NoonWell is a contemplation app built around stillness and Scripture. We believe a quiet practice deserves a quiet relationship with your data. This policy covers both the NoonWell website at noonwell.app and the NoonWell app, and explains what we collect, why, the lawful bases we rely on, and the choices you have. As NoonWell grows, this policy grows with it.
NoonWell is operated by Jędrzej Stefanowicz, a sole proprietorship (jednoosobowa działalność gospodarcza) registered in Poland — NIP 9512542039, REGON 522119984. We are the data controller for the information described here.
Questions about your privacy are welcome at email. You can also ask for our registered postal address in Otrębusy, Poland: . Because we are established in the European Union, no EU Article 27 representative is required.
Here is the whole of it at a glance, split between the website and the app. The sections that follow explain each in plain language.
| Where | What |
|---|---|
| Website | Waitlist sign-up: your email, where on the site you signed up, a short note of your browser, and the time. No cookies, no analytics, no third-party trackers. Our host keeps basic access logs, including IP address. |
| App | Your sessions — photos, audio, and transcripts — are stored on your device. A random Device Id is sent with requests; optionally a display name and a place (“where you pray from”). In Groups, a user token (only its hash is stored) and the text you post (the verse reference, the verse text, and your reflection transcript — photos and audio are not shareable). Fair-use counts, subscription status, and crash/error diagnostics. |
Your photos and audio are the heart of the practice, and they stay on your device — they leave it only briefly, over an encrypted connection, so the app can suggest a passage or write down what you said, and are then discarded by the services that process them. We explain exactly how below.
Our website exists to tell you about NoonWell and to let you join the waitlist. When you sign up, we store your email address, where on the site you signed up, a short note of your browser, and the time. That is all. If we ever turn on operator notifications, a signup may also trigger an internal email to us — this is currently off.
The site uses no cookies, no analytics, and no third-party trackers, and its fonts are served from our own servers — so there is no cookie banner, because there is nothing to consent to. As with any website, our host (Vercel) keeps basic access logs, including IP addresses, to run the service securely.
You can leave the waitlist at any time: email us at email to be removed, or use our deletion page at noonwell.app/delete. Once we begin sending launch email, each message will also carry an unsubscribe link.
The heart of NoonWell is photographing what is in front of you so the app can offer Scripture that meets the moment. When you ask for a suggestion, your photo is sent — over an encrypted connection, through our own backend — to Anthropic, which reads the image once to suggest a passage. The photo itself is held only in memory for that request and then discarded; we never write it to our servers, and it is never used to train any AI model.
We keep only a short, non-image note of the moment — a text description of the scene, a simple appropriateness flag, and quality and confidence signals — so the app can work well and so we can improve it. This note is not linked to your Device Id or to your identity; how long we keep it is set out in section 14. The photo you took stays in your own private session history on your device, and you can delete it, and the whole session, whenever you like. The camera is one of only two permissions NoonWell ever asks for, and this feature runs on your explicit consent (see section 9).
If you record a spoken reflection, the audio is sent — over an encrypted connection, through our backend — to Groq, which transcribes it into text. We do not store the audio; it is discarded as soon as the transcription is made. The transcript is kept in your session history on your device for your own review, and it stays private unless you choose to share it in a Group. We do not publish, sell, or otherwise use your reflections.
The microphone is the second and last permission NoonWell asks for — it is used only when you record a reflection, and, like the camera, this feature runs on your explicit consent (see section 9). NoonWell asks for no location, no access to your photo library, and no push notifications.
So you can begin without creating an account, NoonWell generates a random identifier that is stored on your device and sent with your requests. We use it to keep the practice fair — counting how many suggestions you make so we can offer a weekly allowance on our most capable model — and to prevent misuse of the free tier. These counts are kept only briefly (about two weeks) and, where you have no identifier, we may fall back to your IP address for the same short period.
Separately, we keep one small, non-identifying record tied to your device — simply the fact that your one free suggestion has been used — so the “one free suggestion, then Pro” allowance cannot be reset by reinstalling. This record is retained on a legitimate-interest basis. It is written once, when you spend your free suggestion, and is not refreshed by continued use of the app, so it ages out automatically about a year after that — roughly 365 days — whereupon the device simply regains its one free suggestion. This identifier is app-scoped: it is not the advertising identifier (IDFA on Apple devices, or the Advertising ID on Android), it does not tell us who you are, and it is never shared with advertisers. On Android, where there is no equivalent to Apple’s per-vendor identifier, this is a randomly generated app-scoped identifier kept in the app’s private storage.
NoonWell Groups is an optional, quiet space for shared reflection — you can use all of NoonWell without ever joining. If you choose to join, you provide a display name, an optional place (“where you pray from”), and a user token — of which we store only a one-way SHA-256 hash, never the token itself. What you post — your text reflections, comments, and reactions — is visible only to the members of the groups you choose. There is no public feed and no algorithmic recommendation.
Because taking part in a prayer community, and what you write there, may itself reveal your religious beliefs, Groups is treated as special-category data and runs on your explicit consent, given when you opt in (see section 9). Sharing today is text only — the verse reference, the verse text, and your reflection transcript. Photos and audio are not shareable. You can delete your own posts at any time, and you can report a post or block another member from within the app. We aim to review reports and, where needed, remove content or suspend a member within a reasonable time — generally within about 24 hours of acknowledging a report. You can also raise a concern with us at email, and the community rules that apply in Groups are set out in our Terms of Service. NoonWell is the data controller for the content held in Groups.
NoonWell Pro is an auto-renewable subscription, offered through Apple (and Google Play later) and managed on our behalf by RevenueCat, keyed to your Device Id. RevenueCat and the app store receive only your purchase, receipt, and entitlement status — never your photos, audio, reflections, or any religious content. Your subscription renews automatically at the end of each billing period unless you cancel at least 24 hours before it renews; you can cancel any time in your Apple ID settings (Settings > your name > Subscriptions) — or, on Android, in your Google Play account under Subscriptions — and cancellation takes effect at the end of the current period, with no charge for the unused remainder. Restore Purchases is available in the app. Billing is handled by the app store, not by us. This feature is currently pre-launch and inert until the purchase flow goes live. The full subscription terms live in our Terms of Service.
NoonWell is built around Scripture and prayer, so your use of it — the passages you receive, the reflections you record, the groups you join — may reveal your religious beliefs, which European law treats as a special category of personal data (GDPR Article 9). Your photographs may also incidentally include other people or hints about health.
We rely on your explicit consent (Article 9(2)(a)) to process this information for three activities: the photo suggestion feature, the voice reflection feature, and taking part in NoonWell Groups. Any health-related detail that a photo incidentally captures is covered by the same explicit consent, is used solely to generate the Scripture suggestion, and is held only in memory for that request and then discarded, exactly as the photo itself is. You give this consent in the app — before you first use the camera and voice features, and when you opt in to Groups — and you can withdraw it at any time in Settings (see sections 10 and 15). We never use this information to build advertising profiles.
For each purpose, here is the lawful basis under the GDPR that we rely on:
Groups therefore rests on two bases working together: your explicit consent to opt in and to any religious inference (Articles 6(1)(a) and 9(2)(a)), and, once you have joined, contract for actually running the sub-service (Article 6(1)(b)). You never have to join, and you can leave at any time.
NoonWell is a companion to prayer and reflection. Its Scripture suggestions are generated by AI from the photo you take and, like any such tool, may be imperfect or unexpected. NoonWell is not a substitute for pastoral, medical, mental-health, or other professional care, and nothing it offers should be taken as such advice.
These suggestions are not automated decisions that produce legal or similarly significant effects for you. You can disable automated AI suggestions at any time in Settings, and you may ask us to review a suggestion.
We do not sell your personal information, we do not build advertising profiles, and we do not track you across other apps. We share information only with the service providers (sub-processors) who help us run NoonWell — each only to the extent it needs to do its work — and, within Groups, with the members you choose.
| Provider | What it does & what it receives | Location |
|---|---|---|
| Anthropic | Reads the photo you choose to suggest Scripture for that moment; processed in memory for the request and discarded, never stored, never used to train models. | USA |
| Groq | Transcribes the voice reflections you record; audio is discarded after transcription and never stored. | USA |
| Turso | The database holding your waitlist signup and, in the app, your Groups content and the non-identifying operational notes described in sections 4 and 14. | USA |
| Sentry | Collects crash and error diagnostics (route, status, message, stack) so we can fix problems. | USA |
| RevenueCat | Manages your subscription status, keyed by Device Id; receives purchase/receipt/entitlement only — not your content or religious data. Pre-launch and inert until the purchase flow is live. | USA |
| Vercel | Hosts this website and the waitlist form; keeps basic access logs including IP address. | USA |
| Railway | Hosts the NoonWell backend that the app talks to; your photo and audio pass through it in memory during a request, and are not stored on Railway beyond that request. | USA |
| Resend | Would send an internal notification to us when someone joins the waitlist (receiving only that signup email address) if operator notifications are enabled; currently off. | USA |
| Universalis | Fetches public liturgy Scripture citations only; no personal data and no user data is sent to it. | UK/EU |
The fonts on our website are served from our own servers, not a third party — which is precisely why there is no third-party font request and no cookie banner.
Most of the providers who help us run NoonWell are based in the United States, which does not currently have an EU “adequacy” decision. Where your personal data is transferred there, we rely on the European Commission's Standard Contractual Clauses as our primary safeguard, and we have assessed each transfer. Alongside the Clauses we keep the data protected by minimising what is transferred, sending only what a provider needs, encrypting it in transit, and binding each provider by contract not to re-use it — and, for the sensitive features, by the fact that photos and audio are processed only in memory and then discarded. If you live in the EU or EEA, you may ask us for a copy of the safeguards we use.
We keep information only as long as we need it for the purposes described here. In practice:
| What | How long |
|---|---|
| Waitlist email | Until the launch announcement is sent, then up to 6 months afterwards to allow follow-up — or until you unsubscribe or ask to be removed, whichever comes first. If you convert to an account, we keep it as account data instead. |
| Sessions, photos, audio, transcripts | Held on your device until you delete them or uninstall the app. |
| Photos & audio sent for processing | Not retained — processed in memory and discarded. |
| Scene note & processing signals derived from a photo (not linked to you) | A non-identifying operational record (a short scene description plus appropriateness, quality, and confidence signals), not tied to your Device Id or identity. Kept to run and improve the service until it is no longer needed for that purpose, then deleted in our periodic clean-ups. |
| Fair-use counts (incl. IP fallback) | About two weeks, then automatically pruned. |
| Free-suggestion device record | Ages out automatically about a year (roughly 365 days) after the one free suggestion is used; not refreshed by continued use (abuse control). |
| Groups content | Until you delete it or delete your account. |
| Crash & error diagnostics | About 90 days, then automatically pruned. |
| Subscription status | Held by RevenueCat for as long as needed to manage and verify your entitlement, subject to RevenueCat's own retention policy and any tax or accounting obligations under Polish law; we do not separately store your receipts beyond your entitlement status. |
Under the GDPR you have the right to access the personal data we hold about you, to have it rectified if it is wrong, to have it erased, to restrict or object to our processing, to portability of the data you gave us, to withdraw consent at any time, and not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects.
Your right to object. Where we process your data on the basis of our legitimate interests — including the fair-use counts and the free-suggestion device record described in section 6, error monitoring, and our host's access logs — you have the right to object at any time. Tell us at email and we will stop that processing unless we can show compelling legitimate grounds that override your interests, or that we need it to establish, exercise, or defend legal claims.
You can exercise these rights in the app — Settings > Account > Delete My Account handles erasure directly — or by writing to us at email. We will respond within one month, as the law allows.
Withdrawing consent is as easy as giving it: you can disable AI photo suggestions and voice reflections, and leave Groups, at any time in Settings > Privacy, and you can leave the waitlist by emailing us or using our deletion page (or the unsubscribe link in any launch email, once those are sent). Withdrawal takes effect going forward and does not undo processing already carried out lawfully before you withdrew.
You can delete your NoonWell account at any time from Settings > Account > Delete My Account in the app. Doing so removes your Groups posts, comments, reactions, memberships, blocks, reports, your fair-use counts, and your account itself, and we complete deletion within 30 days. If you have led a group, we either hand it on or remove it. You can also read the steps and request assistance on our web deletion page at noonwell.app/delete.
Two small things intentionally survive account deletion, and neither is linked to your identity. First, the non-identifying device record described in section 6 — the fact that a free suggestion has been used — is kept on a legitimate-interest basis (abuse prevention and free-tier integrity) so the “one free suggestion, then Pro” allowance cannot simply be reset by deleting and reinstalling; it is never used for advertising and ages out on its own about a year (roughly 365 days) after it was written. Second, diagnostic error logs, which do not identify you, age out after about 90 days. Sessions, photos, and audio that live only on your device are removed when you delete them there or uninstall the app.
We protect your information with reasonable technical and organizational measures — encryption in transit, one-way hashing of Groups tokens, and keeping your sessions, photos, and audio on your own device rather than our servers. No method of storage or transmission is perfectly secure, but we treat your trust seriously.
NoonWell is intended for adults. It is not directed to children, and we do not knowingly collect personal information from anyone under 18 (or any higher minimum age that may apply where you live). If you believe a child has provided us information, please write to us at email and we will remove it.
If you have a concern we have not resolved, you have the right to lodge a complaint with a data-protection supervisory authority. Our lead authority is Poland's UODO (Urząd Ochrony Danych Osobowych, ul. Stawki 2, 00-193 Warsaw, uodo.gov.pl). If you live elsewhere in the EU or EEA, you may also complain to the authority in your own country of residence. We would, of course, be glad to try to put things right first — reach us at email.
As NoonWell grows, this policy will grow with it. When we make changes, we will update the date above. For material changes to processing that relies on your consent — photos, voice, and Groups — we will also give you notice in the app and, where appropriate, ask for your consent again.
This policy sits alongside our Terms of Service, which govern your use of NoonWell — including the community rules for Groups and the full subscription terms — and are read in the same unhurried spirit. Polish law applies, and if you are a consumer in the EU you keep all the mandatory protections of your country of residence.
Find God in what's in front of you.