The short version
Sufia Noorbakhshia has no user accounts, no advertising, no analytics, and no tracking of any kind. You do not sign up, log in, or give us your name. Almost everything you do in the app — your bookmarks, tasbih counts, last-read position, and settings — never leaves your phone.
Only three things ever travel off your device:
- Your location, sent to a prayer-times service to calculate accurate prayer timings for where you are. We never receive it.
- Your voice, but only while you are actively using voice search, and only to your phone's own speech-recognition service.
- An issue report, if and only if you choose to submit one from Settings.
We do not sell, rent, or share your personal information with anyone, for any purpose. There is nothing to sell — we do not hold a profile of you.
1.Who we are
The Sufia Noorbakhshia mobile application ("the App", "we", "us", "our") is developed and maintained by the Noorbakhshi IT Team on a non-commercial, volunteer basis, in service of the Sufia Noorbakhshia community.
For the purposes of the EU/UK General Data Protection Regulation, the Noorbakhshi IT Team is the data controller for the limited personal data described in this policy. You can reach us at any time at [email protected].
| App name | Sufia Noorbakhshia |
|---|---|
| Android package | com.devnoorbaksh.noorbakshidunya |
| Publisher | Noorbakhshi IT Team |
| Contact | [email protected] |
2.Scope of this policy
This policy explains what information the App handles, why, and what your choices are. It applies to the Sufia Noorbakhshia app on Android and iOS.
It does not apply to third-party websites or services you reach by tapping a link inside the App (for example nyfpak.org, YouTube, Facebook, Google Forms, or the Play Store). Those are governed by their own privacy policies, and we have no control over them.
3.No account, no profile
The App has no registration, no login, and no user accounts. We do not ask for, and cannot collect, your name, email address, phone number, date of birth, photograph, contacts, or any similar identifying detail.
Because no account exists, we hold no profile of you, and we are unable to link any of the limited data described below back to your identity.
4.What we collect — at a glance
| Data | Why | Where it goes | Optional? |
|---|---|---|---|
| Approximate GPS coordinates | Prayer times & Qibla direction | Aladhan prayer-times API; your phone's OS geocoder. Not to us. | Yes — permission-based |
| Voice audio | Voice search | Your phone's speech-recognition service (Google / Apple). Not to us. | Yes — only while you use it |
| Issue title, description, optional email | Fixing bugs you report | Our Firebase (Firestore) database | Yes — only if you submit |
| Content-sync diagnostics | Confirming content downloads worked | Our backend server | No — but contains no personal data |
| Bookmarks, tasbih counts, reading position, settings | App features | Stays on your device. Never uploaded. | — |
5.Location data
Why we need it
Prayer times and the Qibla direction are meaningless without knowing where you are. The App uses your location for exactly two purposes:
- Prayer times — calculating Fajr, Sunrise, Dhuhr, Asr, Maghrib and Isha for your position.
- Qibla — computing the bearing from you to the Kaaba in Makkah.
How it is handled
- Location is requested at medium accuracy — enough for prayer times, but not the most precise fix your device can produce.
- Your coordinates are sent over an encrypted (HTTPS) connection to Aladhan (aladhan.com), a third-party prayer-times service, which returns the timings for that position. Aladhan receives coordinates only; it receives no identifier and cannot associate them with you. See Aladhan's privacy policy.
- To display your city and country, coordinates are passed to your device's built-in geocoder — Google Play Services on Android, Apple's CoreLocation on iOS — which is subject to Google's or Apple's privacy policy respectively.
- Your coordinates and resolved city are cached on your device so the App works offline and does not need to re-locate you constantly.
Your location is never sent to our servers. We do not log it, store it, or retain any history of where you have been. We could not produce a record of your movements if asked, because none exists.
The Qibla compass
The Qibla feature also reads your device's compass and motion sensors to point the needle. Sensor readings are processed entirely on your device in real time and are never transmitted or stored.
Your control
Location is optional. The App will ask permission before accessing it, and you may refuse or revoke it at any time in your device settings. If you decline, prayer times and Qibla will not be able to calculate for your position; every other part of the App continues to work normally. The App does not collect location in the background — only while you are using it.
6.Microphone & voice search
The App offers voice search so you can find verses and books by speaking instead of typing. The microphone is used only for this, and only while you have actively started a voice search. Listening stops automatically after a short pause or 30 seconds at most.
Important: speech recognition is performed by your device's own speech service — Google's recognition service on Android, Apple's on iOS. This means your spoken audio may be transmitted to and processed by Google or Apple under their privacy policies, exactly as it is for any other voice input on your phone.
For our part: the App never records audio to a file, never stores it, and never sends it to our servers. We receive only the recognised text, which is used immediately as a local search query and then discarded. The microphone is never accessed in the background or when a voice search is not running.
Microphone access is optional. Decline it and the rest of the App — including typed search — works exactly as before.
7.Issue reports
If you choose to report a problem via Settings → Report Issues, we receive:
- The title and description you write;
- Your email address — only if you choose to provide it (the field may be left blank, in which case it is recorded as "not provided");
- The time of submission.
We use this solely to understand and fix the problem, and to reply to you if you gave us an address to reply to. Reports are stored in our Google Firebase (Cloud Firestore) database. We never use an address given here for newsletters, marketing, or anything other than answering your report.
Please do not include sensitive personal information — passwords, financial details, government identifiers, health information, or details about other people — in the title or description. These are free-text fields, and whatever you type is what we receive.
8.Content-sync diagnostics
The App periodically downloads updated religious content (Quran text, books, du'as, calendar data) from our servers. So that we can tell whether these downloads are succeeding, the App reports the outcome of each sync to our backend:
- Whether the sync succeeded or failed, and any error message;
- How long it took and how many bytes were downloaded;
- The content bundle version and app version;
- Your platform (Android or iOS) and operating-system version;
- A randomly generated session identifier.
The session identifier is freshly generated for every sync and is never reused. It is not a device ID, an advertising ID, or a persistent identifier of any kind. It cannot be used to recognise your device across sessions or to build a history of your usage — it exists only to tie the parts of a single sync operation together in our error logs.
This diagnostic data contains no personal information and is not linked to you. Our server does not record your IP address on this path. (As with any internet service, our hosting infrastructure may keep short-lived, standard server logs for security and abuse prevention.)
9.Data that stays on your device
The following is stored only in local storage on your phone. It is never uploaded, never backed up to us, and is invisible to us:
- Bookmarks and saved passages;
- Tasbih (dhikr) counts;
- Your last-read position in the Quran and in books;
- Downloaded content and the offline database;
- Theme, language, and time-format preferences;
- Notification and prayer-time settings;
- Your cached coordinates and city name.
All of it is deleted when you uninstall the App or clear its data. Because it never reaches us, we cannot recover it for you — please note this if you switch phones.
10.Permissions we request
Every permission below is used strictly for the stated feature and nothing else.
| Permission | What it is for |
|---|---|
| Location (while in use) | Prayer times and Qibla direction. Never accessed in the background. |
| Microphone | Voice search only, while you are actively using it. |
| Speech recognition iOS | Converting your voice search to text. |
| Notifications | Prayer-time reminders you have enabled. Delivered by your device — we send nothing. |
| Exact alarms & run at startup Android | Firing prayer reminders at the precise time, and restoring them after a reboot. |
| Foreground service & media playback | Keeping Quran audio playing while the App is in the background. |
| Internet & network state | Downloading content, prayer times, and audio; detecting whether you are offline. |
| Vibration | Tasbih counter and notification feedback. |
| Bluetooth Android | Required by the speech-recognition component so voice search works with Bluetooth headsets. The App itself does not use Bluetooth, scan for devices, or use it for location. |
The App requests no access to your camera, contacts, calendar, call logs, SMS, photos, files, or any advertising identifier.
11.Third-party services
These are every external service the App communicates with, and exactly what reaches each one:
| Service | Purpose | What it receives |
|---|---|---|
| Aladhan | Prayer-time calculation | Your coordinates. No identifier. |
| Google Play Services Android / Apple CoreLocation iOS | Turning coordinates into a city name | Your coordinates. |
| Google Android / Apple iOS speech services | Voice search recognition | Your spoken audio, while voice search is active. |
| Google Firebase (Cloud Firestore & Storage) | Book catalogue, content database downloads, and storing issue reports | Issue reports you submit. Standard connection metadata (including IP) for downloads. |
| Our backend (api.sufianoorbakhshia.com) | Content sync, e-library, hostels and NYF listings | Sync diagnostics only. No personal data. |
| EveryAyah.com | Quran recitation audio | Only what any web request reveals (IP address), when you play audio. |
We have no commercial relationship with any of these providers and receive nothing from them in return. We do not send them your personal data for their own purposes.
12.No advertising, no analytics, no tracking
To be explicit, the App contains:
- No advertising and no ad networks.
- No analytics — we do not measure screen views, sessions, feature usage, or engagement.
- No tracking or profiling — no advertising ID, no device fingerprinting, no cross-app or cross-site tracking, no cookies.
- No sale or sharing of personal information, under any definition, including those in the CCPA/CPRA. We have never sold or shared personal information and have no plans to.
- No automated decision-making or profiling that produces legal or similarly significant effects.
The App is a free, non-commercial religious resource. There is no business model here that depends on your data.
13.Legal bases for processing (GDPR)
If you are in the European Economic Area or the United Kingdom, we rely on the following legal bases:
| Processing | Legal basis |
|---|---|
| Location for prayer times & Qibla | Consent (Art. 6(1)(a)) — given via the OS permission prompt, withdrawable at any time. |
| Microphone for voice search | Consent (Art. 6(1)(a)) — given via the OS permission prompt, withdrawable at any time. |
| Issue reports | Consent (Art. 6(1)(a)) — you choose to submit the form. |
| Sync diagnostics | Legitimate interests (Art. 6(1)(f)) — ensuring the App's content delivery functions correctly. The data is non-personal and the impact on you is negligible. |
Withdrawing consent is as easy as giving it: revoke the permission in your device settings, or simply do not submit a report.
14.How long we keep data
| Data | Retention |
|---|---|
| Location | Never retained by us. Cached on your device until you clear it or uninstall. |
| Voice audio | Never retained by us. Not stored at any point. |
| Issue reports | Until the issue is resolved and no longer needed for reference — typically no more than 24 months. Deleted sooner on request. |
| Sync diagnostics | Up to 12 months, then deleted. Contains no personal data. |
| On-device data | Until you delete it or uninstall the App. Entirely under your control. |
15.Your rights & choices
Depending on where you live, you may have the right to access, correct, delete, restrict, or object to processing of your personal data, to data portability, and to lodge a complaint with a supervisory authority. We honour these rights for everyone, regardless of location.
In practice, the strongest privacy control you have is built into the App itself:
- Revoke a permission — turn off location or microphone in your device settings at any time.
- Do not submit a report — or submit it without an email address.
- Clear the App's data or uninstall it — this removes everything the App has stored on your device.
Because we hold no account and no identifier for you, there is generally nothing to access, correct, or export — we simply have no record of you. The only exception is an issue report you chose to send us, which we can look up if you tell us the email address or details you used.
If you are in the EEA or UK and believe we have mishandled your data, you may complain to your national data protection authority. We would appreciate the chance to put it right first — please write to us.
16.Deleting your data
There is no account to delete, because the App never creates one.
To remove everything stored on your device, uninstall the App or clear its data from your device settings.
To have an issue report you submitted deleted from our records, email [email protected] with the subject "Data Deletion Request", describing the report so we can find it. We will delete it and confirm within 30 days, free of charge.
17.Security
We take reasonable and appropriate measures to protect the limited data we handle:
- All network communication between the App and our services — and to the prayer-times API — uses encrypted HTTPS/TLS connections.
- Issue reports are stored in Google Firebase, which encrypts data in transit and at rest.
- Access to our administrative systems is restricted to authorised members of the Noorbakhshi IT Team and protected by authentication and audit logging.
- Most of all: we minimise by design. The overwhelming majority of your data never leaves your device, and data we never collect cannot be breached.
No method of transmission or storage over the internet is completely secure, so we cannot guarantee absolute security. If a breach ever affects your personal data, we will notify affected users and the relevant authorities as required by law.
18.Children's privacy
The App is a religious and educational resource suitable for family use, including children, and is safe by design: it has no accounts, no chat, no user-to-user contact, no advertising, and no tracking or profiling.
We do not knowingly collect personal information from children. The only way a child could send us personal information is by typing it into an issue report — which is optional and which we ask users not to fill with personal details. If you believe a child has sent us personal information, contact [email protected] and we will delete it promptly.
We encourage parents to supervise their children's use of any app, and to note that location and microphone permissions are requested for the features described above.
19.International transfers
We are based in Pakistan. The third-party services described in section 11 — Google Firebase, Aladhan, EveryAyah, and our hosting provider — operate servers in various countries, so the limited data described in this policy may be processed outside your country of residence, including outside the EEA/UK.
Where such transfers involve personal data of EEA/UK users, they are covered by the safeguards those providers maintain, such as the European Commission's Standard Contractual Clauses. Given how little personal data is involved, the risk to you is minimal by design.
20.Changes to this policy
We may update this policy to reflect changes in the App or in the law. The "Last updated" date at the top always shows the current version, and this page is the authoritative copy — it is the same page the App links to from Settings.
If we ever make a material change — such as collecting a new category of personal data, or introducing analytics — we will make that clear in the App before the change takes effect, and where the law requires it, we will ask for your consent. Continuing to use the App after an update means you accept the revised policy.
21.Contact us
Questions, concerns, or requests about this policy or your privacy are genuinely welcome. We aim to reply within 30 days.
- [email protected]
- Data requests
- [email protected] — subject "Data Deletion Request"
- In the App
- Settings → Report Issues
- Website
- nyfpak.org
- Publisher
- Noorbakhshi IT Team, Pakistan
See also our Terms & Conditions.