error events only, with consumer health data scrubbed from breadcrumbs, contexts, extras, request bodies, and user context before transmission. Scrubbing is verified end-to-end before Sentry is enabled in production; see § 14 of the Privacy Policy. If at any time scrubbing cannot be verified, Sentry is disabled.
- RevenueCat is the subscription-management provider for purchases made through Apple In-App Purchase. RevenueCat does not receive the conversation, the summary, or any prayer; it processes a pseudonymous account reference (an internal Pray With Me user ID), a device identifier and routine device attributes, and App Store purchase and receipt metadata, and returns limited subscription metadata to IRJG. The transaction records involved show the fact that you purchased a Pray With Me subscription, never what you brought to prayer. Payment itself is collected by Apple when you subscribe through the App Store: Apple is not IRJG's service provider, and the payment information you provide to Apple, and the App Store transaction records Apple creates, are processed by Apple under its own terms and privacy policy, including retention obligations that continue regardless of IRJG's instructions.
- Expo operates the app-update service the app checks on launch. That check sends routine device and app metadata and, as with any server, the device's network address, never an account identifier and never anything you brought to prayer, so nothing in it reveals what you use Pray With Me for.
Pray With Me may also disclose consumer health data:
- with your specific consent, where you direct Pray With Me to share data for a particular purpose;
- as required by law, as described in § 15 of the Privacy Policy;
- in connection with a business transfer, as described in § 16 of the Privacy Policy.
5. Consent, and what is not required
Under each of the four laws referenced in § 1, where applicable to Pray With Me, IRJG generally must obtain your consent before collecting, using, or sharing your consumer health data for purposes beyond what is strictly necessary to provide the Service you have requested.
You provide that consent during onboarding through a separate consent step, a distinct affirmative act, separate from your acceptance of the Terms of Service and separate from the religious-belief consent described in § 5 of the Privacy Policy, that states the categories of consumer health data collected, how they are used, who receives them, and how to withdraw, and that covers this Policy and the Privacy Policy. That consent covers:
- collection of the categories of consumer health data described in § 1, where you choose to share them;
- use of that data for the purposes described in § 3. The consent request itself names the ways your data is affirmatively used (composing and adapting your prayers, safety screening, the bounded review of recent conversations and generation records described in § 3, and the operator's AI-assisted service operations and diagnostics) and those uses rest on this consent. The remaining § 3 purposes (measuring how the Service and its subscription flow are used, responding to communications you send, documenting consent, protecting the Service, and complying with legal obligations) are the operational and custodial incidents of providing and maintaining the Service you have requested: they rest on the strict-necessity standard described in § 3's note on MODPA, and this consent covers them as well;
- sharing with the service providers described in § 4, on the terms described in § 4.
A separate written authorization is not required, because Pray With Me does not sell your consumer health data. Under MHMDA RCW 19.373.070, a separate "valid authorization" with specific statutory elements (expiration date, identified recipient, statement of right to revoke, etc.) is required only for the sale of consumer health data. Pray With Me does not sell consumer health data, to anyone, for any consideration, so the authorization regime does not apply.
You may withdraw your consent at any time, and you may do it two ways.
In the app. Settings contains a Consent & Policies screen listing each consent you gave, with a control to turn any of them off. This is the same kind of act, through the same interface, as giving the consent in the first place. Because what you bring to prayer is the material every prayer is composed from, turning off the consumer health data consent pauses your use of Pray With Me: the conversation, new prayers, and the prayers already in your archive all become unavailable. Your data is not deleted. It is retained, and remains unavailable to you, until either you turn the consent back on (which restores your access, including to your existing prayers) or you delete your data. Deletion is offered on the same screen you are returned to, and is described in § 9 of the Privacy Policy.
By email. You may instead withdraw by emailing privacy@trypraywithme.com. When you withdraw by email, IRJG will treat the withdrawal as a request for account deletion (see § 9 of the Privacy Policy) unless you specify otherwise.
Withdrawal does not affect the lawfulness of processing conducted before withdrawal. Whichever route you use, you may request deletion of your consumer health data at any time under § 6.
If Pray With Me's practices change such that consumer health data may be sold (in jurisdictions where sale is permissible with authorization), IRJG will obtain a separate signed authorization meeting the statutory requirements of each applicable state law before any sale. In Maryland, however, the sale of sensitive personal data, including consumer health data, is prohibited under MODPA regardless of consent or authorization, and no future change to Pray With Me's practices would permit sale of Maryland residents' consumer health data.
Pray With Me is for adults only. The children's privacy rule appears in § 11 of the Privacy Policy.
6. Your rights as a Washington, Nevada, Connecticut, or Maryland resident
If you are a resident of Washington, Nevada, Connecticut, or Maryland, you have the rights described below.
A note on voluntary scope. The CTDPA and MODPA each have entity-applicability thresholds. The CTDPA's thresholds changed on July 1, 2026: the general threshold is now 35,000 Connecticut consumers, with no-threshold triggers for processing of sensitive data and for the sale of personal data; MODPA has its own separate thresholds. IRJG extends Connecticut-style and Maryland-style rights to Connecticut and Maryland residents regardless of whether any CTDPA or MODPA entity-applicability threshold is met for Pray With Me in any given year. Where this is a higher standard than required, it is a voluntary commitment, not a description of compelled compliance.
Rights available to all WA, NV, CT, and MD residents
- Right to confirm. Confirm whether IRJG is processing your consumer health data.
- Right to access. Receive a list of all third parties (including affiliates) with whom IRJG has shared your consumer health data, and an active email address or other mechanism to contact each of them. (IRJG does not sell consumer health data; see § 4.)
- Right to delete. Request that IRJG, and IRJG's affiliates, processors, and contractors, delete the consumer health data IRJG has collected about you.
- Right to withdraw consent. Withdraw the consent you provided during onboarding for Pray With Me's collection, use, or sharing of consumer health data, either in the app through Settings or by email. (See § 5: withdrawal pauses your access to Pray With Me; in-app withdrawal retains your data and is reversible, and withdrawal by email is treated as a deletion request unless you specify otherwise.)
- Right to non-discrimination. You have the right not to be discriminated against, retaliated against, or denied service for exercising any right described above. IRJG will not deny Pray With Me to you, charge you a different price, or provide you with a different level or quality of service because you exercised any consumer-health-data right.
Additional rights for Washington residents (MHMDA)
- Right to know (categories). Know the specific categories of consumer health data IRJG has collected, the categories of sources from which the data was collected, the categories of consumer health data IRJG has shared, and the categories of recipients with whom IRJG has shared consumer health data.
- List of third parties (specifics). As part of the right to access above, MHMDA RCW 19.373.040 entitles Washington residents to the literal list of every specific third party with whom IRJG has shared the resident's consumer health data, plus an active contact mechanism for each. IRJG maintains a template for this disclosure; on a verified request, IRJG will provide the list specific to that resident's data within the response timeline in § 7.
Additional rights for Connecticut residents (CTDPA)
- Right to correct inaccurate consumer health data IRJG holds about you.
- Right to portability: receive a portable copy of your consumer health data in a structured, commonly used, machine-readable format.
- Right to opt out of sale. Not applicable: Pray With Me does not sell consumer health data.
- Right to opt out of targeted advertising. Not applicable: Pray With Me does not engage in targeted advertising.
- Right to opt out of profiling in furtherance of decisions that produce legal or similarly significant effects. Not applicable: Pray With Me does not engage in profiling that produces such effects (see § 11).
Additional rights for Maryland residents (MODPA)
- Right to correct inaccurate consumer health data IRJG holds about you.
- Right to portability: receive a portable copy of your consumer health data in a structured, commonly used, machine-readable format.
- Right to opt out of the processing of sensitive personal data (including consumer health data) for purposes other than those strictly necessary to provide the Service. IRJG limits its processing of consumer health data to the purposes listed in § 3, all of which IRJG considers necessary to provide Pray With Me to you. If you exercise this right, IRJG will review its current processing for any non-essential purpose and cease that processing. To date, IRJG is not aware of any such non-essential processing of Maryland residents' consumer health data.
MODPA data-minimization standard. MODPA prohibits the collection or processing of sensitive personal data, including consumer health data, except where strictly necessary to provide or maintain the specific product or service you have requested. § 3 of this Policy is intended to comply with this standard. If you believe IRJG is processing more consumer health data than is reasonably necessary, you may exercise the opt-out described above and, if dissatisfied, appeal under § 8.
Note on universal opt-out signals. MODPA requires controllers to recognize universal opt-out preference signals such as Global Privacy Control. Pray With Me honors GPC where applicable law requires (see § 21 of the Privacy Policy).
7. How to exercise your rights
To exercise any right described in § 6, email privacy@trypraywithme.com from the email address tied to your Pray With Me account. If you do not have access to that email address, you may submit a written request to IRJG at the address in § 1 of the Privacy Policy.
IRJG may request one round of clarifying information to verify your identity. IRJG will respond to your verified request within 45 days (extendable by an additional 45 days where reasonably necessary, with notice).
This 45-day commitment is uniform across all four states covered by this Policy.
Where verification is not possible, IRJG may deny the request and explain why.
You may use an authorized agent to submit a request. IRJG may require proof of your authorization (a signed authorization from you naming the agent, plus identity verification of you directly).
Pray With Me does not charge a fee to process a verifiable consumer-health-data request unless the request is excessive, repetitive, or clearly unfounded. If IRJG determines a fee applies, IRJG will notify you and provide a cost estimate before completing the request.
8. Appeals
If IRJG denies your request, you have the right to appeal. The first-step appeal path is the same across all four states; the second-step regulator differs by state.
First step (all four states)
Reply to the denial email within a reasonable period to request reconsideration. Within 45 days of receipt of an appeal, IRJG will inform you in writing of any action taken or not taken, including an explanation of the reasons for the decision.
Second step: state-specific regulators
- Washington residents. Submit a complaint with the Washington State Attorney General at https://www.atg.wa.gov/file-complaint. Washington residents whose rights under MHMDA have been violated may also have a private right of action under the Washington Consumer Protection Act (RCW 19.86), independent of any complaint to the Attorney General.
- Nevada residents. Submit a complaint with the Nevada Attorney General at https://ag.nv.gov/Complaints/CSU_Complaints___FAQ/.
- Connecticut residents. Submit a complaint with the Connecticut Attorney General at https://portal.ct.gov/ag/common/complaint-form-landing-page (select "Consumer Data Privacy" from the subject list).
- Maryland residents. Submit a complaint with the Maryland Attorney General's Consumer Protection Division at https://portal.oag.state.md.us/cpdportal/?q=Home.
9. Retention of consumer health data
Pray With Me may retain the following data, which may be considered consumer health data, only as long as needed to provide the Service to you and to meet the obligations described below. Specifically:
- Account-linked content (your prayers, in text and audio, the intention set for each, your preferences, and the memory): retained until you request deletion or close your account. The memory additionally holds your last fifty sessions and no more: one entry is added after each session that ends in a prayer, and the fifty-first pushes the oldest one out. No later session rewrites an earlier one, and nothing expires on a timer. On the memory's screen a single session's entry can be forgotten on its own, leaving the prayer itself in place, or the sessions, the facts card and the passage you wrote about yourself can be erased together, at once; that passage can also be changed or cleared at any time; the memory as it stood at each prayer remains inside that prayer's generation record for that record's 90-day window. App-side deletion is processed synchronously through Settings; vendor-side deletion is initiated as an operational follow-up and completes within the response windows in § 7.
- Coach-conversation transcripts: retained for no more than 90 days from capture, for the bounded diagnostic, safety-verification, quality-evaluation, and improvement purposes described in § 3. Transcripts older than 90 days are permanently purged by an automated daily job that runs inside IRJG's own server; all of your transcripts are deleted immediately when you delete your account. Transcripts are never used to train AI models.
- Generation records: for each prayer, Pray With Me retains the assembled generation prompt (the instruction text built from your conversation, intention, summary and preferences to compose that prayer) together with the prayer text it produced, for no more than 90 days from capture, for the same bounded purposes described in § 3. Generation records older than 90 days are permanently purged by the same automated daily job; all of your generation records are deleted immediately when you delete your account. Generation records are never used to train AI models.
- Safety-screening records: described in § 7 of the Privacy Policy. The identifier-free ledger entry counting a notice holds no consumer health data. The short-lived markers that keep tripped text out of the memory are kept for up to 48 hours.
- Server request logs: configured not to contain what you bring to prayer; see § 7 of the Privacy Policy.
- Consent-log records: retained while your account exists and for up to 3 years after your most recent consent; de-identified when you delete your account, and otherwise under IRJG's records-retention practice at the end of that period. The directly identifying fields (user_id, session_id) are removed and a de-identified audit trail is retained (see § 7 of the Privacy Policy for exactly what remains). A consent record carries no consumer health data itself; it is listed here so the record of what Pray With Me holds is complete.
- Sign in with Apple authentication data: where you create your account with Sign in with Apple, Pray With Me holds the identifier Apple assigns to link your Apple ID to the app, the email address Apple supplies, and one token used for a single purpose: withdrawing the app's access to your Apple ID when you delete your account. This is authentication data and not consumer health data: it records that an account exists and how it is signed in to, and carries nothing you brought to prayer. It is retained for the life of your account and deleted when you delete your account, and Apple receives no consumer health data from IRJG in connection with it, at any point.
- Backups: purged on the next rotation cycle following account deletion (see § 7 of the Privacy Policy for backup-window specifics).
- Aggregated, anonymized, or de-identified data: may be retained indefinitely; cannot be used to identify you. IRJG maintains such data only in de-identified form, does not attempt to re-identify it, and contractually requires any recipient of it to commit to the same.
- ElevenLabs generation history: ElevenLabs retains its own record of each speech-synthesis request, including the prayer text that produced it, per its default policy at IRJG's tier; that retention is not user-configurable. IRJG deletes that speech-generation history, the ElevenLabs surface that holds prayer text, through ElevenLabs' history-deletion controls, on an automated schedule covering all accounts: at least monthly as this Policy's commitment, and daily by design. Your prayer text is therefore erased vendor-side on a rolling cycle, without waiting for any request.
- Vendor-side retention generally: governed by each vendor's published retention policy. See § 4 above and § 4.1 of the Privacy Policy.
When you delete your account, vendor-side deletion follows the mechanism each provider actually offers, under the contracts described in § 4. ElevenLabs' speech-generation history is erased by the automated purge described above on its rolling cycle, so your prayer text does not wait for any request at all. Where a provider's standard service tier offers no per-user deletion channel, the contracted retention limit is itself the deletion mechanism: Anthropic's standard API terms delete inputs and outputs within 30 days, and they are never used for training. That mechanism has one limit worth stating plainly rather than leaving to the vendor's terms: where content is flagged under Anthropic's usage policy the window extends to up to two years for the inputs and outputs, and up to seven years for the trust-and-safety scores derived from them. In that case deletion of your Pray With Me account does not shorten the vendor-side window, because IRJG has no per-user deletion channel on that tier. Where any other provider offers deletion of stored content on request, IRJG initiates it promptly, and in any event within the rights-request response windows in § 7. The vendor step is not part of the synchronous app-side deletion endpoint; IRJG confirms completion within the response windows in § 7.
10. Security of consumer health data
IRJG protects consumer health data with the technical and organizational safeguards described in § 12 of the Privacy Policy, including encryption in transit and at rest, need-to-know access controls, a server-logging configuration that does not write what you bring to prayer to request logs, and an error-monitoring configuration verified to scrub consumer health data from error events before transmission (§ 14 of the Privacy Policy). If IRJG determines that a breach affecting consumer health data has occurred and that it triggers a notification obligation under applicable law, IRJG will notify you as described in § 17 of the Privacy Policy.
11. AI processing and consumer health data
Pray With Me's prayers are composed by AI providers operating under each vendor's terms and applicable Data Processing Addenda (see § 4 above and § 4.1 of the Privacy Policy). Prayers and the conversation are AI-generated and not reviewed by any person before delivery; that disclosure, and what the Service is not, are stated in § 13 of the Privacy Policy and § 2 of the Terms of Service. One point bears directly on consumer health data and is named here:
- Automated screening is protective, not consequential. Pray With Me runs automated safety screening over what you type and over each prayer before delivery. This screening can show crisis resources in place of a prayer; it does not produce legal or similarly significant effects on you within the meaning of the CTDPA's or MODPA's profiling-opt-out provisions, MHMDA's processing-purpose limitations, or any equivalent standard.
IRJG does not train its own models on your consumer health data; § 3 states that commitment and § 4 records each provider's posture, including the ElevenLabs training opt-out.
Crisis resources. Pray With Me is not monitored in real time. If you are in crisis, please reach out to one of the resources below immediately.
In the United States:
- Call or text 988 for the Suicide & Crisis Lifeline
- Text HOME to 741741 to reach the Crisis Text Line
- Call 911 if you or someone else is in immediate danger
Outside the United States, call your local emergency number, and see https://findahelpline.com/ for a crisis line in your country.
12. Changes to this Policy
If this Policy changes in a material way, IRJG will update the version and effective date and may require renewed consent. Non-material updates (clarifying language, formatting, additional explanation) are reflected as a version bump without renewed consent.
A change in Pray With Me's practices that would result in (a) the sale of consumer health data, (b) the sharing of consumer health data for advertising, (c) the use of consumer health data to train IRJG's own AI models, (d) the reversal of the ElevenLabs training opt-out, or (e) the introduction of any new vendor whose default terms permit broader use of consumer health data than the vendors named in § 4, would be a material change requiring renewed consent and, in the case of sale, a separate signed authorization meeting the statutory requirements of each applicable state law (subject to MODPA's absolute prohibition on the sale of Maryland residents' sensitive personal data).
13. Contact
For any question about this Policy, including to exercise a right or appeal a denial:
- Email: privacy@trypraywithme.com
- Mail: IRJG Ventures, Inc., 13809 Research Boulevard, Suite 500, Austin, TX 78750
14. Effective date and version
Effective date: 2026-09-18 Version: v1-2026-09-18