Last updated: June 24, 2026
Prayla ("we," "our," or "us") operates the Prayla mobile application and the website at prayla.app (collectively, the "Service"). This Privacy Policy explains what personal data we collect, how we use it, who we share it with, and your rights regarding that data. By using the Service, you agree to the collection and use of information in accordance with this policy. If you do not agree, please do not use the Service.
The Service is intended for users aged 13 and older. By creating an account, you represent and warrant that you are at least 13 years of age. If we become aware that a user is under 13, their account and all associated data will be immediately and permanently deleted.
We collect the following categories of personal data: (a) Account Data: Name or pseudonym, email address (provided via Apple Sign-In), date of birth, country, and profile photo (avatar). This data is collected during account creation and through your profile settings. (b) User-Generated Content: Prayer intentions (text and images), comments, and feedback submissions. This content is created and submitted by you within the Service. (c) Engagement Data: Records of prayers, candles (bookmarks), shares, and comment likes. This data is generated through your interactions with other users' content. (d) Device & Technical Data: Push notification token (Firebase Cloud Messaging), device language preference, and app version. This data is collected automatically when you use the Service. (e) Analytics & Diagnostics Data: App usage patterns (screen views, feature usage events such as creating intentions, sending prayers, and sharing content), crash reports, and device diagnostic data. This data is collected automatically via Firebase Analytics and Firebase Crashlytics to help us understand how the Service is used and to improve app stability. Analytics data is associated with your user ID but does not include the content of your prayers, comments, or messages. We do NOT collect: payment card details (handled exclusively by Apple/Google via RevenueCat), precise location data, contacts, or health data. (f) Direct Messages: The content of private one-to-one messages you send to and receive from other users. This content is created by you when you use the direct messaging feature.
We use your personal data for the following purposes: (a) Providing the Service: Displaying your profile, publishing your intentions and comments, delivering notifications, and enabling community engagement features. (b) Content Moderation: Automated review of intentions, comments, and images using third-party AI to detect and prevent harmful or inappropriate content (see Section 5). (c) Translation: Automated translation of prayer intentions into all supported languages using third-party AI, allowing users to translate intentions into their own language (see Section 5). (d) AI Catholic Chat: Providing an AI-powered spiritual companion feature that uses third-party AI to respond to your questions and conversations about Catholic faith, Scripture, and Tradition (see Section 5). (e) Personalization: Using your country and language preferences to customize your feed and notification language. (f) Analytics & Improvement: Understanding how users interact with the Service to improve functionality, fix bugs, and enhance the user experience. (g) Communication: Sending push notifications about engagement on your intentions, community activity, and Service updates. (h) Direct Messaging: Operating the one-to-one direct messaging feature — delivering your messages to the recipient, showing message previews in notifications, and applying message requests and blocking.
To provide content moderation, translation, and AI Catholic Chat features, certain user data is sent to Google LLC via its Gemini AI platform ("Google Gemini"). Google acts as a data processor on our behalf. Data sent to Google Gemini: • Prayer intention text and attached images — for content safety moderation and translation into all supported languages • Comments — for content safety moderation • Profile photos (avatars) — for image safety validation • AI Catholic Chat conversations — for generating AI-powered spiritual guidance responses Data NOT sent to Google Gemini: • Your name, email address, date of birth, country, or any other personally identifiable information Data protection measures: • All data is transmitted via encrypted connections (TLS) • Google does not use your data for AI model training • Data is processed in real-time on a per-request basis • Data is not retained by Google beyond what is necessary to complete each processing request • Google is contractually obligated to handle data in accordance with applicable data protection regulations For more information, refer to Google's Privacy Policy at https://policies.google.com/privacy. Direct messages are never sent to Google Gemini or any other AI system. They are not processed for AI moderation or translation.
In addition to Google Gemini, the Service uses the following third-party services that may process your data: • Apple Sign-In — Authentication provider. Receives your Apple ID credentials to verify your identity. Subject to Apple's Privacy Policy. • Firebase (Google) — Push notifications (FCM), analytics, and crash reporting. Receives your device token, usage data, and crash logs. Subject to Google's Privacy Policy. • RevenueCat — Subscription management. Processes purchase transactions on behalf of Apple/Google. We do not receive or store payment card details. Subject to RevenueCat's Privacy Policy. • Backblaze B2 — Cloud storage for user-uploaded images (avatars and intention images). Subject to Backblaze's Privacy Policy. All third-party service providers are contractually required to protect your data and use it only for the purposes described above. Push notifications delivered through Firebase Cloud Messaging may include notification content, such as a sender's name and a short preview of a direct message.
Your data may be shared or made visible in the following ways: (a) Community Visibility: Your display name, avatar, and shared content (intentions and comments) are visible to all users of the Service. (b) Social Sharing: Intentions may be shared outside the Service via share links or social media features initiated by you or other users. (c) Third-Party Processors: As described in Sections 5 and 6, your data is shared with third-party service providers solely for the purposes of operating the Service. (d) Legal Requirements: We may disclose your data if required by law, regulation, legal process, or governmental request. We do NOT sell your personal data to third parties. Direct messages are private between you and the recipient and are not shown to other users or made public. Because messages are encrypted at rest with keys we control rather than end-to-end encryption, we retain the technical ability to access message content and may do so to operate the Service, enforce our Terms, respond to reports, or comply with the law.
Your data is stored on secure, encrypted infrastructure using PostgreSQL databases and Redis caching. User-uploaded images are stored on Backblaze B2 cloud storage with CDN delivery. We implement industry-standard security measures including: • Encrypted data transmission (TLS/HTTPS) • Hashed session tokens (JWT with HS256) • Server-side input validation and content moderation • Rate limiting on sensitive operations While we take reasonable measures to protect your data, no method of electronic storage or transmission is 100% secure. We cannot guarantee absolute security. Direct message content is additionally encrypted at rest using AES-256-GCM. Because we manage the encryption keys, this is not end-to-end encryption — it protects messages in storage and backups while allowing us to operate the feature.
We retain your data for as long as your account is active or as needed to provide the Service. Specific retention periods: • Account data: Retained until account deletion • Prayer intentions: Automatically expire after 7 days (free users) or 30 days (premium users) • Comments: Retained until the associated intention expires or is deleted • Notifications: Read notifications are automatically deleted after a set period • Session tokens: Expire after 30 days of inactivity Upon account deletion, all associated data (profile, intentions, comments, engagement records, and uploaded images) is permanently deleted within 24 hours. Direct messages are automatically deleted 7 days after they are sent, except that the most recent messages in each conversation are retained — so shorter conversations may keep their full history. If you report a direct message, a copy of the reported message and related conversation details may be retained beyond these periods for safety, moderation, and legal compliance. All of your direct messages are permanently deleted when you delete your account.
We use Firebase Analytics to collect first-party usage data, including screen views, feature usage events (such as creating intentions, sending prayers, sharing content, and completing purchases), and user properties (language, country, and subscription status). This data helps us understand how the Service is used, identify issues, and improve the user experience. Analytics data is collected automatically when you use the Service and is linked to your user ID. We use Firebase Crashlytics to collect crash reports and diagnostic data to improve app stability. When errors occur, Crashlytics may capture device information and the app state at the time of the crash. This data is used solely for debugging and stability improvements. On iOS, we support Apple's App Tracking Transparency (ATT) framework. You may be asked for permission regarding cross-app tracking for advertising purposes. Declining ATT does not affect the collection of first-party analytics data described above, and your experience with the Service remains identical — no features are restricted. By accepting the Terms of Use and Privacy Policy during account verification, you consent to the collection of analytics and crash reporting data as described in this section.
You have the following rights regarding your personal data: • Access: View your personal data through the app's profile and settings screens. • Correction: Update your name, username, avatar, country, and birthday through the app settings. • Deletion: Delete your account and all associated data at any time through Settings > Delete Account. Deletion is permanent and completed within 24 hours. • Data Portability: Contact us at [email protected] to request an export of your personal data. • Withdraw Consent: You may stop using the Service at any time. Deleting your account withdraws all consent for future data processing. To exercise any of these rights, use the in-app settings or contact us at [email protected].
The Service is not directed at children under the age of 13. We do not knowingly collect personal data from anyone under 13. If you are a parent or guardian and believe your child has provided us with personal data, please contact us at [email protected] and we will promptly delete the data and terminate the account.
We may update this Privacy Policy from time to time. When we do, we will update the "Last updated" date at the top of this page. We encourage you to review this policy periodically. Continued use of the Service after changes constitutes acceptance of the updated policy.
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us at: Email: [email protected] Website: https://prayla.app/support