Overview
Prayer Ledger handles deeply personal prayer, journal, voice, transcript, reflection, reminder, and optional purchase information. The current App Store listing is version 3; the public Prayer Stream disclosures below apply only to an installed version that offers that feature. Private journal records can sync through the user’s private CloudKit database, while voice audio remains local in the reviewed implementation. The app has no advertising, third-party analytics, or cross-app tracking. Brent Gaddis provides Prayer Ledger. It is a general-audience app and is not directed to children under 13. Privacy questions can be sent through the site form or to support@brentgaddis.com.
Optional Prayer Stream and community safety
Only versions that include Prayer Stream send prayer text, category, status, answer updates, engagement, reports, and moderation records to public CloudKit. Public prayers can be viewed, saved, copied, screenshotted, reported, moderated, or retained by other people. They can reveal religious beliefs and health, emotional, relationship, family, or financial details. Do not post names, contact details, diagnoses, account data, or content you lack permission to share. Opaque or one-way identifiers, local blocked/seen/reported history, and private ownership or save indexes can support moderation and abuse prevention. A display described as anonymous does not make content unidentifiable from its words, and reporting does not guarantee immediate removal.
Anonymous iCloud identity and activity
Apple CloudKit provides an opaque user record identifier so Prayer Ledger can enforce ownership and keep records available on your devices. The app does not receive your Apple ID, name, or email from that identifier. A one-way SHA-256 hash may be used as a stable anonymous key to prevent duplicate lifts and reports and support private blocking. Lift records contain a prayer identifier and date. Reports contain the prayer identifier, reason, optional details, date, and a one-way identifier. Reporting immediately hides a prayer on your device; it does not automatically remove it for everyone.
Private indexes and information on this device
Your private CloudKit database stores your private journal and indexes identifying prayers you shared and prayers you chose to keep. These indexes are available only through your iCloud account; they do not make shared prayer text private. On the device, Prayer Ledger stores settings, personal prayer statistics, local viewing history, hidden prayer identifiers, blocked-poster hashes, remembered prayer identifiers, cached public prayers, and a retry queue for CloudKit operations. Reminders are local notifications and contain no prayer text. Basic event names and CloudKit error categories may appear in Apple’s local unified logging system without prayer text and are not sent to a third-party analytics service.
How information is used
Prayer Ledger uses this information to keep your private journal available where iCloud sync is enabled, display and manage public prayers, record one lift per prayer, show private Insight totals and shared prayers’ best-effort lift counts, prevent duplicate lifts and reports, process safety reports, hide content, block anonymous posters, and retry operations after temporary CloudKit failures. Prayer Ledger does not sell this information, use it for advertising, or track you across apps or websites.
Apple services
Apple CloudKit is the only service provider Prayer Ledger uses to store and process app data. Apple protects CloudKit data under its policies and your Apple account settings. Optional support purchases unlock no feature and do not change prayer visibility. If you use the system share sheet, prayer text is handed to another app you choose. Prayer Ledger does not send the message or learn who receives it; the destination app handles it under its own policy.
Retention, deletion, and crisis limits
Private journal records remain until you delete them or use the account/data control; local voice files remain until the related prayer or app data is removed. Public prayer, engagement, report, moderation, and ownership records in versions with Stream remain until deleted or removed for safety/legal reasons. CloudKit must be reachable, and public deletion can partially fail; verify My Prayers and retry or contact support. Uninstalling alone may leave CloudKit records. Exported files, shares, screenshots, saves, and recipient copies remain outside the app. Prayer Ledger is not an emergency, medical, mental-health, crisis, pastoral, legal, or professional counseling service and is not monitored for urgent requests.
Website, support, privacy requests, children, and policy changes
Prayer Ledger’s app-data practices are described above and are separate from its pages on brentgaddis.com. Those pages use first-party aggregate analytics operated through Cloudflare. The site counts page views and allowlisted actions and keeps coarse source, country, device, browser, operating-system, engagement, performance, and reliability totals. It does not store raw analytics events, visitor or session identities, raw or hashed IP addresses, cookie or local-storage visitor IDs, full user agents, full referrers or URLs, form contents, arbitrary text, or a person’s raw click history. Country and source cells below five are suppressed, and aggregates are retained for up to 24 months. Cloudflare still processes request and network metadata to deliver and protect the site. If you contact support, the website, Cloudflare Turnstile, Cloudflare’s delivery services, and the email provider process the app selection, request type, reply email, subject, message, security signals, and delivery metadata you submit. Form contents are delivered to Brent’s monitored mailbox and are not written to website analytics or a website message database. Support email is retained only as reasonably needed to respond, maintain security and support records, resolve disputes, and meet legal obligations, then deleted or de-identified when no longer needed. Do not submit passwords, recovery keys, government identifiers, payment-card data, or unrelated sensitive content. The website does not use cross-site behavioral advertising or sell or share personal information for that purpose, so browser Do Not Track and Global Privacy Control signals do not change its behavior. Prayer Ledger is offered to a general audience and is not directed to children under 13. If Brent learns that a child supplied personal information through a developer-controlled channel without required consent, he will take reasonable steps to delete it. Depending on where you live, applicable law may provide access, correction, deletion, or appeal rights; use the privacy-request form or email support@brentgaddis.com. Identity may be verified, and requests will be handled as applicable law requires. Material changes will be posted on this page with a new effective date, with additional notice or consent when required.
Private journal, audio, transcription, and exports
Prayer Ledger can store prayer text, people and categories, emotions, notes, reflections, answers, voice metadata, and transcripts in local SwiftData and the user’s private CloudKit database when sync is available. Voice audio files remain in local Application Support in the reviewed implementation. Microphone access records voice; speech recognition creates optional transcripts according to the behavior of the installed version and Apple services. Face ID or device authentication can protect access, and local notifications provide reminders. TXT or JSON exports can contain journal text, sensitive metadata, and transcripts but not voice audio; exported copies remain at the chosen destination.
Questions
Contact Brent Gaddis with privacy questions about Prayer Ledger.