Privacy Policy for Dhikr Reminders
1. Who we are and scope
This Privacy Policy applies to the Dhikr Reminders mobile application (the “App”), operated by the Dhikr Reminders developer (“we,” “us,” or “our”). Privacy questions and deletion requests may be sent to dhikrreminders.support@gmail.com.
The App is an independent product and is not an official application of Quran Foundation (“QF”). The App uses Quran Foundation APIs to retrieve Quran-related content and audio. QF operates services in the Quran.com and QuranReflect ecosystem. The App currently uses QF server-to-server API access without signing end users into a QF account; we do not receive a user's QF password or QF user OAuth token.
2. Information the App accesses, collects, or processes
| Data | How it is used | Where it goes |
|---|---|---|
| Precise or approximate location | Foreground location supports prayer times, Qibla, and nearby mosque search. Optional Automatic Travel may obtain a location roughly every few hours in the background to detect a major move and repair prayer/Adhan schedules. | Qibla and Automatic Travel calculations are designed to operate locally. When online prayer times are requested, coordinates are sent to AlAdhan. Nearby Mosque search sends coordinates to our Cloudflare Worker, which queries Foursquare and OpenStreetMap; if the Worker path fails, the App may query an OpenStreetMap Overpass service directly. |
| App activity and diagnostics | Used to understand crashes, app reliability, performance, app lifecycle state, and limited allowlisted diagnostic events. | Firebase Analytics, Crashlytics, Performance Monitoring, and related Firebase services may receive pseudonymous app-instance/install identifiers, device/app metadata, crash information, performance metrics, and approximate geography inferred from IP address. We do not intentionally attach Quran/Hadith/Adhkar text, precise coordinates, search terms, notification content, or a product account user ID to our diagnostic events. |
| Notification / installation identifiers | Firebase Cloud Messaging uses installation and push-token identifiers to deliver app/content updates that are enabled for the device and to manage topic subscriptions. | Google Firebase. |
| Operational provider-health telemetry | Helps us know whether content providers are working and how long requests take. | Our Cloudflare Worker receives provider name, operation name, success/failure, bounded error category, duration, app version, and timestamp. The App intentionally excludes user IDs, device IDs, coordinates, content text, search terms, notification content, and email from this payload. Cloudflare may process ordinary network metadata such as IP address under its own service/privacy terms. |
| Problem reports you choose to send | If you open “Report a problem,” the App prepares an email containing your description, limited screen/content context, app version, device model, OS version, and app language. You may optionally attach one screenshot. | The App opens your email app for review. Nothing is sent until you press Send there. If you send from your own email account, our support inbox receives the sender email address and the content/attachment you chose to send. Your email provider also processes that message under its own policy. |
| Local worship and preference data | Bookmarks, Hifz progress, Khatm plans/progress, prayer check-ins, reading position, settings, downloaded audio, caches, and reminder choices support the features you choose. | Designed to remain in private on-device storage and not be intentionally uploaded by those local features. |
3. Sensitive religious information
Information that can reveal or relate to religious practice may be treated as sensitive information under some privacy laws. The App's Hifz, Khatm, prayer check-in, bookmark, and reminder features process this information locally when you choose to use those features. We do not use this information to build advertising profiles, sell it, mine it for unrelated purposes, or use it to train AI models.
Public Quran text and related metadata retrieved through Quran Foundation are content, not personal data about you. The App does not currently use QF end-user login or QF user-account data.
4. Location details and background location
Foreground location
Location permission is optional at the app level. If you deny it, features such as Quran reading and Adhkar remain available, but location-dependent features may not work or may rely on previously cached information.
For online prayer times, the App sends latitude/longitude and your selected calculation method/Asr school to AlAdhan so it can return the requested schedule. The App has an on-device prayer-time fallback when the network/provider is unavailable.
For Nearby Mosques, the App may send latitude/longitude to our Cloudflare Worker. The Worker rounds the location to approximately two decimal places for its mosque-result cache key and can cache successful area results for up to 24 hours (or a shorter degraded cache). The Worker then queries Foursquare and OpenStreetMap services. The App also keeps a nearby-mosque cache on the device for up to 14 days to reduce repeated lookups.
Automatic Travel (optional background location)
Automatic Travel is opt-in. If enabled and background location is granted, Android may wake the App roughly every four hours to request one balanced-power location fix. The App compares the new area with the location used for the current Adhan schedule and repairs schedules after a meaningful move. This is not continuous GPS tracking. The background travel check stores its most recent location/status in the App's private local storage and is designed to perform the travel comparison and prayer-schedule repair locally.
5. Firebase diagnostics and notifications
The production Android build includes Google Firebase services including Analytics, Crashlytics, Performance Monitoring, Cloud Messaging, Remote Config, Firebase Installations, and related dependencies. Depending on the Firebase service, Google may automatically process app-instance or installation identifiers, crash stack traces, app/device metadata, app lifecycle or interaction events, performance metrics, network timing/URLs without request payloads, IP-derived country/approximate geography, and push-delivery identifiers. Our code does not set a Dhikr Reminders account user ID in Firebase Analytics.
Firebase data is processed under Google's/Firebase's terms and retention settings. For more information, see Privacy and Security in Firebase, Firebase Android data-disclosure guidance, and the Google Privacy Policy.
6. Third-party services and content providers
Depending on the feature you use, the App communicates with or relies on third-party services. These providers may process ordinary network metadata such as IP address, device/browser request headers, and request time. Location providers also receive the coordinates needed to answer a location request. Current relevant providers include:
- Google Firebase — crash reporting, analytics, performance monitoring, push messaging, and remote configuration. Firebase privacy/security.
- Cloudflare — hosts our private API Worker and caches limited API responses. Cloudflare Privacy Policy.
- Foursquare — one provider for Nearby Mosque/Places results. Foursquare Privacy Center.
- OpenStreetMap / Overpass services — mosque/place data and fallback search. OpenStreetMap Foundation Privacy Policy.
- AlAdhan / Islamic Network — online prayer-time calculations and approved Adhan assets. AlAdhan Credits and Terms.
- Quran Foundation — Quran content and Quran audio accessed server-to-server through our Worker. QF Developer Terms and QF Developer Privacy Policy Requirements.
- Al Quran Cloud / Islamic Network — Quran audio fallback/content delivery. Al Quran Cloud Terms.
Other religious-content providers used by the App are identified in the App's “Islamic Content Sources” and “Legal & third-party notices” screens. Their content-rights terms are reviewed separately from this privacy policy.
7. What we do not do
- We do not sell or rent personal information.
- We do not use user data to build advertising profiles, and the current production release contains no advertising SDK.
- We do not require a Dhikr Reminders user account.
- We do not intentionally send Quran text, Hadith text, Adhkar text, precise coordinates, search terms, notification content, or a product account user ID in our custom diagnostic events.
- We do not use personal religious activity or user-generated support content to train AI models without separate, specific consent.
8. Retention and deletion
- On-device data: local settings, worship progress, downloads, and caches remain until you reset/delete the relevant data, clear the App's storage, or uninstall the App. Some screens provide feature-specific reset or cleanup controls.
- Nearby Mosque caches: the App may keep an on-device area result for up to 14 days. Our Worker uses a coarse-area cache key and normally caches successful mosque results for up to 24 hours; degraded results use a shorter cache.
- Provider-health telemetry: we do not build a user/device profile from these events. Events may appear in Cloudflare operational logs subject to Cloudflare's configured/platform retention.
- Firebase: Google/Firebase retains diagnostic, analytics, performance, installation, and messaging data according to the applicable Firebase service and our project settings. See Firebase's published privacy and retention information.
- Support email: support correspondence and attachments are retained only as reasonably necessary to investigate and resolve the report, maintain security/abuse records, or meet legal obligations. We aim not to retain routine resolved support correspondence longer than 12 months.
If you ask us to delete personal data that we control, we will respond and complete deletion of data we can identify and control within 30 days unless a legal/security reason requires limited retention. Where provider backup cycles apply, deletion from backups may take longer, generally up to 90 days where technically applicable.
9. Your choices and rights
- Use Android settings to allow or deny foreground/background location and notification permissions.
- Turn off Automatic Travel, Adhan, Dhikr reminders, prayer check-ins, and app/content update topics in the App where available.
- Reset Hifz/Khatm or other local progress using the App's feature controls, clear downloaded media, clear App storage, or uninstall the App.
- Review any problem-report email and optional screenshot before pressing Send in your email app.
- Email dhikrreminders.support@gmail.com to request access, correction, or deletion of personal information that we can identify and control.
Because the App uses Quran Foundation through server-to-server client credentials and does not sign you into a QF user account, there is currently no end-user QF OAuth token for this App to revoke.
10. Security
We use HTTPS/TLS for App-controlled network transmissions, keep provider secrets such as the Quran Foundation client secret on our server-side Worker rather than in the Android APK, limit data included in custom diagnostic events, and use least-privilege/provider-specific controls where practical. Firebase and Cloudflare provide additional platform security controls and encryption for their services.
For Quran Foundation-related security incidents, our incident process is intended to meet the QF Developer Terms requirement to report actual or suspected unauthorized access, security breach, or data exposure related to QF APIs within 24 hours. Our security program also recognizes the QF Developer Privacy Policy Requirements' reference to “Security Rule 6.9.”
11. International processing
Our service providers may process information in the United States and other countries. Their privacy notices describe their international-transfer safeguards. We use providers for app functionality, reliability, security, and content delivery and expect them to handle data under their applicable contractual and legal obligations.
12. Children's privacy
Dhikr Reminders is not directed to children under 13 and is not designed to solicit personal information from children. The App has no account-registration system. If we learn that personal information from a child under 13 was submitted to our support channel without appropriate authorization, we will take reasonable steps to delete it. If you intend to use or distribute the App as a child-directed product, contact us first because additional privacy and Google Play Families requirements may apply.
13. Changes to this policy
We may update this Privacy Policy when the App, providers, or legal requirements change. The effective date at the top will be updated. Material changes may also be communicated in the App or its store listing when appropriate.
14. Contact
Privacy inquiries, access/correction requests, and deletion requests:
Dhikr Reminders
dhikrreminders.support@gmail.com