Worship StudioYour account
CUTHBERT TECHNOLOGIES · NIGERIA

Privacy Policy

01

Who is responsible

Cuthbert Technologies, operating from Nigeria, is responsible for the account-service data described here. Contact cuthbertayo@gmail.com for privacy questions and requests. This policy covers our website account service and optional app reporting. Local app files and independently selected third-party providers have the distinctions described below.

02

Account and download information

We store your email address, a salted password hash, account creation date, accepted Terms version, and hashed session credentials. We record official installer download requests, version, time, and whether the server finished sending the response. A completed server response is not proof that the installer was saved, installed or used. Account processing supports the service you request; download and short-lived rate-limit records support operation, security and abuse prevention.

03

Essential cookies and connections

An essential, HttpOnly session cookie keeps you signed in to the website for up to seven days. App credentials are stored in the operating system credential store and server sessions expire after ninety days. Your IP address is necessarily visible to the service during a connection and is used in temporary in-memory rate limiting, normally for up to one hour. The application database does not retain an IP history. No advertising trackers or marketing cookies are added by this account system.

04

Optional usage statistics

Only if you opt in, the app sends a random installation identifier, app version and platform as a once-per-Sunday activity signal using the device�s local date. The server validates the reported Sunday date. Reports are linked to your account and are therefore pseudonymous, not anonymous. They help measure distinct active accounts with consenting installations over seven and thirty days, not every person or church. No song names, Bible usage history, sermon content or precise location is included. Usage reporting is off by default.

05

Optional diagnostics

Only if you opt in, the app sends structured technical reports containing its installation identifier, app version, platform and a fixed error category. Current categories cover frontend errors, unhandled promise rejections and startup failures. Raw log files, error messages, stack traces, file paths, audio, transcripts, lyrics, Bible search text, API keys and passwords are not uploaded by this reporting system. Existing local logs stay on your device unless you separately export and share them. Diagnostic reporting is off by default.

06

Consent and withdrawal

Usage and diagnostics have separate choices. Consent records include the choices, installation, policy version and timestamp. You can change them in the app, or withdraw both permissions from the website account page. Website withdrawal takes effect on the server immediately; the app may still attempt a previously enabled request until its local preferences are changed, but the server rejects and does not store that optional report. App withdrawal blocks new optional reports locally even when offline and syncs with the server when connected. If disconnected offline, reconnect the same account to complete the pending withdrawal, or withdraw sharing from the website. Withdrawal also deletes stored usage or diagnostic reports for the affected installations. Consent records remain while your account exists to demonstrate your choices.

07

Local content and cloud features

Your local libraries, sermon audio and transcripts are not sent to Cuthbert Technologies through this account or reporting system. If you choose cloud speech recognition or AI features, content required for those features goes to your selected provider. Review its privacy terms and ensure you have appropriate permission from anyone whose content you transmit. Declining diagnostic or usage sharing does not disable cloud features that you configure independently.

08

Retention and access

We retain account and consent records until you delete the account, and sessions until expiry or revocation. Usage reports expire after ninety days, structured diagnostics after thirty days, and download records after one year. Scheduled cleanup runs hourly while the service runs. Account deletion removes its related reporting data and unlinks retained download records. Authorised administrators can access account emails and installation sharing preferences, aggregate activity and error counts, and privacy requests. We do not sell account or reporting data. Access is restricted to people administering the service.

09

Hosting and international transfers

The local preview runs on the operator's machine. Supabase hosts the account database. Password recovery supports Resend for transactional emails when configured. The website hosting provider, production regions and email sender configuration still need to be finalised. Before public deployment, this policy must identify relevant providers, processing locations and applicable transfer safeguards. There is no automated welcome-email service; configured recovery emails contain a short-lived password-reset link. Infrastructure providers may necessarily process connection and security information; their actual retention must be disclosed before launch.

10

Your rights and requests

You can export or delete account records from the website account page and withdraw optional sharing in the app or website. You may also request access, correction, deletion, restriction or object to processing where applicable, and withdraw consent without affecting the lawfulness of earlier processing. Contact cuthbertayo@gmail.com or record a privacy request on the account page. We will assess and respond in accordance with applicable requirements under Nigeria's data protection law. You may complain to the Nigeria Data Protection Commission at ndpc.gov.ng.

11

Policy changes

We will publish the effective date and version when this policy changes, and seek new optional consent before introducing materially different reporting purposes or data fields. Current version: 2026-10-07. Effective date: 7 October 2026.