Privacy Policy

Effective Date: April 1, 2026  ·  Last Updated: April 1, 2026

1. Introduction

webLuthier, LLC ("we," "our," or "us") operates the Ora mobile application (the "App") and the website located at oraapp.link (the "Site"). This Privacy Policy explains how we collect, use, disclose, and protect your information when you use our App or visit our Site (collectively, the "Services").

Ora is a personal prayer app. We understand that the contents of a prayer list are sensitive and personal, and this policy describes the specific measures we take to protect that content.

By using our Services, you agree to the collection and use of information in accordance with this policy. If you do not agree with any part of this policy, please do not use our Services.

Contact us: If you have any questions about this Privacy Policy, please contact us at [email protected].

2. Information We Collect

2.1 Information You Provide Directly

2.2 Information Collected Automatically

2.3 Information We Do Not Collect

2.4 Encryption of Prayer Content

Prayer Time itself runs from data stored locally on your device. If you choose to sign in to enable backup and sync, the text of your prayer items is encrypted on your device before it is transmitted or stored. We do not hold the plaintext of your prayer items on our servers, and our staff cannot read them.

The exception is described in Section 5.4: if you subscribe to Ora Plus and use guided prompts, the relevant prayer-item text is sent to OpenAI in readable form at the time prompts are prepared, because a prompt cannot be written from encrypted text.

3. How We Use Your Information

We use the information we collect to:

We do not sell your personal data. We do not use your prayer content to train machine-learning models. We do not use your personal data for automated decision-making or profiling that produces legal or significant effects on you.

4. Legal Basis for Processing (EU/EEA Users)

If you are located in the European Economic Area (EEA) or the United Kingdom, we process your personal data under the following legal bases:

Where prayer content reveals religious belief, it may constitute a special category of personal data under Article 9 GDPR. We process it only on the basis of your explicit consent, given when you choose to store it with us, and only for the purposes described in this policy.

5. Third-Party Services and Data Processors

5.1 Database and Authentication Infrastructure

We use Supabase, Inc. as our backend database and authentication provider. Supabase stores your account credentials and the App data you choose to back up, including your encrypted prayer items, settings, and Prayer Time history. Supabase is hosted on AWS and may process data in the United States and other jurisdictions. Supabase complies with SOC 2 Type II standards and provides appropriate data processing agreements under GDPR.

For more information, see Supabase's Privacy Policy at supabase.com/privacy.

5.2 Subscription and In-App Purchase Management

We use RevenueCat, Inc. to manage in-app subscriptions, entitlements, and purchase receipts. When you purchase Ora Plus, RevenueCat receives and processes your transaction receipt from the App Store or Google Play, your device identifier, and your subscription status. RevenueCat does not process your payment card information. All payment processing is handled directly by Apple or Google.

RevenueCat may retain transaction data for fraud prevention and analytics purposes. Their data is stored in the United States. For more information, see RevenueCat's Privacy Policy at revenuecat.com/privacy.

Data shared with RevenueCat includes:

5.3 App Stores

The App is distributed through the Apple App Store and Google Play Store. These platforms have their own privacy policies and data practices independent of ours. Apple's privacy policy is available at apple.com/privacy. Google's privacy policy is available at policies.google.com/privacy.

5.4 Guided Prompt Generation (Ora Plus)

If you subscribe to Ora Plus and use guided prayer prompts, the text of the relevant prayer items is sent to OpenAI, L.L.C. ("OpenAI") through the OpenAI Platform API to generate prompt text. Prompts are prepared ahead of a session and cached on your device, so Prayer Time itself does not require a live internet connection.

We use OpenAI's API under its business terms. OpenAI does not use data submitted through the API to train its models. OpenAI may retain API request and response data for a limited period for abuse and misuse monitoring before deleting it. We do not send your account identity, email address, or contact details with a prompt request. We send only the prayer-item text needed to write the prompt.

Guided prompts are an optional feature. If you do not subscribe to Ora Plus, or you turn prompts off, no prayer content is sent to OpenAI for any purpose.

For more information, see OpenAI's privacy policy at openai.com/policies/privacy-policy and its API data usage policies at openai.com/policies/api-data-usage-policies.

5.5 Prompt Narration

Prompt narration uses the speech synthesis built into your device's operating system. Voice selection and speaking speed are handled entirely on your device, prompt text is spoken locally, and no audio or prompt text is sent to us or to any third party in order to narrate it. No third-party text-to-speech service is involved.

6. Data Retention

We retain your personal data for as long as your account is active or as needed to provide you the Services. If you delete your account, we will delete or anonymize your personal data within 30 days, except where we are required to retain it for legal, tax, or audit purposes. Subscription transaction records required by Apple or Google may be retained for up to 7 years.

Prayer items you delete in the App are removed from our systems on the next sync. If you never sign in, your prayer list exists only on your device and is removed when you delete the App.

You may request deletion of your data at any time by contacting us at [email protected].

7. Data Security

We implement industry-standard security measures to protect your data, including:

No method of transmission over the internet or electronic storage is 100% secure. While we strive to protect your data, we cannot guarantee its absolute security.

8. Data Transfers

We are based in the United States. If you use our Services from outside the United States, your information may be transferred to and processed in the United States and other countries where our service providers operate. These countries may have different data protection laws than your home country.

For transfers of personal data from the EEA, United Kingdom, or Switzerland to the United States, we rely on Standard Contractual Clauses and other transfer mechanisms approved under applicable data protection law to ensure your data receives adequate protection.

9. Children's Privacy

Our Services are not directed to children under the age of 13 (or 16 in certain jurisdictions). We do not knowingly collect personal information from children under 13. If you believe we have inadvertently collected data from a child under 13, please contact us immediately at [email protected] and we will delete that information promptly.

10. Your Rights

10.1 All Users

Regardless of your location, you may:

10.2 European Economic Area and United Kingdom (GDPR Rights)

If you are located in the EEA or UK, you have the following rights under the General Data Protection Regulation (GDPR):

You also have the right to lodge a complaint with your local data protection authority. To exercise any of these rights, contact us at [email protected]. We will respond within 30 days.

10.3 California Residents (CCPA / CPRA)

If you are a California resident, the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), grants you the following rights:

To exercise your California privacy rights, contact us at [email protected] with "California Privacy Request" in the subject line. We will respond within 45 days as required by law.

Categories of personal information collected in the last 12 months: Identifiers (email, device ID); commercial information (subscription records); internet or network activity (usage data); sensitive personal information (encrypted prayer content that may reveal religious belief); and inferences drawn therefrom to understand your preferences.

10.4 Virginia Residents (VCDPA)

If you are a Virginia resident, the Virginia Consumer Data Protection Act (VCDPA) provides you the following rights:

To exercise your Virginia privacy rights, contact us at [email protected] with "Virginia Privacy Request" in the subject line. We will respond within 45 days, with a possible 45-day extension where reasonably necessary. If we decline to take action, you may appeal our decision by replying to our response.

11. Cookies and Tracking Technologies

Our website (oraapp.link) may use cookies and similar technologies for basic site functionality and analytics. Our mobile App does not use cookies.

You may control cookie settings through your browser preferences. Disabling cookies may affect some functionality of the Site but will not affect your use of the App.

12. Links to Third-Party Sites

Our Services may contain links to third-party websites and services. We are not responsible for the privacy practices of those third parties. We encourage you to review their privacy policies before providing any personal information to them.

13. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. When we do, we will update the "Last Updated" date at the top of this page and notify you through the App or by email for material changes. Your continued use of the Services after any changes constitutes your acceptance of the updated policy.

14. Contact Us

If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:

webLuthier, LLC

Email: [email protected]

Website: oraapp.link

For EU/EEA residents: You may also contact your local data protection supervisory authority if you believe your rights have been violated.