Niyyah Privacy Policy#
Last updated: August 6, 2026
Niyyah is a private, local-first prayer, Quran, and dhikr tracker. This Privacy Policy explains how
Niyyah handles information when you use the mobile app, visit niyyah.sohan.dev, or contact
support.
Niyyah is operated by S M Samiul Haque Sohan, an independent developer ("Niyyah," "we," "us," or "our"). On Google Play, Niyyah is published under the developer name Zanvent. For privacy questions, email niyyah@sohan.dev.
The short version#
- You do not create a Niyyah account.
- Your prayer, Quran, and dhikr history is stored in the app's local database on your device. We do not upload that history to a Niyyah account or server.
- Location is used to calculate prayer times. Current-location coordinates are rounded to two decimal places before they are stored or sent for city and timezone lookup. Niyyah does not use background location.
- Optional product analytics is off by default. If you explicitly turn it on, Niyyah uses a random installation profile to understand app usage and may use your connection IP to derive approximate location through PostHog GeoIP. The profile is pseudonymous: Niyyah does not add your name, email, account ID, advertising ID, device GPS, or worship-record contents.
- Essential technical crash diagnostics may be sent to help us keep the app reliable. They are configured to exclude personal worship and location data.
- Niyyah has no advertising, data brokerage, cross-app tracking, sale of personal information, or social profile.
Because Niyyah is a worship app, even coarse information about using its features may be sensitive. Analytics therefore remains off unless you make the choice to enable it, uses a limited event allowlist, and must pass the profile-deletion and privacy checks described below before the production release is published.
Information kept on your device#
Niyyah stores the following in a local SQLite database so the app can work offline:
- prayer records, including prayer day, prayer name, recorded status, combined-prayer information, and relevant timestamps;
- Quran page and khatm progress;
- dhikr sessions, counts, targets, and relevant timestamps;
- your selected city, country, timezone, and latitude/longitude rounded to two decimal places;
- prayer calculation method, Asr method, high-latitude rule, and manual prayer-time offsets;
- prayer and Quran reminder settings;
- theme, time format, Hijri adjustment, haptic preference, onboarding state, analytics consent, and other app settings; and
- a random analytics identifier if analytics is configured in the build.
This information is processed on your device to calculate prayer times, organize local prayer days, show your history and insights, schedule local notifications, create backups, and restore a backup. We cannot see or recover this local database.
Prayer and Quran reminders are scheduled locally through your operating system. Niyyah v1 does not use the Expo push-notification service or maintain a server-side notification profile. Notification text may be visible on your lock screen according to your device settings.
Your operating system or a backup service you enable may copy app data into a device backup. Those copies are controlled by you and the platform provider, not by Niyyah. Deleting data inside Niyyah does not necessarily delete older device backups or exported files.
Information sent off your device#
Location lookup#
You can configure location in three ways:
- Current location. With your foreground permission, Niyyah asks the operating system for a one-time location. Coordinates are rounded to two decimal places before storage or network use.
- Manual city search. The city text you enter is sent for geocoding.
- Manual coordinates. Coordinates and timezone you enter are normalized and stored locally. They are not sent to the geocoding service merely by saving them.
For current-location lookup and manual city search, Niyyah sends the rounded coordinates or city query to a Niyyah Cloudflare Worker. The Worker uses Google Maps Platform's Geocoding and Time Zone services and returns a city, country, timezone, and rounded coordinates.
The Worker does not receive a Niyyah account ID, advertising ID, worship history, or analytics ID. Cloudflare necessarily processes connection and request metadata, which can include your IP address, headers, requested URL, city query, or rounded coordinates. The current Worker configuration may retain invocation logs for up to seven days. The Worker does not cache lookup responses or maintain a shared cross-user location cache. The location you confirm is stored only in your app installation for its direct prayer-time function. The application does not create a user-linked search-history database.
Google receives the lookup data needed to provide its services and processes service logs under its own terms and privacy policy. Learn more in the Google Privacy Policy and Google Maps/Google Earth Additional Terms.
You can avoid current-location access by searching for a city or entering location details manually. You can revoke location permission at any time in your device settings.
Product analytics#
Product analytics is optional and off by default. Niyyah does not capture, queue, or send a product event until you explicitly turn on Share optional usage analytics during onboarding or in Settings. You can turn it off again at any time.
When enabled, Niyyah sends approved events to PostHog Cloud in its EU region. Events may include:
- a random identifier generated by this Niyyah installation;
- session starts and coarse session-duration information;
- app version, build, release channel, platform, operating-system major version, coarse device class, language, and online/offline state;
- permitted onboarding steps, allowlisted screen families, and success or failure of approved app actions;
- whether prayer logging, Quran logging, or dhikr was used, without the underlying record values;
- coarse technical operation and performance outcomes; and
- approximate geography derived by PostHog from the connection IP.
PostHog necessarily receives network connection information, including an IP address, to receive an event. With GeoIP enabled, PostHog may use that address to add approximate country, region, city, or provider-generated approximate coordinate properties. We use this to understand where Niyyah is used and how reliability and adoption differ by region. Niyyah does not send PostHog the device's GPS coordinates, saved prayer-time city or coordinates, city-search query, or background location.
Niyyah does not send PostHog prayer names or statuses, Quran page numbers or goals, dhikr phrases or counts, streak values, prayer settings, saved location, notification contents or schedules, notification opens or deliveries, support messages, free-text notes, exports, local database rows, advertising identifiers, contacts, photos, clipboard contents, or typed text. Feature events can state that an action succeeded or failed, but not the worship record involved.
After consent, PostHog creates a pseudonymous installation profile keyed only by Niyyah's random installation identifier. Niyyah does not send name, email, phone number, account ID, advertising ID, hardware ID, or app-defined person properties, and it does not call PostHog's identity-linking APIs. PostHog may add provider-generated technical event metadata and initial GeoIP properties to the profile from the consented request. Niyyah never links the profile to your support email, a Niyyah account, Sentry, or advertising.
PostHog autocapture, touch capture, session replay, automatic screen capture, and PostHog error capture are disabled. We retain optional usage analytics only while it remains useful for understanding and improving Niyyah. We review that need at least annually and delete data that is no longer needed. PostHog's plan may delete it sooner. You can withdraw consent at any time and request deletion using the installation ID shown in Settings.
Essential crash diagnostics#
The production release is intended to use Sentry in its Germany/EU region for essential error and crash reporting. Niyyah configures diagnostic events with personal information disabled, enables server-side IP scrubbing, and applies a sanitization boundary before sending them. A diagnostic event may contain:
- an error message and technical stack trace;
- app version and release environment;
- device model, operating-system name and version, and platform; and
- non-sensitive technical breadcrumbs needed to understand a failure.
Niyyah does not intentionally attach worship logs, prayer settings, coordinates, Quran pages, dhikr counts, SQLite data, exports, notification contents, request bodies, or support notes. No filtering system is perfect, so unexpected technical data may occasionally appear in an error report. Access to the diagnostic project is restricted and reports are used only for reliability and security.
We retain diagnostic events only while they remain useful for app reliability and security. We review that need at least annually and delete data that is no longer needed; Sentry's plan may delete it sooner. Sentry's own handling is described in its Privacy Policy.
If Sentry is not enabled in the final release build, this section must be removed or revised before publication.
Support email and voluntary reports#
If you email support, we receive your email address, message, and anything you choose to attach. Niyyah's in-app prayer-time report can prepare an email containing the app version. You may also choose to include rounded location details, prayer calculation settings, a prayer-time preview, and notification settings. These optional details are included only after you select them, and you can review or edit the email in your mail app before sending it. Worship history is not attached by the report tool.
Support messages are used to answer your request, troubleshoot problems, prevent abuse, and improve Niyyah. They are retained for up to 12 months after the last interaction, unless a longer period is required for security, legal compliance, or an active dispute. Your email provider and our mailbox provider also process the message under their own policies.
Do not send an export file or worship history to support unless we specifically ask for it and you decide that doing so is necessary.
Website visits#
The Niyyah website is intended to be a static site hosted through Cloudflare. When you visit it, Cloudflare may process IP address, user agent, requested page, timing, and security information to deliver and protect the site. The site does not currently intend to use advertising, behavioral analytics, account cookies, or contact forms. If that changes, this policy and any required consent controls must be updated before those features are enabled.
How we use information#
We use information only to:
- provide app functions you request, including location lookup and support;
- calculate and display local prayer times;
- maintain app and website security and reliability;
- understand product health, adoption, onboarding, retention, feature use, and approximate regional distribution only after explicit analytics consent;
- respond to support, privacy, and legal requests; and
- comply with law and enforce applicable terms.
Where applicable law requires a legal basis, we rely on your consent for optional analytics, foreground location, and optional support diagnostics; on providing the service you request for geocoding and support; and on legitimate interests in securing and maintaining the app and website for essential, minimized diagnostics. You may withdraw consent for future processing through the controls described in this policy.
Service providers and disclosure#
We use service providers only for the purposes described above:
| Provider | Purpose | Information involved |
|---|---|---|
| Cloudflare | Website delivery, geocoding Worker request transit, security, and operational logs | IP/request metadata, city query or rounded coordinates, normalized lookup response |
| Google Maps Platform | City geocoding, reverse geocoding, and timezone lookup | City query or rounded coordinates and service request metadata |
| PostHog | Optional consented product analytics and approximate GeoIP enrichment in its EU region | Random installation ID, approved app/device/action properties, event time, connection IP, derived GeoIP |
| Sentry | Essential technical diagnostics in its Germany/EU region, if enabled | Sanitized crash and technical device/app information |
| Apple and Google | App distribution, operating-system permissions, local notifications, and platform/store analytics | Information those platforms process under your account and device settings |
| Expo/EAS | Development and build infrastructure | Build artifacts and developer/project metadata; no routine upload of your local worship history |
| Email providers | Support communication | Sender address, message, headers, and voluntary attachments |
We do not sell or rent personal information. We do not use personal information for advertising, cross-context behavioral advertising, or tracking you across other companies' apps or websites. We may disclose limited information when required by law, to protect people or services from harm, or as part of a business reorganization with appropriate notice and safeguards.
We require service providers handling Niyyah data on our behalf to use it only for the stated service and to provide privacy and security protections consistent with this policy and applicable law.
Our service providers may process information in countries other than yours. Where required, we use contractual and organizational safeguards appropriate to the service and transfer.
Retention and deletion#
- Local app data: retained until you delete it, clear app storage, or uninstall the app, subject to platform and user-created backups.
- Export files: retained wherever you choose to save or share them until you delete those copies.
- Cloudflare Worker invocation logs: currently up to seven days, subject to final production verification.
- PostHog optional usage analytics: only while useful for understanding and improving Niyyah, reviewed at least annually and deleted when no longer needed; the provider may delete it sooner.
- Sentry diagnostics: only while useful for reliability and security, reviewed at least annually and deleted when no longer needed; the provider may delete it sooner.
- Support email: up to 12 months after the last interaction, unless temporarily needed for security, legal compliance, or an active dispute.
See Delete Niyyah data for step-by-step instructions and the limits of device-only deletion.
Your choices and rights#
Depending on where you live, you may have rights to request access, correction, deletion, restriction, portability, or objection concerning information we control, and to withdraw consent. You may also have the right to complain to a local data-protection authority.
You can act directly in the app:
- turn optional analytics off in Settings → Privacy & data → Privacy & analytics, stopping future product events;
- revoke location permission in your operating-system settings;
- export your local data in Settings → Data & backup → Export Niyyah data; and
- erase the local database, local reminders, settings, and current analytics identifier through Settings → Data & backup → Delete all data.
Turning analytics off does not by itself delete events or the pseudonymous profile PostHog already received. They remain subject to the retention policy above, or you can request earlier deletion using the current analytics installation ID where it is available.
Because Niyyah has no account and does not link analytics or diagnostic identifiers to your name or email, we may be unable to locate a remote event from an email address alone. To make a privacy request, contact niyyah@sohan.dev before resetting the relevant identifier where practical. We may ask for the current random analytics identifier or limited information needed to verify and locate records. We will not ask you to send worship history merely to verify identity.
Security#
Niyyah minimizes network data, uses HTTPS for service requests, restricts production service access, and sanitizes diagnostic payloads. Worship history remains in the app's normal local storage and is not encrypted by a Niyyah-specific key. Niyyah exports are unencrypted JSON and can contain personal worship history, saved rounded location, settings, and timestamps. Store exports privately and send them only to people or services you trust.
No storage or transmission method is completely secure. Keep your device, device account, backups, and exported files protected.
Children#
Niyyah is not specifically directed to children and does not knowingly create accounts or collect names from children. If you believe a child has sent personal information to support, contact us so we can review and delete it where appropriate. A parent or guardian should supervise use where local law requires it.
Changes to this policy#
We may update this policy when Niyyah's features, providers, or legal obligations change. We will post the revised policy at this URL and update the date above. If a change requires new consent, we will ask before beginning that processing.
Contact#
Privacy questions and requests: niyyah@sohan.dev
Operator: S M Samiul Haque Sohan (Google Play developer name: Zanvent)