Your data · Your choice

Privacy Policy

Lampada is a personal Christian prayer app. Prayer content may reveal deeply sensitive information, so it stays on your device unless you explicitly choose a feature that needs external processing.

Effective date
September 5, 2026
Maintainer
Maria Novikova

Scope

This policy applies to the Lampada mobile app and the public website at lampada.app. It does not apply to the separate Bible Garden app or its website, although both apps use the same operator-owned backend at api.bible.garden.

Lampada is provided and maintained by Maria Novikova, who is responsible for the processing described in this policy.

Lampada does not require an account, registration, your name, email address, phone number, contacts or location.

Data kept on your device

The following data is stored locally and is not sent merely because you use the app:

  • prayer topics, generated questions, typed answers and final takeaways;
  • voice recordings and their transcripts;
  • prayer history, saved scripture passages and favourites;
  • consent choices, scripture settings, reminders and prayer-day history;
  • optional PIN and biometric lock settings, and a local diagnostic log that must not contain prayer content.

The PIN itself is never stored or transmitted. Scheduled prayer reminders are local operating-system notifications and are not sent through a push service.

Depending on your operating-system and cloud-backup settings, locally stored app data may be included in a device backup managed by Apple or Google. Lampada does not operate or control those backups.

Optional AI processing

Lampada has three independent AI features. Each one requires its own explicit, versioned choice before the relevant prayer content leaves your device.

  1. Core prayer AI. Sends the prayer topic to generate guiding questions and select relevant scripture.
  2. Answer context. Sends typed answers and completed transcripts so later questions, reflection and scripture selection can take them into account. This is separate from permission to send the topic.
  3. Audio transcription. Sends one recording you select and, when available, the device language as a transcription hint, solely to create a verbatim transcript. The recording is never sent as context for questions or scripture selection.

The app sends no prayer content while a choice is undecided or denied. Refusal does not block prayer: questions use a local curated pool, scripture can be selected without the prayer context, and local recordings remain playable and deletable.

Each AI choice is stored as undecided, allowed or denied. A missing setting, an old permissive default, silence or continued app use never means consent. You can change or withdraw each choice independently in Settings; withdrawal applies before the next request. A request that has already completed cannot be recalled.

Existing installations do not inherit permission from the old answer-sharing setting. A previous refusal remains a refusal; missing or permissive legacy values become undecided.

Server-side AI processing

Content you allow for AI processing is sent over HTTPS to Bible API at api.bible.garden. Text processing uses a self-hosted Qwen3-30B model on company-managed server infrastructure. Semantic search uses bge-m3 on the application server, and voice recordings are transcribed there using Whisper. These models run on servers, not on your phone; the three separate consent choices apply to these transfers.

Prayer content is processed only to fulfil your selected request. It is not sent to Google Gemini or other external AI service APIs, shared with the model developers, or used to train models. Bible API and the self-hosted model services do not persist prayer topics, answers, recordings, transcripts or generated responses, and do not include this content in logs. Technical request metadata is described separately below.

Technical request data

Bible API processes the endpoint, method, response status, latency and network information needed to operate and protect the service. For private AI endpoints, application statistics use an HMAC pseudonym instead of a directly stored client address and omit the user agent. Request and response bodies are never written to application analytics or logs.

Raw rows are deleted from the live application-statistics table after 14 days. Database backups made for disaster recovery may retain earlier pseudonymous rows for longer: rotation keeps recent copies, monthly restore points and two oldest anchor copies, while cross-host storage keeps three recent copies. Anchor copies remain until deliberately retired. Permanent daily aggregates contain counts only and cannot reconstruct prayer content.

Standard reverse-proxy access logs may separately contain the client address, timestamp, method, path, status, referrer and user agent. They contain no request or response bodies and are used only for operations and security. These logs are kept until manual cleanup or container replacement; the 14-day application-statistics retention period does not apply to them.

Website, analytics and tracking

Lampada contains no advertising or analytics SDKs and does not create behavioural profiles. The website sets no analytics cookies and stores only your selected language in local browser storage; that preference is not transmitted by Lampada.

The public website is delivered through Cloudflare. Cloudflare may process IP addresses, request metadata and security signals, and may set strictly necessary security cookies when required to protect the site. In-app AI traffic currently connects directly to api.bible.garden and is not routed through the Cloudflare website proxy.

Retention and deletion

Local prayer data remains until you delete a prayer or erase all Lampada data by uninstalling the app or using its full-wipe flow. Deleting a prayer removes its answers and recordings; its historical prayer-day marker remains until a full wipe. Favourites remain until removed or all data is erased. Device backups, if enabled, are controlled separately through your Apple or Google account.

Bible API and the self-hosted model services process prayer content for the duration of the request without retaining a persistent copy. There is no server-side prayer archive to delete later, and prayer content is not included in server backups. Technical metadata and its retention are described above.

Security

Network requests use HTTPS. Lampada minimises transferred content, keeps server secrets outside the app and offers an optional app lock with a PIN and device biometrics. No method can guarantee absolute security; protect access to your device and avoid sharing sensitive prayer content in public support channels.

Changes to processing

This page and its effective date will be updated when the policy changes. A material change of provider, legal processor, training or human-review use, retention or processing jurisdiction invalidates the affected AI choices. Lampada will show a new notice and ask again before sending affected content. A model-only change under unchanged data terms does not require a new choice.

Questions and requests

For a private question about this policy or your privacy choices, contact the Lampada maintainer on Telegram at @Mandarinka4. GitHub Issues are available for general public questions and bug reports. Do not include prayer text, recordings or other sensitive information in a public issue.

Plain-language summary

Your journal stays on your device. Prayer content is sent only for an AI feature you separately allow and is processed by self-hosted models on server infrastructure without being retained or used to train models.

Back to Lampada