Privacy Policy
Effective Date: April 4, 2026 | Last Updated: August 29, 2026
1. Introduction
Ra3y (راعي) is a church and community management application that helps churches manage family directories, visitation records, prayer requests, events, and pastoral care. This Privacy Policy explains how we collect, use, store, and protect your personal information.
By using Ra3y, you agree to the collection and use of information as described in this policy. If you do not agree, please discontinue use of the application.
2. Information We Collect
2.1 Account & Staff Information
- Full name, email address, phone number
- Role within the church (admin, priest, servant, member)
- Profile photo, date of birth, ordination date
- Church / organization affiliation
2.2 Family & Member Information
- Full name, date of birth, gender, family relationship
- Contact details: mobile, phone, email, WhatsApp, Facebook, Instagram, Twitter, LinkedIn
- Home address: street, city, district, building, floor, apartment number
- National ID number
- Member photo. A scanned page is processed on-device by default; if an authorized user explicitly consents to cloud AI processing, the compressed image is held in private temporary storage only for that scan.
- Employment: job title, company, work address, work phone
- Education: school, university, faculty, graduation year, degree
- Spiritual records: baptism date/place, confirmation, marital status, church ministry and service
- Health: blood type, health notes, chronic conditions, disability status
- Emergency contact name and phone
- Family needs assessment: financial, social, educational, housing status
- Lifecycle events: births, deaths, marriages
2.3 Location Data
- GPS coordinates of family addresses (only with your permission)
- Device location when using the family map feature
2.4 Usage & Technical Data
- Sanitized diagnostic event codes, exception types, stack fingerprints, and redacted top frames (via Firebase Crashlytics and Supabase). Free-form error messages and raw stack traces are not uploaded.
- Device tokens for push notifications (via Firebase Messaging)
- Sync activity and network connection status
- A 30-day, ordered app-action trail for support and quality: session start/end, screen navigation, tab changes, searches, and meaningful save/edit/delete actions. It does not record keystrokes, form values, passwords, OTP codes, phone or national-ID numbers, or the free-text content of notes, prayers, and confessions.
2.5 Feedback You Submit
- Feedback category, the app screen it relates to, and the description you enter
- Platform, app version, build number, church scope, and submission time
- Your account name and phone number are shown to authorized administrators so they can follow up on the report
- Images or videos you explicitly choose to attach; screenshots, media, and diagnostic logs are never attached automatically
The feedback form asks you not to include names, confessions, health, financial, or other sensitive pastoral information.
2.6 Service, Events & Outreach
- Verified links between a login account and a church member record; phone matching is used only to suggest a link and never links automatically
- Group memberships and leadership periods, event invitations, RSVP responses, and attendance
- Assigned Outreach tasks, structured results, optional follow-up notes, and follow-up dates
3. How We Use Your Information
- Pastoral Care: Enable priests and church staff to visit, support, and serve families effectively
- Family Directory: Maintain an organized, searchable directory of church members
- Visitation Tracking: Record and plan family visits by clergy
- Prayer & Spiritual Support: Manage prayer requests and spiritual guidance records
- Crisis Response: Identify and respond to families in need (financial, health, social crises)
- Events & Communication: Organize church events and send relevant notifications
- Distributed Service: Restrict servants to basic contact data for people in groups they lead or Outreach tasks assigned to them
- AI Scanner: Extract fields from a scanned page only after explicit consent. The app never saves extracted fields automatically; an authorized person reviews every field first.
- Data Import / Export: Allow active accounts to export role-scoped fields and administrators to import after recent phone verification. Export audit records contain the actor, church, role, template, record count, and time, but not file contents or free-form filters.
- App Improvement: Analyze crash reports and usage data to improve stability
- Support & Quality: Let the account owner and authorized active super administrators, administrators, or support staff reconstruct the steps in a recent app session when investigating a problem
- User Feedback: Review reported problems and suggestions within the submitting church's administrative scope. Super administrators may review feedback across churches.
4. Third-Party Services
Ra3y integrates the following third-party services that may process your data. Each service has its own privacy policy.
5. Data Storage & Security
- Local Storage: Data is stored on-device in an encrypted SQLite database (SQLCipher) for offline access
- Cloud Storage: Data syncs to Supabase (PostgreSQL) with Row-Level Security. Only authorized members of your church can access your organization's data.
- Encryption in Transit: All communications use HTTPS / TLS
- Access Control: Role-based permissions keep servants separate from priests and administrators. Servants cannot access confessions, health, crises, national IDs, or private notes.
- AI Isolation: Gemini is called from a protected server function. The client has no provider key, and scan images are stored in a private temporary bucket.
6. Data Retention
We retain account information while the login account remains active or as required by applicable law. Sanitized device diagnostics are retained for 14 days. The privacy-safe app-action trail and export audit records are retained for 30 days. Feedback and its private media attachments are deleted 180 days after it is marked resolved or dismissed; the user link is removed if the submitting login account is deleted.
An account-deletion request requires recent phone verification and has a 7-day cancellation period. Final processing occurs within 30 days. It deletes the login identity, profile, avatar, sessions, push tokens, and authentication/diagnostic data associated with the account.
Church pastoral records, including families, members, visits, confessions, health, and support records, are shared organizational records and are not deleted merely because a login account is deleted. Links to the deleted login identity are removed where applicable. Deletion of a pastoral record is a separate church/legal workflow.
An offline device cannot be erased remotely. Its encrypted local data is cleared when it next connects and receives the durable reset instruction.
Temporary scanner images are normally deleted immediately after processing and by a cleanup worker within one hour if processing is interrupted. Raw OCR text and raw AI responses are not stored in the database or diagnostics.
Reversible member-merge field snapshots are removed after the 30-day undo period. The identifier-only merge audit is retained for one year.
Events, attendance, group history, and Outreach activities are shared church records. If a login account is deleted, its identity link is removed while the church record remains and the actor reference becomes anonymous where applicable.
7. Your Rights
Depending on your jurisdiction, you may have the right to:
- Access: Request a copy of the personal data we hold about you
- Correction: Request correction of inaccurate or incomplete data
- Account deletion: Delete your login identity through the protected in-app flow, with a 7-day cancellation period
- Pastoral-record request: Ask the responsible church administrator to review correction or deletion of a shared pastoral record under the applicable church/legal process
- Restriction: Request that we restrict processing of your data
- Portability: Receive your data in a structured, machine-readable format
- Objection: Object to processing of your personal data
To exercise any of these rights, contact your church administrator or reach out to us directly.
8. Children's Privacy
Ra3y collects information about minors (children of church families) as part of family records. This data is entered by authorized church staff or parents/guardians, not directly by minors. We do not knowingly solicit personal information from children under 13 through the app.
9. Sharing of Information
We do not sell, rent, or trade your personal information to third parties. Data is only shared:
- With authorized staff within your church organization
- With third-party service providers listed in Section 4, solely to operate the app
- When required by law or to protect the safety of individuals
10. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of significant changes via the app or by email. Continued use of Ra3y after changes constitutes acceptance of the updated policy.
11. Contact Us
If you have any questions about this Privacy Policy or your data, please contact:
andrew.george.rage@gmail.comWhatsApp: +20 128 616 1777