App Privacy Policy
1. Who is responsible
The controller responsible for the “Prayer Stone” iPhone app under the EU General Data Protection Regulation (GDPR) is Christian Kasper. For any privacy question you can reach us at prayerstoneapp(at)proton(dot)me. The website prayerstone.app has its own privacy policy.
2. No account, no profiles
The app works without any registration. We do not run a server that stores user data, we do not build user profiles, and we do not show advertising. We never sell or rent data to third parties.
3. Data on your device
Everything you do in the app is stored locally on your iPhone: your first name for the greeting (optional), your favourites, your prayer history, your streaks and reminders, your Bible bookmarks and your settings (background, voice, sound). This data is never sent to our systems. You can remove it at any time by deleting individual entries or uninstalling the app.
4. iCloud sync
So that your favourites, history, streaks and bookmarks survive a new device, they are synced through Apple’s iCloud (key-value storage) tied to your personal Apple ID. This data lives in your iCloud account and is processed by Apple under Apple’s privacy terms; we have no access to it. Syncing follows your iCloud settings in iOS.
5. Anonymised usage analytics
We collect anonymised product-interaction data: the event that the app was opened; the event that a prayer was started (with the prayer’s id and the voice and background sound chosen for it); and the coarse local time of these events (hour and weekday). From this we understand which prayers help the community (the app’s “Popular” ranking), which voices and sounds people value — guiding which new content we produce — and how often the app is used overall. This data is not linked to your identity: instead of a name or identifier, only a one-way encrypted (hashed) device value is transmitted, which neither we nor anyone else can trace back to you, and which changes if you reinstall the app.
We use TelemetryDeck (TelemetryDeck GmbH, Berlin, Germany) for this — a privacy-first analytics service that anonymises signals and processes them in the EU in a GDPR-compliant way. No advertising identifiers are used and there is no tracking across apps or websites. The legal basis is our legitimate interest in improving the app (Art. 6(1)(f) GDPR).
6. Attribution measurement (AppsFlyer)
To understand which of our own marketing campaigns — above all Apple Search Ads — lead to installs, trial starts and Plus subscriptions, the app uses AppsFlyer (AppsFlyer Ltd.), a mobile measurement service. The following is shared with AppsFlyer: a device identifier (Apple’s Vendor Identifier/IDFV and an AppsFlyer-generated install ID — not Apple’s advertising ID/IDFA, which the app never accesses); install, first-launch and session events; conversion events (the start of the free trial, the purchase of a subscription including price, currency and the chosen plan, and the completion of a multi-day challenge); and limited technical details such as device model, iOS version and an approximate region derived from your IP address.
AppsFlyer processes this data on our behalf as a data processor; we use it solely to measure the effectiveness of our own advertising. No advertising profiles are built about you and no data is sold. The app shows no App Tracking Transparency prompt because it does not access the IDFA and does not track you across other companies’ apps or websites. Processing may take place on servers in the EU and the USA; transfers are safeguarded by EU standard contractual clauses and, for Israel, by the EU adequacy decision. The legal basis is our legitimate interest in measuring our own marketing (Art. 6(1)(f) GDPR). AppsFlyer’s handling of data is governed by its Services Privacy Policy.
7. Content delivery
Prayer texts, audio recordings and the popularity ranking are loaded from the internet so new content can appear without an app update. When content is fetched, the hosting provider (content delivery network) technically processes your IP address, as with any internet request. We ourselves receive no personal data from this and store no IP addresses.
8. Purchases (Prayer Stone Plus)
The Plus subscription is handled entirely through Apple’s App Store. Apple processes your payment details; we never receive your name, address or payment information. The app checks locally through Apple’s StoreKit whether a valid subscription exists. In addition, the app reports the event of a trial start or purchase (with price, currency and plan — never payment details) to AppsFlyer, for the advertising measurement described in Section 6.
9. Notifications
Reminders (e.g. prayer times, challenge days, the daily verse) are local notifications: they are scheduled and triggered on your device with no server involved. They only appear if you allow notifications, and can be switched off at any time in the app or in iOS Settings.
10. Your rights
Under the GDPR you have the right to access, rectify, erase, restrict and port your data, and to object to processing. Our usage statistics (Section 5) are anonymised — we cannot find you in them. The attribution data (Section 6) is pseudonymous and linked to no name; you can object to this advertising-measurement processing at any time (Art. 21 GDPR) by writing to us. In practice your rights mainly concern data on your device (deletable in the app or by uninstalling) and your iCloud (managed through your Apple ID). For any question, email prayerstoneapp(at)proton(dot)me. You also have the right to lodge a complaint with a data protection supervisory authority.
California residents have comparable rights under the CCPA; we do not sell or share personal data.
11. Children
The app is intended for a general audience. We do not knowingly collect personal data from children.
12. Changes
We may update this policy when needed, for example when new features are added. The current version, with its date, will always be available on this page.