PrayCraft ("we", "us", "our") takes your privacy seriously. This policy explains what we collect, why, and the rights you have under the UK GDPR, EU GDPR and (where relevant) the California CCPA.
1. Who we are
PrayCraft is operated by PrayCraft, based in the United Kingdom. You can reach us at hello@praycraft.co.uk. For UK GDPR purposes, we are the data controller for information you provide through the app.
2. What data we collect
Guest mode (no account)
If you use PrayCraft without signing in, your display name, tradition, focus areas, prayer confidence, streaks and progress are stored only in your browser (localStorage) on this device. We do not receive them. Personal prayer content — journal entries, custom moments, intercession lists, and free-text reflections inside guided sessions — is not saved in guest mode; those features require sign-in so we can honour your right to erase them (see section 8).
With an account
- Your email address (for sign-in) and, if you choose Google sign-in, your Google account identifier and name.
- Your tradition, focus areas, prayer confidence, reminder settings and preferences, synced across devices.
- Personal prayer content you save: journal entries, intercession lists, custom moments, and free-text reflections from guided sessions.
- Timestamps of prayer sessions, lesson completions, seals earned and quests progressed.
AI-assisted features
When you use "A word for today", "Reflect with a verse", "Shape a session", or "Someone on my heart", the text you provide together with limited context (your tradition and focus areas, if set) is sent to our AI provider for processing. Requests are not used to train third-party models.
Voice features ("Say it with me")
When you use "Say it with me", a short audio recording of your voice is sent to our AI provider for transcription in real time. The audio is not stored by us and the transcript is held only long enough to score your attempt, then discarded. You can use the feature text-only by declining microphone access.
Technical data
We receive standard server logs (IP address, user-agent, timestamps) for security and abuse prevention. We do not use tracking cookies, advertising pixels, or third-party analytics.
3. Special category data
Information about your religious beliefs (your tradition, journal content, prayers) is special category data under Art. 9 UK GDPR. We process it only with your explicit consent, given by choosing to enter it into the app. We never sell it or use it for advertising.
4. Lawful basis
- Consent (Art. 6(1)(a) & Art. 9(2)(a)) — for storing your tradition, journal entries and prayer content, and for AI-assisted features.
- Contract (Art. 6(1)(b)) — to provide the account and sync features you sign up for.
- Legitimate interests (Art. 6(1)(f)) — for security, abuse prevention and improving the service.
You can withdraw consent at any time by clearing your data in the app or deleting your account.
5. How we use your data
- To personalise lessons, prompts and sessions to your tradition and focus areas.
- To sync your progress and journal across your devices.
- To generate reflections and session outlines when you request them.
- To keep the service secure and functioning.
6. Sharing & sub-processors
We do not sell your data. We use the following processors:
- Lovable (application hosting and edge functions).
- Supabase (database, authentication, EU region).
- Google (Gemini via Lovable AI Gateway) — for AI reflections and prompts.
Each processor is bound by a data-processing agreement and may only use your data on our instructions. AI inference may involve transfer outside the UK/EEA; where it does, appropriate safeguards (Standard Contractual Clauses / UK IDTA) are in place.
7. Retention & deletion
- Guest data: kept in your browser until you clear it or uninstall.
- Account data: kept while your account is active.
- Clear my data (Account → Danger zone) — immediately erases your journal, prayer sessions, lessons, seals, quests and library progress from every device. Your account, tradition and preferences remain so you can start fresh.
- Delete my account (Account → Danger zone) — immediately and permanently erases your account, profile and every piece of prayer, journal and progress data we hold about you. There is no grace period; once confirmed, it cannot be recovered.
- Server logs: rotated within 30 days.
- AI request content: not retained by us beyond the request; provider retention follows their policy.
- Backups: any residual copies in encrypted backups roll off within 30 days.
8. Your rights
Under UK/EU GDPR you have the right to:
- Access your data and receive a copy.
- Correct inaccurate data.
- Delete your data ("right to be forgotten").
- Restrict or object to processing.
- Data portability (export your journal and progress).
- Withdraw consent at any time.
- Lodge a complaint with the UK Information Commissioner's Office (ico.org.uk) or your local supervisory authority.
California residents have equivalent rights under the CCPA/CPRA, including the right to know, delete, correct and opt out of "sale" or "sharing" (we do neither).
To exercise any right, use Account → Danger zone to clear your data or delete your account instantly, or email us at hello@praycraft.co.uk for access, correction, or portability requests. We respond within one month.
9. Children
PrayCraft is not directed at children under 13. In the UK, users under 16 should have a parent or guardian's consent before creating an account. If you believe a child has provided us data without consent, contact us and we will delete it.
10. Security
We use row-level security on the database so each account can only read its own rows, TLS in transit, and hashed passwords via our authentication provider. No system is perfectly secure — please use a strong, unique password.
Two-factor authentication (2FA)
You can enable app-based 2FA (TOTP) from Account → Privacy & security. When enabled, signing in requires a 6-digit code from your authenticator app in addition to your password. We strongly recommend enabling 2FA for any account holding journal or intercession content.
Journal storage
Journal entries are stored in our database and are protected by row-level security so only your signed-in account can read them. They are encrypted at rest by our infrastructure and transmitted over TLS.
11. Changes to this policy
We will notify you inside the app of material changes. The "Last updated" date below reflects the current version.
12. Contact
Questions or requests: hello@praycraft.co.uk.
Last updated: 20 July 2026