Niyyah - Legal
Privacy Policy
Niyyah is built privacy-first. Almost everything you do in the app stays on your device. This policy explains what we store, what we send to our servers when you sign in, and what we never collect.
What we store on your device
The following data lives in the app's local storage. It is never sent to us or any third party unless you specifically opt in to a feature that requires it (described below). When you sign in, the account-backup items identified below are also stored privately on our servers.
- Your prayer logs, including which of the five daily prayers you marked on time, late, or missed.
- Your streak history, Kaza (make-up prayer) counts, and Year-in-Review aggregates.
- Your settings: onboarding completion, calculation method, combined-prayer preference, theme, notification and reminder preferences, notification sound, community, and how you asked the app to address you (gender preference). If you sign in, these are included in your private account backup and are never shown in Circles.
- Optional profile fields you enter in Settings (name, email, phone). These stay on this device and are not part of your account backup. The email or phone you sign in with and your Circles display name are stored with your account, as described below.
- Your latitude and longitude (or chosen city), used to compute prayer times locally. If you sign in, your saved location is included in your account backup (see below).
What we compute on your device
Prayer times are calculated entirely on your device using the open-source adhan library. We do not call any prayer-times API. Reminder notifications for the five daily prayers and the optional 10pm evening reflection are scheduled locally by your device's operating system. If you sign in, a copy of your upcoming computed prayer times is sent to our servers (see below) so friends' nudges arrive at sensible times.
What we send to our servers (only when you sign in)
Circles is the optional feature that lets friends share their daily prayer status with each other (a free Circle holds up to 4 members including you; with Niyyah Pro a Circle can hold up to 50). None of the data below leaves your device unless you sign in.
- Account: an email address and password (confirmed by a one-time code we email you), OR a phone number verified by a one-time SMS code. We store a hashed password and the phone number / email so you can sign back in. We also record when you accepted the Terms of Use and Privacy Policy and which version you accepted.
- Display name you choose for Circles.
- A push notification identifier (a OneSignal subscription id), so friends can send you a nudge.
- Today's prayer status, shared with your circle as a binary completed / not for each of the five prayers. Circle members never see on time / late / missed details or any history beyond today.
- Circle memberships and invite codes you create or join.
- Your device's IANA timezone and your upcoming computed prayer times (up to ten days of prayer instants, no coordinates), so nudges from friends are only delivered at appropriate moments relative to your local prayer schedule. This is overwritten in place whenever the app recomputes prayer times.
Our privacy contract for Circles
We enforce three rules on the server so the privacy promise is not just a guideline:
- Today only. The date is derived server-side from the IANA timezone your device sends. Any date field in the upload is ignored, so the client cannot backdate or forward-date a completion to a different day.
- Binary only. Only completed / not completed is shared with your circle members. The on time / late / missed nuance stays on your device, and only today's status is ever shown to other members.
- Nudge throttling. A circle member can send you at most one nudge per prayer per day.
Account backup (when you sign in)
When you are signed in, the app keeps a private backup of your data on our servers so you can restore it if you reinstall the app or switch phones. The backup includes your prayer history (including on time / late / missed detail), streaks, Kaza counts, makeup fasts, onboarding completion, saved coordinates or city, calculation method, combined-prayer preference, community, gender preference, and notification and reminder preferences. Community and gender remain private account settings and are never included in Circle data. The backup is sent over an encrypted connection, is never shared with other users or third parties, and is permanently deleted when you delete your account in Settings.
Permissions the app may request
- Notifications. Used for prayer reminders, the 10pm evening reflection, and (if you use Circles) nudges from friends. Optional; the app works without it.
- Location. Used once to fetch your coordinates for accurate prayer times. You can skip this and enter a city manually. Coordinates stay on your device unless you sign in, in which case your saved location is included in your private account backup.
Crash reporting (always on)
We use Sentry to detect and diagnose crashes and unhandled errors in the app and on the Circles backend. This is on by default because without it we can't fix bugs that take the app down for you.
What Sentry receives: the stack trace, the route template you were on (e.g. "/circles/:id" - never the actual circle id), device model, OS version, and the app version. If you are signed in, we attach your internal account id (a random identifier) so we can correlate multiple reports from the same user. We do not send your email, phone, display name, push token, prayer status, completion counts, or location to Sentry.
Product-improvement analytics (with an account)
When you create a Niyyah account and accept these terms, your acceptance also covers a small set of anonymous product-improvement events sent to PostHog (host: us.i.posthog.com) so we can see which features are actually used. If you never create an account, nothing is sent.
When active we capture only these events, and only these:
app_opened,onboarding_completed,signed_in(withmethod= email or phone),signed_out,circle_created,circle_joined,kaza_opened,year_review_opened,qibla_opened,settings_opened.- The distinct id is a random UUID generated on first launch and stored on your device. It is never your account id, email, or phone number. No event payload contains prayer status, completion counts, location, name, email, phone, push token, circle id, or display name.
- To withdraw this consent, delete your account (see Data retention and deletion) or email us at hello@niyyahapp.io. Events already captured remain in PostHog under the anonymous id; email us if you want them deleted.
Subprocessors
Depending on which features you use, your data is processed by the following providers acting on our behalf:
- Sentry (always on for crash reports), receiving the limited data described above.
- PostHog (only if you have created an account and accepted these terms), receiving the limited event list above.
- Twilio, only if you choose phone sign-in, to deliver the one-time SMS verification code.
- Resend, only if you sign up with email, to deliver the one-time email confirmation code.
- OneSignal (which forwards to Apple Push Notification service or Google Firebase Cloud Messaging), to deliver nudge notifications to your device.
- Our PostgreSQL database hosting provider, which stores accounts, circle memberships, today-only completion flags, and your private account backup.
What we do not do
- We do not run A/B testing, session replay, behavioral profiling, or advertising-style tracking.
- We do not embed advertising or third-party advertising trackers.
- We do not sell, rent, or share your data for marketing.
- We do not upload profile photos.
- We do not send your prayer history, on time / late / missed details, name, email, phone, location, or push token to Sentry or PostHog.
- We do not show your prayer history to anyone else. Circle members only ever see today's binary status, circle completion rows are automatically deleted after the 14-day rolling window described below, and your private account backup is readable only by you.
Data retention and deletion
Local data on your device persists until you delete the app or clear app data. Uninstalling Niyyah removes all local prayer history from the device permanently.
If you have an account, you can leave any circle from inside the app, and you can delete your account and all server-side data (account record, circle memberships, push token, any stored daily completion rows, your uploaded prayer schedule and timezone, and your account backup) directly from Settings. You can also email us at hello@niyyahapp.io from the address associated with your account, or include your phone number if you signed in with SMS, and we will action the request within 30 days.
On the server side, each completion row is keyed by user, day, and prayer, and is overwritten in place when you toggle that prayer. Only today's status is ever displayed in a Circle, and a scheduled job automatically deletes any completion row older than 14 days. Your prayer history exists server-side only inside your private account backup, never in the shared Circles data.
Children
Niyyah is not directed to children under 13. We do not knowingly collect data from anyone under 13. If you believe a child has created an account, contact us and we will delete it.
Changes to this policy
If we change this policy in a way that materially affects how we handle your data, we will update the effective date at the top and surface the change in-app on the next launch.
Contact
Questions, deletion requests, or anything else: hello@niyyahapp.io.
Terms of Use
These terms govern your use of the Niyyah mobile app and the Circles backend service. By using Niyyah you agree to them.
What Niyyah is
Niyyah is a personal prayer-tracking tool. It helps you log the five daily prayers, see your streak, track Kaza, view a Year-in-Review, and (optionally) share your daily progress with friends in a Circle (up to 4 members on the free plan, or up to 50 with Niyyah Pro).
Prayer times are computed on your device. They are an aid, not a religious authority. Always verify with your local masjid when accuracy matters.
Your account
You can use the entire app without an account. An account is only required for Circles. You are responsible for keeping your sign-in credentials safe and for activity under your account.
You agree to provide accurate sign-in information. You agree not to share your account with anyone else.
Acceptable use
When using Circles you agree not to:
- Impersonate someone else, including using a misleading display name.
- Use the nudge feature to harass or pressure another person. Circles are intended for mutual encouragement.
- Attempt to bypass our privacy contract - for example, by tampering with the client to upload non-binary or historical prayer data. The server rejects such requests, and we may suspend accounts that try repeatedly.
- Probe, scan, or attack our servers, or attempt to gain access to other users' data.
- Resell, redistribute, or build a competing product on top of our service.
Circles content
The only content you contribute to other users in a Circle is your display name and your today-only completion status. You retain ownership of that content. You grant us only the rights necessary to display it to your circle members and to operate the service.
Service availability
Local features (logging, streaks, Kaza, prayer times, Year in Review, reminders) work fully offline and do not depend on us. Circles depends on our servers and on third-party services like Twilio and Expo Push, which can experience outages. We do not guarantee uninterrupted availability of Circles.
Termination
You can stop using Niyyah at any time by uninstalling the app. To delete a Circles account, see the Privacy Policy.
We may suspend or terminate access to the Circles service, with notice where reasonable, if you violate these terms or if continued service would expose other users or us to significant risk.
Disclaimer
Niyyah is provided "as is" without warranties of any kind. We do not guarantee the accuracy of prayer times, the delivery of any specific notification, or any particular spiritual outcome.
Limitation of liability
To the fullest extent permitted by law, our total liability arising out of or related to your use of Niyyah is limited to the greater of the amount you paid us in the past twelve months (which, for the free app, is zero) or twenty Canadian dollars. We are not liable for indirect, incidental, or consequential damages.
Governing law
These terms are governed by the laws of the Province of Ontario, Canada, without regard to conflict-of-laws principles. Disputes will be brought in the courts located in Ontario, Canada.
Changes to these terms
We may update these terms from time to time. If we do, we will update the effective date and surface the change in-app on the next launch. Continued use after the change means you accept the updated terms.
Contact
Questions about these terms: hello@niyyahapp.io.