BuddhaSide Privacy Policy

Version 1.5 · Effective and last updated August 31, 2026

The current version offers optional email accounts, auto-renewing subscriptions through the Apple App Store or Google Play, and cloud-linked light offerings. Practice records, ordinary prayers, assisted-practice requests, and personal Bodhisattva or temple photos remain on the device by default. The app does not provide advertising, behavioral analytics or tracking, or real-world temple-service fulfillment.

1. Scope and Product Boundaries

This policy applies to the BuddhaSide iOS, Android, and corresponding Web apps. The current app supports personal practice records, offline scripture reading, meditation, prayers, and the storage of temple-service requests. It does not represent any temple's official services and does not promise real-world outcomes.

Account and subscription services do not change the on-device boundary for ordinary practice records. A cloud-based Ask Dharma service retained in the source repository for future evaluation is not included in the current release. If cloud-based Ask Dharma, broader synchronization, analytics, or real-world services are enabled in the future, we will update this policy, the relevant store privacy labels, and any required user notices before enabling them.

2. Data Processed on Your Device

When you choose to use the relevant features, the app may store the following data in its local application container:

Except for the Dharma name or display name and region synchronized when you choose to create an account, the ordinary practice content listed above is not synchronized through the publisher's account service. Depending on your system settings, Apple or your device operating system may include the app container in a full-device backup or migration. Those system services are controlled by the relevant platform provider.

3. Account and Cloud Processing

When you choose to register or sign in, the account server processes your email address, Dharma name or display name, region, email-verification status, account status, registration time, and most recent sign-in time. Your password is used only to create an irreversible salted hash; the server does not store plaintext passwords. The app stores only a revocable, time-limited session token on your device.

Email verification and password recovery use random, single-use secure links. The server stores only a SHA-256 digest of each link token. Email-verification links are retained for no more than 24 hours, and password-recovery links for no more than 30 minutes. A link becomes invalid after it is used, expires, or is reissued. Resetting a password revokes the account's previous sign-in sessions.

When the Core API is enabled, membership entitlements and light-offering records that you submit are linked to your account. The display name and prayer text you enter are returned only to the owner of that record. Other users see only the fixed anonymous label “A fellow practitioner” and do not receive another user's entered name or prayer text. The operations console reads only necessary account information, aggregate statistics, and account status; it does not read passwords, session tokens, or prayer text.

When you choose to purchase a subscription, the iOS app initiates the transaction with Apple StoreKit 2 and the Android app with Google Play Billing. The app submits either a random UUID associated with the app account or an irreversible SHA-256 digest to the applicable store to reduce duplicate entitlements and account confusion. The Android app sends the purchase token returned by Google Play to the Core API for verification. The server stores the token encrypted with AES-256-GCM, together with an irreversible token hash, product and plan, order, subscription and acknowledgement state, start and expiry times, auto-renewal, trial or test markers, and verification time. Google Play real-time developer notifications (RTDN) cause the server to query Google again and update entitlements after renewals, cancellations, refunds, or other state changes. Apple or Google processes your store account, payment method, billing, refunds, and subscription transactions. This app does not read or store your card number, store-account password, or full payment details.

4. System Permissions

You may revoke camera or photo-library access at any time in system settings. If you revoke access, the corresponding photo-capture or library-selection feature may become unavailable.

5. Network Access and Third-Party Services

Core content is included in the installation package. The app does not integrate advertising or third-party behavioral analytics SDKs. Registration, sign-in, membership entitlements, and cloud-linked light offerings access the publisher-configured Core API. Cloudflare Email Service sends email-verification and password-recovery messages on our behalf and may process the recipient address, sending domain, message content, sending time, and delivery or bounce status. Email-service credentials remain on the server and are not included in the app.

The current version does not provide SMS sign-in or SMS verification codes. Your device accesses an external website or system service only when you choose to open an external temple source, map, search, or similar link. The external provider may process your IP address, device information, or submitted search terms under its own policy.

Apple App Store, Google Play, StoreKit, Play Billing, operating-system services, full-device backups, and crash diagnostics are independently provided by the applicable platform and are not controlled by this app. You can view, change, or cancel a subscription through “Manage Subscription” in the app or through your system or store-account settings.

6. Retention, Deletion, and Your Controls

Deleting your account does not automatically clear on-device practice records. To remove both, also use “Clear Local Records.”

7. Security and Children's Privacy

The app applies length, type, and capacity limits to local input. The account service uses salted password hashes, rate limiting, email verification, single-use tokens, revocable sessions, and HTTPS transport. No storage or transmission method can guarantee absolute security. Please protect your device passcode, email account, and app-account password.

The app is not directed specifically to children and does not knowingly collect children's personal data. If a guardian permits a minor to use the app, the guardian should review the content and system permissions together with the minor.

8. Changes and Contact

The operator and publisher of this app is NOVASHOT SPORTS TECHNOLOGY LIMITED. If a feature or data-processing practice changes materially, the publisher will update the policy version and effective date and, when appropriate, provide an in-app notice.

For questions about privacy or data controls, email mukelun@icloud.com. The publisher will continue to provide a public HTTPS version of this policy and a valid support channel on the Apple App Store and Google Play product pages.