Mümin 360 — Privacy Policy
Last Updated: 5 July 2026 Effective Date: 5 July 2026 Data Controller: Burak Arslan / Türk Otağ — contact@turkotag.com — turkotag.com
1. Introduction and Data Controller
At Türk Otağ (the “Company”, “we”, “us”, “our”), we take the privacy of the users of the Mümin 360 mobile application (the “Application”) seriously. This Privacy Policy (the “Policy”) explains which data is collected whilst you use the Application, how it is processed, where it is stored, with which third parties and for what purpose it is shared, how long it is retained, and your rights over your personal data.
By downloading, installing or using the Application you declare that you have read, understood and accepted this Policy. If you do not accept this Policy, please do not use the Application.
- Data Controller: Burak Arslan / Türk Otağ
- Application: Mümin 360 (Bundle ID:
com.turkotag.mumin360) - Contact: contact@turkotag.com
- Website: https://turkotag.com
This Policy has been prepared to comply with the Turkish Personal Data Protection Law No. 6698 (KVKK), the EU General Data Protection Regulation (GDPR — for EU users), the California Consumer Privacy Act (CCPA — for US users), Apple App Store Privacy (Privacy Nutrition Label / Privacy Manifest) and Google Play Data Safety requirements.
2. Our Core Principles
Mümin 360 is built on a privacy-by-design approach:
- No account required: you do not need to register, provide an e-mail address or sign in to use the Application.
- Local storage first: your worship records, journals and preferences stay on your device; we cannot see them.
- Data minimisation: we process only the minimum data strictly necessary for the Application to work.
- Transparency: this document lists in full which data is shared, for what purpose and with which third party.
- You are in control: you may delete your data from the device at any time, revoke permissions and refuse ad tracking.
3. Data We Collect
3.1. Data Stored Only on Your Device (Never Reaches Our Servers)
The following data is kept only on your device, through the Application’s local state management (Zustand) and device storage (AsyncStorage):
Personalisation and preferences
- The name you provide (optional; a “Continue without a name” option is available)
- Language, theme (Onyx/Museum), sound, notification and high-contrast preferences
- Prayer calculation method and school (madhhab) preference
- Your chosen city/district (Diyanet mode) or device GPS coordinates (automatic location mode)
Worship and spiritual progress records
- Prayer completion status and prayer habit history
- Dhikr counts, custom dhikrs and dhikr sets
- Tahajjud tracking and pre-dawn intentions
- Spiritual journey progress, khatm plans, Qur’an reading history
- Journal entries and mood notes
- Mentor (local recommendation engine) chat state and history
- Favourite verses, hadiths, duas and search history
Encryption of this data is provided by the operating system’s application sandbox security. When you delete the Application, this data is permanently removed from your device. If iCloud backup on iOS or automatic backup on Android is enabled, this data may be included in the device-level backup; this is your operating system’s general backup behaviour and lies outside our control.
3.2. Data Transferred to Third Parties for Limited Purposes
| Data | Purpose | Recipient | Contains personal identifiers? |
|---|---|---|---|
| City/district code (Diyanet mode) | Fetching the 30-day prayer timetable | Turkish Presidency of Religious Affairs (Diyanet) EzanVakti service | No |
| GPS coordinates (automatic mode, one-off) | Fallback prayer time calculation | Aladhan API | No |
| Anonymous push notification token | Notification delivery | Supabase (push_tokens table), Expo Push service | No — a random, device-specific token |
| Crash/error stack traces | Fault diagnosis and application quality | Sentry | No — PII is automatically scrubbed (see 3.3) |
| Advertising identifier (IDFA/GAID) | Ad display (free tier only) | Google AdMob | Device-level, subject to your ATT/ad settings |
| Anonymous app-user ID | Subscription/premium status management | RevenueCat | No |
| Surah/verse/translation number | Fetching Qur’an text and recitation | AlQuran.cloud | No |
| Hadith/category ID | Fetching hadith content | HadeethEnc.com | No |
No data beyond what is listed in this table is shared with third parties.
3.3. Error Reporting with Sentry and PII Scrubbing
Sentry is used to monitor application stability. Before anything is sent to Sentry, fields that could contain personal data — name, e-mail, phone number, location coordinates, journal content, mentor messages — pass through an automatic PII-scrubbing layer and are replaced with [REDACTED]; e-mail/phone/GPS-coordinate patterns in free text are also masked using regex-based rules. In production the transaction sampling rate (tracesSampleRate) is limited to 20%.
3.4. Data We Never Collect
We do not collect the following categories of data under any circumstances:
- E-mail address or phone number (unless you contact us by e-mail)
- Payment or card details (purchases are processed entirely by Apple/Google; card data never reaches us)
- Photos, videos, audio recordings or camera imagery (microphone and camera permissions are never requested by the Application and are blocked at operating-system level)
- Contacts/address book data
- Biometric data (fingerprint, face recognition)
- Health data
- Social media account details
- Browsing history
4. Purposes of Data Use
The limited data collected is used solely for the following purposes:
- Calculating accurate prayer times for your location
- Determining the qibla direction
- Delivering prayer, tahajjud, holy night/Eid and dhikr reminder notifications on time
- Remembering your language, theme, sound and calculation-method preferences
- Calculating your spiritual score (0–100) and worship statistics
- Generating personalised suggestions from the locally-run mentor engine (a rule-based system that sends no data off the device and connects to no external AI service)
- Monitoring application stability and fixing faults (Sentry)
- Displaying ads in the free tier (AdMob) and verifying premium subscription status (RevenueCat)
Your data is never sold to third parties for profit, combined for user profiling, or added to marketing lists.
5. Third-Party Services — Complete List
| Service | Purpose | Privacy policy |
|---|---|---|
| Presidency of Religious Affairs (Diyanet) — EzanVakti | Official Turkish prayer times | ezanvakti.diyanet.gov.tr |
| AlQuran.cloud (Islamic Network) | Qur’an text, translations, recitation audio | alquran.cloud/privacy |
| HadeethEnc.com | Hadith content (Riyāḍ al-Ṣāliḥīn) | hadeethenc.com |
| Aladhan API | Fallback prayer times / Hijri calendar conversion | aladhan.com/privacy |
| RevenueCat | Subscription and purchase management | revenuecat.com/privacy |
| Google AdMob | Ad display (free tier only) | policies.google.com/privacy |
| Sentry (Functional Software Inc.) | Crash/error reporting | sentry.io/privacy |
| Supabase | Anonymous push token storage | supabase.com/privacy |
| Expo (Push Notifications, Updates, EAS) | Notification delivery, in-app updates | expo.dev/privacy |
| Apple App Store / Google Play Store | Distribution and payment processing | apple.com/privacy, policies.google.com/privacy |
Services not used: Google Analytics, Firebase Analytics, AppsFlyer, Mixpanel, Amplitude, Facebook/Meta SDK, TikTok SDK and session-recording tools (FullStory, Hotjar) are not used in the application.
Under Apple’s Privacy Manifest, tracking-related network traffic in the free tier may reach the following domains: googleads.g.doubleclick.net, pagead2.googlesyndication.com, googleads4.g.doubleclick.net, app-measurement.com.
6. Application Permissions
| Permission | Purpose | Required? |
|---|---|---|
| Location (While Using) | Prayer time calculation, qibla direction | No — without it, core functions continue via city selection |
| Notifications | Prayer/holy night/tahajjud/dhikr reminders | No |
| Motion and Compass (magnetometer) | Qibla compass | No — used only on the qibla screen |
| Background audio playback | Uninterrupted Qur’an recitation | No |
The Application explicitly blocks access to the microphone, camera and contacts at operating-system level. Background location access is never requested — location is processed only whilst the Application is in use.
All permissions are optional and can be changed at any time from your device’s Settings. Declining a permission does not prevent the rest of the Application from working.
7. Advertising and Tracking (App Tracking Transparency)
- Google AdMob ads are shown in the free tier.
- On iOS 14.5 and above, Apple’s App Tracking Transparency (ATT) prompt appears roughly 5 seconds after the home screen opens. If you decline, you will only see non-personalised ads.
- You may change this preference at any time via iOS Settings > Privacy & Security > Tracking. On Android you can reset your advertising ID or turn off ad personalisation in device settings.
- With a Premium subscription, all ads and all ad-SDK network traffic are disabled entirely.
- Beyond ad display, no behavioural profiling is performed and no data is sold outside the ad networks.
8. Data Security
- End-to-end TLS/HTTPS encryption is used for all network communication.
- Sensitive on-device data relies on iOS Keychain / Android Keystore and application sandbox isolation.
- A no-hardcoded-secrets policy applies to the source code; API keys are managed through environment variables.
- Data minimisation and purpose limitation are embedded across the entire development process.
No system can guarantee 100% security. We recommend keeping your device’s screen lock active and your operating system up to date.
9. Data Retention
- On-device data: remains on your device until you uninstall the Application; deletion is immediate and irreversible.
- Anonymous push token: becomes invalid when you uninstall the Application or disable notification permission; stale tokens are periodically purged server-side.
- Sentry error records: subject to Sentry’s standard retention policy (90 days by default); they contain no personal data.
- No persistent user profile or account record is ever kept on our servers.
10. Children’s Privacy
In terms of App Store and Play Store categories, Mümin 360 is aimed at a general audience of ages 13 and above, and — within the framework of the US Children’s Online Privacy Protection Act (COPPA) and GDPR Article 8 — aims never to knowingly and directly collect personal data from children under 13.
The in-app “Kids Mode” is an optional content module offering religious-educational content for children aged 5–12, intended for use under the supervision of a parent or legal guardian. Even this module involves no account creation or identity requests; its usage data, like all other data, stays on the device only. We recommend that parents ensure children under 13 use the Application (including Kids Mode) under their supervision.
If we become aware that we have collected identifying personal data belonging to a child under 13, we will delete it immediately following notification to contact@turkotag.com.
11. Your Rights (KVKK / GDPR)
Under Article 11 of KVKK No. 6698 and the GDPR, you have the following rights:
- Right to be informed — to learn whether your data is being processed.
- Right of access — as your data lives on your device, you can access it directly within the Application.
- Right to rectification — you may correct inaccurate/incomplete data within the Application, or request it via contact@turkotag.com.
- Right to erasure — Settings > “Delete All Data” instantly deletes all your local data; uninstalling the Application has the same effect. To delete the only server-held datum — the anonymous push token — write to contact@turkotag.com.
- Right to object to processing — you may object to ad tracking by declining the ATT prompt on iOS, or by resetting your advertising ID on Android.
- Data portability — an in-app automatic export feature does not currently exist; upon written request to contact@turkotag.com, the limited data we hold (only the anonymous push token) will be provided to you in a structured form. The data on your device is already under your direct control.
- Right to complain — to the Turkish Personal Data Protection Authority (kvkk.gov.tr) in Türkiye, or to the data protection authority of your country of residence in the EU.
You may submit requests to contact@turkotag.com; requests are answered within 30 days at the latest.
12. International Data Transfers
User data is processed primarily on-device and no international transfer takes place. However, limited data — the anonymous push token, crash reports and advertising services — may be processed on servers in the European Union or the United States. Appropriate safeguards are provided for these transfers under the GDPR’s Standard Contractual Clauses (SCC).
13. Changes to This Policy
This Policy may be updated from time to time.
- Significant changes are announced via in-app notification.
- The “Last Updated” date at the top of this document is revised.
- Continuing to use the Application after a change means you accept the updated Policy.
- Previous versions are available on request from contact@turkotag.com.
14. Contact
Türk Otağ / Burak Arslan
- E-mail: contact@turkotag.com
- Web: https://turkotag.com
KVKK applications: Personal Data Protection Authority — kvkk.gov.tr
15. Summary Table
| Question | Answer |
|---|---|
| Do I need to create an account? | No |
| Do you collect personal identifiers (name, e-mail, phone)? | No (unless you send them to us) |
| Where do my worship/journal records live? | Only on your device |
| Is a profile kept on your servers? | No |
| Are there ads? | Free tier only; entirely off in Premium |
| Can I delete my data? | Yes — instantly and permanently (Settings > Delete All Data) |
| Is it suitable for children? | Aimed at 13+; Kids Mode should be used under parental supervision |
This Privacy Policy came into force on 5 July 2026.