Privacy Policy — House of Prayer Mobile App
Last Updated: June 19, 2026 Effective: June 19, 2026
Developer: Magnolia Technology Consultants Contact: support@magnoliatcs.com
Scope of this policy. This policy covers only the House of Prayer mobile app for iOS and Android ("the App") and the server that the App talks to. The Magnolia Technology Consultants website at hop.magnoliatcs.com (and any other Magnolia Technology Consultants website) is a separate product with its own privacy policy — please consult that policy for anything you do on the website. If something isn't covered here, it isn't done by the App.
In plain English
House of Prayer ("the App") is a private app for prayer groups. We collect only what we need to make the App work — your account, the things you write in the App, and the people you talk to. We don't sell your data, we don't run ads, we don't track you across other apps, and we don't share what you share inside the App with anyone outside your prayer group. You can delete your account at any time from inside the App. When you do, your account becomes unusable and your personal info (email, profile photo, phone, birthday, bio) is removed; the content you posted in your prayer group is kept but attributed to "Deleted Member" so the group's shared record isn't broken.
The rest of this document spells that out in detail so you (and the App Store) know exactly where you stand.
1. Who we are
The App is built and operated by Magnolia Technology Consultants, the data controller responsible for your information in the App. You can reach us at support@magnoliatcs.com for any privacy question, correction request, or deletion request. This policy applies only to the App; the website at hop.magnoliatcs.com has its own separate policy.
2. What we collect
2.1 Information you give us when you sign up
- Email address — used to sign you in and for account recovery.
- Display name — shown to other people in your prayer groups.
- Password — stored only as a one-way hash (we cannot read it).
If you choose Sign in with Apple instead, we receive an Apple identity token from Apple, which we verify and then discard. If you choose to share your name and email with us through Apple, we receive those; if you choose Apple's private email relay, we receive only the relay address.
2.2 Optional profile information
You may add any of the following — none of it is required:
- Phone number
- Birthday
- Short bio
- Profile photo
You can edit or remove any of these at any time from Settings → Edit Profile.
2.3 Information you create in the App
- Messages and attachments you send in direct messages and group chats
- Reactions (emojis) you add to messages
- Prayer requests, prayer comments, and prayer reactions you post in your group's prayer hub
- Hub content you create or edit: announcements, events, ministries, songs, weekly plans, sign-ups
- Read receipts (only if you have read receipts enabled)
- Photos, voice recordings, and other files you upload to your profile or share in chat
A note on uploaded files. The files you and your group upload — song charts, documents, photos, voice recordings, and similar material — are stored only to operate the App and share them with the other members of your prayer group. We do not control, monitor, review, or manage what you upload, and we provide no content of our own. You are responsible for ensuring you have the right to upload and share anything you post, and group administrators are responsible for the uploads of their members. (For more on your responsibility for this content, see Section 5 of our Terms of Service.)
2.4 Technical information your device sends
- Push notification token — a unique identifier issued by Apple (APNs) or Google (FCM) that lets us deliver a notification to your specific device. We cannot read your messages from this token.
- App version, OS version, and device type — for diagnostics and to deliver app updates that work on your device.
2.5 What we do NOT collect
- We do not collect location, GPS, or Wi-Fi network information.
- We do not access your contacts, calendar, or health data.
- We access your microphone only while you are actively recording a voice message in a chat — never in the background, and never for any other purpose.
- We do not include any advertising SDKs, analytics SDKs, or third-party trackers.
- We do not use any device identifier (such as IDFA) for tracking, and we do not present an App Tracking Transparency prompt because we do not track.
3. How we use your information
We use what we collect only to:
- Sign you in and keep your session active.
- Deliver the messages, prayer requests, and hub content you create to the other members of your prayer group.
- Send push notifications you have opted into (new messages, prayer reminders, etc.).
- Display your profile to other members of groups you belong to.
- Operate, secure, and improve the App — for example, rate-limiting failed logins to protect your account.
We do not use your data to build advertising profiles, train AI models, or sell to data brokers. We do not run advertising in the App.
4. Who we share your information with
Inside the App: the other members of conversations and prayer groups you participate in can see the messages, prayer requests, comments, and hub content you post there. That's the point of the App. Group administrators can see additional management information about their group.
Outside the App: we share information only with the limited service providers we need to operate the App:
| Provider | What they receive | Why |
|---|---|---|
| Apple — APNs | Your iOS push token + the notification payload | To deliver iOS push notifications |
| Google — Firebase Cloud Messaging | Your Android push token + the notification payload | To deliver Android push notifications |
| Apple — Sign in with Apple | The identity token we verify | To support Sign in with Apple |
| Our own servers (operated by Magnolia Technology Consultants) | All App data | Storage and operation of the App's servers |
We do not sell your personal information. We do not share your personal information with any third party for their own advertising, marketing, or profiling purposes.
We may disclose information if we are legally required to do so (court order, subpoena, etc.), and only to the narrowest extent the law requires.
5. How we keep your information secure
- All traffic between the App and our servers uses HTTPS (TLS) end-to-end. The App refuses unencrypted connections.
- Your authentication token is stored in the device's secure storage (iOS Keychain / Android Keystore).
- Passwords are stored only as one-way hashes.
- Your private messages and prayer requests are encrypted on our servers, so they can't be read directly from the database — someone with database access sees only scrambled text, not your conversations.
- We do not have your Apple ID password — Sign in with Apple authenticates you with Apple directly and only returns a verified token to us.
- We apply rate limiting and abuse detection on authentication endpoints.
No system is perfectly secure. If we ever experience a security incident that affects your data, we will notify you by email and through the App as required by law.
6. How long we keep your information
- Active accounts: for as long as your account exists.
- Deleted accounts: when you delete your account, we anonymize it. We immediately and permanently remove your email address, password, Apple Sign-In link, push token, phone number, birthday, bio, and profile photo from our active systems, and we change your display name to "Deleted Member." Login is then impossible — the account can never be reactivated. Backups containing the pre-anonymization data are overwritten within 30 days.
- Content you posted in your community: prayer requests, prayer comments, hub announcements, plans, messages, and other contributions you made to your prayer group remain visible to the members of that group, attributed to "Deleted Member." We retain this content because it belongs to the shared record of the prayer group, not to any one member. If you want a specific post fully removed (rather than just anonymized), edit or delete it yourself before deleting your account. If you've already deleted your account, or if someone else's post mentions you and you'd like it scrubbed, email support@magnoliatcs.com.
- Chat attachments: photos, voice recordings, and files shared in chat are automatically deleted from our servers 30 days after they are sent. After that the attachment is no longer available, though the surrounding message remains.
- Service logs: technical logs (request timestamps, error traces) are kept for up to 90 days and contain no message content.
7. Your rights and choices
We've built in-app tools so you can exercise your rights yourself without waiting on us:
- See your data — Settings → Privacy & Security → Your Data shows everything in your account record (your user ID, email, display name, phone, birthday, bio, avatar, and role). The button at the bottom of that screen exports the same data as JSON if you want a portable copy. Messages you've sent, prayer requests you've written, and other content you've posted are already visible to you in the App's normal navigation.
- Correct your data — Settings → Edit Profile.
- Delete your account — Settings → Privacy & Security → Delete Account. Permanent and immediate. (See Section 6 for what happens to content you posted.)
- Adjust what we collect or send — Settings → Privacy & Security to disable read receipts or hide moderation options; Settings → Notifications (or your device Settings) to turn off push notifications.
These tools cover the rights granted by GDPR, UK GDPR, CCPA/CPRA, and similar data-protection laws — access, rectification, erasure, portability, and restriction. We won't charge you for using them and we won't retaliate against you for using them.
If something falls outside what the in-app tools can do, email support@magnoliatcs.com. We read what comes in but make no specific response-time guarantees — the in-app tools above will always be faster than email.
8. Children
The App is not directed at children under 13 and we do not knowingly collect personal information from children under 13. If you believe a child under 13 has created an account, please contact us at support@magnoliatcs.com and we will delete the account.
9. International users
Our servers are operated in the United States. If you use the App from outside the United States, you understand that your information will be transferred to, stored in, and processed in the United States, which may have different data-protection rules than your home country.
10. Changes to this policy
If we change this policy, we will update the "Last Updated" date at the top and, for material changes, notify you in the App or by email at least 14 days before the changes take effect. Your continued use of the App after the effective date constitutes acceptance of the updated policy. If you do not accept the new policy, you can delete your account from Settings → Privacy & Security.
11. How to contact us
For any privacy question, request, or complaint:
Magnolia Technology Consultants Email: support@magnoliatcs.com
We aim to respond within 5 business days, and always within 30 days for formal data-rights requests.
By creating an account or using the App, you acknowledge that you have read and understood this Privacy Policy.