Skip to content

Privacy

There are two things to describe here: a waitlist form that asks for your email address, and a page-view counter run by Cloudflare. Nothing on this site follows you as a person, and the NaveLight application itself sends nothing anywhere at all.

Last updated 10 September 2026

What the waitlist stores

Everything below except your email address is optional, and the form submits happily without any of it.

Your email address
Required. It is the only way to tell you when NaveLight is ready.
Roughly how many people attend on a Sunday
Optional, and a range rather than a number. It tells us which church sizes to test against.
What you're running now
Optional. It tells us which imports matter most — EasyWorship, ProPresenter, or nothing yet.
Which page you signed up from
So we know which parts of the site are answering real questions.
The date you signed up, and the date you last updated it
Nothing more.

The page counter, in plain terms

We want to know whether anyone reads these pages and which country they read them from. We chose the counter that answers that and nothing more.

Cloudflare is the network that sits in front of this site's server, so every request you make here already passes through it. It also runs a page-view counter called Cloudflare Web Analytics, which adds one small script to each page. When a page loads, that script tells Cloudflare the address of the page, the address you arrived from, the kind of browser and device you are using, your operating system, the country you are in, and how long the page took to appear. That is the whole list, and it is what we see: a chart of page views by page, by country, by browser.

What it does not do is the part that matters. In Cloudflare's own words, it "does not use any client-side state, such as cookies or localStorage" and does not "fingerprint individuals via their IP address, User Agent string, or any other data". So it cannot recognise you on a second visit, it cannot follow you to another site, and it cannot tell us — or Cloudflare — who you are. It counts, it does not identify.

One number is ours rather than Cloudflare's. When you click a Download button, our release server adds one to a tally for that platform — Windows, macOS, Linux — before it sends you to the file. That tally is a count and nothing else: it has no row for you, no address, no browser, and no way to tell a second download from a second person. We keep it because whether anyone downloads the Linux build decides whether we keep making one.

Cloudflare adds one more script of its own, and we would rather you heard it from us: it hides our email address from bots that harvest addresses for spam, and reveals it to you when the page loads. It is served from this domain and it sends nothing anywhere.

How to stop it

Any content blocker stops the counter, and Firefox's and Safari's own protections often do. The site works identically without it. If you would rather we did not count you at all, email us and say so; we cannot exclude one person from a count that never knew who anyone was, but we will tell you exactly what is running on the day you ask.

What it doesn't

This is the part most privacy pages are vague about, so here it is as a list you can check for yourself with your browser's network inspector.

  • No cookies. This site sets none, of any kind, so there is no consent banner to dismiss.
  • Nothing is stored in your browser unless you ask for it. If you click the light/dark switch, that one choice is saved on your own device so the site remembers it next time. It is never sent to us and it is not linked to anything. Leave the switch alone and the site simply follows your operating system, storing nothing at all. Clearing your site data removes it.
  • No tracking pixels, and no analytics beyond the Cloudflare page counter described above. It tells us how many people opened a page and which country they were in; it cannot tell us who they were. We do keep one number of our own: each click of a Download button adds one to a running total for that platform, and that total is all there is — no address, no browser, nothing that says the click was yours.
  • No IP addresses or browser fingerprints are stored with your signup.
  • No other company. Cloudflare carries every request to this site — it is the network in front of our server — and it runs the counter. Nobody else is told you were here, and fonts are served from this domain.
  • No advertising, no data sharing, no selling, no profiling. There is no business here that involves your data.

Who else can see it

Three companies, each because it is doing a job for us and none for its own purposes:

  • Our database host. The signup is stored in a PostgreSQL database we run.
  • Our email provider. Delivers the one confirmation email, and needs your address to do it. Nothing else is sent to them.
  • Cloudflare. Carries every request to this site as the network in front of our server, and runs the page counter described above. It sees which page was opened, from where, on what kind of browser and device, and in which country. It sets no cookie and, by its own published terms, does not use your IP address or browser to recognise you. It never receives your signup — the form posts to our own server.

Nobody else. We don't share the list, we don't sell it, and there is no advertising business attached to it.

How long we keep it

The waitlist: until NaveLight is released and we've told you, or until you ask us to delete it — whichever comes first. If the product never ships, the list is deleted rather than kept.

How many emails

One when you join, confirming you're on the list. One when NaveLight is ready. There is no sequence in between, and no newsletter you have to opt out of.

Your rights, and how to use them

You joined the waitlist by choosing to, which is the lawful basis we rely on, and you can withdraw at any time. You can ask us to show you what we hold, correct it, or delete it.

Email [email protected] and say which. We'll do it and confirm, and we won't ask why or try to talk you out of it. Deletion means the row is removed, not flagged as hidden.

If you are in the UK or the EU, you also have the right to complain to your data protection authority. If you are in Nigeria, that is the Nigeria Data Protection Commission.

The application is a separate matter, and a shorter one

Everything above is about this website. NaveLight itself runs entirely on your church's computer. Sermon audio, transcripts, your songs, your media and your services stay on that machine — there is no server for them to go to, no account required, and, unless you choose to sign in, no identifier that could tie an installation to a church. Nothing watches how you use it.

The application talks to us in exactly three situations, and this is the complete list. Once, a few seconds after it starts, it asks whether a newer version exists — that request carries the version you are running and your operating system, nothing else, and if it can't get an answer it stays quiet rather than bothering anyone. You can turn it off in Settings, and off means off: the application then contacts nothing on its own. Second, if you choose to send a problem report, it sends what you typed, the computer's hardware description, and — unless you untick it — a short log of application events. The dialog shows you the exact contents before anything is sent, and the log never contains the transcript, captions, or anything said in the room: those are never captured for it in the first place.

Third, if you choose to create an account — it is optional, and nothing in the application ever requires one — signing in sends the email address you type, a name you choose for the computer, and the application's version and operating system. The computer then holds a sign-in token, and while signed in the application refreshes your account details at launch using it. That token is the one identifier that can recognise this computer, it exists only because you signed in, and signing out — from the application or by removing the device from your account — deletes it. An installation that never signs in never gains any identifier at all.

On our side of that: the sign-in code we email you is stored only as a hash, expires, and is deleted the moment you use it, so there is never a live code sitting in a table. The computer gets a row holding the name you gave it, its platform and version, and the sign-in token — again only as a hash, never the token itself, which means the table is worth nothing to anyone who steals it. Removing a device marks that row revoked rather than deleting it, so you can still see which machine it was when you look.

Apart from that sign-in token, no request carries an account, a serial number, or any way to recognise the same computer twice — which also means we cannot count installations that never sign in, and have chosen not to be able to. If a future version ever adds to this list, this page changes first and the application shows the change, not a changelog you'd have to go looking for.

Who we are

NaveLight is made by KED Creative Technologies Limited, which is the data controller for the waitlist. Write to [email protected] about anything on this page.

If this page changes we will change the date at the top. If a change ever means collecting something new, we will ask before it applies to a signup already on the list.