Privacy Policy

Last updated: September 5, 2026

Overview

Lotus Chant is designed with your privacy in mind. We believe your spiritual practice is personal, and your data should be treated with care. This policy covers the Lotus Chant iOS and Android apps and the website at lotuschant.app. Lotus Chant requires no account, does not sell your information, and does not use advertising networks or data brokers. Optional online, purchase, analytics, and support features use limited data as described below.

Data we collect

We collect or process only limited data needed to run, protect, support, and improve Lotus Chant. The app does not require an account. The data we process may include local app settings and practice history, optional website contact form messages, limited product analytics and diagnostics, subscription and entitlement information for Lotus+, and data needed to deliver premium audio downloads. We do not intentionally collect the content of your prayers, audio, or private spiritual reflections.

Data stored on your device

The app stores the following data locally on your device. Some limited usage events, such as completed sessions or settings changes, may also be reflected in analytics as described below, but the app does not upload your full practice history or private spiritual reflections:

  • Your preferences, such as theme, language, keep-awake, haptics, bell sound, gong sound, chant mode, playback speed, and related app settings
  • Notification settings (whether reminders are enabled and at what time)
  • Practice history, including session dates, durations, mode, and optional Daimoku count
  • First-practice state, Android install-attribution processing state, and store-review prompt counters
  • Onboarding, welcome, tour, and hint status
  • Cached premium audio files, generated share images, and temporary files used for downloads or sharing
  • Temporary screenshots used only for in-app visual transitions

Most of this data stays on your device unless a feature described below sends related information to our servers or a third-party service. Your operating system or device backup service may also back up local app data depending on your device settings.

Website storage

The website stores your selected theme and language in browser local storage. It also stores a locale cookie for up to one year so the server can show the right language on future visits. These preferences are unaffected by your analytics choice. An essential lotus_consent cookie remembers your acceptance or rejection of optional website analytics for 180 days. It is available across the website, uses SameSite=Lax, and is marked Secure on HTTPS. A local storage entry with the same name only notifies other open tabs of a change; it does not grant consent.

Only after you accept, configured website analytics can store Google Analytics cookies and website-managed PostHog identifiers and attribution in local storage. The PostHog SDK itself uses memory only and creates no new PostHog cookies; accessible legacy analytics cookies are removed when analytics storage is cleared. Attribution can include the initial or attributed path, referrer, UTM parameters, and advertising click identifiers such as fbclid and gclid. Google Analytics cookies are configured to expire after 180 days, without refreshing their expiry on each visit. Browser storage lifetimes do not determine how long providers retain received data.

With consent, the website stores an anonymous visitor identifier, session identifier, and last-activity time in a local storage record named ph_<key>_identity, where the key identifies our PostHog project. This keeps the visitor identity stable across pages and preserves an active session for up to 30 minutes of inactivity, with a 24-hour maximum session length. An existing valid anonymous PostHog record can be migrated with consent. Withdrawal clears this identity and website attribution.

Network requests

Lotus Chant makes the following types of network requests:

  • Daily phrase content — The app and website fetch the "Thought for the Moment" quote fromlotuschant.app/api/tmf, our own server. The request includes your selected language. Our server fetches the public source content from SGI-USA and, for non-English languages, sends the public quote and attribution text to MyMemory for translation. Hosting providers may process standard technical request data needed to deliver the response.
  • Daily phrase images — When you view or share a daily phrase image, the app or website requestslotuschant.app/api/tmf-image with language and view parameters. Shared images may be cached locally before being passed to your operating system share sheet.
  • Subscriptions and purchases — If you use Lotus+ or restore purchases, the app communicates with Apple App Store, Google Play, and RevenueCat to process purchases and validate subscription or lifetime access. We do not receive your full payment card details.
  • Premium audio packs — If you download a premium gong sound, the app sends your RevenueCat app user ID and the selected sound ID to lotuschant.app/api/audio-packs/gongs.json. Our server checks your Lotus+ entitlement with RevenueCat and returns a short-lived Cloudflare R2 download URL when access is valid.
  • App updates — The app checks for and downloads over-the-air updates through Expo/EAS Updates.
  • Analytics — The native app may send limited usage and technical information to PostHog. The website uses PostHog and Google Analytics only after you accept optional website analytics, as described below.
  • Contact form — If you choose to contact us through the website, your name, email address, message, and the page URL are sent to our server so we can deliver the message by email using Resend.
  • External links and store redirects — The website may use your user agent to redirect you to the App Store, Google Play, or the homepage. The app may open external study resources, store review prompts, or website pages in your browser.

All network communication is encrypted via HTTPS. The app functions offline for core chanting; an internet connection is only needed for features such as loading the daily phrase, purchase validation, premium audio downloads, checking for updates, sharing generated images, opening external links, contacting support, and sending analytics when analytics is configured for the app or configured and accepted for the website. Rejecting website analytics does not stop necessary requests for hosting, content delivery, contact submissions, or other features you use. Hosting providers and third-party services may process standard technical data such as IP address, user agent, timestamps, and request metadata to operate and protect these services.

Subscriptions and premium audio

Lotus+ subscriptions and purchases are handled by RevenueCat together with Apple App Store or Google Play. RevenueCat may process an anonymous app user ID, product identifiers, entitlement status, subscription state, renewal or expiration dates, purchase and restore results, and related device or store metadata. Payment card details are handled by Apple or Google and are not provided to us.

If you download a premium gong sound, the app sends your RevenueCat app user ID and the selected sound ID to our audio-packs endpoint. Our server rate-limits the request by app user ID, checks your Lotus+ entitlement with RevenueCat, and returns a short-lived Cloudflare R2 signed download URL. These signed URLs expire quickly, and downloaded audio may be cached locally on your device. Our server may keep operational logs related to entitlement checks, app user IDs, sound IDs, and request outcomes to diagnose issues and protect premium content.

Analytics and tracking

We use PostHog for product analytics and Google Analytics 4 (GA4) for website traffic measurement to understand usage and improve reliability, usability, and features. Both website providers are optional and load only after you accept analytics. Website PostHog events include explicitly recorded page views, download redirects, link clicks, blog and section views, scroll depth, and theme changes. Automatic PostHog page-leave and web-vitals collection are disabled. GA4 measures website visits and interactions under its configuration; we do not send copies of our custom PostHog events to GA4 or run GA4 on the download redirect page.

App analytics may include events such as app opened, onboarding activity, practice started, completed, or cancelled, practice durations, selected timer duration, bell enabled state, reminder creation and reminder times, notification opens, paywall views, purchase outcomes, premium feature usage, settings changes, app errors, and Android install attribution. Website consent controls do not change native app analytics. For campaign download links, attribution can include allowlisted UTM parameters, advertising click identifiers, and a random download click identifier. The website attaches this attribution and generates a download click identifier only when the server receives a valid accepted consent cookie. Without that consent, downloads go directly to plain store links without added attribution or waiting for analytics. On Android, Google Play may provide these values to the app through its Install Referrer API so an attributed download redirect can be associated with an app installation. Common properties can include product surface, platform, app version, selected language, theme, and effective theme. We do not use a Lotus Chant account identifier, and mobile session replay is disabled.

PostHog may process limited technical identifiers, such as anonymous user or session identifiers, IP address, and device or browser information, as part of providing analytics. On the website, after acceptance, these identifiers and attribution data persist in website-managed local storage so page and download events can be associated across navigation. PostHog automatic autocapture is disabled, and no account or identify call is required. Google Analytics may process cookie-based identifiers, page URLs, referrers, interactions, and browser, device, and technical request information. Google Signals and advertising personalization are disabled in our website integration, and all Google advertising consent permissions remain denied even if you accept analytics.

Each website PostHog event is sent as a single best-effort request to its public ingestion API through our configured host. The request may finish after navigation, but the website does not retry failed events or buffer them for later delivery.

We use analytics to improve Lotus Chant, fix issues, and make product decisions. We do not use PostHog to sell personal information, serve ads, or intentionally collect the content of your chanting practice, prayers, audio, or private spiritual reflections.

Website analytics consent and withdrawal

We rely on your consent as the legal basis for optional website analytics. The website-wide banner offers equally prominent accept and reject choices in English, Spanish, Portuguese, and Dutch. One choice applies across website pages and languages to both configured analytics providers. These controls apply only to this website, not to the Lotus Chant iOS or Android apps.

We use Basic Consent Mode v2, not Advanced Consent Mode. Until you accept, neither Google Analytics nor PostHog loads or sends analytics requests, including cookieless analytics pings. Missing, expired, or invalid consent is treated as unknown and keeps analytics off; consent is rechecked on active pages. If your browser prevents us from saving your choice, analytics stays off on the current page and the banner shows an error. An older saved choice may remain on a later visit if the browser refuses to overwrite it. Necessary website requests continue regardless of this choice.

You can reopen analytics preferences using the footer or the button below and choose reject to withdraw consent. Withdrawal disables further collection and removes accessible analytics-owned first-party cookies and browser storage, while keeping your theme, language, and consent preferences. It cannot recall requests already in flight or delete data providers have already received. Provider-held data is subject to their retention practices and our account settings; you can contact us about deletion as described below.

Contact form

If you submit the website contact form, we collect the name, email address, message, and page URL you provide. The form includes a hidden honeypot field to reduce spam, and our server uses your IP address together with your email address for short-term rate limiting. We send contact messages through Resend so we can receive and reply to them by email.

Notifications

Lotus Chant offers optional practice reminders and daily phrase notifications. These are scheduled locally on your device using the native operating system scheduler. The daily phrase notification may fetch the latest daily phrase before scheduling. No push notification backend is used, and no notification tokens are collected or sent to our server. If analytics is enabled, opening a reminder notification may be tracked as a product analytics event. You can enable, disable, or change reminder times from app settings.

Permissions

The app may request the following device permissions:

  • Notifications — Required only if you enable daily reminders. No notification token is sent to our server.
  • Internet — Used to fetch daily phrase content, validate purchases, download premium audio, check for app updates, open external resources, and send analytics when analytics is configured for the app.
  • Audio settings — Used to play and manage gong, Gongyo, and Daimoku sounds. No audio is recorded.
  • Vibration — Used for haptic feedback, which you can disable in settings.
  • Storage on older Android versions — May be used by the operating system for cached files, downloads, or sharing workflows.

The app does not access your microphone, camera, contacts, precise location, health data, or calendar, and it does not record audio.

Widgets and Live Activities

Lotus Chant provides optional home-screen widgets, quick actions, and iOS Live Activities. A Live Activity may display chanting status, duration, remaining time, formatted time, and progress on the lock screen or Dynamic Island. These features run on your device and do not communicate with an external server, but their content may be visible to anyone who can see your screen or lock screen.

Sharing

If you choose to share a daily phrase image, the app downloads the generated image to a temporary local cache and passes it to your operating system share sheet. What happens after you choose a destination is controlled by the app or service you share with.

Third-party services

Lotus Chant uses third-party services to operate the app and website: PostHog for analytics, Google Analytics for optional website analytics, Resend for contact email delivery, RevenueCat for subscription and entitlement management, Apple App Store and Google Play for purchases and reviews, Cloudflare R2 for premium audio file storage, Expo/EAS for app updates, Vercel and related hosting infrastructure for the website and API routes, SGI-USA as the public source for daily phrase content, MyMemory for server-side translation of public daily phrase text, and Google Fonts for server-side image generation. We do not use advertising networks, social media SDKs, or data brokers.

For more information, see the PostHog Privacy Policy, Google Privacy Policy, and how Google uses information from sites and apps that use its services.

Children's privacy

Lotus Chant is designed as a general-audience practice companion and does not require an account. If a child is not old enough to consent to app use, purchases, or data processing in their jurisdiction, they should use Lotus Chant only with permission from a parent or legal guardian. We do not knowingly collect personal information from children for advertising, and analytics is not used to build advertising profiles.

Data retention and deletion

Local app data remains on your device until you delete it, clear app data, or uninstall the app, subject to any operating system backups or restores you have enabled. Website theme and language local storage remain until cleared. The locale cookie expires after up to one year; the essential analytics consent cookie lasts 180 days. Google Analytics cookies have a configured 180-day expiry without rolling updates. Website-managed PostHog identity and attribution remain in local storage until cleared; the SDK uses memory only and creates no new PostHog cookies. Withdrawing website analytics consent removes accessible analytics-owned first-party cookies and storage, but does not delete information already received by providers. You can also clear website data using your browser controls. Contact form messages are retained only as long as needed to respond and maintain support records. Premium audio signed URLs expire quickly, while cached audio files remain on your device until cleared by the app or operating system. Analytics, purchase, email, hosting, and update providers retain data according to their own retention practices and our account settings. If you have questions or want to request deletion of data associated with you, contact us using the address below.

Changes to this policy

If we update this policy, we will post the changes on this page and update the date above. We recommend checking back periodically.

Contact

If you have questions about this privacy policy, reach out atme@reinierhernandez.com.