Privacy Policy
This Privacy Policy explains how Istiqamah ("we", "us", or "our") handles information when you use Istiqamah: Quran & Salah (also called "Istiqamah" or the "App"). The App helps users build Islamic habits, prayer routines, Qur'an reading, reminders, family journeys, and related spiritual-growth routines.
Information You Provide
You may provide onboarding and app-use information such as your name, display name, goals, practice level, time commitment, habit completions, check-ins, reflections, reading progress, reminder settings, and family or child profile details if you choose to use family features.
Current app code stores this spiritual progress and settings data locally on your device. It is not uploaded to an Istiqamah backend in the current build.
Account and Sign-In Information
The App uses Clerk for authentication. If you sign in with Apple or Google, Clerk and the identity provider may process account information such as your email address, name or profile information made available by the provider, authentication identifiers, session information, and a Clerk user ID.
Apple and Google handle their sign-in flows under their own privacy policies.
Subscription and Purchase Information
Istiqamah uses Apple App Store payments and RevenueCat for subscriptions. Apple and RevenueCat may process the subscription product selected, purchase, renewal, trial, cancellation, refund, restore, entitlement status, App Store receipt, transaction information, and RevenueCat customer identifier. We use this information to load subscription products, complete purchases, Restore Purchases, and unlock Premium features.
Location Information
If you choose to enable location, Istiqamah requests foreground location access to calculate accurate prayer times, support Salah-related reminders, and calculate the Qibla direction. The app may store latitude, longitude, a readable location name, prayer calculation settings, and reminder preferences locally on your device.
The app does not declare background location access in the current build.
Camera and Photos
If you enable Salah Shield Prayer Mat Check, the App may request camera access so you can photograph your prayer mat as a confirmation step. The photo is analysed on your iPhone using an on-device Core ML image classification model. It is not uploaded or copied to your photo library and the temporary image is deleted when the check finishes or the screen is closed. If recognition is uncertain, you can retake the photo or confirm manually.
Microphone and Recitation Recordings
If you choose to record your Qur'an recitation, Istiqamah requests microphone access and keeps the recording temporarily on your iPhone for private listening. It is not added to your media library.
If you separately tap Analyze in Recitation Coach (Beta), the selected recording, requested ayah reference, and signed-in session are securely sent through Istiqamah's authenticated Cloudflare service to its serverless inference provider for that analysis. The raw recording is deleted automatically after processing and is not used to train the model. Istiqamah retains only a daily usage total needed to enforce the beta allowance, not the recording, transcript, or feedback history.
Recitation Coach provides fallible practice suggestions. It does not certify pronunciation, Tajweed, makhraj, faith, reward, or acceptance, and it does not replace guidance from a qualified Qur'an teacher.
Notifications and Live Activities
Istiqamah may request notification permission to send local reminders, such as prayer, adhkar, reflection, Qur'an, Sunnah, family, journey, or Focus Shield reminders. Notification schedules and preferences are stored locally on your device.
If remote Live Activities are enabled, the App sends your Clerk user ID, Apple ActivityKit push tokens, timezone, locale, app version, and derived prayer names and timestamps to Istiqamah's Cloudflare-hosted Live Activity service. The service does not receive your prayer-time latitude or longitude. It uses Apple Push Notification service (APNs) to start, update, and end relevant Live Activities.
Optional App Analytics
If you choose to allow app analytics, Istiqamah uses Firebase Analytics to measure a limited set of broad app and subscription-journey events. These include first opening the App, completing onboarding, viewing the paywall, starting checkout, and an App Store in-app purchase. This helps us understand whether the App and its subscription flow work as intended and helps measure App campaign performance.
When measuring campaigns that advertise the App, Google can use these consented events with Apple's privacy-preserving, aggregated SKAdNetwork attribution. We do not use this information for personalised advertising, remarketing audiences, or cross-app tracking.
Firebase assigns a pseudonymous app-instance identifier and may receive basic app and device information, such as app version, device model, operating-system version, and coarse geographic region derived by Google from a masked IP address. Istiqamah does not set your Clerk account identifier as a Firebase Analytics user ID, and this build does not include Apple's advertising identifier framework.
We do not send prayer completions, Qur'an passages or reading history, reflections, Screen Time selections, selected-app details, child or family profile data, or precise location to Firebase Analytics. Advertising storage, advertising user data, and advertising personalisation remain disabled. You can withdraw or grant analytics consent at any time in the App's Settings screen.
Salah Shield and Family Controls
If you enable App Shield, the App uses Apple's Family Controls, Managed Settings, and Device Activity frameworks. You select apps through Apple's private system picker. Istiqamah receives opaque selection tokens rather than the names of selected apps and does not receive your browsing history or app-usage history. The selection and prayer shield schedules are stored on your device and used by Apple system services to apply and remove the shields you configure.
Local Storage
Istiqamah stores app state locally on your device using local storage. This may include onboarding profile data, habit and worship-progress records, check-ins, reflections, family feature data, reminder preferences, Qur'an bookmarks, reading progress, Salah settings, and shield preferences.
The Straight Path
The Straight Path is a visual reflection of worship and habit actions you choose to record. Its settings, dated event history, and derived daily or weekly journey state are stored locally on your device. The current build retains up to approximately 400 days of this local event history and does not upload it to an Istiqamah backend.
Straight Path event records do not contain reflection text, child names, selected app names, Family Controls tokens, precise location, or authentication identifiers. The feature does not measure faith, guidance, reward, or acceptance.
Qur'an Content API
The app fetches Qur'an text, translations, and transliteration content from the public alquran.cloud API. Requests to that service may include the requested surah, ayah, edition, and normal network information such as IP address handled by the service provider.
When you choose to open an English tafsir, the app sends the requested ayah reference and your signed-in session token to Istiqamah's Cloudflare service. The service verifies that you are signed in and retrieves licensed tafsir content from Quran Foundation. Istiqamah does not send your Clerk user identity to Quran Foundation and does not store a history of the tafsir passages you request.
Data Sharing
We share information only as needed to provide app functionality:
- Clerk for authentication.
- Apple and Google for sign-in flows.
- Apple App Store and RevenueCat for subscriptions and entitlement management.
- Apple system services for location, notifications, camera, and StoreKit.
- Apple Family Controls and related Screen Time frameworks for app shielding you configure.
- Cloudflare and Apple APNs for remote Live Activity scheduling and delivery.
- alquran.cloud for public Qur'an content requests.
- Quran Foundation for licensed English tafsir content you choose to open.
- Cloudflare and our serverless inference provider for a temporary recording only when you tap Analyze in Recitation Coach.
- Google Firebase for the limited optional analytics events described above.
We do not sell personal information.
Data Retention
Local app data remains on your device until you clear it, reset the app, sign out using cleanup flows, or delete the app. Authentication and subscription records may be retained by Clerk, Apple, Google, and RevenueCat according to their policies and legal/accounting requirements. Remote Live Activity registration and schedule data may remain until it is refreshed, unregistered, or removed through operational cleanup. If enabled, analytics event retention is governed by our Firebase Analytics retention settings and Google's applicable terms. Raw Recitation Coach recordings are deleted after processing. The associated daily usage total is retained for operational quota and abuse prevention and is not a recitation history.
Account Deletion and Data Requests
In the app, Settings > Delete Account offers permanent account deletion when supported by the sign-in provider, explains that App Store subscriptions are managed separately in Apple subscription settings, and offers local device data cleanup.
To request deletion or access for account-related data processed through Istiqamah, contact [email protected].
Children's Privacy
Istiqamah includes family and child-profile features intended to be used by a parent or guardian. Child profile details entered in the app are stored locally in the current build.
Security
We use platform and third-party services designed to protect authentication, subscription, and app data. No method of storage or transmission is completely secure, so we cannot guarantee absolute security.
Changes To This Policy
We may update this Privacy Policy from time to time. The updated version will be posted at the Privacy Policy URL used by the App and App Store listing.
Contact
Istiqamah
Postal correspondence available on request via support email.
Contact: [email protected]