Privacy Policy

Last updated: September 26, 2026

Who is responsible. The controller of the data described here is Faithlocked, reachable at support@faithlocked.app.

Faithlocked respects your privacy. This policy explains how the app handles your information. Blocking rules, prayer history, streaks, and reading progress live on your device and are never uploaded. The Community is the one part that needs a server: if you choose to use it, your profile and what you post are stored with our provider, Google Firebase, in the United States (Section 3.6). Everything else works without an account.

This policy covers Faithlocked on iOS (App Store) and on Android (Google Play). Sections that apply to only one platform are labelled as such.

1. Information We Access

1.1 App Settings (Stored Locally)

Your preferences — blocking rules, selected apps, prayer history, streaks, and unlock sessions — are stored locally on your device — on iOS via SwiftData and an App Group container, on Android via Room and DataStore. They never leave your device.

1.2 App Blocking

iOS. Faithlocked uses Apple's Screen Time framework (FamilyControls, ManagedSettings, DeviceActivity) to block apps you select until you complete a prayer. Apple processes this entirely on-device. The app does not see the content, history, or notifications of the apps you choose to block — only opaque tokens managed by iOS.

Android. To show the prayer screen the moment you open a blocked app, Faithlocked needs to know which app you have just brought to the foreground. It does this with whichever permission you grant: Android's Accessibility service, or Usage access (usage statistics). In both cases the app reads only the package name of the app in the foreground — never the contents of your screen, your messages, or anything you type. The Accessibility service is declared to receive window-state-change events only and cannot retrieve window content. A foreground service keeps blocking active, and the "display over other apps" permission lets the prayer screen appear on top of a blocked app. All of this stays on your device: the names of the apps you open are never collected, transmitted, stored off-device, or shared with anyone. You can decline these permissions or revoke them later at any time (see Section 5).

1.3 Prayer Generation

When you request a guided prayer, Faithlocked sends a short payload to our Cloudflare Worker proxy, which forwards it to Google Gemini to generate the prayer text. That payload is: the two moods you selected on the sliders, the first name you entered during onboarding (empty if you skipped it), your prayer streak and total prayer count, your language, and your local hour, so the prayer can address you and match the moment. The request is authenticated with an HMAC signature and rate-limited by IP. No account information, email address or device identifier is sent, and the payload is not stored: the Worker keeps nothing beyond a per-IP rate-limit counter. The generated prayer is returned to your device and stored locally.

1.4 Notifications

With your permission, Faithlocked sends you notifications: your prayer reminders, the verse of the day, an occasional encouragement, and a warning when an unlock session is about to end. Every one of them is scheduled and shown by your own device, offline, with nothing sent from our servers and no push service involved. The verse of the day is one of these: the whole verse library ships inside the app. On Android, scheduled blocking windows and reminders may also use exact alarms, which run entirely on your device.

Some of that text is written by us rather than shipped in the app: your device downloads a small catalogue of sentences and decides for itself which ones apply to you and when to show them. That download is a one-way read — we do not know who read it, and no device registers itself with us. When a sentence is personalised with your name or your goal, your device fills it in; those values never leave the phone. We also never receive which apps you block, what you write in your journal, or what you read.

You can turn notifications off at any time in your device settings, or choose which kinds you want inside the app.

1.5 Refund Requests (Apple)

If you request a refund for an in-app purchase, we may provide Apple — through our subscription management provider, RevenueCat — with information about your in-app purchase activity so Apple can evaluate the request fairly. This may include details such as the time since app installation, total app usage time, an anonymized account identifier, whether the in-app purchase was fully consumed, whether it included a trial period, the total amount spent, and the total amount refunded. This data is shared only with Apple, only in response to a refund request, and solely to process that request. You can withdraw your consent at any time — see Section 4 of our Terms of Use or email us at support@faithlocked.app. This applies to purchases made through the App Store only. Purchases made through Google Play are handled by Google under Google Play's refund policy, and we do not share consumption data with Google.

1.6 Community (optional)

The Community is the only feature that stores data off your device. It is optional: blocking, prayers, the Bible reader, and widgets all work without it.

Reading. Opening the Community creates an anonymous session with Firebase Authentication so the app can load the feed. That session identifies an app installation, not a person, carries no name or email, and cannot post, comment, react, or chat.

Posting. To post, comment, react, or chat you create a permanent Community account with Sign in with Apple on iOS or Google Sign-In on Android, in each case through Firebase Authentication. Firebase Authentication replaces the anonymous session. We then store: the account identifier and email address that the applicable sign-in provider provides (with Sign in with Apple you may use Apple's private relay address instead of your own), your display name, an optional bio, an optional avatar — a character we supply, or a photo you upload — your chosen language, your favourite verse reference, how your sheep is dressed (the scene and the items it wears), and your prayer streak and prayer count so your public profile can show them.

What you post. Prayer requests, posts, notes, reactions, chat messages, reports you file, and the users you block are stored on the server. Posts, notes, and reactions are visible to other users; chat messages are visible in the room and deleted automatically after 7 days; reports and blocks are visible only to you and to us. Publishing anonymously hides your name and avatar from other users, not from us.

Where it lives. Community data is hosted by Google Firebase in the United States (region us-east1): Firebase Authentication for the account, Cloud Firestore for the profile and the content, Cloud Functions for every read and write of personal data, and Cloud Storage for profile photos. The app additionally reads two things straight from Firestore: change notices that carry no content at all (they only say something was updated, so the app asks again) and the editorial campaign documents, which contain nobody's data. Profile photos are kept in a private bucket and served through links that expire; a photo we remove stops being served to anyone else.

1.7 Moderation

Every post, note, and chat message passes a word filter on our own server before it is published; none of it leaves our infrastructure or is sent to any third party. What the filter catches is blocked; everything else is published immediately.

Profile photos are the exception, because a word filter cannot look at an image. When you upload one, it is sent once — through our own proxy — to Google Gemini, which answers only whether the image is acceptable. The photo is not stored by Google or used to train anything, and it is never sent with your name, your email or your account identifier. Until that answer arrives, the photo is visible only to you.

Those two checks are automated. They can hide a message or a photo, and nothing else: they cannot suspend your account, and no decision about you is taken by a machine alone. The real review is done by a person on our team — daily, and whenever someone reports something — seeing both the content and who wrote it. Whenever we remove something of yours or suspend your account, you get a notice in the App saying what, why, and whether it was decided automatically or by a person, and you can ask a person to look again. Moderation results, reports, and bans are kept while the account exists so that repeat abuse can be acted on.

2. Information We Do Not Collect

3. Third-Party Services

3.1 RevenueCat

Faithlocked uses RevenueCat to manage subscriptions on both platforms (StoreKit on iOS, Google Play Billing on Android). RevenueCat may collect subscription status, purchase history, device type, OS version, and an anonymous RevenueCat App User ID. RevenueCat does not receive prayer data, blocking rules, or any personal information you enter into the app. See RevenueCat's Privacy Policy.

3.2 PostHog (Analytics)

Faithlocked uses PostHog to collect anonymous product analytics (feature usage, screen views, app version, OS version) so we can improve the app. Data is processed on EU servers. No personal information, prayer content, or blocking rules are sent. See PostHog's Privacy Policy.

Session recording. For one stretch per installation, we record how the app is used: from the moment the subscription screen appears at the end of onboarding until you first leave the app after completing your first prayer, so we can see where new users hesitate or get stuck while setting it up. The recording is made of screenshots of the app's own screens and the places you tap. It never covers the onboarding questions, and anything you type into a text field is hidden. It can show text the app itself displays on those screens, such as your first name. It is processed by PostHog on EU servers, is not linked to your email, and nothing outside that stretch is ever recorded.

3.3 Google Gemini (via our proxy)

Prayer generation requests are forwarded by our Cloudflare Worker to Google Gemini. Google processes the prompt to generate the response and is subject to Google's Privacy Policy. The prompt contains the fields listed in Section 1.3 — including your first name, if you gave one — and nothing that identifies your account or your device.

3.4 Apple Services (iOS)

Faithlocked integrates with Apple FamilyControls (app blocking) and StoreKit (subscriptions), governed by Apple's Privacy Policy.

3.5 Google Play (Android)

On Android, subscriptions and consumable Faith Coin and streak-freeze packs are purchased and billed through Google Play Billing, and the app is distributed and updated through Google Play Store — both governed by Google's Privacy Policy.

3.6 Google Firebase (Community)

If you use the Community, Google Firebase hosts the account, the profile, the posts, the chat, and the avatar photos described in Section 1.6, in the United States (region us-east1). This covers Firebase Authentication, Cloud Firestore, Cloud Functions, and Cloud Storage. Google acts as our processor and does not use that data for its own purposes. Firebase App Check additionally verifies that requests come from a legitimate installation of the app — App Attest on iOS, Google Play Integrity on Android. See Firebase's privacy information and Google's Privacy Policy.

3.7 Sign in with Apple (iOS) and Google Sign-In (Android)

Permanent Community accounts use Sign in with Apple on iOS and Google Sign-In on Android, each through Firebase Authentication. Apple or Google provides the account identifier and, when available, an email address; with Sign in with Apple you may hide your real address behind Apple's private relay. We never receive your password. See Apple's Privacy Policy, Firebase's privacy information, and Google's Privacy Policy.

International transfers

Analytics and subscription data stay in the European Union. What leaves it is processed by Google in the United States:

Google LLC is certified under the EU-US Data Privacy Framework, and our contract with Google incorporates the European Commission's Standard Contractual Clauses.

4. Data Storage & Retention

Your blocking rules, selected apps, prayer history, streaks, reading progress, and unlock sessions are stored locally on your device and are never uploaded. The prayer proxy is stateless beyond per-IP rate limiting.

Community data is the exception: your profile and what you post are stored with the provider named in Section 3.6 — Google Firebase in the United States — for as long as you keep your account. Chat messages are deleted automatically 7 days after they are sent. Posts, notes, and reactions stay until you delete them or delete your account. Reports and moderation decisions are kept while the account exists, so that repeat abuse can be acted on.

5. Data Deletion

Uninstalling the app removes all on-device app data, with one exception: your streak, prayer total, sheep wallet, earned medals and Bible reading progress are kept in a small record in the device keychain, so that reinstalling restores your progress instead of resetting it. If you use iCloud Keychain, that record syncs to your other Apple devices. It holds no name, no email and nothing you have written. Delete account in the app's settings erases it.

If you created a Community account, uninstalling does not remove it — use Delete account in the app's settings. That deletes your account and, with it, your profile, posts, notes, reactions, chat messages, avatar photo, blocks, and reports. Deletion is immediate and cannot be undone; residual copies may persist in routine backups for a short period. A record of the erasure itself — your former account identifier and the state of the deletion — is kept for 90 days so that a question about it can still be answered after the account is gone; it holds nothing you wrote. You can also request deletion by writing to support@faithlocked.app from the address on the account.

6. Children's Privacy

The blocking and prayer features need no account and no personal data. The Community carries content written by other users and requires an account: you must be at least 14 in Spain (Article 7 of the LOPDGDD), and at least the age of digital consent set by your own country (13 to 16 across the EU), to create one. Before the account is created we ask you to confirm that you are old enough, and we keep only that confirmation, never your date of birth. We do not knowingly collect personal information from children below that age; if we learn that an account belongs to one, we delete it. Parents and guardians are responsible for supervising use by minors.

7. Your Rights

All Users

EU Users (GDPR)

California Users (CCPA)

8. Changes to This Policy

We may update this policy from time to time. Changes will be indicated by updating the "Last Updated" date. Significant changes will be communicated within the app.

9. Contact

If you have questions about this policy, contact us at support@faithlocked.app.

© 2026 Faithlocked. All rights reserved.