Datenschutzerklärung
Prayerboard App · Stand: Juli 2026
1. Verantwortlicher
Marcel Magens
Hasenweg 9
25365 Klein Offenseth-Sparrieshoop
E-Mail: privacy@prayerboard.de
2. Mindestalter
Prayerboard richtet sich an Nutzer ab 16 Jahren. Gemäß Art. 8 DSGVO ist für eine eigenständige Einwilligung zur Verarbeitung personenbezogener Daten ein Mindestalter von 16 Jahren erforderlich (Deutschland). Nutzer unter 16 Jahren dürfen die App nur mit Zustimmung eines Erziehungsberechtigten verwenden. Die Cloud-Version stellt dies durch eine Pflicht-Bestätigung im Einrichtungsassistenten sicher.
3. Berechtigungen
| Berechtigung | Zweck | Version |
|---|---|---|
| Benachrichtigungen | Lokale Gebetserinnerungen planen | Alle |
Es werden keine weiteren Berechtigungen benötigt (kein Zugriff auf Kamera, Mikrofon, Kontakte oder Standort).
4. Keine Analytics, kein Tracking
Prayerboard enthält keine Analyse-Tools, Werbenetzwerke oder Crash-Reporter. Es findet keinerlei Nutzungsanalyse statt.
Tritt in der App ein Fehler auf, protokolliert die App ihn ausschließlich lokal auf deinem Gerät – nur mit technischen Angaben (Fehlercode, App-Version, Betriebssystem), nie mit Gebetsinhalten, Namen oder E-Mail-Adressen. Dieses Diagnose-Protokoll wird niemals automatisch übertragen; es verlässt dein Gerät nur, wenn du es in den Einstellungen unter „Diagnose“ selbst teilst (z. B. als E-Mail an den Support). Du kannst es dort jederzeit einsehen und löschen; Einträge werden nach spätestens 30 Tagen automatisch entfernt.
5. Drittanbieter-Bibliotheken
Die verwendeten Open-Source-Bibliotheken (Flutter, Hive, Riverpod u. a.) arbeiten ausschließlich lokal und übertragen keine Daten.
6. Abo-Verwaltung (RevenueCat)
Für die Verwaltung von Abonnements nutzen wir RevenueCat (Revenue Cat, Inc., USA). RevenueCat verarbeitet Kaufbelege von Apple bzw. Google, um deinen Abo-Status zu bestätigen, sowie eine pseudonyme Nutzer-ID — eine zufällig generierte technische Zeichenfolge ohne Klarnamen, E-Mail-Adresse oder andere identifizierende Merkmale. RevenueCat kann dich als Person nicht identifizieren. RevenueCat hat keinen Zugriff auf deine Gebetsanliegen oder andere Inhalte. Diese ID ist pseudonym, nicht anonym: Wir selbst können sie über unsere Datenbank deinem Konto zuordnen, RevenueCat hingegen nicht.
Da RevenueCat ein US-amerikanisches Unternehmen ist, findet ein Drittlandtransfer statt. Dieser ist durch EU-Standardvertragsklauseln (SCCs) abgesichert. RevenueCat wird erst kontaktiert, wenn du aktiv einen Kauf oder eine Kauf-Wiederherstellung startest oder dich mit deinem Konto anmeldest; danach wird der Abo-Status beim App-Start aktualisiert. Bei rein lokaler Nutzung ohne Kauf und ohne Konto findet kein Kontakt zu RevenueCat statt.
7. Gebetserinnerungen
Prayerboard plant zwei Arten lokaler Push-Benachrichtigungen ausschließlich auf deinem Gerät:
- Anliegen-Erinnerungen: einmalig, täglich oder wöchentlich an bestimmten Wochentagen – direkt am jeweiligen Gebetsanliegen konfigurierbar.
- Gebetszeit-Erinnerungen: wöchentlich wiederkehrend an von dir gewählten Wochentagen und Uhrzeiten – zentral in den Einstellungen konfigurierbar.
Die Benachrichtigungsinhalte verlassen dein Gerät nicht und werden nicht an Apple, Google oder Dritte übermittelt.
8. Home Screen Widget
Das optionale Home Screen Widget zeigt Gebetsanliegen auf dem Startbildschirm. Damit das Betriebssystem das Widget auch dann anzeigen kann, wenn die App nicht läuft, müssen die angezeigten Anliegen in einem separaten, vom Betriebssystem verwalteten Speicherbereich (Shared Container) abgelegt werden. Dieser Shared Container ist durch die App-Sandbox des Betriebssystems geschützt und für andere Apps nicht zugänglich. Die Daten verlassen dein Gerät nicht. Dennoch werden dort nur die Daten temporär abgelegt, die vom Widget verwendet werden. Das Widget kann in den Einstellungen jederzeit deaktiviert werden; bei Deaktivierung wird der Container sofort geleert.
9. Export-Funktion
Der JSON-Export erstellt eine Datei auf deinem Gerät. Wie du diese Datei verwendest oder teilst, liegt in deiner Verantwortung. Die exportierten Daten werden nicht automatisch übertragen.
10. Datenspeicherung (Local)
Alle von dir eingegebenen Daten (Gebetsanliegen, Boards, Kategorien, Notizen) werden ausschließlich lokal auf deinem Gerät gespeichert. Es findet keine Übertragung an Server oder Dritte statt. Die Datenbank ist mit AES-256 verschlüsselt; der Schlüssel wird im gesicherten Schlüsselspeicher des Betriebssystems (iOS Secure Enclave / Android Keystore) verwahrt.
11. Deine Rechte (Local)
Da keine personenbezogenen Daten auf externen Servern gespeichert werden, liegen sämtliche Daten ausschließlich auf deinem Gerät unter deiner Kontrolle. Du kannst alle Daten jederzeit durch Deinstallation der App vollständig entfernen. Ein JSON-Export aller Daten ist über die Einstellungen jederzeit möglich.
12. Verarbeitete Daten (Cloud)
| Datenkategorie | Zweck | Speicherort |
|---|---|---|
| E-Mail-Adresse | Authentifizierung via OTP | Supabase, Frankfurt (DE) |
| Anzeigename | Sichtbarkeit als Mitglied in geteilten Boards; frei wählbarer Name, der weder Klarname noch E-Mail-Adresse sein muss | Supabase, Frankfurt (DE) |
| Gebetsanliegen, Boards (verschlüsselt) | Sync & Backup | Supabase, Frankfurt (DE) |
| Einwilligungs-Zeitstempel | DSGVO-Nachweis | Supabase, Frankfurt (DE) |
| Push-Token (Android) | Cloud-Benachrichtigungen | FCM / Google (USA) — siehe Abschnitt 17 |
| Push-Token (iOS) | Cloud-Benachrichtigungen | APNs / Apple (USA) — siehe Abschnitt 17 |
13. Speicherfristen (Cloud)
| Datenkategorie | Speicherdauer |
|---|---|
| E-Mail-Adresse, Profildaten | Bis zur Konto-Löschung |
| OTP-Code | 15 Minuten (automatisch ungültig) |
| Session-Token | 7 Tage; Refresh-Token: 90 Tage |
| Gebetsanliegen, Boards (verschlüsselt, aktiv) | Bis zur Konto-Löschung |
| Gebetsanliegen / Boards (vom Nutzer gelöscht) | 30 Tage, danach physisch gelöscht. Kein nutzersichtbarer Papierkorb — die Übergangsfrist dient der geräteübergreifenden Synchronisation. |
| Cloud-Board-Daten nach Deaktivierung der Cloud-Sicherung | 30 Tage, danach physisch gelöscht. Die Übergangsfrist stellt sicher, dass alle deine Geräte den Wegfall des Boards synchronisieren können, bevor es endgültig entfernt wird. |
| Einwilligungs-Zeitstempel | Bis zur Konto-Löschung |
| Push-Token (FCM / APNs) | Bis zur Konto-Löschung oder Deaktivierung von Push-Benachrichtigungen |
| Audit-Log (Aktivitätsprotokoll) | 90 Tage |
| Audit-Log (nach Konto-Löschung) | 30 Tage nach Konto-Löschung |
| Sicherungskopien (Datenbank-Backups) | Anbieterseitig (Supabase): 7 Tage rollierend · eigene verschlüsselte Sicherungskopien: längstens 30 Tage |
Nach einer Löschung können Daten für längstens 30 Tage in verschlüsselten Sicherungskopien fortbestehen und werden dann endgültig entfernt.
Zum Aktivitätsprotokoll (Audit-Log): Zur Sicherheit und Nachvollziehbarkeit administrativer Aktionen in geteilten Boards (z. B. Mitglied hinzugefügt/entfernt, Rolle geändert, Einladung erstellt/widerrufen, Moderation, Board- oder Konto-Löschung) führen wir ein serverseitiges Aktivitätsprotokoll: Akteur- und betroffene Nutzer-Kennung (UUID), Aktionstyp, Board-/Ressourcen-ID und Zeitstempel — bewusst ohne IP-Adresse. Rechtsgrundlage: Art. 6 Abs. 1 lit. f DSGVO (berechtigtes Interesse an Sicherheit und Missbrauchsprävention). Speicherfristen siehe Abschnitt 13.
14. Rechtsgrundlagen (Cloud)
Gebetsdaten fallen als Angaben zu religiösen Überzeugungen unter Art. 9 DSGVO (besondere Kategorien). Die Verarbeitung erfolgt auf Basis deiner ausdrücklichen Einwilligung (Art. 9 Abs. 2 lit. a DSGVO), die du vor der ersten Cloud-Nutzung aktiv erteilst. Du kannst diese Einwilligung jederzeit widerrufen.
15. Authentifizierung
Die Cloud-Version verwendet Magic Link / OTP per E-Mail – kein Passwort, kein Social Login (Google/Apple). Deine E-Mail-Adresse wird ausschließlich für die Authentifizierung verwendet. OTP-E-Mails werden über die E-Mail-Infrastruktur von Supabase versandt; Supabase handelt dabei als Auftragsverarbeiter (AVV).
16. Inhaltsverschlüsselung
Die Inhalte deiner Gebetsanliegen (Titel, Notizen, Erhörungen) sowie Board- und Kategorienamen werden auf deinem Gerät verschlüsselt, bevor sie auf unseren Servern gespeichert werden. Jedes Board hat einen eigenen Verschlüsselungsschlüssel. Diese Schlüssel werden ihrerseits verschlüsselt auf unseren Servern gespeichert — der dafür nötige Hauptschlüssel ist Bestandteil der App.
Was das bedeutet: Wer nur unsere Datenbank stiehlt, kann deine Inhalte nicht lesen. Wer zusätzlich die App selbst analysiert (Dekompilierung der App-Binary), könnte theoretisch den Hauptschlüssel extrahieren und damit Zugriff auf die Board-Schlüssel erlangen. Dieses Angriffsszenario setzt technisches Know-how und gezieltes Interesse an deinen Daten voraus.
Eine vollständige Ende-zu-Ende-Verschlüsselung — bei der selbst wir als Betreiber keinen theoretischen Zugriff hätten — ist für geteilte Boards technisch außerordentlich komplex und nicht Teil der aktuellen Version. Wir halten diese Einschränkung für wichtig zu kommunizieren, weil wir der Meinung sind, dass du selbst entscheiden sollst, welche Daten du in der Cloud speicherst.
17. Push-Benachrichtigungen (FCM / APNs)
Prayerboard vermeidet US-Dienste für alle Kerndaten. Für Cloud-Push-Benachrichtigungen nutzen wir plattformabhängig:
- Android: Firebase Cloud Messaging (FCM) von Google (USA) — es gibt aktuell keine gleichwertige Alternative ohne Nutzerkonfiguration.
- iOS: Apple Push Notification service (APNs) von Apple (USA) — von iOS technisch zwingend vorgegeben; kein alternativer Dienst möglich.
Wir halten das für wichtig zu sagen, weil du selbst entscheiden sollst, ob das für dich in Ordnung ist.
Push-Benachrichtigungen werden für folgende Ereignisse ausgelöst: Beitrittsanfragen für geteilte Boards, Löschung eines Boards durch den Owner, Hinweise zum Abo-Status, neue Gebetsanliegen in geteilten Boards (konfigurierbar: pro Anliegen, tägliche Board-Zusammenfassung oder tägliche Gesamt-Zusammenfassung — Standard: deaktiviert).
Die Benachrichtigungen enthalten bewusst keine Namen, keine Board-Bezeichnungen und keine Gebetsinhalte — nur einen allgemeinen Hinweis wie „Jemand möchte einem deiner Boards beitreten". Die vollständigen Details erscheinen erst in der App selbst, die sie ausschließlich aus dem lokalen Speicher deines Geräts liest.
Was Google und Apple dabei sehen: Zeitpunkt der Benachrichtigung, eine pseudonyme Geräte-ID sowie unsere App-Kennung. Da Prayerboard eine Gebets-App ist, ist allein der Zeitpunkt einer Benachrichtigung ein indirektes Signal religiöser Aktivität — dieser Zeitpunkt erreicht Google (Android) bzw. Apple (iOS). Wenn du das nicht möchtest, kannst du Push-Benachrichtigungen jederzeit in den App-Einstellungen deaktivieren — alle anderen Funktionen bleiben vollständig erhalten.
18. Anonyme Anliegen in Gruppenboards
In geteilten Boards kannst du Gebetsanliegen als „anonym" kennzeichnen. „Anonym" bedeutet: Dein Name ist für andere Mitglieder (Viewer und Editoren) nicht sichtbar. Board-Owner und -Admins können sehen, wer ein Anliegen verfasst hat — das ist für die Moderation des Boards notwendig. Als Betreiber haben wir technisch ebenfalls Zugriff auf diese Information; wir nutzen diese Information nicht (außer ggf. zu Supportzwecken) und geben sie nicht weiter.
19. Datenlöschung & Board-Mitgliedschaft (Cloud)
Konto löschen: Du kannst deinen Account jederzeit in den Einstellungen löschen. Alle persönlichen Daten werden vollständig entfernt. Bei Mitgliedschaft in geteilten Boards erhältst du vorher pro Board eine Wahl: Anonymisieren (Inhalte bleiben für die Gruppe, dein Name wird entfernt) oder Löschen (alle deine Inhalte werden aus dem Board entfernt).
Freiwilliger Austritt: Du kannst ein geteiltes Board jederzeit verlassen. Du wählst dabei — identisch zur Account-Löschung — pro Board: Anonymisieren oder Löschen deiner Inhalte.
Entfernung durch Owner oder Admin: Wenn ein Owner oder Admin dich aus einem Board entfernt, wählen sie, was mit deinen Anliegen im Board passiert: Anonymisieren oder Löschen. Du wirst über die Entfernung benachrichtigt, hast auf diese Entscheidung aber keinen Einfluss. Du kannst deine auf unseren Servern gespeicherten Daten jederzeit über privacy@prayerboard.de löschen lassen (Art. 17 DSGVO).
Lokale Daten nach Entfernung: Nach der Entfernung verlierst du sofort den Zugriff auf neue Inhalte dieses Boards auf unseren Servern. Bereits auf deinem Gerät gespeicherte Inhalte bleiben unter deiner Kontrolle — wir löschen lokale Daten nicht ohne deine Entscheidung vom Gerät (Offline-First-Prinzip). Die App zeigt dir eine Benachrichtigung mit drei Optionen:
- Alles jetzt löschen — eigene und fremde Anliegen werden sofort von deinem Gerät entfernt
- Eigene Anliegen behalten, alles andere jetzt löschen — deine Anliegen bleiben lokal; Anliegen anderer Mitglieder werden sofort entfernt
- Später entscheiden — Anliegen anderer Mitglieder werden nach 30 Tagen automatisch von deinem Gerät entfernt; deine eigenen Anliegen bleiben erhalten
Hinweis zu Inhalten: „Anonymisieren" entfernt deinen Namen als Ersteller eines Anliegens. Inhalte, die persönliche Angaben über andere Personen enthalten (z.B. Namen in Gebetsanliegen), liegen verschlüsselt auf unseren Servern und können von uns nicht automatisch geprüft oder bereinigt werden. Du trägst Verantwortung dafür, welche Daten anderer Personen du in Anliegen einträgst.
20. Widerruf der Einwilligung
Bei wesentlichen Änderungen der Datenschutzerklärung wirst du in der App zur erneuten Einwilligung aufgefordert. Lehnst du ab, wird der Cloud-Sync sofort deaktiviert. Du erhältst 30 Tage Zeit, deine Daten zu exportieren oder zuzustimmen. Nach 30 Tagen werden alle Cloud-Daten automatisch gelöscht.
21. Deine Rechte (Cloud)
Auskunft (Art. 15), Berichtigung (Art. 16), Löschung (Art. 17), Einschränkung (Art. 18), Datenübertragbarkeit (Art. 20) und Widerspruch (Art. 21). Anfragen an: privacy@prayerboard.de
22. Änderungen
Wesentliche Änderungen werden in der App-Beschreibung im App Store kommuniziert. Die jeweils aktuelle Version ist unter prayerboard.de/privacy-policy abrufbar.
23. Beschwerderecht
Du hast das Recht, dich bei der zuständigen Datenschutzaufsichtsbehörde zu beschweren, z. B. beim Unabhängigen Landeszentrum für Datenschutz Schleswig-Holstein (ULD).
24. Kontakt
Marcel Magens
E-Mail: privacy@prayerboard.de
Privacy Policy
Prayerboard App · Last updated: July 2026
1. Controller
Marcel Magens
Hasenweg 9
25365 Klein Offenseth-Sparrieshoop
Germany
Email: privacy@prayerboard.de
2. Minimum Age
Prayerboard is intended for users aged 16 and older. Under Art. 8 GDPR, independent consent to personal data processing requires a minimum age of 16 (Germany). Users under 16 may only use the app with the consent of a parent or guardian. The Cloud version enforces this through a mandatory confirmation in the setup wizard.
3. Permissions
| Permission | Purpose | Version |
|---|---|---|
| Notifications | Schedule local prayer reminders | All |
No additional permissions are required (no access to camera, microphone, contacts, or location).
4. No Analytics, No Tracking
Prayerboard contains no analytics tools, ad networks, or crash reporters. No usage analysis takes place.
If an error occurs in the app, it is logged exclusively locally on your device – only with technical details (error code, app version, operating system), never with prayer content, names or e-mail addresses. This diagnostic log is never transmitted automatically; it leaves your device only if you share it yourself in Settings under “Diagnostics” (e.g. as an e-mail to support). You can view and delete it there at any time; entries are removed automatically after 30 days at the latest.
5. Third-Party Libraries
The open-source libraries used (Flutter, Hive, Riverpod, etc.) operate exclusively on-device and transmit no data.
6. Subscription Management (RevenueCat)
For subscription management we use RevenueCat (Revenue Cat, Inc., USA). RevenueCat processes purchase receipts from Apple or Google to confirm your subscription status, along with a pseudonymous user ID — a randomly generated technical string containing no name, email address, or other identifying details. RevenueCat cannot identify you as a person. RevenueCat has no access to your prayer requests or other content. This ID is pseudonymous, not anonymous: we ourselves can link it to your account via our database, whereas RevenueCat cannot.
As a US company, RevenueCat involves a third-country transfer, which is covered by EU Standard Contractual Clauses (SCCs). RevenueCat is only contacted once you actively start a purchase or a purchase restore, or sign in with your account; after that, your subscription status is refreshed at app start. Purely local use — without a purchase and without an account — never contacts RevenueCat.
7. Prayer Reminders
Prayerboard schedules two types of local push notifications exclusively on your device:
- Request reminders: once, daily, or weekly on specific weekdays — configured directly on each prayer request.
- Prayer time reminders: recurring weekly on weekdays and times you choose — configured centrally in the app settings.
Notification content does not leave your device and is not transmitted to Apple, Google, or any third party.
8. Home Screen Widget
The optional home screen widget displays prayer requests on your home screen. For the operating system to display the widget even when the app is not running, the displayed requests must be stored in a separate, OS-managed storage area (shared container). This shared container is protected by the operating system's app sandbox and is not accessible to other apps. The data does not leave your device. Only the data used by the widget is stored there temporarily. The widget can be disabled in the settings at any time; upon disabling, the container is immediately cleared.
9. Export Feature
The JSON export creates a file on your device. How you use or share this file is your responsibility. Exported data is not automatically transmitted anywhere.
10. Data Storage (Local)
All data you enter (prayer requests, boards, categories, notes) is stored exclusively locally on your device. No data is transmitted to servers or third parties. The database is encrypted with AES-256; the key is stored in the operating system's secure key storage (iOS Secure Enclave / Android Keystore).
11. Your Rights (Local)
Since no personal data is stored on external servers, all data resides exclusively on your device under your control. You can permanently remove all data at any time by uninstalling the app. A full JSON export is available at any time via the app's settings.
12. Data Processed (Cloud)
| Data | Purpose | Location |
|---|---|---|
| Email address | Authentication via OTP | Supabase, Frankfurt (DE) |
| Display name | Visibility as a member in shared boards; freely chosen name that need not be a real name or email address | Supabase, Frankfurt (DE) |
| Prayer requests, boards (encrypted) | Sync & backup | Supabase, Frankfurt (DE) |
| Consent timestamp | GDPR record-keeping | Supabase, Frankfurt (DE) |
| Push token (Android) | Cloud notifications | FCM / Google (USA) — see Section 17 |
| Push token (iOS) | Cloud notifications | APNs / Apple (USA) — see Section 17 |
13. Data Retention (Cloud)
| Data | Retention Period |
|---|---|
| Email address, profile data (incl. display name) | Until account deletion |
| OTP code | 15 minutes (automatically invalidated) |
| Session token | 7 days; refresh token: 90 days |
| Prayer requests, boards (encrypted, active) | Until account deletion |
| Prayer requests / boards (deleted by user) | 30 days, then permanently deleted. No user-visible trash — the grace period is required for cross-device synchronisation. |
| Cloud board data after disabling cloud backup | 30 days, then permanently deleted. The grace period ensures all your devices can synchronise the removal before the data is permanently deleted. |
| Consent timestamp | Until account deletion |
| Push token (FCM / APNs) | Until account deletion or deactivation of push notifications |
| Audit log (activity log) | 90 days |
| Audit log (after account deletion) | 30 days after account deletion |
| Backup copies (database backups) | Provider-side (Supabase): 7 days rolling · our own encrypted backup copies: at most 30 days |
After a deletion, data may persist in encrypted backup copies for at most 30 days and is then permanently removed.
About the activity log (audit log): For the security and traceability of administrative actions in shared boards (e.g. member added/removed, role changed, invitation created/revoked, moderation, board or account deletion) we keep a server-side activity log: actor and affected-user identifier (UUID), action type, board/resource ID, and timestamp — deliberately without an IP address. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in security and abuse prevention). Retention periods: see Section 13.
14. Legal Basis (Cloud)
Prayer data constitutes information about religious beliefs and falls under Art. 9 GDPR (special categories). Processing is based on your explicit consent (Art. 9(2)(a) GDPR), which you actively provide before first use of Cloud features. You may withdraw this consent at any time.
15. Authentication
The Cloud version uses Magic Link / OTP via email — no password, no social login (Google/Apple). Your email address is used exclusively for authentication. OTP emails are sent via Supabase's email infrastructure; Supabase acts as a data processor under a DPA.
16. Content Encryption
The content of your prayer requests (title, notes, outcomes) and board and category names are encrypted on your device before being stored on our servers. Each board has its own encryption key. These keys are themselves stored encrypted on our servers — the master key needed for this is embedded in the app.
What this means: Anyone who only steals our database cannot read your content. Anyone who additionally analyses the app itself (decompilation of the app binary) could theoretically extract the master key and thereby gain access to the board keys. This attack scenario requires technical expertise and targeted interest in your data.
Full end-to-end encryption — where even we as the operator would have no theoretical access — is technically extremely complex for shared boards and is not part of the current version. We believe it's important to communicate this limitation, because we think you should be able to decide for yourself what data you store in the cloud.
17. Push Notifications (FCM / APNs)
Prayerboard avoids US services for all core data. However, for cloud push notifications we use platform-specific services:
- Android: Firebase Cloud Messaging (FCM) by Google (USA) — there is currently no equivalent alternative without user configuration.
- iOS: Apple Push Notification service (APNs) by Apple (USA) — technically required by iOS; no alternative service is possible.
We think it's important to be transparent about this, because you should be able to decide for yourself whether this is acceptable to you.
Push notifications are triggered for the following events: join requests for shared boards, deletion of a board by the owner, subscription status updates, new prayer requests in shared boards (configurable: per item, daily board summary, or daily global summary — default: disabled).
Notifications intentionally contain no names, board names, or prayer content — only a generic notice such as "Someone wants to join one of your boards." Full details appear only in the app itself, which reads them exclusively from your device's local storage.
What Google and Apple see: the timestamp of the notification, a pseudonymous device ID, and our app identifier. Because Prayerboard is a prayer app, even the timing of a notification is an indirect signal of religious activity — this timestamp reaches Google (Android) or Apple (iOS). If you prefer, you can disable push notifications at any time in the app settings — all other features remain fully available.
18. Anonymous Requests in Group Boards
In shared boards you can mark prayer requests as "anonymous". "Anonymous" means: your name is not visible to other members (viewers and editors). Board owners and admins can see who wrote a prayer request — this is necessary for board moderation. As the operator, we also have technical access to this information; we do not use this information (except possibly for support purposes) and do not share it.
19. Data Deletion & Board Membership (Cloud)
Delete account: You can delete your account at any time in the settings. All personal data will be permanently removed. If you are a member of shared boards, you will first be given a choice per board: Anonymise (content remains for the group, your name is removed) or Delete (all your content is removed from the board).
Voluntary departure: You can leave a shared board at any time. As with account deletion, you choose per board: Anonymise or Delete your content.
Removal by owner or admin: If an owner or admin removes you from a board, they decide what happens to your prayer requests: anonymise or delete. You will be notified of the removal but have no influence over this decision. You can request deletion of your data on our servers at any time via privacy@prayerboard.de (Art. 17 GDPR).
Local data after removal: After removal you immediately lose access to new content from this board on our servers. Data already stored on your device remains under your control — we do not delete local data from your device without your decision (offline-first principle). The app will show you a notification with three options:
- Delete everything now — your own and other members' prayer requests are removed from your device immediately
- Keep my own requests, delete everything else now — your requests stay locally; other members' requests are deleted immediately
- Decide later — other members' requests are automatically removed from your device after 30 days; your own requests remain
Note on content: "Anonymise" removes your name as the creator of a prayer request. Content containing personal information about others (e.g. names in prayer requests) is stored encrypted on our servers and cannot be automatically reviewed or cleaned by us. You are responsible for what personal data about others you include in your prayer requests.
20. Withdrawal of Consent
When material changes are made to this privacy policy, you will be prompted to consent again in the app. If you decline, cloud sync is immediately disabled. You have 30 days to export your data or accept the updated policy. After 30 days, all cloud data is automatically deleted.
21. Your Rights (Cloud)
Access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), data portability (Art. 20), and objection (Art. 21). Requests to: privacy@prayerboard.de
22. Changes
Material changes will be communicated in the App Store description. The current version is always available at prayerboard.de/privacy-policy.
23. Right to Lodge a Complaint
You have the right to lodge a complaint with a supervisory authority, e.g. the Independent Centre for Privacy Protection Schleswig-Holstein (ULD), Germany.
24. Contact
Marcel Magens
Email: privacy@prayerboard.de
Política de privacidad
App Prayerboard · Última actualización: julio de 2026 · Esta traducción se ofrece a título informativo; jurídicamente vinculante es la versión alemana.
1. Responsable del tratamiento
Marcel Magens
Hasenweg 9
25365 Klein Offenseth-Sparrieshoop
Alemania
Correo electrónico: privacy@prayerboard.de
2. Edad mínima
Prayerboard se dirige a usuarios a partir de 16 años. Conforme al art. 8 del RGPD, para un consentimiento propio al tratamiento de datos personales se requiere una edad mínima de 16 años (Alemania). Los menores de 16 años solo pueden usar la app con el consentimiento de un tutor legal. La versión Cloud lo garantiza mediante una confirmación obligatoria en el asistente de configuración.
3. Permisos
| Permiso | Finalidad | Versión |
|---|---|---|
| Notificaciones | Programar recordatorios de oración locales | Todas |
No se necesitan más permisos (sin acceso a cámara, micrófono, contactos ni ubicación).
4. Sin analíticas, sin rastreo
Prayerboard no contiene herramientas de análisis, redes publicitarias ni informes de fallos. No se realiza ningún análisis de uso.
Si ocurre un error en la app, se registra exclusivamente en tu dispositivo, solo con datos técnicos (código de error, versión de la app, sistema operativo), nunca con contenidos de oración, nombres ni direcciones de correo. Este registro de diagnóstico nunca se transmite automáticamente; solo sale de tu dispositivo si tú mismo lo compartes en Ajustes, en «Diagnóstico» (p. ej., como correo al soporte). Allí puedes consultarlo y borrarlo en cualquier momento; las entradas se eliminan automáticamente a más tardar a los 30 días.
5. Bibliotecas de terceros
Las bibliotecas de código abierto utilizadas (Flutter, Hive, Riverpod, entre otras) trabajan exclusivamente en local y no transmiten datos.
6. Gestión de suscripciones (RevenueCat)
Para gestionar las suscripciones usamos RevenueCat (Revenue Cat, Inc., EE. UU.). RevenueCat procesa los justificantes de compra de Apple o Google para confirmar el estado de tu suscripción, así como un identificador de usuario seudónimo: una cadena técnica generada al azar, sin nombre real, dirección de correo ni otros rasgos identificativos. RevenueCat no puede identificarte como persona. RevenueCat no tiene acceso a tus peticiones de oración ni a otros contenidos. Este identificador es seudónimo, no anónimo: nosotros podemos asociarlo a tu cuenta a través de nuestra base de datos; RevenueCat, no.
Como RevenueCat es una empresa estadounidense, se produce una transferencia a un tercer país, cubierta por las cláusulas contractuales tipo de la UE (SCC). Solo se contacta con RevenueCat cuando inicias activamente una compra o una restauración de compras, o cuando inicias sesión con tu cuenta; después, el estado de tu suscripción se actualiza al arrancar la app. El uso puramente local — sin compra y sin cuenta — nunca contacta con RevenueCat.
7. Recordatorios de oración
Prayerboard programa dos tipos de notificaciones locales exclusivamente en tu dispositivo:
- Recordatorios por petición: una vez, a diario o semanalmente en días concretos, configurables directamente en cada petición.
- Recordatorios de tiempo de oración: semanales, en los días y horas que elijas, configurables de forma central en los ajustes.
El contenido de las notificaciones no sale de tu dispositivo y no se transmite a Apple, Google ni a terceros.
8. Widget de pantalla de inicio
El widget opcional muestra peticiones de oración en la pantalla de inicio. Para que el sistema operativo pueda mostrar el widget aunque la app no esté abierta, las peticiones mostradas deben guardarse en un área de almacenamiento separada gestionada por el sistema (contenedor compartido). Ese contenedor está protegido por el aislamiento de apps del sistema operativo y no es accesible para otras apps. Los datos no salen de tu dispositivo. Aun así, allí solo se guardan temporalmente los datos que usa el widget. El widget se puede desactivar en cualquier momento en los ajustes; al desactivarlo, el contenedor se vacía de inmediato.
9. Función de exportación
La exportación JSON crea un archivo en tu dispositivo. Cómo uses o compartas ese archivo es responsabilidad tuya. Los datos exportados no se transmiten automáticamente.
10. Almacenamiento de datos (Local)
Todos los datos que introduces (peticiones, Prayerboards, categorías, notas) se guardan exclusivamente en local, en tu dispositivo. No hay transmisión a servidores ni a terceros. La base de datos está cifrada con AES-256; la clave se guarda en el almacén seguro del sistema operativo (Secure Enclave de iOS / Keystore de Android).
11. Tus derechos (Local)
Como no se guardan datos personales en servidores externos, todos los datos están únicamente en tu dispositivo, bajo tu control. Puedes eliminarlos por completo en cualquier momento desinstalando la app. Una exportación JSON de todos los datos está siempre disponible en los ajustes.
12. Datos tratados (Cloud)
| Categoría de datos | Finalidad | Ubicación |
|---|---|---|
| Dirección de correo | Autenticación mediante OTP | Supabase, Fráncfort (DE) |
| Nombre para mostrar | Visibilidad como miembro en Prayerboards compartidos; nombre de libre elección que no tiene por qué ser el real ni la dirección de correo | Supabase, Fráncfort (DE) |
| Peticiones y Prayerboards (cifrados) | Sincronización y copia de seguridad | Supabase, Fráncfort (DE) |
| Marca de tiempo del consentimiento | Prueba conforme al RGPD | Supabase, Fráncfort (DE) |
| Token push (Android) | Notificaciones de la nube | FCM / Google (EE. UU.), véase la sección 17 |
| Token push (iOS) | Notificaciones de la nube | APNs / Apple (EE. UU.), véase la sección 17 |
13. Plazos de conservación (Cloud)
| Categoría de datos | Plazo |
|---|---|
| Dirección de correo, datos de perfil | Hasta la eliminación de la cuenta |
| Código OTP | 15 minutos (caduca automáticamente) |
| Token de sesión | 7 días; token de renovación: 90 días |
| Peticiones y Prayerboards (cifrados, activos) | Hasta la eliminación de la cuenta |
| Peticiones / Prayerboards (eliminados por el usuario) | 30 días; después, eliminación física. No hay papelera visible: el plazo de transición sirve para la sincronización entre dispositivos. |
| Datos de un Prayerboard tras desactivar la copia en la nube | 30 días; después, eliminación física. El plazo garantiza que todos tus dispositivos sincronicen la retirada del Prayerboard antes de su eliminación definitiva. |
| Marca de tiempo del consentimiento | Hasta la eliminación de la cuenta |
| Token push (FCM / APNs) | Hasta la eliminación de la cuenta o la desactivación de las notificaciones push |
| Registro de actividad (audit log) | 90 días |
| Registro de actividad (tras eliminar la cuenta) | 30 días después de la eliminación de la cuenta |
| Copias de seguridad (base de datos) | Del proveedor (Supabase): 7 días, rotatorio · copias de seguridad cifradas propias: como máximo 30 días |
Tras una eliminación, los datos pueden persistir en copias de seguridad cifradas durante un máximo de 30 días y después se eliminan definitivamente.
Sobre el registro de actividad (audit log): para la seguridad y la trazabilidad de las acciones administrativas en Prayerboards compartidos (por ejemplo, miembro añadido/eliminado, rol cambiado, invitación creada/revocada, moderación, eliminación de un Prayerboard o de una cuenta) llevamos un registro en el servidor: identificador (UUID) del actor y del usuario afectado, tipo de acción, identificador del Prayerboard o recurso y marca de tiempo, deliberadamente sin dirección IP. Base jurídica: art. 6, apdo. 1, letra f del RGPD (interés legítimo en la seguridad y la prevención de abusos). Plazos de conservación: véase la sección 13.
14. Bases jurídicas (Cloud)
Los datos de oración, como información sobre convicciones religiosas, entran en el art. 9 del RGPD (categorías especiales). El tratamiento se basa en tu consentimiento expreso (art. 9, apdo. 2, letra a del RGPD), que otorgas activamente antes del primer uso de la nube. Puedes revocarlo en cualquier momento.
15. Autenticación
La versión Cloud usa enlace mágico / OTP por correo electrónico: sin contraseña, sin inicio de sesión con redes sociales (Google/Apple). Tu dirección de correo se usa exclusivamente para la autenticación. Los correos con el OTP se envían a través de la infraestructura de correo de Supabase; Supabase actúa como encargado del tratamiento (contrato de encargo).
16. Cifrado de contenidos
El contenido de tus peticiones (título, notas, respuestas) y los nombres de Prayerboards y categorías se cifran en tu dispositivo antes de guardarse en nuestros servidores. Cada Prayerboard tiene su propia clave de cifrado. Esas claves se guardan a su vez cifradas en nuestros servidores; la clave maestra necesaria forma parte de la app.
Qué significa esto: quien solo robe nuestra base de datos no puede leer tus contenidos. Quien además analice la propia app (descompilando el binario) podría, en teoría, extraer la clave maestra y con ella acceder a las claves de los Prayerboards. Ese escenario de ataque requiere conocimientos técnicos y un interés dirigido a tus datos.
Un cifrado de extremo a extremo completo —en el que ni siquiera nosotros como operador tendríamos acceso teórico— es técnicamente extraordinariamente complejo para Prayerboards compartidos y no forma parte de la versión actual. Nos parece importante comunicar esta limitación, porque creemos que debes decidir tú qué datos guardas en la nube.
17. Notificaciones push (FCM / APNs)
Prayerboard evita servicios de EE. UU. para todos los datos centrales. Para las notificaciones push de la nube usamos, según la plataforma:
- Android: Firebase Cloud Messaging (FCM) de Google (EE. UU.); actualmente no existe una alternativa equivalente sin configuración por parte del usuario.
- iOS: Apple Push Notification service (APNs) de Apple (EE. UU.); impuesto técnicamente por iOS, sin servicio alternativo posible.
Nos parece importante decirlo, porque debes decidir tú si te parece bien.
Las notificaciones push se envían para estos eventos: solicitudes de acceso a Prayerboards compartidos, eliminación de un Prayerboard por su propietario, avisos sobre el estado de la suscripción y nuevas peticiones en Prayerboards compartidos (configurable: por petición, resumen diario por Prayerboard o resumen diario global; predeterminado: desactivado).
Las notificaciones no contienen deliberadamente ni nombres, ni títulos de Prayerboards, ni contenidos de oración: solo un aviso genérico como «Alguien quiere unirse a uno de tus Prayerboards». Los detalles completos aparecen solo en la app, que los lee exclusivamente del almacenamiento local de tu dispositivo.
Lo que Google y Apple ven: el momento de la notificación, un identificador seudónimo del dispositivo y el identificador de nuestra app. Como Prayerboard es una app de oración, el mero momento de una notificación es una señal indirecta de actividad religiosa, y ese momento llega a Google (Android) o Apple (iOS). Si no lo quieres, puedes desactivar las notificaciones push en cualquier momento en los ajustes de la app; todas las demás funciones se mantienen íntegras.
18. Peticiones anónimas en Prayerboards de grupo
En los Prayerboards compartidos puedes marcar peticiones como «anónimas». «Anónimo» significa: tu nombre no es visible para los demás miembros (lectores y editores). Los propietarios y administradores del Prayerboard pueden ver quién redactó una petición; es necesario para la moderación. Como operador, también tenemos técnicamente acceso a esa información; no la usamos (salvo, en su caso, para soporte) y no la cedemos.
19. Eliminación de datos y pertenencia a Prayerboards (Cloud)
Eliminar la cuenta: puedes eliminar tu cuenta en cualquier momento en los ajustes. Todos los datos personales se eliminan por completo. Si perteneces a Prayerboards compartidos, antes eliges por cada uno: anonimizar (los contenidos quedan para el grupo, tu nombre se retira) o eliminar (todos tus contenidos se retiran del Prayerboard).
Salida voluntaria: puedes abandonar un Prayerboard compartido en cualquier momento. Eliges entonces —igual que al eliminar la cuenta— por cada Prayerboard: anonimizar o eliminar tus contenidos.
Expulsión por el propietario o un administrador: si un propietario o administrador te retira de un Prayerboard, ellos deciden qué pasa con tus peticiones: anonimizar o eliminar. Se te informa de la retirada, pero no influyes en esa decisión. Puedes pedir en cualquier momento la eliminación de tus datos guardados en nuestros servidores en privacy@prayerboard.de (art. 17 del RGPD).
Datos locales tras la retirada: tras la retirada pierdes de inmediato el acceso a los contenidos nuevos de ese Prayerboard en nuestros servidores. Los contenidos ya guardados en tu dispositivo quedan bajo tu control; no eliminamos datos locales de tu dispositivo sin tu decisión (principio «offline primero»). La app te muestra un aviso con tres opciones:
- Eliminar todo ahora: tus peticiones y las de otros se retiran de inmediato de tu dispositivo
- Conservar mis peticiones, eliminar el resto ahora: tus peticiones quedan en local; las de otros miembros se retiran de inmediato
- Decidir más tarde: las peticiones de otros miembros se retiran automáticamente de tu dispositivo a los 30 días; las tuyas se conservan
Nota sobre los contenidos: «anonimizar» retira tu nombre como creador de una petición. Los contenidos que incluyan datos personales de otras personas (por ejemplo, nombres en peticiones) están cifrados en nuestros servidores y no podemos revisarlos ni depurarlos automáticamente. Eres responsable de qué datos de otras personas introduces en tus peticiones.
20. Revocación del consentimiento
Si esta política de privacidad cambia de forma sustancial, la app te pedirá un nuevo consentimiento. Si lo rechazas, la sincronización se desactiva de inmediato. Tienes 30 días para exportar tus datos o dar tu consentimiento. Pasados los 30 días, todos los datos de la nube se eliminan automáticamente.
21. Tus derechos (Cloud)
Acceso (art. 15), rectificación (art. 16), supresión (art. 17), limitación (art. 18), portabilidad (art. 20) y oposición (art. 21). Consultas a: privacy@prayerboard.de
22. Cambios
Los cambios sustanciales se comunican en la descripción de la app en la tienda. La versión vigente está siempre disponible en prayerboard.de/privacy-policy.
23. Derecho de reclamación
Tienes derecho a reclamar ante la autoridad de control competente, por ejemplo el Centro Independiente de Protección de Datos de Schleswig-Holstein (ULD), Alemania.
24. Contacto
Marcel Magens
Correo electrónico: privacy@prayerboard.de