Your privacy

Effective 8 October 2026. This policy explains what data the Sajadah app and the sajadah.org website process, why, and how you control it.

In short

  • Prayer times are calculated on your phone. Your coordinates are not stored on our servers.
  • An account is optional. Without one, your progress stays on your device.
  • We don't sell data, show ads, or track you across other companies' apps.
  • We use Google's Firebase for accounts, sync, group khatam, usage statistics, and crash reports.
  • You can delete your account from inside the app at any time.

Location

Sajadah needs a location to calculate prayer times and the qibla direction. You can allow device location, or choose a city by name.

  • Calculated on the device. Prayer times and the qibla direction are calculated on your phone. Your coordinates are not sent to our servers or stored in your account.
  • City names. To show the city name for your coordinates, the app uses the operating system's built-in geocoder (Apple or Google), which receives those coordinates.
  • City search. When you type a city name, the search text is sent to the operating system's geocoder, and may be sent to Photon (komoot) and Nominatim (OpenStreetMap Foundation).
  • Qibla map. If you open the map on the qibla screen, map tiles load from OpenStreetMap, so the tile server learns the area shown.

You can revoke location permission at any time in your device settings and pick a city manually.

Account (optional)

You can use Sajadah without an account. If you sign in with Apple, Google, or email, we store in Firebase:

  • your name, email address, sign-in method, operating system, app language, and the dates the account was created and last active;
  • the data you sync so it can be restored on another device: prayer and daily logs, dhikr progress, fasting, recitation lessons, Qur'an reading (last position and bookmarks), khatam, tasbih, the 99 Names, the hajj and umrah guide, and du'a counts;
  • a log of in-app activity (for example opening a screen or finishing a lesson), which helps sync your history.

Group khatam and user content

When you start or join a group khatam, the app creates a random anonymous identity (Firebase Anonymous Auth) so the juz you take is linked to you. We store the group name, intention, target date, the name you write for each juz, and when each juz was taken and finished.

The group name, intention, and per-juz names are visible to anyone who has the group's code or link. Don't put sensitive personal information there.

If you use the in-app du'a requests feature, we store the request text, your first name, its category and language, and "Ameen" and report records. Du'a requests are visible to other users.

If you report content, we store the reported item, the reason, and the reporter's identity so the report can be acted on.

Feedback

If you send feedback from inside the app, we store its category, the message, your platform, language, and account identifier. If you email us, we keep your email in order to reply.

Usage statistics and crash reports

We use Firebase Analytics to understand which features are used (for example in-app events, app language, device type, and an app-installation identifier), and Firebase Crashlytics for crash reports (the error trace and device state at the time of the crash). We use this data to improve the app, not for advertising. Sajadah contains no advertising SDKs and does not track you across other companies' apps or websites.

Content and third parties

The Qur'an text, translations, recitations, and some fonts load from the content providers below. Like any website, they receive your IP address and standard request information:

ProviderUsed for
Google Firebase (Auth, Firestore, Analytics, Crashlytics)Accounts, sync, group khatam, feedback, statistics, crash reports
Apple / Google geocoderCity names from coordinates, city search
Photon (komoot), Nominatim (OpenStreetMap)City search
OpenStreetMapQibla map tiles
api.quran.com, api.alquran.cloud, verses.quran.foundation, static.qurancdn.comQur'an text, translations, fonts
everyayah.com, audio.qurancdn.comRecitation audio
Google FontsFonts

Data in Firebase is stored on Google's servers, which may be outside your country.

On-device data and notifications

Your settings, progress, and logs are stored on your device. Adhan reminders and other notifications are scheduled on the device. We don't send push notifications from a server.

The sajadah.org website

This website uses no cookies, ads or analytics tools, and loads no third-party scripts except Firebase on the khatam invite page. Fonts are served from our own server. Our server and content-delivery network (Cloudflare) keep standard technical logs, such as IP address and browser type, for security; these logs are rotated regularly.

  • Kept in your own browser (localStorage), not on our server: the city you choose for prayer times, where you last read in the Qur'an, the Arabic text size and display choices, today's dhikr progress, and the name you type on a khatam invite page. Clear the site's data in your browser to remove them.
  • Location. Your browser asks for your location only when you tap Use my location. For prayer times, the coordinates are used in the browser to find the nearest region. For the qibla, they are used in the browser to calculate the direction. Coordinates are not sent to our server.
  • Qibla map. Map tiles load from OpenStreetMap (tile.openstreetmap.org), so the tile server learns the area shown and your IP address.
  • Recitation. When you play a recitation, the audio loads from everyayah.com, which receives your IP address like any website.
  • Khatam invites. The /k/… page signs in to Firebase anonymously so you can take a juz.

Keeping and deleting data

Account data is kept until you delete your account. Delete it in the app under Profile → Account (tap your name) → Delete account. This deletes your profile, synced data, and activity log, and then deletes your sign-in account.

Some data is not deleted automatically: group khatams and their per-juz names, du'a requests, reports, and feedback. A group's creator can delete the group or clear a juz. To remove the rest, email [email protected] and we'll process it within 30 days. Statistics and crash data are kept for a limited period under Google's retention settings.

Your rights

Depending on where you live (including under Indonesia's Personal Data Protection Law No. 27 of 2022 and the EU/UK GDPR), you can ask to access, correct, or delete your personal data, and withdraw consent (such as location permission). Send requests to [email protected].

Children

Sajadah is not directed at children under 13, and we don't knowingly collect their personal data. If you believe a child has given us data, contact us and we will delete it.

Security

Data is sent over encrypted connections (HTTPS/TLS), and access to Firestore is limited by security rules. No system is perfectly secure, but we take reasonable care to protect your data.

Changes and contact

If this policy changes, we'll update the date above and, for significant changes, let you know in the app. Questions? Email [email protected].