DigiRosary
Privacy Policy
Effective 2 August 2026
DigiRosary is a prayer app developed and operated by Sahil Sunny. This policy explains what the app keeps on your device, what is sent to the DigiRosary service at sahilsunny.com, why it is used, and how to delete it.
Data kept on your device
Prayer preferences, custom prayer content, saved progress, reminders, settings, and a local copy of prayer statistics are stored on your device. Foreground location may be used, only after you enable motion cues and grant permission, to derive travel speed on the device. Coordinates and derived speed are not sent to DigiRosary or stored by the DigiRosary service.
Deleting a cloud account does not erase this local data. Use DigiRosary's local reset controls, clear the app's storage, or uninstall the app if you also want to remove data held on the device.
Account and cloud statistics
Creating an account is optional. When you create one, the service stores your email address, a one-way password hash, hashed authentication tokens, server-keyed digests of verification or reset codes, whether the email is verified, and the prayer statistics you choose to synchronize. Plain-text passwords are never stored. Account records and cloud statistics remain until you delete the account; this includes unverified accounts. API sessions expire after 90 days, email-verification codes after 24 hours, and password-reset codes after 30 minutes. Expired credentials are removed by scheduled pruning.
Synchronized statistics are linked to your account and can record your exact Rosary practice. This information can reveal religious practice or belief.
Remote usage telemetry
DigiRosary 1.0.0's launch build disables automatic remote usage telemetry. It does not create a persistent analytics installation identifier, send prayer-use or recitation events, transmit device or language dimensions for analytics, or cause the server to infer an analytics region. This does not disable optional cloud sync, release checks, foreground on-device motion cues, or bug reports that you explicitly review and submit.
The source retains a disabled mode for future consent-based analytics. If a later build offers that mode, DigiRosary will request affirmative consent before collection and update its in-app, public, and store disclosures first. Such a mode could link fixed Rosary start, completion, and active-recitation events to a pseudonymous installation identifier; those events and prayer language can reveal religious practice or belief. Anonymous rows already stored from pre-release or test builds become eligible for deletion after 30 days, and the daily cleanup normally removes them within the following 24 hours.
Bug reports
Bug reports are sent only when you submit them. A report can contain your description and reviewed annotated screenshot; exact app, operating-system, device, display, language, and connectivity context; navigation history; active mystery; Rosary total and streak; saved-progress key names; sign-in and verification flags; relevant settings; recent fixed diagnostic categories; and an optional contact email. User-entered text, screenshots, and prayer-state context can contain personal information or reveal religious practice or belief. Bug reports and attachments become eligible for deletion after 60 days; the daily cleanup normally removes them within the following 24 hours.
Network processing and service providers
sahilsunny.com processes requests over HTTPS. Network addresses are used transiently for security and abuse-rate limits but are not stored in the DigiRosary application database. Fly.io hosts the service and an email delivery provider processes account verification and password-reset mail. Data is not sold, used for advertising, or used for cross-app tracking.
Deleting your data
In DigiRosary, open Settings → Help → Cloud sync → Delete cloud account. You can also follow the instructions on the account-deletion page. Account deletion removes the email, password hash, authentication tokens and codes, and synchronized cloud statistics from the active service. The launch build sends no automatic analytics. Historical anonymous pre-release or test rows cannot be matched back to an account and follow the 30-day eligibility and daily-cleanup schedule above.
If you supplied an email address in a bug report, mention that in a manual deletion request so the report can also be located and removed. Routine encrypted disaster-recovery snapshots may retain deleted records for up to five additional days; they are isolated and used only for recovery.
Contact
DigiRosary is developed by Sahil Sunny. Questions and privacy requests can be sent to hello@sahilsunny.com.