Skip to content

Legal

Privacy Policy

This policy explains what information Safa handles, where it is stored, and what choices you have.Last updated: August 5, 2026

1. Who this policy covers

This policy applies to the Safa mobile application and this website, operated under the name Safa. For privacy questions, contact safaquransupport@gmail.com.

2. Our approach: local-first

Safa is designed so its core features work without an account. Where possible, personal usage data stays on your device. Information leaves your device only when a feature requires it, such as creating an account, using optional cloud synchronization, requesting Quran content, checking prayer times, finding nearby mosques, or receiving push notifications on a signed-in device.

3. Data stored locally on your device

The following may be stored locally by the app:

  • Quran, recitation, and display preferences
  • Prayer settings and preferences
  • Favorites, Quran bookmarks, and Quran reading progress
  • Memorization and practice progress
  • Cached content the app has downloaded so it can be read offline
  • Recent location history
  • Recitation recordings made for practice
  • Local application settings

Quran bookmarks and Quran reading progress are currently stored only on your device and are not yet synchronized to Safa's servers, even when you are signed in.

Recitation recordings made for practice remain on your device and are not uploaded to Safa's servers. Removing the app, or clearing its data from your device settings, removes local data from that device.

4. Account information and optional synchronization

If you create an account, Safa can collect and store:

  • Email address when an account is created
  • Authentication credentials handled by Supabase
  • Display name
  • Avatar image if you choose to upload one
  • Account-linked installation UUID
  • Memorization and practice progress when signed in
  • Favorites and prayer settings when signed in and cloud synchronization is used
  • Push notification device tokens for signed-in users

Creating an account is optional. If you do not create an account, Safa does not associate your app usage with an account identity on Safa's servers.

5. Location data

Prayer-related features, Qibla direction, travel features, and mosque discovery may depend on approximate or precise location. Safa requests foreground, "when in use" location access only. Safa does not use background location.

Location is not stored in Safa's Supabase database. Coordinates may be sent to AlAdhan when prayer-time functionality requires them. Coordinates may be sent to OpenStreetMap/Overpass when the mosque finder is used. Recent location history is stored locally on your device.

6. Local identity

Safa creates a random installation UUID and stores it securely on your device. This identifier supports Safa's local-first identity system and can be associated with your account when you sign in. It is not an advertising identifier and is not used for advertising or tracking.

7. Notifications

Prayer reminders are local, on-device notifications. They do not require an account. Firebase Cloud Messaging is used for push notifications for signed-in users, and push notification device tokens are associated with signed-in devices.

You can turn off notifications at any time in Safa settings or your device settings.

8. Analytics, tracking, and advertising

No analytics SDK is used. No advertising SDK is used. No tracking pixel is used. Safa does not sell personal information. Safa does not use advertising IDs for tracking. Debug logging is disabled from release builds.

9. Third-party services

Safa relies on third-party services to provide content and functionality. When the app contacts these services, technical information such as your IP address and request details may be visible to them. Each service handles data under its own privacy policy.

  • Supabase - authentication, account data, and optional cloud synchronization. Data is processed according to Supabase's privacy practices and the region configured for the Safa project.
  • Quran.com API - Quran text, translations, tafsir, search, and related Quran content. Content returned through the API may have different source and licensing terms.
  • everyayah.com - Quran recitation audio. The exact redistribution/streaming terms still require verification.
  • AlAdhan - prayer-time functionality. Coordinates may be transmitted when needed.
  • OpenStreetMap / Overpass - mosque finder functionality. Coordinates may be transmitted when the mosque finder is used. © OpenStreetMap contributors.
  • Firebase Cloud Messaging - push notifications for signed-in users.
  • Apple / Google - platform and app-store distribution.

10. How we use information

  • To provide the app's features and content
  • To authenticate you and keep you signed in, if you have an account
  • To synchronize supported data across your devices when you enable that
  • To deliver notifications you have enabled
  • To respond to support and privacy requests
  • To diagnose and fix problems, and to keep the service secure

We do not sell your personal information, and we do not use it for advertising.

11. Legal bases and privacy rights

Where applicable privacy laws give you rights of access, correction, deletion, or portability for account data we hold, you can exercise them by emailing safaquransupport@gmail.com. We aim to respond within 30 days.

12. Data retention

Account data is kept while your account remains active. After an account deletion request is completed, associated server-side account data is removed from active systems, subject to short-lived backups and any legal retention requirements. Local-only data remains on your device until you uninstall the app or clear its data.

13. Account deletion

You can request deletion of your Safa account and its associated server data by emailing safaquransupport@gmail.com with the subject “Account deletion” and the email address on the account. Data kept only on your device is not held by Safa's servers — uninstall the app or clear app data to remove it locally.

14. Security

Safa takes reasonable measures to protect information handled by the app and website, including relying on the access controls and transport protections provided by its infrastructure providers. No method of transmission or storage is completely secure.

15. Children's privacy

Safa is not directed at children under 13. If you believe we have collected personal information from a child under 13, contact safaquransupport@gmail.com and we will delete it.

16. International data transfers

Safa uses cloud providers that may process data in the United States or other regions where those providers operate. By using account features, you understand that account data may be processed outside your country of residence under those providers' safeguards.

17. Changes to this policy

We may update this policy as the app changes. When we do, we will revise the "Last updated" date at the top of this page. Significant changes may be highlighted in the app or on this site.

18. Contact

Privacy contact: safaquransupport@gmail.com. Operator: Safa. These practices are intended to be interpreted under Applicable laws of the United States. General support information appears on the Support page.