Privacy Policy

Your prayers are between you and Allah. We built Ilmora to keep it that way.

Effective date: March 21, 2026 · Last updated: August 26, 2026

Plain language summary: Ilmora does not sell your data, does not show ads, and does not share your personal information with third parties. Account creation is optional. Your precise GPS location is processed on-device only and never sent to our servers. If you create an account, your city-level location is synced to our servers so it can be restored on your other devices. Firebase Analytics is explicitly disabled. We do not use any advertising or behavioural tracking SDKs. If an account goes 24 months without being used, we delete the backup we hold for it — the data on your own device is not affected.

1. Who We Are

Ilmora ("we", "us", "our") is an Islamic prayer companion app for iOS, developed and maintained by Yavuz Akbay. This Privacy Policy explains what information we collect when you use the Ilmora app and website (ilmora.app), how we use it, and the choices you have.

By using the App you agree to the practices described in this policy.

2. Information We Collect

2.1 Account Information (Optional)

Account creation is optional and enables cloud sync across your devices. If you register, we collect:

  • Email address: for authentication and account recovery.
  • Display name: the name you provide for your profile.
  • User ID: a unique identifier assigned by Firebase Authentication.
  • Gender: an optional profile field you may choose to provide.
  • Authentication provider: whether you signed in via email/password, Google, or Apple.

You may use many features without an account. All data for non-account users remains local to your device.

2.2 Prayer & Worship Activity

When you use the App, we record your worship data to power features like streaks, history, and statistics:

  • Prayer records: prayer name, date, time, completion state (on time, late, missed), and optional personal notes.
  • Fasting records: fasting type, status, date, intention, notes, and whether it is a Qada fast.
  • Dhikr sessions: the phrase recited, count, date, and time of day.
  • Quran reading sessions: surah, session start/end time, duration, verses read, and whether translation was displayed.
  • Achievement unlocks: which of the app's achievements you have earned.

2.3 Precise Location

The App requests your precise GPS location only to calculate accurate prayer times and Qibla direction for your current position, to show you nearby mosques and halal places, and to confirm you are physically at a place when you verify it for the community. Your precise GPS coordinates are processed entirely on your device and are never transmitted to or stored on our servers, regardless of whether you have an account.

Your city name or manual location setting is stored locally on your device. If you create an account, it is also synced to our servers (linked to your account) so it can be restored on your other devices. For guests without an account, it never leaves your device.

2.4 Purchase History

If you subscribe to Ilmora Premium, we record your subscription status (active or inactive) to unlock premium features and restore your subscription across devices. Transaction verification is handled by Apple's StoreKit framework. We never access your payment details.

2.5 Notification Interaction Data

We track whether local notifications are sent, delivered, and opened to improve notification timing and relevance. This data is stored locally on your device only and is not transmitted to our servers. Earlier versions of the app also kept a synced copy of this data on our servers for existing accounts; that copy is deleted if you delete your account (see Section 7), and no new copy is created.

2.6 Website Waitlist

This website, separately from the App, offers a pre-launch waitlist. If you choose to join it, we collect:

  • Email address: the address you enter in the waitlist form.
  • Signup timestamp and queue position: so we can recognise Founding Members at launch.

Purpose and lawful basis. We use this address for one purpose only: to email you when Ilmora launches, and occasional updates about that launch. The lawful basis is your consent (GDPR Art. 6(1)(a)), given by ticking the consent box in the waitlist form. You may withdraw it at any time via the unsubscribe link in any email, or by writing to privacy@ilmora.app. Withdrawal is as easy as giving consent, and does not affect processing carried out before withdrawal.

Processor and storage location. Waitlist entries are stored by Supabase (Supabase Inc.) on infrastructure hosted in the European Union (AWS eu-central-1, Frankfurt). Submissions are protected by Cloudflare Turnstile, a privacy-preserving bot check that does not track you across sites; Cloudflare processes your IP address and a challenge token solely to determine whether the submission is automated.

Retention. Waitlist entries are deleted within 90 days of launch, or immediately upon your request or unsubscribe, whichever comes first. We do not sell, rent, or share waitlist addresses with anyone.

2.7 Menstrual Cycle Tracking (Optional)

If you enable cycle tracking, the App records the days you mark, so that prayers and fasts are not counted as missed during them. This is health data, and we treat it as the most sensitive thing in the App.

It is never sent to our servers, and it is never included in cloud backup. It is stored in a protected file on your device and mirrored through Apple's iCloud Keychain so it is available on your other Apple devices. iCloud Keychain is end-to-end encrypted by Apple: the data is readable only on your own devices, and not by us, not by any server we operate, and not by Apple. We mention the mirroring explicitly because "stays on your device" could otherwise be read as excluding it.

You can turn cycle tracking off in the App at any time, which removes the stored days.

2.8 Zakat Figures (Optional)

If you use the Zakat calculator, the asset figures you enter (cash, gold, silver, and similar holdings, and their computed value) are stored so your assessment survives a device change. If you have an account with cloud backup on, this is backed up to our servers keyed to your account. We never collect payment instruments, bank details, or account numbers — only the figures you type in.

2.9 Qur'an Bookmarks, Notes & Memorization Progress

Bookmarks you place on a verse, personal notes you write against a verse, and your memorization (Hifz) progress are stored on your device and, with an account and cloud backup on, synced to our servers so they are available on your other devices. Like the rest of your worship activity (§2.2), this reveals religious practice and is treated as special category data under Article 9 GDPR.

2.10 Saved Halal Places

Places you save in the halal restaurant/mosque finder, and any verification notes you submit about a place (for example, confirming or disputing that a listing is halal), are stored so your saved list follows you across devices with an account. Verification notes you submit are visible to other users of the finder as part of that place's community-sourced record.

2.11 Points, Achievements & Mosque Catalogue Progress

The App records engagement activity — prayer completions, feature use, and session counts — to power streaks, points, achievements, and mosque-catalogue gamification (unlocking a mosque hero image to apply to your Home screen, a Premium feature). This is local-first on your device; with an account, your points total and mosque-catalogue progress are also synced to our servers so they follow you across devices.

2.12 Device Identifier

The App sends a Firebase Installations ID when it checks Firebase Remote Config for the Mosque Catalogue's download kill switch and daily download cap (see §5). This only happens when you open the Mosque Catalogue feature, not at app launch, and it identifies the installation, not you: it is not the IDFA or IDFV, it is not joined to advertising data, it is never used for tracking, and it resets if you reinstall the App. It is sent whether or not you have an account, and nothing on our side maps it to a person or account.

2.13 Content You Submit About Others

If you report another user or a listing for moderation, the report content and the user IDs involved are stored so we can act on it. If you use Ikhwah (Prayer Buddy), your prayer status is shared with buddies you have mutually added; see §3 for the legal basis. See §7 for how long report content is kept.

3. How We Use Your Information

Purpose Data Used Legal Basis
Authenticate your account and restore your session Email, User ID, auth provider Performance of a contract — Art. 6(1)(b)
Calculate prayer times and Qibla direction, show nearby mosques and halal places, and confirm place verification Precise location Not transmitted to us; processed on your device only
Show your prayer history, streaks and statistics Prayer, fasting, dhikr and Qur'an records On your device only. Not transmitted unless you turn on cloud backup
Back up and restore your records across your devices All account and activity data Consent — Art. 6(1)(a), and explicit consent under Art. 9(2)(a) for worship records
Enable the Ikhwah (Prayer Buddy) feature User ID, display name (optional), buddy code, prayer status shared with mutual buddies Consent — Art. 6(1)(a), and explicit consent under Art. 9(2)(a) for shared prayer status
Calculate and keep a record of your Zakat Asset figures you enter. No payment instruments, no bank details Consent — Art. 6(1)(a)
Unlock and restore your Premium subscription Purchase history Performance of a contract — Art. 6(1)(b)
Send prayer time and fasting reminders None — notifications are scheduled locally on your device No personal data leaves your device
Improve notification delivery timing Notification interaction data, stored on your device only No personal data leaves your device
Keep the community features safe — moderation reports, blocking, bans User ID, report contents Legitimate interests in preventing abuse — Art. 6(1)(f)
Save and sync your Qur'an bookmarks, notes and memorization progress Bookmarked verses, note text, memorization progress Consent — Art. 6(1)(a), and explicit consent under Art. 9(2)(a), via the same Cloud Synchronization switch
Save your halal-finder places and verification notes Saved place IDs, verification notes you submit Performance of a contract — Art. 6(1)(b)
Track your points, achievements and mosque-catalogue progress Points total, achievement unlocks, mosque-catalogue progress Performance of a contract — Art. 6(1)(b)
Fetch configuration and feature-flag values, and keep the App working correctly Device identifier (Firebase Installations ID), not linked to your identity Legitimate interests in operating the App — Art. 6(1)(f)

About consent for worship records. Records of prayer, fasting, dhikr and Qur'an reading reveal religious belief, which makes them special category data under Article 9 GDPR. We rely on your explicit consent under Art. 9(2)(a) to hold them, and the single Cloud Synchronization switch in the app is that consent. It is off by default — a new account backs up nothing until you turn it on — and you can withdraw it at any time in Settings → Storage. Withdrawing is as easy as giving it: turning the switch off deletes the copy on our servers and keeps everything on your device. Withdrawal does not affect processing carried out before it.

Creating an account always writes an account record (your email, display name and user ID) even when cloud backup is off. That record exists so you can sign in, and rests on Art. 6(1)(b), not on consent.

We do not use your data for advertising, behavioural tracking, or sale to third parties.

4. How We Store and Protect Your Information

4.1 Cloud Storage

Account and activity data for registered users is stored in Google Firebase Firestore. All data is isolated to your account using your Firebase UID as a namespace. Access is governed by server-side security rules that prevent any unauthorised access.

4.2 Local Storage

Settings, cached prayer data, bookmarks, and progress are stored locally using iOS UserDefaults. Sensitive authentication data is stored in the iOS Keychain with kSecAttrAccessibleWhenUnlockedThisDeviceOnly. This means it cannot be accessed when your device is locked and cannot be transferred to another device via backup.

4.3 Widget Data

The Prayer Times Widget reads prayer time and Islamic calendar data from a shared App Group. The widget does not collect any data independently.

4.4 Data in Transit

All communication between the App and Firebase servers uses HTTPS/TLS. Arbitrary HTTP connections are blocked by App Transport Security.

5. Third-Party Services

Service Provider Applies to Purpose
Firebase Authentication Google LLC App Account creation and sign-in
Firebase Firestore Google LLC App Cloud data storage and sync
Google Sign-In Google LLC App OAuth authentication
Apple Sign-In Apple Inc. App OAuth authentication
Apple CloudKit Apple Inc. App Retained as a safety-net entitlement only: when you delete your account, we ask CloudKit to purge any private-zone records left over from Ilmora's earlier iCloud-sync design, which this version no longer uses for live sync
Supabase Supabase Inc. Website Website waitlist storage (EU, AWS eu-central-1)
Turnstile Cloudflare, Inc. Website Bot protection on the website waitlist form
Cloudflare Pages Cloudflare, Inc. Website Hosts this website. Every request to ilmora.app, including its IP address, passes through Cloudflare's network before reaching our content
Firebase Remote Config Google LLC App Mosque-catalogue download kill switch and daily download cap. Fetched only when you open the Mosque Catalogue feature, not at app launch
Firebase App Check Google LLC App Confirms requests to our backend come from a genuine copy of the App, to block abusive traffic
Firebase Cloud Functions Google LLC App Server-side logic — purchase verification, account-deletion data purge, moderation notices, buddy-code management, retention sweeps
Firebase Storage Google LLC App Mosque hero images (public-read, downloaded only when you apply a mosque to your Home screen)
Adhan (open source) Batoul Apps App Prayer time calculation (on-device, no data sent)

The "Applies to" column tells you whether a service is part of the iOS App or this website — most rows are one or the other, not both, so if you only use the App, the website-only rows above (Supabase, Turnstile, Cloudflare Pages) never see your data, and vice versa.

Firebase is subject to Google's Privacy Policy. Google Sign-In is subject to Google's Terms of Service. Apple Sign-In and Apple CloudKit are subject to Apple's privacy practices.

We do not use any advertising networks, behavioural tracking SDKs, or analytics platforms. Firebase Analytics is explicitly disabled in the App.

6. Permissions We Request

Permission Why It Is Needed
Location (When In Use) To calculate accurate prayer times and Qibla direction for your location, show nearby mosques and halal places, and confirm you are at a place when you verify it for the community.
Notifications To send prayer time reminders, fasting alerts, and Islamic calendar events. All notifications are scheduled locally on your device.
Camera To scan a QR code when adding an Ikhwah prayer buddy.
Photo Library (Add Only) To save a wisdom card or dua image you choose to share, so you can post it elsewhere.

Each permission is requested only when you access the relevant feature. You can revoke any permission at any time in iOS Settings → Ilmora.

7. Data Retention

We keep each category of data only for as long as it is needed for the purpose it was collected for. These are the periods we apply:

Data We keep it for
Worship records backed up to our servers (prayer, fasting, dhikr, Qur'an, memorisation, notes, bookmarks) Until you delete your account, or 24 months after you last use the app, whichever comes first
Zakat assessments, saved halal places Same as above
Account record (email, display name, user ID) Until you delete your account
Prayer status shared with your Ikhwah buddies 2 months, on a rolling basis — older shared months are removed automatically
Moderation reports — both reports about a person and reports about a place (a restaurant or mosque listing) The reporter's and reported person's user IDs and any free text are erased after 90 days, or immediately when the reporter deletes their account. The outcome is kept without them as a safety audit trail
Diagnostic logs on your device 7 days
Website waitlist entries 90 days after launch, or immediately on request or unsubscribe
Data of users without an account Never reaches our servers. Removed from your device when you delete the app
Website access logs held by Cloudflare Pages (visitor IP, request path, timestamp) Governed by Cloudflare's own retention schedule; we do not export or separately retain these logs

7.1 Accounts that are no longer used

Holding a record of someone's religious practice indefinitely, for an account nobody opens any more, has no purpose left to justify it. So if 24 months pass without the app being opened on any of your devices, we delete the backup we hold on our servers. This runs automatically, as a daily check.

What that removes: every worship record, Zakat assessment, note, bookmark, saved place and setting we hold in the cloud for you. What it does not touch: your account itself, and the copy of your data on your own device — the app keeps its records locally, so a dormancy deletion costs you the ability to restore onto a new device, not the history on the device in your hand.

You can sign in again at any time and the account will work normally; it will simply start empty on our side. Your consent to cloud backup is not carried across the deletion — the app asks again before it uploads anything. The next time you open the app after this has happened, it tells you so.

Accounts with an active paid subscription are not swept while the subscription lasts.

7.2 Deleting your account yourself

You can delete your account at any time via Settings → Delete Account in the App. Deletion requires re-authentication to confirm your identity, and then:

  • Your user document and all subcollections (prayer archives, fasting records, dhikr history, Qur'an history, notes, bookmarks, memorisation, Zakat assessments, saved places) are permanently deleted.
  • Your public profile and buddy code are removed, and your user ID is stripped from community content you authored elsewhere.
  • Local app data is cleared from your device and Keychain entries are removed.

8. Using Ilmora Without an Account

An account is optional. Prayer times, the Qibla compass, tracking, the Qur'an reader, Zakat and the rest of the App work without one, and this is the mode we designed for first, not an afterthought.

If you do not create an account, none of your personal data reaches our servers. There is nothing to back up, nothing to restore and nothing for us to delete on request, because we never receive it. Everything lives on your device and is removed when you delete the App. This is enforced in the code, not merely by policy: the component that writes to our database refuses to start at all without a signed-in account.

Two things still leave your device even without an account, and you should know about them:

  • Firebase receives an installation identifier when the App checks for configuration updates at launch. It identifies the installation, not you; it is not an advertising identifier, it is reset if you reinstall, and nothing on our side connects it to a person.
  • Apple receives your search text and approximate location when you search for a city, a mosque or a halal place, because those searches use Apple's own map service. That request goes to Apple, not to us, and is covered by Apple's privacy policy.

If you later create an account, the data you built up beforehand is attached to it, and becomes eligible for cloud backup at that point — but only once you turn cloud backup on, which is a separate question the App asks you.

9. Children's Privacy

The App is not directed at children under 13 years of age. We do not knowingly collect personal information from children under 13. If you believe a child under 13 has provided personal information to us, please contact us and we will delete it promptly.

10. Your Rights

If you are in the European Economic Area or the United Kingdom, the GDPR gives you the following rights over your personal data. We honour them for everyone who asks, wherever they live.

  • Access (Art. 15) — obtain a copy of the personal data we hold about you, and information about how it is processed.
  • Rectification (Art. 16) — have inaccurate data corrected.
  • Erasure (Art. 17) — have your data deleted. You can do this yourself at any time via Settings → Delete Account in the App.
  • Restriction of processing (Art. 18) — ask us to stop using your data while a dispute about its accuracy or our grounds for holding it is resolved.
  • Data portability (Art. 20) — receive your data in a structured, machine-readable format. Settings → Export Your Data in the App does this immediately and without asking us.
  • Object (Art. 21) — object to processing carried out on the basis of our legitimate interests. Where we rely on that basis (moderation and abuse prevention), tell us and we will stop unless we can show compelling grounds that override your interests.
  • Withdraw consent (Art. 7(3)) — where we rely on your consent, withdraw it at any time. For cloud backup this is the Cloud Synchronization switch in Settings → Storage; turning it off also deletes the copy on our servers. Withdrawal does not affect processing carried out beforehand.
  • Not be subject to automated decision-making (Art. 22) — there is none in Ilmora. Nothing in the App profiles you or makes decisions about you automatically; the statistics you see are arithmetic on your own records.

To exercise any of these rights, email privacy@ilmora.app. We will respond within one month of receiving your request, as required by Art. 12(3). If the request is complex we may extend that by two further months and will tell you why within the first month. We do not charge for this.

Right to lodge a complaint. If you believe we have handled your personal data unlawfully, you have the right under Art. 77 GDPR to lodge a complaint with a data protection supervisory authority — in the EU member state where you live, where you work, or where you believe the infringement took place. A list of national supervisory authorities is published by the European Data Protection Board at edpb.europa.eu. In the United Kingdom the authority is the Information Commissioner's Office (ico.org.uk). You do not have to contact us first, though we would rather have the chance to put things right.

10.1 Additional Rights for Users in Türkiye (KVKK)

If you are in Türkiye, the Personal Data Protection Law No. 6698 (KVKK) gives you rights over your personal data that we honour on request. Under KVKK Art. 11, you may: learn whether we are processing your personal data; request information about that processing; learn its purpose and whether it is used consistently with that purpose; know the third parties, in Türkiye or abroad, to which your data is transferred; request correction of inaccurate or incomplete data; request its deletion or destruction — the same Settings → Delete Account flow described in §7.2 does this; object to a result reached solely through automated analysis of your data; and claim compensation for damage arising from unlawful processing.

KVKK Art. 10 requires us to disclose, at the point data is collected, who the data controller is, why the data is processed, to whom it may be transferred, how it is collected and on what legal basis, and what your rights are. This Policy is that disclosure: the controller is identified in §13, the purposes and legal bases in §2–§3, and the categories of recipient in §5.

You can send a request under KVKK, or lodge a complaint with Türkiye's Kişisel Verilerin Korunması Kurumu (Personal Data Protection Authority), or write to us directly at privacy@ilmora.app — we respond to KVKK requests on the same terms as the GDPR requests in §10 above.

11. International Data Transfers

App data handled by Google/Firebase may be stored and processed in the United States or other countries where Google maintains infrastructure. Where personal data of individuals in the European Economic Area or the United Kingdom is transferred outside that area, the transfer is made under the European Commission's Standard Contractual Clauses, which Google incorporates into the Firebase Data Processing Terms.

Website waitlist data is stored within the European Union (AWS eu-central-1, Frankfurt) and is not transferred outside it. Cloudflare Turnstile and Cloudflare Pages (which hosts this website) process request metadata, including your IP address, through Cloudflare's global network under its own Standard Contractual Clauses.

You may contact us at privacy@ilmora.app for a copy of the relevant safeguards.

12. Changes to This Policy

We may update this Privacy Policy from time to time. When we do, we will update the "Last Updated" date at the top of this page. For material changes, we will notify you through the App or via email if you have an account. Continued use of the App after changes take effect constitutes acceptance of the updated policy.

13. Contact Us

If you have questions, requests, or concerns about this Privacy Policy or how we handle your data, please reach out:

Yavuz Akbay, Developer at Ilmora

Email us at privacy@ilmora.app and we'll respond within 48 hours.

Ilmora App Free Islamic Companion