Back

Privacy Policy

Version 2026-05-15 · Applies to UK & EU GDPR Compliant

Who We Are

This application is operated by Ethiopian Christian Fellowship Church UK ("we", "us", or "our"), acting as the Data Controller. We are committed to protecting and respecting your privacy.

For any data protection enquiries or to exercise your privacy rights under the GDPR, you can contact our Church Administrator directly by emailing media@ecfcuk.org.

What We Collect and Why

We practice strict data minimization. We only collect the bare minimum amount of data required to make the application function correctly.

  • Device Identifier: A random, anonymous ID stored locally on your device. This is used solely so that the "I prayed", "chapter read", and "episode played" counters function normally without forcing you to create an account. It is not linked to your real name or identity.
  • Prayer Requests: We collect only the text you choose to type into the request box. You can submit these completely anonymously by leaving the name field blank.
  • Push Token: If you choose to enable push notifications, a temporary push token is generated so we can send updates to your device.
  • Reading-Plan Progress: Your personalized reading plan progress is kept securely on your device. An anonymous "chapter read" event is sent to our backend so the church can evaluate aggregate user engagement metrics.

Note on Personal Data: We do not collect, scrape, or access your name, email address, physical address, precise location, or device contacts unless you deliberately type them into a prayer request or sign in explicitly as a system administrator.

Lawful Basis for Processing

Under the UK and EU General Data Protection Regulation (GDPR), we rely on the following legal bases to process your information:

  • Legitimate Interests: Essential features of the app (such as rendering the Bible text, displaying sermons, and delivering news updates) rely on our legitimate interest in providing spiritual and community services to our fellowship.
  • Consent: Anonymous usage analytics and the delivery of push notifications rely entirely on your explicit consent, which you can grant or withdraw at any time via your device settings.
  • Special Category Data Condition: Because prayer requests may inherently reveal your religious beliefs, we process this specific text strictly based on your explicit consent (GDPR Article 9(2)(a)) when you hit submit, or as part of our legitimate activities as a non-profit religious body (GDPR Article 9(2)(d)).

Data Storage and International Transfers

Data is processed and stored securely inside the United Kingdom and the European Economic Area (EEA). We utilize the following sub-processors to maintain app infrastructure:

  • Lovable Cloud (Managed Supabase): Used for database management, secure file storage, and administrator authentication.
  • Cloudflare: Used for fast application hosting, performance optimization, and edge network delivery.
  • Firebase Cloud Messaging: Used exclusively to deliver push notifications if you have opted-in to receive them.

All of our sub-processors are contractually bound by GDPR-compliant Data Processing Agreements (DPAs). All data transmitted between your device and our servers is strictly encrypted in transit using TLS 1.2+ and encrypted at rest.

Data Retention: How Long We Keep It

  • Anonymous Engagement Data: General engagement events are retained for a maximum of 24 months, after which they are permanently deleted or fully anonymized.
  • Prayer Requests: Submitted prayer requests remain visible within our systems until you or an admin requests their removal.
  • Compliance Logs: Technical audit logs regarding consent updates and data deletion actions are retained for 24 months to satisfy legal compliance requirements.

Your Legal Rights & Data Deletion

Under UK & EU GDPR, you hold comprehensive rights regarding your personal data. You have the right to access, rectify, erase, restrict, port, or object to the processing of your data, as well as the right to withdraw consent at any moment.

You can instantly exercise these rights natively from inside the application's settings menu:

  • To clear everything from our servers: Tap "Withdraw consent & delete my data" to revoke your consent states and request the purging of your remote records (such as push notification tokens or associated backend entries). This option fully satisfies Google Play and Apple App Store data deletion requirements for regular users and administrators.
  • To clear your device data: Tap "Reset App Data (local only)" to instantly wipe out your locally stored reading plan progress and device tracking counters without affecting our servers.

External Requests: For any account or data deletion requests outside the application, you may email us directly at media@ecfcuk.org.

Automated Decision-Making

We do not use automated profiling, machine learning tracking, or automated decision-making algorithms within this application to make decisions that hold legal or significant consequences for you.

Children's Privacy

Our core application features (such as reading the Bible or listening to sermons) do not identify users and are entirely safe for family members of all ages. We do not knowingly collect personal data from children under the age of 13 (or 16 within certain EU jurisdictions) without parental consent. If you are under 13, please do not submit identifiable personal details within a prayer request without permission from a parent or guardian.

Complaints

If you believe we have failed to handle your data in accordance with the law, you have the right to lodge an official complaint with a data safety supervisory authority.

  • In the United Kingdom, you can contact the Information Commissioner's Office (ICO) at ico.org.uk.
  • In the European Union, you may contact your local national Data Protection Authority (DPA).