Effective date: 3 August 2026 · Last updated: 3 August 2026
Prayer Lock (“the App”, “we”, “us”) is published by Zappsco. This policy explains what the App collects, why, where it goes, and what control you have over it.
Contact us at any time: hello@zappsco.com
1. Summary
- We do not sell your personal information, and we do not share it with data brokers or advertisers.
- Your location is used only to calculate prayer times and Qibla direction. We do not store a location history.
- Your App Blocker selections never leave your device.
- Reading the Quran, viewing prayer times, and using the Qibla compass do not require an account.
- An account is required only to purchase, restore, or hold a Pro subscription, because your entitlement is tied to your account rather than to a device.
2. Information we collect
2.1 Information you provide
| Data | When | Why |
|---|---|---|
| Email address | You create an account or sign in | Account identity, sign-in, account recovery |
| Display name | You create an account with email | Shown in the App's profile area |
| Invite code | You redeem one | Validating the code and granting Pro |
Sign in with Apple. If you sign in with Apple and choose Hide My Email, we receive only Apple’s private relay address. That relay address is the only email we hold for you, and we treat it as your email address.
Sign in with Google. We receive the email address and basic profile information associated with the Google account you choose.
We never receive or store your password for Apple or Google. Passwords for email accounts are handled by Firebase Authentication and are never visible to us.
2.2 Information collected automatically
| Data | Purpose | Leaves the device? |
|---|---|---|
| Approximate/precise location | Calculating prayer times and Qibla direction | Coordinates are sent to the prayer-times API (see §4) |
| Device compass / motion data | Pointing the Qibla compass | No |
| Time zone | Scheduling adhan and reminders at the correct local time | No |
| Crash diagnostics (stack traces, device model, OS version, app version) | Diagnosing crashes | Yes — Firebase Crashlytics |
| Product analytics events (screens viewed, features used, subscription lifecycle) | Understanding which features are used and where people get stuck | Yes — see §3 |
| Purchase and subscription state | Determining whether Pro is active | Yes — RevenueCat and the app store |
2.3 Information that stays on your device
The following is stored locally and is never transmitted to us or anyone else:
- Your App Blocker selections — the list of apps you choose to block during prayer windows. This is deliberately excluded from analytics and is never attached to any event we send.
- Quran text, translations, bookmarks, last-read position, and search index.
- Cached prayer times (retained for roughly 30 days so the App works offline).
- Your settings: theme, calculation method, madhab, Arabic font size, translation visibility, notification preferences.
Uninstalling the App deletes all of this local data.
3. Analytics and crash reporting
We use two analytics services, both configured to minimise what they receive:
- Firebase Analytics and Firebase Crashlytics (Google)
- PostHog (product analytics)
Specific commitments about how these are configured:
- Session Replay is disabled. PostHog’s screen-recording feature is switched off in the App’s configuration. We do not record your screen.
- Sensitive keys are redacted before sending. Property values whose names match
email,password,token,card,cvc, orsecretare replaced with***before any event leaves the device. - App Blocker data is never sent as an event property, in any form.
- Analytics are disabled in development builds and enabled only in released versions of the App.
- Crash reporting is disabled in development builds.
Analytics events are associated with your account identifier once you sign in, so that we can distinguish “one person using the App on five occasions” from “five people”. We attach a small set of properties to your profile: platform, app version, build number, whether Pro is active, country (when available), which sign-in provider you used, and whether this is a first install.
Advertising identifiers
The App includes the Firebase Analytics SDK, which links Apple’s AdSupport framework on iOS. The App does not currently display advertisements and does not use this for advertising or cross-app tracking. If we ever introduce advertising, we will update this policy before doing so and, on iOS, request your permission through the system App Tracking Transparency prompt.
4. Third parties who receive data
| Service | What it receives | Why |
|---|---|---|
| Firebase Authentication (Google) | Email address, sign-in provider, account identifier | Account creation and sign-in |
| Firebase Crashlytics (Google) | Crash diagnostics, device and OS information | Diagnosing crashes |
| Firebase Analytics (Google) | Product analytics events | Understanding feature usage |
| Firebase Cloud Functions (Google) | Your account identifier when you redeem an invite code or delete your account | Validating invite codes; deleting your server-side data |
| PostHog | Product analytics events | Understanding feature usage |
| RevenueCat | Your account identifier and purchase receipts | Managing subscription entitlement across devices |
| Apple App Store / Google Play | Payment details, handled entirely by them | Processing purchases |
| Aladhan API (api.aladhan.com) | Latitude and longitude, date, calculation method | Calculating prayer times |
| Al-Quran Cloud API (api.alquran.cloud) | No personal information | One-time download of Quran text |
We never see your payment card details. All payments are processed by Apple or Google under their own terms and privacy policies.
Each of these providers processes data under their own privacy policy. We select them for the function described and do not authorise them to use your information for their own advertising.
5. Location, in detail
Location deserves its own section because it is the most sensitive thing the App touches.
- Location is requested only for prayer-time calculation and Qibla direction.
- We request “when in use” access. The App does not track you in the background.
- Coordinates are sent to the Aladhan API to compute prayer times for your area, and the resulting times are cached on your device.
- We do not build or retain a location history. We do not store your coordinates on our servers.
- You can decline location access and enter your city manually instead. Prayer times will still work.
- You can revoke location access at any time in your device settings.
6. Notifications
Prayer notifications and the adhan are local notifications scheduled on your device. The App does not use push notification servers, and we do not send you remote messages. Nothing about your prayer schedule is transmitted to us.
On Android the App requests permission to schedule exact alarms and to run outside battery optimisation, solely so the adhan sounds at the correct moment.
7. App Blocker
The App Blocker restricts selected apps during prayer windows.
- On Android it uses the Usage Access and Display-over-other-apps permissions to detect and cover a blocked app. These permissions are requested explicitly through an in-app screen — never silently.
- On iOSit uses Apple’s Screen Time (Family Controls) framework. Because of how that framework works, the App never sees the identity of the apps you select; Apple’s picker keeps that private even from us.
In both cases, your selections and any usage data the feature relies on stay on your device. None of it is transmitted, logged remotely, or included in analytics.
8. Children
Prayer Lock is a general-audience app and is not directed at children under 13 (or the equivalent minimum age in your country). We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, contact hello@zappsco.com and we will delete it.
9. Data retention
- Account data is retained while your account exists.
- Cached prayer times are retained on your device for about 30 days.
- Crash and analytics data is retained according to the provider’s default retention period, after which it is deleted or aggregated.
- Invite-code redemption records are retained while your account exists, to enforce one redemption per person.
- Local content (Quran text, bookmarks, settings, App Blocker selections) remains until you delete the App.
10. Your rights and choices
Depending on where you live, you may have the right to access, correct, export, restrict, or delete your personal information, and to object to certain processing. To exercise any of these, contact hello@zappsco.com.
Deleting your account. You can delete your account from within the App (More → your profile → Delete Account). Deletion completes in-app: it removes your authentication record and the data we hold that is keyed to your account. If in-app deletion fails for any reason, the App offers a fallback that emails the request to us, and you can always write to hello@zappsco.com directly. Note that:
- Local data on your device is removed by uninstalling the App.
- Purchase records held by Apple or Google are governed by their policies, not ours; we cannot delete them on your behalf.
- Deleting your account does not cancel an active subscription. Cancel through your App Store or Google Play subscription settings first.
Withdrawing permissions. Location, notifications, Usage Access, and Display-over-other-apps can each be revoked at any time in your device settings. The App degrades gracefully: prayer times fall back to manual location, and blocking simply stops.
11. Security
We use industry-standard measures to protect your information, including encryption in transit and access controls on our backend. Authentication is handled by Firebase Authentication. Server-side invite-code validation and account deletion run through authenticated Cloud Functions that verify your identity server-side rather than trusting the App.
No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
12. International transfers
Our service providers may process and store data in countries other than yours, including the United States. Where required, these transfers rely on appropriate safeguards such as the European Commission’s standard contractual clauses.
13. Changes to this policy
We may update this policy as the App changes. When we make a material change we will update the “Last updated” date above and, where the change is significant, give notice inside the App. Continuing to use the App after an update means you accept the revised policy.
14. Contact
Questions, requests, or complaints about privacy: