myQt · My Quran Tracker

Privacy Policy

Plain-language. No tracking. No ads.

Effective 2026-05-10 · policy v1.1 · backend v0.20.5

In one paragraph

myQt is an app for reading and organising Khatam al-Qur'an together. We collect only what the app needs to do its job — your email to sign in, your Juz claims, your reading progress. We don't track you across the internet, we don't sell anything, and we don't have ads or third-party analytics. You can ask for a copy of everything we know about you, or ask us to delete it, directly from the app.

Who we are

myQt is operated by saMas IT Services, located at 1296 Glacier Dr, Milpitas, CA 95035, United States. Syed Ali Bilgrami is the responsible developer and primary contact for privacy matters. For the purposes of the GDPR / UK GDPR, saMas IT Services is the data controller. There is no separately appointed Data Protection Officer; the listed developer fulfils that contact role directly.

You can reach the team for any privacy request via our contact form. Our backend runs in the United States on Fly.io (specifically: iad/sjc/fra edge regions); our mobile app ships via Expo / EAS.

International transfers. If you're in the EU, EEA, UK, or Switzerland, your data is transferred to the United States to be hosted by Fly.io, Inc. and routed through Expo Inc.'s push and OTA infrastructure. We rely on the EU Standard Contractual Clauses (Module 2: controller-to-processor) and, where applicable, the UK International Data Transfer Addendum, included in the data-processing terms of those vendors. The transfer is necessary for performance of the contract you accept by using the app (Art. 49(1)(b) GDPR). You can ask us to delete your data at any time.

What we collect, and why

WhatWhy (legal basis)Source
Email + password (hashed) To sign you in (contract) You, at sign-up
Your name To show who's reading which Juz (contract) You, at sign-up
Khatam title, location, dates, description, organiser email/name, link code To run the Khatam (contract) You or the Khatam organiser
Juz assignments (who claimed what, when completed) Core feature — the board (contract) Your actions in the app
Verses read, last-read position Sync your progress across devices (contract) Your actions while reading
Reading-history timeline (each time you resume reading: surah, ayah, juz, timestamp) Power the "Where you left off" home card + reading-history screen so you can return to the exact verse (contract). Subject to your personal-reading consent toggle. Recorded automatically when you scroll the reader; you can wipe it with Delete my data.
Bookmarks + notes Save verses you want to return to (contract) You, via long-press
Profile: nickname, bio, gender, location, avatar emoji Public profile (consent — you opt in by filling it) You, via Profile Settings
Online presence (last-seen timestamp) Show "N online" to people who can see you (legitimate interest) App heartbeat while open
Messages between organiser and participants Coordinate the Khatam (contract) Organiser, via the Send sheet
Activity log (claim / complete / release / join actions) Real-time activity feed (contract) Your actions in the app
Push notification token, platform, app version Send you event-related pushes (consent — at first push permission) Expo, if you allow push
Crash reports (stack trace, app version, platform, optional email) Fix bugs (legitimate interest) App, automatically on crash
Feedback reports you submit via 🐞 Report an issue Respond to your feedback (legitimate interest) You, via the form
Salat tracker (which prayers you logged, on what date, and how) Track your personal prayer habits (consent — you opt in by enabling the tracker) You, via the Salat screen
Search history (Quran queries) Show recent searches for quick re-use (contract) You, via the search bar
Shared verses (surah, ayah, optional note) Keep a history of verses you've shared (contract) You, via the share sheet
Qibla Finder usage (timestamp only — no GPS coordinates) Award the Qibla Finder profile badge (legitimate interest) App, when you open Qibla Finder
Personal reading plans (target days, start date) Help you finish a Khatam on your chosen schedule (contract) You, via the reading plan screen
Event posts (text you write on an event's wall) Let participants communicate within a Khatam (contract) You, via the event feed
Global Pulse consent + anonymous activity feed Show aggregate activity to inspire others around the world (consent — separate opt-in) You, via Profile Settings

What we do and don't collect

  • We do include Firebase Analytics in the mobile app, but it is gated by your explicit consent. The native SDK boots disabled and only activates if you opt in via the analytics consent prompt or Settings → Privacy → Analytics. We don't include Mixpanel, Amplitude, Sentry, or any other analytics or crash-reporting SDK in the mobile app.
  • If you opt in to analytics, the data Firebase collects (anonymous app-usage events, screen views, install attribution) is processed by Google in the United States. You can revoke this opt-in at any time from Settings → Privacy → Analytics, and the SDK stops collection within seconds.
  • We don't have advertising or ad-network identifiers.
  • We don't scan your contacts, photos, microphone, or location GPS.
  • We don't share what verses you read with other users, organisers, or advertisers — your reading history is yours alone, and we never sell it.
  • We don't use cookies on the mobile app. The admin site (internal use only) uses standard Django session cookies.

Who else sees your data

We use a small number of third parties strictly to run the service:

ServiceWhat they seeWhy
Fly.io (US) Everything on the backend (they host the database) Application hosting
Expo / EAS Your push token + platform + app version. Which OTA update your phone downloaded. Push delivery + over-the-air updates
quran.com, alquran.cloud Only that someone asked for Juz N. Your identity is never sent. Translation + recitation proxy (we pre-bundle Tier 1)
NASA APOD Only that someone opened About myQt that day. Anonymous. Daily inspiration image on the About screen

We do not share, sell, or rent your data to advertisers, data brokers, or any other third party.

Your rights — and how to exercise them

Under the GDPR (EU / EEA / UK) you have the rights below. They are available to everyone else too.

  • Access + portability — get a copy of everything we hold about you. Open the app → Profile Settings → Export my data. Or call GET /api/privacy/me/ with your auth token (add ?download=1 for an attachment-style download).
    Once you tap Export my data, the app shows you a confirmation reminding you the file contains personal data. After you close the share sheet, the temporary copy in the app's private cache is deleted immediately — only the destination you chose (Files, Mail, a chat app, etc.) holds the data after that. You control where it goes; we generate no shareable URL — the export is a file, not a magic link anyone can re-fetch.
  • Erasure (right to be forgotten) — ask us to delete your account. Open the app → Profile Settings → Delete my data. Or call DELETE /api/privacy/me/ with your auth token. We scrub PII across every table within 30 days — usually within minutes.
  • Rectification — update anything that's wrong via the in-app settings screens. For things you can't edit (e.g. an old event description), email us.
  • Restrict or object — you can mute all organiser nudges (Settings → Notifications → Mute), turn off auto-mark-as-read, or disable push notifications from your OS settings. Email us for anything else.
  • Withdraw consent — any setting you opted into (profile, push, ambient sound) can be switched off in the app. For religious-data consents (Art. 9(2)(a) GDPR), use Settings → Privacy → Religious Data — each purpose can be withdrawn individually, and withdrawing also deletes the corresponding stored data.
  • Khatam participation — special note. Joining a Khatam is the core function of myQt and processes information about your religious practice. We rely on your explicit consent for this processing under European law (Art. 9(2)(a) GDPR). Because removing your participation from a live event would disrupt other users who are reading alongside you, you can only withdraw this specific consent by deleting your account. Other religious-data consents (prayer logging, bookmarks, search history, learning module, personal reading) can be withdrawn individually from Settings at any time. (See Art. 7(3): withdrawal of consent must be as easy as giving it; the regulation permits this withdrawal-via-erasure path provided the constraint is disclosed at consent capture, which we do here and on the Religious Data settings screen.)
  • Complain to a regulator — if we haven't helped, you can contact your local data protection authority.

How long we keep things

DataKept for
Account (email, name, password hash)Until you delete it
Events you organiseUntil you delete them, or 1 year after end_date
Juz assignments, verse progress, bookmarksTied to the event / user — removed with them
Activity feed90 days after an event ends, then purged
Crash reports90 days
Feedback reportsUp to 2 years (so we can spot abuse patterns)
Organiser messages (including soft-deleted ones)Retained for moderation audit — scrubbed of sender/target email on user deletion
Push notification tokensUntil you disable push or delete your account
Salat tracker logsUntil you delete your account
Search historyUntil you delete your account (capped at 50 recent queries)
Shared versesUntil you delete your account
Qibla Finder usage90 days
Personal reading plansUntil you delete your account
Event postsUntil the event is deleted, or 1 year after end_date
Global Pulse anonymous activity48 hours, then permanently deleted

When you delete your account, the scrub is immediate: we replace your email and name with an anonymous placeholder in any table we can't erase outright (because others rely on the row's existence), and we delete the rest.

Children + age limits

myQt is intended for users 13 and over (US — COPPA), and 16 and over in the EU/EEA where the GDPR member state has set the digital-consent age at 16. The app is rated 4+ on the Apple App Store and Everyone on Google Play; despite the rating, we do not knowingly market to or accept sign-ups from children below the applicable consent age.

If you believe a child has signed up, contact us via our contact form (mark "child account" in the subject line so we route it correctly). We'll delete the account and all associated data within 7 days and confirm to the parent / guardian. You can also use the in-app erasure flow yourself (Profile Settings → Delete my data).

We comply with the UK Age-Appropriate Design Code (Children's Code) defaults: no profiling, no nudge tactics, no behavioural advertising, no geolocation by default, and no public-by-default profile fields.

App Store privacy nutrition

Apple's App Store requires every app to declare its data practices in a structured form. For myQt:

CategoryLinked to identityUsed for tracking
Contact Info — Email AddressYesNo
User Content — Other (your bookmarks, notes, dedications)YesNo
Identifiers — User ID (your account email)YesNo
Usage Data — Product Interaction (Juz claims, completions, reading progress, prayer logs, search queries, Qibla opens)YesNo
Diagnostics — Crash DataNoNo

We do not use any data to track you across other companies' apps or websites, and we don't share data with data brokers, advertising networks, or analytics SDKs.

Google Play Data Safety

The Play Console requires the same disclosures in Google's vocabulary. For myQt:

  • Data collected: Email address, Name, App interactions (your reading + Juz actions, prayer logs, search queries, Qibla opens), App content (bookmarks, notes, dedication text, event posts), Crash logs, Diagnostics.
  • Data shared with third parties: none for advertising or analytics. Operational sharing (hosting on Fly.io, push delivery via Expo) is limited to running the service.
  • Encryption in transit: yes (HTTPS / WSS).
  • Can users request data be deleted: yes — in-app (Profile Settings → Delete my data) and via email.
  • Account deletion URL: https://link.myqt.app/privacy/ (this page) — see Your rights above.

AI-generated decorative art

The "Daily Ornament" feature shows decorative geometric / arabesque / tile-pattern images that are generated by an AI image model from a human-written prompt. The images are ornamental only — they are not Quran scripture, not calligraphy, and not a depiction of any prophet, person, animal, or religious symbol.

Every generation is filtered before it reaches you:

  • The prompt explicitly excludes humans, animals, faces, text, calligraphy, religious symbols, and references to the Quran or any holy book.
  • Each generated image is automatically scanned for stray text (OCR) and faces (face detection); anything that fails is rejected from the pool, never shown.
  • You can report any image you find inappropriate via the flag icon on the screen. Three independent reports auto-hide the image while we review it.
  • The selection rotates daily; we keep a curated pool and don't repeat a piece within 30 days unless the pool runs thin.

We do not claim any artistic merit or originality for AI-generated content. It exists as a contemplative visual texture alongside your reading, nothing more. We don't share your prompts, reading data, or any personal information with the AI provider — prompts are pre-written templates we control, never user input.

Security

  • All network traffic to and from the app is over HTTPS / WSS.
  • Passwords are stored hashed (Django's default PBKDF2, never plaintext).
  • Auth tokens are stored on-device in the platform's secure async storage.
  • The backend uses standard Django defaults for CSRF, XSS, clickjacking, and secure cookies in production.

Changes to this policy

If we change what we collect or how we use it, we'll update this page and bump the "Effective" date at the top. Material changes will also show up as an announcement banner in the app.

Contact

For any privacy request — access, deletion, rectification, complaint, or just a question — use our contact form or the 🐞 Report an issue flow in the app (hamburger menu).

Global Pulse

With your explicit consent, we anonymously share your in-app activity in a global feed visible to all app users. This is entirely separate from analytics and can be enabled or disabled at any time in Profile Settings.

We share only:

  • The action type (e.g., "completed Juz 2", "logged Fajr")
  • Your coarse country (inferred from device timezone, not GPS)
  • A rounded timestamp (nearest 5 minutes)

We never share your name, email, profile photo, precise location, or any content you created (notes, bookmarks, etc.).

Data is retained for 48 hours and then automatically permanently deleted. You can export your Global Pulse history at any time via "Export my data" in Profile Settings. If you revoke consent, your future actions are no longer shared, and your existing history is immediately deleted.