1. Introduction & Data Controller
PrayPath is a mobile application providing Islamic worship tools including prayer times, dhikr tracking, Quran reading progress, and personal dua management.
This Privacy Policy has been prepared in accordance with the Turkish Personal Data Protection Law (KVKK, Law No. 6698) and the EU General Data Protection Regulation (GDPR).
Data Controller: PrayPath Contact: hello [at] praypath [dot] app
2. Data We Collect
• Sign-in with Apple or Google. We do not store a password. Your name or email is received only if Apple or Google shares it with us. • Your progress (Quran and hatim reading, prayer tracking, dhikr, personal duas) is saved under an account. Before you sign in, this account is created anonymously on your device, and your progress is stored on our servers under it. • Location (to calculate prayer times; only while the app is open, stored at city level only) • Preferences and settings (language, notification times, etc.) • Personalization from the intro questions (your goal, your relationship with the Quran, what gets in the way, reading pace, mode, and reminder time). Your gender and your 'how connected do you feel' answer stay on your device and are not sent to our servers or to analytics. • Device type and operating system (for technical support and debugging) • App activity sent to the Meta (Facebook) SDK. When we promote the app with Instagram or Facebook ads, we send Meta only counts (how many times the app was installed, opened, or subscribed to) so we can see which ad worked. We do not share your advertising identifier (IDFA), we do not track you across other apps, and we do not send your name, email, or phone. • Optional (missed-prayers / Qada calculator): you enter your gender, birth date and (for women only) monthly menstrual days for an accurate count. This calculation runs entirely on your device; your gender and menstrual data are never sent to or stored on our servers. Only the resulting missed-prayer count is saved to your account. You do not have to enter this information.
We do not store credit card or payment information; subscription payments are processed through Apple App Store or Google Play.
3. How We Use Your Data
We use the collected data for the following purposes:
• Prayer time calculations and personalized notifications • Saving and syncing your progress (hatim, prayer tracking, dhikr, personal duas) • Monitoring app performance and resolving errors • Managing your subscription status • Seeing which of our ads worked (we send Meta only counts of installs, app opens and subscriptions, never your advertising identifier)
We do not use your personal content (duas, dhikr, intentions, prayer logs) for advertising or marketing, and we do not sell your data to third parties.
4. Data Sharing
We share your data with the following providers to deliver the service:
• Supabase: database and sign-in (AWS Frankfurt / eu-central-1 region) • PostHog: product analytics, hosted on EU Frankfurt servers (on by default; opt-out) • Sentry: error reporting (no personal content or screenshots) • RevenueCat: subscription management • Apple / Google: in-app purchase processing • Meta Platforms (Facebook/Instagram): we send only counts (installs, app opens, subscriptions) so we can measure which of our ads worked. We do not share your advertising identifier, and personal details such as your name, email, or phone are not shared with Meta. You can see how Meta handles this data in its own data policy: https://www.facebook.com/privacy/policy
Prayer times are computed locally on your device; your location is not sent to any third party for prayer-time calculation.
Product analytics relies on the legitimate-interest basis (KVKK Art. 5(2)(f) / GDPR Art. 6(1)(f)). Your identity is pseudonymous (a stable user ID, with no name or email in events); only counters and metadata (e.g. "prayer_logged: fajr") are sent. If you turn analytics off, both product analytics and Meta measurement stop (opt-out). You can change the preference any time from Settings → Privacy inside the app.
User-written content such as personal duas, intentions, prayer-log notes, and custom dhikr names is never sent to any analytics or advertising service.
KVKK Art. 9 international transfers: Supabase (EU Frankfurt), PostHog Inc. (EU Frankfurt) and Sentry (EU) operate in GDPR-adequate regions; Standard Contractual Clauses (SCCs) in their Data Processing Agreements (DPAs) apply for KVKK transfers. RevenueCat (US), Meta Platforms (US) and Apple/Google (international) are also covered by SCCs and signed DPAs.
Your data is not shared with any other party unless required by law.
5. Location Data
We request access to your device's location to accurately calculate prayer times. Location data:
• Is only used while the app is in the foreground • Is stored locally on your device as a city name • Full coordinates are not stored on our servers • You can switch to manual city entry in settings at any time
6. Data Security
Your data is transmitted over encrypted HTTPS connections. Supabase infrastructure is GDPR and SOC 2 compliant.
Data retention periods: • Account data: Until you delete your account • Dhikr and hatim history: Until you delete your account • Unused anonymous accounts: deleted after 60 days if they have no subscription and no saved data • Location data: Only last city name stored on device • Error logs (Sentry): 90 days • Analytics data: 14 months (Google policy)
Deleting your account permanently removes all personal data.
7. Ads and Measurement
PrayPath does not show any ads. There is no ad tier and no ad tracking inside the app.
The only ad-related thing we do is measure which of our own ads worked. When we promote PrayPath with Instagram or Facebook ads, we send Meta only counts (how many times the app was installed, opened, or subscribed to). We do not use your advertising identifier, and we do not track you across other apps.
We do not share your name, email, or phone with Meta for this.
8. Your Rights
Under KVKK (Article 11) and GDPR, you have the following rights:
• Learn whether your personal data is being processed • Request access to processed data • Request correction of incomplete or inaccurate data • Request deletion or destruction of your data (Profile → Edit Profile → Delete Account) • Request that third parties be notified of processed data • Object to results produced by automated analysis against you
To exercise your rights, contact hello [at] praypath [dot] app.
9. Children's Privacy
PrayPath is not intended for children under 13. We do not knowingly collect personal data from children. If we become aware of such a situation, we will promptly delete the relevant data.
By using the app, you confirm you are at least 13 years old.
10. Policy Changes
We may update this policy from time to time. We will notify you of significant changes via an in-app notification or email. You can always see the current date at the top of this page.
11. Contact
For privacy-related questions: