Back to home

Privacy Policy

Last updated: April 17, 2026 | Effective date: April 17, 2026

1. Data Controller

This app is developed and operated by Arda Coşkun. I act as the data controller within the scope of the Turkish Personal Data Protection Law No. 6698 ("KVKK") and the EU General Data Protection Regulation ("GDPR"). Contact: support@muridapp.com

2. Personal Data We Collect

The following categories of personal data are collected during your use of the App: a) Account Information Your email address and password (for email registration). If you sign in with Google, your Google account name, email address, and profile photo. For guest usage, only an anonymous user identifier is created. b) Chat Data Chat messages exchanged with the AI assistant and any attached images. Messages are stored in Google Firebase Firestore database; images are stored in Firebase Storage. c) Special Category Personal Data — Religious Belief Information Your madhab (school of Islamic jurisprudence) preference shared during onboarding is classified as special category (sensitive) personal data under KVKK Art. 6 and GDPR Art. 9. This data is processed only with your explicit consent and through a consent mechanism independent from other personal data. Your madhab preference is used to personalize AI responses according to your religious viewpoint. Sharing this information is entirely optional; if you choose not to share it, generic responses will be provided. d) User Profile Preferences Your age group, app goals, and interests shared during onboarding. This information is used to personalize AI responses. e) Location Data Your foreground location is processed only with your explicit permission for prayer time calculations, Qibla direction finding, and nearby mosque search. Location data is cached locally on your device. For nearby mosque searches, location data is sent to Google Places API; all other location operations are performed entirely on your device. f) Device Security Data Firebase App Check is used to verify that the App is running on a genuine device. On iOS, Apple DeviceCheck attestation signals are collected; on Android, Google Play Integrity signals are collected. This data is used solely for security verification purposes. g) Error and Performance Data In the event of app crashes or errors, technical error information (stack traces, session data, error messages) is collected via the Sentry error tracking service. This data is collected only in production with a sampling rate (20%). Personal data scrubbing is applied before sending to Sentry; no screenshots are captured. h) Subscription Information Your premium subscription status is managed through the RevenueCat service. Your Firebase user ID (UID) is shared with RevenueCat for cross-device subscription matching. i) Local Device Data (Not Sent to Any Server) Usage statistics (number of questions asked, verses viewed, chats created) are stored only on your device in AsyncStorage, automatically deleted after 8 weeks, and never sent to any server. Dhikr counter data, hatim tracking, saved verses, and prayer tracking are also stored on your device and can optionally be synced to Firebase. j) Notifications Prayer time notifications are scheduled locally on your device. Daily verse and weekly summary notifications are delivered via Firebase Cloud Messaging (FCM). To enable server-side delivery, your FCM device token and IANA timezone are stored in Firebase Firestore under your user profile. FCM tokens are removed from Firestore when you sign out. Note on Advertising: The free version of the App displays ads via Google AdMob. In this context, your device's advertising identifier (advertising ID / IDFA) and limited device information may be shared with Google. Users in the EU/UK are shown a GDPR consent form before any ads are served; on iOS, App Tracking Transparency (ATT) permission is requested for personalized ads. If you decline, only non-personalized ads are shown. Premium subscribers see no ads. Beyond this, the App does not use Facebook SDK or similar third-party tracking tools.

3. Processing of Special Category Personal Data

Your madhab preference is considered special category personal data in the "religious belief" category under KVKK Art. 6 and GDPR Art. 9. The processing of this data: • Is based solely on your explicit consent (KVKK Art. 6/2, GDPR Art. 9/2-a). • Is obtained through a separate consent mechanism independent from the consent given for processing your other personal data. • Is entirely optional; you may choose not to share this information. • Is used solely for personalizing AI responses according to your religious viewpoint. • Is not shared with any third party (the madhab preference is transmitted as an anonymous parameter in system instructions sent to the Gemini API, not transferred as direct personal data). You may withdraw your explicit consent at any time. In this case, your madhab preference will be deleted and AI responses will be provided in a generic format.

4. Purposes and Legal Bases for Processing

Your personal data is processed for the following purposes and legal bases: • Provision of App services (AI chat, prayer times, dhikr counter, Qibla finder, prayer collection) — Legal basis: Performance of contract (KVKK Art. 5/2-c, GDPR Art. 6/1-b) • AI personalization based on madhab preference — Legal basis: Explicit consent, via separate consent mechanism (KVKK Art. 6/2, GDPR Art. 9/2-a) [Special category data] • Personalization of AI responses (based on age group and interests) — Legal basis: Explicit consent (KVKK Art. 5/1, GDPR Art. 6/1-a) • Detection and resolution of technical issues (Sentry error tracking) — Legal basis: Legitimate interest (KVKK Art. 5/2-f, GDPR Art. 6/1-f). A Legitimate Interest Assessment (LIA) has been conducted for this processing under GDPR Art. 6/1-f; error tracking directly improves the user experience and does not create a disproportionate impact on user rights. • Ensuring App security (App Check, profanity filtering) — Legal basis: Legitimate interest. A Legitimate Interest Assessment has been conducted; security measures are proportionate and necessary for the protection of all users. • Subscription management and payment processing — Legal basis: Performance of contract • Compliance with legal obligations — Legal basis: Legal obligation (KVKK Art. 5/2-ç, GDPR Art. 6/1-c)

5. Profiling and Automated Decision-Making

The App performs profiling (GDPR Art. 4/4) using your profile information such as madhab preference, age group, and interests to personalize AI chat responses. This profiling: • Is used solely for adapting the content of AI responses. • Is not used for making automated decisions that produce legal effects or similarly significantly affect you. • The profanity filtering system performs automated analysis for inappropriate content detection. Repeated violations may result in account suspension; however, this decision is ultimately made with human intervention. Under GDPR Art. 22, no decisions based solely on automated processing that produce legal effects are made. Your right to object to profiling results is reserved.

6. Third-Party Service Providers

The following third-party service providers are used to deliver App services: • Google Firebase (Authentication, Firestore database, Storage, Cloud Functions, App Check) Status: Data processor Privacy policy: https://firebase.google.com/support/privacy • Google Generative AI — Gemini (AI chat responses) Status: Data processor Chat content is sent to the Gemini API via Firebase Cloud Functions; the App does not connect to Gemini directly. The API key is stored server-side as a Firebase Secret. Important notice: The App uses the paid tier of the Gemini API. Google does not use data submitted through the paid tier to train or improve its AI models; data may be retained only for a limited period for abuse and policy-violation monitoring. Active consent (opt-in) is obtained from the user before first use of the AI chat feature. Terms of service: https://ai.google.dev/gemini-api/terms • Google Places API (Location data for nearby mosque search) Status: Data processor Privacy policy: https://policies.google.com/privacy • RevenueCat (Subscription and in-app purchase management) Your Firebase user ID (UID) is shared with RevenueCat. RevenueCat acts as a data processor for service provision; however, it may also process aggregate data as an independent data controller for its own service improvement and analytics purposes. In this regard, RevenueCat's own privacy policy applies independently and is beyond our control. Privacy policy: https://www.revenuecat.com/privacy • Sentry (Error tracking and performance monitoring) Status: Data processor Sentry is a GDPR-compliant service offering a Data Processing Addendum (DPA). Personal data scrubbing tools are available. Privacy policy: https://sentry.io/privacy/

7. Data Sharing

Your personal data is not sold, rented, or shared for marketing purposes with third parties. Your data may only be shared: • With the service providers listed above, only to the extent necessary for service provision. • With competent public authorities when required by law. • In other cases where your explicit consent has been obtained.

8. International Data Transfers

Under Firebase, Google Cloud, and Sentry services, your personal data may be transferred to servers outside Turkey (USA, EU countries). These transfers are conducted: • For Google: Under the Google Cloud Data Processing Addendum and Standard Contractual Clauses (SCCs). • For Sentry: Under the Data Processing Addendum and SCCs. • For RevenueCat: Under the Data Processing Addendum. Adequate protection levels are ensured in accordance with KVKK Art. 9 and GDPR Art. 46.

9. Data Retention Periods

• Account information and chat data: Retained as long as your account is active. • After account deletion: All personal data is permanently deleted within 30 days. • Local usage statistics: Stored on your device for 8 weeks, then automatically deleted. • Sentry error data: Retained according to Sentry's data retention policy (default 90 days). • Gemini API data: On the paid API tier, Google does not use submitted data for model training or improvement; data may be retained only for the limited period specified in Google's policy for abuse monitoring. Data subject to legal retention obligations is retained for the period prescribed by applicable legislation.

10. Data Security Measures

The following technical and administrative measures are implemented to protect your personal data: • All data transmission is protected with TLS/SSL encryption. • Firebase's industry-standard security infrastructure (server-side encryption, security rules) is utilized. • The Gemini API key is stored server-side as a Firebase Secret and is never exposed in the client application. • Firebase App Check ensures only genuine applications can access APIs. • Personal data scrubbing is applied to data sent to Sentry. • Firebase Security Rules ensure users can only access their own data. No security measure can provide 100% guarantee. In the event of a data breach: • The relevant Supervisory Authority will be notified within 72 hours in accordance with GDPR Art. 33. • Individual users will be notified without undue delay for high-risk breaches in accordance with GDPR Art. 34. • The Personal Data Protection Board and affected individuals will be notified as soon as possible under KVKK.

11. Your Rights

Under KVKK Article 11 and the GDPR, you have the following rights: • Right to learn whether your personal data is being processed. • Right to request information about your processed data. • Right to learn the purpose of processing and whether data is used in accordance with its purpose. • Right to learn the third parties to whom your data is transferred domestically or abroad. • Right to request correction of incomplete or inaccurate data. • Right to request deletion or destruction of your data under KVKK Art. 7 / GDPR Art. 17. • Right to request notification of correction and deletion operations to third parties to whom data has been transferred. • Right to object to a result arising from the analysis of your data exclusively through automated systems. • Right to claim compensation for damages arising from unlawful processing of your data. • Right to data portability (GDPR Art. 20): You may request your data in a structured, commonly used, and machine-readable format (JSON). Your request will be fulfilled within 30 days. • Right to object to processing (GDPR Art. 21). • Right to request restriction of processing (GDPR Art. 18). • Right to object to automated decision-making including profiling (GDPR Art. 22). To exercise your rights: • In-app: Settings → Delete Account to delete your account and all associated data. • By email: Contact support@muridapp.com. • KVKK application: You may apply in writing with identity verification documents or via registered electronic mail (KEP) in accordance with the Communiqué on Application Procedures to the Data Controller. Guest (anonymous) users: Guest users who use the App without creating an account may exercise the above rights by contacting support@muridapp.com and providing their anonymous user ID. You can access your anonymous user ID via the App Settings. Your applications will be concluded within 30 days at the latest.

12. Children's Privacy

The App is not intended for children under 13 years of age. We do not knowingly collect personal data from users under 13. If we become aware that we have collected personal data from a child under 13, we will take immediate steps to delete such data. Users between 13 and 18 years of age must use the App with parental or legal guardian consent. The App relies on user self-declaration for age verification during account creation. A parent or legal guardian may request the deletion of their child's account or removal of their data by contacting support@muridapp.com. In the European Union, the age limit of 16 applies under GDPR Art. 8 (within the limit that member states may lower to 13). If you become aware of such a situation, please contact us at support@muridapp.com.

13. Policy Changes

This privacy policy may be updated from time to time. When significant changes are made: • We will notify you via an in-app notification. • The updated policy will be published on this page and the "Last updated" and "Effective date" will be revised. • For significant changes such as the processing of special category personal data or new data collection categories, explicit re-consent will be requested.

14. Contact

For questions, requests, or complaints about our privacy policy: • Email: support@muridapp.com Your right to apply to the Personal Data Protection Authority (kvkk.gov.tr) under KVKK is reserved. Your right to lodge a complaint with the relevant Data Protection Authority in the EU member state under GDPR is reserved.