Faith & Religion
Using a prayer or scripture app tells the company your faith, and one policy says outright that it collects your religion by inference. The location it needs for prayer times or a nearby place of worship also feeds ads and analytics. Your giving and your activity go back to your congregation.
The read at a glance
A prayer app knows your faith and, each time it sets a prayer time, where you are.
A leak exposes your religion, where you pray, and what you asked others to pray for.
Giving records are kept for years for tax; app accounts and their history as long as the account exists.
Sign-up asks for little; the app itself tells the company your religion.
Industry profile reviewed 29 September 2026. Also machine-readable via the free API.
If it leaks
This is your religion and your routine together: your faith, where you pray and when, and what you asked others to pray for. Leaked, it can mark you out wherever that faith is not safe to hold.
What repeats in the policies
Your faith, read from using the app
Opening a prayer or scripture app is itself a record of your religion. One policy says it collects your religious beliefs by inference, and treats using the app as accepting every use it lists, so the only way to refuse is to stop. Your location comes too: prayer times and the direction of prayer depend on it.
To advertisers and back to your congregation
In most of the policies read, the location you give for prayer times or a nearby mosque or church is also used for ads and analytics. Giving goes to the congregation with more than the money: one platform tells a church which followers are most active and where they live, and passes on each donor's name and amount.
Gifts kept for years, the rest left open
How long any of this stays is their claim. Giving records carry the firmest numbers: seven years of billing at one platform, at least six years of donations at another, which keeps your contact details indefinitely. Apps mostly keep your history while you have an account, and one keeps your email address after you delete it.
What a company here typically holds
Worked out from the industry, not from any one company. What you actually handed over is yours to record.
What this can reveal about you
Built only from what this kind of service actually collects. A dimension that the data does not support is not listed.
Religion and community Highly likely
Using a prayer or scripture app is itself the record of your faith.
Where you go Highly likely
Prayer times follow your location through the day, to your home and your place of worship.
Health Possible
Prayer requests shared with a community often name illness and family troubles.
What lawfully stays after you leave
Two kinds of hold. Law sets it: a statute makes them keep it. They set it: a ground the company grants itself.
Tax and accounting records Law sets it about 6 years
Tax and company law makes them keep billing and payment records.
A do-not-contact record They set it kept indefinitely, by design
A minimal note kept on purpose so they do not contact you or re-add you.
Records tied to a live or potential dispute They set it the limitation period of the claim
They can keep records to defend a live or possible legal claim.
Who wants this data
Prayer app location has been sold. In 2020 a Muslim prayer app sent users' precise location to a broker whose customers included US defence contractors, and in 2021 another sold its users' movements to a French broker. The US regulator's orders against three brokers name places of worship as sensitive locations they may no longer sell.
Sold or shared Likely
Prayer app location has been sold to data brokers, and through them to defence contractors.
AI training Low
Little sign of faith app data training models; the value sold has been location.
Even anonymised, this can still be you
Location sold from prayer apps carried advertising IDs, and the FTC found such data could track visits to places of worship (FTC, 2024); four time-and-place points single out 95% of people (de Montjoye et al., 2013).
Name, date of birth, postcode Typical
Fifteen demographic attributes re-identify 99.98% of Americans in a released dataset (Rocher, Hendrickx and de Montjoye, Nature Communications, 2019); date of birth, postcode, and sex alone did it for most people in the first study of the problem (Sweeney, 2000).
Location traces Typical
Four time-and-place points single out 95% of people in mobility data (de Montjoye et al., Scientific Reports, 2013).
Payment patterns Sometimes
Four card transactions identify 90% of people in payment data (de Montjoye et al., Science, 2015).
How you write Sometimes
Language models infer where a person lives, their income, and their sex from their writing alone, at near-human accuracy and at scale (Staab et al., ICLR 2024).
Browsing fingerprint Typical
Browser and device fingerprints were unique for 84% of visitors in the first large study (Eckersley, 2010), and sparse histories of what people viewed re-identified them against public reviews (Narayanan and Shmatikov, 2008).
The studies Estimating the success of re-identifications in incomplete datasets using generative models (Nature Communications 10, 3069, 2019)·Simple Demographics Often Identify People Uniquely (Carnegie Mellon University, Data Privacy Working Paper 3, 2000)·Unique in the Crowd: The privacy bounds of human mobility (Scientific Reports 3, 1376, 2013)·Unique in the shopping mall: On the reidentifiability of credit card metadata (Science 347 (6221), 2015)·Beyond Memorization: Violating Privacy via Inference with Large Language Models (ICLR 2024, 2024)·How Unique Is Your Web Browser? (Privacy Enhancing Technologies Symposium (PETS 2010), 2010)·Robust De-anonymization of Large Sparse Datasets (IEEE Symposium on Security and Privacy, 2008)·FTC order prohibits data broker X-Mode Social and Outlogic from selling sensitive location data (US Federal Trade Commission, 2024)
The wording that does the work
Clauses that recur across this industry, and what each one actually permits.
“to provide and improve our services”
The catch-all purpose. Analytics, profiling, personalisation and AI training all fit under it. When they want to do something new with your data, this sentence usually already allows it.
The move An objection tells them to use your data to run the service and nothing more.
“we do not sell your personal information”
Usually this means no cash changes hands. Your data can still go to ad networks, analytics firms and partners, because they count that as sharing rather than selling.
The move Use the do-not-sell switch where there is one, and put an objection in writing as well.
“service providers, partners, and affiliates”
This is how your data leaves with no name attached. Recipients are described by what they do rather than named, and you cannot send a request to a company you cannot name.
The move An access request can ask for recipients by name rather than by category, and UK and EU law put that choice with you.
“aggregated or de-identified information”
Taking your name off does not take away the pattern, and the pattern often still points at you. Policies give themselves free use of this data with no end date, on the basis that it is no longer about you.
The move If a deletion comes back as 'anonymised', keep the reply. It usually means de-identified, and it is their claim, not a fact you can check.
“retained as long as necessary, or as required by law”
They can keep it for legal duties, tax rules, fraud prevention, possible lawsuits and their own business reasons. None of those has a firm end date, so deletion turns into something you have to argue for.
The move Which reasons apply to you, and how long each runs, is a request of its own.
“you grant us a licence to use your content”
This is a contract term rather than a data setting, so a privacy request cannot undo it. A careful version ends when your account does. A broad one can be passed on, never expires and survives deletion.
The move Their terms say whether the licence ends when the account does. Close the account and log the date here.
“collect by inference sensitive personal information concerning you, in particular your religious beliefs”
The app treats using it as telling it your faith, and treats carrying on using it as accepting every use in the policy. There is no separate consent step for data about your religion.
The move A See request asks what it has recorded about your faith and who it went to.
“deliver you relevant content and ads based on your location”
Location you gave so the app could work out prayer times or find a nearby place of worship is also used to choose your ads and for the company's analytics.
The move A Limit request asks them to use your location only for the feature you gave it for.
“to determine which followers are most active and where those individuals reside”
The platform reports back to your church or mosque how active you are and where you live, and on a donation passes on your name and the amount.
The move A See request asks what your congregation has been sent about you.
“should contact the organization they are affiliated with directly”
The giving or church-management platform holds your records but says it does so for your congregation, so a request to delete or stop is sent back to the church or mosque.
The move Ask the platform and your congregation; each answers for its own copy.
Their own policy is the one that binds them. Pin it down with a request, and keep the reply.