Privacy Policy — Salaha
Effective Date: September 5, 2026 Last Updated: September 6, 2026 Application: Salaha (“the App”) Developer / Data Controller: Codethenic (“we,” “us,” or “our”) Contact: codethenic@gmail.com
1. Introduction
This Privacy Policy describes how Codethenic (“we,” “us,” or “our”) collects, uses, stores, discloses, and safeguards information when you use the Salaha mobile application for Apple iOS.
Salaha is a prayer-times, Qibla-compass, devotional-tracking, and voluntary app-blocking utility. It is designed on a privacy-first, on-device architecture:
Salaha operates without a proprietary backend server. Your prayer records, location, onboarding answers, preferences, and health-related settings are stored exclusively on your device. We do not operate a server that stores your personal data, and we do not sell your personal data.
By downloading, installing, or using the App, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with this Policy, please do not use the App.
This Policy should be read in conjunction with Apple’s Privacy Policy, RevenueCat’s Privacy Policy, and Mixpanel’s Privacy Policy, each of which governs their respective processing as described in Section 6.
2. Definitions
For the purposes of this Policy:
- “Personal Data” means any information relating to an identified or identifiable individual, as defined under the EU General Data Protection Regulation (“GDPR”), the UK GDPR, and the California Consumer Privacy Act / California Privacy Rights Act (“CCPA/CPRA”).
- “Sensitive Data” means Personal Data revealing religious beliefs, health-related information, precise geolocation, or other special-category data under applicable law.
- “On-Device Processing” means computation or storage that occurs locally on your iPhone and is not transmitted to a server controlled by the Developer.
- “Third-Party Processor” means an independent service provider (Apple Inc., RevenueCat, Inc., Mixpanel, Inc.) that processes limited data on our behalf or in its capacity as an independent controller, as described in Section 6.
3. Summary of Data Practices
The following table provides an overview. Full details are set forth in Section 4.
| Category | Examples | Storage Location | Transmitted Off-Device |
|---|---|---|---|
| Precise Geolocation | Location coordinates, elevation, time zone, city/country name | Device only | To Apple only, when you use current location or city search. Never to our server. |
| Religious Practice Data | Prayer prayed/missed records, devotional counts, calculation preferences, blocking selections | Device only | No |
| Health-Related Data | Period Mode status and related dates | Device only | No |
| User-Provided Onboarding Data | First name, age range, gender, motivations, prayer habits, occupation type, self-reported screen time | Device only | No |
| Purchase Data (only upon purchase) | Subscription status, expiration/renewal state | Device, Apple App Store, subscription provider | To Apple and our subscription provider for verification only |
| Motion and Compass Signals | Device orientation, compass heading | Processed temporarily on-device; not stored | No |
| Product Analytics | Anonymous app-open and paywall-interaction counts (see Section 4.8) | Device (ephemeral) → analytics provider | To our analytics provider only. No name, email, location, or prayer data. |
The App does not collect, access, or process: contacts, photos, camera, microphone, Face ID biometrics, Apple HealthKit data, Bluetooth data, advertising identifiers, or data for cross-app tracking. App Tracking Transparency is never requested.
4. Data We Collect and Lawful Purposes
4.1 Precise Geolocation
- When collected. Only when you tap “Use Current Location,” grant Location permission, search for a city, or open the live Qibla compass.
- What is collected. Location coordinates, elevation, time-zone information, and a city/country name derived via Apple’s geocoding services.
- Purpose and legal basis. To display accurate prayer times, Qibla direction and distance, and the applicable local time zone. All prayer-time and Qibla calculations are performed on-device with no network dependency. Processing is based on your consent (permission grant) and is necessary for the core functionality you request.
- Default. If you decline permission, the App uses a default location (Makkah) and permits manual city entry.
- Disclosure. Location or a typed place query is transmitted to Apple Inc. solely to resolve place names and time zones, governed by Apple’s Privacy Policy. Data is never sent to a server controlled by the Developer.
4.2 Religious Practice and App-Usage Data (Sensitive Data)
Because this data may reveal religious beliefs, we treat it as Sensitive Data and apply heightened protections: on-device storage only, no analytics, no advertising, no sale.
- Prayer records. Daily prayer completion status with dates, used solely for streaks, consistency views, and progress screens rendered locally.
- Devotional counters. Selected remembrances, current counts, and targets, stored on-device.
- Prayer settings. Calculation method, jurisprudence setting, rounding preferences, time adjustments, and blocking configurations you choose.
- App-blocking selections. Blocking choices you make through Apple’s Screen Time framework. These are managed by iOS; we cannot see your app-usage activity and receive no usage histories from Apple. Used solely to enforce voluntary blocking schedules you configure.
- Purpose and legal basis. Strictly necessary for the performance of the App’s requested functionality and processed on the basis of your explicit consent.
4.3 Health-Related Data — Period Mode (Sensitive Data)
- What is collected. Whether Period Mode is active and its associated dates, stored on-device.
- Purpose and legal basis. When you voluntarily enable Period Mode, the App pauses streak penalties, reminders, and app blocking during menstruation. Processing is based on your explicit consent, is entirely on-device, and is never transmitted or used for any other purpose.
4.4 User-Provided Onboarding Data
- What is collected. Only what you voluntarily provide during onboarding: first name; age range; gender; what matters most to you; prayer frequency; reasons for and feelings about missed prayers; occupation or lifestyle descriptor; and self-reported screen-time information.
- Purpose and legal basis. In-app personalization only (e.g., tailored messaging and progress projections). Based on your consent. Stored on-device only. Never uploaded, profiled remotely, or used for advertising.
- Deletion. You may delete this data at any time by deleting the App, by using the in-app clear or reset option where available, or by contacting us at codethenic@gmail.com for assistance.
4.5 Motion and Compass Signals
- What is collected. Device orientation and compass heading, used on the Qibla screen to render direction and to warn when the device is not held flat.
- Storage and disclosure. Processed temporarily on-device for display purposes only. Not stored, logged, or transmitted.
4.6 Local Notifications
- What is collected. Prayer reminders scheduled locally on your device. Scheduling is paused while Period Mode is active.
- Disclosure. Local only. No remote push server is operated and no notification content leaves the device.
4.7 Screen Time and App Blocking
- What is processed. Blocking rules and schedules you configure, enforced locally by iOS through Apple’s Screen Time framework and the App’s system extension. We do not receive usage duration, app-activity histories, or any other Screen Time analytics from Apple.
- Disclosure. Strictly local communication between the App and its system extension on your device. Governed by Apple’s system privacy guarantees.
4.8 Product Analytics (Anonymous Only)
We use a third-party analytics provider (Mixpanel, Inc.) for minimal, privacy-preserving product measurement. Automatic data collection is disabled. No user profiles are created and the App has no login, so no identity is attached to analytics events.
We collect only aggregate, anonymous counts for two purposes: (a) understanding overall retention (app opens, with whether onboarding was completed), and (b) understanding paywall performance (how often the subscription screen is shown and whether it is dismissed, purchased, or restored, along with the subscription tier selected where applicable).
No name, email, precise location, prayer record, onboarding answer, or advertising identifier is included in any analytics payload. Analytics is based on our legitimate interest in maintaining and improving the App.
You may limit this processing by using the App offline; events cannot be delivered without network connectivity.
4.9 Purchase Data (Only Upon Purchase or Restore)
- When collected. Only if you initiate a purchase of Salaha Plus or restore prior purchases.
- What is collected. Transaction confirmation, subscription status, and expiration/renewal state needed to unlock paid features.
- Purpose and legal basis. Necessary to validate the transaction and unlock paid features you request (performance of contract).
- Disclosure. Shared with the Apple App Store and our subscription management provider (RevenueCat, Inc.) solely for receipt verification and entitlement management, governed by their respective privacy policies. No location, prayer, onboarding, or health data is shared with our subscription provider.
5. Where Data Is Stored
All Personal Data described in Sections 4.1–4.7 is stored exclusively on your device using iOS-provided local storage and system stores managed by iOS (including scheduling and notification stores).
There is no iCloud synchronization, no Developer backend, no custom server, and no cross-device account. The only network transmissions involving user-adjacent data are the anonymous analytics events (Section 4.8) and the Apple / subscription-provider exchanges described in Sections 4.1 and 4.9. Deleting the App permanently deletes all locally stored data, subject only to any encrypted device backup you independently maintain.
6. Disclosure to Third Parties
We do not sell, rent, share for cross-context behavioral advertising, or otherwise monetize your Personal Data.
| Recipient | Data Disclosed | Circumstances | Governing Policy |
|---|---|---|---|
| Apple Inc. | Location or typed place query; purchase receipts | When you use current location, search a city, use the Qibla compass, or make a purchase | https://www.apple.com/privacy/ |
| RevenueCat, Inc. | Purchase confirmation and subscription status | Only when you purchase or restore a subscription | https://www.revenuecat.com/privacy |
| Mixpanel, Inc. | Anonymous aggregate event counts (app opens, paywall views and outcomes) | On app open and on paywall interaction | https://mixpanel.com/legal/privacy-policy/ |
All other features function offline. Prayer-time and Qibla computations never leave the device.
7. Permissions Requested
| iOS Permission | Purpose | Required? |
|---|---|---|
| Location When In Use | Prayer times and Qibla | No — manual city entry is available |
| Motion & Fitness | Flat-device detection for compass accuracy | No — compass remains visible without it |
| Notifications | Prayer reminders | No — in-app times remain available |
| Screen Time | Voluntary app blocking until prayer confirmation | No — the App is fully usable without blocking |
We do not request access to the camera, microphone, photos library, contacts, Face ID, Bluetooth, local network, or cross-app tracking.
8. Data Retention and Your Rights
- Retention. Data persists on your device until you delete it. Prayer records accumulate locally over time; you may reset settings or delete the App at any time to remove them. Purchase records retained by Apple and our subscription provider are subject to their retention schedules.
- Deletion. Deleting the App removes all local Personal Data. Onboarding data may additionally be cleared in-app or by contacting codethenic@gmail.com. To delete purchase-related data held by Apple or our subscription provider, please exercise your rights directly with those providers pursuant to their policies.
- Access and correction. All locally stored data is viewable and editable within the App (Settings, Analytics, City Search, Onboarding). Because there is no account or server copy, there is no hosted profile to export from our systems.
- No account. The App offers no login and maintains no server-side copy of your data; accordingly, account-deletion workflows do not apply.
8.1 Rights of Users in the European Economic Area, the United Kingdom, and Switzerland (GDPR)
If you are located in the EEA, UK, or Switzerland, you have the following rights, subject to applicable limitations:
- Access (Art. 15) — to obtain confirmation of processing and a copy of Personal Data under our control;
- Rectification (Art. 16) — to correct inaccurate data;
- Erasure (Art. 17) — to request deletion where a ground applies;
- Restriction (Art. 18) — to restrict processing in specified circumstances;
- Portability (Art. 20) — to receive locally stored data you provided in a structured, commonly used format where technically feasible;
- Objection (Art. 21) — to object to processing based on legitimate interests;
- Withdrawal of consent (Art. 7(3)) — to withdraw consent at any time (e.g., by revoking Location, Motion, Notification, or Screen Time permissions in iOS Settings), without affecting prior lawful processing.
Because processing is on-device, most rights can be exercised directly and immediately within the App or iOS Settings. For any request we must handle, contact codethenic@gmail.com; we will respond within one month as required by law. You also have the right to lodge a complaint with your local supervisory authority.
Lawful bases relied upon: consent (location, motion, notifications, Screen Time, onboarding, Period Mode, Sensitive Data); performance of a contract (purchase validation); legitimate interests (anonymous aggregate analytics to maintain and improve the App).
8.2 Rights of California Residents (CCPA/CPRA)
If you are a California resident, you have the following rights:
- Right to know — the categories and specific pieces of Personal Data collected, sources, purposes, and categories of third parties to whom data is disclosed (all as set forth in Sections 3–6);
- Right to delete — deletion of Personal Data, subject to statutory exceptions (exercisable by deleting the App for all Developer-held data);
- Right to correct — correction of inaccurate Personal Data (exercisable directly in-app);
- Right to opt out of sale/sharing — we do not sell Personal Data and do not share Personal Data for cross-context behavioral advertising; there is therefore nothing to opt out of;
- Right to limit use of Sensitive Personal Information — Sensitive Data (religious practice, Period Mode, precise geolocation) is used solely for requested App functionality and never for inferring characteristics or for advertising;
- Right to non-discrimination — you will not be penalized for exercising your privacy rights.
You may designate an authorized agent to act on your behalf by providing written authorization and verifying your identity. To exercise any CCPA right against the Developer, contact codethenic@gmail.com. We will verify, respond, and complete qualifying requests within the timeframes required by law.
8.3 International Data Transfers
Our analytics and subscription providers are based in the United States. Where data described in Sections 4.8–4.9 is transmitted to the United States, it is protected by the contractual and technical safeguards maintained by those providers. Developer-held Personal Data (Sections 4.1–4.7) is not transferred internationally by us because it never leaves your device except to Apple for on-request geocoding as described in Section 4.1.
9. Children’s Privacy
The App is not directed to children under the age of 13, and we do not knowingly collect Personal Data from children under 13. Users under the age of majority should use the App with parental or guardian guidance. If you believe a child under 13 has provided Personal Data through the App, please contact us at codethenic@gmail.com and we will provide instructions for deleting all locally stored data. Given the on-device architecture, deletion is accomplished by removing the App from the device.
10. Security
Personal Data is protected by Apple’s iOS sandboxing, data-protection features, and the device passcode and biometric protections you enable. No Developer server exists that could be breached. Transmissions to Apple and our service providers are protected in transit and governed by those providers’ security programs. While we implement reasonable safeguards appropriate to an on-device architecture, no method of electronic transmission or storage is completely secure, and we cannot guarantee absolute security of transmissions to third parties.
11. Changes to This Policy
We may update this Privacy Policy to reflect changes to the App, our practices, or legal requirements. When we do, we will revise the “Last Updated” date above and, where appropriate, describe the changes in the App Store release notes or within the App. Your continued use of the App after an update constitutes acknowledgment of the revised Policy. For material changes affecting Sensitive Data or introducing new third-party disclosures, we will provide prominent in-app notice and obtain any additional consent required by law.
12. Contact Us
For questions, requests to exercise your privacy rights, or complaints regarding this Privacy Policy or our data practices, contact:
Developer: Codethenic Application: Salaha Email: codethenic@gmail.com
We endeavor to respond to all inquiries promptly and in any event within the timeframes required by applicable law.
13. Apple App Store Privacy Nutrition Label Summary
For Apple App Store Connect, this Policy corresponds to the following disclosures:
- Tracking: None. The App does not track you across apps or websites. No advertising identifier is collected.
- Data Not Linked to You / Not Used for Tracking:
- Precise Location — App Functionality (on-device computation; Apple geocoding on request);
- Sensitive Info (religious practice; health-related features) — App Functionality, on-device only;
- User Content (first name, onboarding answers) — App Functionality, on-device only;
- Purchases — App Functionality (Apple and subscription-provider verification);
- Product Interaction (anonymous app-open and paywall counts) — Analytics, not linked to identity.
- Screen Time API use is declared; the App does not receive usage content beyond the blocking selections you make.