Carried

Privacy policy

How Carried handles your words, temporary local data and service providers.

Who is responsible

Carried is developed by Dominik Drąg. For privacy questions, contact [email protected].

Your reflection and prayer

Carried lets you speak or type a reflection, review it, and ask for a Christian prayer based on those words. A reflection may contain personal or sensitive information, including religious beliefs. Include only what you want processed for this purpose; you do not need to identify yourself or another person.

Speech transcription runs on your iPhone. Your recording is not uploaded. When you agree and ask Carried to write a prayer, the app sends the current reviewed reflection over an encrypted connection to Carried’s prayer service hosted on Cloudflare. The service sends the reflection with Carried’s fixed instructions through OpenRouter to OpenAI, which runs GPT-5.6 Luna.

Earlier reflections, earlier prayers, recordings, purchase identifiers and App Attest identifiers are not sent to OpenRouter or OpenAI. Carried does not offer a public feed or publish your prayer to other users.

Prayer service and providers

Cloudflare hosts Carried’s prayer service and receives ordinary connection information such as your IP address and request timing. OpenRouter routes the prayer-writing request to OpenAI. Carried restricts model routing to OpenAI and does not fall back to another model provider if that route is unavailable.

OpenAI retains prompts for a period it does not publish. Carried does not promise zero retention or a fixed provider deletion period. Removing something from your iPhone does not delete a copy already processed by a provider.

Read Cloudflare’s privacy policy, OpenRouter’s privacy policy, its data collection documentation, and OpenAI’s privacy policy. Provider policies describe their own practices and do not replace this app-specific explanation.

App authenticity and service records

Carried uses Apple’s App Attest service to check that requests come from a valid installation. The app sends an App Attest key identifier, attestation or assertion, request binding and one-use server challenge. Carried’s service retains the verified public key, receipt, replay counter, environment and a derived installation identifier while that installation remains authorized.

The service stores content-free attempt and operation records for idempotency, recovery, allowance, fraud prevention, concurrency and spend control. These can include random operation identifiers, client correlation identifiers, purpose, namespace, a keyed request fingerprint, outcome, timestamps, token and cost accounting, and allowance or spend reservations. They are linked to a pseudonymous installation or subscription principal; hashing or HMAC does not make them anonymous.

Challenges expire after two minutes. If an enrollment is rejected, the service retains a keyed value derived from its App Attest key identifier for 24 hours so the rejected enrollment cannot race or replay into acceptance; it does not retain the rejected attestation, public key or receipt in that record. Signed attempt or operation tickets have a fixed maximum 24-hour expiry. The Worker source deletes detailed attempt and operation rows, including provider token and cost fields, after 30 days. It deletes per-principal attempt timestamps and per-installation daily free-dispatch counts after 90 days. Day-only aggregate dispatch, successful-operation, enrollment, token and provider-cost totals also remain for 90 days; those aggregate rows contain no installation, subscription, attempt, operation, request or content identifier. The schema and disabled Worker are deployed, but scheduled cleanup has not yet been observed running against production data. Installation authentication, replay state and consumed allowance remain while the installation is authorized. Owner deletion removes the installation’s public key, receipt, attestation metadata, replay state, allowance and linked operation material, but retains a durable keyed value derived from its App Attest key identifier solely to deny reenrollment and another free allowance. The owner-only revocation and deletion tooling has not been exercised against deployed service data.

Carried’s service is designed not to store reflections, prayers, recordings, raw StoreKit transaction JWS values, authorization headers, provider responses or raw provider errors in its database or application logs. A lost successful prayer cannot be recovered from the service. Cloudflare, OpenRouter, OpenAI, Apple and RevenueCat also process infrastructure or service records under their own policies.

What stays on your iPhone

Current-attempt files and audio are protected with iOS file protection and excluded from device backup by the app. Carried does not synchronize reflections or prayers to an account or iCloud library.

Purchases and subscription data

Purchases use Apple’s in-app purchase system. Apple processes payment; Carried uses RevenueCat to manage subscription access. The app does not ask you to enter payment-card details.

RevenueCat receives purchase and subscription records and a randomly generated app user ID so it can validate purchases, restore access and provide subscription history and analytics. Carried does not create a sign-in account or supply a name or email address to RevenueCat. Automatic advertising and device-identifier collection is disabled in the app’s RevenueCat configuration. RevenueCat still stores subscription records off your device.

For paid prayer access, the app also sends a StoreKit 2 signed subscription transaction to Carried’s service. The service verifies the transaction and current subscription status with Apple. It does not store the raw signed transaction. It stores a keyed identifier derived from the Apple environment and original transaction ID so one subscription lineage can be recognized across renewals, restores, relaunches and devices.

Your reflection, recording, transcript and prayer are not sent to RevenueCat. App Attest and subscription identifiers are not forwarded to OpenRouter or OpenAI.

See Apple’s privacy information and RevenueCat’s privacy policy.

Support messages

If you email support, your email address and anything you include in the message will be received through the support mailbox and used to respond. Please describe technical problems without sending your reflection, recording or prayer. You can redact screenshots before attaching them.

Your choices and deletion

You can type instead of using the microphone, change the reviewed text, or decline the processing disclosure before sending a prayer request. You can manage microphone permission in iPhone Settings. Declining a new request does not retract a request already processed.

Use the app’s discard controls to clear a recoverable attempt or retained recording. Deleting the app removes local app data and resets that installation’s App Attest key. It does not cancel an Apple subscription, erase device backups, delete support emails, or immediately remove provider, purchase, security, allowance or content-free operation records.

For a privacy or deletion request, email the address above without including prayer content. Carried has no sign-in account or direct identity profile, so the developer may be unable to locate an anonymous provider record from a reflection alone. Provider-held data may require that provider’s process. The service-side owner tooling can revoke or delete a located installation, subject to the durable anti-reenrollment record described above; it has not been exercised against deployed service data.

Tracking, analytics and website information

Carried has no advertising SDK, IDFA use, data broker sharing, cross-app tracking or general-purpose app analytics SDK. RevenueCat provides purchase-history and subscription analytics. The Carried service keeps content-free security, operation, token and spend records for app functionality; it does not use them for advertising or product-behavior analytics. The OpenRouter workspace was observed with prompt storage, broadcast, paid-endpoint training and its data-sharing discount off. Cloudflare account-level exports and enabled runtime behavior still need final verification, so Carried does not claim that providers keep no logs.

The Carried website has no reflection submission form or product analytics. Its light/dark preference is stored in your browser for this domain. The website is hosted by Cloudflare, which receives connection information when serving it. Website hosting and support-email processing are separate from on-device app storage.

Changes to this policy

This page will be updated when Carried’s data handling changes. The date above identifies the latest revision. A changed in-app processing disclosure requires agreement before a new prayer-writing request.