Introduction
PrayerMap ("we," "our," or "us") is a non-profit ministry platform that enables users to share prayer requests and support one another through a location-based map interface. This Privacy Policy explains how we collect, use, disclose, and protect your information when you use our mobile application and website (collectively, the "Service").
By using PrayerMap, you agree to the collection and use of information in accordance with this policy.
Information We Collect
1. Account Information
When you create an account, we collect:
- Email address — Used for account authentication and optional notifications
- Display name (optional) — Shown to other users unless you choose to post anonymously
- Profile photo (optional) — Displayed on your profile and with your prayers
If you sign in with Apple, we receive your Apple ID email (or a private relay email if you choose "Hide My Email"). If you sign in with Google, we receive your Google account email address and display name via OAuth 2.0.
PrayerMap also supports passwordless authentication via magic links. When you choose this method, a one-time sign-in link is sent to your email address. No password is created or stored.
2. Location Data
PrayerMap is a location-based service. We collect:
- Precise location — AR Prayer Vision uses it on your device to place prayers around you, and does not send it to us. When you post a prayer, your position is sent to our servers so the offset can be calculated there; what the database holds is the offset position, not the position your device reported. Nearby-prayer alerts do not send it: from build 159 the app rounds your position on your device first, and on earlier builds it is sent and rounded on our servers instead
- Location and the map — Whether a prayer appears on the map is your choice, and a prayer does not need a location if you leave that off. If you have granted location access, your position is still attached to a feed-only prayer, offset in the same way, so that people near you can be told a prayer was posted nearby. It is not shown on the map, and you can stop this by turning off location access for PrayerMap
The choice you make when posting is whether to show the prayer on the map at all. There is no setting for sharing an exact position: every prayer shown on the map is offset, without exception.
2.1 Location Data Privacy Protection
To protect your privacy while maintaining map functionality, PrayerMap applies location protection measures:
- Geographic Offset — Prayers shown on the map are offset from your actual location by roughly 1 to 1.5 kilometers. That is a band, not a fixed radius and not an open-ended one: the distance and the direction are both derived from a secret unique to your account, and both vary. The variation is the protection — a single fixed distance would let anyone draw a circle of known radius around a published point and know your real position sits somewhere on it. This describes the map inside the app; the public website applies a second, independent offset on top of this one, and the combined distance is described in 2.4 rather than promised here
- What the offset is for — To make your home, workplace, and the places you go regularly substantially harder to identify from the map. It reduces that risk rather than removing it — see the note below
- Consistent, on purpose — The same person posting from the same area receives the same offset, so a prayer does not move between refreshes. That also means several prayers you post from one place share a single offset point. Re-rolling the offset each time would let those points be averaged together to trace a ring around where you actually are
- Applied Before Storage — The offset is applied on our servers the moment your prayer arrives, before anything is written down. Your position travels to us over an encrypted connection and is used to calculate the offset. What the database holds is the offset position; the position your device reported is not written to it, is not returned by any part of the app, and is not shown to anyone, including you
- Why the offset happens on our servers — An offset calculated on your phone could not protect anyone whose app had been modified, and it could be worked backwards. Our servers apply it using a secret unique to your account that no app can read, so the published position cannot be worked backwards from the map alone. A prayer whose location cannot be offset is refused rather than published
2.1a Your Last Known Position (for nearby-prayer alerts)
This is separate from the prayer offset described above, and it works differently. You should know about it.
If you turn on push notifications and allow location access, we store the position your device reports at that moment, so we can tell whether a newly posted prayer is near you. We reduce its precision before storing it: the coordinates are rounded to two decimal places, which places you somewhere inside a grid cell roughly a kilometre across. We give that distance as an estimate rather than a guarantee — the exact size depends on how far you are from the equator, and narrows nearer the poles. The nearest-radius setting is three miles, so anything finer would be precision we keep without ever using. The rounding happens on our servers as well as in the app, so it applies even on older versions.
It is held in a table that nothing in the app can read. There is no public access to it at all, and only four internal database functions can reach it: the one that writes it, the two that check whether a prayer is near you, and the one that erases it. It is replaced each time notifications register again, and it is deleted when you delete your account.
Turning nearby-prayer alerts off erases the position we hold for you, in build 159 and later. While either nearby-prayer alerts or notifications as a whole is off, we do not store a new one. On earlier builds, switching notifications off stopped the position being updated but did not by itself erase it — if you are on an earlier build, or would simply rather we removed it now, email contact@prayermap.net and we will delete it.
Important: While the offset substantially reduces the risk, it is not anonymisation. Your approximate neighborhood or city may still be inferable.
2.2 No Exemptions to the Offset
Earlier versions of PrayerMap attempted to detect public places (churches, parks, hospitals) and show prayers posted there at their true coordinates. That feature has been removed. The location offset is now applied to every prayer without exception, regardless of where it was posted.
- No prayer is ever shown at its exact coordinates
- PrayerMap no longer sends your coordinates to a mapping provider to classify your location
- If the offset cannot be applied for any reason, the prayer is not placed on the map at all
2.3 Per-Prayer Location Consent
PrayerMap requires explicit consent each time you share your location on the map:
- Manual Opt-In — You must enable "Show on Map" for each individual prayer
- Default OFF — Location sharing is disabled by default
- No Automatic Sharing — There is no setting to automatically share all prayers
- Revocable — You can hide any prayer from the map at any time by editing it
2.4 What Someone Without an Account Can See
prayermap.net is a public website. Part of the map is visible to anyone who opens it — no account, no sign-in required. Two things outside the map are visible the same way, and this section covers those too.
- Only the Shape of the Map — A signed-out visitor sees offset points showing that a prayer exists somewhere, and the lines drawn between people who have prayed together
- Never the Content — The words of any prayer, any title, and any profile are never shown to a signed-out visitor. A name is shown only as described in the "Names Are Off By Default" bullet below
- Never an Exact Location — A signed-out visitor never receives a stored coordinate. The point shown has the offset described in 2.1 applied to it, and then a second, independently generated offset applied on top of that. Because the two are generated independently they can pull in different directions, so the combined distance from your real position varies: usually further than a single offset, sometimes less. We describe that mechanism rather than promise a distance for it. There is no separate, less-protected layer for signed-out visitors — the point a signed-out visitor sees is not the point a signed-in viewer sees
- "Show on Map" Governs This Absolutely — A prayer you never place on the map is not part of this public layer, and turning "Show on Map" off removes it
- Names Are Off By Default — Your name never appears on the public web unless you separately turn that on, and that setting is off for everyone by default
- Discoverable Groups — If a group's owner has turned on "Discoverable," a signed-out visitor can see that group's name, description, member count, and location label, along with an internal identifier for whoever created it — never that person's name or profile. A group that is not discoverable shows none of this
- The Daily Devotional — The day's verse, reflection, and prayer prompt are visible with no account required. This is content we publish, not anyone's personal information
Important: As with the offset itself, this is not absolute anonymization. A point on a public map still says a prayer was placed near a place, and someone reading the map over time may infer an approximate area.
2.5 What We Store In Your Browser
Less than this section used to claim. The website itself stores nothing in your browser. What is there is written by the mapping library, plus a temporary cleanup of an older tracker's leftovers. There are no cookies, nothing in session storage, and nothing in IndexedDB.
- Map telemetry, written by Mapbox — the library that draws the map stores an anonymous identifier and a note of when it last reported usage back to Mapbox. It is written on any page showing a map, including the home page. We do not read it and we do not use it for advertising or profiling, and it is not connected to an account, because this website has no accounts. What Mapbox does with what it receives is governed by Mapbox's own privacy policy
- A one-time cleanup — a visitor-identification tracker was removed from this site on 2026-08-27, and its leftovers stayed behind in the browsers of people who had visited before then. Every page now deletes them on your next visit. That code only removes data; it reads nothing else and stores nothing new
What is not stored, though this section used to say it was. There is no sign-in session, no record of your age or Terms acceptance, and no cached copy of the map. None of those exist: this website has no account sign-in at all, and the map is fetched fresh each time. Signing in happens in the app, and the page that completes it hands the result straight to the app rather than keeping anything in your browser.
Clearing your browser's site data removes anything described here.
3. User-Generated Content
When you use PrayerMap, we collect the content you create:
- Prayer requests — Text, audio recordings, or video recordings you submit
- Prayer responses — Your responses to others' prayer requests
- Messages — Private conversations with other users
- Reactions — Your "Amen" reactions and saved prayers
3.1 Anonymous Posting
When you post a prayer anonymously:
- Your identity is hidden from other users — Other PrayerMap users will see your prayer marked as "Anonymous"
- Your identity is visible to PrayerMap administrators — For safety, legal compliance, and content moderation purposes, our administrators can view the real identity behind anonymous posts
- Your location is still displayed — The general location of your prayer remains visible on the map
This "pseudo-anonymous" system protects your privacy from other users while allowing us to maintain a safe community and comply with legal requirements.
4. Device Information
We automatically collect device identifiers (for push notifications), device type and OS version, and app version.
5. Contact Data
With your permission, PrayerMap can access your phone contacts to help you find friends who are already using PrayerMap:
- One-Way Hashing — Phone numbers and email addresses are converted to SHA-256 hashes on your device; the original values are not sent to us
- Limits of Hashing — We want to be straightforward about this: a hash of a phone number is not the same as making it unknowable. Phone numbers come from a small enough range of possibilities that a hash of one can be worked back to the number itself. Treat contact matching as a convenience feature, not as a guarantee that we cannot determine which numbers you uploaded
- Additional Salting — A per-user salt is applied server-side when the hashes are stored, which protects them against reuse across accounts but does not change the point above
- Matching Only — Contact hashes are used solely for friend matching, and only against people who have opted in to being discoverable
- Revocable — You can revoke contact sync and delete all hashed data at any time via Settings > Contacts > Revoke Sync
We never store, share, or sell your contact list.
5.1 Social Connections (Priends)
PrayerMap allows you to connect with other users as "Priends" (prayer friends). When you use this feature, we collect:
- Friend Requests — Records of friend requests you send and receive, including timestamps and status (pending, accepted, rejected)
- Friendships — A list of your confirmed connections with other users
- Block List — Users you have blocked are recorded to prevent unwanted contact
Your friends list is visible only to you. Other users can see your friendship status with them (e.g., whether you are connected) but cannot see your full friends list. You can remove any friend or block any user at any time.
6. Spiritual & Religious Preferences
PrayerMap collects your spiritual tradition preference (e.g., Christianity, Judaism, Islam, Hinduism, Buddhism, Catholic) to personalize content recommendations:
- Sensitive Personal Data — Religious beliefs are classified as special category data under GDPR Article 9
- Explicit Consent — We process this data only with your explicit consent, which you provide during the Spiritual Lens onboarding flow
- User Control — You may change or remove your tradition preference at any time via Profile > Spiritual Lens
- Limited Use — Your tradition preference is stored in your user profile and used solely for content personalization
Your spiritual preferences are never shared with third parties or used for advertising.
7. Push Notification Data
If you enable push notifications, we collect:
- Device push token — A unique identifier generated by Apple Push Notification service (APNs) to deliver notifications to your device
- Notification preferences — Your choices about which types of notifications to receive
Push notifications are processed through Expo's push notification service, which relays to Apple Push Notification service (APNs) for iOS delivery. We use push notifications to alert you about new prayer responses, messages, friend requests, and community activity.
7.1 Prayer Reminder Notifications
PrayerMap offers optional daily prayer reminder notifications. When you enable this feature:
- Scheduled Time — Your preferred reminder time (morning, afternoon, or evening) is stored locally on your device
- Local Notifications — Reminders are scheduled as local notifications on your device and do not require server communication
- Opt-In Only — Prayer reminders are not enabled by default; you choose to enable them during onboarding or in settings
8. Usage Data & Analytics
We collect information about how you use PrayerMap to improve the Service:
- App Interactions — Screen views, feature usage patterns, and navigation events
- Content Interactions — Plays, skips, completions, and search queries
- Crash Reports & Performance — Error logs and performance metrics
8.1 Behavioral Analytics
PrayerMap is built to support behavioral analytics, and we want to be accurate about what that currently means in practice. The behavioral event pipeline is present in the app but is not active. No usage events are being recorded, and the event store is empty. The bullets below describe the design, and we will update this section and record it in the revision history if it is switched on:
- Local Event Buffering — Where the pipeline is enabled, usage events are temporarily buffered on your device before being sent to our servers
- Feature Flags — PostHog is integrated for feature availability and A/B testing. It is not currently configured in production and receives no events or device identifiers from us
- Automated Classification — Usage patterns (such as which content you skip or complete) are analysed statistically to improve recommendations. This analysis is performed by our own systems and does not involve any third-party AI service or the content of your prayers or messages
- No Profiling for Ads — Behavioral data is used solely to improve the PrayerMap experience and is never shared with advertisers or used for ad targeting
9. Media Playback & Listening History
PrayerMap records your content interactions to improve recommendations:
- Content Interactions — Play, skip, and completion events for media content
- Playback Progress — Duration watched or listened for partially consumed content
- Listening History — A record of content you have played, stored in your user profile
This data is used for personalized recommendations, taste profile computation, and content ranking. You can view and manage your listening history in the app.
10. Groups & Community Features
When you participate in PrayerMap Groups, we collect:
- Membership Information — Group membership, roles (admin, moderator, member), and permissions
- Group Content — Messages sent within group channels (text, audio, video, images)
- Event Data — Event attendance and interest responses
- Moderation Logs — Audit logs are maintained for safety and community standards enforcement
Group content is visible to other group members according to the group's privacy settings (public or private).
10.1 Group File Attachments
PrayerMap allows users to share files within group channels:
- Uploaded Media — Images, videos, audio files, and documents you upload are stored in our cloud storage (Supabase Storage)
- Link Previews — When you share a URL, PrayerMap fetches the page's title, description, and thumbnail image (Open Graph metadata) to generate a preview. Only the metadata is stored, not the full page content
- File Retention — Uploaded files are retained for the lifetime of the group or until deleted by a group administrator
11. Voice & Video Communication
PrayerMap uses LiveKit for real-time voice and video rooms within Groups:
- Encryption — Audio and video streams are encrypted using AES-128 for media and TLS for signaling
- Real-Time Only — Voice and video data is transmitted in real-time and is NOT recorded or stored by PrayerMap
- Data Processor — LiveKit processes audio/video streams as a data processor under our instructions
For more information, see the LiveKit Privacy Policy.
12. College Hub Verification
For college-specific groups, PrayerMap verifies your .edu email address:
- Verification Process — A verification code is sent to your .edu email address
- Affiliation Link — Your verified college affiliation is linked to your account to grant access to your school's group
- Secure Storage — .edu email addresses are stored securely and used only for verification purposes
13. Apple Watch Companion App
PrayerMap offers an optional Apple Watch companion app that syncs data from your iPhone:
- Data Synced — Your groups, recent messages, prayer feed, and notification summaries are synced to your watch via Apple's WatchConnectivity framework
- On-Device Only — Data is transferred directly between your iPhone and Apple Watch over a secure, encrypted connection managed by Apple. No additional data is sent to PrayerMap's servers
- Location on Watch — The watch app may access your location independently for prayer placement and Qibla compass features, subject to the same privacy protections described in Section 2
14. AR Prayer Vision (Augmented Reality)
PrayerMap offers an optional AR Prayer Vision feature that displays prayer pins and connection lines in the real world through your phone's camera.
- Camera Use — The camera is activated only when you open AR Prayer Vision. The camera feed is processed entirely on your device by Apple's ARKit (iOS) or Google's ARCore (Android) for world tracking and surface detection
- No Image Collection — PrayerMap does not capture, record, store, or transmit any images or video from the AR camera feed. All camera processing occurs on-device
- Location in AR — AR Prayer Vision uses your device's GPS location (already collected per Section 2) to position prayers at their real-world coordinates. No additional location data is collected
- Existing Prayer Data — AR displays the same prayer pins and connection lines visible on the 2D map. No new data is collected for the AR experience
- Device Sensors — AR uses your device's accelerometer, gyroscope, and compass for spatial tracking. This sensor data is processed on-device and is not collected or transmitted
How We Use Your Information
We use your information to:
- Provide the Service — Display prayers on the map, enable prayer responses and messaging
- Personalize your experience — Show nearby prayers based on your location
- Personalize content — Recommend spiritual content based on your tradition preference, listening history, and content interactions
- Send notifications — Alert you to new prayer responses, messages, and nearby prayers (with your permission)
- Moderate content — Screen prayers and messages for inappropriate content
- Improve the Service — Analyze usage patterns to enhance features
We do NOT sell your personal information, use your data for targeted advertising, or monetize your prayer content in any way.
Information Sharing
Service Providers
We share information with third-party services that help us operate PrayerMap:
| Provider | Purpose |
|---|---|
| Supabase | Database, authentication, file storage |
| Mapbox | Map display and location services |
| Apple | Sign in with Apple authentication, push notifications (APNs), WatchConnectivity |
| Google Sign-In authentication (OAuth 2.0) | |
| Expo (Expo Application Services) | Push notifications, over-the-air updates |
| YouTube / Google (YouTube Data API v3) | Video content search and playback |
| LiveKit | Real-time voice and video communication in group rooms |
| Spotify | Music catalog search and metadata |
| SoundCloud | Audio content search |
| Podcast Index | Podcast search and RSS feed metadata |
| Apple Music (MusicKit) | Music catalog search and playback |
| OpenAI | Automated content screening. Prayer text and images are checked by OpenAI's moderation service shortly after they are posted. This means the text and images you post, which may reveal religious belief or health information, are sent to OpenAI. Prayer responses and private messages are not sent. They are used to screen that content and are not used to train their models. |
| Cloudflare (Workers AI) | Voice and video transcription. So that spoken prayers can be screened for safety in the same way written ones are, the audio of a voice or video prayer is sent to Cloudflare's Workers AI service, which returns a transcript. That transcript is then screened as described above. Cloudflare's published data terms state that your audio is not used to train any AI model, and that content sent to Workers AI is not stored by Cloudflare unless we separately store it — we do not. Cloudflare acts as a data processor for this under its Customer Data Processing Addendum. |
| Resend | Email delivery. Sends the email we send you — sign-in and verification messages, and our replies when you contact support. Receives your email address and the contents of those messages. |
| TheHive.ai | Standby transcription provider. Voice and video transcription is currently handled by Cloudflare. TheHive.ai remains configured as a fallback and would receive that audio only if the primary provider were unavailable. It is listed here because it is configured, not because it is currently in use. |
| PostHog | Product analytics and feature flags, not currently active. PostHog is integrated in the app but is not configured in production, and receives no events or identifiers from us at this time. It is listed here because it is present in the code, not because it is currently receiving your data. |
| Anthropic (Claude) | Content moderation, second review. Built in, not currently enabled. A context-aware second review by Anthropic's Claude is wired into our moderation code. It would receive the text of a prayer whose automated score was borderline, to reduce false positives: prayers about death, illness and grief are expressions of faith, not harm, and an automated score alone reads them badly. That escalation is switched off, and no prayer text has been sent to Anthropic. It is listed here because the integration exists and a configuration change would enable it, and we would update this policy before making that change. Were it enabled, the content sent would not be used to train their models. |
| Vercel | Website hosting |
YouTube API Services
PrayerMap uses YouTube API Services to discover and play spiritual content. By using PrayerMap, you are also bound by:
- YouTube Terms of Service — https://www.youtube.com/t/terms
- Google Privacy Policy — http://www.google.com/policies/privacy
You can revoke PrayerMap's access to your data via the Google security settings page at https://security.google.com/settings/security/permissions.
YouTube Data We Store
- Video metadata — Title, description, thumbnail URL, duration, channel name, and video ID are cached server-side to power content discovery and recommendations.
- User engagement data — When you interact with YouTube content (play, complete, like, save, skip, or share), those interactions are logged in your
user_content_interactionsrecord to improve personalization. - Automated refresh — Cached metadata is refreshed every 6–48 hours via automated background jobs to keep content accurate and up to date.
- Data retention — YouTube content metadata that has not been refreshed for 30 days and is not part of an active collection is automatically deleted (see Data Retention below).
YouTube Data We Do NOT Access
- We do not access your YouTube account, subscriptions, watch history, or any personal Google data.
- Video playback is handled entirely through YouTube's embedded player — we do not download, cache, or re-host any video or audio content.
Data Retention
- Account data — Retained while your account is active, deleted within 30 days of account deletion
- Prayers and responses — A prayer stops appearing on the map 30 days after you post it. It is hidden at that point, not deleted: the prayer stays in your account, because your own prayer history is yours to keep and returning to a prayer that was answered is part of why people use PrayerMap. It is deleted when you delete the prayer, or when you delete your account
- Memorial lines — The connecting lines drawn on the map between people who have prayed together are displayed for 1 year. This is how long the lines are shown, not how long a prayer is kept
- Messages — Retained until you delete them or delete your account
- Friend connections — Retained until you remove the connection or delete your account
- Group file attachments — Retained for the lifetime of the group or until deleted by a group administrator
- Voice/video room data — NOT stored; transmitted in real-time only
- Contact hashes — Retained until you revoke sync via Settings
- Usage analytics — Crash reports and performance metrics are retained while they remain useful for diagnosing a fault, and are not tied to a fixed schedule
- College verification — Retained while your account is active
- Apple Watch data — Synced data on the watch follows the same retention as the source data on your iPhone
- AR camera data — NOT stored; processed on-device in real-time only
- YouTube content metadata — Automatically deleted 30 days after last refresh if not in an active collection
Your Rights
- Access — Request a copy of your data at contact@prayermap.net
- Data Export — Request a portable copy of your data in a machine-readable format at contact@prayermap.net
- Correction — Update your profile in the app
- Deletion — Delete your account via Profile > Settings > Delete Account
- Notifications — Manage push notification preferences in device settings or disable them entirely
- Consent Withdrawal — Revoke consent for sensitive data processing (religious preferences) at any time via Profile > Spiritual Lens
Sensitive Personal Data (GDPR Article 9)
PrayerMap processes certain categories of sensitive personal data with your explicit consent:
- Religious/Spiritual Preferences — Your tradition preference (e.g., Christianity, Judaism, Islam) is classified as special category data under GDPR Article 9
- Prayer Content — The prayers you write are themselves capable of revealing religious belief, and we treat them as special category data under Article 9 on the same basis
- Legal Basis — Processed only with explicit consent per GDPR Article 6(1)(a) and Article 9(2)(a)
- Right to Withdraw — You may withdraw consent at any time without affecting the lawfulness of processing based on consent before withdrawal
- No Automated Decision-Making — Your sensitive personal data will not be used for profiling or automated decision-making that produces legal effects
Legal Basis for Processing (GDPR)
For users in the European Economic Area (EEA), PrayerMap processes your data based on:
- Explicit Consent (Article 6(1)(a)) — You provide consent via the per-prayer "Show on Map" toggle and during onboarding
- Explicit Consent (Article 9(2)(a)) — For processing special category data (religious beliefs) via the Spiritual Lens onboarding
- Legitimate Interest (Article 6(1)(f)) — For providing the core location-based prayer service
You have the right to withdraw consent at any time by hiding your prayers from the map, changing your spiritual preferences, or deleting your account.
California Privacy Rights (CCPA)
If you are a California resident, you have additional rights under the California Consumer Privacy Act:
- Right to Know — Request disclosure of personal information collected about you
- Right to Delete — Request deletion of your personal information
- Right to Opt-Out — PrayerMap does not sell personal information
- Right to Limit Use of Sensitive Personal Information — PrayerMap allows you to limit how your sensitive personal information (including religious beliefs) is used via Profile > Spiritual Lens settings
- Non-Discrimination — Exercise your rights without discriminatory treatment
To exercise these rights, contact us at contact@prayermap.net.
Data Portability
You have the right to receive a copy of your personal data in a structured, commonly used, machine-readable format. You can download everything we hold about you at any time from Profile › Download My Data in the app. It arrives as a JSON file you can keep or move elsewhere. A few records are deliberately left out and the file names each one and why — security credentials, the secret used to offset your location, and data belonging to other people. If you think something is missing, email contact@prayermap.net.
Content Moderation
Automated Content Screening
To maintain a safe and respectful community, prayers are automatically screened. Screening does not cover everything, and it does not happen before a prayer appears, so this section sets out exactly what it does:
- Prayer text and images are screened by OpenAI's moderation service, which receives the text and images you post
- Screening runs shortly after a prayer is posted, not before it appears. A recurring job picks up new prayers and screens them, rather than a check standing between you and posting, so a prayer can appear in the app before it has been screened. The public website is stricter: a prayer's words appear there only once screening has approved it
- Voice and video prayers are first sent to Cloudflare's Workers AI service to produce a transcript, which is then screened in the same way. Where no transcript can be produced, the prayer is left unapproved rather than treated as having passed
- Prayer responses and private messages are not automatically screened. They remain subject to user reporting and human review, both described below
- Screening detects potentially harmful, inappropriate, or policy-violating content, and helps identify content that may indicate self-harm or a crisis situation
- A second-opinion review by Anthropic's Claude is built into our moderation code but is switched off. It would send borderline prayer text for a context-aware review, to reduce false positives. It is not enabled, and no prayer text has been sent to Anthropic. If we enable it, we will update this policy first
- Content sent to these providers is not used by them to train their models
User Reporting
PrayerMap allows users to report content that violates our community guidelines. When you submit a report:
- Your identity as the reporter is kept confidential from the reported user
- Reports submitted from the PrayerMap app are reviewed by our moderation team via our admin dashboard. Reports submitted from the prayermap.net website are sent by email to contact@prayermap.net instead — they reach our team but do not create a dashboard record
- Reports of self-harm concerns include access to crisis resources (988 Suicide & Crisis Lifeline)
Human Review
Our moderation team at admin.prayermap.net reviews flagged content and user reports to:
- Make final decisions on content that requires human judgment
- Respond to user reports and appeals
- Enforce our community guidelines
- Comply with legal obligations
- Protect the safety of our users
Data Security
We implement encryption in transit (TLS/HTTPS), encryption at rest, and row-level security on our database tables. Row-level security is enabled on every table that holds your data. The location offset is enforced on our servers rather than trusted to the app, and a prayer whose location cannot be offset is refused rather than stored. We review our security posture periodically and when we make significant changes; we do not claim a fixed audit schedule or third-party certification. No method of transmission or storage is completely secure, so while we work to protect your information we cannot guarantee absolute security.
Children's Privacy
PrayerMap is restricted to users 18 years of age or older. You confirm that you meet this requirement when you create an account, and our Terms of Service reserve the right to terminate accounts of users who misrepresent their age. Our App Store listing carries a 17+ age rating, so the listing alone does not establish the 18 requirement; the confirmation at sign-up is what does. We do not knowingly collect personal information from individuals under 18. If we discover that a user is under 18, we will promptly delete their account and associated data.
Changes to This Policy
We may update this policy as PrayerMap changes. When we do, we update the effective date at the top and record what changed in the revision history below. If a change materially affects your rights, we will ask you to review it in the app before you continue using PrayerMap, rather than relying on you to revisit this page.
Changes to Our Service Providers
We may add, replace, or remove the providers listed above as PrayerMap changes. When we do, we update that list and note it in the revision history. We do not add a provider that receives your prayers, messages, or media without saying so here.
If There Is a Data Breach
If a security incident affects your personal information and is likely to put your rights at risk, we will notify the relevant supervisory authority and the people affected, within the timeframes applicable law requires of us. We will tell you what happened and what you can do, rather than only what we are obliged to disclose.
International Data Transfers
PrayerMap and the providers listed above operate in the United States. If you use PrayerMap from outside the United States, your information is transferred to and processed in the United States, which may have data-protection laws that differ from those in your own country. Where a provider acts as our processor, that processing is governed by a data processing agreement with them.
Links and Embedded Content
PrayerMap links to and embeds content we do not control — YouTube videos, Apple Music, and external crisis-support directories among them. This policy covers PrayerMap only. When you follow a link or play embedded media, that provider's own privacy policy governs what they collect.
Raising a Concern
If you are unhappy with how we have handled your information, please tell us at contact@prayermap.net so we can put it right. You do not have to come to us first. If you are in the European Economic Area or the United Kingdom you have the right to lodge a complaint with your local data protection authority, and if you are in California you may contact the California Privacy Protection Agency.
Revision History
August 29, 2026. This revision removes a description of analytics we do not collect, and corrects our description of automated content screening. It narrows what this policy claims; it does not expand what we collect.
- We described a retention and aggregation lifecycle for analytics that are not collected. The Data Retention section promised that usage analytics were "aggregated and anonymized after 90 days" and that behavioral analytics events were "retained for 90 days, then aggregated." No such events are being recorded: the event store is empty, and nothing aggregates or deletes on that schedule because there is nothing in it. Describing a lifecycle for data that does not exist told you we hold more about you than we do. Both lines have been removed, and the remaining entry describes crash and performance diagnostics accurately.
- PostHog is not receiving your data. Section 8.1 said "PostHog receives anonymized usage events and device identifiers." It is integrated in the app but is not configured in production and receives nothing. Section 8.1 and the service provider table now say so. PostHog stays listed because the integration is present in the code, and we would rather name a provider that could receive data than quietly drop it from the list.
- Section 8.1 now states plainly that the behavioral event pipeline is inactive. The section previously read as a description of something running.
- We said prayers were screened before they appear. They are screened shortly after. Screening runs on a recurring job rather than as a gate at the moment of posting, so a prayer can appear in the app before it has been checked. The public website already behaved as this policy described, showing a prayer's words only once screening has approved it. The Content Moderation section now describes both.
- We said every prayer, response, and image was screened. Responses and messages are not. Automated screening covers prayers. Prayer responses and private messages are not automatically screened, and rely on user reporting and human review. Claiming otherwise described more protection than we actually provide, which is the more serious direction for an error of this kind. It has been corrected in the Content Moderation section and in the service provider table.
- Section 2.5 described three things in your browser that are not there, and omitted the one that is. It claimed a sign-in session, a record of your age and Terms acceptance, and a cached copy of the map. We checked a real browser: none of the three exists, and this website has no account sign-in at all. What is stored is map telemetry written by Mapbox, which the section had not mentioned. It now describes what is actually there, and what is not.
- We cited our App Store listing as establishing an 18+ restriction. It carries a 17+ rating. The age requirement itself is unchanged and is real: you confirm you are 18 or older when you create an account, and that confirmation is what establishes it. The Children's Privacy section previously pointed at the App Store listing as the evidence, and the listing does not say 18. It now names the sign-up confirmation instead and states the listing's actual rating.
- No prayer text has been sent to Anthropic. This policy said content with a borderline score was sent to Anthropic's Claude for a second review. That escalation is built into our moderation code but has never been switched on. The service provider table now describes it as built in and not enabled, and Anthropic remains listed because the integration exists and a configuration change would activate it. The August 16, 2026 entry below, which introduced the description we are correcting, has been annotated rather than rewritten.
August 28, 2026. This revision records a change that increased privacy protection, corrects an overstatement of what we collect, discloses public-facing behavior that already existed but had not been described, and credits content we already publish.
- Turning nearby-prayer alerts off now erases the position we hold for you. In build 159 and later, switching off nearby-prayer alerts — or notifications as a whole — deletes that stored position, and no new one is stored while either is off. On earlier builds, switching notifications off stopped the position being updated but did not by itself erase it. Section 2.1a now describes both, and you can still email us to have it removed on any version.
- We overstated the precision of the position we store for nearby alerts. Section 2.1a said that position was not offset and was your actual position. It is rounded to two decimal places before it is stored, which is roughly a kilometre — a figure we give as an estimate rather than a guarantee, since the exact distance varies with latitude. The rounding happens on our servers as well as in the app, so it applies on every version, including older ones. The section now says so.
- The public, no-account view of the map is now described. Signed-out visitors to prayermap.net have always been able to see the shape of the map — offset points and prayer connections — with no account required. That was not previously stated in this policy. Section 2.4 now describes exactly what a signed-out visitor can and cannot see.
- Browser storage is now described. Section 2.5 now states what the website stores in your browser and why.
- Scripture quotations are now credited. The daily devotional publishes verse text from the ESV® Bible. That translation's required credit now appears on this page.
- Four sentences were corrected against the live site. Section 2.5 said browser storage held two things; it holds a third, a record of the age/terms acceptance this same revision introduced, and now lists all three. Section 2.4 said a name is never shown to a signed-out visitor, which contradicted the bullet immediately below it describing when a name is shown by consent; the first sentence now points to the second instead of overriding it. The User Reporting section said all reports are reviewed via our admin dashboard; reports submitted from this website are emailed to our team instead and do not create a dashboard record, and the section now says so.
- Section 2.4 now covers two things besides the map. A signed-out visitor can also see a discoverable group's name, description, member count and location label, and the day's devotional verse, reflection and prayer prompt. Both were already true; the section's heading has always asked the broader question, and it now answers it in full.
August 27, 2026. This revision names the providers that process your content, and corrects a description of where location offsetting happens. Nothing in this revision expanded what we collect or how we use it.
- The location offset is applied on our servers, not on your phone. The previous wording said the offset happened on your device and that your precise coordinates were never transmitted. That described an earlier design. Offsetting moved to our servers because a device-side offset cannot protect anyone running a modified app and could be reversed; the server version uses a per-account secret no app can derive and refuses to store a prayer it cannot offset. Your precise coordinates are still never stored — but they are transmitted to us, over an encrypted connection, to be offset. That sentence has been corrected.
- The providers that screen your content are now named. OpenAI performs first-pass moderation and receives the text and images you post. Cloudflare transcribes voice and video prayers so they can be screened. Resend delivers our email. TheHive.ai is described as the standby transcription provider it now is, rather than as the active screener.
- How long prayers are kept is described accurately. The previous policy said prayers were retained for 1 year. That conflated two different things: a prayer stops appearing on the map after 30 days, and the memorial lines drawn between people who prayed together are displayed for 1 year. Neither was a deletion schedule — prayers are kept until you delete them or your account, which is deliberate, because your own prayer history is yours. The wording now says that.
- Analytics and tracking were removed from this website. Google Tag Manager and a visitor-identification tracker were loading on our pages, including this one, and were not disclosed. Both have been removed from every page.
August 16, 2026. This revision corrects descriptions that no longer matched how PrayerMap works, and records changes that increased privacy protection. Nothing in this revision expanded what we collect or how we use it.
- Location offset is now guaranteed and universal. A previous feature could display prayers posted at recognised public places (churches, parks, hospitals) at their true coordinates. That feature has been removed entirely, and the offset is now applied to every prayer with no exception. The offset is also now at least 1 kilometer. It is applied on our servers before storage — see the August 27, 2026 entry above, which corrects this sentence.
- Exact prayer coordinates are no longer stored. The previous policy said your exact location was retained and visible to you alone. It is not retained at all any more, so that statement has been removed as inaccurate.
- Anonymous prayers no longer carry your account identifier. Previously the identifier accompanied anonymous prayers even though your name was hidden. It is now withheld from other users entirely, while remaining available to our moderation team for safety and legal compliance.
- Corrected our description of AI processing. We previously described Anthropic's Claude as performing behavioural analysis on aggregated patterns. That was wrong in both directions: our behavioural analysis uses no AI service at all, and Claude is instead used to review flagged prayer content during moderation. The entry now says so. Corrected again on August 29, 2026: the replacement was also wrong. The Claude escalation has never been enabled and no prayer content has been sent to Anthropic. See the August 29, 2026 entry above.
- Plainer description of contact hashing. Our previous wording implied that hashing made uploaded phone numbers unknowable to us. It does not, and we now say so directly.
- Account deletion now removes uploaded files. Voice and video prayers, avatars and attachments are now deleted along with your account data.
- Security wording. We removed a claim of "regular security audits" in favour of describing the controls we actually operate.
Contact Us
If you have questions about this Privacy Policy, please contact us at:
Email: contact@prayermap.net
Website: https://prayermap.net
