In one paragraph
myQt is an app for reading and organising Khatam al-Qur'an together. We collect only what the app needs to do its job — your email to sign in, your Juz claims, your reading progress. We don't track you across the internet, we don't sell anything, and we don't have ads or third-party analytics. You can ask for a copy of everything we know about you, or ask us to delete it, directly from the app.
Who we are
myQt is operated by saMas IT Services, located at 1296 Glacier Dr, Milpitas, CA 95035, United States. Syed Ali Bilgrami is the responsible developer and primary contact for privacy matters. For the purposes of the GDPR / UK GDPR, saMas IT Services is the data controller. There is no separately appointed Data Protection Officer; the listed developer fulfils that contact role directly.
You can reach the team for any privacy request via our
contact form. Our backend runs in the United States
on Fly.io (specifically: iad/sjc/fra
edge regions); our mobile app ships via Expo / EAS.
International transfers. If you're in the EU, EEA, UK, or Switzerland, your data is transferred to the United States to be hosted by Fly.io, Inc. and routed through Expo Inc.'s push and OTA infrastructure. We rely on the EU Standard Contractual Clauses (Module 2: controller-to-processor) and, where applicable, the UK International Data Transfer Addendum, included in the data-processing terms of those vendors. The transfer is necessary for performance of the contract you accept by using the app (Art. 49(1)(b) GDPR). You can ask us to delete your data at any time.
What we collect, and why
| What | Why (legal basis) | Source |
|---|---|---|
| Email + password (hashed) | To sign you in (contract) | You, at sign-up |
| Your name | To show who's reading which Juz (contract) | You, at sign-up |
| Khatam title, location, dates, description, organiser email/name, link code | To run the Khatam (contract) | You or the Khatam organiser |
| Juz assignments (who claimed what, when completed) | Core feature — the board (contract) | Your actions in the app |
| Verses read, last-read position | Sync your progress across devices (contract) | Your actions while reading |
| Reading-history timeline (each time you resume reading: surah, ayah, juz, timestamp) | Power the "Where you left off" home card + reading-history screen so you can return to the exact verse (contract). Subject to your personal-reading consent toggle. | Recorded automatically when you scroll the reader; you can wipe it with Delete my data. |
| Bookmarks + notes | Save verses you want to return to (contract) | You, via long-press |
| Profile: nickname, bio, gender, location, avatar emoji | Public profile (consent — you opt in by filling it) | You, via Profile Settings |
| Online presence (last-seen timestamp) | Show "N online" to people who can see you (legitimate interest) | App heartbeat while open |
| Messages between organiser and participants | Coordinate the Khatam (contract) | Organiser, via the Send sheet |
| Activity log (claim / complete / release / join actions) | Real-time activity feed (contract) | Your actions in the app |
| Push notification token, platform, app version | Send you event-related pushes (consent — at first push permission) | Expo, if you allow push |
| Crash reports (stack trace, app version, platform, optional email) | Fix bugs (legitimate interest) | App, automatically on crash |
| Feedback reports you submit via 🐞 Report an issue | Respond to your feedback (legitimate interest) | You, via the form |
| Salat tracker (which prayers you logged, on what date, and how) | Track your personal prayer habits (consent — you opt in by enabling the tracker) | You, via the Salat screen |
| Search history (Quran queries) | Show recent searches for quick re-use (contract) | You, via the search bar |
| Shared verses (surah, ayah, optional note) | Keep a history of verses you've shared (contract) | You, via the share sheet |
| Qibla Finder usage (timestamp only — no GPS coordinates) | Award the Qibla Finder profile badge (legitimate interest) | App, when you open Qibla Finder |
| Personal reading plans (target days, start date) | Help you finish a Khatam on your chosen schedule (contract) | You, via the reading plan screen |
| Event posts (text you write on an event's wall) | Let participants communicate within a Khatam (contract) | You, via the event feed |
| Global Pulse consent + anonymous activity feed | Show aggregate activity to inspire others around the world (consent — separate opt-in) | You, via Profile Settings |
What we do and don't collect
- We do include Firebase Analytics in the mobile app, but it is gated by your explicit consent. The native SDK boots disabled and only activates if you opt in via the analytics consent prompt or Settings → Privacy → Analytics. We don't include Mixpanel, Amplitude, Sentry, or any other analytics or crash-reporting SDK in the mobile app.
- If you opt in to analytics, the data Firebase collects (anonymous app-usage events, screen views, install attribution) is processed by Google in the United States. You can revoke this opt-in at any time from Settings → Privacy → Analytics, and the SDK stops collection within seconds.
- We don't have advertising or ad-network identifiers.
- We don't scan your contacts, photos, microphone, or location GPS.
- We don't share what verses you read with other users, organisers, or advertisers — your reading history is yours alone, and we never sell it.
- We don't use cookies on the mobile app. The admin site (internal use only) uses standard Django session cookies.
Who else sees your data
We use a small number of third parties strictly to run the service:
| Service | What they see | Why |
|---|---|---|
| Fly.io (US) | Everything on the backend (they host the database) | Application hosting |
| Expo / EAS | Your push token + platform + app version. Which OTA update your phone downloaded. | Push delivery + over-the-air updates |
| quran.com, alquran.cloud | Only that someone asked for Juz N. Your identity is never sent. | Translation + recitation proxy (we pre-bundle Tier 1) |
| NASA APOD | Only that someone opened About myQt that day. Anonymous. | Daily inspiration image on the About screen |
We do not share, sell, or rent your data to advertisers, data brokers, or any other third party.
Your rights — and how to exercise them
Under the GDPR (EU / EEA / UK) you have the rights below. They are available to everyone else too.
-
Access + portability — get a copy of everything we hold about you. Open the app → Profile Settings → Export my data. Or call
GET /api/privacy/me/with your auth token (add?download=1for an attachment-style download).
Once you tap Export my data, the app shows you a confirmation reminding you the file contains personal data. After you close the share sheet, the temporary copy in the app's private cache is deleted immediately — only the destination you chose (Files, Mail, a chat app, etc.) holds the data after that. You control where it goes; we generate no shareable URL — the export is a file, not a magic link anyone can re-fetch. - Erasure (right to be forgotten) — ask us to delete your account. Open the app → Profile Settings → Delete my data. Or call
DELETE /api/privacy/me/with your auth token. We scrub PII across every table within 30 days — usually within minutes. - Rectification — update anything that's wrong via the in-app settings screens. For things you can't edit (e.g. an old event description), email us.
- Restrict or object — you can mute all organiser nudges (Settings → Notifications → Mute), turn off auto-mark-as-read, or disable push notifications from your OS settings. Email us for anything else.
- Withdraw consent — any setting you opted into (profile, push, ambient sound) can be switched off in the app. For religious-data consents (Art. 9(2)(a) GDPR), use Settings → Privacy → Religious Data — each purpose can be withdrawn individually, and withdrawing also deletes the corresponding stored data.
- Khatam participation — special note. Joining a Khatam is the core function of myQt and processes information about your religious practice. We rely on your explicit consent for this processing under European law (Art. 9(2)(a) GDPR). Because removing your participation from a live event would disrupt other users who are reading alongside you, you can only withdraw this specific consent by deleting your account. Other religious-data consents (prayer logging, bookmarks, search history, learning module, personal reading) can be withdrawn individually from Settings at any time. (See Art. 7(3): withdrawal of consent must be as easy as giving it; the regulation permits this withdrawal-via-erasure path provided the constraint is disclosed at consent capture, which we do here and on the Religious Data settings screen.)
- Complain to a regulator — if we haven't helped, you can contact your local data protection authority.
How long we keep things
| Data | Kept for |
|---|---|
| Account (email, name, password hash) | Until you delete it |
| Events you organise | Until you delete them, or 1 year after end_date |
| Juz assignments, verse progress, bookmarks | Tied to the event / user — removed with them |
| Activity feed | 90 days after an event ends, then purged |
| Crash reports | 90 days |
| Feedback reports | Up to 2 years (so we can spot abuse patterns) |
| Organiser messages (including soft-deleted ones) | Retained for moderation audit — scrubbed of sender/target email on user deletion |
| Push notification tokens | Until you disable push or delete your account |
| Salat tracker logs | Until you delete your account |
| Search history | Until you delete your account (capped at 50 recent queries) |
| Shared verses | Until you delete your account |
| Qibla Finder usage | 90 days |
| Personal reading plans | Until you delete your account |
| Event posts | Until the event is deleted, or 1 year after end_date |
| Global Pulse anonymous activity | 48 hours, then permanently deleted |
When you delete your account, the scrub is immediate: we replace your email and name with an anonymous placeholder in any table we can't erase outright (because others rely on the row's existence), and we delete the rest.
Children + age limits
myQt is intended for users 13 and over (US — COPPA), and 16 and over in the EU/EEA where the GDPR member state has set the digital-consent age at 16. The app is rated 4+ on the Apple App Store and Everyone on Google Play; despite the rating, we do not knowingly market to or accept sign-ups from children below the applicable consent age.
If you believe a child has signed up, contact us via our contact form (mark "child account" in the subject line so we route it correctly). We'll delete the account and all associated data within 7 days and confirm to the parent / guardian. You can also use the in-app erasure flow yourself (Profile Settings → Delete my data).
We comply with the UK Age-Appropriate Design Code (Children's Code) defaults: no profiling, no nudge tactics, no behavioural advertising, no geolocation by default, and no public-by-default profile fields.
App Store privacy nutrition
Apple's App Store requires every app to declare its data practices in a structured form. For myQt:
| Category | Linked to identity | Used for tracking |
|---|---|---|
| Contact Info — Email Address | Yes | No |
| User Content — Other (your bookmarks, notes, dedications) | Yes | No |
| Identifiers — User ID (your account email) | Yes | No |
| Usage Data — Product Interaction (Juz claims, completions, reading progress, prayer logs, search queries, Qibla opens) | Yes | No |
| Diagnostics — Crash Data | No | No |
We do not use any data to track you across other companies' apps or websites, and we don't share data with data brokers, advertising networks, or analytics SDKs.
Google Play Data Safety
The Play Console requires the same disclosures in Google's vocabulary. For myQt:
- Data collected: Email address, Name, App interactions (your reading + Juz actions, prayer logs, search queries, Qibla opens), App content (bookmarks, notes, dedication text, event posts), Crash logs, Diagnostics.
- Data shared with third parties: none for advertising or analytics. Operational sharing (hosting on Fly.io, push delivery via Expo) is limited to running the service.
- Encryption in transit: yes (HTTPS / WSS).
- Can users request data be deleted: yes — in-app (Profile Settings → Delete my data) and via email.
- Account deletion URL:
https://link.myqt.app/privacy/(this page) — see Your rights above.
AI-generated decorative art
The "Daily Ornament" feature shows decorative geometric / arabesque / tile-pattern images that are generated by an AI image model from a human-written prompt. The images are ornamental only — they are not Quran scripture, not calligraphy, and not a depiction of any prophet, person, animal, or religious symbol.
Every generation is filtered before it reaches you:
- The prompt explicitly excludes humans, animals, faces, text, calligraphy, religious symbols, and references to the Quran or any holy book.
- Each generated image is automatically scanned for stray text (OCR) and faces (face detection); anything that fails is rejected from the pool, never shown.
- You can report any image you find inappropriate via the flag icon on the screen. Three independent reports auto-hide the image while we review it.
- The selection rotates daily; we keep a curated pool and don't repeat a piece within 30 days unless the pool runs thin.
We do not claim any artistic merit or originality for AI-generated content. It exists as a contemplative visual texture alongside your reading, nothing more. We don't share your prompts, reading data, or any personal information with the AI provider — prompts are pre-written templates we control, never user input.
Security
- All network traffic to and from the app is over HTTPS / WSS.
- Passwords are stored hashed (Django's default PBKDF2, never plaintext).
- Auth tokens are stored on-device in the platform's secure async storage.
- The backend uses standard Django defaults for CSRF, XSS, clickjacking, and secure cookies in production.
Changes to this policy
If we change what we collect or how we use it, we'll update this page and bump the "Effective" date at the top. Material changes will also show up as an announcement banner in the app.
Contact
For any privacy request — access, deletion, rectification, complaint, or just a question — use our contact form or the 🐞 Report an issue flow in the app (hamburger menu).
Global Pulse
With your explicit consent, we anonymously share your in-app activity in a global feed visible to all app users. This is entirely separate from analytics and can be enabled or disabled at any time in Profile Settings.
We share only:
- The action type (e.g., "completed Juz 2", "logged Fajr")
- Your coarse country (inferred from device timezone, not GPS)
- A rounded timestamp (nearest 5 minutes)
We never share your name, email, profile photo, precise location, or any content you created (notes, bookmarks, etc.).
Data is retained for 48 hours and then automatically permanently deleted. You can export your Global Pulse history at any time via "Export my data" in Profile Settings. If you revoke consent, your future actions are no longer shared, and your existing history is immediately deleted.