1. Information We Collect
1.1 Types of Information We Collect
- Account Information: Email address, username (used to create and manage your account)
- Prayer Content: Prayer text you submit (used solely to generate responses)
- Usage Data: App usage frequency, feature usage statistics (used to improve services)
- Device Information: Device type, operating system version, app version (used for technical support)
- Push Notification Tokens: Used to send notification reminders
- Purchase Information: Subscription status, purchase records (used to verify paid features)
1.2 How We Collect Information
- Information you provide directly (registration, prayer input)
- Automatically collected usage data (app analytics)
- Information from third-party services (Google sign-in, app store purchases)
2. How We Use Your Information
2.1 Purposes of Use
- Core Functionality: Generate relevant biblical scripture responses to your prayers
- Account Management: Create and maintain your user account
- Personalized Service: Customize content based on your preferences
- Technical Support: Resolve technical issues and provide customer service
- Service Improvement: Analyze usage patterns to improve app functionality
- Notification Service: Send important updates and reminders
- Paid Features: Manage subscriptions and verify purchases
2.2 Legal Basis for Data Processing
- Contract performance (providing app services)
- Legitimate interests (improving service quality)
- User consent (push notifications, data analytics)
- Legal requirements (financial record keeping)
3. Information Sharing
3.1 We Do Not Sell Your Personal Information
We promise to never sell your personal information to third parties.
3.2 Limited Information Sharing
We may share information in the following circumstances:
- Technical Service Providers: Supabase (database), OpenAI (AI services)
- Payment Processing: Google Play, App Store (purchase verification)
- Analytics Services: Anonymous usage statistics (no personally identifiable information)
- Legal Requirements: Court orders or government requests
- Security Protection: Preventing fraud or protecting user safety
4. Data Security
4.1 Security Measures
- Encrypted Transmission: All data transmission uses HTTPS encryption
- Database Security: Row-level security policies, users can only access their own data
- Access Control: Strict limits on data access permissions
- Server Security: Using enterprise-grade cloud services (Supabase)
- Regular Audits: Regular security vulnerability checks
4.2 Data Storage
- Data stored in SOC 2 compliant secure data centers
- Regular backups to prevent data loss
- Multi-layered security protection implementation
5. Data Retention
5.1 Retention Periods
- Account Data: For the duration of account existence
- Prayer Records: For the duration of account existence (can be manually deleted)
- Usage Statistics: Maximum 2 years (anonymous data)
- Purchase Records: Legal retention period (typically 7 years)
- Technical Logs: Maximum 90 days
5.2 Data Deletion
You can at any time:
- Delete individual prayer records
- Request deletion of entire account and related data
- Cancel subscriptions and stop data collection
6. Your Rights
6.1 Data Rights
Under applicable privacy laws, you have the following rights:
- Right to Know: Understand how we process your data
- Right to Access: Obtain a copy of your data we hold
- Right to Rectification: Correct inaccurate personal information
- Right to Deletion: Request deletion of your personal information
- Right to Restriction: Restrict certain data processing activities
- Right to Portability: Obtain data in a commonly used format
- Right to Object: Object to certain data processing
- Right to Withdraw Consent: Withdraw previously given consent at any time
6.2 Exercising Your Rights
To exercise these rights, please contact us through the following methods:
7. Third-Party Services
7.1 Integrated Services
- Google Services: Sign-in authentication (follows Google Privacy Policy)
- Apple Sign-In: Sign-in authentication (follows Apple Privacy Policy)
- OpenAI: AI content generation (does not store personal data)
- Supabase: Database services (complies with GDPR and SOC 2 standards)
7.2 Linked Websites
Our app may contain links to third-party websites. We are not responsible for the privacy practices of these websites. We recommend reading each website's privacy policy.
8. Children's Privacy
Our app is intended for users aged 13 and above. We do not knowingly collect personal information from children under 13. If we discover we have collected such information, we will delete it immediately.
9. International Data Transfers
Your data may be transferred to servers outside your country/region for processing. We ensure such transfers comply with applicable data protection laws and take appropriate security measures.
10. Policy Updates
We may periodically update this privacy policy. We will notify you of significant changes through in-app notifications or email. Continued use of our services indicates acceptance of the updated policy.
11. Contact Us
If you have any questions about this privacy policy or need to exercise your data rights, please contact us through:
- Email: yingapple0819@gmail.com
- In-App Feedback: Settings → Help & Feedback
- Data Deletion Request: Click here
Response Time: We will respond to your request within 30 days.