Blessen

Privacy Policy for Blessen

Effective date: 14 August 2026
Last updated: 17 August 2026

1. Introduction

This Privacy Policy explains how LUMENGATE LTD (“Lumengate,” “we,” “us,” or “our”) collects, uses, stores, shares, and protects personal data when you use the Blessen mobile application (the “App”) and related services (together, the “Services”).

LUMENGATE LTD is the data controller responsible for the personal data described in this Privacy Policy.

Company: LUMENGATE LTD
Company number: 17053891
Registered office: 61 Bridge Street, Kington, United Kingdom, HR5 3DJ
Privacy contact email: help@lumengate.io
Website: https://lumengate.io

By using Blessen, you acknowledge that your personal data will be handled as described in this Privacy Policy. Where applicable law or platform rules require consent, we will request it separately.

2. Personal Data We Collect

2.1 Guest profiles

You may begin using Blessen without creating a registered account. When you first use the App, we create a guest profile associated with a device identifier and an internal user identifier. This allows us to provide the Services and retain your preferences, progress, and other App data without requiring registration.

A guest profile may include:

2.2 Registered accounts

If you create or connect an account using Sign in with Apple or Google Sign-In, we may receive and store:

We do not receive your Apple ID or Google Account password.

2.3 App activity and personalisation data

We collect information needed to provide and personalise Blessen, including:

2.4 Blessing and group data

Blessen allows users to share a Bible verse or prayer selected from the App’s catalogue with another user or a group. In connection with this feature, we may store:

Users cannot write or send their own personal messages or personal notes through Blessing. The content sent through Blessing is selected from content provided in the App.

2.5 Subscription and purchase information

Purchases and subscriptions are processed by Apple through the App Store or by Google through Google Play. We and our subscription management providers may receive:

We do not receive or store your full payment card or bank account details. Apple and Google process payment information under their own terms and privacy policies.

2.6 Photos and images

With your permission, Blessen may access selected photos for the following purposes:

An image selected as an avatar is uploaded to our storage. Images saved to your device are not uploaded to us solely because you save them. You can manage photo permissions through your device settings.

2.7 Device, session, and log data

We may automatically collect:

Our application logs may contain request type, request path, response code, error text, and an internal user identifier. They are not designed to contain request bodies, authentication tokens, or email addresses. Technical web-server logs may contain an IP address and user-agent.

2.8 Analytics, attribution, and notification data

We use analytics, attribution, subscription management, remote configuration, notification, and error-monitoring technologies. Depending on the platform, App version, permissions, and services enabled, these technologies may process:

We do not use this information to display third-party advertising inside Blessen.

2.9 Communications with us

If you contact us, we may collect your name, email address, the content of your message, attachments you choose to provide, and information required to respond to or resolve your request.

3. Religious and Sensitive Information

Blessen is a Bible application. Your use of Bible passages, prayers, favourites, search, and Blessing features may relate to or suggest religious interests or beliefs.

We do not ask you to state your religion or denomination, and we do not use App activity to classify you by religion, make decisions producing legal or similarly significant effects, or serve third-party targeted advertisements. We use this information to provide the features you request, retain your preferences and progress, personalise your experience, and operate the Services.

Where applicable law treats such information as sensitive or special-category data, we handle it in accordance with the additional requirements of that law and obtain consent where legally required.

4. How We Use Personal Data

We use personal data to:

Where UK or European data protection law applies, we rely on one or more of the following legal bases:

If we rely on consent, you may withdraw it through the relevant App or device settings or by contacting us. Withdrawal does not affect processing that occurred before consent was withdrawn.

6. How We Share Personal Data

We do not sell your personal data. We may disclose personal data to the following categories of recipients when necessary for the purposes described in this Privacy Policy.

6.1 Service providers

Our service providers may include:

Provider Purpose
Amazon Web Services (AWS) Hosting, server infrastructure, database, file storage, logs, and backups. Our primary production infrastructure is hosted in the us-east-1 region in the United States.
Apple App distribution, Sign in with Apple, subscriptions, purchases, purchase restoration, device permissions, and push-notification infrastructure.
Google Google Play distribution, Google Sign-In, subscriptions, purchases, purchase restoration, and related platform services.
API.Bible / American Bible Society Bible text licensing and delivery for supported Bible translations. We do not intentionally provide API.Bible with your account profile or Blessing history.
AppsFlyer Mobile attribution, campaign measurement, analytics, and fraud prevention.
Mixpanel Product and usage analytics. Blessen’s Mixpanel project uses EU data residency.
Adapty Subscription entitlement management, paywalls, subscription analytics, and related testing.
OneSignal Push-notification delivery, notification subscription management, and engagement messaging.
Firebase (Google) Firebase Remote Config, used to manage App configuration and feature settings.
Sentry Crash reporting, error monitoring, diagnostics, and application performance.
Branch, where enabled Deep links, invitation links, and related attribution or routing.

The exact providers and features used may differ by platform and App version. We require service providers processing personal data on our behalf to protect it in accordance with applicable law and their contractual obligations and to use it only for the relevant services.

6.2 Professional advisers and contractors

We may share information with authorised developers, hosting and operations contractors, legal advisers, auditors, or other professional advisers where they need it to provide services to us and are subject to appropriate confidentiality and data-protection obligations.

We may disclose information where reasonably necessary to comply with law, regulation, legal process, or a valid governmental request; protect the rights, safety, and property of users, Lumengate, or others; investigate fraud, abuse, or security incidents; or enforce our agreements.

6.4 Business transfers

If Lumengate is involved in a merger, acquisition, financing, reorganisation, sale of assets, or similar transaction, personal data may be disclosed or transferred as part of that transaction, subject to applicable law.

7. International Data Transfers

Lumengate is established in the United Kingdom, and Blessen is available internationally. Your personal data may be processed in countries other than the country where you live.

Our primary AWS infrastructure, including production server resources, is hosted in the us-east-1 region in the United States. Our Mixpanel project uses Mixpanel’s European data-residency environment. Other providers may process data in the United States, the United Kingdom, the European Economic Area, or other countries where they or their subprocessors operate.

Where required, we use recognised safeguards for international transfers, such as adequacy regulations or decisions, the UK International Data Transfer Agreement or UK Addendum, European Commission Standard Contractual Clauses, and participation by eligible recipients in recognised data-privacy frameworks.

8. Data Retention

We retain personal data as described below and for as long as reasonably necessary for the purposes described in this Privacy Policy, subject to applicable legal obligations.

Data Retention
Registered account data Retained without a fixed expiry until you delete your account.
Guest profile Retained without a fixed expiry until you delete the guest profile. Guest profiles are not automatically removed for inactivity, including after the App is uninstalled.
Favourites, reading progress, daily assignments, onboarding responses, preferences, and subscription level Retained without a fixed expiry while the relevant guest profile or registered account exists.
Search history Limited to the 50 most recent searches. Older searches are automatically replaced. The retained searches have no separate time-based expiry and are deleted with the relevant profile or account.
Groups and membership Retained while the group and relevant membership records exist. A group is deleted when its last member leaves.
Group invitations An invitation link expires after 24 hours. The related invitation record may remain as part of the group records without a separate automatic expiry.
Blessing and sharing history Retained without a fixed automatic expiry while the relevant group, recipient history, or account records exist. Copies previously delivered to recipients may remain after the sender deletes an account, but the sender’s account reference is removed.
Session IP address and user-agent Retained with the relevant session. A session becomes expired after 14 days of inactivity and is removed when the user next signs in or when the account or guest profile is deleted. If the user does not return, an expired session record may remain until profile or account deletion.
Central application and security logs Up to 60 days.
Local web-server access logs Up to 14 days for App traffic. Administrative-panel access logs may be retained for up to 60 days.
Avatar Retained until replaced, removed, or the account or guest profile is deleted.
Incomplete uploads Generally removed after they are more than 24 hours old; storage-level cleanup may take up to two days.
Database backups Daily database backups are retained for 30 days. Daily server-disk snapshots are retained for seven days. Data deleted from the live database may therefore remain in protected backups for up to 30 days.
Third-party service data Retained according to the applicable service configuration, our business needs, and the provider’s contractual retention rules. Aggregated or de-identified information may be retained where it no longer identifies an individual.

9. Account and Data Deletion

Registered users and guest users can request deletion through the deletion option made available in the App. You may also contact us at help@lumengate.io to request deletion or assistance.

When a profile or account is deleted:

Deletion from the live database occurs when the deletion request is processed. Residual copies may remain in protected backups for up to 30 days and will disappear through the normal backup-rotation process. Backups are used for disaster recovery and are not used to restore a deleted profile during normal operations.

Deleting a Blessen account does not automatically cancel an App Store or Google Play subscription. Subscriptions must be managed through the relevant store. Apple, Google, and other third parties may retain records that they control under their own legal obligations and privacy policies.

After a guest profile is deleted, opening Blessen again on the same device may create a new, empty guest profile. Previously deleted data will not be restored to that new profile.

10. Your Choices and Permissions

You can control certain processing through Blessen and your device settings:

Disabling a device permission may limit the feature that requires that permission but will not prevent use of unrelated App features.

11. Your Privacy Rights

Depending on where you live and subject to applicable exceptions, you may have the right to:

To exercise a right, contact help@lumengate.io. We may need to verify your identity before completing a request. We will respond within the period required by applicable law.

If you are in the United Kingdom, you may complain to the Information Commissioner’s Office at https://ico.org.uk/make-a-complaint/. If you are in the European Economic Area, you may contact the supervisory authority in the country where you live or work.

United States state privacy disclosures

Where applicable US state privacy laws apply, you may have rights to know, access, correct, delete, or obtain a copy of personal information and to opt out of certain sale, sharing, targeted advertising, or profiling activities. We will not discriminate against you for exercising an applicable privacy right.

We do not sell personal information for money. We do not use personal information to display third-party targeted advertisements inside Blessen, and we do not engage in automated decision-making that produces legal or similarly significant effects concerning users.

12. Children’s Privacy

Blessen’s content may be suitable for a broad audience, but the Services are not intended for children under 13 to use independently. If you are under 13, or below the minimum age required to consent to data processing in your country, you may use Blessen only with the involvement and permission of a parent or legal guardian.

We do not knowingly request that children provide personal data independently. If you believe that a child has provided personal data contrary to this section, contact us at help@lumengate.io, and we will review and handle the information as required by applicable law.

13. Security

We use reasonable administrative, technical, and organisational safeguards designed to protect personal data. These include encrypted network communications, access controls, role-based permissions, protected authentication tokens, logging and monitoring, backups, and security measures provided by our infrastructure and service providers.

No system is completely secure, and we cannot guarantee absolute security. If you believe your account or personal data may have been compromised, contact us at help@lumengate.io.

Blessen may contain links to or integrations with third-party services. Those third parties may process information under their own terms and privacy policies. This Privacy Policy does not control processing performed by third parties acting independently from Lumengate, including Apple and Google in connection with their stores, accounts, and payment services.

15. Changes to This Privacy Policy

We may update this Privacy Policy to reflect changes to Blessen, our providers, legal requirements, or data practices. We will publish the updated version and revise the “Last updated” date above. Where required, we will provide additional notice or request consent before a material change takes effect.

16. Contact Us

For privacy questions, requests, or complaints, contact:

LUMENGATE LTD
61 Bridge Street
Kington, United Kingdom
HR5 3DJ
Company number: 17053891
Privacy contact email: help@lumengate.io
Website: https://lumengate.io