Privacy Policy
This comprehensive privacy policy governs all applications developed and published by myquranpak Organisation. We are committed to protecting your privacy and personal data across our entire ecosystem of Islamic applications.
This privacy policy applies to all current and future applications published under the myquranpak Organisation developer account on Google Play Store:
1 Scope & Applicability
This Privacy Policy ("Policy") describes how myquranpak Organisation ("we", "us", "our", or "the Company") collects, uses, stores, shares, and protects information when you use any of our mobile applications (collectively, the "Apps"), our website at www.myquranpak.cloud (the "Website"), and any related services, features, or content (collectively, the "Service").
This Policy applies to:
- All mobile applications currently published under the myquranpak Organisation developer account on Google Play Store.
- All mobile applications that will be published in the future by myquranpak Organisation.
- Our website and any web-based administration panels.
- Any APIs, backend services, and cloud infrastructure supporting these applications.
2 Information We Collect
We collect different types of information depending on which App you use and which features you interact with. Not all apps collect all data types listed below.
2.1 Information You Provide Directly
- Account Registration: Name, email address, and password when you create an account. If you use Google Sign-In, we receive your Google profile name, email, and profile photo URL as permitted by your Google account settings.
- Profile Information: Display name, username, biography, profile photo, cover photo, website URL, phone number, city, state, country, and address that you optionally provide.
- User-Generated Content: Posts, comments, likes, text messages, images, videos, audio recordings, documents, contact shares, location shares, and poll votes submitted through social features and chat functionality.
- Identity Verification Documents: If you choose to verify your identity on our Super-App platform, we collect selfie captures and government-issued identification documents (national ID card or passport). These are used strictly for community trust, moderation, and anti-fraud purposes.
- Payment & Transaction Data: If you purchase ad-free access or other premium features, we collect payment reference details (transaction IDs, receipt screenshots). We do not directly store credit card numbers, bank account numbers, or any full financial credentials.
- Customer Support Communications: Any emails, messages, or feedback you send to our support team.
2.2 Information Collected Automatically
- Device Information: Device model, manufacturer, operating system version, app version, unique device identifiers, screen resolution, language preferences, and timezone.
- Usage Analytics: Session timestamps, features accessed, pages viewed, Quran reading progress, Hadith browsing history, prayer tracking records, XP/gamification scores, leaderboard rankings, and interaction patterns.
- Log & Diagnostic Data: IP addresses, request timestamps, API endpoints accessed, error logs, crash reports, and performance metrics.
- Location Data (Country-Level Only): We determine your approximate country from your IP address (through Cloudflare headers or IP geolocation APIs) for prayer time calculations, localized content delivery, and relevant regional popup campaigns. We do NOT collect precise GPS coordinates unless you explicitly use features like Qibla Finder, which processes compass data locally on your device only.
- Notification Tokens: Push notification tokens (OneSignal Player IDs) for delivering notifications.
2.3 Information from Third-Party Sources
- Google Sign-In: Public profile information (name, email, profile picture) as permitted by your Google account privacy settings.
- Google Play: Download counts, app ratings, and review data (publicly available).
2.4 Data Collected Per App Category
The following table summarizes data collection across our different app types:
| Data Type | Super-App (myquranpak) | Quran Apps | Hadith Apps |
|---|---|---|---|
| Account/Login | Yes | Yes | Yes |
| Profile Info | Full | Basic | Basic |
| Social/Chat Data | Yes | No | No |
| Identity Verification | Optional | No | No |
| Prayer/XP/Gamification | Yes | No | No |
| Usage Analytics | Yes | Yes | Yes |
| Advertising (AdMob) | Yes | Yes | Yes |
| Push Notifications | Yes | Yes | Yes |
| Device Info | Yes | Yes | Yes |
3 How We Use Your Information
We use the information we collect for the following specific purposes:
- Service Delivery: To operate, maintain, and provide you with the features and functionality of our Apps — including Quran reading, Hadith study, prayer tracking, social networking, messaging, gamification, and other Islamic tools.
- Account Management: To create, authenticate, and manage your user account across our platform, including Google Sign-In integration and multi-device session management.
- Personalization: To customize your experience including prayer time schedules based on your detected country, Quran bookmarks, reading progress, preferred language, and content recommendations.
- Communication: To send you important notifications such as prayer reminders (Adhan alerts), direct message notifications, community updates, system announcements, and security alerts.
- Safety & Moderation: To verify user identities, moderate user-generated content (posts, comments, media), detect and prevent fraud, abuse, spam, and violations of our Terms of Service.
- Gamification & Rewards: To calculate and display XP scores, prayer streaks, leaderboard rankings, level progress, and physical gift eligibility.
- Analytics & Improvement: To understand how users interact with our Apps, diagnose technical issues, track performance metrics, and improve our features and user experience over time.
- Advertising: To display advertisements through Google AdMob to users who have not purchased ad-free access. Ad-related data helps serve relevant ads and measure ad performance.
- Legal Compliance: To comply with applicable laws, regulations, legal processes, or governmental requests.
4 Data Sharing & Disclosure
We may share your data only in the following strictly limited circumstances:
- With Your Consent & Public Actions: Information you choose to make public (posts, profile, comments, username) is visible to other users. Chat messages are only shared with the intended recipient.
- Trusted Service Providers: With third-party service providers who help us operate our Service (cloud hosting, database management, push notifications, analytics, advertising), all bound by strict confidentiality and data processing agreements.
- Legal Requirements: When disclosure is required by law, regulation, subpoena, court order, or governmental authority, or to protect the rights, property, or safety of myquranpak, our users, or the public.
- Safety & Anti-Fraud: When necessary to detect, prevent, or address fraud, security threats, or technical issues affecting our Service.
- Business Transfers: In connection with a merger, acquisition, reorganization, or sale of all or substantially all of our assets. In such an event, you will be notified before your personal data is transferred and becomes subject to a different privacy policy.
- Aggregated & Anonymized Data: We may share aggregated, anonymized statistics (e.g., total downloads, total prayer tracks, regional usage) that cannot be used to identify individual users.
5 Third-Party Services & SDKs
Our Apps integrate with trusted third-party services. Each service has its own privacy policy governing data it collects. We encourage you to review these policies:
Google AdMob
Cloudflare (R2 & CDN)
For more information about how Google uses data from apps that use their services, visit: How Google uses data when you use our partners' sites or apps.
6 Advertising (Google AdMob)
All our Apps use Google AdMob to serve advertisements. This helps us sustain free access to Islamic content. AdMob may collect and process certain data to deliver personalized or non-personalized ads:
- Advertising Identifiers: Google Advertising ID (GAID) for ad targeting and frequency capping.
- IP Address: Used for approximate geolocation (country-level) and fraud prevention.
- Device Information: Model, OS version, screen dimensions, and connectivity type to serve appropriate ad formats.
- Ad Interaction Data: Clicks, impressions, views, and conversion data to measure ad performance.
- App Usage Context: The general category of content being viewed (non-specific) to serve contextually relevant ads.
Option 1 — Device Settings: On Android, go to Settings → Google → Ads → Opt out of Ads Personalization (or "Delete advertising ID" on newer Android versions). This stops personalized ads across all apps.
Option 2 — Ad-Free Purchase: In our Super-App (myquranpak), you can purchase the ad-free experience to remove all advertisements entirely.
Option 3 — Google Ads Settings: Visit adssettings.google.com to manage your Google ad preferences globally.
7 Push Notifications
Our Apps use OneSignal push notification service to deliver:
- Prayer Reminders: Adhan alerts and prayer time notifications based on your country.
- Message Notifications: Real-time alerts for incoming chat messages and social interactions (Super-App only).
- System Announcements: App updates, feature releases, and important service notifications.
- Broadcast Campaigns: Occasional Islamic reminders, event announcements, and community updates from our admin team.
When you enable push notifications, a unique device token (OneSignal Player ID) is generated and stored on our servers. This token does not contain your personal identity and is used solely to route notifications to your device.
8 Permissions & Device Access
Our Apps may request the following device permissions. All permissions are optional and can be revoked at any time through your Android device settings:
| Permission | Purpose | Required? |
|---|---|---|
| Internet | Core app functionality, data sync, content loading, authentication | Required |
| Camera | Profile photo capture, identity verification selfie, media sharing | Optional |
| Storage / Photos | Upload images/videos, save offline content, access gallery for posts | Optional |
| Microphone | Record audio messages in chat | Optional |
| Location | Qibla direction finder, prayer time calculations | Optional |
| Notifications | Adhan alerts, message alerts, prayer reminders | Optional |
| Contacts | Share contact cards in chat messages | Optional |
| Vibration | Haptic feedback for Tasbih counter and notifications | Optional |
We follow the principle of least privilege — we only request permissions that are necessary for the specific feature you are using, and only at the moment you use that feature (runtime permissions).
9 Data Retention & Storage
We retain your personal information only for as long as is necessary to fulfill the purposes described in this Policy. Our retention schedule:
- Account Data: Retained for as long as your account remains active. Upon account deletion, all personal data is permanently removed within 30 days.
- Identity Verification Documents: Stored in encrypted Cloudflare R2 buckets. Retained only until the verification review is complete. If your account is deleted, all verification documents are permanently erased immediately as part of the cascading deletion process.
- User-Generated Content: Posts, comments, chat messages, and uploaded media are retained until you delete them individually or delete your entire account.
- Prayer & Gamification Data: XP scores, prayer tracking records, streaks, and leaderboard history are retained while your account is active and permanently deleted with your account.
- Chat Messages: Real-time messages are stored in our database and retained until either participant deletes them or until account deletion triggers cascading cleanup.
- Server & API Logs: Technical access logs and error logs are retained for up to 90 days for security monitoring and debugging, then automatically purged.
- Aggregated Analytics: Anonymized, aggregated usage statistics (which cannot identify individual users) may be retained indefinitely for service improvement purposes.
10 Data Security Measures
We implement comprehensive, industry-standard security measures to protect your personal data at every layer of our infrastructure:
- Encryption in Transit: All data transmitted between your device and our servers is encrypted using HTTPS/TLS protocols. Our servers enforce HSTS (HTTP Strict Transport Security).
- Password Hashing: User passwords are irreversibly hashed using bcrypt with salt rounds before storage. We never store plaintext passwords. Even our own engineers cannot see your password.
- Helmet Security Headers: Our web server uses Helmet.js to set secure HTTP headers including Content-Security-Policy (CSP), X-Frame-Options, X-Content-Type-Options, and more.
- Input Sanitization: All user inputs are sanitized against Cross-Site Scripting (XSS), HTML injection, and NoSQL injection attacks using multi-layer sanitization (HTML tag stripping + mongo-sanitize).
- Rate Limiting: API endpoints are protected with granular rate limiting to prevent brute-force attacks, credential stuffing, and denial-of-service (DoS) attacks. Authentication endpoints have stricter limits.
- Role-Based Access Control (RBAC): Strict role-based permissions limit internal access to user data. Admin actions are logged and audited.
- Secure File Storage: All user-uploaded files and verification documents are stored in encrypted Cloudflare R2 buckets with signed, time-limited access URLs.
- CORS Protection: Cross-Origin Resource Sharing is restricted to only our authorized domains (myquranpak.cloud).
- Reverse Proxy & WAF: Our servers are protected behind Cloudflare's Web Application Firewall (WAF) and DDoS protection layers.
- Session Security: Device session management allows you to monitor and revoke access from any logged-in device.
- Continuous Monitoring: We continuously monitor our systems for security vulnerabilities, unauthorized access attempts, and anomalous activity patterns.
11 Your Rights & Choices
You have the following rights regarding your personal data. These rights apply regardless of which app you use:
- Right to Access: You can view and review your personal information at any time through your profile settings within the App.
- Right to Correction: You can update or correct your personal information (name, email, photo, bio, location, etc.) directly through the App's profile editing features.
- Right to Deletion: You have the right to permanently delete your account and all associated data at any time. See Section 12 (Account & Data Deletion) for complete details.
- Right to Data Portability: You may request a machine-readable copy of your personal data by contacting us at the email address listed below. We will respond within 30 days.
- Right to Restrict Processing: You may request that we limit the processing of your personal data under certain circumstances (e.g., while a dispute is being resolved).
- Right to Object: You may object to the processing of your personal data for direct marketing or profiling purposes.
- Notification Opt-Out: You can disable push notifications through your device settings or app settings at any time without affecting your account.
- Ad Personalization Opt-Out: You can opt out of personalized advertising through your Android device settings or purchase the ad-free experience within our App.
- Withdrawal of Consent: Where processing is based on your consent, you may withdraw it at any time by contacting us or adjusting your settings. Withdrawal does not affect the lawfulness of prior processing.
To exercise any of these rights, contact us at myquranpakofficial@gmail.com. We will acknowledge your request within 72 hours and fulfill it within 30 business days.
12 Account & Data Deletion
You may delete your account at any time directly from within the App (Settings → Account → Delete Account). You can also request account deletion by emailing us. When you delete your account, the following comprehensive cleanup process is executed:
Database Deletion (Cascading)
- User profile record (name, email, username, bio, all personal fields)
- All posts, comments, likes, and bookmarks authored by you
- All chat conversations and individual messages
- All follow/follower relationships
- All notification history and read receipts
- Prayer tracking records, XP scores, and gamification progress
- Gift claim records and reward history
- All active device sessions and authentication tokens
- Admin moderation logs related to your account
- Report history (both reports you filed and reports filed against you)
Cloud Storage Deletion
- Profile photo and cover photo from Cloudflare R2
- All uploaded media files (images, videos, audio) from Cloudflare R2
- Identity verification documents (selfie, ID scans) permanently purged from R2
- All cached thumbnails and processed media variants
External Service Cleanup
- OneSignal push notification tokens and player records are deactivated
- Authentication sessions are revoked across all devices
13 Children's Privacy
Our Service is not directed to children under the age of 13 (or the applicable minimum age of digital consent in your jurisdiction, e.g., 16 in the European Economic Area under GDPR). We do not knowingly collect personally identifiable information from children under these age thresholds.
While our apps contain Islamic educational content suitable for all ages, the account registration and social features require users to meet the minimum age requirement.
If you are a parent or guardian and you become aware that your child has provided us with personal information without your consent, please immediately contact us at myquranpakofficial@gmail.com. If we become aware that we have collected personal data from a child under the applicable age without verified parental consent, we will take immediate steps to delete that information from our servers and all associated cloud storage.
14 International Data Transfers
Your information may be transferred to, and maintained on, servers and systems located outside your country of residence, including regions where data protection laws may differ from those in your jurisdiction. Our primary infrastructure is distributed across:
- MongoDB Atlas: Cloud database clusters (multi-region deployment)
- Cloudflare R2: Global edge storage and CDN (distributed worldwide)
- Application Servers: Backend compute infrastructure
By using our Service, you consent to the transfer of your information to these locations. We take appropriate contractual and technical measures to ensure your data is treated securely and in accordance with this Privacy Policy, regardless of where it is processed or stored.
For users in the European Economic Area (EEA), UK, or other jurisdictions with data transfer restrictions, we rely on standard contractual clauses and other legally approved transfer mechanisms where applicable.
15 Cookies & Tracking Technologies
Our mobile applications do not use browser cookies. However, our website (www.myquranpak.cloud) and web-based admin panel may use:
- Essential Cookies: For authentication session management (admin panel login). These are strictly necessary for the service to function.
- Security Cookies: CSRF tokens and session identifiers to prevent cross-site request forgery attacks.
We do not use any third-party tracking cookies, social media pixels, or cross-site advertising trackers on our website.
Our mobile apps may use the following local storage mechanisms:
- SharedPreferences / Secure Storage: To save your login state, theme preferences, reading progress, and offline settings locally on your device.
- SQLite / Local Database: For caching Quran text, Hadith data, and downloaded content for offline access.
16 Google Play Data Safety Disclosures
In accordance with Google Play's Data Safety requirements, we provide the following summary of our data practices. This information is also reflected in each app's Data Safety section on the Google Play Store:
- Data Encrypted in Transit: Yes — all data transmitted between the app and our servers is encrypted.
- Data Deletion Mechanism: Yes — users can request data deletion through in-app settings or by contacting us directly.
- Data Shared with Third Parties: Limited sharing with service providers (Google AdMob for advertising, OneSignal for notifications, Cloudflare for storage) as described in this Policy.
- Data Collected: Personal info (name, email), app activity (feature usage), and device/app info (device identifiers, app version) — as detailed in Section 2 of this Policy.
17 Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other operational factors. When we make changes:
- Minor Changes: We will update the "Last Updated" date at the top of this page. Continued use of the Service after such changes constitutes acceptance of the updated Policy.
- Material Changes: For significant changes that affect your rights or how we handle your data, we will provide prominent notice through one or more of the following: in-app push notification, in-app popup announcement, email notification (if we have your email), or a banner on our website.
- Consent Re-Collection: Where required by applicable law, we will seek your renewed consent before applying any material changes to the processing of your data.
We encourage you to periodically review this page for the latest information on our privacy practices. You can always access the current version at www.myquranpak.cloud/privacy-policy.
18 Contact Us
If you have any questions, concerns, complaints, or data requests regarding this Privacy Policy or our data practices, please contact us through any of the following channels:
| Organisation | myquranpak Organisation |
| myquranpakofficial@gmail.com | |
| Website | www.myquranpak.cloud |
| Developer Account | myquranpak Organisation (Google Play) |
| Response Time | Acknowledgment within 72 hours; resolution within 30 business days |