Privacy Policy
Effective date: 4 October 2026.
This policy explains information handled when you read Devotional library, use its reading tools or contact us. Reading does not require an account. We use no website analytics, advertising, tracking pixels or third-party font services. We do not sell personal information or share it for targeted or cross-context behavioral advertising.
Controller and contact
Sabiedrība ar ierobežotu atbildību Grigerlab (SIA Grigerlab), established in Latvia, is the controller for information handled by us. Contact [email protected] for privacy questions or requests.
Reading information on your device
When you choose to save a place, this browser stores the selected text, its edition, reading block and time saved. Reading mode, visible layers and text size are also stored when you change those settings. These records stay in this browser’s local storage; the library does not upload them or maintain a server backup. They are not synchronized between devices. Using a shared browser can allow another person using it to see them.
The catalogue search and category filter work within the loaded page. Search words are not stored by the library or submitted to a search server or analytics service. Scrolling and following a reading block do not upload a reading history. The part of an address after the # sign that identifies a reading block is normally not sent with the page request.
You can remove individual saved texts or clear current saved readings on the Saved reading page. This leaves display preferences intact. Your browser’s site-data controls remove this site’s stored data, including preferences and data left by an earlier version. Local records remain until removed or cleared by you or your browser. Storage restrictions can prevent saving while leaving ordinary reading available. The site sets no cookies; these local reading features use browser storage for the functions you choose.
Website requests and religious information
Loading a page, font, image or PDF requires a request to the service delivering it. That service receives your IP address, requested address, request time, browser or device information and relevant request headers. Operational records may contain such information for delivery, security and diagnosing errors.
Reader and PDF addresses name devotional texts. Preparing a reading sheet sends the chosen text identifiers in its address to generate the sheet. These request addresses can reveal religious interests. Browser history can retain visited addresses. This is separate from the saved-place record that stays locally. We do not send prayer history, titles, reading positions, search words or religious interests to analytics, and do not build religious or health profiles.
Source and other external links take you to another operator. That operator receives your request and handles information under its own policy. When you follow an external link, the other site normally receives this site’s domain rather than the full devotional page address, depending on your browser and settings. External pages are not embedded into the reader. Fonts and downloadable PDFs are served from our CDN at cdn.prayers.page, delivered by Cloudflare. Requests include the technical connection information described above.
Correspondence and purposes
If you email us, we receive your email address, message, attachments and related delivery information. We use these to answer questions, correct content, investigate rights notices, handle privacy requests and document their resolution. Sending an email is voluntary; ordinary reading does not require it. Necessary information may be needed to resolve a specific request, and we explain a need for additional information.
Please send only information needed for the issue. Do not send prayer intentions, medical details, identity documents or information about another person unless necessary and requested. Religious belief and health information require additional protection. We do not seek it for ordinary support. Where handling such information is necessary, an applicable legal condition, such as explicit consent or legal-claims necessity where available, is required; unnecessary sensitive details are removed or minimized. Sending a message alone is not blanket consent to unrelated use or publication.
We process necessary operational and correspondence information on the basis of legitimate interests in delivering and securing the library and resolving requests, subject to your rights. Legal obligations and necessary legal claims can provide other bases. If we rely on consent for a specific purpose, it is explained separately and can be withdrawn without affecting earlier lawful processing. GDPR applies to processing in the context of our Latvian establishment, including relevant processing of people outside the EU.
Recipients, transfers and retention
Authorized personnel and providers for hosting, technical maintenance and email can handle information needed for their roles. Advisers, courts or authorities may receive limited information where needed for a legal duty or claim. We do not disclose local reading records that we do not receive.
Where processing involves transfers outside the European Economic Area, applicable safeguards are required, such as an adequacy decision or approved contractual clauses with additional measures where needed. Contact us for information about the recipients, relevant countries and safeguards for your information, and how to obtain a copy of applicable safeguards.
Operational records are kept only while necessary for delivery, diagnostics and security. Information needed for a particular incident, legal obligation or claim may be held for that matter. Correspondence is kept while needed to answer and resolve the request and subsequently only as necessary to document handling, meet a legal duty or address a specific claim. Unnecessary sensitive details are removed when no longer needed. Local reading data follows the browser-removal rules above.
Your rights and complaints
Subject to the applicable conditions, you may request access, correction, deletion, restriction or portability and withdraw consent. You may object to legitimate-interest processing on grounds relating to your situation. We stop unless law permits continuation, for example for overriding compelling grounds or legal claims.
Email [email protected] with enough information to locate relevant records. We may seek proportionate identity or authority verification. Do not send identity documents unless we explain why they are needed. For data held only on your device, use the local controls above.
For GDPR requests, we respond without undue delay and within one month of receipt. If a permitted extension is needed, we explain the reasons within that first month. Other applicable deadlines and routes to challenge a refusal remain. You may complain to Latvia’s Data State Inspectorate or another competent supervisory authority, including where you live, work or believe an infringement occurred. You need not contact us first.
India and other regions
India’s Digital Personal Data Protection Act, 2023 and Rules, 2025 have staged commencement. As of this policy’s effective date, the main processing obligations and individual-rights provisions have not yet commenced under the official commencement notification. We do not present future statutory procedures as currently available under those provisions. Applicable existing Indian rights remain, and you can contact us now using the route above. As the remaining provisions commence, their protections apply where their statutory conditions are met. Hindi or English language choice does not establish that you are in India.
United States privacy rights depend on your state and the law’s applicability. Where applicable, you may have rights to know, obtain a copy, correct, delete, opt out of sale, sharing or targeted advertising, limit certain uses of sensitive information or appeal a denied request. We do not engage in those sale or advertising activities. Contact us with a request or appeal; an authorized agent can act where permitted, with appropriate authority verification. We do not discriminate for exercising applicable rights.
Other applicable local protections remain. These statements do not claim that every national or state privacy statute applies to the library.
Children, security and changes
The library is for a general audience and does not offer child accounts or collect children’s information for analytics. Children should read with appropriate adult guidance and avoid sending personal information to support. If a child’s information has been handled improperly, contact us so it can be investigated and applicable safeguards or parental-consent requirements addressed. Age thresholds differ between laws; this is not a worldwide under-13 rule.
We use appropriate technical and organizational measures, including limiting access to information, but no system guarantees absolute security. We address personal-data breaches and notify authorities or affected people when law requires. The current policy and effective date appear here. Material changes receive appropriate notice, and new consent is obtained where required before a new consent-based use begins.