This is a draft. It has been written to be technically accurate and to reflect how Ripple's systems actually work, but it has not been reviewed by a lawyer and must not be published, relied upon, or treated as legally binding until it has.
Entity: Kivfer Holdings Inc., Winnipeg, Manitoba, Canada ("Ripple," "we," "us," or "our")
This Privacy Policy explains what information Ripple collects, why, how it's used, who we share it with, and the choices you have.
Account information. When you create an account, we collect your email address, your first and last name (used for our own communications with you — never shown to anyone you pray for or who prays for you), a self-declared confirmation that you're 16 or older, and, if you sign in with Apple or Google, the identifier those services provide us.
A separate, public display name. You can choose a display name that's shown to the person you're praying for or being prayed for by. This is deliberately kept separate from your real name and is never linked to it for anyone but you and Ripple.
Prayer requests. The text of any prayer request you submit, along with an optional category and urgency flag.
Recorded prayers. The audio recording you make when praying for someone, along with an automatically generated transcript used for content screening (Section 3).
Device and usage data. Basic technical information (device type, app version, crash and performance data) collected automatically to keep the Service working and to fix problems.
Anonymous submissions. If you submit a prayer request through our public website without creating an account, we collect the display name, email address, and request text you provide — the same core information listed above, without an associated Ripple account.
Analytics and cookies. When you visit our website, we use Google Analytics and Google Tag Manager to understand how visitors use it — which pages are viewed, which links are clicked, and how a visitor moves from our marketing pages through to signing up or joining. This is anonymized, aggregate usage data, not linked to your prayer content or account activity. A cookie-consent banner lets you choose whether this analytics tracking is enabled when you first visit; declining does not affect your ability to use the site or app.
Referral information (pre-launch only). While Ripple is pre-launch, we run a waitlist referral program (see our Terms of Service, Section 10A). If you join the waitlist through another member's referral link, we record which member referred you. If you share your own link, we record which waitlist signups came from it and how many confirm their email address. To detect fake or automated referral activity, we also store a one-way, irreversible fingerprint derived from your network address at the time you sign up (not the address itself, which we never keep), together with the time of signup. If you arrive through a referral link (a ripple.faith/r/... address), we set one first-party cookie, ripple_ref, that remembers the referral code so you're still credited to the right member if you finish signing up later. It holds only that short code, expires after 30 days, and is never used for advertising. All of this information is used only to run and protect the referral program, is not shared with anyone, and will be removed when the program ends.
We do not sell your personal information, and we do not use your prayer requests or recorded prayers for advertising.
Recorded prayers are stored in private cloud storage — never a public location. The only way a recorded prayer is ever accessible is through a short-lived, signed link generated specifically for the intended recipient at the time of delivery. There is no public bucket or open folder of prayer audio.
Before a prayer request enters the queue that matches it to a Praying Member, and before a recorded prayer is delivered, both are automatically screened by an AI-assisted validation step, and recorded audio is automatically transcribed to support that screening. This is an automated process, not manual staff review of every submission — see our Terms of Service, Section 5, for what this screening does and doesn't catch.
Ripple's public prayer-listening page is a deliberately different, intentionally shareable space: it's the page a Prayer Recipient uses to listen to the prayer recorded for them, and it's designed to be shareable (for example, so a recipient can send the link to a friend or family member). This is a separate mechanism from the private, signed-URL-only storage described above — the listening page is meant to be shared by the recipient; the underlying raw audio storage is not.
We use a small number of service providers to run Ripple. We don't sell your data to them — they process it on our behalf, under agreements that limit what they can do with it:
(Once Ripple's regular paid membership system is live, this section will be updated to name the payment processors involved — Apple's and Google's own in-app payment systems, and, if we route certain purchases through a web checkout instead, Superwall (our paywall provider) and Stripe (that checkout's payment processor). No new category of data is anticipated; this is a small addition to this list, not a rewrite of this policy.)
We may also disclose information if required by law, to protect the safety of our users, or in connection with a merger, sale, or transfer of Ripple (see our Terms of Service, Section 16).
We keep your information for as long as your account is active, and for a period afterward as described below.
When you delete your account:
Referral program data (pre-launch only). Records of who referred whom are kept as part of the waitlist record for as long as the pre-launch referral program runs, so that rewards can be calculated and verified. The one-way origin fingerprint described in Section 1 is deleted when the referral program ends.
Depending on where you live, you may have rights to access, correct, export, or delete your personal information, and to object to or restrict certain uses of it.
If you're located in the European Union or United Kingdom, you may also have rights under the GDPR, including the right to lodge a complaint with your local data protection authority. If you're located in a US state with its own privacy law (such as California), you may have additional rights under that law. (Because Ripple may serve users outside Canada, this section needs specific legal review to confirm what applies where — flagged here and in the Terms of Service as a known open question for attorney review, not silently assumed out of scope.)
Ripple's minimum account age is 16. We do not knowingly collect personal information from anyone under 16, and we do not knowingly allow anyone under 16 to create an account. If we learn that someone under 16 has created an account, we will take steps to close it.
We use industry-standard safeguards to protect your information, including encrypted storage, access controls, and the private-storage/signed-URL approach described in Section 3. No system is perfectly secure, and we can't guarantee absolute security, but protecting your information — especially your prayer content — is treated as a first-order responsibility, not an afterthought.
If we make a material change to this policy, we'll let you know through the app or by email before it takes effect.
Questions about this Privacy Policy, or requests regarding your personal information, can be sent to [contact email — to be added].
The Creator Platform is a separate feature from the Ripple app. It lets a Christian content creator connect a social media channel so that sincere prayer requests left in their public comments can be prayed for by Ripple members, with the recorded prayer delivered back as a public reply from the creator's own account. This section describes the data handling specific to that feature. It involves two groups of people: creators, who choose to connect a channel, and commenters, who leave public comments on that creator's content.
Creators. A creator connecting a channel provides an email address and basic contact information (an ordinary business-style signup) and authorizes Ripple to act on their channel through the platform's official API. For YouTube, this authorization is granted through Google and covers two things: reading the public comments and public video information on the creator's channel, and, on the creator's behalf and only for delivering a completed prayer, posting reply comments and reading the creator's own channel details. The creator's authorization credential (an OAuth token) is stored encrypted, is used only for those purposes, and can be revoked by the creator at any time from their Google Account's security settings or by disconnecting the channel in Ripple. Disconnecting stops all monitoring and posting.
Commenters. When a creator has connected a channel, Ripple reads the public comments on that channel's videos and uses an automated classifier to identify which ones are sincere personal requests for prayer. Comments that are not are discarded. For a comment that is a genuine prayer request, Ripple creates an anonymized, third-person version for its prayer queue. A first name is kept only when the request is for a named person and only the first name (for example, "Mary"); every other identifying detail, including last names, full-name pairings, the commenter's own name, locations, ages, contact details, and links, is removed before any Ripple member sees it. Ripple stores the public identifier of the comment and the commenter's public channel identifier, which are needed so the eventual reply can be posted to the right place, together with that anonymized request text. Ripple does not collect the commenter's name or email address on this path, and does not send them any private message. Nothing is posted publicly unless and until a real recorded prayer exists, at which point the creator's account posts a short public reply containing a link to Ripple's prayer-listening page.
The basis for this processing is that the comment was a request for prayer, made publicly, on the content of a creator who invites such requests. If you left a public comment that has been processed this way and you would like the anonymized request or the stored identifiers removed, contact us at the address in Section 10 and we will remove them.
Google API Services. Ripple's use of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Data obtained through the YouTube Data API is used only to provide and improve the prayer-request features described in this section. It is not sold, not used for advertising, and not transferred to others except as needed to provide the feature or as required by law.