Privacy Policy
Last updated September 21, 2026
Your words are never public without your say-so, never indexed, and never sent anywhere you didn’t send them yourself.
That’s the whole policy in one sentence. The rest of this page explains what it means in practice, because on a service where people write about their mother’s illness, “we take your privacy seriously” isn’t good enough. You should be able to check.
1. Why this page reads differently
Prayer apps have a bad record. One’s published list of vendors left out three advertising companies it was actually sending data to. One described its members’ personal information as a business asset. We’re a two-person company, and good intentions are not a safeguard. What we can do is build the thing so that those failures aren’t available to us, and then describe the structure — so you’re trusting the design, not our word.
We treat what you write as sensitive under both California law and the European GDPR — whichever gives you more — and we build to the stricter of the two. If your browser sends a Global Privacy Control signal, we load no analytics for you at all.
We use PostHog to understand how the site is used: which pages people open, where they get stuck, what they click. It never sees a prayer, a response, a draft or your name. Session replay is masked before it leaves your browser — what we can see is the shape of the page and where you moved, not what anyone wrote. And we do not tell PostHog who you are, so it cannot build a picture of you across visits.
2. What we collect
What you give us
- Your email address, so you can sign in and so we can send you the emails you’ve asked for.
- The name you choose to show. It doesn’t have to be your real one.
- Your country, if you tell us. We use it for one thing: choosing which support services to show you if a post looks like you’re in crisis. Nothing else.
- What you write: prayers and responses.
- Reports you make about someone else’s post, and the few words you add to them.
What the service records on its own
- The usual technical record that any website keeps: your IP address, browser, and the time of each request. We keep it for security — spotting attacks and abuse — and for nothing else.
- The results of automated screening on each post and comment (see §4).
What we don’t collect
- We don’t ask for your real name, your address, your phone number, or your date of birth. We ask you to confirm you’re 18 or older, and that’s all.
- We don’t collect your location. Your country is something you tell us, not something we work out.
3. Who sees what you write
Every signed-in member. There is no public board, no search engine can reach your words, and no “discover” feed surfaces them to strangers. Finer control over who sees what is on our roadmap, and is not built yet.
Two more people can see a post: the two of us, when a post is flagged for a human to read (§4). We read what we have to and nothing more, and we don’t discuss it with anyone.
When group spaces exist, group owners will be able to see and moderate posts in their own group. They won’t be able to see anything outside it, and they will never see the crisis screening described in §4.
If a post is set aside for a person to read, you can still see your own words — it is hidden from other people, never from you.
You can’t make a post narrower once people have replied to it. That’s deliberate: someone who responded did so in a room of a certain size, and we won’t quietly shrink the room around them.
4. Automated screening, and the people behind it
Every post and comment is checked automatically the moment you write it, by one classifier — named on Specs & services. It looks for content that breaks the ground rules. We won’t describe exactly what it looks for, because publishing that would tell people how to route around it.
Then a person reads it. Not just the flagged ones — all of them. That’s how it works while we’re small, and we’d rather tell you than have you wonder.
Some things worth knowing about this:
- The automated check is not a judgment about you. It’s a net. It catches ordinary grief and ordinary lament all the time, and a person sorts that out.
- It works best in English. Its Spanish is being checked by Spanish-speaking crisis specialists. In other languages, it catches very little on its own, and a person reading is what catches things.
- The classifier is run by a third party (see §9). It reads the post to screen it, returns a result, and that’s the end of its involvement. The endpoint we use keeps no copy of what we send it — not for thirty days, not at all — and nothing is used to train anyone’s models.
- We used to plan a second check, by a language model, for posts that looked like someone might be in crisis. It isn’t running. That company’s terms allow them to keep flagged messages for up to two years, and the posts we’d have sent are exactly the ones most likely to be flagged. We’d rather a person read those than hand them to someone who might keep them that long.
- We don’t identify, predict, or assess anyone’s risk of self-harm. We flag posts for a person to look at and we show information about services that can help. That’s the full extent of it. The details are in our Crisis Response Policy.
5. What we do with all this
| We use | To |
|---|---|
| Your email | Sign you in; send you the emails you’ve turned on; nothing else |
| Your display name | Show your posts to other members |
| Your country | Choose which crisis-support services to show you |
| What you write | Show it to other members; screen it as described in §4 |
| Reports | Put a post in front of a person sooner |
| Technical logs | Keep the service secure and working |
| Screening results | Let a person review flagged posts; measure whether the screening is working |
That’s the complete list. We don’t build a profile of you. We don’t infer your religion, health, or anything else from what you write and store it as a fact about you. We don’t use anything here to decide what to show you next.
6. Analytics and tracking
Two tools, both named on Specs & services: PostHog and Google Analytics. Two is one more than we want, and it’s temporary — we moved to PostHog in September and are running Google Analytics alongside it until the end of the year, to check the two against each other before we trust either. Then Google Analytics comes off.
Both record the same ordinary things: which pages were opened, roughly where from, what kind of browser and device. IP addresses are shortened before storage. Advertising features are switched off, and neither tool is told who you are, so neither can follow you between visits or build a picture of you.
PostHog can also record a session replay — a reconstruction of a visit, so we can see where a page confused someone. Two limits on it, and they’re the important part. It runs only on the public pages: the home page, the about and help pages, the sign-in screens. It is never switched on for the board, a conversation, the box you write a prayer in, or anything under your account. And every piece of text is masked in your browser before anything is sent — we get the shape of the page and where you moved, never the words. A replay also stops after twenty minutes.
If your browser sends a Global Privacy Control signal, neither tool loads at all — nothing is sent, and no analytics cookie is set. You don’t have to ask us; your browser already did. You can also just block analytics scripts with a content blocker. The site works fine either way.
No advertising or attribution SDK runs on PrayerGroup.Live, and we keep cookies to a minimum and never use them for advertising.
7. Your prayers are sensitive data, and we treat them that way
Under data-protection law in Europe and the UK, what you write here is “special category” data: it can reveal your religious beliefs, your health, and other things the law gives extra protection. Under the GDPR that’s Article 9, and it means we need your explicit consent to handle it, not just a general agreement to terms.
So, in plain words, when you post you’re agreeing to this:
I understand that what I write may reveal my religious beliefs, my health, or other sensitive things about me or the people I write about, and I’m choosing to share it with the other members of this community, screened as described in this policy.
You can withdraw that consent at any time by deleting the post, or your account. There’s no other reason we handle this content — no research, no training, no marketing — and if we ever wanted one, we’d have to come back and ask you first (see §8 and the Terms of Service, §2).
We ask you to keep other people in mind too. If you write about your brother’s diagnosis, that’s his health information. Write what you need to; just know that it’s his as well as yours.
8. AI, and your words
We don’t use what you write to train AI models today. We reserve the right to in the future. If we ever decide to, we’ll tell you before it starts, we’ll explain exactly what it would mean, you’ll have time to delete anything you don’t want included, and for the prayers themselves we’ll ask you rather than assume.
The screening in §4 is not training. The model reads your post to check it and keeps nothing.
9. The companies that touch your data
Everyone who processes your data on our behalf, with what they get and why, is listed on Specs & services — every entry there that receives anything about you says what it receives. If a company is not named there, it does not have your data.
We have signed data-processing terms with each of them. None of them may use your data for their own purposes. We’ll update that page before we add anyone, not after.
Nobody else. No data brokers, no advertising networks, no “partners.” We don’t sell your data, we don’t rent it, and we don’t trade it. Not now, not on the way out (see §12).
10. Deleting
A post. Delete it and it’s gone — from the board immediately, from our systems and backups within 30 days. If people had replied, an empty shell stays where your post was so their replies still make sense; your words are not in it.
Your account. Same thing, for everything: your posts, your responses, your email, the lot. Removed from every service in §9 and from backups within 30 days. Other people’s replies to your posts belong to them and stay; yours go.
Two things survive, on purpose, and we’d rather tell you than have you find out:
- A record that a moderation decision was made — what was decided, when, and a one-line reason. Never a copy of what you wrote. It’s kept because we have to be able to show that we act consistently, and because you can’t appeal a decision that no longer exists. Crisis-lane records are kept for up to 24 months; a scrambled fingerprint of the text is stored, from which the text can’t be recovered.
- A one-way scramble of your email address. Not the address itself — a fingerprint that can’t be reversed. Its only job is to stop anyone re-inviting you by accident after you’ve left. That’s all it can do.
One exception, required by law: if we’ve encountered material involving the abuse of a child, we’re required to preserve it and report it, and we do.
11. If something goes wrong
If we confirm a breach that affects your data, we’ll tell you within 72 hours of confirming it — you personally, not just a regulator. The law in most places requires us to tell the regulator in that window; we hold ourselves to telling you too.
12. If the company changes hands
If PrayerGroup.Live is sold, or Umunhum Labs is, this policy goes with it. Whoever takes over is bound by exactly these terms for everything already written here, and can’t loosen them for existing content. We’ll tell you before it happens, with enough notice to delete your posts or your account first if you’d rather they didn’t come along. What we won’t do is let your prayers become a line item in someone else’s deal without you knowing.
13. Adults only
You have to be 18 or older to use PrayerGroup.Live. That’s not a judgment about young people; it’s about what we can responsibly do. If we learn that an account belongs to someone under 18, we’ll close it and delete its data.
14. Your rights
Wherever you are, you can:
- See what we hold about you.
- Get a copy of what you’ve written, in a form you can take elsewhere.
- Correct your email or display name.
- Delete any post, or your whole account, yourself, any time.
- Ask us to do any of the above if you’d rather, and we’ll do it within 30 days.
- Complain to your data-protection regulator if you think we’ve got something wrong. We’d rather you told us first, but that’s your right either way.
And where an automated check has held your post, you can:
- Ask a person to look at it. A person already reviews every hold (§4) — but you can ask for another look, and you don’t have to accept a machine’s result.
- Tell us why we’ve got it wrong, in your own words.
- Challenge the outcome, and have that challenge decided by a person rather than a system.
If you’re in the EU, UK, or another place with data-protection law, those rights are yours in law as well as by our choice. Umunhum Labs LLC, San José, California, is the controller of your data.
15. Changes
We’ll date every change to this page and tell you before anything material takes effect — by email, not by silently editing the page and hoping you notice.
16. Contact
hello@prayergroup.live — we read every message. Put “privacy” in the subject and it gets to the front of the line.