Back to home

Trust

Privacy Policy

We built this app because another Islamic app sold its users' location data to government-affiliated brokers. Our entire business model is built on not doing that.

Last updated: September 2026

The short version

Quran Islam Pro is a privacy-first product. That is not a tagline added after the fact - it is the founding reason the app exists. Here is what that means in practice:

  • Prayer times and Qibla direction are computed entirely on your device. Your location never leaves your phone for these features.
  • Your Quran reading progress, dhikr counts, prayer logs, and habits are stored locally by default. Sync to the cloud is optional and requires you to create an account.
  • We do not sell, rent, share, or broker your data. Not to advertisers. Not to governments. Not to anyone.
  • There are no third-party advertising SDKs in the build. We enforce this as a dependency policy, audited before every release.
  • You can export everything or delete your account at any time, directly from the app. No forms to fill, no waiting period beyond what the law requires.

If anything in this policy conflicts with the principle “we do not sell your data or use it against you”, treat the principle as the true statement and report the discrepancy to privacy@quranislampro.com so we can fix it.

What we collect and why

We collect only what is necessary to provide the product. Every data point we hold has a specific, stated purpose. Here is the complete list.

Device identifier
A random UUID generated locally on first launch. Used to enforce the free-tier AI question limit (3 per day) without requiring an account. Never linked to a name, email, or location.
Account email
Only collected if you choose to create an account for multi-device sync. We use Supabase Auth. Your email is stored server-side, encrypted at rest. It is used only for authentication and critical service notifications.
Prayer logs and reading progress
Stored locally on your device. If you enable sync, a copy is stored on our servers keyed to your user ID, protected by row-level security so only your account can access it.
AI questions
Questions you send to Ask QIP are processed on our backend to generate an answer. We store a count per user for rate-limiting. The text of the question is not stored after the session ends unless you have conversation history enabled in settings.
Subscription status
We use RevenueCat on mobile to manage subscriptions. RevenueCat has its own privacy policy. We receive only whether your entitlement is active; we do not receive payment card details.
Crash reports
Anonymous crash data to identify and fix bugs. No personal data is included. This can be disabled in Privacy settings.

For details on how AI questions are specifically handled, read how our AI works.

Sensitive data and how it is protected

Several features handle data that is particularly private. Each is treated with extra care beyond the baseline.

  • Women's health data (cycle tracking, hayd rules) is stored on-device only, encrypted with AES-256-GCM using a key held in the platform keychain (iOS Keychain / Android Keystore). It is excluded from OS-level automatic backup. It is never synced to any server. It is scoped by profile so it is not visible across Family Mode profiles.
  • Mood entries and dream journal are encrypted on-device with the same mechanism and are also excluded from OS backup. No server copy exists.
  • Islamic will (Wasiyyah) is stored locally, encrypted, and excluded from backup. It is never transmitted.
  • Family Mode PIN is stored as a PBKDF2-HMAC-SHA256 hash with a per-install salt. The plaintext PIN is never stored anywhere.

What we never do

  • We do not sell your data to data brokers, advertisers, or any third party.
  • We do not share your prayer times, Qibla usage, or location data with anyone.
  • We do not use your data to build an advertising profile.
  • We do not include any third-party advertising SDK, analytics SDK that sends data to an ad network, or location broker SDK in the app binary.
  • We do not transmit your AI questions to any model provider for training purposes. Questions are sent to Gemini for inference only, under a data processing agreement that prohibits training use.
  • We do not retain the text of AI questions after the session ends unless you have explicitly enabled conversation history in Settings.

Third-party services we use

We use a small number of external services to operate the product. Each is chosen for minimal data exposure and governed by a data processing agreement.

  • Supabase - Database and authentication. Your account data and synced prayer logs are stored here. Data is encrypted in transit and at rest. EU data residency available on request.
  • Google Gemini API - Powers the Ask QIP AI feature. Questions are sent for inference only. We have a DPA with Google prohibiting training use of your queries.
  • RevenueCat - Manages in-app subscription entitlements on mobile. Receives your app-store anonymous subscriber ID and subscription status. No payment card data reaches us or RevenueCat.
  • OpenStreetMap / Overpass API - Used for the mosque and halal place finder. Your search query (a typed city name or one-time coordinates) is sent to retrieve results. Nothing about your request is stored on our side after the response is returned.

Your rights

You have the following rights regardless of where you live. We honour them without requiring you to prove jurisdiction.

  • Access - Export all your data from Settings > Privacy Dashboard > Export My Data at any time.
  • Deletion - Delete your account and all associated data from Settings > Privacy Dashboard > Delete Account. Local data is wiped immediately; server data is deleted within 30 days.
  • Correction - Update any stored personal information from your account settings at any time.
  • Portability - The data export produces a structured JSON file you can import into another service.
  • Objection to processing - You can disable optional data collection (analytics, conversation history) from Settings at any time without losing core features.

Children and Family Mode

The app includes a Kids Mode designed for children under 13. When Kids Mode is active, no account creation is permitted for that profile, no AI features are available, no external links are shown, and no data is transmitted. The Family Mode PIN is required to exit Kids Mode.

We do not knowingly collect personal data from children under 13 outside of Family Mode's locally-stored assignment data. If you believe a child has provided personal data through a channel we have not anticipated, contact us at privacy@quranislampro.com and we will delete it promptly.

Changes to this policy

When we make material changes, we will notify you through the app and update the date at the top of this page. Continuing to use the app after the effective date constitutes acceptance of the updated policy. If the changes are significant enough that you would not have chosen to use the app under the new terms, you can delete your account before the effective date and we will honour that choice.

Contact

Questions about this policy, data deletion requests, or formal GDPR requests can be sent to our privacy contact.

Email
privacy@quranislampro.com
Response time
Within 5 business days for routine queries; within 30 days for formal data requests.