- Effective Date
- 2026-05-25
- Last Updated
- 2026-10-10
- App
- Rawha: Quran & Prayer Times
- Publisher and data controller
- Ridvan Kizil, Türkiye, publishing as Rawha ("we", "us", "our")
- Contact
- privacy@rawhaapp.com
On this page
- 1. Summary (Plain English)
- 2. Information We Collect
- 3. How We Use Information
- 4. Third-Party Services
- 5. Storage & Security
- 6. Your Rights
- 7. Children's Privacy
- 8. International Transfers
- 9. Notifications, Location & Microphone Permissions
- 10. Account & Data Deletion
- 11. Changes to This Policy
- 12. Open Source
- 13. Hosted URLs
- 14. Contact
This Privacy Policy explains what information Rawha collects, how it is used, with whom it is shared, and the choices you have. By using Rawha you agree to this policy. If you do not agree, please do not use the app.
1. Summary (Plain English)#
| Question | Answer |
|---|---|
| Do you sell my data? | No. Never. |
| Do you show ads? | No. Rawha is ad-free. |
| Do you track me across other apps or websites? | No. |
| Do you use analytics? | No usage analytics or third-party analytics SDKs. If the app crashes, an anonymous crash report (error, stack trace, coarse breadcrumbs, app version and build, platform, OS version, device model, locale, and a random per-session ID — never message text, never your identity) is stored in our Supabase project so we can fix it. See §2.2 and §4. |
| Is my journal private? | Journal entries, mood check-ins, intentions and reflections you save are stored only on your device. But anything you type into an AI feature (the Mental Wellbeing companion, AI mood reflection, the spiritual guides, the coaches, or Ask-AI on a verse) is sent to our AI provider and saved as your chat history — see below. |
| What goes to a server? | Your account email and display name (if you sign in); your Quran bookmarks, reading position and streak, and any verse reminders you save while signed in; family-circle / group-khatmah participation; every message you send to any AI feature — including emotional or mental-health text you choose to share — which is processed by Anthropic and stored as your AI conversation history until you delete your account; only when you tap "Check my recitation", the short recording of the one verse you just recited, which is transcribed by ElevenLabs and not stored by us; and anonymous crash reports. |
| Can I delete everything? | Yes. See §10 for instructions. |
2. Information We Collect#
2.1 Information you provide#
- Account information (only if you create an account): email address and an optional display name. Rawha has no photo upload — your avatar is the first letter of your name, or an emoji you pick for group features.
- Quran activity synced to your account (only while signed in): bookmarks, your last reading position and reading streak, and verse reminders — including any short reflection or action plan you type into a reminder. These are stored in your account so they follow you across devices.
- AI features (important — please read): Rawha includes several optional AI features powered by Anthropic (Claude): the Mental Wellbeing companion, AI mood reflection, the morning / evening spiritual guides, the prayer and memorization coaches, and Ask-AI on a verse. When you use any of these, the text you type — including anything you choose to share about your feelings, mental health, or personal situation — together with any relevant verse reference and your recent conversation history, is sent to our server and then to Anthropic to generate a response, with your account ID attached for rate limiting. Because some of this text can reveal information about your health or state of mind, we treat it as sensitive (special-category) data under GDPR Article 9 and only process it with your explicit consent, which the app asks for before your first AI message and which you can withdraw at any time (§6). You are never required to use these features, and you should not enter anything you are not comfortable sharing with an AI service.
- Recitation check (optional): Recitation Practice lets you record yourself reciting one verse. The recording stays on your phone unless you tap "Check my recitation". If you do, that recording (audio, at most 30 seconds) — and nothing else: no name, no email, no other data — is sent to our server and forwarded to ElevenLabs, a speech-to-text provider, which transcribes the words you recited so the app can show which of the verse's words it heard. This is a word check, not a judgement of your pronunciation or tajweed. We do not store the audio or the transcript; the only record we keep is a timestamp against your account for rate limiting. ElevenLabs' own retention applies to what it receives — see its Privacy Policy. The check is covered by the same explicit consent as the other AI features (§6). After the check, the app keeps the recording on your phone only so you can play it back, and deletes it when you leave the screen.
- Membership (optional): If you buy a membership for the AI features, the purchase is made through Apple or Google. We receive and store whether your account has an active membership, which plan, when it renews or ends, and whether it is in a free trial — never your card number, billing address or store account email. To connect the purchase to your account we give the store-billing service (RevenueCat, §4) your Rawha account id.
- Your acceptance of the Terms: when you accept the Terms of Service we record the version you accepted, the date and time, your app version, platform (iOS/Android) and app language, and attach it to your account. We keep it as evidence of the agreement; it is deleted with your account. We do not record your IP address for this.
- AI usage counters: to apply the free allowance and the member limits we keep a count of your AI requests and the size of each (number of tokens) — never their content — in a ledger only our server can read.
- Group features: If you create or join a Family Circle or Group Khatmah, your display name, avatar emoji, and the prayers / Juz you have completed within that group — plus any du'a or dedication you choose to share — are visible to the other members of that group.
- Free text you save (not sent to AI): journal entries, mood check-ins, intentions, and reflections you write are stored only on your device and are not uploaded — unless you send that text into an AI feature, a verse reminder, or a group feature, in which case the paragraphs above apply.
2.2 Information collected automatically#
- Device identifier: a randomly generated app-install ID (
device_id) used to recognise your device across app launches. It is not your hardware identifier and it is reset when you reinstall the app. - Location (only with your permission, foreground only): used for prayer times, Qibla direction, and the mosque finder. Your location is never stored on our servers. Three services receive it directly from your device, without any account identifier attached: your phone's operating-system geocoder (Apple on iOS, Google on Android) receives your precise coordinates to turn them into the city name shown on the prayer-times card; the Aladhan prayer-times API receives your coordinates rounded to about 1 km, and — only when you open the mosque finder — an OpenStreetMap Overpass mirror receives your coordinates and the search radius you chose. See §4.
- Crash reports: if the app crashes, it stores an anonymous crash report — the error message, a stack trace, coarse breadcrumbs (which screens were opened), app version and build, platform, OS version, device model, locale, and a random per-session ID that is not linked to your account — in our Supabase project. Reports never contain message text, journal content, or your identity; the app scrubs user content before anything leaves the device. Apple and Google may separately collect OS-level crash logs under their own policies if you opted into sharing them.
2.3 Information we do not collect#
- We do not access your contacts, photo library, calendar, SMS, call logs, browser history, or other apps.
- The microphone is used only if you choose to record your own recitation practice. The recording stays on your device unless you tap "Check my recitation", in which case only that clip is sent for transcription as described in §2.1 — it is never uploaded in the background or without that tap.
- We do not use the IDFA / Advertising ID.
- We do not use third-party advertising or analytics SDKs.
3. How We Use Information#
We use the information described above only to:
- Provide core features (prayer times, Qibla, Quran reading, bookmarks and reading progress, journal, notifications).
- Power the optional AI features described in §2.1.
- Enable optional social features (Family Circle, Group Khatmah).
- Send notifications you have opted into (prayer reminders, daily streak, group activity).
- Maintain app stability, fix crashes, and prevent abuse (including rate-limiting AI requests).
- Comply with legal obligations.
We do not use your data for advertising, profiling, or sale to third parties.
4. Third-Party Services#
The table below lists every outside service the app sends data to, and exactly what each receives.
| Service | Purpose | Data it receives |
|---|---|---|
| Supabase (database, authentication, edge functions) | Runs your account and everything tied to it | Email, display name, device_id, bookmarks, reading position and streak, verse reminders, group memberships and shared group content, AI conversation history, push token, anonymous crash reports |
| Anthropic (Claude API) | All AI features — verse Q&A, Mental Wellbeing companion, mood reflection, spiritual guides, coaches | The text you send to an AI feature (which may include emotional or mental-health content), any relevant verse text, and recent conversation history — only after you have given explicit consent in the app. See Anthropic's Privacy Policy. |
ElevenLabs (speech-to-text, api.elevenlabs.io) |
Recitation check — transcribing the words you recited | Your recitation recording (audio, ≤ 30 s) and nothing else, only when you tap "Check my recitation" and only after the AI consent in §6. Used to transcribe the words you recited; not stored by us; the app deletes the file from your phone when you leave the screen (it is kept until then so you can play it back). ElevenLabs' retention is governed by its own policy — see ElevenLabs' Privacy Policy. |
| Apple App Store / Google Play billing | Taking payment for an optional membership | Handled entirely by the store under its own privacy policy; we never receive your payment details |
RevenueCat (api.revenuecat.com) |
Confirming and tracking membership purchases on our behalf | Your Rawha account id (a random identifier), the store's purchase receipt and transaction ids, product, price, currency, country of the store account, and app/device model and OS version. No name, no email, no content you write. Only if the membership feature is active on your device |
| Expo push service (relays to Apple Push and Google FCM) | Delivering notifications you opt into | Your push token and the notification text (e.g. "Ahmed completed Juz 5") |
Expo update service (u.expo.dev) |
Checking for app updates when the app starts | App version, runtime version, platform, update channel, and a random per-install ID — no account data |
| Apple Maps (iOS only) | The map view inside the mosque finder | The map area being displayed, handled by Apple's MapKit on your device under Apple's policy. "Get directions" opens your maps app with the mosque's location. |
| Apple / Google geocoding (your phone's operating system) | Turns your coordinates into a city name for the prayer-times card | Your precise coordinates, handled by iOS (Apple) or Android / Google Play services (Google) under their policies; no account identifier |
Aladhan API (api.aladhan.com) |
Prayer-time and Hijri-date calculation | Your coordinates rounded to about 1 km, the date, and your calculation method — no identifier |
OpenStreetMap Overpass mirrors (overpass-api.de, overpass.kumi.systems, overpass.private.coffee) |
Mosque finder | Your coordinates and the search radius, only when you open the mosque finder — no identifier |
Gold-price and exchange-rate APIs (api.gold-api.com, open.er-api.com) |
Live gold/silver prices and exchange rates for the zakat calculator | No personal data — a plain price / rate lookup |
Wikimedia Commons (upload.wikimedia.org) |
One-time download of the adhan audio, then cached on your device | No personal data |
Google (google.com/generate_204) |
A tiny connectivity probe so the app knows whether it is online | No personal data |
mp3quran.net (www.mp3quran.net for verse timings, audio on server*.mp3quran.net / cdn.mp3quran.net) |
Qur'an recitation audio for most reciters | The surah and reciter being played. Our server fetches the verse timings, so mp3quran.net sees our server's address for that; the audio file then streams from their CDN to your device (your IP address, the file requested) — no account or other identifier |
Quran Foundation (apis.quran.foundation, audio on download.quranicaudio.com) |
Qur'an recitation audio, streamed through our server | The surah and reciter being played. The request to Quran Foundation is made by our server, so they see our server's address, not yours; their CDN then streams the audio file to your device (your IP address, the file requested) |
| QuranEnc.com (Quran Encyclopedia, Rowwad Translation Center) | Qur'an translations in 28 languages | The surah and edition you are reading (your IP address, the file requested) — no identifier; the text is cached on your device afterwards |
| Apple App Store / Google Play | App distribution and OS-level crash logs | Per their respective policies |
We have no control over how Apple, Google, Anthropic, ElevenLabs, or the other services above process data they receive from your device; their own privacy policies govern that processing.
5. Storage & Security#
- Local data (journal, mood check-ins, intentions, streak counters, settings, the cached adhan audio) is stored in your device's app sandbox.
- Account data on Supabase is protected by TLS in transit and encryption at rest, with row-level security so that each user can read only their own rows (and, for groups, only the groups they belong to).
- We retain account data for as long as your account exists. Group Khatmah and Family Circle data are retained while the group exists.
- AI conversation history is retained. Your messages to AI features and the responses are stored in your account (the
ai_conversationsrecord) so the chat has context and history, and are kept until you delete your account (see §10) or ask us to remove them. Separately, Anthropic processes each message to generate the response under its own terms; see Anthropic's Privacy Policy. We do not use your AI conversations to train any model, and we do not sell them. - Anonymous crash reports are deleted automatically after 30 days.
- Recitation recordings are not stored by us. When you tap "Check my recitation", the clip passes through our server to ElevenLabs and is discarded; neither the audio nor the transcript is written to our database. On your phone the file is kept only until you leave the screen.
No system is perfectly secure. You are responsible for the security of the device you use Rawha on.
6. Your Rights#
Depending on where you live, you may have rights under GDPR (EEA / UK), CCPA (California), LGPD (Brazil), PIPEDA (Canada), and similar laws, including:
- Access: request a copy of the personal data we hold about you.
- Correction: ask us to fix inaccurate data.
- Deletion: ask us to delete your account and personal data (see §10).
- Portability: request a machine-readable export.
- Objection / restriction: object to certain processing.
- Withdraw consent: for processing based on consent — location and notifications (in your OS settings) and the AI features, including the recitation check (Profile → Withdraw AI consent, stop using them, or ask us to delete your conversation history).
To exercise any of these rights, email privacy@rawhaapp.com. We will respond within 30 days.
The legal bases for our processing under GDPR are: (a) your consent (location, notifications, the recitation check) and, for the AI features, your explicit consent under Article 9(2)(a) because your messages may reveal health information; (b) performance of a contract (running your account, sync, and groups); and (c) our legitimate interest in keeping the service stable and secure (crash reports, abuse prevention).
7. Children's Privacy#
Rawha is intended for users aged 13 and older (or the higher minimum age of digital consent in your jurisdiction). When you sign in you confirm that you meet this requirement.
- We do not knowingly collect personal information from children under 13 (or the applicable minimum age) without verifiable parental consent.
- If we learn that we have collected personal information from a child below that age, we will delete it.
- A parent or guardian who believes their child has provided us with personal information may email privacy@rawhaapp.com to request deletion.
8. International Transfers#
Your data may be processed in the United States and other countries where our service providers operate. We rely on Standard Contractual Clauses or equivalent safeguards for transfers out of the EEA / UK.
9. Notifications, Location & Microphone Permissions#
- Notifications are off by default. You explicitly grant permission. You can revoke it at any time in your OS settings.
- Location is requested only when you use the prayer-time, Qibla, or mosque-finder features. We use it only while the app is in the foreground. You can revoke it at any time in your OS settings.
- Microphone is requested only if you use the recitation practice recorder. Audio stays on your device and is transmitted only if you tap "Check my recitation" (§2.1), and then only that clip, only to ElevenLabs via our server.
10. Account & Data Deletion#
You can delete your account and all server-side data at any time:
In the app: open the Profile tab, scroll to the bottom, tap Delete Account, then confirm. Your account and its server-side data are deleted immediately. By email: send a deletion request from your account email to privacy@rawhaapp.com with the subject "Delete my Rawha account". We will process it within 30 days and confirm by email.
After deletion:
- Your profile, bookmarks, reading progress, reminders, group memberships, AI conversation history, and push tokens are erased from our active systems (immediately for in-app deletion; within 30 days for email requests).
- Backups containing residual data are rotated out within 90 days.
- Your local data (journal, mood check-ins, settings) is independent — clear it by uninstalling the app.
A standalone copy of these instructions is published at the URL in §13 so that people without the app can still request deletion.
11. Changes to This Policy#
We may update this Privacy Policy when the app changes. We will revise the "Last Updated" date and, for material changes, post an in-app notice and/or email you. Continued use after the change means you accept the revised policy.
12. Open Source#
Rawha uses open-source software and openly licensed content listed on our Open-Source Licenses page. None of these libraries receive personal data from us.
13. Hosted URLs#
This policy is published at:
Account deletion instructions:
14. Contact#
Data controller: Ridvan Kizil, Türkiye (publishing as Rawha) Email: privacy@rawhaapp.com
Back to top ↑