Public prayer content
When you share a prayer, the public CloudKit database stores the text, an optional category, dates, status, optional answer updates, and best-effort lift counts. Other people can read an active prayer, but Prayer Ledger does not display your name, email address, Apple ID, profile, or location with it. Prayer content may reveal religious or philosophical beliefs and can also include sensitive health, medical, financial, relationship, or family information. Do not include diagnoses, account numbers, names, contact details, or other identifying information. Automated filters help, but no filter is perfect.
Anonymous iCloud identity and activity
Apple CloudKit provides an opaque user record identifier so Prayer Ledger can enforce ownership and keep records available on your devices. The app does not receive your Apple ID, name, or email from that identifier. A one-way SHA-256 hash may be used as a stable anonymous key to prevent duplicate lifts and reports and support private blocking. Lift records contain a prayer identifier and date. Reports contain the prayer identifier, reason, optional details, date, and a one-way identifier. Reporting immediately hides a prayer on your device; it does not automatically remove it for everyone.
Private indexes and information on this device
Your private CloudKit database stores your private journal and indexes identifying prayers you shared and prayers you chose to keep. These indexes are available only through your iCloud account; they do not make shared prayer text private. On the device, Prayer Ledger stores settings, personal prayer statistics, local viewing history, hidden prayer identifiers, blocked-poster hashes, remembered prayer identifiers, cached public prayers, and a retry queue for CloudKit operations. Reminders are local notifications and contain no prayer text. Basic event names and CloudKit error categories may appear in Apple’s local unified logging system without prayer text and are not sent to a third-party analytics service.
How information is used
Prayer Ledger uses this information to keep your private journal available where iCloud sync is enabled, display and manage public prayers, record one lift per prayer, show private Insight totals and shared prayers’ best-effort lift counts, prevent duplicate lifts and reports, process safety reports, hide content, block anonymous posters, and retry operations after temporary CloudKit failures. Prayer Ledger does not sell this information, use it for advertising, or track you across apps or websites.
Apple services
Apple CloudKit is the only service provider Prayer Ledger uses to store and process app data. Apple protects CloudKit data under its policies and your Apple account settings. Optional support purchases unlock no feature and do not change prayer visibility. If you use the system share sheet, prayer text is handed to another app you choose. Prayer Ledger does not send the message or learn who receives it; the destination app handles it under its own policy.
Retention and deletion controls
Prayer Ledger does not automatically expire records. Public prayers and counts remain until you delete a prayer, use the account-and-data deletion control, or the developer removes content for safety or legal reasons. Lift records, reports, private indexes, and synced private journal records remain until deletion or authorized CloudKit administration removes them. Local history, statistics, safety choices, retries, cached data, and preferences remain until cleared, changed, the deletion control is used, or the app is removed. Delete a prayer from My Prayers. Clear local history or statistics in Settings → Data and Backup. Review hidden prayers and blocked posters in Settings → Prayer Stream. CloudKit must be available to remove cloud records; retry a partial deletion on a stable connection or contact support.
Website analytics
Prayer Ledger’s pages on brentgaddis.com use first-party aggregate website analytics operated through Cloudflare. The site counts page views and allowlisted actions and keeps coarse source, country, device, browser, operating-system, engagement, performance, and reliability totals. It does not store raw event rows, visitor or session identities, IP or hashed-IP identifiers, cookie or local-storage visitor IDs, full user agents, full referrers or URLs, form contents, arbitrary text, or a person’s raw click history. Country and source cells below five are suppressed, and aggregates are retained for up to 24 months. Cloudflare processes request and network metadata as needed to deliver and protect the site. These website measurements are separate from the app, which has no third-party analytics.
Questions
Contact Brent Gaddis with privacy questions about Prayer Ledger.