Quran Tutor app icon
Privacy policy

Privacy Policy

There is no account and no sign-in. What you learn stays on your phone. Here is the little that leaves it, and why.

Effective September 7, 2026
📵

No account

Nothing to sign up for, so there is no login, password or profile anywhere.

📱

Learning stays on the phone

Your name, age, progress, what you read, your recordings and your location never leave your device.

🔘

Anonymous, and optional

Usage statistics carry no identity, and one switch in Settings turns them off.

This policy explains how Quran Tutor (“the app”) handles information. The app is made and published by Syed Haider, an independent developer in Dubai, United Arab Emirates (“we”, “us”). If anything here is unclear, write to hello@syedhaider.dev and we will explain it in plain words.

1. What stays on your phone

Most of what the app knows about you is stored only on your device, in the app's own storage. It is never uploaded, and it is removed when you delete the app.

  • What you told us when you started — your first name, age, gender and how much time you want to spend each day. These are used to address you and to pitch the course; nothing else.
  • Your learning — lessons passed, what the review system remembers about each letter, the ayahs you have marked as read, your daily steps and streaks, and your reading settings.
  • Recordings of yourself — when you use the microphone to read a line back, the recording is kept on your phone so you can hear it beside the teacher's voice. It is not analysed by us, not sent anywhere, and you can record over it or delete the app to remove it.
  • Your location — used to work out prayer times and the direction of the qibla, and, if you keep prayer reminders on, to schedule those reminders. The last position is kept on the device between runs so the times are there when you open the app. It is never transmitted — not to our server, not to a map or geocoding service, not in usage statistics. The app does not even turn it into a place name.
  • Reminders — prayer-time notifications and a nudge after a few days away are scheduled by the app on your phone itself. No push service and no server is involved, and both can be switched off in Settings → Reminders.
  • Story videos you create from an ayah are rendered on your phone and saved only where you choose to save or share them.

2. What the app sends to our server

The app talks to a server we run on Google Cloud in Belgium (europe-west1). Four kinds of request go there.

2.1 Content: recitation audio, timings, translations and lessons

Recitation audio, the word timings that light each word as it is read, translations and the course itself are fetched from our server as you use them. Like any web server, it keeps standard request logs — the IP address the request came from, the time and the file requested. These logs are held by Google Cloud for up to 30 days and are used only to keep the service running and to investigate problems.

2.2 Anonymous usage statistics

To see which parts of the app are used and where people get stuck, the app reports events such as “surah opened”, “recitation started”, “lesson completed” or “story created”. Each event carries its name, the time, and a few small values: which reciter was chosen, which lesson number was finished and whether its check was passed, which backdrop a story used, whether a permission prompt was accepted, which subscription plan was bought. With each batch the app also sends its version, the iOS version, the device model (for example “iPhone14,2”) and the language setting. No event says which surah or ayah you opened, played, marked or shared — what you read stays on your device.

  • Events are grouped under a random session id that is created fresh every time the app is opened. It is not stored across launches, and it is not derived from you or your device, so sessions cannot be tied together or to a person.
  • Your name, age, gender, reading history, recordings and location are never included.
  • You can switch this off at any time in Settings → Privacy → Share anonymous usage. Anything not yet sent is discarded.
  • Sessions are deleted from our database 365 days after their last event.

2.3 Messages you send us

The “Talk to us” box at the bottom of the Home screen sends us exactly what you type, plus — if you choose to fill it in — how we can reach you back (an email address, phone number or similar). The app attaches its version and the current session id so we can see what happened around the time you wrote. This is the only place in the app where you can give us something that identifies you, and you never have to.

  • We use it to answer you and to fix what you reported. Nothing else.
  • Messages are deleted 365 days after we receive them, or sooner if you ask (see section 8).
  • The contact detail you typed is remembered on your phone only, so you don't have to type it again.

2.4 Settings

On launch the app fetches a small settings file (for example, when it is allowed to ask for an App Store review). That request carries nothing about you beyond the request log described above.

3. Purchases

Subscriptions are sold through Apple's App Store and billed to your Apple ID. We never see your name, email address or payment details — Apple keeps those under its own privacy policy.

To know whether a subscription is active we use RevenueCat, a purchase-management service. When the app starts and when you buy or restore, RevenueCat receives a random identifier the app generates for your install, the App Store transaction information (product, dates, price and currency), and the device type, iOS version, app version and language. It does not receive your name or email. RevenueCat is based in the United States and handles this under its privacy policy.

4. Advertising measurement

We advertise the app on Meta's platforms (Facebook and Instagram), and we need to know whether those adverts work. The app includes Meta's SDK for that single purpose. It reports these events to Meta: that the app was installed and opened, that onboarding was completed, that a first lesson was completed, that a story was created, and that a subscription or free trial was started (which plan, the amount and the currency). Along with each event Meta receives the usual device details — model, iOS version, language, time zone, app version.

  • If you allow tracking when iOS asks, the events also carry your device's advertising identifier (IDFA), which lets Meta match your install to the advert you tapped.
  • If you don't allow it, no identifier is sent. Apple's SKAdNetwork tells us an advert led to an install without saying who installed, and that is all we get.
  • You can change your answer at any time in iOS Settings → Privacy & Security → Tracking.
  • If you told the app you are under 13, it never asks for tracking permission, and so never has an advertising identifier to send.
  • Nothing you read, record or write in the app is ever shared with Meta.

Meta processes this under its own privacy policy. We do not show adverts inside the app.

5. Permissions the app may ask for

PermissionWhyWhere the data goes
MicrophoneRecord yourself reading a line, to play back beside the teacher's voice.Stays on your phone.
Location (while using)Prayer times, qibla direction and prayer reminders.Stays on your phone — never sent to a server or a map service.
Photos (add only)Save an ayah video you made to your Photos library, if you choose to.Your own Photos library.
NotificationsPrayer-time reminders and a nudge after a few days away, scheduled on the phone.Stays on your phone.
TrackingAdvert measurement, as in section 4.Meta, only if you allow it.
Local networkOnly for developers streaming audio from a server on their own computer.Your own network.

Every one of these can be refused, and the app keeps working without it.

6. Children

Learning to read Quran often starts young, and the app can be used by a child with a parent's help. The app does not ask children for anything personal: a name and age stay on the device, there is no account, no chat, nothing a child writes is shown to other users, and there are no adverts in the app. When a learner gives an age under 13, the app never shows the tracking prompt. We do not knowingly collect personal information from children under 13; if you believe a child has sent us something through the “Talk to us” box, tell us at hello@syedhaider.dev and we will delete it.

7. Where information is kept, and for how long

WhatWhereKept for
Everything in section 1Your phone onlyUntil you delete the app or reset it in Settings
Server request logsGoogle Cloud, BelgiumUp to 30 days
Anonymous usage sessionsGoogle Cloud Firestore, Belgium365 days after the last event
Messages you send usGoogle Cloud Firestore, Belgium365 days, or until you ask
Purchase statusRevenueCat, United StatesPer RevenueCat's policy
Advert eventsMeta, United StatesPer Meta's policy

Where information travels outside the country you are in — to Google in the European Union, or to RevenueCat and Meta in the United States — it does so under those providers' standard contractual safeguards.

8. Your choices and rights

  • Turn usage statistics off: Settings → Privacy → Share anonymous usage.
  • Withdraw tracking permission: iOS Settings → Privacy & Security → Tracking.
  • Erase what is on the phone: Settings → Progress → Start the course again, or delete the app.
  • Delete a message you sent us: email hello@syedhaider.dev from the address you gave, or quote the message, and we will delete it within 30 days.
  • Ask what we hold: the honest answer for almost everyone is “nothing that identifies you”, because usage sessions carry no identity. If you sent us a message, we can send you a copy or delete it.

Depending on where you live (for example the EU/EEA, the United Kingdom, or California) the law gives you rights of access, correction, deletion, portability and objection, and the right to complain to a supervisory authority. Write to us and we will respond within 30 days. We do not sell personal information and never have.

Where a legal basis is needed: purchases are processed to perform our contract with you; anonymous usage statistics and advert measurement without an identifier rest on our legitimate interest in running and improving the app, which you can object to with the switches above; anything involving the advertising identifier happens only with your consent.

9. Security

Every connection the app makes uses HTTPS. Our server and database are on Google Cloud with access limited to the developer, and the dashboard where messages are read is password-protected. No system is perfect, but we hold as little as possible so there is little to lose.

10. Changes to this policy

If we change how the app handles information we will update this page and its effective date. For a change that matters — anything new leaving your phone — the app will tell you before it happens.

11. Contact

Syed Haider · Dubai, United Arab Emirates
hello@syedhaider.dev

About the app · Support · Privacy policy · Terms of use · Delete your data