Pray.com

pray.com · faith & religion

Using a prayer or scripture app tells the company your faith, and one policy says outright that it collects your religion by inference. The location it needs for prayer times or a nearby place of worship also feeds ads and analytics. Your giving and your activity go back to your congregation.

Reported incidents

Named one of the six worst apps for privacy in Mozilla's review of 32 apps

2022-05-02

Affected Pray.com app

Mozilla's *Privacy Not Included guide to mental health and prayer apps, published on 2 May 2022, named Pray.com among its six worst offenders, citing its sharing of personal information with third parties. Mozilla's review said the app collects personal, usage and location data, says it can buy data from brokers such as religious affiliation, household income and political party, and can use and share all of it to target ads, including with other "faith-based organizations". It gave the app its warning label and told readers: "Please be very careful if you chose to use this app. We don't recommend you do." Mozilla reviewed four other prayer apps in the guide.

Policy let it add broker data about users; an audit found views sent to Facebook

2022-01-24

Affected Pray.com app content and its public prayer groups

BuzzFeed News reported on 24 January 2022 that Pray.com's privacy policy let it add data bought from "third-parties such as data analytics providers and data brokers", including religious affiliation, ethnicity, household income and political party affiliation, to what it recorded about users. Pray.com added that wording on 22 December 2021, after BuzzFeed's inquiry. An audit by privacy researcher Zach Edwards found the app sent details of which content a user viewed, including a podcast episode on dating, porn, sex and divorce, to Facebook and the attribution firms LeadsRX and Branch.io, none of them on its vendor list. Pray.com said it "is not in the business of renting or selling data."

Open cloud storage exposed church lists, donations and users' uploaded phonebooks

2020-11-19

Affected Amazon S3 storage served through the app's CloudFront content network

Researchers at vpnMentor reported on 19 November 2020 that four Amazon S3 buckets belonging to Pray.com were misconfigured, and that files marked private could still be reached through its CloudFront content network. The exposed files held church attendee lists with names, home addresses and marital status, records of donations made through the app, user profile photos, and whole phonebooks uploaded from users' phones. The researchers estimated that up to 10 million people were exposed and said most of them did not use the app. They first wrote to Pray.com on 7 October 2020. The contact files were removed on 17 November, and the chief executive's only reply was "Unsubscribe".

People affected typically ask Pray.com to confirm whether their information was included, and which categories.

The verified route

privacy@pray.com
Privacy Recommended

DÆTRAX is a personal data accountability ledger: a dated record of which companies hold your personal data, what you asked them to do about it, and what they claimed in reply.