Privacy Policy
Effective date: May 3, 2026 Last updated: September 29, 2026
Manevi Halka (“the App”, “we”, “us”) values your privacy. This policy explains what information we collect when you use the App, how we use it, and what rights you have.
1. Data Controller
Name: Emirhan Ayaz Email: privacy@manevihalka.app App: Manevi Halka
2. Information We Collect
2.1. Information you provide directly
- Account info: Email address, full name, profile picture (optional)
- Authentication: If you use Sign in with Apple or Google, the identity token from the respective service
- Preferences: App language, theme, notification preferences and the circles you hide from your Circles list (only you can see this; it is deleted when you leave the circle)
- Cross-device backup: The personal worship records and reading preferences you keep while signed in are backed up on our servers so they are not lost when you change devices. This backup includes: your prayer and supererogatory (nafl) tracking records, your prayer tracking preferences, your Qur’an bookmarks, your last reading position in the Qur’an and Jawshan, your reader preferences (secondary translation language, mushaf font style). If you use the same account on more than one device, these records are kept in sync between them; notification and reminder settings are not part of this backup and stay separate on each device. Only you can access this backup; members of your circles, circle admins and other users cannot see it (protected by row-level access rules in the database). The backup is deleted when you delete your account. Your location coordinates are NOT included in this backup and remain only on your device
- User content: Group descriptions you create, custom dhikr texts, Quran verse notes, book reading notes
- One-time circle (dedication): The title and dedication text of any one-time circle you create. You are responsible for any third-party information (e.g., a name) you enter in the dedication text
- Dhikr list sharing: You can share your personal dhikr list with others via a share code/link. When you share, a copy (snapshot) of your list at that moment is stored with the share code; recipients can add the list to their own library. You can revoke a share at any time
- Completion certificates: When you complete a Hatim, Cevshen, or book, a PDF certificate is generated locally on your device (never uploaded to our servers, stays on your device for sharing)
-
Report records: When you use the in-app “Report” feature, your report (the reporting account ID, the reported group/member/event, the selected reason, and your optional note) is stored on our servers. These records are used solely to review the report and prevent abuse, are never shared with third parties, and are deleted or anonymized within a reasonable period after the review is completed
- Shared practice check-ins: If you join a circle’s shared practice (prayer tracking, memorisation/review, supplication) of your own accord, the day and unit you mark (for example “maghrib, 22 August”) is stored on our servers. By default a task is in “admin only” mode: only that circle’s admin can see this record; other members of the circle and other users cannot. If the admin who created the task chose “Mutual”, everyone who joins the task sees each other’s check-ins by day (the admin too, but only after joining the task); members who have not joined still cannot. The mode that applies is shown on the task screen before you join. A mutual task can later be switched to admin only, not the other way round. Joining is a separate, explicit act: being a member of a circle does NOT enrol you in a shared practice, you have to join the task as well. When you leave the task or leave the circle, these check-ins are deleted immediately. Your personal prayer tracking on the home screen is entirely separate and is never transferred here. The two markings are independent: marking a prayer on your personal card does not mark the circle task, and nobody, including the admin, can see your personal record (see the “Cross-device backup” item above)
- Gestures between participants in mutual tasks: In a mutual task you can say “May Allah accept it” on another participant’s checked day, or send them “I remembered you in my dua”. For this, the sender, the recipient, the type of gesture and the day concerned are stored on our servers; no free text can be written. Only the sender and the recipient see a gesture. No push notification is sent to the recipient; it appears in the in-app notification list, at most once a day, with the sender’s name
- Personal targets in memorization tasks: A circle’s admin can give someone who has joined a memorization task a personal memorization target (a surah, for example). For this, the target, who set it and when are stored on our servers; the person receives an in-app notification and a push notification. Only that person and the task’s admin see the target; in mutual tasks the other participants cannot see it either. For the targets that person is working on (a personal target or the task’s own), the admin sees only a coarse state of their Cetele progress (not started, learning, memorized); the places they struggle with, the review schedule and section details stay with the person
- Guest members without the app: A circle’s admin can add someone close to them who does not use the app to the circle as a guest member. For this, only the name the admin enters is stored (no surname needed); the guest’s phone number, email address or any other contact detail is not collected. A guest has no password or way to sign in and does not use the app themselves. A member of the circle (the person looking after the guest) keeps track of the guest’s reading tasks; that member or the admin marks a task as read, and who did so is recorded. The guest’s name and task status are visible to the circle’s members. The member looking after the guest can share a plan of the guest’s upcoming readings as a PDF or an image; this document is created on the device and not uploaded to our servers. To alert that member and the admin when something changes in the circle, only a short summary of the plan (round, number of the section to read and date) is stored. When you add someone close to you as a guest, do so with their knowledge; you are responsible for the information you enter about them
2.2. Automatically collected information
- Progress data: Quran page progress, completed tasks, hatim count, dhikr counters, Cevshen knot completions, your Cetele (memorization) progress and review schedule
- Notification token: Device token for push notifications (Apple APNs / Google FCM)
- Signed-in devices: For each device your account is signed in on, we keep the device model (for example iPhone 15 Pro), the operating system and app version, that device’s notification token and the time of its last activity. This is used only for account security: under Account & Security > My devices you can see where your account is signed in and sign out any device, and when your account is signed in on a new device, your other devices are notified. The name you gave the device, your IP address and your location are not part of this record. It is not kept for guest use (before the account is secured)
- Location: Only your device’s current location, used to compute prayer times and the qibla direction. Location data is not sent to or stored on our servers — used only on-device for calculation. So that the app can notice you have moved and offer prayer times for your new city, the last known coordinate is stored on your device only; it is deleted when you clear your account data.
- Subscription info: If you have a Premium subscription: term, plan type, store (App Store / Play Store), subscription status
2.3. Information we do NOT collect
- Credit card / payment details (handled by Apple/Google — never visible to us)
- Health data
- Sensitive personal data (except religion — voluntarily provided through use of the app, given the nature of tracking Islamic practices)
2.4. Joining from the web without an account (manevihalka.app)
On manevihalka.app you can take on a portion or contribute to a shared dhikr without creating an account. There are two ways in: opening a circle’s invitation link when you do not have the app, or visiting the public Shared Reading page (no invitation needed). In both cases we collect only the following:
- A random identifier generated in your browser. It is kept in your browser’s local storage. The identifier itself is not stored on our servers; only an irreversible digest of it (SHA-256) is kept. It serves one purpose: so that you can see your own portion when you return to the same link
- Your interface language (to show the page in the right language)
- The portion you took on (page or chapter range) and whether you marked it finished
- The count you added to a shared dhikr
- First-seen and last-seen timestamps
- A name, if you choose to give one. It is optional and never a condition for anything: taking on a portion, contributing, marking it finished — all of it works without a name. If you leave it blank you appear in the circle as “Guest”. You can remove a name you gave from the same page later
- To limit abuse: your IP address is never written in raw form; an irreversible digest of it (SHA-256) is kept with a counter, and those records are deleted automatically after 1 hour
Not collected: email, phone number, account, location. A name is taken only if you type one. The page carries no advertising, analytics or tracking tools. While you view or read the page, no request goes to any third party (every file it uses is served from our own servers).
Bot check (Cloudflare Turnstile): Only at the moment you contribute (taking on a portion, marking it complete, adding to a shared dhikr count or entering a name) does the page run Cloudflare’s verification service to tell automated programs apart from real people. Your browser then connects to Cloudflare, which processes your IP address, browser information (such as the User-Agent) and the site on which the check runs. Usually you see nothing; if something looks suspicious, a checkbox may appear. For this purpose Cloudflare may store strictly necessary technical data on its own domain, and it also uses these signals, under its own responsibility, to improve its bot detection. Details: Cloudflare Turnstile privacy addendum.
If you gave no name, the circle’s administrator and members cannot see who you are; they only see that the portion was taken on, or that a contribution was added to the count. If you gave a name, they see that name alongside the portion you took and what you contributed.
Clearing your browser’s site data removes the identifier and severs the link to your portion. If you wish to access or erase this data, simply send us your identifier; without it we have no way to locate the record.
Three things are different on the Shared Reading page: there is no name field and you are never asked for one; the page has no administrator and no members, so nobody sees anything about you, only the shared counter grows; and because the page never ends, your record follows a 90-day retention rule.
3. How We Use Your Information
- To provide core app functionality (group tracking, task distribution, progress recording)
- To send reminders (task deadline, streak warning, milestone celebration)
- To verify Premium subscription status
- To diagnose errors and performance issues (anonymous technical data)
- To meet legal obligations
- To improve user experience (aggregated/anonymous analytics)
We do not use your data for advertising. We do not sell your data to ad networks.
4. Third-Party Services
We use the following third-party services to provide our service:
| Service | Purpose | Data |
|---|---|---|
| Supabase (privacy) | Database, auth, server functions | Account, progress, all app data |
| Resend (privacy) | Account emails (verification, password reset) | Email address and email content; sent from EU servers |
| RevenueCat (privacy) | Subscription management | User ID, subscription status |
| Apple Push Notification Service | iOS push notifications | Device token |
| Google Firebase Cloud Messaging | Android push notifications | Device token |
| Expo (privacy) | Push notification infrastructure | Device token |
| Apple Sign In | OAuth login | Apple ID, email, name |
| Google Sign In | OAuth login | Google ID, email, name |
| Sentry (privacy) | Error reporting, crash tracking | Anonymous error logs, stack traces, device/OS info |
| PostHog (privacy) | Product analytics (opt-out available) | Anonymous usage events (no PII), hosted on EU servers |
| Quran Foundation (privacy) | Recitation audio (reciter list and verse audio files) | Audio files download directly to your device from Quran Foundation and quranicaudio.com servers; these servers see your IP address and the requested file. No account information is sent; the reciter list is fetched anonymously through our server |
| Cloudflare Turnstile (privacy) | Bot check when contributing on manevihalka.app | IP address, browser information (User-Agent, TLS fingerprint), site name; only at the moment you contribute on the website |
5. Data Retention
- Shared practice check-ins: Check-ins are kept for 180 days, then permanently deleted by a daily automated job. If you leave the task or the circle, your check-ins are deleted immediately, without waiting for that period
- Gestures between participants: Gestures older than 30 days are permanently deleted by a weekly automated job. If you leave the task or the circle, the gestures you sent and received are deleted immediately
- Personal memorization targets: Deleted immediately when you leave the task or the circle, and when the admin removes the target
- Signed-in devices: When you sign out of a device or remove it under My devices, its record and notification token are deleted immediately. Records of devices whose session has ended and that have not been seen for 30 days, or that have not been used for 180 days, are deleted by a weekly automated job
- Active account: Data is retained as long as your account is active
- Account deletion: Your account is first marked as soft-deleted. You can restore your account within 30 days by signing in again. After 30 days, an automated cron job (pg_cron) permanently deletes all your personal data. If you want immediate permanent deletion, contact us by email. Only accounting/subscription records that must legally be retained may be kept (anonymized)
- Completed one-time circles: When a one-time circle ends, a summary (participant count, work completed) is archived; individual task details are cleared
- Inactive circles: Circles with no activity for a long time are automatically frozen and later archived (content is kept, active task distribution stops)
- Empty, abandoned circles: Circles that have been inactive for more than 90 days, have at most one member and contain no reading/task content are permanently deleted by a weekly automated job
- Unused guest accounts: Guest accounts with no linked identity (email/Google/Apple) that remain unused for 90 days and have no circle memberships, event participation, family plan or subscription are marked for deletion and go through the permanent deletion process above after 30 days
- Shared dhikr lists: A snapshot created when you share a dhikr list continues to be kept for those who added it to their library, even if you delete your account; however, your name as the sharer is anonymized when your account is deleted
- Guest members: When a guest is removed from a circle, their name and the shared plan summaries are deleted immediately. The anonymous record of the tasks they read is permanently deleted under the “Unused guest accounts” rule above. If no members other than guests remain in a circle, the guests are removed too
- Notification logs: Auto-deleted after 30 days
-
Audit logs: Retained for 12 months for security and compliance
- Web participation without an account: A guest record belongs to the circle it was created in. When that circle is deleted after it ends (24 hours after its end date), the guest record, the portion taken and the contributed count are permanently deleted with it. Abuse counters are deleted after 1 hour. Because the Shared Reading page never ends, records there follow a separate rule: if you make no contribution for 90 days, your guest record, the portion you took and your dhikr contribution are deleted automatically. If a portion is still open in your name at that moment, deletion waits until it closes
6. Your Rights (GDPR / KVKK)
Under GDPR (EU) and KVKK (Turkey), you have these rights:
- Access: Learn what data we store about you
- Rectification: Update inaccurate information (via app’s profile screen)
- Erasure: Delete your account and all data (in-app: Profile → Settings → Account Security → Delete My Account)
- Portability: Request a copy of your data. In-app: Profile → Settings → Data Export downloads all your data as a PDF
- Object: Object to specific processing activities. Analytics opt-out is available anytime: Profile → Settings → Privacy → Analytics (default on)
- Complaint: File a complaint with your data protection authority
For requests: privacy@manevihalka.app
7. Children
The App is not intended for children under 13. We do not knowingly collect data from users under 13. If you believe your child has provided us data, please contact us — we will delete it immediately.
App Store age rating: 4+ (Islamic content — no aggressive/inappropriate content)
8. Security
- All data is transmitted over HTTPS/TLS
- Database access is protected by Row-Level Security (RLS) policies
- Passwords are hashed with bcrypt (Supabase Auth standard)
- Auth tokens are short-lived and stored in secure device areas (iOS Keychain / Android Keystore)
- Server access is restricted by 2FA + IP allow-list (developer account)
No system is 100% secure. While we cannot guarantee absolute security, we will notify affected users and authorities within 72 hours of discovering a data breach.
9. Cross-Border Data Transfer
Supabase and our other service providers may host servers in the EU and US. For data transferred outside the European Economic Area, GDPR Article 46 “Standard Contractual Clauses” apply.
10. Cookies / Local Storage
The App is a mobile app and does not use web cookies. However, the following data is stored locally on your device:
- Session token (for login, in Keychain/Keystore)
- Preference settings (language, theme)
- Cached data (for offline use)
- Notification counters
- Widget data (UserDefaults / SharedPreferences)
- Recitation files you download (offline listening) and temporary copies of recently played verses. Under the provider’s terms they are kept for at most 6 days and refreshed whenever you are online; you can delete downloads in the app
Deleting your account or uninstalling the app removes this data.
Website (manevihalka.app): The account-free participation page uses no cookies, but stores a single value in your browser’s local storage: the random identifier described above (section 2.4). Nothing is written for analytics or advertising. Clearing your browser’s site data also removes this value. The Cloudflare check that runs when you contribute may store strictly necessary technical data on its own domain (challenges.cloudflare.com) for bot detection (section 2.4).
11. Changes to This Policy
We may update this policy from time to time. For significant changes, we will send an in-app notification. The effective date is shown at the top.
12. Contact
For questions:
Email: privacy@manevihalka.app Subject: Manevi Halka — Privacy
We respond within 15 days.