← waqtapp.net
Privacy Policy
Effective August 18, 2026 · Waqt ("we", "us") — waqtapp.net
The short version
Waqt is local-first. Prayer times, qibla, and the Qur'an are computed and read on your device. No analytics, no trackers, no ads, no selling or sharing data for advertising — ever. If you create an optional account, we store your email and a copy of your app data so your devices stay in sync. One button deletes everything.
What we store, and why
- Without an account: everything lives on your device. We store nothing on our servers and receive no analytics.
- With an account: your email address (sign-in), an internal account identifier, and one copy of your app data — schedule, routines, events, prayer check-offs, reflections, adhkar and sunnah logs, duas, Qur'an reading position, bookmarks, notes, memorization progress, appearance settings, and your chosen city location (approximate, city-level). This is stored solely to sync your devices and is encrypted in transit (TLS).
- Sign-in codes: stored hashed, valid 10 minutes, deleted on use, rate-limited against abuse.
- What we never collect: GPS location (the app has no GPS permission), contacts, photos, precise movement, browsing history, analytics or usage telemetry, advertising identifiers, or any payment information (the zakat calculator runs entirely on your device and transmits nothing).
Device permissions
- Notifications — scheduled locally on your device for prayer reminders. Nothing leaves the device.
- Motion & compass — used only while the qibla compass is open, processed entirely on-device, never transmitted or stored.
Third-party services
- ipwho.is — only if you tap "Detect my location": your IP is used once to estimate your city. You can type a city instead.
- Open-Meteo geocoding — only your typed city search text, to find coordinates.
- OpenStreetMap (Overpass API) — only if you open the Masjids tool: your saved city's coordinates are sent to fetch nearby mosques. Results are cached on your device.
- Resend — delivers sign-in code emails on our behalf (they process your email address for delivery only).
- Railway — hosts our sync server and database (US region).
None of these receive your name, and none are given data for advertising. We have no advertising or analytics SDKs in the app.
Retention & deletion
- Account data is kept only while your account exists.
- Delete account (Settings) immediately and irreversibly erases your synced data, email, identifiers, and usage counters from our servers.
- Sign out everywhere (Settings) revokes every signed-in session on all devices.
- Local data on your devices is yours to keep or clear; Export (Settings) gives you a full JSON copy at any time.
Your rights
Wherever you live, we honor the substance of GDPR/UK-GDPR and CCPA rights: access and portability (use Export, or email us), correction (edit in-app), and erasure (Delete account, or email us). We do not "sell" or "share" personal information as those terms are defined in the CCPA, and we do not use personal data for profiling or automated decisions. To exercise any right or ask questions: codes@waqtapp.net.
Children
The app is suitable for all ages, but accounts are not directed at children: you must be 13 or older to create one. We do not knowingly collect personal information from children under 13; if you believe a child has created an account, contact us and we will delete it.
Security
All traffic is encrypted in transit (TLS). Sign-in codes are stored hashed with attempt limits and expiry. Sync tokens can be revoked at any time from Settings. No system is perfectly secure — if we learn of a breach affecting your data, we will notify affected users without undue delay.
Changes & contact
Material changes to this policy will be reflected by the effective date above. Questions, requests, or concerns: codes@waqtapp.net.