Privacy Policy
Nedaa is a mobile app, built and published by NedaaDev — a community of contributors. This policy describes what Nedaa does and does not do with your data. Plain language. No fine print.
TL;DR
- We don't collect personal data. No accounts. No tracking.
- A few things happen locally on your device (your settings, custom Athkar, fasting Qada counter).
- The only data that leaves your device is: anonymized crash reports from your app store (automatic, like every app), diagnostic log files you explicitly choose to share from the app, prayer-time requests, which carry a location accurate to about a kilometre that we round again before forwarding, and which we retain nowhere, downloads you ask for (a mushaf edition, a reciter's audio), and, unless you switch them off, two anonymous counters that say a recitation was played or a mushaf edition was installed, never who did it.
- If you want your data gone: delete the app. There is nothing on a server to delete.
What information we collect, how, and why
On your device only (we never see it)
- Your settings, custom Athkar, and fasting Qada counter. Stored locally so the app works between sessions.
What may reach us — and only under these conditions
- App-store crash reports. When the app crashes, your platform (Apple or Google) sends us anonymized crash counts and stack traces. This is the same as every app; it is handled by the store, not by us.
- In-app diagnostic logs (only if you share them). Nedaa has no crash-reporting SDK. The app writes diagnostic logs locally on your device (automatically pruned by age and size). If something goes wrong — including after a crash — the app asks whether you want to send a report; nothing is sent unless you choose to share it. Logs may contain app version, device/OS info, and a record of what the app did before the issue. We use them solely to help you.
- Content you download. When you ask for a mushaf edition, for Quran or Athkar recitation, or for the city database behind manual location, the app fetches it from our content server (
cdn.nedaa.dev). Our server therefore sees the request for that file. We keep aggregate counts only: no account, no device identifier, no record of who asked for what. Once a file is on your device, reading or listening needs no further request. - Two anonymous counters (on by default, and you can switch them off). A setting called Share anonymous usage stats lets the app report that a recitation was played, or that a mushaf edition was installed. The request carries only the recitation id or the edition version, plus the app version. It carries no account, no device identifier, no user id, no location, and nothing about what or when you read. The app sends each at most once every thirty minutes, and never from a development build. We use these to see which reciters and editions get used, and we publish the totals on our own operational ledger. Turn the setting off in Settings and nothing is sent at all.
- Where you are. Computing prayer times needs a location, so the app asks your device for one at its lowest setting, which is accurate to about a kilometre. Your precise position is never requested. That approximate point goes to our API, which rounds it further before doing anything with it, and the rounded pair is all we pass to the prayer-time provider and to the service that turns coordinates into a city name. We store none of it: request logs live inside the running server and go when it restarts, and nothing is aggregated or backed up. Your times are unaffected, because across that distance Fajr moves by a few seconds. To send nothing at all, choose your city by hand. The app then computes from the city you picked and never reads your device location.
- Prayer-time API requests. Our API is a proxy that forwards requests to a prayer-time provider — currently Aladhan, which is open source. Nedaa requests times roughly once a year per area, plus an extra request whenever you change a setting that requires a refetch (e.g., calculation method or madhab); the rest of the year, timings are read from local storage on your device. Your location is rounded at our proxy before anything is forwarded, so only the area bucket reaches the provider. We retain no IPs, request headers, or request bodies.
What we never collect
- No accounts, sign-ups, emails, or passwords.
- No advertising SDKs.
- No analytics SDKs that profile, segment, or fingerprint individuals.
- No location data sent off your device — ever.
- No third-party data brokers.
- No cookies, no cross-site tracking.
How we use what we receive
- App-store crash reports are used to diagnose and fix bugs. We do not sell, share, or use them for any other purpose.
- Log files you send are used only to answer your support request.
- Prayer-time requests are served and discarded; nothing about who requested them is retained.
- Download requests and the two anonymous counters become public totals, showing how many people use a given reciter or mushaf edition, so we can decide what to add next. We join them to nothing else, because there is nothing to join them to.
Sharing and third parties
Nedaa uses a small number of third parties strictly to operate. No data is sold or shared with advertisers.
- Your app store (Apple App Store, Google Play, Huawei AppGallery) — distributes the app, reports anonymized crash counts.
- The Nedaa API — operated by us; a proxy that forwards bucketed prayer-time requests to a provider. No retention as described above.
- Aladhan — current open-source provider behind our proxy. Receives the rounded area, never a precise position, and no device identifiers.
- BigDataCloud — turns a rounded coordinate into a city name for display. Receives the rounded area only.
- The Nedaa content server (
cdn.nedaa.dev) — operated by us; serves the mushaf page images and recitation audio you choose to download. Aggregate counts only.
We do not work with advertising networks, analytics ad networks, or data brokers.
Data retention
- Diagnostic logs live on your device only, where the app prunes them automatically. Logs you share reach us as a support attachment.
- Support emails and attached logs are retained for as long as the support thread is active, then deleted.
- API request logs, download requests, and usage counters: aggregate counts only; we retain no identifying data.
Your rights
Because Nedaa does not maintain user accounts or personal data on a server, traditional data-subject requests (access, deletion, portability) are mostly moot — there is nothing on our side to access, delete, or port.
- To remove all data: delete the app. Local data is removed with it.
- Diagnostic logs: stay on your device unless you share them — there is nothing to opt out of.
- Anonymous usage counters: turn off Share anonymous usage stats in Settings. Nothing is sent from then on. There is nothing to delete afterwards, because nothing sent was ever tied to you.
- For any other privacy question: email ••••••nedaa.dev . We respond within five working days.
International transfers
Nedaa is available globally. Nothing leaves your device automatically. If you choose to share diagnostic logs with support, they may be processed in regions outside your country; everything else operates locally or stays anonymized.
Children
Nedaa is suitable for users of all ages. We do not knowingly collect personal information from anyone — adult or child.
Security
We follow standard practices to protect what little data we receive:
- HTTPS in transit for all network calls.
- Crash data accessed only by maintainers.
- No system is perfectly secure; we'll notify users promptly if a breach affecting them ever occurs.
Changes to this policy
If we change this policy in a material way, we'll show a one-time, dismissible notice in the app — not a wall of text you must accept to continue praying. Non-material clarifications may be posted to this page without notice. The effective date at the top reflects the latest version.
Contact
For any privacy-related question or concern, email ••••••nedaa.dev .
Nedaa is open source. Our source code, including everything that handles your data, is at github.com/NedaaDevs/nedaa.