Deutsch

Privacy Policy

Mushafly is designed to keep personal Quran reading and recitation data on your device and in your private iCloud account.

Controller

Can Turhan, Allersberger Straße 144, 90461 Nürnberg, Germany. Email: support@mushafquran.app. Mushafly does not use advertising or cross-app tracking and does not sell personal data.

Purposes and legal bases

We process data only to provide functions you request (Article 6(1)(b) GDPR), answer support requests or protect the app where necessary (Article 6(1)(b) or (f)), and comply with legal obligations (Article 6(1)(c)). Permission-based features start only after your action and can be disabled in iOS Settings. Mushafly makes no solely automated decision with legal or similarly significant effects.

Data stored on device

Reading history and progress, bookmarks, notes and drawings, goals and streaks, favorites, playlists, prayer settings, app preferences, downloads, offline resources, recitation-practice state and an optional profile photo are stored locally. An optional Apple/Google profile and a random installation identifier are stored in the Keychain. They remain until deleted, all app data is erased or the app is removed, subject to iOS backup behavior.

iCloud sync

Only after a separate, explicit opt-in and when iCloud is available for Mushafly, reading positions and history, bookmarks, text snapshots of notes, Quran-completion and streak state, favorites, playlists and collections, manually selected prayer location and prayer settings, and notification, audio, translation, download and display preferences are synchronized through the user's private iCloud account. Drawings, downloaded audio, offline resources, caches, the Keychain profile, profile photo and installation identifier are not synchronized. Apple processes iCloud data under the user's Apple Account settings. “Delete Account & All Data” also sends deletion markers for Mushafly's synchronized values.

Optional sign-in

Apple or Google processes authentication and returns an identifier and, depending on the user's choice, name and email. The resulting Mushafly profile remains on device and is not sent to a Mushafly-operated server. The Google Sign-In SDK may additionally process contact details (including a phone number if associated with the provider account), user and device identifiers, diagnostics, usage data, coarse network-location information and other technical data for authentication, security, app functionality and its own analytics as declared by Google; it declares no tracking. Provider access can be revoked in the respective Apple or Google account.

On-device AI, microphone and speech

Live recitation guidance is clearly identified as AI. Only after the user starts it, an on-device Core ML speech model processes microphone samples in memory to compare the recitation with the selected ayah and highlight words. Release builds do not save or upload the recording, do not identify the voice and do not use it for training. Voice search requires Apple's on-device speech recognition and does not upload audio. Results can be wrong and are a learning aid, not a qualified teacher or religious ruling. Microphone and Speech Recognition access can be revoked in iOS Settings.

Sensitive religious-context data and consent

Reading progress, Quran notes, prayer settings and similar activity can reveal a religious context. Mushafly stores it locally for requested features. It is synchronized through the user's private iCloud account only after a separate, explicit opt-in. Consent is optional and can be withdrawn in Privacy settings; withdrawal stops future sync and sends deletion markers for Mushafly's existing private iCloud values.

Quran Foundation content

Mushafly is an independent app and is not an official Quran Foundation product. It uses Quran Foundation APIs in the Quran.com ecosystem for public Quran text, translations, tafsir, chapter information and timing metadata; it does not use Quran Foundation user accounts or OAuth user data. Content API caches expire after at most seven days and are refreshed or deleted. Quran Foundation's QuranReflect service is not integrated into Mushafly.

Network services and international processing

Quran Foundation/Quran.com, Islamic Network, MP3Quran, QUL/Tarteel, jsDelivr/GitHub-hosted datasets and Mushafly's Cloudflare-hosted domain provide requested Quran content, timing, audio, tafsir, transliteration and legal pages. Apple provides iCloud, Maps city search, purchases, subscriptions, updates and reviews; Google provides optional sign-in. These services receive technically necessary connection data such as IP address, request time and headers and may process data outside the EEA under their own privacy terms and lawful transfer safeguards. Requests for religious content can reveal a sensitive context; Mushafly sends only what is necessary and operates no analytics server of its own. Provider privacy information: https://www.apple.com/legal/privacy/ ; https://policies.google.com/privacy ; https://quran.com/privacy ; https://www.mp3quran.net/eng/privacy ; https://www.cloudflare.com/privacypolicy/ .

Location, Maps, photos and notifications

After permission, an approximate location is used locally for prayer-time and Qibla calculations. If the user manually searches for a city, Apple Maps processes the search text and necessary connection data to return results. A selected city and coordinates may be included in private iCloud sync only after consent. The system photo picker supplies only the selected photo, which is stored locally. Notifications are used only for enabled reminders and are scheduled locally.

Children and families

Mushafly is a general-audience app and its local Quran reading functions can be used without an account. The app does not request a child's age, and Mushafly operates no profile or analytics backend that knowingly collects children's data. Parents or guardians should supervise a minor's use of Apple or Google sign-in, purchases, device permissions and iCloud synchronization. Where a child cannot legally consent independently, a parent or guardian must enable and consent to the optional synchronization of religious-context data. Apple and Google account-age and family-account rules continue to apply.

Security and incidents

Network requests use HTTPS/TLS. Private iCloud and Keychain data use Apple's platform access controls and encryption; Mushafly keeps no reading-data backend. Access to developer systems and secrets is limited and credentials are rotated when exposure is suspected or access changes. Security incidents are assessed without delay; any incident involving Quran Foundation APIs is reported to Quran Foundation within 24 hours as required by its Developer Terms (including its referenced Security Rule 6.9), and legally required authority notifications are made within the applicable deadline.

Purchases and support

Apple processes Mushafly+ purchases and purchase history. Mushafly receives entitlement status but no payment-card details. If support is contacted, the email address, message and attachments are processed to answer the request and deleted when no longer needed unless statutory retention duties apply.

Retention, deletion and rights

Users can delete only the local profile or choose “Delete Account & All Data” to erase local data and Mushafly's iCloud-synchronized values. Quran Foundation Content API caches expire after at most seven days. Support correspondence is deleted when no longer needed unless statutory retention applies. Removing the app deletes local downloads and caches but does not cancel an Apple subscription. Subject to the GDPR, users may request access, correction, erasure, restriction or portability, object to processing and withdraw consent where consent is the basis. Requests are answered without undue delay and normally within one month. A complaint can be made to a data-protection authority, including the Bavarian State Office for Data Protection Supervision. Contact: support@mushafquran.app.

Last updated: 1 September 2026