Back

Privacy Policy

Version 2026-07-22 · Applies to UK & EU GDPR Compliant

Who We Are

This application is operated by Ethiopian Christian Fellowship Church UK ("we", "us", or "our"), acting as the Data Controller. We are committed to protecting and respecting your privacy.

For any data protection enquiries or to exercise your privacy rights under the GDPR, you can contact our Church Administrator directly by emailing media@ecfcuk.org.

What We Collect and Why

We practice strict data minimization. We only collect the bare minimum amount of data required to make the application function correctly. Most data is collected only when you explicitly opt in.

1. Data collected automatically for essential app function

These are needed to make the app work and are not based on consent. No personally identifiable information is collected.

  • Device Identifier: A random, anonymous ID generated on your device. It is stored locally and used only so that counters like "I prayed", "chapter read", and "episode played" work without requiring you to create an account. It is not linked to your real name, email, or identity.
  • Reading-Plan Progress: Your personalized reading plan progress is stored only on your device. The app does not send your actual progress to our servers unless you have also opted in to anonymous analytics.

2. Data collected only when you opt in

You choose whether to share the following data through the Privacy & Cookies banner or the settings screen. You can change these choices at any time.

  • Anonymous usage analytics: If you choose "Accept all" or turn on "Anonymous analytics" in settings, we receive events such as episode plays, chapter reads, and prayer prays. Each event is tied only to your anonymous device ID — never to your name or identity.
  • Push notifications: If you enable notifications in settings, a temporary push token is generated so we can send you daily-verse or church announcements. You can turn this off at any time.

3. Data you submit yourself

  • Prayer Requests: We collect only the text you choose to type into the request box. You can submit these completely anonymously by leaving the name field blank. Because prayer requests may reveal your religious beliefs, they are processed only when you press submit and in line with GDPR rules for special category data.

Note on Personal Data: We do not collect, scrape, or access your name, email address, physical address, precise location, or device contacts unless you deliberately type them into a prayer request or sign in explicitly as a system administrator.

How and Where Data Is Stored

DataWhen it is collectedWhere it is storedHow long it is kept
Device IDFirst app launchOn your device (localStorage). Also sent with anonymous events only if you opt in.Until you reset the app or delete app data.
Prayer request textWhen you submit a requestLovable Cloud database (UK/EEA).Until you or an admin deletes it.
Anonymous analytics eventsOnly if you consent to analyticsLovable Cloud database (UK/EEA).Up to 24 months, then deleted or anonymized.
Push tokenOnly if you enable notificationsLovable Cloud database / Firebase Cloud Messaging (for delivery only).Until you disable notifications or delete your data.
Consent choicesWhen you respond to the consent banner or settingsOn your device and in our compliance logs.24 months for compliance logs.
Reading-plan progressAs you use the reading planOnly on your device (localStorage).Until you reset the app.

Lawful Basis for Processing

Under the UK and EU General Data Protection Regulation (GDPR), we rely on the following legal bases to process your information:

  • Legitimate Interests: Essential features of the app (such as rendering the Bible text, displaying sermons, and delivering news updates) rely on our legitimate interest in providing spiritual and community services to our fellowship.
  • Consent: Anonymous usage analytics and the delivery of push notifications rely entirely on your explicit consent, which you can grant or withdraw at any time via the Privacy & Cookies banner or in your Profile settings.
  • Special Category Data Condition: Because prayer requests may inherently reveal your religious beliefs, we process this specific text strictly based on your explicit consent (GDPR Article 9(2)(a)) when you hit submit, or as part of our legitimate activities as a non-profit religious body (GDPR Article 9(2)(d)).

Security, Sub-Processors and International Transfers

Data is processed and stored securely inside the United Kingdom and the European Economic Area (EEA). We utilize the following sub-processors to maintain app infrastructure:

  • Lovable Cloud (Managed Supabase): Used for database management, secure file storage, and administrator authentication.
  • Cloudflare: Used for fast application hosting, performance optimization, and edge network delivery.
  • Firebase Cloud Messaging: Used exclusively to deliver push notifications if you have opted-in to receive them.

All of our sub-processors are contractually bound by GDPR-compliant Data Processing Agreements (DPAs). All data transmitted between your device and our servers is strictly encrypted in transit using TLS 1.2+ and encrypted at rest.

Data Retention: How Long We Keep It

  • Anonymous Engagement Data: General engagement events are retained for a maximum of 24 months, after which they are permanently deleted or fully anonymized.
  • Prayer Requests: Submitted prayer requests remain visible within our systems until you or an admin requests their removal.
  • Compliance Logs: Technical audit logs regarding consent updates and data deletion actions are retained for 24 months to satisfy legal compliance requirements.

Your Legal Rights & Data Deletion

Under UK & EU GDPR, you hold comprehensive rights regarding your personal data. You have the right to access, rectify, erase, restrict, port, or object to the processing of your data, as well as the right to withdraw consent at any moment.

You can instantly exercise these rights natively from inside the application's settings menu:

  • To clear everything from our servers: Tap "Withdraw consent & delete my data" to revoke your consent states and request the purging of your remote records (such as push notification tokens or associated backend entries). This option fully satisfies Google Play and Apple App Store data deletion requirements for regular users and administrators.
  • To clear your device data: Tap "Reset App Data (local only)" to instantly wipe out your locally stored reading plan progress and device tracking counters without affecting our servers.

External Requests: For any account or data deletion requests outside the application, you may email us directly at media@ecfcuk.org.

Content You Post, Moderation and Reports

Prayer requests are user-generated content. Every request is reviewed by a church administrator before it becomes visible to anyone else — nothing is published automatically. You must be 13 or over to submit content; see our Community Rules & Terms of Use.

If you report a prayer request using the flag icon, we store only the reason you selected, your optional note, the ID of the reported request, and your anonymous device ID. We do not record your name or contact details. Reports are visible only to church administrators, are reviewed within 3 working days, and are kept for 12 months before deletion.

Where content is removed for breaching our community rules, we keep a short administrative record of the action for the same 12-month period so we can handle appeals and demonstrate that the app is moderated.

Automated Decision-Making

We do not use automated profiling, machine learning tracking, or automated decision-making algorithms within this application to make decisions that hold legal or significant consequences for you.

Children's Privacy

Our core application features (such as reading the Bible or listening to sermons) do not identify users and are entirely safe for family members of all ages. We do not knowingly collect personal data from children under the age of 13 (or 16 within certain EU jurisdictions) without parental consent. If you are under 13, please do not submit identifiable personal details within a prayer request without permission from a parent or guardian.

Complaints

If you believe we have failed to handle your data in accordance with the law, you have the right to lodge an official complaint with a data safety supervisory authority.

  • In the United Kingdom, you can contact the Information Commissioner's Office (ICO) at ico.org.uk.
  • In the European Union, you may contact your local national Data Protection Authority (DPA).