← Back to Cairn

Privacy Policy

Last updated: July 14, 2026

Cairn (“we,” “us”) is a prayer and scripture app. This policy explains what we collect, why, and your choices. Our guiding principle: your prayers and reflections are yours. We do not sell your personal data, we do not share it for advertising, and we never use the content of your prayers, journal, or chat to train AI models.

What we collect

Information you provide: your first name, the topics you choose to pray about, your onboarding answers (how your heart feels, what brought you to Cairn, and how familiar prayer is to you), your chosen reminder time, your prayer-journal entries, verses you save, and anything you post or reply on the community prayer wall. If you open the wall, we ask your birth year once, only to confirm you are 13 or older. If you link an email or Google account, we store that sign-in email.

Account data: an anonymous account identifier created automatically so your data syncs across visits. If you subscribe, Stripe (our payment processor) handles your payment details; we store only your subscription status and Stripe references, and we never see your card number.

Usage data: your prayer streak dates, Bible reading and plan progress, and how many chat reflections you have used today (a number, not the messages). We also use privacy-friendly, cookieless analytics (Vercel Analytics) that give us aggregate counts like page views, not profiles of you, and basic technical information needed to run the app reliably and securely, including your IP address (used briefly for security rate limiting and ordinary server logs, never to build a profile of you) and the abuse-protection signals described under Third parties below.

A note on sensitive information: Cairn is a prayer app, so by its nature the content you choose to write (prayers, journal entries, chat messages, wall posts) may reveal your religious beliefs, and some laws treat that as sensitive personal information. We use it for one purpose only: providing Cairn to you. We never use it for advertising, profiling, or sale, we never analyze it to infer characteristics about you, and we do not use it for any purpose that would require a “Limit the Use of My Sensitive Personal Information” option under California law.

What we deliberately do not do

  • We do not sell your personal data, and we do not share it for cross-context behavioral advertising.
  • We do not show ads and we do not use advertising trackers.
  • We do not collect your precise location, contacts, or photos.
  • We do not store your chat conversations on our servers (see the next section).
  • We do not use your prayers, journal, or chat content to train or fine-tune AI models.

The AI companion

The chat companion is artificial intelligence, and it is labeled as AI in the app. When you send it a message, the recent conversation is sent to our server and then to our AI provider, Google (the Gemini API), so a response can be generated and returned to you. We do not store your chat messages. The conversation lives on your device for the current session and starts fresh next time; our server processes messages in the moment and keeps only your daily reflection count.

Your messages are not used to train or fine-tune AI models, and we use a paid Google service tier chosen so that your content is not used to train Google's models either. If a message suggests you may be in crisis, we do not send it to the AI at all; Cairn replies directly with crisis resources (988 in the US) instead. The companion is not a substitute for pastoral, medical, or professional advice, and it is not a crisis service.

How we use your information

To provide the app: save your streak, journal, and saved verses; personalize your daily verse to the topics you chose; generate companion responses; run the community wall safely; manage subscriptions; keep the service secure and prevent abuse; and respond when you contact us. We do not use your data for advertising.

Third parties we use

We rely on a few providers to operate Cairn, and we share only what each needs to do its job. Each has its own privacy policy:

  • Google Firebase: accounts and data storage.
  • Google Gemini: generates AI companion responses (paid tier; no training on your content).
  • Google reCAPTCHA / Firebase App Check: protects sign-in and data from bots and abuse. Google collects device and interaction signals for this purpose under the Google Privacy Policy and Terms of Service.
  • Stripe: subscription payments.
  • Vercel: app hosting and cookieless, aggregate analytics. As our host, its servers see the technical request data (like IP addresses) that any web server sees.
  • Upstash: rate limiting that protects the service, keyed to your account identifier and, for some protections, your IP address. These keys expire within minutes.
  • jsDelivr: a public content delivery network that serves the Bible text files when you open a book in the reader. Like any web server, it sees your IP address when a book loads; no account information is sent to it.

These providers process data on servers in the United States. If you use Cairn from elsewhere, your data is processed in the US.

Cookies

Cairn uses only what is essential: sign-in state so you stay logged in, and local storage on your device for small preferences (like your chosen voice for read-aloud). Our analytics are cookieless. We do not use advertising or cross-site tracking cookies.

Do Not Track and Global Privacy Control: we do not track you across other websites or services, and we do not sell or share your personal information, so there is nothing for these browser signals to turn off. Cairn behaves the same way, with the same protections, whether or not they are enabled.

The community prayer wall

Unlike your journal and chats, which are private, anything you post or reply on the wall is public to other Cairn users. You choose whether each post shows your first name or is anonymous. Public posts carry no account identifier at all; a private account code, visible only to our moderation system, lets moderators act on posts that break the rules without revealing who wrote what to anyone else.

The first time you open the wall, we ask your birth year so we can limit the wall and the chat companion to users 13 and older. We store only the year, and only for this purpose. To keep the wall safe we run automated checks (for example, profanity and self-harm language) and keep the records needed for moderation, such as reports and which account posted an item.

Children's privacy

Cairn is not directed to children under 13, and our Terms require users to be 13 or older. We do not ask for age at sign-up; the one place we collect a birth year is the community prayer wall gate, and if that year shows a user is under 13, the wall and the chat companion close automatically and stay closed. If you are a parent or guardian and believe a child under 13 is using Cairn or has provided us information, contact us at support@cairnprayer.com and we will promptly delete the child's account and information.

Your choices and rights

You can edit your details in Settings, delete individual journal entries, saved verses, and wall posts in the app, and sign out at any time. You can also delete your whole account in Settings: deletion is scheduled with a 30-day waiting period so an impulsive tap cannot erase years of prayers, you can cancel anytime during those 30 days, and after that everything is permanently deleted, including your sign-in, journal, saved verses, wall posts, and any subscription (which is canceled so you are never charged again). You can also request a copy or deletion of your data by emailing support@cairnprayer.com. We honor access and deletion requests for everyone, wherever you live. Depending on where you live, laws such as the GDPR (Europe) or CCPA (California) give you formal rights to access, correct, delete, and port your data, and the right not to be discriminated against for exercising them. We do not sell or share personal information as those laws define it, so there is nothing to opt out of.

Where the GDPR or similar laws apply, our legal bases are: performing our agreement with you (providing the app you signed up for, including its optional features you choose to use), our legitimate interests in keeping the service secure and free of abuse, and your consent for anything optional you choose to share, which you can withdraw by removing the information or deleting your account. You also have the right to complain to your local data protection authority.

Data retention & security

We keep your data while your account is active and delete it when your account is deleted (after the 30-day waiting period) or on request. Chat conversations are not retained at all. One narrow exception, for safety: if an account was banned from the community wall for abuse, we keep a scrambled one-way fingerprint (a cryptographic hash) of its sign-in email after deletion, so the ban cannot be evaded by remaking the account. The fingerprint cannot be turned back into the email, and accounts in good standing leave nothing behind. We protect your data with security measures including encryption in transit, server-side access rules so only your account can read your private data, and abuse protection on sign-in, though no system is perfectly secure. If we ever learn of a breach affecting your personal data, we will notify you as the law requires.

Changes & contact

If we update this policy, we will revise the date above and, for significant changes, notify you in the app. Questions or requests? Contact us at support@cairnprayer.com.