Privacy Policy
What Risalah collects, what it does not, and what you can ask for.
1. The short version
Risalah collects the minimum it needs to run an account-based library and a set of prayer tools. We do not sell your data. We do not build an advertising profile of you. Our content analytics are aggregate-only by design: no user IDs, no IP addresses and no per-event rows are stored, so there is no per-person browsing history for us to sell, lose or be compelled to hand over.
2. What we collect
Account details you give us: email address, username and display name; and optionally a phone number, gender, address, country, region, time zone, preferred language and preferred madhab. Only email, username and password are required.
Your password is never stored. We keep only an Argon2id hash of it, which cannot be reversed into your password.
Activity tied to your account: content you create, comments, likes, bookmarks, collections, reading progress, reading history and your notification preferences.
Session and security records: the IP address, browser and device of each active session, so you can review and revoke them, and so we can detect account takeover. Failed login attempts are recorded to block brute-force attacks.
Request logs: method, path, response status, latency, IP address, user agent and approximate location for requests to our API. These exist for security, abuse prevention and debugging.
Approximate location, derived from your IP address by our CDN at country, region and city level. It is cached briefly and used for security signals and regional availability rules.
Device location, only if you grant permission. Prayer times and the qibla are calculated on your device and those coordinates are not sent anywhere. Coordinates are sent to us only to find nearby mosques, and are not stored as a location history.
The state or province your device reports, if you have granted location permission and ask to see events near you. It is sent with that request so we can show events in your region rather than anywhere in your country, and it is not stored against you.
Push notification tokens, if you enable notifications.
3. What we deliberately do not collect
Announcement and content analytics are stored as daily aggregate counters only — impressions, clicks, dismissals and total dwell time, broken down by country, region, city and device category. No user IDs, no IP addresses, no device identifiers and no individual event rows are kept.
To count a view or an impression once rather than repeatedly, we use a salted, truncated visitor hash held in temporary cache for one hour and then discarded. It is scoped per item per day, so it cannot be used to link your activity across items or across days, and it is never written to the database.
We do not use third-party advertising or cross-site tracking SDKs.
4. Why we use it
To provide the service: authenticate you, show your library, sync reading progress across devices, and send the notifications you asked for.
To keep the service secure: detect and block brute-force attempts and abuse, alert you to sensitive changes such as a password change or a login from a new device, and investigate incidents.
To improve the platform: understand in aggregate which content is read, and where the product is failing, using the aggregate counters described above.
To meet legal obligations where they apply.
5. Email
We send transactional email — verification, password reset, security alerts — and, if you have opted in, notification and digest email.
Every message carries a one-click unsubscribe link and header. Unsubscribing takes effect immediately, requires no login, and turns off notification email without deleting any of your data. Security and account-critical messages are still sent.
6. Who else processes your data
We use a small number of infrastructure providers, acting on our instructions: a CDN and network provider that terminates connections and supplies the country-level location signal; object storage providers that hold media files; a search service; and an email delivery provider. Media is served through our own API rather than directly from storage, so storage URLs are never exposed to your browser.
If you configure an AI feature with your own provider key, the text you submit for translation, summarisation or transcription is sent to that provider under your account with them. Your key is encrypted at rest with AES-256-GCM and is used only for requests you initiate.
We do not sell personal data, and we do not share it with advertisers.
7. How long we keep it
Account data is kept while your account exists. Session records end when a session expires or you revoke it. Security and request logs are kept for a limited period for abuse investigation and then purged automatically. Aggregate analytics counters contain no personal data and are retained indefinitely.
8. Your choices and rights
You can view and edit your profile, change your password, enable two-factor authentication, review and revoke sessions, change your notification preferences, and delete your account — all from Settings in the app.
Deleting your account removes your profile and personal data. Content you published may be retained where others rely on it, but is disassociated from your identity unless you ask for it to be removed as well.
Depending on where you live you may have additional rights over your data, including access, correction, deletion, portability and objection. Write to support@risalahapi.net and we will honour them.
Location permission can be withdrawn at any time in your device settings. Prayer times will then fall back to a city you choose manually.
9. Children
Risalah is not directed at children under 13, and we do not knowingly collect their personal data. If you believe a child has created an account, contact support@risalahapi.net and we will remove it.
10. Security
Passwords are hashed with Argon2id. Access tokens are short-lived and refresh tokens rotate on every use, with reuse treated as theft and the session revoked. Sensitive stored values — AI keys, backup codes, reset tokens — are encrypted or hashed. Traffic is served over HTTPS.
No system is perfectly secure. If you find a vulnerability, please report it to security@risalahapi.net rather than disclosing it publicly, and we will work with you on a fix.
11. Changes to this policy
We will update this page when our practices change and revise the date at the top. Material changes will be announced in the app or by email before they take effect.
12. Contact
Privacy questions and data requests: support@risalahapi.net Security reports: security@risalahapi.net