Privacy Policy
Effective date: 2026-09-07
Applies to the Sunnah Helper app (Android and iOS) and the website sunnahhelper.com.
Summary
- Sunnah Helper works without an account. Prayer times, reminders, tracking, the Qur'an, hadith, names and companions collections, Qibla and the widgets all run on your device, offline. That data stays on your phone.
- We show no advertising and use no crash-reporting SDK. The app does count anonymous usage — which screens and features are opened — so it can be improved where it is actually used. Never your duas, your location or anything you wrote, and never linked to your identity. You can turn it off in Settings → Data (section 8).
- Your location is used on the device to calculate prayer times and the Qibla direction. It leaves your device only if you type a city name into the search (sent to the search provider) or if you sign in and turn on cloud backup.
- If you create an account (email, Google or Apple), we store your account details and, with Sunnah Helper Plus, a backup of your settings and history on Google Firebase.
- If you ask for dua on the At-Tadāʿī wall, the text you write is sent to our server, screened and translated by AI services, and shown to other users in the languages and for the period you choose. Do not include personal details in a dua.
- Subscriptions are processed by Apple, Google and RevenueCat. We never see your card details.
- You can delete your account and all cloud data from inside the app at any time (Settings → Cloud backup & sync → Account → Delete account) or by following the steps on the account-deletion page.
1. Who we are
Sunnah Helper is developed and published by Mammad Shahmaliyev, an individual developer ("we", "us"). Contact: support@sunnahhelper.com.
2. What the app stores on your device
The following is stored locally on your phone and is not transmitted to us unless you turn on cloud backup (section 5):
- Your settings (language, theme, text size, prayer calculation method and adjustments, Hijri settings, home-screen preferences).
- Your saved location (coordinates, place name, time zone).
- Your deeds and reminder rules, including custom deeds and hint text.
- Your tracking log (which reminders you marked done, per day) and quiz results.
- Which content the app has already shown you (the rotation position of the ayah, hadith, names and companions collections), and widget preferences.
You can erase your deeds and reminders with Settings → "Reset deeds & reminders", and everything by uninstalling the app.
3. Location
- Why: prayer times, the Qibla direction, and the automatic choice of a calculation method depend on where you are. Location is optional; you can type a city instead.
- Foreground: with your permission the app reads your device location when you tap "Locate automatically" and, if "Auto-update location" is on, when the app opens.
- Background (Android "Allow all the time", iOS "Always"): requested separately and only if you agree, so that prayer times and reminders stay correct when you travel. You can decline it and the app keeps working with the last location.
- Reverse geocoding: to name your location and find your country, the coordinates are sent to your phone's platform geocoder (Apple or Google, depending on the device), under their privacy policies.
- City search: the text you type in the location search is sent to the Photon geocoding service operated by komoot (photon.komoot.io) to return matching places. Only the search text is sent, not your device location.
- Your location is not sent to us unless cloud backup is on (section 5).
4. Notifications
Reminders are local notifications scheduled on your device. The app does not use push notifications and no notification content leaves your phone.
5. Accounts and cloud backup
Creating an account is optional. It is used for cloud backup & sync (part of Sunnah Helper Plus) and for taking part in the At-Tadāʿī dua wall.
- Sign-in providers: email & password, Google, Apple — through Firebase Authentication (Google LLC). We receive your email address, a display name and profile photo URL if the provider supplies them, and a user id.
- Anonymous session: to show the dua wall before you sign in, the app may create an anonymous Firebase session (a random id, no personal data). It cannot be used to post or react.
- What is backed up (Plus, when signed in): your settings, saved location, deeds and reminder rules, tracking log and quiz history, stored in Google Cloud Firestore under your user id in the nam5 region.
- When: automatically after a change, on sign-in and on app resume, and when you tap "Sync now".
- If your subscription lapses: the backup is kept and remains readable by you; nothing is deleted until you delete the account.
- Signing out keeps your data on the device and in the cloud. Deleting the account removes the account and everything stored under it in the cloud; local data stays on the device.
6. At-Tadāʿī — the community dua wall
At-Tadāʿī lets you read other people's requests for dua and ask for dua yourself.
- Reading shows you duas other users published, translated into your language. No account is needed. Nobody's name or account is shown to anyone.
- Asking requires an account. What you type (up to 300 characters) is sent to our server (Firebase Cloud Functions, Google LLC), where it is: 1. screened by an AI model for content that is not a dua, abusive, sexual, political, spam, unsafe, or that contains personal data; 2. translated into the app's languages (also by an AI model); 3. stored as a draft for up to 30 minutes so you can review the translations; 4. published, if you confirm, in the languages you tick, for the period you choose (6 hours to 3 days), together with five AI-written responses that other readers may say for you.
- AI processing: the screening, translation and the optional "rewrite" button send your text to AI models through OpenRouter, Inc., which routes it to the model provider currently configured. Only the dua text and its language are sent; not your name, email or location. Text that is refused by the screening is not stored; a refusal is logged with a reason code but without the text.
- What we store: the published dua in each language, when it was published and until when it is visible, your user id (never shown), the count of Ameens, and any reports. Ameens you say and duas you ask are kept in your history for 30 days. Reports and blocks are stored so that hidden content stays hidden.
- Moderation: a dua reported by several users is hidden automatically. We may review reported content.
- Please do not write personal data (names, phone numbers, addresses, health details about identifiable people) into a dua. If you notice such content, use Report.
- You can delete a dua you asked from "My duas" at any time.
7. Subscriptions (Sunnah Helper Plus)
Plus is a subscription sold through the Apple App Store and Google Play.
- Payment is handled entirely by Apple or Google under their terms and privacy policies. We do not receive your payment card details.
- To know whether your subscription is active, the app uses RevenueCat (RevenueCat, Inc.), which receives a purchase receipt or token, an app user id (a random id, or your Firebase user id if you are signed in) and basic device information (platform, app version).
- When you are signed in, our server marks your account as a subscriber so the dua wall can apply the Plus limits.
- Nothing in the app that is worship is behind the subscription, and a lapsed subscription never deletes your data.
8. Usage analytics
The app counts how it is used, so it can be improved where it is actually used rather than where we guess. This is done with Google Analytics for Firebase.
What is counted. Anonymous events with no content in them: which screen was opened, whether a reminder notification was tapped, which Sunnah deeds are switched on, whether a quiz was started and finished, whether the intro was completed, when a free limit was reached, and which of four settings were changed (language, theme, text size, clock format). Three attributes are attached to each event: the app's language, whether you have Plus, and whether your phone is currently letting reminders through.
What is never counted. Nothing you write or read. Not a dua, not an ayah, not a hadith, not a companion's story, not a deed you named, not your city or coordinates, not your email, and not your account id. Where an event needs a detail it is always one of a short fixed list — a kind of deed, a collection name, a reason code — never free text and never an identifier of yours.
No advertising identifiers. The app does not use the advertising id, IDFA or any cross-app identifier. Usage data is not linked to your identity and is not used to track you across other apps or websites. On iOS this is why the app never shows the App Tracking Transparency prompt.
Turning it off. Settings → Data → "Share anonymous usage data". It is on by default and off in one tap. Turning it off stops collection in the SDK — events are not gathered and filtered later. The choice syncs with the rest of your settings, so you make it once rather than once per phone. A build without our Firebase configuration collects nothing at all.
9. Service providers
We use these providers to run the app. Each processes data only to provide its service to us:
| Provider | Purpose | Data |
|---|---|---|
| Google Firebase (Authentication, Cloud Firestore, Cloud Functions, Analytics) | Accounts, cloud backup, the dua wall server, anonymous usage counts | Account details, backup data, dua text, server logs, usage events tied to a Firebase installation id |
| OpenRouter, Inc. (and the AI model providers it routes to) | Screening, translating and rewriting duas | Dua text and its language |
| RevenueCat, Inc. | Subscription status | Purchase receipt/token, app user id, device info |
| Apple Inc. / Google LLC | App distribution, payments, sign-in, platform geocoding | As per their policies |
| komoot GmbH (Photon) | City name search | The typed search text |
| Cloudflare, Inc. | Hosting of this website | Standard web server logs |
We do not sell personal data, we do not use it for advertising, and no usage data is linked to your identity or used to track you across other apps or websites.
10. The website (sunnahhelper.com)
The website is static and sets no cookies. Fonts and images are served from our own domain, and there is no advertising, no social media SDK and no cross-site tracker on any page. Cloudflare, which hosts the site, may keep standard server logs (IP address, user agent, timestamp) for security. We may also run Cloudflare Web Analytics, which counts page views from the browser: it sets no cookie, stores nothing on your device, and does not identify you or follow you to other sites. A "theme", a "chosen language" and a "language hint dismissed" preference may be stored in your browser's local storage, so the site opens the way you left it; that data never leaves your browser. The app's usage analytics (section 8) do not run on the website.
11. Data retention
- Device data: until you delete it or uninstall the app.
- Account and cloud backup: until you delete the account.
- Published duas: until their chosen visibility period ends; your own history of asked and answered duas: 30 days; drafts: 30 minutes.
- Server logs (Firebase): up to 30 days.
- Anonymous usage events (section 8): up to 14 months.
- RevenueCat purchase records: for as long as needed to honour your subscription and comply with tax and accounting law.
12. Security
Data in transit is encrypted (HTTPS/TLS). Cloud data is stored on Google Cloud with access restricted by Firebase security rules to the signed-in owner of the data. No method of transmission or storage is completely secure; we cannot guarantee absolute security.
13. Your rights
Depending on where you live, you may have the right to access, correct, export, restrict or delete your personal data, and to object to its processing. Most of this you can do yourself in the app: change settings, edit or delete deeds and history, delete a dua, sign out, or delete your account. For anything else, email support@sunnahhelper.com; we answer within 30 days. If you are in the EU/EEA or the UK you may also complain to your data protection authority.
14. International transfers
Our providers may process data in the United States and other countries. Where required, transfers rely on the providers' standard contractual clauses or equivalent safeguards.
15. Children
Sunnah Helper is not directed at children under 13 and we do not knowingly collect personal data from them. If you believe a child has created an account, contact us and we will delete it.
16. Changes to this policy
We may update this policy as the app changes. The effective date at the top shows the current version; significant changes are announced in the app.
17. Contact
Mammad Shahmaliyev · support@sunnahhelper.com · https://sunnahhelper.com