Pray With Me

Privacy Policy

Version v1-2026-09-18 · Effective 2026-09-18

Your data, explicitly

Your data is yours. Pray With Me never sells it, never shares it for cross-context behavioral advertising, and never uses what you bring to prayer, your memory, or your tradition for any advertising purpose. Pray With Me uses what you share only to operate the product, compose and speak your prayers, keep the memory that lets a later conversation and a later prayer know what you brought before, measure how the product and its subscription flow are used (first-party records IRJG creates itself, never handed to an advertising platform, and never used to advertise to you), document consent, protect the service, and honor your choices.

What you bring to prayer says something about what you believe, and often about what you are carrying. Pray With Me treats your religious belief, including the tradition you choose, as sensitive data that is processed only with your explicit consent, and treats anything health-related you share, whether about your body, your mind, or someone you love, as consumer health data with the protections of the separate Consumer Health Data Privacy Policy.

Pray With Me does not sell your data. Pray With Me does not share what you tell it, or any record about you, with an advertising or marketing platform. Pray With Me does not use your conversations, your intentions, or the prayers composed for you to train its own models, and its AI service providers process your data only under each vendor's applicable, operator-verified terms; see § 4.1 for vendor-specific detail.

Pray With Me is not a healthcare provider and is not covered by HIPAA, so the health-related information you share is not governed by HIPAA. Pray With Me protects it instead under this Policy and the Consumer Health Data Privacy Policy, including the commitments never to sell it and never to use it for third-party or targeted advertising.

You can delete your account and associated data from Settings. Deletion is permanent and runs synchronously: when you confirm deletion, IRJG deletes account-linked data, your prayers and their audio, your memory, your conversation transcripts, the records described in § 9, and de-identifies consent-log records by removing the fields that directly identify you (see § 9 and § 7 for exactly what the audit trail retains).

1. Provider / controller identification

This Privacy Policy applies to Pray With Me, provided by IRJG Ventures, Inc. ("IRJG"), a Delaware corporation formed 2026-04-24. IRJG is the data controller for personal data processed through Pray With Me.

Mailing address: 13809 Research Boulevard, Suite 500, Austin, TX 78750 Privacy contact: privacy@trypraywithme.com EU and UK representative: see § 6.

2. Categories of personal data Pray With Me collects

Pray With Me collects:

Pray With Me collects no location data, no contacts, no photos, no microphone audio, and no health data from your device or from any other app.

3. Purposes of processing

Pray With Me uses the data described above to:

Pray With Me does not use the data described in this section for cross-context behavioral advertising, profiling for targeted advertising, or training its own AI models. Pray With Me sends exactly one kind of reminder about using the Service, and only to a person who has turned it on: one notification a day, at the local time that person chose, saying that it is their time to pray. It is off unless you turn it on, you are offered it once and only once, you can turn it off at any time under Reminder in the app's Settings, and turning it off removes the notification token for every device on your account. The notification carries none of what you have brought to prayer: no intention, no summary, no tradition, and no scripture. Apart from that reminder, Pray With Me sends no re-engagement or marketing messages about using the Service; the only subscription notices it sends are the two described in § 4: a courtesy notice before a free trial converts, and the yearly reminder the law requires for an annual subscription.

4. Service providers and vendors

IRJG uses the following providers to operate Pray With Me. IRJG shares with each only the data necessary for the specific service they perform, under written contracts (DPAs and, where applicable, EU Standard Contractual Clauses) that require them to protect your data and use it only for the purposes IRJG directs.

Vendor Role Data shared
Anthropic AI language-model processing for the conversation, the composing of each prayer, the memory, and the pre-delivery safety review of each prayer; AI-assisted service operations, diagnostics, and maintenance (§ 4.1) The conversation, the intention, the memory, your tradition and length preferences, and the scripture passages retrieved for the prayer; the finished prayer text for the safety review; for operations and diagnostics, the specific stored records retrieved while investigating or maintaining the service, and correspondence sent to IRJG's contact addresses where AI-assisted triage and drafting is used
ElevenLabs Voice synthesis for the spoken prayer, in the voice you chose (Theo or Anna) The prayer text and related metadata
Supabase Authentication, database, storage; authentication-related email (sign-in links, password resets, email verification, and account-security notices such as confirmation that your password was changed) is composed by Supabase Auth and delivered through the Resend relay below Account data, what you bring to prayer, the memory, your preferences, prayer text and audio, consent-log records; recipient email address for authentication messages
Resend Transactional email delivery of authentication messages via Supabase Auth's custom SMTP relay Recipient email address, and the authentication link or token where the message carries one
Railway Server hosting Server hosting logs and deploy metadata; see § 7 for log content
Vercel Hosting of the public website, which serves this Policy, the ambient sound files the app streams, and the page that completes a sign-in link Ordinary web-server request logs (network address, path, timestamp); no analytics
RevenueCat Subscription management for purchases made through Apple In-App Purchase: links the App Store transaction to your Pray With Me account, tracks subscription and trial state, and notifies IRJG of subscription events (purchase, trial start, renewal, cancellation, refund, billing issue) A pseudonymous account reference (an internal Pray With Me user ID), a device identifier and routine device attributes (such as device model and operating-system version), and App Store purchase and receipt metadata; IRJG receives back only the limited subscription metadata described in § 2
Expo Two services. First, the app-update service the Pray With Me app checks on launch to learn whether a newer app bundle should be delivered. Second, where you have turned the daily reminder on, delivery of that notification: Pray With Me hands Expo the notification and Expo passes it to Apple's push service, which delivers it to your device. The Apple signing key this requires is held by Expo and never by IRJG's servers For app updates, routine device and app metadata and, as with any server, the device's network address; no account identifier and no conversation, intention, summary, or prayer content. For the reminder, your device's notification token and the text of the notification, which is the app's name and one short line saying it is your time to pray, and nothing else
Sentry Error monitoring with verified user-input scrubbing (§ 14) Error events at error and fatal level only, with conversation, intention, summary, and prayer text scrubbed before transmission
Cloudflare Inbound email routing for IRJG's contact addresses (privacy@ and contact@) Transit of inbound email you choose to send to IRJG, and its routing metadata; no message body retained beyond delivery
Google (Workspace) Operator email infrastructure: the mailbox where correspondence sent to IRJG's contact addresses is received and handled The content of correspondence you choose to send to IRJG's contact addresses, which may include information you decide to include about yourself
Prighter IRJG's EU and UK privacy representative (Article 27; see § 6): receives and forwards data-subject correspondence for EU/UK rights requests The content of rights-request correspondence you submit through the Prighter portal, and the contact details you provide with it

Apple is not listed in the table above because Apple is not IRJG's service provider: when you subscribe through the App Store, Apple collects and processes your payment directly, as an independent company acting under its own terms and privacy policy, as described in § 2. The App Store transaction records Apple creates include the fact that you purchased a Pray With Me subscription, and never anything you brought to prayer.

The same is true of Sign in with Apple. Where you use it, Apple verifies your identity as an independent company under its own terms and privacy policy, and tells Pray With Me only the identifier and email address described in § 2. IRJG sends Apple nothing about your conversations, your summary, or your prayers. IRJG sends Apple only two messages about your account, each of which returns a credential Apple itself issued: at sign-in, IRJG's server exchanges the one-time code Apple has just created for the revocation token described in § 2, and at deletion, the request to withdraw the app's access to your Apple ID (§ 9).

Authentication-related email is composed by Supabase Auth and delivered through Resend; purchase receipts and subscription notices for App Store purchases are sent by Apple, not by IRJG; material-policy-change notices are operational, not marketing. Pray With Me sends no reminder or re-engagement email about using the Service and uses no marketing-email vendor; two subscription notices are transactional and are sent through the same provider as sign-in email: a courtesy notice before a free trial converts to a paid subscription, which IRJG sends whether or not the law requires one, and the yearly reminder of the terms of an annual subscription, which the law requires. The optional product-update choice in Settings under Consent & Policies records whether you want occasional product-update messages, a category IRJG does not currently send; if IRJG adds a vendor to send them, that vendor will be added to this section first, and the change will be treated as a material privacy-notice change requiring re-consent.

4.1 AI service providers: what they may and may not do with your data

The AI service providers IRJG uses (Anthropic and ElevenLabs) are bound by their published commercial terms and, where applicable, executed Data Processing Addenda. IRJG does not authorize either provider to use your data for any purpose other than providing the service IRJG has contracted them to provide. Vendor-side retention and processing beyond what IRJG instructs follow each vendor's own published default terms.

Anthropic processes the conversation, the intention, the memory, your preferences, and the retrieved scripture to compose each prayer; it processes the conversation turn by turn together with the memory to carry the conversation, so that the conversation recognises what you bring today against what you have brought before; it processes the session just made to write its one entry into the memory; and it reads what you wrote together with the finished prayer for the safety review described in § 13. Under Anthropic's default API terms, Anthropic does not use API inputs or outputs to train its models. Anthropic deletes inputs and outputs from its systems within 30 days. That window extends where content is flagged under Anthropic's usage policy: flagged inputs and outputs may be retained for up to two years, and the trust-and-safety scores derived from them for up to seven years. Anthropic's standard API tier offers no separate per-user deletion channel, so that contracted retention limit is itself the deletion mechanism: on account deletion, any user-associated data still within the window ages out and is purged by Anthropic no later than the end of it.

IRJG also uses Anthropic's AI systems as an operational tool when administering, diagnosing, and maintaining the service. In that use, Anthropic may process the specific records retrieved during an operational session, which can include the same categories of data Pray With Me stores on your behalf. This processing occurs under the Anthropic terms governing the operator's tooling account, which the operator verifies before use: those terms do not permit Anthropic to use these inputs or outputs to train its models, and vendor-side retention follows the verified terms of that account, which IRJG records in its vendor-contract register and re-verifies at each material update of this Policy. IRJG limits each operational session to the data reasonably necessary for the task at hand, and does not authorize Anthropic to use this data for any purpose other than providing the operational service to IRJG. The same operational use extends to correspondence you send to IRJG's contact addresses (for example, rights requests and support email): the operator may use the tooling to read, triage, and draft responses to that correspondence.

ElevenLabs processes the prayer text to produce the spoken prayer. ElevenLabs' processing is governed by ElevenLabs' default terms and DPA at IRJG's tier. IRJG has opted out of ElevenLabs' training use on its account, so the prayer text sent to ElevenLabs is not used to improve ElevenLabs' models. ElevenLabs' history-retention behavior is tier-dependent; on IRJG's tier, generation history is retained per ElevenLabs' default retention policy, and IRJG deletes the speech-generation history, the surface that holds the prayer text, through ElevenLabs' history-deletion controls, on an automated schedule covering all accounts: at least monthly as this Policy's commitment, and daily by design.

If a vendor's default terms change in a way that materially affects how your data is used, IRJG will treat that as a material change to this Privacy Policy and require renewed consent where appropriate.

5. Sensitive data: religious belief and consumer health data

Religious belief. Choosing a tradition, and bringing something to prayer, discloses religious belief. IRJG processes that data only with your explicit consent, given during onboarding through a consent step that is separate from your acceptance of the Terms of Service and separate from the health-data consent below, and that states what is collected, how it is used, who receives it, and how to withdraw. Withdrawing that consent in Settings clears the stored tradition preference and pauses the service until you consent again; if the clearing of the preference fails for a technical reason, the withdrawal still stands and IRJG completes the clearing by hand once it becomes aware; deleting your account deletes it. IRJG does not sell religious-belief data, does not share it for advertising, and does not use it to infer anything about you beyond the form of the prayer you asked for.

Consumer health data. A separate Consumer Health Data Privacy Policy provides the detail required under Washington, Nevada, Connecticut, and Maryland law. Pray With Me is not a health app and asks you nothing about your health; the health-related information it may hold is what you choose to bring to prayer. For Washington residents specifically: IRJG collects and processes information that may qualify as "consumer health data" under the Washington My Health My Data Act ("MHMDA") where you share it, including information about your mental and emotional state, a health condition, or a struggle with a substance. During onboarding, you provide consent under MHMDA through a separate consent step, a distinct affirmative act, separate from your acceptance of the Terms of Service, that states the categories of consumer health data collected, how they are used, who receives them, and how to withdraw. That consent covers IRJG's collection, use, processing, and sharing of your consumer health data as described in this Privacy Policy, including sharing with its AI service providers (Anthropic and ElevenLabs) to compose and speak your prayers and, in Anthropic's case, to support the secure operation, diagnosis, and maintenance of the service as described in § 4.1.

You have the right to withdraw either consent at any time, either in the app or by email. In the app, Settings contains a Consent & Policies screen listing each consent you gave, with a control to turn any of them off; withdrawing there pauses your access to Pray With Me, retains your data rather than deleting it, and is reversible by turning the consent back on. By email, write to privacy@trypraywithme.com; a withdrawal sent by email is treated as a request for account deletion unless you specify otherwise. Either route is available to you at any time, and § 5 of the Consumer Health Data Privacy Policy describes both in full. Withdrawal does not affect processing that occurred before withdrawal. You also have the right to request access to, correction of, and deletion of your consumer health data. IRJG does not sell your consumer health data and does not share consumer health data for cross-context behavioral advertising or targeted advertising.

If IRJG denies a rights request, you may appeal by replying to the denial email; if your appeal is denied, you may contact the Washington Attorney General at https://www.atg.wa.gov/file-complaint.

6. European Users (GDPR, UK GDPR, Swiss FADP)

For Users in the European Economic Area, United Kingdom, and Switzerland. If you are located in the EEA, UK, or Switzerland, IRJG processes your personal data in accordance with the EU General Data Protection Regulation (GDPR), the UK GDPR, and the Swiss Federal Act on Data Protection.

Legal basis. IRJG processes your data on the following legal bases:

Purpose Legal basis
Creating and operating your account; providing the Pray With Me service Performance of a contract (GDPR Art. 6(1)(b))
Composing and speaking your prayers, and carrying the conversation, from what you bring, your tradition, and the memory Performance of a contract (Art. 6(1)(b)); for religious-belief data and any health data, your explicit consent (Art. 9(2)(a))
Processing religious-belief data (the tradition preference; what you bring to prayer) Your explicit consent (Art. 9(2)(a))
Processing health-related data you choose to bring to prayer Your explicit consent (Art. 9(2)(a))
Screening what you type, and reviewing each prayer before delivery, for expressions of a crisis (§ 13) Legitimate interest (Art. 6(1)(f)): protecting your safety where the service would otherwise respond automatically; for special-category data, the same explicit consent
Managing subscriptions purchased through the Apple App Store (via RevenueCat) Performance of a contract (Art. 6(1)(b))
Responding to support and rights requests Performance of a contract (Art. 6(1)(b)); compliance with a legal obligation (Art. 6(1)(c))
Protecting Pray With Me against fraud, abuse, and security incidents, including daily use metering Legitimate interest (Art. 6(1)(f))
Measuring how Pray With Me and its subscription flow are used, and which channels people find it through Legitimate interest (Art. 6(1)(f))
Measuring whether IRJG's own App Store ads led to installs, through Apple's identifier-free framework (§ 14), if IRJG advertises Legitimate interest (Art. 6(1)(f))
Operating, diagnosing, and maintaining the service, including through AI-assisted operational tooling (§ 4.1) Performance of a contract (Art. 6(1)(b)); for special-category data, your explicit consent (Art. 9(2)(a))
Service-related communications (account, security, material policy changes) Performance of a contract (Art. 6(1)(b))
Complying with legal obligations Compliance with a legal obligation (Art. 6(1)(c))

Your rights. You have the right to access, correct, delete, restrict processing of, and receive a portable copy of your personal data. You have the right to withdraw consent at any time, without affecting the lawfulness of processing conducted before withdrawal; withdrawal is available in the app through Settings, by the same kind of act and through the same interface you used to give the consent, and also by email (§ 5 of the Consumer Health Data Privacy Policy). Where you withdraw consent in the app, your data is retained rather than erased so that you can restore your access by consenting again; you may request erasure at any time, on the same screen or through the rights-request workflow described below. You have the right to lodge a complaint with your local supervisory authority (EU users: see https://www.edpb.europa.eu/about-edpb/our-members_en; UK users: https://ico.org.uk/; Swiss users: https://www.edoeb.admin.ch/). Bringing something to prayer is necessary for the contract: without it, Pray With Me can compose only from the memory, and with neither it has nothing to compose from.

Right to object. You have the right to object, on grounds relating to your particular situation, to any processing Pray With Me bases on legitimate interest (Art. 21).

Automated decision-making. Pray With Me runs automated safety screening over what you type and over each prayer before its audio is produced, which can decline to compose or deliver a prayer and display crisis resources instead; this screening is protective and informational, and it does not deny you the service overall. The screening produces no legal or similarly significant effects on you within the meaning of GDPR Article 22.

International transfers. IRJG operates from the United States. When your personal data is transferred from the EEA, UK, or Switzerland to the US, it is processed by IRJG and its service providers under the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum, or equivalent transfer mechanisms, supplemented as required by the Schrems II decision. You can obtain a copy of the relevant safeguards (with commercial terms redacted where necessary) by emailing privacy@trypraywithme.com.

Data controller. The data controller for your personal data is IRJG Ventures, Inc., reachable at privacy@trypraywithme.com.

EU and UK representative (Art. 27 GDPR / Art. 27 UK GDPR). IRJG has appointed Prighter Group with its local partners as IRJG's privacy representative and your point of contact for the European Union (EU) and the United Kingdom (UK). Prighter gives you an easy way to exercise your privacy-related rights (for example, requests to access or erase personal data). To contact IRJG via IRJG's representative or to make use of your data subject rights, please visit https://app.prighter.com/portal/14001499687.

Switzerland (FADP Art. 14). IRJG has not appointed a Swiss representative under Article 14 of the Swiss Federal Act on Data Protection because IRJG's processing of Swiss-resident data does not currently meet that article's cumulative criteria; specifically, the processing is not "on a large scale" and "carried out regularly" within the meaning of FADP Art. 14(1)(b) and (c). Swiss residents may exercise their FADP rights directly by emailing privacy@trypraywithme.com; IRJG honors the same response windows and rights described in this section. IRJG monitors Swiss-resident usage on a recurring basis under an internal monitoring tripwire and will appoint a Swiss representative if and when those criteria are met.

Exercising your rights. Email privacy@trypraywithme.com. IRJG will respond within 30 days, extendable by an additional 60 days where reasonably necessary, with notice to you.

7. Retention and server logging

Account-linked content. Your prayers (text and audio), the intention set for each, your preferences, and the name you gave the app are retained until you request deletion. Self-serve deletion through Settings is processed synchronously for app-side data: when you confirm deletion, IRJG deletes the data described in § 9 within the request itself. Vendor-side data follows each provider's deletion mechanism described in §§ 4.1 and 9, an automated purge for ElevenLabs speech-generation history and the contracted retention limit for Anthropic, and is gone within the rights-request response windows in § 20, in accordance with the contracts described in § 4, except, for Anthropic, content flagged under Anthropic's usage policy, which follows the extended windows described in § 4.1.

The memory. One entry is added after each session that ends in a prayer, and the memory holds your last fifty sessions: the fifty-first pushes the oldest one out. No later session rewrites an earlier one, and nothing expires on a timer. On the memory's screen you can forget a single session, which removes that session's entry and leaves the prayer itself in your past prayers, or forget everything at once, which erases the sessions, the facts card and the passage you wrote about yourself together. The passage stays until you change or clear it, forget the memory, or delete your account, and all of the memory is deleted with your account. Forgetting, or changing or clearing the passage, does not reach into your past prayers: each prayer's generation record (described below) keeps the memory as it stood when that prayer was composed, for that record's own 90-day window and no longer.

Coach-conversation transcripts. Pray With Me retains the raw transcript of your conversation for no more than 90 days from capture, for the bounded quality, diagnostic, and safety-verification purposes described in § 3 of the Consumer Health Data Privacy Policy. Transcripts older than 90 days are purged by an automated daily job that runs inside IRJG's own server, and all of your transcripts are deleted immediately when you delete your account (§ 9). Transcripts are never used to train AI models.

Generation records. For each prayer, Pray With Me retains the assembled generation prompt (the instruction text built from your conversation, intention, memory, preferences, and retrieved scripture to compose that prayer) together with the prayer text it produced, for no more than 90 days from capture, for the same bounded purposes described in § 3 of the Consumer Health Data Privacy Policy. Generation records older than 90 days are purged by the same automated daily job, and all of your generation records are deleted immediately when you delete your account (§ 9). Generation records are never used to train AI models.

Browser privacy signals. The record of a Global Privacy Control or Do Not Track signal Pray With Me received on your behalf (§ 21) is retained until you delete your account, at which point it is deleted with the rest of your account data.

Sign in with Apple. Where you created your account with Sign in with Apple, the Apple identifier and the revocation token described in § 2 are retained for the life of your account and deleted when you delete it, as described in § 9. The token is stored so that only IRJG's server can read it, is never included in anything the app displays or returns to you, and is never written to IRJG's logs. It cannot be used to read anything from your Apple ID; its only function is to withdraw the app's own access.

Consent log. Consent-log records are retained while your account exists and for up to 3 years after your most recent consent; they are de-identified when you delete your account, and any record not de-identified that way is de-identified under IRJG's records-retention practice at the end of that period: the user_id and session_id (the fields that directly identify you) are removed, and the remaining audit fields are retained for compliance audit purposes: the timestamp, the document version, the consent event type (which checkbox was presented and whether it was accepted), a request identifier, and a one-way hashed form of the IP address recorded at the time of consent. The hash is computed with a secret key held only on IRJG's servers, so the stored value cannot be turned back into your address by anyone who obtains the record without also holding that key. It is retained as part of the tamper-evident record that a given consent event occurred.

Server request logging. IRJG's server is configured not to write the conversation, the intention, the summary, or prayer text to request logs. Server logs contain only operational metadata (user ID, run ID, prompt template ID, queue cursor, error codes) and not free-text user input. This configuration is verified by code audit before launch and re-verified at each material release.

Product-usage and diagnostic event records. The first-party event records Pray With Me creates about how the product is used (§ 3), and the per-prayer operational records used for diagnostics, are purged on a rolling 90-day schedule by the automated daily job described above, and all such records are deleted earlier when you delete your account. Other account-linked operational records (for example, the daily use meter) are retained until you delete your account. Hosting-provider server logs follow the hosting provider's own retention, as described under Server request logging above.

Working copies on the server. While a prayer is being composed and spoken, its text and audio are written to the server's own disk. Once the prayer is in your archive, the working copy is redundant and is removed by an automated sweep after 30 days; the archive copy stays until you request deletion.

Safety-screening records. Pray With Me's automated crisis screening (described in § 3 of the Terms of Service and on the published safety page) keeps a small set of records. When it shows a referral notice in place of a normal response, it keeps a ledger entry counting the notice, which holds no names, no account identifiers, and no message content, and is retained indefinitely in that identifier-free form so the number of notices can be reported where law requires; and a record that a prayer request was replaced by a notice, kept with your prayer records, with an operational log entry that follows the 90-day window above. It also keeps short-lived internal markers, for up to 48 hours, that keep out of the memory both the text that triggered a notice and any message the conversation answered by pointing you to a crisis line. No person is notified which account was shown a notice, and none of these records is shared.

Subscription and payment records. Subscription metadata and billing records are retained for the period required by US tax and accounting law, and are removed once it expires. These records are held under a records-retention practice rather than an automatic expiry, and they are the one category that survives deletion of your account, as § 9 describes: a record that a transaction occurred is a legal obligation IRJG cannot discharge by deleting it.

Backups and disaster-recovery copies. Backups are purged on the next rotation cycle following account deletion. Pray With Me relies on Supabase daily backups, which retain a rolling 7 days of daily snapshots. The backup window varies with Supabase tier and is updated here when it changes.

Aggregated, anonymized, or de-identified data. May be retained indefinitely; this data cannot be used to identify you and is not subject to this Privacy Policy. IRJG maintains such data only in de-identified form, does not attempt to re-identify it, and contractually requires any recipient of it to commit to the same.

Support and rights-request correspondence. Retained for the period needed to fulfill the request and demonstrate compliance with the response timelines in § 20, then deleted, unless longer retention is required by an open legal matter.

Vendor-side retention. Beyond IRJG's instructions, vendor-side retention follows each vendor's own published retention policy. See § 4.1 for AI-provider specifics.

8. User rights

Depending on where you live, you may have rights to access, confirm, correct, delete, or receive a copy of your data, to withdraw consent, to object to certain processing, and to appeal a denial. IRJG honors rights workflows for CCPA and CPRA, MHMDA, GDPR, UK GDPR, Swiss FADP, and other applicable US state privacy laws through privacy@trypraywithme.com. See § 20 for the rights-request workflow. Three rights are additionally exercisable directly in the app, without writing to anyone: withdrawal of consent, through the Consent & Policies screen in Settings; erasure of the memory, through the "Forget all of this" control on the memory's screen; and deletion of your data, as described in § 9.

9. Self-serve account deletion

You can delete your account and associated data from Settings, under Delete My Data. The app-side deletion is synchronous and permanent. When you confirm deletion, IRJG:

Vendor-side deletion (Anthropic and ElevenLabs) is not part of the synchronous endpoint; it follows the mechanism each vendor offers, promptly, and in any event within the response windows in § 20. Subscription and billing records are retained as described in § 7 notwithstanding account deletion. For Anthropic, inputs and outputs age out under Anthropic's published 30-day default-retention purge, the deletion mechanism on its standard API tier, which offers no separate per-user deletion channel, and records processed during operational sessions follow the verified retention terms of the operator's tooling account as described in § 4.1; for ElevenLabs, IRJG's automated purge of speech-generation history (§ 4.1), committed at least monthly and daily by design, erases vendor-side prayer text for all accounts on a rolling basis, without waiting for any request. Three further records outlive your account for a bounded time and are named here so the list is complete: the subscription-management provider's record of your account reference and purchase metadata, which is the link between the retained billing record described in § 7 and the App Store transaction, and which is removed when that billing record is; error events held by the error-monitoring provider that carry your internal account identifier, which resolves to no person once your account is gone and which expire under that provider's own retention; and the email relay's delivery logs for the authentication messages sent to you, which hold your address for the relay's own log window.

If a deletion request fails partway through, IRJG remediates manually within a reasonable amount of time from when IRJG becomes aware of the deletion failure.

10. Do Not Sell or Share

IRJG does not sell personal data, religious-belief data, or consumer health data, in any circumstance, in any jurisdiction. IRJG does not share personal data for cross-context behavioral advertising and does not use the data you share with Pray With Me, or any data the application collects about you, to target advertising to you, to build an advertising audience, or to profile you for advertising; this commitment applies regardless of your jurisdiction. Religious-belief data and consumer health data are never used or shared for any advertising purpose, without exception. The public website loads no third-party advertising or analytics tag, script, or pixel of any kind. If IRJG advertises Pray With Me on the App Store, it may measure whether those ads led to installs through Apple's privacy-preserving attribution framework, which sends Apple a small numeric signal from your device that carries no identifier for you or your device and nothing you brought to prayer; IRJG receives counts, not information about you, and this is neither a sale nor a sharing of your data.

11. Children

Pray With Me is for adults age 18 and older only. IRJG does not knowingly collect personal data from anyone under 18.

Pray With Me uses age attestation (a checkbox during onboarding by which you affirm you are 18 or older) as its age gate; IRJG relies on your attestation and does not independently verify age. The attestation is recorded in the consent log. Paid Pray With Me subscriptions are purchased through Apple's In-App Purchase system, which requires an Apple ID with a valid payment method; this provides additional friction but is not an age check.

If IRJG learns that a person under 18 has provided personal data to Pray With Me, IRJG will delete the account and associated data; where possible, IRJG will notify the user before deletion.

12. Security

Data is encrypted in transit (TLS) and at rest. Pray With Me is not end-to-end encrypted: IRJG and its service providers can technically access your data to operate the service. IRJG also uses access controls, role-based permissions, multi-factor authentication on the cloud-vendor consoles through which IRJG administers the service (Supabase, Vercel, Railway, RevenueCat, App Store Connect, Sentry, Cloudflare, Resend, Google Workspace, Anthropic, ElevenLabs, GitHub, Expo), and provider-level security features. Pray With Me does not expose an in-app administrative console to end users.

No system is perfectly secure. If IRJG determines that a breach has occurred that affects your personal data and triggers a notification obligation under applicable law, IRJG will notify you by email without undue delay and within any period required by the law of your jurisdiction; IRJG's goal is to provide that notice within 72 hours of confirming the breach. See § 17.

13. AI processing, AI-generated content, and crisis screening

Pray With Me uses AI providers to turn what you bring into a spoken prayer. Prayers are AI-generated, not written or reviewed by a human author, a member of the clergy, or any other person before delivery. The conversation in Pray With Me is likewise conducted by an automated AI system, not a human being and not a licensed professional, and the app says so at the start of every conversation. The voices that speak your prayer, named Theo and Anna in the app, are synthesized AI voices, not people. Prayers may reflect the limits of automated systems, including occasional inaccuracies, a passage of scripture that is misread, or phrasing that does not match what you would expect.

Pray With Me offers you words to pray. It does not pray on your behalf, and it is not a substitute for a faith community, for clergy or pastoral care, or for professional medical, mental-health, or therapeutic care.

Crisis screening. Pray With Me runs a two-layer safety protocol, described in full on the published safety page. The first layer is a fixed set of patterns, run on IRJG's own server over each message you type, over your intention before a prayer is composed, and over the passage you write about yourself before it is saved, that recognizes a first-person, present-tense statement of intent to harm yourself or another person and shows a crisis-resources notice at once. The second layer is a separate automated review, by a language model pinned to one fixed version, of what you wrote together with the finished prayer, before any audio is produced; it can deliver the prayer, ask for it to be rewritten, or show a crisis-resources notice in its place. The notice names 988 and the Crisis Text Line, or 911 where someone may be in immediate danger, and it is secular. No person is notified when either layer fires, and the records kept are described in § 7.

Crisis resources. Pray With Me is not monitored in real time. If you are in crisis, please reach out to one of the resources below immediately.

In the United States:

Outside the United States, call your local emergency number, and see https://findahelpline.com/ for a crisis line in your country.

14. Advertising, analytics, and error monitoring

Advertising, session replay, and analytics tools Pray With Me does not use. Pray With Me does not use ad pixels, session-replay tools, or analytics that capture free text. Specifically, Pray With Me does not use Google Analytics, Mixpanel, Amplitude, Segment, PostHog, Heap, Hotjar, FullStory, LogRocket, Microsoft Clarity, Smartlook, the Meta pixel, the TikTok pixel, or Google Ads pixels in the application or on the public website. The Pray With Me iOS app ships its typefaces inside the app and makes no font request to any third party.

Measurement inside the application. IRJG measures how Pray With Me and its subscription flow are used with first-party records it creates itself: for example that a prayer was composed, that a subscription offer was shown or declined, or that an account completed setup. These records are created by Pray With Me's own servers rather than by any third-party tag, which is why the tools listed above remain absent from the application. Where you have answered the optional setup question about how you found Pray With Me, that answer is stored with your account and joined to those records so IRJG can tell which channels bring people who go on to use the product. It is a fixed choice from a short list, never free text. Where you reached the App Store through a link IRJG itself published, the campaign label IRJG wrote into that link may be stored with your account in the same way. Neither record is used to advertise to you, neither is handed to an advertising platform, and neither is joined to any identifier an advertising platform created. If IRJG ever changes that, IRJG will update this section first.

Measuring Apple's own App Store ads. If IRJG advertises Pray With Me on the App Store, it may measure whether those ads led to installs and subscriptions through Apple's privacy-preserving attribution framework. In that framework your device sends Apple a small numeric signal that carries no identifier for you or your device and nothing you brought to prayer, and IRJG receives campaign-level counts from Apple, not information about you. IRJG sends Apple no email address, no account identifier, and no record about you for this purpose, and the app contains no third-party advertising or attribution software. IRJG does not use any other advertising measurement, and if that ever changes, IRJG will update this section first.

The public website. The website at trypraywithme.com is a set of static pages: this Policy and the other legal documents, the safety page, the sound files the app streams, and the page that completes a sign-in link. It hosts no signup form, collects no email address or other information you provide about yourself, sets no cookies, and loads no third-party script, font, tag, pixel, or tracker; nothing on it will ever load one. Its processing is the ordinary request logging of its hosting provider. IRJG may count visits to its pages from those logs or with its own first-party, cookieless measurement that identifies no visitor, sets nothing on your device, and shares nothing with any advertising platform; if IRJG adds such measurement, IRJG will describe it in this section before it begins, and where the law of your country requires it, IRJG will ask first or give you a simple way to object.

Error monitoring (Sentry). IRJG uses Sentry for error monitoring. Sentry is configured to:

One thing Sentry does receive, stated plainly rather than left to the word "scrubbed": an error raised while a prayer is being composed is tagged with your account identifier, so that a fault can be traced to the run it broke. The identifier is an internal reference, not your email address or your name, and it travels without any of the content listed above.

Sentry is enabled in production only after end-to-end scrubbing has been verified against a production-side test event; that verification is recorded in IRJG's internal privacy-operations records and can be re-verified on request. If at any time scrubbing cannot be verified, Sentry is disabled.

15. Legal disclosures

IRJG may disclose personal data when required to do so by law, including to comply with subpoenas, court orders, search warrants, or other lawful requests by public authorities, and to enforce IRJG's Terms of Service or protect the rights, property, or safety of IRJG, its users, or others. Where permitted, IRJG will notify affected users before disclosing their personal data in response to a legal request.

16. Business transfers

If IRJG is involved in a merger, acquisition, financing, reorganization, bankruptcy, or sale of all or a portion of its assets, your personal data may be transferred as part of that transaction. IRJG will provide notice (through this Privacy Policy or by direct communication) before personal data becomes subject to a different privacy policy.

17. Breach notification

If IRJG determines that a reportable breach has occurred, IRJG will notify affected users by email without undue delay and within any period required by applicable law. IRJG's goal is to provide that notice within 72 hours of confirming the breach.

18. California residents (CCPA / CPRA)

This section supplements the rest of this Privacy Policy and applies to California residents.

Categories of personal information collected in the past 12 months:

Sources of this information are: you, your device, and IRJG's service providers (limited to technical data and, in the case of RevenueCat, subscription metadata).

Business and commercial purposes for using this information are listed in § 3. IRJG discloses the categories above to the service providers listed in § 4 for those business purposes; IRJG does not otherwise disclose personal information for a business purpose. The retention period or criteria for each category are described in § 7.

No sale; no sharing. IRJG does not "sell" personal information, does not "share" personal information for cross-context behavioral advertising, and does not "sell" or "share" sensitive personal information, in any circumstance. Measuring IRJG's own App Store advertising through Apple's privacy-preserving framework, described in § 14, involves no identifier for you and is neither a sale nor a sharing of personal information.

Your California rights. You have the right to know, access, correct, delete, opt out of sale or sharing, and limit use of sensitive personal information. IRJG does not sell or share personal information, so the opt-out has nothing to act on.

Right to limit use of sensitive personal information. IRJG has already limited its use of your sensitive personal information to the purposes permitted by California Civil Code § 1798.121(a) and its implementing regulations: providing the service you have requested. IRJG does not infer characteristics about you from sensitive personal information for any other purpose, and does not use sensitive personal information for advertising or commercial purposes beyond providing Pray With Me to you. As a result, no additional action is required when you exercise the right to limit. If you believe sensitive personal information is being used for an impermissible purpose, contact privacy@trypraywithme.com.

Authorized agents. You may use an authorized agent to submit a request. IRJG may require proof of authority and may ask you to verify your identity directly.

California "Shine the Light." IRJG does not disclose personal information to third parties for their own direct marketing purposes.

Appeals. If IRJG denies your request, you may appeal by replying to the denial email or contacting privacy@trypraywithme.com.

19. Other US state privacy laws

For residents of states with comprehensive privacy laws (including Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, Delaware, Iowa, Nebraska, New Hampshire, New Jersey, Tennessee, Minnesota, Maryland, Indiana, Kentucky, and Rhode Island, as each law takes effect), IRJG provides the rights and disclosures required by your state's law. Those laws treat data revealing religious beliefs as sensitive data, and most require consent before it is processed: the explicit consent described in § 5 is that consent, and where a state instead requires notice and a chance to opt out, the same consent step and the Consent & Policies screen in Settings provide both. Maryland's law permits sensitive data to be processed only where strictly necessary to provide the service you asked for and prohibits its sale outright; IRJG processes your tradition preference and what you bring to prayer only to compose the prayer you asked for, and sells none of it. Specific consumer-health-data rights are described in the separate Consumer Health Data Privacy Policy; comprehensive-privacy-law rights (access, correction, deletion, portability, opt-out) are honored through the rights-request workflow in § 20.

20. Rights-request workflow

To exercise your rights, email privacy@trypraywithme.com from the email address tied to your account. IRJG may request one round of clarifying questions to verify your identity. IRJG responds within:

If IRJG denies a request, the denial email includes the reason and a short appeal path. IRJG does not retaliate or discriminate against any user who exercises a privacy right.

21. Cookies and browser privacy signals

The Pray With Me iOS app does not use cookies; it keeps you signed in with an authentication session token stored securely on your device. The app sets no advertising cookies, third-party analytics cookies, or tracking pixels.

The public website sets no cookies of any kind and loads no third-party trackers, scripts, or pixels.

IRJG honors Global Privacy Control (GPC) signals universally. Where a browser sends a Sec-GPC: 1 header, or sets the equivalent JavaScript signal, to a Pray With Me service that can receive it, Pray With Me records the signal against the user's account and treats it as a valid opt-out of any sale, sharing for cross-context behavioral advertising, or targeted advertising. Pray With Me engages in none of these, so the signal has nothing to act on today; the recorded signal applies prospectively to any future change. To request a copy of the privacy preferences Pray With Me has recorded against your account, use the rights-request workflow in § 20.

Some places in the app open pages that IRJG does not operate: Apple's subscription-management settings and the crisis resources listed in § 13. These open outside the application, in your browser or in the relevant Apple interface, and each is governed by its operator's own terms, privacy practices, and cookie choices rather than by this Policy. Pray With Me sends these operators no information about you or your account; when you follow such a link, the operator receives only what your browser ordinarily provides when you visit any website.

22. Changes to this policy

If this Privacy Policy changes in a material way, IRJG will update the version and effective date and may require renewed consent. Non-material updates may also be reflected through a version and effective-date update without renewed consent.

Before publishing each material version, IRJG verifies that the in-app re-consent flow surfaces the new version distinctly from prior versions and records a new consent-log row on acceptance.

23. Effective date and version

Effective date: 2026-09-18 Version: v1-2026-09-18