1. Who we are, and what this covers
This policy applies to the Daily Muslim mobile app on iOS and Android (app identifier io.mydeen.app) and to the website at dailymuslim.org, including the blog, the public feedback board, the roadmap and the private My Data page. Together we call these “the Service”. In this policy, “we” and “us” mean Daily Muslim, the team that publishes them.
It replaces every earlier version, including the one published at pi-sys.com/deen/privacy. By installing or using Daily Muslim you agree to what is described here. If you do not agree, please stop using the app and uninstall it.
2. Using Daily Muslim without an account
Reading the Qur'an and its translations, the mushaf, prayer times, the Qibla compass, duas and ruqyah, hadith, adhkar, the dhikr counter, the Amal tracker, Word Study, Know Allah, Islam Basics, the Hijri calendar and downloaded books all work signed out, and much of it works with no network connection at all.
When you are signed out, the app still contacts our servers to download content you ask for, to show the blog, feedback board and roadmap, to receive notifications, and to keep the installation's backup described in the next section. None of these requests carries a name, email address or account identifier. As with any web request, our hosting provider sees the IP address it came from; we use it only for routing, rate limiting and abuse prevention, and we do not store it with your data.
3. The installation record and Amal backup
So that your Amal tracker survives a lost phone or a reinstall, every installation of the app keeps a small record on our servers from its first launch, whether or not you ever sign in. It is built to identify an installation, not a person:
- An installation number — ten random digits generated on your phone at first launch. It is not derived from your advertising ID, a hardware or vendor identifier, or anything else about your device, is stored only in the app's private storage, and does not survive uninstalling the app.
- A signing key for that installation, so that no one who guesses the number can write into its record. Every sync request is signed with it (HMAC) and carries a timestamp.
- The platform (iOS or Android) and the app version.
- The country, as a two-letter code, which our network edge (Cloudflare) derives from the incoming connection. The app does not send it, and no IP address, city or coordinates are stored.
- An app-open counter and the times the record was first created and last synced.
- The Amal tracker backup — one compact, binary-encoded block per calendar year containing the status of each tracked deed for each day (for example, whether a prayer was marked as prayed).
Open counts are also added up into daily totals per country and platform (opens, active installations and new installations), which contain no installation numbers. We use the record to restore your history, to keep sync consistent between retries, and to understand, in aggregate, where the app is used and which versions still need support.
If you later sign in on that installation, the record is linked to your account and stores the account's email address alongside it, so your history can follow you to a new device. Deleting your account removes that link and that email again (see section 17).
4. If you create an account
Signing in is optional. It enables syncing across your devices, Family reports, the My Data page, and posting on the feedback board. You can sign in with Google or Sign in with Apple. We never see or store your Google or Apple password.
When you sign in, the provider gives us, and we store:
- a stable identifier for your account with that provider;
- your email address, and whether the provider says it is verified;
- your display name and profile picture URL, when the provider supplies them;
- the language and time zone reported for your account.
If you use Sign in with Apple and choose to hide your email, Apple gives us a relay address instead of your real one, and that is all we ever have.
For each signed-in session we keep a hashed session token, the platform it came from (iOS, Android or web) and when it was created and expires. On the website, the session is held in a secure, HTTP-only cookie. Hashing means that even we cannot read a token back out of our database.
We do not ask for and do not store your phone number, postal address, date of birth, payment details or any government identifier.
5. What syncs when you are signed in
While you are signed in, the app keeps the following in step between your devices. It syncs once a day and whenever you ask it to, and more often only if you share with a Family (section 6):
- Bookmarks — Qur'an, dua and hadith bookmarks, with the folder, folder name, icon and colour you chose and when each was last changed. A deleted bookmark is kept as a small “deleted” marker so it disappears on your other devices too.
- Your Qur'an reading position — the surah, ayah, page and juz you last read, and when.
- Your Amal tracker and prayer log — the same per-day deed statuses described in section 3, linked to your account.
- Daily time in the app — the number of seconds the app was open on each day, used for your own activity charts and reports.
This information is private to your account. You can review it at any time on the My Data page after signing in with the same account. It is not shown to other users, except as described in section 6, and it is not used for advertising or profiling.
6. Family
Family lets up to twelve signed-in people, usually one household, encourage each other. You join only by accepting an invitation and explicitly agreeing to share. While you share, the other members of your Family can see your display name and your Amal tracker reports (the deeds you marked, day by day, for the period they choose). They cannot see your email address, bookmarks, reading position or anything else.
You can pause sharing at any time, which hides your reports immediately, or leave the Family. Reports are read live from your synced data each time; they are not copied into anyone else's account. When a Family organiser deletes their account, the Family is dissolved.
7. What you post publicly
The feedback board at dailymuslim.org/feedback and the roadmap are public pages. Anything you post there — the title and text of your suggestion or bug report, your comments, and the fact that you voted — is visible to anyone and may be indexed by search engines. Your display name and profile picture from your sign-in provider appear beside your posts. When you send feedback from inside the app, we attach the app version and platform so a report can be tied to a build; that is stored with the item but not shown publicly.
The app's Community feed is served by our earlier backend at pi-sys.com. Posts, comments and reactions there are public. Community identifies you only by the name you choose for it. That name, the optional email address you may add, your saved posts, the list of your own posts, the authors you have blocked and the content you have reported are all kept on your device. If you are signed in, the name is pre-filled from your account for your convenience; you can change it. Your email is never sent to the Community server — it is only placed into a report email if you choose to send one.
Please do not put your phone number, home address or anything else private into a public post.
8. Reporting a content issue
If you report a problem with an ayah, a translation, a tafsir or other content, we store the report so it can be reviewed: the time, the kind of content, its source and exact reference (for example, surah and ayah), the language, the reason and any description you write, and the app version and platform. Reports are not linked to your name or email address.
9. What stays on your device
A large part of what the app remembers never leaves your phone:
- reading settings, fonts, mushaf page colour, theme and language choices;
- dhikr and tasbih counts, and your Khatm and Qur'an reading history beyond the last position;
- Word Study progress — lessons, streak, quiz scores, notes, known and saved roots, and review schedule;
- Know Allah and Islam Basics progress;
- prayer notification, alarm and widget settings, and your calculation method and madhab;
- downloaded translations, tafsirs, recitations, books and dua databases;
- your last known coordinates and place name, cached so prayer times work offline;
- your Community name and email, saved posts, own posts, blocked authors and reports;
- the notification inbox and the entries the app adds to your device's search (Spotlight or its Android equivalent), which are indexed on the device only.
Uninstalling the app removes all of it. Whether a copy ends up in your own device backup (iCloud or Google) is controlled by your operating system settings, not by us.
10. Location
Daily Muslim asks for location permission to calculate prayer times for where you are, to point the Qibla compass and to find nearby mosques. It is optional: without it the app estimates your city as described below. When permission is granted, the app refreshes your position periodically while it is open, so prayer times follow you when you travel.
Your coordinates are never sent to, or stored on, Daily Muslim's servers. Prayer times and the Qibla direction are computed on your phone. The places where location touches something outside the app are these:
- Showing a city name. The app asks your phone's own geocoder (Apple or Google software on the device) to turn coordinates into a place name.
- The mosque finder. When you search, the coordinates of the area you are looking at, or the place name you type, are sent to OpenStreetMap's public Nominatim and Overpass services to fetch mosques there.
- When GPS is unavailable or refused. The app asks
ipapi.cofor an approximate city derived from your network address, and otherwise uses your device's time zone. Like any web request, this reveals your IP address to that service. - Regional notifications. To offer notices relevant to your country (for example, a local Ramadan announcement), the app asks our server which country the connection comes from. Our network edge answers with a two-letter code only; the app may also use your device's time zone, mobile network or region setting for the same purpose. No permission is involved and nothing more precise is used.
You can withdraw location permission at any time in your device settings. The app keeps working with your last known or estimated location.
11. Notifications
Prayer reminders, adhan alarms, Jumu'ah reminders and daily reflections are scheduled on your device by the operating system.
Announcements, new blog articles and regional notices are delivered with Firebase Cloud Messaging (a Google service), through Apple Push Notification service on iPhone. The app registers with Firebase, which issues a device token, and subscribes to general topics: all users, blog categories, and your country's topic. We send a message to a topic, not to a person, and we do not collect or store device tokens on our servers. We use Firebase only for message delivery — not Firebase Analytics or any other Firebase product.
You can turn notifications off in the app's settings or your device settings at any time.
12. Service statistics
We measure how the Service performs using the following, and nothing else:
- Installation totals — the daily counts described in section 3.
- A daily session report sent to our earlier backend at pi-sys.com, containing a random identifier created on your device (not your advertising ID or account), when a session started and how long it lasted, the app version, the platform and the device model name (such as “iPhone15,2”). You can switch it off in Settings → Privacy & Contact.
- Blog article counts — how many times each article was opened, split only by whether it was read in the app or on the web and whether the reader was a person or an automated crawler (judged from the browser's user-agent string). No per-reader record is kept.
None of these includes what you read, searched for, bookmarked or where you were. The website uses no analytics scripts and sets no tracking cookies; it remembers your chosen language in your browser's local storage.
13. Services the app contacts
These are the outside services the app talks to, and why. Each has its own privacy policy, which governs what it does with the request.
| Service | When it is contacted | What it receives |
|---|---|---|
| dailymuslim.org (hosted on Cloudflare) | Installation backup, sign-in, account sync, Family, feedback, content reports, blog, content downloads, country for notifications | The request, your IP address (not stored with your data), and your session when signed in |
| Firebase Cloud Messaging (Google) and Apple Push Notification service | To deliver notifications | A device token and the topics your device subscribes to |
| pi-sys.com | Community feed, the daily session report, dua and ruqyah audio | Community posts and your chosen name; the session report in section 12; your IP address |
| Google Sign-In, Sign in with Apple | Only when you choose to sign in | Handled by Google or Apple; we receive the fields listed in section 4 |
| OpenStreetMap (Nominatim, Overpass) | Only when you search in the mosque finder | The coordinates or place name you are searching |
| ipapi.co | Only when GPS is unavailable or refused | Your IP address, from which it returns an approximate city |
| Qur'an text and audio providers (Quran.com and Quran Foundation, EveryAyah, Al Quran Cloud, DuaRuqyah, IslamicAPI, Daily Islam CDN) | When you stream or download recitations, word audio or text | The file requested and your IP address |
| YouTube and MakkahLive | Only when you open a live stream or linked video | Loaded in an in-app browser view; these providers may set their own cookies |
| Apple App Store, Google Play | Installation, updates and the “rate this app” prompt | Handled by the store; we receive only aggregate store statistics |
14. How we use information, and why we may
- To provide the features you use — backing up and syncing your data, Family reports, keeping you signed in, showing your public posts (performance of our service to you).
- To deliver notifications you have allowed (your consent, which you can withdraw in settings).
- To answer you — replying to feedback, reports and support emails.
- To maintain and improve the app — aggregate statistics, and tying a bug report to an app version (our legitimate interest in a reliable service).
- To keep the Service safe — signing and rate limiting requests, blocking spam and abuse (legitimate interest).
- To meet legal obligations where the law requires it.
We do not use your information for advertising, behavioural profiling, scoring, selling, or training machine-learning models.
16. How long we keep things
| What | How long |
|---|---|
| Account details | Until you delete your account; an emptied record is kept afterwards (section 17) |
| Sign-in sessions | Until they expire or you sign out |
| Synced bookmarks, reading position, Amal and daily usage | Until you delete them or your account |
| Installation record and Amal backup | While the installation keeps syncing; unlinked from your account when you delete it |
| Daily installation totals and blog article counts | Kept as aggregate statistics; they contain no personal information |
| Family membership | Until you leave, the Family is dissolved, or you delete your account |
| Feedback posts, comments and votes | Until you or we remove them; deleting your account removes your name from them and your votes |
| Content reports | Until they have been reviewed and resolved |
| Daily session reports (pi-sys.com) | Up to 12 months |
| Server request logs | Short-lived, on our hosting provider's rotation |
17. Deleting your account and your data
Open the app, go to My Account, and choose Delete account. This is immediate and permanent. It erases your display name, email address, profile picture, language and time zone, your sessions, your synced bookmarks, reading position, Amal history and daily usage, and your votes. It removes you from your Family, and dissolves any Family you organise. Installations you had signed in on are unlinked from the account and the email copied to them is erased.
Two things remain. First, an emptied account record holding only the anonymous identifier your sign-in provider gave us, so the deletion cannot be quietly undone by a later sign-in; it contains no name, email address or picture. Second, the anonymous installation backup of section 3, which belongs to the phone rather than to the account, so reinstalling on that phone can still restore its history; uninstall the app to stop it syncing.
Feedback posts and comments you made are kept, because others have replied to and voted on them, but they lose their attribution. To have the text of a post removed as well, or to remove a Community post on pi-sys.com, email us with the post and roughly when you made it. We confirm deletion requests within 14 days.
18. Security
- Every connection between the app, the website and our servers uses HTTPS with TLS.
- Installation sync requests are signed with a per-installation key and a timestamp, so they cannot be forged or replayed.
- We never store a password for app accounts, because sign-in is handled by Google and Apple.
- Session tokens are stored hashed; website sessions use secure, HTTP-only cookies.
- Family reports are authorised and read in a single database step, so a report is only ever returned while the member is sharing.
- Write endpoints are rate limited, and every submission is validated on the server.
- Access to the database is restricted to the application and the people who operate it.
No service on the internet can promise perfect security. We use reasonable, current practices, and we will tell affected users promptly if something goes wrong.
19. Your choices and your rights
Wherever you live, you can:
- Use the app without an account, and refuse location and notification permissions, at any time.
- Switch off the daily session report in Settings.
- Pause or stop Family sharing at any time.
- See what we hold about you on the My Data page, or ask us for a copy.
- Correct anything that is wrong, including editing or removing something you posted.
- Delete your account and your data — see section 17.
- Object to a use you disagree with, or ask us to restrict it.
- Complain to your local data protection authority if you are not satisfied with our answer.
Email dailymuslim.org@gmail.com with the subject “Privacy request”. We reply within 30 days.
20. Children
Daily Muslim is suitable for all ages and contains no advertising, no in-app purchases and no age-restricted material. We do not knowingly collect personal information from children under 13. Signing in, Family and posting on the feedback board require a Google or Apple account, which have their own age rules.
Because feedback and Community posts are public, we ask parents to supervise younger children using those parts of the app. If you believe a child has posted personal information, email us and we will remove it promptly.
21. Changes to this policy
We update this page when the app changes or the law requires it. The “last updated” date at the top always reflects the current version, and for anything significant we will say so in the app as well. Continuing to use Daily Muslim after a change means you accept the updated policy.