Privacy
Privacy Policy
Last updated 15 August 2026. Version 1.1.
This policy explains what Sirat does with your information. We have tried to write it the way we would explain it to a friend, because a privacy policy nobody can read is not really a privacy policy.
If anything here is unclear, or if you think we have got something wrong, write to us at sirat.support@gmail.com and we will fix the wording.
The short version
- You can use almost all of Sirat without an account. If you never sign in, your data never leaves your phone.
- We do not sell your data, and we do not share it for advertising. There are no ad networks in this app and no advertising identifiers.
- We never read your journal, and we do not train anything on it.
- Your location is used on your phone to work out prayer times. Your coordinates are not sent to us.
- The analytics we run count events, not content. We can see that a reading session happened. We cannot see what you read.
- If you join the Android test from this website, we keep only the Google Play email you submit. It is not added to a newsletter.
- You can export everything and then delete everything, from inside the app, whenever you like.
The rest of this page is the detail behind those points.
Who we are
Sirat is made and operated from Pakistan by the team behind it. When this policy says “we”, “us” or “our”, that is who it means.
| Operator | Sirat |
| Established in | Pakistan |
| Privacy contact | sirat.support@gmail.com |
| Data protection contact | sirat.support@gmail.com |
Every request in this policy is answered from that one inbox, by a person, and we do not put a request at the back of a queue for arriving by email rather than by post.
If you are in the UK, the EEA or anywhere else with a similar law, we are the controller of the data described here. That means we decide what is collected and why, and we are the ones answerable for it.
Three ways to use Sirat
How much we hold depends entirely on how you choose to use the app. This is the most important section on the page.
Local only. You install the app, set your location, and start. There is no account and no sign in. Everything you do, every prayer you log, everything you write, every bookmark, sits in storage on your phone. We cannot see any of it, we cannot recover it if you lose your phone, and deleting the app deletes all of it.
Signed in. You create an account with an email address, or with Apple or Google. Now your practice is backed up so you can move to a new phone and pick up where you left off. This is the point at which data starts being stored on our servers, and the tables below describe it.
In a circle. You join a small private group with people you know. The others in that circle can see your display name and the fact that you completed things. They cannot see what you wrote, what you read, what you searched for, or where you are. More on that in Who else touches your data.
You can move between these. Signing out returns you to a local install. Leaving a circle takes your history in that circle with you.
Permissions we ask for
Every one of these is asked for at the moment it is needed, never on first launch, and all of them can be declined. Here is what each one is for and what happens if you say no.
| Permission | What we do with it | If you decline |
|---|---|---|
| Location, while using the app | Work out prayer times and the qibla direction for where you are. The calculation happens on your phone using the adhan library. | The app asks you to pick a city instead. Everything still works, just with less precision. |
| Notifications | Prayer reminders, streak nudges, and challenge updates that you have asked for. | No reminders. Every other part of the app is unaffected. |
| Network access | Backing up your account, syncing circles, checking your subscription. | Local only mode. Nothing breaks; nothing syncs. |
| Storage on the device | Keeping your data, your settings and your offline Qur’an text on the phone. | The app cannot function without this one. |
We do not ask for, and the app contains no code that could use: your camera, your microphone, your photo library, your contacts, your calendar, your call or message logs, your health records, your background location, or any advertising identifier.
Your latitude and longitude are used on the device and are not transmitted to us. If you choose to set a city, we store the name of the city, not your coordinates.
What we collect
Things you give us
| What | When | Where it lives |
|---|---|---|
| Email address, and a display name if you set one | When you create an account | Our servers |
| Google Play email | If you ask to join the Android closed test on this website | Our servers |
| Sign in identifier from Apple or Google | If you use one of those | Our servers |
| Prayers, habits and acts you mark complete | Every time you tap a mark | Your phone, and our servers if signed in |
| Streak, shields, repairs and excused days | As you use the app | Your phone, and our servers if signed in |
| Journal entries and reflections | When you write them | Your phone, and our servers if signed in |
| Qur’an bookmarks and reading positions | As you read | Your phone, and our servers if signed in |
| Habits, goals and challenges you pick | When you set them up | Your phone, and our servers if signed in |
| Settings: calculation method, madhhab, reminder times, theme, language | When you change them | Your phone, and our servers if signed in |
| City name, if you choose one instead of using location | When you set it | Your phone, and our servers if signed in |
| Circle membership and your activity inside it | When you join a circle | Our servers |
| Reports you send us about something in a circle | When you report | Our servers |
Things collected automatically
| What | Why | Who processes it |
|---|---|---|
| Device model, operating system version, app version, language, coarse region | So we can tell whether a bug affects everyone or only one kind of phone | Firebase, Sentry |
| Crash reports and error traces | Fixing crashes | Sentry |
| Event counts: screen opened, session started, subscription screen shown | Understanding which parts of the app people actually use | Firebase Analytics |
| A random installation identifier | Tying a crash to a session without tying it to you | Firebase, Sentry |
| IP address, at the moment of a request | Unavoidable in how the internet works. Used for security and rough region, then dropped | Firebase, Sentry |
| Subscription status and store receipt | Unlocking Plus and honouring refunds | RevenueCat, Apple, Google |
| Browser and network signals, including IP address, browser type and challenge result | Stopping automated abuse of the Android tester form | Cloudflare Turnstile |
The analytics events are a fixed list of about twenty names. Not one of them carries the content of anything you wrote, read, recited or searched for. An event can say a journal entry was saved. It cannot say what was in it.
The sensitive parts: faith and health
Two kinds of information in Sirat get extra protection under the GDPR, the UK GDPR and several other laws. We would rather tell you about them plainly than bury them.
Your religion
Sirat is a Muslim prayer and habit app. Using it reveals that you are probably Muslim, and the record of your prayers is a record of religious practice. Under Article 9 of the GDPR that is special category data, and we rely on your explicit consent to hold it. The consent is what you give when you create an account and choose to back your practice up.
You can take that consent back at any time by signing out or deleting your account. Doing so does not stop you using the app locally, and it does not make anything you did before that point unlawful.
Excused days, and why they may be health data
Sirat lets you mark a period as excused so your streak is held rather than broken. The reasons you can pick include travelling, unwell, and a general excused option that many women will use for menstruation.
The moment you pick “unwell” or “excused”, that setting can reveal something about your health. We treat it as health data and hold it to the same Article 9 standard, on the same basis of explicit consent. Specifically:
- It is never sent to any analytics service. Not the fact that it is on, not which reason you chose.
- It is never visible to anyone in a circle. Other members see that your streak is intact. They see no reason and no label.
- It is never used to target you with anything, because we do not target you with anything.
- It is deleted along with the rest of your account when you delete it.
If you would rather this never left your phone at all, use the app signed out.
Why we are allowed to hold it
Different pieces of data rest on different legal grounds. If you are covered by the GDPR or UK GDPR, this is the table your regulator will want to see.
| What | Ground | In plain terms |
|---|---|---|
| Your account, sync and backup | Performance of a contract, Article 6(1)(b) | You asked us to keep your practice safe across devices |
| Records of worship, and excused days | Explicit consent, Article 9(2)(a) | You chose to store religious and health related data with us, and you can withdraw that |
| Reminders you have switched on | Consent, Article 6(1)(a) | You asked to be reminded, and you can stop it in one tap |
| Crash reports and product analytics | Legitimate interests, Article 6(1)(f) | Keeping the app working and knowing what to build next, weighed against your privacy and limited to non content signals |
| Circle moderation and abuse handling | Legitimate interests, and legal obligation | Keeping people safe and meeting store safety rules |
| Payments, tax records, refunds | Contract, and legal obligation | We have to keep financial records for the tax authority |
| Answering your emails to us | Legitimate interests | You wrote to us and we would like to write back |
| Android tester email | Consent, Article 6(1)(a) | You asked us to invite your Google Play account to the closed test; you can withdraw that request by email |
Children and teenagers
Sirat is rated as suitable for all ages, and a young child can absolutely use the app on a parent’s phone in local only mode. Accounts are different.
- You must be at least 13 to create a Sirat account.
- In the EEA and the UK you must be at least 16, or the age your own country sets, whichever is higher.
- Circles are for account holders only, so the same minimum applies.
We do not knowingly collect personal information from a child under 13. We do not ask for a birth date beyond checking you are old enough, we run no age inference, and we build no profiles of anyone. If we learn that an account belongs to a child under 13 we delete it and its data promptly.
If you are a parent or guardian and think your child has created an account, write to sirat.support@gmail.com and we will remove it. You do not need a lawyer and you do not need to prove anything elaborate.
Local only mode remains available to everyone, at any age, with no account and no data leaving the device.
Who else touches your data
Circles
A circle is a small private group you are invited into. Inside one, other members can see:
- your display name,
- that you completed things, and how your streak is doing,
- messages you deliberately post to the circle.
They cannot see your journal, your reading, your searches, your location, your city, your email address, your excused reasons, or anything from a circle they are not in. Circles are not public, are not indexed, and are not discoverable. There is no directory.
Anyone can report a message or a member. We aim to look at reports within 72 hours and you can block a member yourself at any time without waiting for us. To use circles at all you need a verified email address, which is a deliberate speed bump against throwaway accounts.
Companies that process data for us
These are our processors. Each one is contractually bound to use your data only for what we ask, and none of them is allowed to use it for their own purposes.
| Who | What they do | Where |
|---|---|---|
| Google Firebase (Auth, Firestore, Functions, Storage) | Accounts, database, sync, backend | Google Cloud, region set at project level |
| Google Analytics for Firebase | Anonymous event counts, no advertising features enabled | |
| Sentry | Crash and error reporting | Sentry |
| RevenueCat | Subscription state and receipt validation | RevenueCat |
| Apple | App Store distribution, in app purchase, Sign in with Apple | Apple |
| Google Play | Play distribution, billing, Google Sign in | |
| Expo | Over the air app updates | Expo |
| Cloudflare Turnstile | Checks the Android tester form for automated abuse using browser and network signals | Cloudflare |
Apple and Google run their own payment systems under their own privacy policies. We never see your card number, and we could not collect it if we wanted to.
Everyone else
Nobody. We do not sell personal information. We do not share it for cross context behavioural advertising. We do not rent, trade or barter it. There is no data broker in this picture.
We would disclose data if a valid legal order compelled us, or if it were genuinely necessary to prevent serious harm. If that ever happens we will tell you, unless we are legally forbidden from doing so.
If Sirat is ever sold or merged, your data may move to the buyer. We will tell you first, and the commitments on this page travel with it.
Where your data goes and how long we keep it
Our providers run infrastructure in several countries, so your data may be processed outside the country you live in. When it leaves the EEA or the UK we rely on the European Commission’s Standard Contractual Clauses, the UK International Data Transfer Addendum, or an adequacy decision, whichever fits.
| What | How long |
|---|---|
| Account and practice data | Until you delete your account |
| Data in a dormant account | Deleted after 24 months of no sign in, after we email you first |
| Journal entries | Until you delete them, or delete your account |
| Analytics events | 14 months, then automatically dropped |
| Crash reports | 90 days |
| Circle messages | Until the circle is deleted, or you leave and take yours with you |
| Moderation and abuse records | Up to 24 months after the report is closed |
| Payment and tax records | As long as tax law requires, usually 6 to 7 years |
| Backups | Rolling, overwritten within 35 days |
| Android tester email | Until the test ends, you ask us to remove it, or 12 months pass, whichever comes first |
Your rights, and how to use them
Some of these rights come from the GDPR, some from the CCPA, some from other laws. Rather than make you work out which applies to you, we honour all of them for everyone, everywhere. It is simpler for you and simpler for us.
- See it. Get a copy of everything we hold about you.
- Take it with you. Export it in a machine readable file you can move somewhere else.
- Fix it. Correct anything wrong.
- Delete it. Erase your account and its contents. See Deleting everything.
- Limit it. Ask us to stop certain processing while a dispute is sorted out.
- Object. Tell us to stop processing that rests on legitimate interests.
- Withdraw consent. Turn off reminders, or stop storing your practice with us, without losing the app.
- Do not sell or share. Standing answer: we never do, for anyone.
- No automated decisions. There are none. Nothing about your account is decided by an algorithm without a human.
- Complain. To us first, we hope, and to your regulator whenever you like.
How to ask. Export and delete are inside the app under Settings, then Your data. For anything else—including removal from the Android testing list—email sirat.support@gmail.com from the relevant address. We reply within 30 days, usually much sooner. It is free. If a request is genuinely repetitive or excessive we may say so and explain why, but the default is that we just do it.
No retaliation. Using any of these rights will never get you a worse app, a higher price, or a slower service. That would be illegal in several places and wrong in all of them.
Complaints. If you are in the EEA or the UK you can complain to your national data protection authority. In the UK that is the Information Commissioner’s Office. You do not have to come to us first, though we would like the chance to sort it out.
Deleting everything
You can delete your account and its data from Settings, then Account, then Delete account. It happens immediately.
If you cannot get into the app, email sirat.support@gmail.com with the subject “Delete my account”. We confirm within 72 hours and finish within 30 days.
A short list of things survives deletion because the law requires it: payment records, moderation records, security logs, and backups until they rotate out. The full picture, including what happens to circles you created and why deleting your account does not cancel your subscription, is on the Delete your account page.
How we protect it
- Everything in transit is encrypted with TLS. Everything at rest on our servers is encrypted.
- Access to production data is limited to the people who need it, and it is logged.
- Database rules deny by default. A rule has to explicitly allow a read before it happens, and every write is checked for size and shape.
- Firebase App Check is on, so requests have to come from a genuine copy of the app.
- We never handle your card details. Apple and Google do that.
- If you use email and password, your password is hashed by Firebase Authentication and is never visible to us.
No system is perfect, and anyone who tells you otherwise is selling something. If a breach ever affects your rights, we will notify the relevant regulator within 72 hours and tell you directly without undue delay.
If you have found a security problem, please tell us at sirat.support@gmail.com. We will not take legal action against anyone who reports a genuine issue in good faith and gives us a reasonable chance to fix it.
If you are in a particular place
The UK and the EEA. We are the controller, and the legal grounds we rely on are set out in Why we are allowed to hold it. Two of the things Sirat holds — your religious practice, and the health reason behind an excused day — are special category data under Article 9, so we rely on your explicit consent for them and nothing else. You can withdraw that consent at any time, in the app or by email, and withdrawing it does not make what we did before it unlawful. Alongside the rights listed above you have the right to complain to your national supervisory authority: in the UK that is the Information Commissioner’s Office, and in the EEA it is the data protection authority of the country you live in. You are welcome to raise it with us first, but you do not have to. Our representative in the EU, where one is required, is named in Who we are.
California. Under the CCPA and CPRA you have the rights listed above, and they map to the California terms directly: know, delete, correct, opt out of sale or sharing, and limit use of sensitive personal information. Two things worth stating outright. First, we have not sold or shared personal information in the last twelve months, and we have no plans to. Second, we collect religious belief and, through excused days, health information, which California treats as sensitive personal information. We use it only to provide the app you asked for, which is one of the permitted purposes, so the “limit” right does not restrict anything we actually do. An authorised agent may act for you with written permission.
Nevada. We do not sell covered information, and would not even if you asked.
Virginia, Colorado, Connecticut, Utah, Texas and other US states with comprehensive privacy laws. You have rights to access, correct, delete, take a copy, and opt out of targeted advertising, sale and profiling. We do none of those three things at all. Where an appeal process is required, email us and we will handle the appeal and tell you the outcome in writing.
Canada. We handle personal information in line with PIPEDA. You can complain to the Office of the Privacy Commissioner of Canada.
Australia. We handle personal information in line with the Australian Privacy Principles. You can complain to the Office of the Australian Information Commissioner.
Brazil. You have the LGPD rights of confirmation, access, correction, anonymisation, portability, deletion and information about sharing. Email us to use any of them.
Everywhere else. Use the rights in Your rights, and how to use them. We do not check your address before answering.
When this policy changes
We will update this page when the app changes. The version and date are at the top.
If a change materially affects your rights, we will tell you inside the app and by email at least 30 days before it takes effect, so you have time to read it, ask about it, or leave. We will never quietly widen what we collect and hope you do not notice.
Talk to us
| Privacy questions and requests | sirat.support@gmail.com |
| Data protection contact | sirat.support@gmail.com |
| Something wrong in a circle | sirat.support@gmail.com |
| Everything else | sirat.support@gmail.com |
Related pages: Terms of Service, Licence agreement, Delete your account.