Privacy
Your data, clearly explained.
This policy explains what DeenKit processes, why it is needed, how long it is kept and the choices available to you.
Last updated · 29 July 2026
1. Controller and scope
This policy covers the DeenKit iOS app, its widgets, this website and support requests.
No account is required. We only process data necessary for a requested feature, service security or optional analytics.
2. Data stored on your device
Your first name, personalization choices, favorites, reading progress, streak and widget settings are stored on your device or in the local App Group. When notifications are enabled, selected times and prayers are also synchronized with our API to keep them working.
This information is not used for advertising or sent to PostHog or TikTok. Uninstalling normally removes it, subject to Apple backup and synchronization settings.
3. Location and prayer services
With your permission, location is used to calculate prayer times and Qibla. Necessary coordinates are sent to our API and UmmahAPI for that request only, not for advertising or movement profiling.
To continue prayer alerts while the app stays closed, we retain coordinates rounded to about three decimals, timezone, calculation method, an installation identifier and the Apple Push Notification token while the feature is active. They are not used for advertising or movement tracking.
4. Optional analytics and advertising attribution
With consent, PostHog EU receives a pseudonymous identifier and events such as app opens, screens, key actions, paywall loading, technical purchase outcomes and crashes.
Your first name, precise location, spiritual answers, favorites, read text and support message content are excluded from the intended analytics events. Consent can be withdrawn in the app.
To measure and optimize DeenKit campaigns, the TikTok SDK processes a limited commercial funnel: consented installs, onboarding completion, Premium offer views, trial starts, first paid conversions and StoreKit-verified renewals. Paid events contain only the product, price and currency needed to measure advertising return. TikTok auto-capture of launches, payments and StoreKit purchases is disabled. No first name, email, phone number, location, spiritual answer or religious content is sent to TikTok.
Without iOS tracking permission, no direct event is sent to TikTok. Apple may still provide privacy-preserving aggregate install attribution through SKAdNetwork without allowing DeenKit to identify the person. You can withdraw advertising measurement in the app’s privacy settings and manage the system permission in iOS Settings > Privacy & Security > Tracking.
5. Website and contact
When you contact us, we process your name, email, topic, message and strictly necessary security data in order to answer, investigate an incident or handle a rights request.
Ordinary messages are retained for up to 24 months after the last response unless a legal claim or obligation requires longer. Security logs are generally retained for no more than 30 days.
6. Purchases
Apple processes payment and billing details. DeenKit receives only the StoreKit and Apple server-notification data needed to display products, verify Premium entitlement, restore purchases and process technical subscription events. We do not receive card details or your Apple Account password.
If you consent to optional analytics, a random installation UUID may accompany the transaction so PostHog can measure trial starts and conversions, renewals, expirations, failures, cancellations or refunds. Without consent, this analytics UUID is not attached to the purchase and subscription events are not sent to PostHog.
7. Legal bases and providers
Providers include Apple, TikTok, PostHog EU, Vercel, Neon, UmmahAPI and our email delivery provider. International transfers, where applicable, rely on a GDPR-recognized safeguard such as adequacy decisions or standard contractual clauses.
- Performance of the requested service.
- Consent for optional analytics, TikTok tracking attribution and location permission.
- Legitimate interests in API security, abuse prevention and error correction.
- Legal obligations where applicable.
8. Retention
- Local data: until deletion or uninstall, subject to Apple backups.
- Notification configuration: while the relay is active, then deleted or anonymized after lasting deactivation or Apple-token invalidation.
- Optional analytics: deleted or aggregated within 12 months.
- TikTok attribution: according to TikTok’s advertising-service retention periods and your iOS tracking choice.
- Support: up to 24 months after the last response.
- Transactions: according to Apple policies and applicable law.
9. Your rights
Depending on your situation, you may request access, correction, deletion, restriction, portability or object to processing, and withdraw consent. Use the Contact page. You may lodge a complaint with the French CNIL or your local supervisory authority.
10. Children, security and changes
DeenKit does not knowingly seek to collect children’s data. Parental involvement may be required where a child cannot consent alone under local law.
We use reasonable safeguards but cannot promise absolute security. Material changes will be announced on this page and, where appropriate, in the app.
References and contact
Apple Standard EULA · CNIL · Contact us
DeenKit