Skip to content

Privacy policy

Last updated:

Items to complete before publishing: 7

PrayerNight is a mobile app for sharing prayer requests and material needs with communities, and for responding to them. This website, prayernight.org, presents it. This policy explains what data we process, why, on what legal basis, for how long, and what your rights are. It covers both the app and the website.

1. Who is responsible for your data?

The data controller is [À COMPLÉTER / TO BE COMPLETED: name or company name of the data controller, legal form and company number where applicable], [À COMPLÉTER / TO BE COMPLETED: full postal address].

For any question about your data or to exercise your rights: [À COMPLÉTER / TO BE COMPLETED: contact e-mail address].

2. The data we process

In the app

  • Your account: e-mail address, first name (or the name you choose to display), app language. Your password is never stored in clear: our authentication service only keeps a hash of it, and we do not know it.
  • Your requests: title, text, type (prayer or material need), status (open, answered), dates, and the communities you share them with. This content may reveal your religious beliefs, and sometimes other sensitive information (health, family situation…). It is special-category data under Article 9 of the GDPR: we only process it with your explicit consent (see section 3).
  • Your communities: communities you create or join, your role (member or leader), date joined, invitations and join requests, your personal invitation QR code.
  • Your interactions: the "I prayed" and "I can help" you give and receive. When you offer help, your message and the contact details you provide (phone or e-mail) are shown only to the person who made the request.
  • Moderation and safety: reports you make and people you choose to stop seeing.
  • Notifications: your device's technical notification identifier ("push token") and its platform (Android or iOS), plus a log of notifications sent, which stops us from notifying you twice.
  • Sessions: your sign-in tokens (stored only as a hash), their date and the type of device or browser used, to keep your account secure.
  • Camera: used only to scan an invitation QR code. No image is stored or sent.

The app contains no advertising, no analytics and no trackers.

On this website

  • News list (waitlist): if you sign up, your e-mail address, chosen language and the dates of sign-up, confirmation and, where relevant, unsubscription. Signing up takes two steps (double opt-in): you receive an e-mail with a confirmation link, valid 7 days; without confirmation, we do not write to you. We run this list ourselves, on our own servers; sign-ups previously collected by our former provider Brevo are moved into it and receive a single e-mail asking them to confirm again.
  • Technical logs: like any web server, ours records the IP address, date, requested page and browser of each visit, for security and troubleshooting. These logs are deleted after 30 days.
  • No tracking or analytics cookies, no third-party scripts: fonts and the form's anti-spam protection (ALTCHA, a small computation done by your browser) are self-hosted.
  • Donations are made on PayPal's website; PayPal processes your payment data as a separate controller under its own privacy policy. PayPal shares the donation details with us (name, e-mail address, amount, date).

3. Why, and on what legal basis?

  • Running the app (account, communities, interactions, notifications): performance of our contract with you, i.e. the terms of use (Article 6(1)(b) GDPR).
  • Processing your prayer requests, which may reveal your religious beliefs: your explicit consent (Article 9(2)(a) GDPR), given by ticking a box when creating your account; the account cannot be created without it. You can withdraw this consent at any time by deleting your requests or your account; withdrawal does not affect what was done before.
  • Keeping the service secure (sessions, technical logs, anti-spam, moderation, reports): our legitimate interest in protecting the app and its users (Article 6(1)(f)).
  • Sending you news about the app (news list): your consent (Article 6(1)(a)), given by confirming your address and withdrawn in one click with the unsubscribe link in every e-mail.
  • Handling donations: our legal obligations, in particular accounting (Article 6(1)(c)).

We do no profiling, no automated decision-making and no advertising.

4. Who can access your data?

  • In the app, a request is visible only to members of the communities you share it with, or only to you if you keep it in your private journal. Nothing about a community (members, requests) is visible before you are a member: this rule is enforced by the database itself, not just by the app. Community leaders see its members and, in moderated communities, requests awaiting approval.
  • Our processors, strictly for what their task requires:
    • Hetzner Online GmbH (Germany): server and database hosting, in the European Union.
    • Expo (650 Industries, Inc., United States): routes notifications to Google's (Firebase Cloud Messaging) and Apple's (Apple Push Notification service) delivery services, which deliver them to your device. They receive your device's push token and the notification text, which may include an excerpt of a request's title. This transfer outside the European Union is covered by [À COMPLÉTER / TO BE COMPLETED: applicable safeguard, e.g. the European Commission's standard contractual clauses or the provider's Data Privacy Framework certification].
    • OVH SAS (France): sending the app's e-mails (password reset codes, invitations) and the news list.
  • We never sell, rent or hand over your data to anyone.
  • Public authorities, only where the law requires it.

5. How long do we keep it?

  • Account and content: as long as your account exists. You can delete it at any time from the app (Profile → Delete my account). Deletion immediately erases your e-mail address, name, requests, interactions, push tokens and sessions. Communities where you were the only member are deleted; if you were a community's only leader, its longest-standing member becomes leader.
  • A deleted request is removed together with all its prayers and offers of help.
  • Sessions: at most 60 days after last use.
  • Invitation links: at most 14 days.
  • Website technical logs: 30 days.
  • News list: until you unsubscribe. We then keep only your address, the date and the "unsubscribed" status, so that we never write to you again. A sign-up that is never confirmed is never mailed.
  • Backups: deleted data disappears from backups as they rotate, at the latest after [À COMPLÉTER / TO BE COMPLETED: backup retention period].

6. Your rights

At any time you can:

  • access your data and get a copy — the app offers a full export in JSON format (Profile → Download my data);
  • correct it (your name and language can be changed directly in the app);
  • erase it, by deleting a request or your account;
  • restrict processing or object to it where it relies on our legitimate interest;
  • withdraw your consent, without affecting what was done before;
  • ask for data portability.

Write to us at [À COMPLÉTER / TO BE COMPLETED: contact e-mail address]: we reply within one month. If you believe your rights are not respected, you can lodge a complaint with the data protection authority of your country — in Belgium, the Data Protection Authority (www.dataprotectionauthority.be).

7. Security

Encrypted connections (HTTPS), passwords and tokens stored only as hashes, community isolation enforced by the database, server access limited to those who need it. No system is invulnerable: if a data breach puts you at risk, we will inform you and the competent authority within the legal deadlines.

8. Children

The app is not intended for children under [À COMPLÉTER / TO BE COMPLETED: minimum age, e.g. 16]. We do not knowingly collect data about them.

9. Changes

We may update this policy, for instance when the app changes. The date of the last update is shown at the top of this page; we will let you know in the app about any significant change.