Legal
Privacy policy
This describes what Ardent Word actually does with information about you. It is written from the system’s own data inventory rather than from a template, which is why it names specific providers and specific retention periods instead of saying “may” a great deal.
- Last updated
- 16 September 2026
- Status
- Draft, pending legal review
Before you rely on this
This is a draft. It is published now so the commitments in it can be read and challenged before anything is built on top of them. It is reviewed by a qualified lawyer, and finalised against the code as shipped, before Ardent Word is submitted to either app store.
Who is responsible for your information
Ardent Word is a project founded, developed and funded by Mawuli Dzaka under the Ardent Africa Foundation. The Foundation is the data controller: it decides what is collected and why, and it is the organisation you can hold to this policy.
The Foundation’s contact details for privacy questions are published on the support page before release.
Four commitments that shape everything below
- Your prayers are not our product. Prayer journals, prayer requests and Emmaus conversations are treated as sensitive religious information. They are encrypted, excluded from analytics, and never used to train a model, by us or by anyone we send data to.
- We do not sell or share your data. Not to advertisers, not to data brokers, not for tracking you across other companies’ apps or websites. There is no advertising in Ardent Word and there never will be.
- We collect what a feature needs and nothing beyond it. We do not collect your location, your contacts, your browsing history, sensor health data or an advertising identifier. Dictation is processed on your device. What you type into the reader’s search box stays on your device.
- You can take it all with you, and you can end it. Export and deletion are available in the app and from this website, without asking us and without speaking to anyone.
What we collect, and why
Grouped by purpose. The short version is that everything here exists because a feature you use needs it.
To give you an account
| Information | Why we have it | How long we keep it |
|---|---|---|
| Account identifier and sign-in provider | To know it is you when you sign in, and to sync your writing between your devices. | For as long as your account exists. |
| Email address | Sign-in, receipts, and replying to you when you contact support. | For as long as your account exists. Afterwards we keep only an irreversible hash, so that a deleted account is not accidentally re-created or emailed again. |
| Display name, avatar and short bio | So other people can see who is praying with them. | For as long as your account exists. |
| Year of birth | To apply the minimum age for your country, and to set safer defaults for members under eighteen. We ask for the year only, never the full date. | For as long as your account exists. |
| Country, language and time zone | To show the right crisis resources, send notifications at a sensible hour, and pick the right content language. | For as long as your account exists. |
To let you read, study and pray
| Information | Why we have it | How long we keep it |
|---|---|---|
| Bookmarks, highlights, notes, reading plans and progress | They are the point of the app, and they follow you to a new phone. | Until you delete them, or delete your account. |
| Your prayer journal and its attachments | So you can keep and return to what you have written. | Until you delete it. Encrypted at rest with a key belonging to your account. |
| Emmaus conversations | To answer your question, to keep the thread readable afterwards, and to act on a safety concern where one appears. | Until you delete them, or delete your account. Encrypted at rest. |
| Your optional faith background | To answer doctrinal questions in a way that is useful to you rather than generic. | Until you change or clear it. |
| Reading and engagement signals | To make the app’s suggestions personal rather than random: what you have been reading, where you left a plan. | Individual events for 90 days. A daily summary profile is kept while the feature is on. |
To let you pray with other people
| Information | Why we have it | How long we keep it |
|---|---|---|
| Prayer requests, group posts, responses and images you share | To show them to the people you chose to show them to. | Until you delete them. Moderation records are kept as described in the community standards. |
| Reports you make about other people’s content | To act on them. Your report is private and encrypted, and the person you report is never told who reported them. | As long as the moderation record is kept. |
To keep the service running and honest
| Information | Why we have it | How long we keep it |
|---|---|---|
| Device information: platform, app version, push token, attestation key identifier | To deliver notifications and to confirm that requests come from a real copy of the app rather than a script. | While the device record exists. |
| Product analytics without content | Which screens and features are used, so we can improve them. Never what you wrote, asked or prayed. | Twelve months. |
| Crash reports and performance traces | To fix the crashes. No user identifier is attached. | Provider default retention. |
| Security records: sign-up checks, rate limit events, abuse events, IP addresses in server logs | To stop abuse and to investigate it when it happens. | 30 to 90 days. |
| Consent records | To show what you agreed to and when. | Life of the account plus three years. |
If you give
| Information | Why we have it | How long we keep it |
|---|---|---|
| Your name and email, the amount, the channel, the card brand and last four digits, and any recurring authorisation | To process the gift, send you a receipt, keep proper accounts and prevent fraud. We never see or store your full card number or your mobile money PIN; the payment processor handles those. | Seven years, because financial records have to be kept. |
What we deliberately do not collect
Precise or approximate device location. Your contacts. Your browsing history. Health data from sensors. Advertising identifiers. Dictation audio, which is processed on your device and never sent to us. What you type into the reader’s search, which is answered from the copy of the Bible on your phone.
Private prayer requests are never read by the automated moderation check and never by a person at the Foundation. Only content you choose to share with a group or with everyone is checked before it appears.
Emmaus, in particular
Emmaus is the study companion in the app. When you ask it something, your question and the recent thread are sent to Anthropic, which runs the model that composes the answer. Anthropic processes it on our behalf under a contract and does not use it to train models.
- Your conversations are encrypted at rest with a key belonging to your account, not one key that opens everything.
- They are never used to train a model, by us or by anyone in the chain.
- They never appear in a product analytics payload, in any form.
- An administrator can reach them only through a path that requires a stated reason and writes an entry to an audit log that cannot be quietly edited.
- Retrieval queries sent to the embedding provider are stripped of personal circumstances by design.
- Your prayer journal is not sent to Emmaus at all, unless you turn on journal themes, which is off by default and explained where you turn it on.
Who else processes your information
These are service providers acting on the Foundation’s instructions under contract. None of them may use your information for their own purposes.
| Provider | What they do | What they see |
|---|---|---|
| Supabase | Database, sign-in, file storage | Most stored data, encrypted where this policy says so |
| Fly.io | Runs the backend | Data in transit through the backend |
| Cloudflare | Media storage, DNS, and the anti-bot check on forms | Generated audio, exports, backups, form challenges |
| Vercel | Hosts this website and the internal admin app | Website form submissions in transit |
| Anthropic | Runs the model behind Emmaus, the safety classifier and community moderation | Emmaus conversations, shared community content |
| Paystack | Processes payments | Your card or mobile money details, which we never see |
| Resend | Sends transactional email | Your email address and receipt contents |
| PostHog | Product analytics, hosted in the EU | Content-free feature events under a pseudonymous identifier |
| Firebase Crashlytics | Crash reporting | Crash traces, with no user identifier attached |
| Apple and Google | Push notifications and device attestation | Device tokens and attestation results |
Nothing here is sold, shared for advertising, or used to track you across other companies’ apps and websites.
Where your information is held
The database is hosted in Europe, because no major managed provider offers an African region for it. Some providers process data in the United States. Where information leaves your country, it travels under the safeguards those providers offer, which are named in full in the final version of this policy after legal review.
Why we are allowed to hold it
Where the law asks us to name a basis, ours are: performing the agreement with you for anything that makes the app work; your explicit consent for information that reveals religious belief, which covers your journal, your prayer requests and your Emmaus conversations; our legitimate interest in keeping the service secure and free of abuse; and legal obligation for financial records and for child safety reporting.
Consent that you gave you can withdraw. Withdrawing it stops the feature it relates to rather than ending your account.
What you can do
- See it. Ask for a copy of what we hold about you.
- Take it. Export your notes, highlights, journal and conversations in a portable format, from the app.
- Correct it. Change your profile and settings in the app at any time.
- Delete it. Delete individual items, or your whole account, from the app or from this website without needing the app installed. Deletion is real: your content is removed and backups age out on their normal cycle. Financial records and child safety reports are kept where the law requires it.
- Object, restrict, or complain. Ask us to stop a particular use, and complain to your data protection authority if we have not put something right.
Children and young people
Ardent Word is for people aged thirteen and over, and the minimum is higher in countries whose law sets it higher. We ask for a year of birth at sign-up and apply the minimum for your country.
Members aged between thirteen and eighteen get stricter defaults: new prayer requests start visible to a group rather than to everyone, the bio is hidden, and age is never shown to other members. Our standards against child sexual abuse and exploitation are on the child safety page.
How it is protected
Sensitive content is encrypted at rest with per-account keys, which are themselves wrapped by a managed key service. Everything is encrypted in transit. Every request that writes your data is authenticated and attested, and the database enforces row level security so that one account cannot reach another’s rows even if something above it is wrong.
Administrator access to personal content requires a stated reason and is written to a hash-chained audit log. No system is perfect, and if a breach affects you we will tell you and the relevant authority within the time the law allows.
Changes to this policy
The version and date are at the top. When something material changes we will tell you in the app rather than quietly updating the page, and we keep the previous versions available.