This Privacy Policy explains what information is collected from users of the Hatırla İslam mobile app (the "App"), how that information is used, and what rights you have. By downloading and using the App, you accept this policy.
1.1 Account information
When you register in the App, the following is collected and stored in our PostgreSQL database hosted on Supabase infrastructure:
- First and last name
- Email address
- Password (never stored in plain text; hashed with the industry-standard bcrypt algorithm)
Instead of registering with an email and password you may use Sign in with Google or Sign in with Apple. In that case the provider (Google or Apple) passes us only your name and email address so that we can create your account; when social sign-in is used, no password is stored on our side.
1.2 Usage data (activity history)
So that the App can provide its core functions and let you review your own history, the following activities are recorded against your account:
- Prayers completed / missed / made up (qada)
- Dhikr (tasbih) counts and history
- Khatm progress and completed juz
- Du'a and Qur'an sessions read or completed
This data is linked only to your own account. It is not shared with third parties and is never used for advertising.
1.3 Location
We need your device's location to calculate accurate prayer times for where you are and to show the qibla direction.
- Your location is processed on your device only.
- It is never sent to our servers and never stored there.
- You can revoke location permission at any time in iOS or Android settings.
- There is no background location tracking.
1.4 Push notification token
So that we can send you an athan reminder when a prayer time enters, a device-specific notification token is generated through the Expo Push Notifications service and stored on our servers against your account. This token is used solely to deliver notifications to you; it does not directly reveal your identity and is never used for advertising.
1.5 Anonymous usage analytics
To understand which features are used most and to improve the experience, we collect anonymous product analytics.
Collected- Which screens are opened
- Basic app events (e.g. "hatim_started", "zikir_saved", "namaz_guide_opened")
- App version, operating system version
- Device type (iOS / Android), language preference
- An anonymous device identifier
Not collected- Name, surname, email, IP address
- Precise location, advertising identifier (IDFA / AAID)
- Qur'an / du'a / dhikr content
- Message content, session replay recordings
Provider: PostHog (European Union data centre — eu.i.posthog.com).
Association: Events are associated only with an anonymous device/session identifier; in addition, only your city and theme preference are sent for segmentation. Analytics events are not matched to your account (your user identity). When an account is deleted, a reset call is made in PostHog and future events from that device are processed under a new anonymous identity.
No advertising, no tracking: This analytics data is never used for ad serving, profiling, sale to third parties or cross-app tracking.
1.6 Advertising data
Because the App is offered free of charge, it shows ads through Google AdMob. To serve, frequency-cap, measure and protect those ads from fraud, AdMob may process the following technical data:
- IP address and the approximate (city / country) location derived from it
- Device type, operating system version, app version, language and time zone
- Interaction data about ads shown or clicked
- A device-level technical identifier used for frequency capping and fraud prevention
This data is processed by Google's advertising infrastructure and is not stored on Hatırla İslam servers. The App requests non-personalised (contextual) ads only; ads are never selected based on your account, your worship data or a behavioural profile. See 03. Advertising for details.
1.7 Information we do not collect
The App does not collect any of the following:
- Contacts
- Photo library
- Microphone recordings
- Calendar
- Health data
- Your account, worship and activity data is never used for advertising or shared with advertising partners
- The App does not request App Tracking Transparency permission on iOS; there is no cross-app user tracking
We process the information we collect solely for the following purposes:
- To create, verify and manage your account
- To provide the App's core functions (prayer times, qibla, Qur'an, dhikr, khatm, du'a, calendar)
- To deliver the prayer time notifications you have chosen
- To keep the service secure and prevent abuse
- To respond to user requests and complaints
- To improve the App's stability and user experience through anonymous usage analytics
- To show ads through Google AdMob so that the App can remain free
- To verify your "Remove Ads" purchase and apply it to your account
Your account, worship and activity data is never used for profiling, cross-device tracking or sale to third parties. Ads run only on the non-personalised model described in 03. Advertising.
To keep the App free, we show ads through Google AdMob. These are native ads on the home and tools screens, plus full-screen (interstitial) ads shown between screen transitions.
- Non-personalised ads only: The App always requests non-personalised (contextual) ads from AdMob. Ads are not targeted using your past behaviour or a personal profile.
- iOS — no tracking prompt: The App does not show Apple's App Tracking Transparency prompt and does not access the advertising identifier (IDFA). Its privacy manifest declares that no tracking takes place (NSPrivacyTracking).
- Content rating: AdMob requests are limited to a maximum content rating of "G" (general audiences); inappropriate or adult ads are blocked.
- Not stored on our servers: The technical data processed by the ad infrastructure (see 1.6) is handled by Google and is not kept on Hatırla İslam servers.
Removing or managing ads
- Remove ads entirely: use the in-app "Remove Ads" purchase (see 04. In-app purchase).
- iOS: Settings → Privacy & Security → Apple Advertising lets you manage your device ad preferences.
- Android: Settings → Google → Ads lets you reset or delete your Advertising ID.
- Google ad settings: adssettings.google.com
Google's advertising and data policy: policies.google.com/technologies/ads
The App offers one optional, one-off (lifetime) purchase called "Remove Ads".
- The purchase is made through the Apple App Store or Google Play; payment is handled entirely by the relevant store.
- We never see, receive or store your card or payment details.
- Once your purchase completes, a purchase confirmation (receipt) is obtained from the store and used to mark your account as ad-free. This status is stored against your account on our server and cached on your device for fast access.
- You can recover your purchase on a new device with "Restore Purchases".
We use the following service providers to run the App. The data passed to them is limited to what is necessary to deliver the service.
| Provider | Purpose | Data shared | Data region |
|---|
| Supabase | Database infrastructure (PostgreSQL hosting) | Name, email, password hash, activity records, notification token | EU / USA |
| Expo Push Notifications | Push notification delivery | Notification token, notification content | USA |
| PostHog | Anonymous product analytics | Anonymous event names, anonymous device/session id, app version, OS version, city, theme preference | European Union |
| Google AdMob | Mobile ad serving and measurement | IP, approximate location, device / OS information, ad interaction, device-level technical identifier | USA / global |
| Sign in with Google | Authentication (optional) | Name, email | USA / global |
| Sign in with Apple | Authentication (iOS only, optional) | Name, email (or the private relay address generated by Apple) | USA / global |
| Apple App Store / Google Play | Distribution, updates and in-app purchase | Purchase confirmation (receipt) | — |
Each provider's own privacy policy applies:
- Your data is retained for as long as your account is active.
- When you use Profile > Delete Account in the App, your password is verified and then all of your account information, activity history and notification token are permanently deleted.
- Account deletion cannot be undone.
- Anonymous analytics data (PostHog) is not linked to personal data in the first place; independently of account deletion, a
reset call is made on the client, and future events from that device are held under a new anonymous identity. - Technical data processed by the ad infrastructure is retained by Google under Google's own retention policies.
- Where we have legal retention obligations (if any), the relevant data is kept only for the period required by the applicable legislation.
You can also start the deletion process from the account deletion page.
The following technical measures are in place to protect your data:
- Passwords are stored hashed with bcrypt; no plain-text password exists in the system.
- Sessions are managed with JWT (JSON Web Tokens).
- JWTs are kept on your device in secure storage — Apple Keychain / Android Keystore (expo-secure-store).
- All client–server communication runs over HTTPS / TLS.
- Our infrastructure provider, Supabase, stores data encrypted in AWS data centres.
No system is 100% secure, but we work continuously to apply industry standards.
Under the GDPR where applicable, and under Türkiye's Personal Data Protection Law No. 6698 (KVKK), you have the following rights:
- To request access to the personal data held about you
- To request that data be corrected or deleted
- To request that processing be restricted
- To learn which third parties your data has been transferred to
- To object to processing
- To lodge a complaint with the competent supervisory authority under the GDPR, or with the Personal Data Protection Board under the KVKK
To exercise these rights, email hatirlaislam@gmail.com. Requests are answered within 30 days at the latest.
The App is intended for general audiences. We do not knowingly collect personal data from children under 13. Parents are encouraged to supervise their children's use of the App. If we become aware that we have inadvertently collected information from a child under 13, that information is deleted immediately.
On the advertising side, AdMob requests are limited to a maximum content rating of "G" (general audiences) and only non-personalised ads are shown; there is no behavioural targeting and no remarketing.
Our Supabase infrastructure may host your data in data centres in the EU / USA region, and Google AdMob uses global data centres. International transfers are carried out under standard contractual clauses (SCCs) and equivalent safeguards.
We may update this Privacy Policy from time to time. Significant changes will be:
- announced inside the App, and
- reflected in the "Last updated" date at the top of this page.
Continuing to use the App means you accept the current policy.
For any question, request or complaint about this policy or your data, get in touch by email.