Privacy
Your prayer is personal.
Prayer Pew is designed to work without an account and to collect less, not more. This notice explains what leaves your device when you use the service.
When you use Prayer Pew as a guest
Your prayer plan and finished prayer are saved locally in the browser or app on the device where you made them, so you can return to them. The words you submit are sent securely to our text-generation providers to prepare the plan and prayer.
Personal narration and Fish Audio
When personal narration is prepared, Prayer Pew sends the finished prayer text to Fish Audio, operated by Hanabi AI Inc., to create the spoken audio. A finished prayer contains religious content and may include health or wellbeing details. Fish Audio is an independent third-party service, not part of Prayer Pew. In the mobile app, this transfer cannot begin until you see the in-app disclosure and choose Agree and play.
On the web, if Fish Audio cannot complete the request, ElevenLabs may receive the same finished prayer text to prepare a backup recording.
Fish Audio's public terms permit it to use Usage Data and Content to develop, train, or improve AI and machine-learning models. Its privacy policy says it may retain Content for as long as its systems need it and may transfer data from the UK or EEA to countries outside that region. Fish Audio may therefore retain the prayer text, use it for model improvement or training, and process it outside your country under its own terms and privacy policy.
On mobile, you can choose Not now and read the prayer without personal narration. Daily Prayer uses public editorial content and does not send your personal prayer text to Fish Audio.
Audio and cloud copies
Generated prayer audio and word timings are stored in private, environment-specific Cloudflare R2 storage. They are not published on a public asset domain. Signed-in prayer records are encrypted by Prayer Pew before they are stored in the application database.
When you sign in or subscribe
Signing in is optional. If you choose Apple, Google, or email sign-in, we keep the verified email address, the name the provider supplies, the provider’s account identifier, and an internal Prayer Pew account identifier so your prayers and access can follow you across devices. The mobile app does not keep a Google profile photo because it has no profile-photo feature.
Apple, Google Play, Stripe, and RevenueCat tell us which plan was purchased and whether access is active. We do not receive or store your full card or payment account details. A keychain-backed installation identifier, push token when notifications are enabled, and the minimum account link needed for purchases and rate limits may also be stored.
When you use Prayer Pew on Alexa
Amazon processes what you say to Alexa and sends Prayer Pew a structured skill request; Prayer Pew does not receive your raw microphone audio. To play the daily prayer for the right day, the skill uses the device-scoped ID and short-lived Alexa API token in that request to ask Amazon for the device's configured time zone. Prayer Pew uses those values only while answering the request and does not log or retain them or the returned time zone. It then gives Alexa the public address of that day's finished narration. The current daily-prayer skill does not require a Prayer Pew account and does not collect a personal prayer request.
If you ask for prayer in a comment on social media
Commenting our keyword on one of our own Instagram posts is a request to have a prayer prepared and sent to you privately. When you do, we read that one comment from Instagram, use your words to write a prayer, and send you a private link to it. We do not store your comment, your username, or your Instagram account details, and the private message we send never repeats or paraphrases what you wrote, because it may appear on a locked device screen. Your words are sent to our text-generation providers to prepare the prayer, in the same way as words typed on this site. The prayer itself is encrypted and kept behind an unguessable private link, and opening that link places a copy in that browser so you can delete it. If a comment suggests someone may be in danger we send information about real help instead, and no prayer is written.
We may also reply publicly, under your comment, to comments on our own posts that do not use the keyword. A public reply never repeats or hints at what you wrote, never carries a link to anyone’s prayer, and is never sent to you privately, because you did not ask us for anything privately. Where a public comment suggests someone may be in danger we post nothing at all, so that no attention is drawn to them, and a person at Prayer Pew is alerted instead.
Sharing
A prayer is private unless you create a sharing link. Anyone who receives an active link can open it without signing in, so share it only with people you trust. You can turn the link off from the original prayer.
Open Pew
Open Pew is public. Anyone may read a request that appears there. You must sign in to post, mark that you prayed, report a request, or block its author, but your account email is never shown on Open Pew. Before posting, you choose either Anonymous or a separate name for Open Pew and confirm that you understand the request may appear publicly.
The request and chosen Open Pew name are sent to OpenAI for automated safety and personal-information screening before anything is published. OpenAI may keep API safety-monitoring data for up to 30 days under its service terms unless our account has a shorter approved retention setting. A request that clearly passes the checks can appear straight away. A request containing private details or an immediate safety concern is not published and the app asks you to edit it or seek appropriate help; nobody is monitoring Open Pew as an emergency service.
Published requests are encrypted in our application database and normally expire from the public Open Pew feed after 30 days. You can remove your own request at any time. Text held only because an automated check was temporarily unavailable is encrypted and deleted after seven days unless it is resolved sooner. We do not keep the raw text of a rejected request. We may keep text-free moderation codes and reports for up to 180 days so we can operate the safeguards, answer an appeal, and prevent repeated abuse.
Product analytics and errors
PostHog and Vercel Web Analytics receive anonymous, low-cardinality events such as whether a prayer was played or completed. We do not send prayer text, titles, prayer IDs, share URLs, or Scripture excerpts, and session replay is disabled. Sentry is used for operational errors and performance; request bodies, account data, cookies, and private route identifiers are scrubbed before reporting. If you deliberately send feedback, the note and optional reply email are stored only in PostHog for our team to review. The form asks you not to include prayer text, private details, or sharing links.
For a tagged advert, we keep a closed first-party campaign tuple (the source, campaign, creative ID, format and variant) for the current browser tab and copy it to Stripe subscription metadata at checkout. This lets us understand our own funnel without carrying tracking parameters into private prayer URLs. It contains no prayer or account information and is not sent to an advertising network unless you allow the optional measurement below.
When Stripe verifies that a trial began or that its first payment succeeded, we send that product event to PostHog with the plan and, for the payment, its amount and currency. Trial and payment are joined with an opaque value derived from our random checkout reference. We do not send Stripe customer, subscription or invoice IDs, advertising click IDs, email, account details, or private content with these events, and they do not create a person profile.
Optional advertising measurement
If you allow it, the Meta Pixel and the TikTok Pixel measure visits on a few public pages that carry no prayer, draft, or sharing identifier in their address, and they receive standard browser and device information along with their own measurement cookies when present. Neither ever runs on the pages that hold your plan, your finished prayer, or a shared prayer. The record that a prayer was successfully generated is sent by Meta Conversions API and the TikTok Events API from our server alone, precisely so the private address of your prayer is never handed to either company. If you open checkout, begin a trial, or become a paid subscriber, we may also send that standard event. A first paid invoice includes only its amount and currency; later renewals are not used as new-subscriber conversions.
When you arrive from an advert, the link carries an identifier that tells the network which advert you clicked. We hold that identifier in memory only until you answer the question below. If you allow measurement we store it in a cookie and copy it to Stripe subscription metadata at checkout, so that the network can match a trial or first payment after the seven-day delay. If you decline, the network’s advert identifier is discarded and never written to your device or the subscription.
We do not send prayer text, titles, themes, Scripture choices, voice choices, email address, account IDs, prayer IDs, private URLs, or health or religious details. We do not use email or phone matching for advertising. This measurement stays off until you choose to allow it, and you can change that choice at any time. A withdrawal is saved on our server before we try to remove delayed identifiers from Stripe, so a provider outage cannot cause a pending trial or payment event to be sent later. For a signed-in account, withdrawing keeps server-side subscription conversion measurement off for that account; allowing browser measurement again does not resurrect those delayed events.
Your choices
You can remove guest prayers from inside the app or, on the web, by clearing this site’s browser data. You can also revoke any active sharing link or contact us about a signed-in cloud copy. Please do not include the private details of a prayer in a support email.
Contact us about privacyUpdated 29 August 2026