Niyyah Privacy Policy#

Last updated: August 6, 2026

Niyyah is a private, local-first prayer, Quran, and dhikr tracker. This Privacy Policy explains how Niyyah handles information when you use the mobile app, visit niyyah.sohan.dev, or contact support.

Niyyah is operated by S M Samiul Haque Sohan, an independent developer ("Niyyah," "we," "us," or "our"). On Google Play, Niyyah is published under the developer name Zanvent. For privacy questions, email niyyah@sohan.dev.

The short version#

Because Niyyah is a worship app, even coarse information about using its features may be sensitive. Analytics therefore remains off unless you make the choice to enable it, uses a limited event allowlist, and must pass the profile-deletion and privacy checks described below before the production release is published.

Information kept on your device#

Niyyah stores the following in a local SQLite database so the app can work offline:

This information is processed on your device to calculate prayer times, organize local prayer days, show your history and insights, schedule local notifications, create backups, and restore a backup. We cannot see or recover this local database.

Prayer and Quran reminders are scheduled locally through your operating system. Niyyah v1 does not use the Expo push-notification service or maintain a server-side notification profile. Notification text may be visible on your lock screen according to your device settings.

Your operating system or a backup service you enable may copy app data into a device backup. Those copies are controlled by you and the platform provider, not by Niyyah. Deleting data inside Niyyah does not necessarily delete older device backups or exported files.

Information sent off your device#

Location lookup#

You can configure location in three ways:

  1. Current location. With your foreground permission, Niyyah asks the operating system for a one-time location. Coordinates are rounded to two decimal places before storage or network use.
  2. Manual city search. The city text you enter is sent for geocoding.
  3. Manual coordinates. Coordinates and timezone you enter are normalized and stored locally. They are not sent to the geocoding service merely by saving them.

For current-location lookup and manual city search, Niyyah sends the rounded coordinates or city query to a Niyyah Cloudflare Worker. The Worker uses Google Maps Platform's Geocoding and Time Zone services and returns a city, country, timezone, and rounded coordinates.

The Worker does not receive a Niyyah account ID, advertising ID, worship history, or analytics ID. Cloudflare necessarily processes connection and request metadata, which can include your IP address, headers, requested URL, city query, or rounded coordinates. The current Worker configuration may retain invocation logs for up to seven days. The Worker does not cache lookup responses or maintain a shared cross-user location cache. The location you confirm is stored only in your app installation for its direct prayer-time function. The application does not create a user-linked search-history database.

Google receives the lookup data needed to provide its services and processes service logs under its own terms and privacy policy. Learn more in the Google Privacy Policy and Google Maps/Google Earth Additional Terms.

You can avoid current-location access by searching for a city or entering location details manually. You can revoke location permission at any time in your device settings.

Product analytics#

Product analytics is optional and off by default. Niyyah does not capture, queue, or send a product event until you explicitly turn on Share optional usage analytics during onboarding or in Settings. You can turn it off again at any time.

When enabled, Niyyah sends approved events to PostHog Cloud in its EU region. Events may include:

PostHog necessarily receives network connection information, including an IP address, to receive an event. With GeoIP enabled, PostHog may use that address to add approximate country, region, city, or provider-generated approximate coordinate properties. We use this to understand where Niyyah is used and how reliability and adoption differ by region. Niyyah does not send PostHog the device's GPS coordinates, saved prayer-time city or coordinates, city-search query, or background location.

Niyyah does not send PostHog prayer names or statuses, Quran page numbers or goals, dhikr phrases or counts, streak values, prayer settings, saved location, notification contents or schedules, notification opens or deliveries, support messages, free-text notes, exports, local database rows, advertising identifiers, contacts, photos, clipboard contents, or typed text. Feature events can state that an action succeeded or failed, but not the worship record involved.

After consent, PostHog creates a pseudonymous installation profile keyed only by Niyyah's random installation identifier. Niyyah does not send name, email, phone number, account ID, advertising ID, hardware ID, or app-defined person properties, and it does not call PostHog's identity-linking APIs. PostHog may add provider-generated technical event metadata and initial GeoIP properties to the profile from the consented request. Niyyah never links the profile to your support email, a Niyyah account, Sentry, or advertising.

PostHog autocapture, touch capture, session replay, automatic screen capture, and PostHog error capture are disabled. We retain optional usage analytics only while it remains useful for understanding and improving Niyyah. We review that need at least annually and delete data that is no longer needed. PostHog's plan may delete it sooner. You can withdraw consent at any time and request deletion using the installation ID shown in Settings.

Essential crash diagnostics#

The production release is intended to use Sentry in its Germany/EU region for essential error and crash reporting. Niyyah configures diagnostic events with personal information disabled, enables server-side IP scrubbing, and applies a sanitization boundary before sending them. A diagnostic event may contain:

Niyyah does not intentionally attach worship logs, prayer settings, coordinates, Quran pages, dhikr counts, SQLite data, exports, notification contents, request bodies, or support notes. No filtering system is perfect, so unexpected technical data may occasionally appear in an error report. Access to the diagnostic project is restricted and reports are used only for reliability and security.

We retain diagnostic events only while they remain useful for app reliability and security. We review that need at least annually and delete data that is no longer needed; Sentry's plan may delete it sooner. Sentry's own handling is described in its Privacy Policy.

If Sentry is not enabled in the final release build, this section must be removed or revised before publication.

Support email and voluntary reports#

If you email support, we receive your email address, message, and anything you choose to attach. Niyyah's in-app prayer-time report can prepare an email containing the app version. You may also choose to include rounded location details, prayer calculation settings, a prayer-time preview, and notification settings. These optional details are included only after you select them, and you can review or edit the email in your mail app before sending it. Worship history is not attached by the report tool.

Support messages are used to answer your request, troubleshoot problems, prevent abuse, and improve Niyyah. They are retained for up to 12 months after the last interaction, unless a longer period is required for security, legal compliance, or an active dispute. Your email provider and our mailbox provider also process the message under their own policies.

Do not send an export file or worship history to support unless we specifically ask for it and you decide that doing so is necessary.

Website visits#

The Niyyah website is intended to be a static site hosted through Cloudflare. When you visit it, Cloudflare may process IP address, user agent, requested page, timing, and security information to deliver and protect the site. The site does not currently intend to use advertising, behavioral analytics, account cookies, or contact forms. If that changes, this policy and any required consent controls must be updated before those features are enabled.

How we use information#

We use information only to:

Where applicable law requires a legal basis, we rely on your consent for optional analytics, foreground location, and optional support diagnostics; on providing the service you request for geocoding and support; and on legitimate interests in securing and maintaining the app and website for essential, minimized diagnostics. You may withdraw consent for future processing through the controls described in this policy.

Service providers and disclosure#

We use service providers only for the purposes described above:

Provider Purpose Information involved
Cloudflare Website delivery, geocoding Worker request transit, security, and operational logs IP/request metadata, city query or rounded coordinates, normalized lookup response
Google Maps Platform City geocoding, reverse geocoding, and timezone lookup City query or rounded coordinates and service request metadata
PostHog Optional consented product analytics and approximate GeoIP enrichment in its EU region Random installation ID, approved app/device/action properties, event time, connection IP, derived GeoIP
Sentry Essential technical diagnostics in its Germany/EU region, if enabled Sanitized crash and technical device/app information
Apple and Google App distribution, operating-system permissions, local notifications, and platform/store analytics Information those platforms process under your account and device settings
Expo/EAS Development and build infrastructure Build artifacts and developer/project metadata; no routine upload of your local worship history
Email providers Support communication Sender address, message, headers, and voluntary attachments

We do not sell or rent personal information. We do not use personal information for advertising, cross-context behavioral advertising, or tracking you across other companies' apps or websites. We may disclose limited information when required by law, to protect people or services from harm, or as part of a business reorganization with appropriate notice and safeguards.

We require service providers handling Niyyah data on our behalf to use it only for the stated service and to provide privacy and security protections consistent with this policy and applicable law.

Our service providers may process information in countries other than yours. Where required, we use contractual and organizational safeguards appropriate to the service and transfer.

Retention and deletion#

See Delete Niyyah data for step-by-step instructions and the limits of device-only deletion.

Your choices and rights#

Depending on where you live, you may have rights to request access, correction, deletion, restriction, portability, or objection concerning information we control, and to withdraw consent. You may also have the right to complain to a local data-protection authority.

You can act directly in the app:

Turning analytics off does not by itself delete events or the pseudonymous profile PostHog already received. They remain subject to the retention policy above, or you can request earlier deletion using the current analytics installation ID where it is available.

Because Niyyah has no account and does not link analytics or diagnostic identifiers to your name or email, we may be unable to locate a remote event from an email address alone. To make a privacy request, contact niyyah@sohan.dev before resetting the relevant identifier where practical. We may ask for the current random analytics identifier or limited information needed to verify and locate records. We will not ask you to send worship history merely to verify identity.

Security#

Niyyah minimizes network data, uses HTTPS for service requests, restricts production service access, and sanitizes diagnostic payloads. Worship history remains in the app's normal local storage and is not encrypted by a Niyyah-specific key. Niyyah exports are unencrypted JSON and can contain personal worship history, saved rounded location, settings, and timestamps. Store exports privately and send them only to people or services you trust.

No storage or transmission method is completely secure. Keep your device, device account, backups, and exported files protected.

Children#

Niyyah is not specifically directed to children and does not knowingly create accounts or collect names from children. If you believe a child has sent personal information to support, contact us so we can review and delete it where appropriate. A parent or guardian should supervise use where local law requires it.

Changes to this policy#

We may update this policy when Niyyah's features, providers, or legal obligations change. We will post the revised policy at this URL and update the date above. If a change requires new consent, we will ask before beginning that processing.

Contact#

Privacy questions and requests: niyyah@sohan.dev

Operator: S M Samiul Haque Sohan (Google Play developer name: Zanvent)