Niyyah Privacy Policy#

Last updated: September 2, 2026

Niyyah is a private, local-first app that delivers a Daily Hadith and tracks prayer, Quran, and dhikr. This Privacy Policy explains how Niyyah handles information when you use the mobile app, visit niyyah.sohan.dev, or contact support.

Niyyah is operated by S M Samiul Haque Sohan, an independent developer ("Niyyah," "we," "us," or "our"). On Google Play, Niyyah is published under the developer name Zanvent. For privacy questions, email niyyah@sohan.dev.

The short version#

Because Niyyah is a worship app, even coarse information about using its features may be sensitive. Analytics therefore uses a limited event allowlist, stays silent until onboarding is complete, and has an opt-out on onboarding and in Settings. Its setting, payload, identity-reset, and profile-deletion behavior is tested on both iPhone and Android before release.

Information kept on your device#

Niyyah stores the following in a local SQLite database so the app can work offline:

This information is processed on your device to calculate prayer times, organize local prayer days, show your history and insights, schedule local notifications, create backups, and restore a backup. We cannot see or recover this local database.

Prayer and Quran reminders are scheduled locally through your operating system. Daily Hadith is different: if you explicitly enable it, Niyyah uses Expo's push-notification service and stores a device notification address as described below. Notification text may be visible on your lock screen according to your device settings.

Your operating system or a backup service you enable may copy app data into a device backup. Those copies are controlled by you and the platform provider, not by Niyyah. Deleting data inside Niyyah does not necessarily delete older device backups or exported files.

Information sent off your device#

Location lookup#

You can configure location in two ways:

  1. Current location. With your foreground permission, Niyyah asks the operating system for a one-time location. Coordinates are rounded to two decimal places before storage or network use.
  2. Manual city search. The city text you enter is sent for geocoding.

For current-location lookup and manual city search, Niyyah sends the rounded coordinates or city query to a Niyyah Cloudflare Worker. The Worker uses Google Maps Platform's Geocoding and Time Zone services and returns a city, country, timezone, and rounded coordinates.

The Worker does not receive a Niyyah account ID, advertising ID, worship history, or analytics ID. Cloudflare necessarily processes connection and request metadata, which can include your IP address, headers, requested URL, city query, or rounded coordinates. Cloudflare Workers Logs may retain invocation logs for up to seven days; the actual period may be shorter depending on the plan. The Worker does not cache lookup responses or maintain a shared cross-user location cache. The location you confirm is stored only in your app installation for its direct prayer-time function. The application does not create a user-linked search-history database.

Google receives the lookup data needed to provide its services and processes service logs under its own terms and privacy policy. Learn more in the Google Privacy Policy and Google Maps/Google Earth Additional Terms.

You can avoid current-location access by searching for a city or entering location details manually. You can revoke location permission at any time in your device settings.

Daily Hadith content and notifications#

Niyyah downloads the published Bengali Daily Hadith archive from a Cloudflare Worker and keeps a copy on your device for offline reading. These public content requests necessarily include normal network metadata such as your IP address and headers. They do not include a Niyyah account, worship records, saved folders, or the optional PostHog analytics identifier.

Daily Hadith notifications are off by default. If you enable them, the app obtains an Expo push token—a pseudonymous address for this app installation—and sends it with the device platform to the Daily Hadith Worker. The server uses it only to deliver the selected hadith at 9:00 AM Bangladesh time through Expo Push Service and the Apple or Google notification service. The visible title and short Bengali excerpt may appear on your lock screen.

The push token is not an account ID, advertising ID, or worship record. Niyyah does not join it to PostHog, Sentry, support email, saved folders, or reading activity. Turning Daily Hadith notifications off deletes the token and its delivery rows from Niyyah's server; invalid tokens are also deleted after delivery receipts. Delete all data performs the same server deletion before clearing the local database, so it may need an internet connection when Daily Hadith notifications are enabled. The downloaded archive continues to work when notifications are off.

Product analytics#

Product analytics is optional and the Share usage analytics switch is on during setup. Niyyah does not capture, queue, or send a product event until you finish onboarding with that switch on. You can turn it off before continuing or at any time in Settings.

When enabled, Niyyah sends approved events to PostHog Cloud in its EU region. Events may include:

PostHog necessarily receives network connection information, including an IP address, to receive an event. With GeoIP enabled, PostHog may use that address to add approximate country, region, city, or provider-generated approximate coordinate properties. We use this to understand where Niyyah is used and how reliability and adoption differ by region. Niyyah does not send PostHog the device's GPS coordinates, saved prayer-time city or coordinates, city-search query, or background location.

Niyyah does not send PostHog prayer names or statuses, Quran page numbers or goals, dhikr phrases or counts, streak values, prayer settings, saved location, notification contents or schedules, notification opens or deliveries, support messages, free-text notes, exports, local database rows, advertising identifiers, contacts, photos, clipboard contents, or typed text. Feature events can state that an action succeeded or failed, but not the worship record involved.

When analytics is enabled, PostHog creates a pseudonymous installation profile keyed only by Niyyah's random installation identifier. Niyyah does not send name, email, phone number, account ID, advertising ID, hardware ID, or app-defined person properties, and it does not call PostHog's identity-linking APIs. PostHog may add provider-generated technical event metadata and initial GeoIP properties to the profile from an analytics request. Niyyah never links the profile to your support email, a Niyyah account, Sentry, or advertising.

PostHog autocapture, touch capture, session replay, automatic screen capture, and PostHog error capture are disabled. We retain optional usage analytics only while it remains useful for understanding and improving Niyyah. We review that need at least annually and delete data that is no longer needed. PostHog's plan may delete it sooner. You can turn analytics off at any time and request deletion using the installation ID, which you can copy in Settings → Data & backup.

Essential crash diagnostics#

Niyyah uses Sentry in its Germany/EU region for essential error and crash reporting. Niyyah configures diagnostic events with personal information disabled, enables server-side IP scrubbing, and applies a sanitization boundary before sending them. A diagnostic event may contain:

Niyyah does not intentionally attach worship logs, prayer settings, coordinates, Quran pages, dhikr counts, SQLite data, exports, notification contents, request bodies, or support notes. No filtering system is perfect, so unexpected technical data may occasionally appear in an error report. Access to the diagnostic project is restricted and reports are used only for reliability and security.

We retain diagnostic events only while they remain useful for app reliability and security. We review that need at least annually and delete data that is no longer needed; Sentry's plan may delete it sooner. Sentry's own handling is described in its Privacy Policy.

Support email and voluntary reports#

If you email support, we receive your email address, message, and anything you choose to attach. Niyyah's in-app prayer-time report can prepare an email containing the app version. You may also choose to include rounded location details, prayer calculation settings, a prayer-time preview, and notification settings. These optional details are included only after you select them, and you can review or edit the email in your mail app before sending it. Worship history is not attached by the report tool.

Support messages are used to answer your request, troubleshoot problems, prevent abuse, and improve Niyyah. They are retained for up to 12 months after the last interaction, unless a longer period is required for security, legal compliance, or an active dispute. Your email provider and our mailbox provider also process the message under their own policies.

Do not send an export file or worship history to support unless we specifically ask for it and you decide that doing so is necessary.

Website visits#

The Niyyah website is a static site hosted through Cloudflare. When you visit it, Cloudflare may process IP address, user agent, requested page, timing, and security information to deliver and protect the site.

The website also sends a page-view event, and a click event when you tap a store link, to PostHog in its EU region. Each event carries a random identifier that exists only for that page load, the page address, the referring page, and the store you tapped. The site sets no cookies and no browser storage, so visits are not linked to each other or to you. PostHog receives your IP address to accept the event and may derive an approximate location from it. If your browser sends the Do Not Track or Global Privacy Control signal, the site sends nothing. The site has no advertising, account cookies, or contact forms.

How we use information#

We use information only to:

Where applicable law requires a legal basis, we rely on legitimate interests in understanding, improving, securing, and maintaining the app and website through minimized analytics and diagnostics. You can object to future product analytics through the onboarding and Settings controls. We rely on your choices or consent for foreground location and optional support details, and on providing the service you request for geocoding and support.

Service providers and disclosure#

We use service providers only for the purposes described above:

Provider Purpose Information involved
Cloudflare Website delivery, geocoding and Daily Hadith Workers, security, and operational logs IP/request metadata, city query or rounded coordinates, public hadith requests, optional push token
Google Maps Platform City geocoding, reverse geocoding, and timezone lookup City query or rounded coordinates and service request metadata
PostHog Optional app analytics, cookieless website page analytics, and approximate GeoIP enrichment in its EU region Random installation or page-load ID, approved app/device/action properties, page address, event time, connection IP, derived GeoIP
Sentry Essential technical diagnostics in its Germany/EU region, if enabled Sanitized crash and technical device/app information
Apple and Google App distribution, operating-system permissions, local and opted-in push notifications, and platform/store analytics Information those platforms process under your account and device settings
Expo/EAS Development/build infrastructure and opted-in Daily Hadith push delivery Build/project metadata and push token/message; no routine upload of local worship history
Email providers Support communication Sender address, message, headers, and voluntary attachments

We do not sell or rent personal information. We do not use personal information for advertising, cross-context behavioral advertising, or tracking you across other companies' apps or websites. We may disclose limited information when required by law, to protect people or services from harm, or as part of a business reorganization with appropriate notice and safeguards.

We require service providers handling Niyyah data on our behalf to use it only for the stated service and to provide privacy and security protections consistent with this policy and applicable law.

Our service providers may process information in countries other than yours. Where required, we use contractual and organizational safeguards appropriate to the service and transfer.

Retention and deletion#

See Delete Niyyah data for step-by-step instructions and the limits of device-only deletion.

Your choices and rights#

Depending on where you live, you may have rights to request access, correction, deletion, restriction, portability, or objection concerning information we control, and to withdraw consent. You may also have the right to complain to a local data-protection authority.

You can act directly in the app:

Turning analytics off does not by itself delete events or the pseudonymous profile PostHog already received. They remain subject to the retention policy above, or you can request earlier deletion using the current analytics installation ID where it is available.

Because Niyyah has no account and does not link analytics or diagnostic identifiers to your name or email, we may be unable to locate a remote event from an email address alone. To make a privacy request, contact niyyah@sohan.dev before resetting the relevant identifier where practical. We may ask for the current random analytics identifier or limited information needed to verify and locate records. We will not ask you to send worship history merely to verify identity.

Security#

Niyyah minimizes network data, uses HTTPS for service requests, restricts production service access, and sanitizes diagnostic payloads. Worship history remains in the app's normal local storage and is not encrypted by a Niyyah-specific key. Niyyah exports are unencrypted JSON and can contain personal worship history, saved rounded location, settings, and timestamps. Store exports privately and send them only to people or services you trust.

No storage or transmission method is completely secure. Keep your device, device account, backups, and exported files protected.

Children#

Niyyah is not specifically directed to children and does not knowingly create accounts or collect names from children. If you believe a child has sent personal information to support, contact us so we can review and delete it where appropriate. A parent or guardian should supervise use where local law requires it.

Changes to this policy#

We may update this policy when Niyyah's features, providers, or legal obligations change. We will post the revised policy at this URL and update the date above. If a change requires new consent, we will ask before beginning that processing.

Contact#

Privacy questions and requests: niyyah@sohan.dev

Operator: S M Samiul Haque Sohan (Google Play developer name: Zanvent)