Privacy Policy
Holy Quran Daily
This policy explains how this application handles information and how to contact us about privacy.
Information we process
Holy Quran Daily does not require an account. The app stores reading position, bookmarks, favorite verses and duas, dhikr sessions, custom dhikr formulas, selected city and coordinates, language, text size, calculation method and reminder preferences on the device. If you allow location access, the app reads the device location while you use it to calculate prayer times and the Qibla bearing. City search and reverse geocoding use Apple's geocoding service. The app sends bookmarks, reading position and dhikr sessions to our API with a random installation secret; it does not send your location or city to our API. Our server stores a SHA-256 hash of the secret as the installation identifier, not the secret itself. HTTPS requests also expose ordinary network information such as IP address and request metadata to Railway infrastructure and the service. Quran and dua text is bundled in the app.
How we use information
Device data supports offline reading, saved places in the Quran, favorites, prayer calculations, dhikr counting, calendar dates, settings and local reminders. The API synchronizes bookmarks, reading position and dhikr session history for this installation and resumes after an offline period. Network request metadata is used to operate and troubleshoot the service. We do not use the data for advertising or analytics.
Service providers and sharing
Railway hosts the same service that serves the API and this policy, and its PostgreSQL service holds synchronized records. Railway infrastructure processes network requests and may generate infrastructure logs. Apple processes geocoding requests when you search for a city or reverse geocode a permitted location, and iOS handles local notifications and device backups according to your Apple settings. When you explicitly use Copy or Share, the selected text goes to the device pasteboard or the destination you choose through the iOS share sheet. There is no account provider, analytics SDK, advertising SDK, email delivery service or sale of personal data. We do not share synchronized records with other app installations.
Data retention
Local records remain until you delete them in the app or remove the app, subject to any device backups controlled by your Apple settings. Server records remain while the installation secret is available for synchronization; the in-app Delete All Data action deletes that installation's active server records when a connection is available and queues the request while offline. We do not assert a fixed retention period for Railway infrastructure logs or backups because their lifecycle is controlled by the hosting provider. Deletion from provider backups, where present, follows that provider's backup lifecycle and may not be immediate.
Deleting your information
In Settings, choose Delete All Data and confirm. The app immediately clears local reading, favorite, dhikr, city and preference data, removes pending local reminders, and sends an authenticated deletion request for synchronized records. If offline, it keeps the installation secret only long enough to retry that deletion when the connection returns, then removes it. Removing the app before a queued deletion reaches the server may leave server records inaccessible because the secret can no longer be recovered. For help with a deletion request, contact osric.sterlingham@icloud.com; without the installation secret we may be unable to identify a particular record set.
Permissions and your choices
Location permission is optional and requested only when you choose Use My Location. You can deny or withdraw it in iOS Settings and enter a city instead. Notification permission is optional and requested when you enable local prayer or calendar reminders. You can disable reminders in the app or iOS Settings. The app does not request camera, contacts, microphone or photo-library access.
Your privacy rights
You can read, update and delete local practice data in the app, turn permissions off, and request information or assistance at osric.sterlingham@icloud.com. Your ability to identify server records depends on retaining your installation secret; there is no account or recovery process. Applicable privacy rights vary by location, and we will respond to requests using the information we can verify without exposing another installation's records.
Security
The app generates a random installation secret and stores it in the device Keychain with device-only protection. API requests use HTTPS. The server authorizes every private request using the secret and stores only its SHA-256 hash as the owner key in PostgreSQL; one installation cannot read another installation's records through the API. We limit request size and validate inputs. No system can guarantee absolute security, and the secret should not be shared.
Children’s privacy
The app provides Quran reading and Islamic practice content for a general audience and is not directed specifically to children under 13. It has no account, advertising or social features. If a child uses the app, the same device and server processing described here applies. A parent or guardian may use in-app deletion or contact osric.sterlingham@icloud.com.
Changes to this policy
We may update this policy when the app, backend or hosting practices change. The effective date above will change when a new version is published. The current policy is available at /privacy on the product website. For questions, contact osric.sterlingham@icloud.com.