Skip to content
Ardent Word

Legal

Privacy policy

This describes what Ardent Word actually does with information about you. It is written from the system’s own data inventory rather than from a template, which is why it names specific providers and specific retention periods instead of saying “may” a great deal.

Last updated
16 September 2026
Status
Draft, pending legal review

Before you rely on this

This is a draft. It is published now so the commitments in it can be read and challenged before anything is built on top of them. It is reviewed by a qualified lawyer, and finalised against the code as shipped, before Ardent Word is submitted to either app store.

Who is responsible for your information

Ardent Word is a project founded, developed and funded by Mawuli Dzaka under the Ardent Africa Foundation. The Foundation is the data controller: it decides what is collected and why, and it is the organisation you can hold to this policy.

The Foundation’s contact details for privacy questions are published on the support page before release.

Four commitments that shape everything below

  1. Your prayers are not our product. Prayer journals, prayer requests and Emmaus conversations are treated as sensitive religious information. They are encrypted, excluded from analytics, and never used to train a model, by us or by anyone we send data to.
  2. We do not sell or share your data. Not to advertisers, not to data brokers, not for tracking you across other companies’ apps or websites. There is no advertising in Ardent Word and there never will be.
  3. We collect what a feature needs and nothing beyond it. We do not collect your location, your contacts, your browsing history, sensor health data or an advertising identifier. Dictation is processed on your device. What you type into the reader’s search box stays on your device.
  4. You can take it all with you, and you can end it. Export and deletion are available in the app and from this website, without asking us and without speaking to anyone.

What we collect, and why

Grouped by purpose. The short version is that everything here exists because a feature you use needs it.

To give you an account

InformationWhy we have itHow long we keep it
Account identifier and sign-in providerTo know it is you when you sign in, and to sync your writing between your devices.For as long as your account exists.
Email addressSign-in, receipts, and replying to you when you contact support.For as long as your account exists. Afterwards we keep only an irreversible hash, so that a deleted account is not accidentally re-created or emailed again.
Display name, avatar and short bioSo other people can see who is praying with them.For as long as your account exists.
Year of birthTo apply the minimum age for your country, and to set safer defaults for members under eighteen. We ask for the year only, never the full date.For as long as your account exists.
Country, language and time zoneTo show the right crisis resources, send notifications at a sensible hour, and pick the right content language.For as long as your account exists.

To let you read, study and pray

InformationWhy we have itHow long we keep it
Bookmarks, highlights, notes, reading plans and progressThey are the point of the app, and they follow you to a new phone.Until you delete them, or delete your account.
Your prayer journal and its attachmentsSo you can keep and return to what you have written.Until you delete it. Encrypted at rest with a key belonging to your account.
Emmaus conversationsTo answer your question, to keep the thread readable afterwards, and to act on a safety concern where one appears.Until you delete them, or delete your account. Encrypted at rest.
Your optional faith backgroundTo answer doctrinal questions in a way that is useful to you rather than generic.Until you change or clear it.
Reading and engagement signalsTo make the app’s suggestions personal rather than random: what you have been reading, where you left a plan.Individual events for 90 days. A daily summary profile is kept while the feature is on.

To let you pray with other people

InformationWhy we have itHow long we keep it
Prayer requests, group posts, responses and images you shareTo show them to the people you chose to show them to.Until you delete them. Moderation records are kept as described in the community standards.
Reports you make about other people’s contentTo act on them. Your report is private and encrypted, and the person you report is never told who reported them.As long as the moderation record is kept.

To keep the service running and honest

InformationWhy we have itHow long we keep it
Device information: platform, app version, push token, attestation key identifierTo deliver notifications and to confirm that requests come from a real copy of the app rather than a script.While the device record exists.
Product analytics without contentWhich screens and features are used, so we can improve them. Never what you wrote, asked or prayed.Twelve months.
Crash reports and performance tracesTo fix the crashes. No user identifier is attached.Provider default retention.
Security records: sign-up checks, rate limit events, abuse events, IP addresses in server logsTo stop abuse and to investigate it when it happens.30 to 90 days.
Consent recordsTo show what you agreed to and when.Life of the account plus three years.

If you give

InformationWhy we have itHow long we keep it
Your name and email, the amount, the channel, the card brand and last four digits, and any recurring authorisationTo process the gift, send you a receipt, keep proper accounts and prevent fraud. We never see or store your full card number or your mobile money PIN; the payment processor handles those.Seven years, because financial records have to be kept.

What we deliberately do not collect

Precise or approximate device location. Your contacts. Your browsing history. Health data from sensors. Advertising identifiers. Dictation audio, which is processed on your device and never sent to us. What you type into the reader’s search, which is answered from the copy of the Bible on your phone.

Private prayer requests are never read by the automated moderation check and never by a person at the Foundation. Only content you choose to share with a group or with everyone is checked before it appears.

Emmaus, in particular

Emmaus is the study companion in the app. When you ask it something, your question and the recent thread are sent to Anthropic, which runs the model that composes the answer. Anthropic processes it on our behalf under a contract and does not use it to train models.

  1. Your conversations are encrypted at rest with a key belonging to your account, not one key that opens everything.
  2. They are never used to train a model, by us or by anyone in the chain.
  3. They never appear in a product analytics payload, in any form.
  4. An administrator can reach them only through a path that requires a stated reason and writes an entry to an audit log that cannot be quietly edited.
  5. Retrieval queries sent to the embedding provider are stripped of personal circumstances by design.
  6. Your prayer journal is not sent to Emmaus at all, unless you turn on journal themes, which is off by default and explained where you turn it on.

Who else processes your information

These are service providers acting on the Foundation’s instructions under contract. None of them may use your information for their own purposes.

ProviderWhat they doWhat they see
SupabaseDatabase, sign-in, file storageMost stored data, encrypted where this policy says so
Fly.ioRuns the backendData in transit through the backend
CloudflareMedia storage, DNS, and the anti-bot check on formsGenerated audio, exports, backups, form challenges
VercelHosts this website and the internal admin appWebsite form submissions in transit
AnthropicRuns the model behind Emmaus, the safety classifier and community moderationEmmaus conversations, shared community content
PaystackProcesses paymentsYour card or mobile money details, which we never see
ResendSends transactional emailYour email address and receipt contents
PostHogProduct analytics, hosted in the EUContent-free feature events under a pseudonymous identifier
Firebase CrashlyticsCrash reportingCrash traces, with no user identifier attached
Apple and GooglePush notifications and device attestationDevice tokens and attestation results

Nothing here is sold, shared for advertising, or used to track you across other companies’ apps and websites.

Where your information is held

The database is hosted in Europe, because no major managed provider offers an African region for it. Some providers process data in the United States. Where information leaves your country, it travels under the safeguards those providers offer, which are named in full in the final version of this policy after legal review.

Why we are allowed to hold it

Where the law asks us to name a basis, ours are: performing the agreement with you for anything that makes the app work; your explicit consent for information that reveals religious belief, which covers your journal, your prayer requests and your Emmaus conversations; our legitimate interest in keeping the service secure and free of abuse; and legal obligation for financial records and for child safety reporting.

Consent that you gave you can withdraw. Withdrawing it stops the feature it relates to rather than ending your account.

What you can do

  1. See it. Ask for a copy of what we hold about you.
  2. Take it. Export your notes, highlights, journal and conversations in a portable format, from the app.
  3. Correct it. Change your profile and settings in the app at any time.
  4. Delete it. Delete individual items, or your whole account, from the app or from this website without needing the app installed. Deletion is real: your content is removed and backups age out on their normal cycle. Financial records and child safety reports are kept where the law requires it.
  5. Object, restrict, or complain. Ask us to stop a particular use, and complain to your data protection authority if we have not put something right.

Children and young people

Ardent Word is for people aged thirteen and over, and the minimum is higher in countries whose law sets it higher. We ask for a year of birth at sign-up and apply the minimum for your country.

Members aged between thirteen and eighteen get stricter defaults: new prayer requests start visible to a group rather than to everyone, the bio is hidden, and age is never shown to other members. Our standards against child sexual abuse and exploitation are on the child safety page.

How it is protected

Sensitive content is encrypted at rest with per-account keys, which are themselves wrapped by a managed key service. Everything is encrypted in transit. Every request that writes your data is authenticated and attested, and the database enforces row level security so that one account cannot reach another’s rows even if something above it is wrong.

Administrator access to personal content requires a stated reason and is written to a hash-chained audit log. No system is perfect, and if a breach affects you we will tell you and the relevant authority within the time the law allows.

Changes to this policy

The version and date are at the top. When something material changes we will tell you in the app rather than quietly updating the page, and we keep the previous versions available.