Privacy

Privacy Policy

Last updated 15 August 2026. Version 1.1.

This policy explains what Sirat does with your information. We have tried to write it the way we would explain it to a friend, because a privacy policy nobody can read is not really a privacy policy.

If anything here is unclear, or if you think we have got something wrong, write to us at sirat.support@gmail.com and we will fix the wording.

The short version

  • You can use almost all of Sirat without an account. If you never sign in, your data never leaves your phone.
  • We do not sell your data, and we do not share it for advertising. There are no ad networks in this app and no advertising identifiers.
  • We never read your journal, and we do not train anything on it.
  • Your location is used on your phone to work out prayer times. Your coordinates are not sent to us.
  • The analytics we run count events, not content. We can see that a reading session happened. We cannot see what you read.
  • If you join the Android test from this website, we keep only the Google Play email you submit. It is not added to a newsletter.
  • You can export everything and then delete everything, from inside the app, whenever you like.

The rest of this page is the detail behind those points.

Who we are

Sirat is made and operated from Pakistan by the team behind it. When this policy says “we”, “us” or “our”, that is who it means.

OperatorSirat
Established inPakistan
Privacy contactsirat.support@gmail.com
Data protection contactsirat.support@gmail.com

Every request in this policy is answered from that one inbox, by a person, and we do not put a request at the back of a queue for arriving by email rather than by post.

If you are in the UK, the EEA or anywhere else with a similar law, we are the controller of the data described here. That means we decide what is collected and why, and we are the ones answerable for it.

Three ways to use Sirat

How much we hold depends entirely on how you choose to use the app. This is the most important section on the page.

Local only. You install the app, set your location, and start. There is no account and no sign in. Everything you do, every prayer you log, everything you write, every bookmark, sits in storage on your phone. We cannot see any of it, we cannot recover it if you lose your phone, and deleting the app deletes all of it.

Signed in. You create an account with an email address, or with Apple or Google. Now your practice is backed up so you can move to a new phone and pick up where you left off. This is the point at which data starts being stored on our servers, and the tables below describe it.

In a circle. You join a small private group with people you know. The others in that circle can see your display name and the fact that you completed things. They cannot see what you wrote, what you read, what you searched for, or where you are. More on that in Who else touches your data.

You can move between these. Signing out returns you to a local install. Leaving a circle takes your history in that circle with you.

Permissions we ask for

Every one of these is asked for at the moment it is needed, never on first launch, and all of them can be declined. Here is what each one is for and what happens if you say no.

PermissionWhat we do with itIf you decline
Location, while using the appWork out prayer times and the qibla direction for where you are. The calculation happens on your phone using the adhan library.The app asks you to pick a city instead. Everything still works, just with less precision.
NotificationsPrayer reminders, streak nudges, and challenge updates that you have asked for.No reminders. Every other part of the app is unaffected.
Network accessBacking up your account, syncing circles, checking your subscription.Local only mode. Nothing breaks; nothing syncs.
Storage on the deviceKeeping your data, your settings and your offline Qur’an text on the phone.The app cannot function without this one.

We do not ask for, and the app contains no code that could use: your camera, your microphone, your photo library, your contacts, your calendar, your call or message logs, your health records, your background location, or any advertising identifier.

Your latitude and longitude are used on the device and are not transmitted to us. If you choose to set a city, we store the name of the city, not your coordinates.

What we collect

Things you give us

WhatWhenWhere it lives
Email address, and a display name if you set oneWhen you create an accountOur servers
Google Play emailIf you ask to join the Android closed test on this websiteOur servers
Sign in identifier from Apple or GoogleIf you use one of thoseOur servers
Prayers, habits and acts you mark completeEvery time you tap a markYour phone, and our servers if signed in
Streak, shields, repairs and excused daysAs you use the appYour phone, and our servers if signed in
Journal entries and reflectionsWhen you write themYour phone, and our servers if signed in
Qur’an bookmarks and reading positionsAs you readYour phone, and our servers if signed in
Habits, goals and challenges you pickWhen you set them upYour phone, and our servers if signed in
Settings: calculation method, madhhab, reminder times, theme, languageWhen you change themYour phone, and our servers if signed in
City name, if you choose one instead of using locationWhen you set itYour phone, and our servers if signed in
Circle membership and your activity inside itWhen you join a circleOur servers
Reports you send us about something in a circleWhen you reportOur servers

Things collected automatically

WhatWhyWho processes it
Device model, operating system version, app version, language, coarse regionSo we can tell whether a bug affects everyone or only one kind of phoneFirebase, Sentry
Crash reports and error tracesFixing crashesSentry
Event counts: screen opened, session started, subscription screen shownUnderstanding which parts of the app people actually useFirebase Analytics
A random installation identifierTying a crash to a session without tying it to youFirebase, Sentry
IP address, at the moment of a requestUnavoidable in how the internet works. Used for security and rough region, then droppedFirebase, Sentry
Subscription status and store receiptUnlocking Plus and honouring refundsRevenueCat, Apple, Google
Browser and network signals, including IP address, browser type and challenge resultStopping automated abuse of the Android tester formCloudflare Turnstile

The analytics events are a fixed list of about twenty names. Not one of them carries the content of anything you wrote, read, recited or searched for. An event can say a journal entry was saved. It cannot say what was in it.

The sensitive parts: faith and health

Two kinds of information in Sirat get extra protection under the GDPR, the UK GDPR and several other laws. We would rather tell you about them plainly than bury them.

Your religion

Sirat is a Muslim prayer and habit app. Using it reveals that you are probably Muslim, and the record of your prayers is a record of religious practice. Under Article 9 of the GDPR that is special category data, and we rely on your explicit consent to hold it. The consent is what you give when you create an account and choose to back your practice up.

You can take that consent back at any time by signing out or deleting your account. Doing so does not stop you using the app locally, and it does not make anything you did before that point unlawful.

Excused days, and why they may be health data

Sirat lets you mark a period as excused so your streak is held rather than broken. The reasons you can pick include travelling, unwell, and a general excused option that many women will use for menstruation.

The moment you pick “unwell” or “excused”, that setting can reveal something about your health. We treat it as health data and hold it to the same Article 9 standard, on the same basis of explicit consent. Specifically:

  • It is never sent to any analytics service. Not the fact that it is on, not which reason you chose.
  • It is never visible to anyone in a circle. Other members see that your streak is intact. They see no reason and no label.
  • It is never used to target you with anything, because we do not target you with anything.
  • It is deleted along with the rest of your account when you delete it.

If you would rather this never left your phone at all, use the app signed out.

Why we are allowed to hold it

Different pieces of data rest on different legal grounds. If you are covered by the GDPR or UK GDPR, this is the table your regulator will want to see.

WhatGroundIn plain terms
Your account, sync and backupPerformance of a contract, Article 6(1)(b)You asked us to keep your practice safe across devices
Records of worship, and excused daysExplicit consent, Article 9(2)(a)You chose to store religious and health related data with us, and you can withdraw that
Reminders you have switched onConsent, Article 6(1)(a)You asked to be reminded, and you can stop it in one tap
Crash reports and product analyticsLegitimate interests, Article 6(1)(f)Keeping the app working and knowing what to build next, weighed against your privacy and limited to non content signals
Circle moderation and abuse handlingLegitimate interests, and legal obligationKeeping people safe and meeting store safety rules
Payments, tax records, refundsContract, and legal obligationWe have to keep financial records for the tax authority
Answering your emails to usLegitimate interestsYou wrote to us and we would like to write back
Android tester emailConsent, Article 6(1)(a)You asked us to invite your Google Play account to the closed test; you can withdraw that request by email

Children and teenagers

Sirat is rated as suitable for all ages, and a young child can absolutely use the app on a parent’s phone in local only mode. Accounts are different.

  • You must be at least 13 to create a Sirat account.
  • In the EEA and the UK you must be at least 16, or the age your own country sets, whichever is higher.
  • Circles are for account holders only, so the same minimum applies.

We do not knowingly collect personal information from a child under 13. We do not ask for a birth date beyond checking you are old enough, we run no age inference, and we build no profiles of anyone. If we learn that an account belongs to a child under 13 we delete it and its data promptly.

If you are a parent or guardian and think your child has created an account, write to sirat.support@gmail.com and we will remove it. You do not need a lawyer and you do not need to prove anything elaborate.

Local only mode remains available to everyone, at any age, with no account and no data leaving the device.

Who else touches your data

Circles

A circle is a small private group you are invited into. Inside one, other members can see:

  • your display name,
  • that you completed things, and how your streak is doing,
  • messages you deliberately post to the circle.

They cannot see your journal, your reading, your searches, your location, your city, your email address, your excused reasons, or anything from a circle they are not in. Circles are not public, are not indexed, and are not discoverable. There is no directory.

Anyone can report a message or a member. We aim to look at reports within 72 hours and you can block a member yourself at any time without waiting for us. To use circles at all you need a verified email address, which is a deliberate speed bump against throwaway accounts.

Companies that process data for us

These are our processors. Each one is contractually bound to use your data only for what we ask, and none of them is allowed to use it for their own purposes.

WhoWhat they doWhere
Google Firebase (Auth, Firestore, Functions, Storage)Accounts, database, sync, backendGoogle Cloud, region set at project level
Google Analytics for FirebaseAnonymous event counts, no advertising features enabledGoogle
SentryCrash and error reportingSentry
RevenueCatSubscription state and receipt validationRevenueCat
AppleApp Store distribution, in app purchase, Sign in with AppleApple
Google PlayPlay distribution, billing, Google Sign inGoogle
ExpoOver the air app updatesExpo
Cloudflare TurnstileChecks the Android tester form for automated abuse using browser and network signalsCloudflare

Apple and Google run their own payment systems under their own privacy policies. We never see your card number, and we could not collect it if we wanted to.

Everyone else

Nobody. We do not sell personal information. We do not share it for cross context behavioural advertising. We do not rent, trade or barter it. There is no data broker in this picture.

We would disclose data if a valid legal order compelled us, or if it were genuinely necessary to prevent serious harm. If that ever happens we will tell you, unless we are legally forbidden from doing so.

If Sirat is ever sold or merged, your data may move to the buyer. We will tell you first, and the commitments on this page travel with it.

Where your data goes and how long we keep it

Our providers run infrastructure in several countries, so your data may be processed outside the country you live in. When it leaves the EEA or the UK we rely on the European Commission’s Standard Contractual Clauses, the UK International Data Transfer Addendum, or an adequacy decision, whichever fits.

WhatHow long
Account and practice dataUntil you delete your account
Data in a dormant accountDeleted after 24 months of no sign in, after we email you first
Journal entriesUntil you delete them, or delete your account
Analytics events14 months, then automatically dropped
Crash reports90 days
Circle messagesUntil the circle is deleted, or you leave and take yours with you
Moderation and abuse recordsUp to 24 months after the report is closed
Payment and tax recordsAs long as tax law requires, usually 6 to 7 years
BackupsRolling, overwritten within 35 days
Android tester emailUntil the test ends, you ask us to remove it, or 12 months pass, whichever comes first

Your rights, and how to use them

Some of these rights come from the GDPR, some from the CCPA, some from other laws. Rather than make you work out which applies to you, we honour all of them for everyone, everywhere. It is simpler for you and simpler for us.

  • See it. Get a copy of everything we hold about you.
  • Take it with you. Export it in a machine readable file you can move somewhere else.
  • Fix it. Correct anything wrong.
  • Delete it. Erase your account and its contents. See Deleting everything.
  • Limit it. Ask us to stop certain processing while a dispute is sorted out.
  • Object. Tell us to stop processing that rests on legitimate interests.
  • Withdraw consent. Turn off reminders, or stop storing your practice with us, without losing the app.
  • Do not sell or share. Standing answer: we never do, for anyone.
  • No automated decisions. There are none. Nothing about your account is decided by an algorithm without a human.
  • Complain. To us first, we hope, and to your regulator whenever you like.

How to ask. Export and delete are inside the app under Settings, then Your data. For anything else—including removal from the Android testing list—email sirat.support@gmail.com from the relevant address. We reply within 30 days, usually much sooner. It is free. If a request is genuinely repetitive or excessive we may say so and explain why, but the default is that we just do it.

No retaliation. Using any of these rights will never get you a worse app, a higher price, or a slower service. That would be illegal in several places and wrong in all of them.

Complaints. If you are in the EEA or the UK you can complain to your national data protection authority. In the UK that is the Information Commissioner’s Office. You do not have to come to us first, though we would like the chance to sort it out.

Deleting everything

You can delete your account and its data from Settings, then Account, then Delete account. It happens immediately.

If you cannot get into the app, email sirat.support@gmail.com with the subject “Delete my account”. We confirm within 72 hours and finish within 30 days.

A short list of things survives deletion because the law requires it: payment records, moderation records, security logs, and backups until they rotate out. The full picture, including what happens to circles you created and why deleting your account does not cancel your subscription, is on the Delete your account page.

How we protect it

  • Everything in transit is encrypted with TLS. Everything at rest on our servers is encrypted.
  • Access to production data is limited to the people who need it, and it is logged.
  • Database rules deny by default. A rule has to explicitly allow a read before it happens, and every write is checked for size and shape.
  • Firebase App Check is on, so requests have to come from a genuine copy of the app.
  • We never handle your card details. Apple and Google do that.
  • If you use email and password, your password is hashed by Firebase Authentication and is never visible to us.

No system is perfect, and anyone who tells you otherwise is selling something. If a breach ever affects your rights, we will notify the relevant regulator within 72 hours and tell you directly without undue delay.

If you have found a security problem, please tell us at sirat.support@gmail.com. We will not take legal action against anyone who reports a genuine issue in good faith and gives us a reasonable chance to fix it.

If you are in a particular place

The UK and the EEA. We are the controller, and the legal grounds we rely on are set out in Why we are allowed to hold it. Two of the things Sirat holds — your religious practice, and the health reason behind an excused day — are special category data under Article 9, so we rely on your explicit consent for them and nothing else. You can withdraw that consent at any time, in the app or by email, and withdrawing it does not make what we did before it unlawful. Alongside the rights listed above you have the right to complain to your national supervisory authority: in the UK that is the Information Commissioner’s Office, and in the EEA it is the data protection authority of the country you live in. You are welcome to raise it with us first, but you do not have to. Our representative in the EU, where one is required, is named in Who we are.

California. Under the CCPA and CPRA you have the rights listed above, and they map to the California terms directly: know, delete, correct, opt out of sale or sharing, and limit use of sensitive personal information. Two things worth stating outright. First, we have not sold or shared personal information in the last twelve months, and we have no plans to. Second, we collect religious belief and, through excused days, health information, which California treats as sensitive personal information. We use it only to provide the app you asked for, which is one of the permitted purposes, so the “limit” right does not restrict anything we actually do. An authorised agent may act for you with written permission.

Nevada. We do not sell covered information, and would not even if you asked.

Virginia, Colorado, Connecticut, Utah, Texas and other US states with comprehensive privacy laws. You have rights to access, correct, delete, take a copy, and opt out of targeted advertising, sale and profiling. We do none of those three things at all. Where an appeal process is required, email us and we will handle the appeal and tell you the outcome in writing.

Canada. We handle personal information in line with PIPEDA. You can complain to the Office of the Privacy Commissioner of Canada.

Australia. We handle personal information in line with the Australian Privacy Principles. You can complain to the Office of the Australian Information Commissioner.

Brazil. You have the LGPD rights of confirmation, access, correction, anonymisation, portability, deletion and information about sharing. Email us to use any of them.

Everywhere else. Use the rights in Your rights, and how to use them. We do not check your address before answering.

When this policy changes

We will update this page when the app changes. The version and date are at the top.

If a change materially affects your rights, we will tell you inside the app and by email at least 30 days before it takes effect, so you have time to read it, ask about it, or leave. We will never quietly widen what we collect and hope you do not notice.

Talk to us

Privacy questions and requestssirat.support@gmail.com
Data protection contactsirat.support@gmail.com
Something wrong in a circlesirat.support@gmail.com
Everything elsesirat.support@gmail.com

Related pages: Terms of Service, Licence agreement, Delete your account.