Case study · 2019 to 2026 · filed 30 September 2026

A prayer app took users' phonebooks and left them in open storage

Pray.com uploaded the contact lists of users who let it, so it held people who had never used it. In 2020 researchers found those lists open to anyone, beside church member lists and donation records.

Pray.com is a Christian app for prayer, Bible readings and giving to a church. When a user allowed it, the app uploaded their whole phonebook, every contact saved on the phone. In October 2020 researchers at vpnMentor found Pray.com's cloud storage open to anyone through its content network. It held church member lists with names, home addresses and marital status, a record of every donation with the amount and the donor's details, photos, some of them of children, and the phonebooks. The researchers estimated that up to 10 million people were exposed and said most of them did not use the app. After three attempts to reach the company, the reply from its chief executive was one word: "Unsubscribe". The phonebook files were taken down in November; the researchers said the rest stayed open.

In December 2021, after questions from BuzzFeed News, Pray.com added a line to its privacy policy saying it could add data bought from "data brokers" to what it held about users, including religious affiliation, ethnicity, household income and political party. An audit for the same report found the app sending what a user listened to, down to a podcast episode on dating, porn, sex and divorce, to Facebook and two ad attribution firms, none of them on its list of vendors. Pray.com said it "is not in the business of renting or selling data." In May 2022 Mozilla named it one of the six worst of 32 apps it reviewed.

Its privacy policy, updated in May 2026, now says it in writing: "if you appear in other users' contact books, we will collect information about you."

What it shows

You can be in an app's records without ever installing it. A friend who shares their contacts hands over your name and number, and from then on the company decides what happens to them. Here they sat in open storage beside church lists and giving records.

For your own record

If you think someone who uses an app has your number saved, you can still ask that app what it holds about you and ask it to delete it. On your own phone, refusing an app access to your contacts keeps your friends' details out of it.

More case studies

Grindr A Catholic group bought app data to find priests who used Grindr Phone data with no names on it, showing which devices used Grindr and where they went, was on sale through brokers. A Catholic group in Denver bought it, matched phones to parishes and seminaries, and passed what it found to bishops.
Gloo A church marketing firm predicted who might be depressed, divorcing or addicted Gloo told churches it could predict who might have a marriage in trouble, depression or a drug addiction, from data it bought about Americans. After The Wall Street Journal asked, it stopped using mental health data and its main data supplier left.
CatholicVote Phones seen inside Catholic churches were used to find voters A political group bought location data that came from ordinary phone apps, drew a line around Catholic churches, and sent ads to the people whose phones had been inside. The churches did not know.