Privacy Policy
Effective date: July 12, 2026 · Contact: mizanofficialapp@gmail.com
The short version
Mizan is built to keep your spiritual life private. Your data lives on your device, backed up to a private, anonymous cloud record only you can access. We show no ads, embed no analytics or tracking SDKs, never sell data, and never use your data for advertising. The app's privacy manifest declares no tracking.
What we collect and why
- Profile you provide. Your first name, gender, age bracket, and your onboarding answers (how you rate your relationship with Allah, struggles you selected, goals, aspirations). Used to personalize the app.
- Your daily record. Prayers logged (with presence quality, congregation, and make-ups), good deeds, slips you name, tawbah completion, nightly intentions, reflections, and your streak. This is the core function of the app. We understand this is deeply sensitive religious information — see “Where it lives” and “Retention & deletion.”
- Location (optional). If you grant location access, we capture your coordinates and timezone to compute prayer times on your device and schedule prayer reminders. Location is stored in your private record; it is not used for advertising or shared for any other purpose. You can decline; the app falls back to a default schedule.
- Talk-to-my-Quran conversations. Your questions and the answers are stored only on your device (not in your cloud record). They are transmitted for AI processing (see below).
- Food scans. Barcode numbers are sent to the Open Food Facts public database with no personal identifiers. Photos you take of labels or meals are transmitted for AI analysis to produce your reading; we do not retain these photos on our servers.
- Purchases. Subscriptions are processed by Apple. Our subscription partners (RevenueCat, Superwall — see below) receive purchase and entitlement records identified by an anonymous ID. We never see your payment details.
AI processing
Talk-to-my-Quran questions, temptation descriptions in the Return tab, and food photos are processed by Claude, an AI model by Anthropic. Requests are routed through Mizan's own server; they are associated with an anonymous user ID, never your name or contact details. Per Anthropic's commercial API terms, API inputs and outputs are not used to train their models. Voice input is transcribed using Apple's speech recognition; audio may be processed by Apple per their terms.
Where it lives
Your data is stored locally on your device and backed up to a single private row in our database (hosted by Supabase), protected by row-level security so it is only readable by your own anonymous account. Accounts are anonymous by design: no email, no password, no phone number. The session key is stored in your device's Keychain.
Service providers (processors)
Anthropic (AI processing), Supabase (database, anonymous authentication, and our server functions), RevenueCat (subscription management), Superwall (subscription screen), Apple (App Store, payments, notifications, speech recognition), and Open Food Facts (barcode database lookups — receives only the barcode). We share only what each needs to perform its function. None of them are permitted to use your data for their own advertising.
What we don't do
No ads. No third-party analytics or tracking SDKs. No sale or rental of personal data. No cross-app or cross-site tracking. No use of your spiritual record for anything other than showing it back to you.
Notifications
Notifications are scheduled locally on your device (prayer times, the nightly scale reminder). We operate no push-notification server.
Retention & deletion
Your data persists so your history and streak work. Because accounts are anonymous, deleting the app on your only device and requesting deletion covers everything: email mizanofficialapp@gmail.com from within the app's Contact option and we will delete your cloud record. See How to delete your data for exact steps. [IF IN-APP DELETION EXISTS BY LAUNCH: “You can also erase everything in Settings → Delete my data.”]
Your rights
Under GDPR/UK GDPR, CCPA/CPRA and similar laws, you may request access, correction, deletion, or a copy of your data by contacting mizanofficialapp@gmail.com. We do not “sell” or “share” personal information as defined by the CCPA/CPRA. Legal bases under GDPR: performance of contract (providing the app), consent (location, notifications, photos/microphone), and legitimate interest (service integrity). You may lodge a complaint with your supervisory authority.
Children
Mizan is not directed to children under 13, and we do not knowingly collect personal information from them. If you believe a child has provided data, contact us and we will delete it.
International transfers
Our providers may process data in the United States and other countries; where required, transfers rely on appropriate safeguards such as standard contractual clauses.
Changes
We will post any material changes here and update the effective date.