meowslimah
Privacy Policy
meowslimah is built around a single principle: your data stays on your device by default. We do not sell your data. There are no ads, no trackers, no third-party analytics, and no telemetry. The app now offers optional cloud sync, which is off until you create an account and turn it on — you can use meowslimah exactly as before, with no account and nothing leaving your device. Khalwah, your private journal, is separate again: it is never included in sync unless you turn it on a second time, on each device, and it is encrypted on your device before it is uploaded. The app makes outbound network requests only for narrow, user-initiated content downloads — Qur'an recitation audio when you tap Stream or Download in the reader, Hisnul Muslim du'a recitation audio when you tap Play on a du'a or Download all du'a audio in Settings, and Mushaf pack archives when you opt in to Page Mode from Settings — plus the optional sync path if you turn it on. Qur'an recitation downloads can cover the current surah or the whole selected reciter, and saved recitations can be reviewed or deleted from Settings → Worship & reading → Qur'an audio. This document explains exactly what that means and the few specific exceptions where information may leave your device — always at your direction, never silently.
What data does meowslimah collect?
The current released app stores the following on your device only:
- Prayer logs, fasting logs, journal entries, gratitude entries, goals, notes, and reminders
- Du'a favorites, Qur'an reading progress, and 99 Names progress
- Your selected city (for prayer-time calculation), madhab, calculation method, and voice preference
- App settings (notifications, biometric unlock, theme)
- Your Khalwah (private journal) entries — encrypted at rest using your device's secure keystore (iOS Keychain / Android Keystore)
Nothing on this list is transmitted to us or any third party unless you use one of the internet features described below. Optional cloud sync requires an account and your explicit opt-in before any of it is stored online, and it stays off until you do that.
What permissions does meowslimah request, and why?
| Permission | Why | Who sees the data |
|---|---|---|
| Location (approximate) | To calculate accurate prayer times and Qiblah direction for your area, on your device. | Only your device. The location is used by an offline calculation library and is never sent anywhere. |
| Notifications | To send local reminders (prayer times, daily reflections you opted into). | Only your device. Notifications are scheduled locally; no server is involved. |
| Biometric (FaceID / fingerprint) | To unlock the Khalwah private-journal area, if you enable this option. | Your device's biometric subsystem only. We never receive your biometric data. |
| Internet | To stream and download Qur'an recitation audio from public CDNs when you tap Stream or Download in the Qur'an reader, including current-surah downloads and user-initiated whole-reciter downloads; to fetch Hisnul Muslim du'a recitation audio from www.hisnmuslim.com when you tap Play on a du'a or tap Download all du'a audio in Settings → Worship & reading → Du'a audio; to download optional Mushaf pack archives for Page Mode reading from meowslimah's content CDN when you tap Download on a pack in Settings → Worship & reading → Mushaf packs; and to sign in and sync through Supabase if you turn sync on. |
The CDN or host serving the audio file or Mushaf pack archive (see below). If you turn sync on, Supabase processes account and sync data as described below. The app does not add analytics or tracking identifiers. |
Does meowslimah ever connect to the internet?
Yes, in specific places — all narrow, and either initiated by you or explicitly enabled by you:
- Qur'an recitation audio. When you tap Stream or Download in the Qur'an reader, the app fetches the requested surah or reciter audio MP3s from one of two public Qur'an CDNs:
audio.qurancdn.com(operated by Quran Foundation / QUL — for Mishary Al-Afasy, As-Sudais, and Al-Shatri)www.everyayah.com(BunnyCDN — for Minshawi, Al-Husary, Yasser Al-Dossary, and Aziz Alili)
- Hisnul Muslim du'a audio. When you tap Play on a du'a that includes recitation audio, the app may fetch that MP3 from:
www.hisnmuslim.com(for Hisnul Muslim du'a recitations)
You can also download every du'a recitation at once for offline listening: Settings → Worship & reading → Du'a audio → Download all du'a audio fetches all the bundled du'a recitations from
www.hisnmuslim.comin a single user-initiated pass (about 120 MB) with visible progress you can cancel. It is whole-library only (there is no per-du'a or per-category download), never automatic, never in the background, with no silent retries and no telemetry. The downloaded audio is cached on your device in a folder that is excluded from device and cloud backups and is not part of the in-app export; once downloaded, du'a playback uses the local files with no further network calls. You can delete all of it anytime from the same screen. - Qur'an Page Mode pack downloads. Page Mode renders the Qur'an in printed-Mushaf page-by-page layout (the same format as a physical mushaf). To keep the install size small, each Mushaf edition is an optional pack you download once from Settings → Worship & reading → Mushaf packs. When you tap Download on a pack, the app fetches a single archive — about 2 MB for the KFGQPC Nastaleeq 15-line pack and about 46 MB for the KFGQPC V1 Madani 1405 pack at V1 — from a CDN we operate:
meowslimah-assets.raiyanasaral.com(Cloudflare R2 — for Mushaf pack archives)
- Bug reports (only when you initiate one). Settings → Report a bug opens a screen that previews the diagnostic information attached to your report: app version and build, device manufacturer and model, OS name and version, locale, timezone offset, your voice / gender / madhab / calculation-method preferences, whether today is marked as a rest day in the app (sent only as the word “rest” — the specific rest mode is never included), and Android alarm-system signals (battery-optimization status, exact-alarm permission, DND status, pending alarms) — plus the description you type and any screenshot you choose to attach. When you tap Send, your device's browser opens a URL that hands this data to a Cloudflare Worker we operate at
meowslimah-bug-report.mraiyanasaral.workers.dev. The Worker then files a GitHub issue in our public issue tracker at github.com/werdoe/meowslimah/issues with the diagnostic block and your description in the issue body. Attached screenshots are uploaded to a public Cloudflare R2 bucket and linked from the issue.This flow is fully opt-in — it only runs when you explicitly tap Send on the bug-report screen, after you've previewed exactly what will be attached. We use the information only to diagnose the issue you reported. Because the issue is filed in the public repo, please redact anything sensitive (names, locations, prose from your journal, etc.) before sending. If you'd rather email instead, write to [email protected] — same address, private inbox.
- Optional outbound links — the app includes occasional links to external Islamic-knowledge sources (currently: islamqa.info, for referenced fiqh rulings and fatwa source links). Tapping a link opens your device's browser. The app itself does not load any web content. Once you leave meowslimah, the destination website's privacy policy applies.
- Optional cloud sync (off until you turn it on). You can create a sync account with an email address and password so your own devices stay in step. Sync is entirely optional: meowslimah works fully without an account, and if you never make one, nothing on the list above ever leaves your device. When you turn sync on, selected app data — prayer logs, fasting logs, planner items, goals, notes, reminders, bookmarks, memorization progress, and settings — is stored in Supabase-protected cloud storage so your other signed-in devices can download it. This normal sync path is secure cloud storage; we are not claiming every normal synced field is encrypted in a way we could never read. Supabase receives the account information needed for sign-in, standard security metadata such as your IP address and user-agent, and the synced records themselves. We do not add ads, trackers, third-party analytics, or telemetry, and we do not sell or share any of it.
You stay in control of it: Settings → Sync & account lists the devices on your account and lets you remove any of them, delete everything stored in the cloud while keeping your local data, or delete the account outright.
Khalwah is different, and stays different. Your private journal is never included in ordinary sync. It syncs only if you turn it on separately, and you must turn it on on each device, entering your account password there. Khalwah pages are encrypted on your device before they are uploaded: Supabase stores only encrypted text and encrypted key material, never readable Khalwah. What the server can see for a synced journal day is the calendar date, the size of the encrypted page, when it was last edited, and which of your devices sent it — never a word of what you wrote.
One consequence you should understand before you turn Khalwah sync on, and which the app also tells you at that moment: your password protects the key that unlocks your synced journal. If you reset your password by email and no device remains signed in with your journal already unlocked, journal pages already uploaded may not be recoverable. The pages on a device you still have are unaffected — they are stored under that device's own key and are not lost.
Turning Khalwah sync off on a device is per-device and destroys nothing: that device simply stops sending and receiving journal pages. Erasing your Khalwah is a separate, deliberate action in Settings → Privacy & data.
Prayer times, Hijri calendar, du'a text, the 99 Names, and the bundled hadith corpus are all calculated or read locally. Du'a audio only leaves the device when you explicitly tap Play on an audio-enabled du'a or tap Download all du'a audio. Sync data leaves the device only if you turn sync on.
Analytics, advertising, and trackers
- No Google Analytics, Firebase Analytics, Mixpanel, Amplitude, or other third-party analytics.
- No advertising SDKs (no AdMob, no Meta Audience Network, no AppLovin, no IronSource).
- No tracking libraries (no Facebook SDK, no AppsFlyer, no Adjust).
- No telemetry beacons.
- Optional sync is not analytics. It exists only to keep your own devices in sync after you turn it on.
Children's privacy
meowslimah is suitable for users 3 and older per content rating. The app does not collect personal data for cloud processing unless you use an internet feature described above. A sync account, if you choose to create one, requires an email address and password, which are provided to Supabase.
Your rights and controls
- Export your data: Settings → Privacy & data → “Export your data” creates a JSON file with your non-sensitive data (Khalwah entries are deliberately excluded from this export).
- Delete your data: Uninstalling the app removes local app data from your device. If you turned sync on, deleting local data is separate from deleting what is stored in the cloud: Settings → Sync & account lets you delete your synced data while keeping the app, or delete the account entirely.
- Withdraw consent: You can revoke OS permissions (location, notifications, biometric) at any time in your device settings — the app will gracefully handle reduced functionality. Sync can be turned off at any time, and Khalwah sync can be turned off on its own without touching the rest.
- Bug reports stay opt-in: If you've filed a bug, the issue lives in our public GitHub tracker. You can request deletion or redaction of a specific issue by emailing [email protected].
Changes to this policy
If we change this policy again, we will update the "Last updated" date at the top of this page and notify users in-app before any new data flow begins.
Contact
For privacy questions or concerns, email [email protected].