Privacy Policy
Effective Date: September 24, 2026
DuoFaith ("the App") is developed by Luke Downie ("we," "us," or "our"). This Privacy Policy explains what the App stores, what it sends to our servers, and what it never touches at all. We use information to operate and improve the App, and we never sell your data.
The Short Version
- There is no sign-up. No email address, no phone number, no password.
- Your profile and settings are stored on your device. Couples Mode shares your display name and written reflections with your partner, and the App sends usage events to our server.
- Every install is given a random anonymous ID, which is what lets the App load each day's devotional, redeem access codes and pair you with a partner.
- We never see which apps you choose to shield. Apple's frameworks are built so that we cannot.
- There are no adverts inside the App. We use first-party usage measurement through Supabase, and Meta's SDK to measure our own advertising. The App asks your permission before that measurement is linked to you.
Information Stored on Your Device
DuoFaith stores the following on your device using Apple's SwiftData framework:
- Your first name, entered during onboarding
- Your chosen lock time (hour and minute)
- Devotional progress: current streak, total devotionals completed, and the date of your last devotional
- Which of the last 60 days you completed a devotional, so the week view can be drawn
- Whether you have finished onboarding
- Your subscription status, including whether Pro came from an access code
- A copy of the devotionals you have already been shown, so the App still works with no signal
Deleting the App removes its local data. Some information is also transmitted for Couples Mode, subscription management, and first-party usage measurement, as described below. Uninstalling does not itself delete server-side data.
During onboarding the App asks for an age range and other routine preferences. These answers can be included in usage events, as described below.
Your Anonymous ID
The first time you open DuoFaith, the App creates an anonymous account on our server, which is hosted by Supabase. This happens for everyone, not only people who use Couples Mode, because it is what lets the App fetch each day's devotional, redeem access codes and pair you with a partner if you choose to.
This account uses a randomly generated identifier rather than an email address or password. Information needed for app features and usage measurement is associated with identifiers. If you use Couples Mode, this includes the display name and reflections you choose to share.
First-Party Usage Measurement
The App sends usage events to our Supabase server to understand onboarding, daily devotional completion, app blocking, retention, and subscription outcomes. Events include an installation identifier, session and account identifiers where available, timestamps, screen and action names, time spent, app version, device model, iOS version, locale, region setting, and time zone.
Event properties can include onboarding choices such as age bracket, self-reported screen time, morning routine preference, chosen lock time, selected app count, and subscription selections or outcomes. The analytics events do not include the text of your name or your reflection answers. Couples Mode separately sends your display name and reflections to provide sharing, as described below. Region and time zone come from device settings; the App does not request GPS location.
Devotional Content
Daily devotionals are written in advance and stored on our server. The App requests them using your anonymous identifier and keeps a local copy of the ones you have already seen so it works offline. These requests carry no name and no personal information. Bible passages are quoted from the World English Bible, a public domain translation.
Push Notifications
On launch, the App registers a device token with Apple's Push Notification service and stores that token on our server against your anonymous identifier. The token is used to deliver notifications from DuoFaith, including shared-reflection updates. It is associated with your app account and is removed when you delete your account.
Reminder and streak notifications are scheduled locally and never leave your device. You can turn notifications off at any time in your device's Settings.
Couples Mode (Pro Feature)
If you pair with a partner, the following is stored on our server, associated with the paired app accounts:
- The invite code you generated and its expiry time (codes expire after 24 hours)
- A couple record linking two anonymous identifiers
- The date each of you completed a devotional, so your partner can see when you have finished
- Nudge records: who sent a reminder, to whom, and when
- Your shared reflection streak
- Your display name and your written answers to daily reflection questions
Your display name and written reflections are shared with the person you pair with. Your partner’s answer is not returned to your app until you submit your own answer; both answers are available once both partners have written. A reflection written offline can be stored locally and sent when connectivity returns. Your partner can also see your reading status and shared reflection streak. Your selected app identities are not shared with your partner.
Screen Time and Family Controls
DuoFaith uses Apple's Screen Time API (Family Controls and Managed Settings) to shield selected apps until you complete your daily devotional. Your app selections are handled entirely inside Apple's on-device frameworks, which are deliberately designed so that the App is never told which apps you picked. We never see, store or transmit that list. You can revoke Screen Time authorization at any time in your device's Settings.
Subscriptions
DuoFaith uses RevenueCat to manage in-app subscriptions. RevenueCat receives an anonymous app user identifier and your subscription status from Apple's App Store. It does not receive your name or any other personal information from DuoFaith. For more information, see RevenueCat's Privacy Policy. Where you have allowed tracking, RevenueCat may also pass subscription events to Meta for the advertising measurement described below.
Advertising Measurement
If you installed DuoFaith after tapping one of our adverts in the App Store, the App passes Apple's AdServices attribution token to RevenueCat. This tells us which advert or search term led to the install, so we can see which adverts are worth paying for. This part is first-party measurement of our own adverts on Apple's platform, provided by Apple.
We also advertise DuoFaith on Facebook and Instagram. To know whether those adverts work, the App includes Meta's SDK. It reports a short list of events to Meta: that the App was installed and opened, that the paywall was shown, that onboarding was finished, that a devotional was completed, and that a trial or subscription started, including the amount and currency.
Meta is never told your name, your written reflections, the devotionals you read, or which apps you chose to shield.
Before any of this can be connected to you as a person, iOS asks your permission using Apple's App Tracking Transparency prompt. If you allow it, Meta can match these events to the advert you saw. If you decline, Meta receives only anonymous, aggregated measurement and cannot connect it to your device. You can change your answer at any time in your device's Settings, under Privacy and Security, then Tracking.
No advert is ever shown inside DuoFaith.
Access Codes
If you redeem an access code to unlock Pro, the redemption is recorded on our server against your anonymous identifier so that the same code cannot be used twice. The App also notes locally that your Pro access came from a code, so it still works offline. Nothing else is collected when you redeem.
Data We Do NOT Collect
DuoFaith does not:
- Ask you to create an account with an email address, phone number or password
- Sell your data to anyone
- Track you across other companies' apps or websites without asking your permission first
- Collect your location
- Use cookies or web tracking inside the App
- See or record which apps you choose to shield
Where Your Data Is Stored
Server-side data is held by Supabase, our hosting provider, and by RevenueCat for subscription status. Both act as processors on our behalf. Advertising measurement events are sent to Meta, as described above. None of these are given your name or contact details. Depending on where you live, this may mean your anonymous identifier is stored outside your own country.
Data Retention and Deletion
On-device data is kept for as long as the App is installed. You can clear your progress at any time with "Reset Progress" in Settings, and deleting the App removes everything stored locally.
On the server, you can unpair from your partner in Settings, which ends the couple relationship. You can also delete your account from Settings, which removes everything held against your anonymous identifier: the account itself, completion records, nudge history, invite codes and your device token.
Because the identifier is anonymous, we cannot recover any of it afterwards, and we cannot look your account up for you by name or email address. That is a deliberate trade: it is the same property that stops us from building a profile of you.
Children's Privacy
DuoFaith is not directed at children under 13, and we do not knowingly collect personal information from them. The App requires no email address, password or precise location. If you use Couples Mode, the display name and reflections you choose to share are transmitted to your paired partner and our service so the feature can work. If you believe a child has provided us with personal information, contact us and we will remove it.
Changes to This Policy
We may update this Privacy Policy from time to time. Changes will be posted on this page with an updated effective date. Continued use of the App after a change constitutes acceptance of the revised policy.
Contact Us
If you have questions about this Privacy Policy, contact us at:
duofaithsupport@gmail.com
© 2026 DuoFaith. All rights reserved.