← /fitra / privacy
Fitra — Privacy & Terms
- Version
- v1.0
- Updated
- 2026-07-22
- Effective
- 2026-07-22
Fitra runs on your phone. We don’t collect your data, we don’t sell ads, and there is no server you sign in to. Everything below is the long form of that.
What we collect
Nothing leaves your device under normal use. Your preferences, prayer log, fasting log, tahajjud history, reading minutes, bookmarks, custom dhikr names, and Hijri event reminders are stored on your phone in an AES-256 encrypted database. The encryption key lives in the iOS Keychain, protected by your device passcode.
Location
If you grant location permission, your latitude and longitude are used on-device to compute prayer times and the Qibla bearing. Two public services help name your city and fetch a weather snapshot; they receive your coordinates over an encrypted connection with no identifier attached. We do not store your coordinates on any server.
Notifications
Adhan and Hijri-event reminders are scheduled locally on your device. There is no push server. Times are computed from your saved location and calculation method, then handed to iOS to fire at the right instant. Toggling adhan off cancels every scheduled future notification.
Qurʾān, hadith, dua content
All Qurʾān text, translations, tafsir, hadith collections, and duas are bundled inside the app and read entirely on your device — nothing is fetched to display them, and they work fully offline. The only content that streams is optional audio: Qurʾān recitation (from quran.com and everyayah.com) and downloadable audio packs (from Fitra’s content delivery network). Those requests carry no account or identifier; the servers see your IP address the way any download does.
No ads, no selling, no tracking
The app is sadaqah jariyah — built as ongoing charity. There are no ads on any screen, no advertising identifiers, no analytics SDKs, no cross-app tracking. We don’t sell, share, or monetise any data. There is no plan to change this.
Crash reports
There is no crash reporting. Fitra contains no crash-reporting SDK, no analytics SDK, and sends no diagnostic data anywhere. If the app misbehaves, the only way we find out is if you tell us — and we’d appreciate it.
Sign-in
There is no sign-in. Fitra has no account system, no user IDs, and no server that would recognise you. Your data lives on your device and, if you enable it, in your own private iCloud backup that only you control.
Your rights
You own your data because it lives on your device. To delete everything, delete the Fitra app — iOS removes the entire encrypted database when the app is uninstalled, and there is nothing on our side because we never received it. If you use iCloud backup, deletion of those backups is handled by your own iCloud settings. Each bookmark, prayer-log entry, and custom dhikr can also be deleted individually inside the app.
Children (COPPA & Apple 4+ rating)
The app is rated 4+ on the App Store and complies with the Children’s Online Privacy Protection Act (COPPA). It collects no information that identifies a child or an adult, requests no personal information at any age, has no chat or social features, and serves no advertising. Parents can supervise location and notification permissions through iOS Settings → Fitra.
Third-party services we connect to
None of these receive any account or device identifier from us; they see only your IP address, as any website does. All connections are encrypted and certificate-pinned where supported.
- quran.com & everyayah.com — Qurʾān recitation audio streaming, only while you play recitation.
- cdn.fitra.app — Fitra's own content delivery for optional audio-pack downloads. It serves files and stores nothing about you.
- open-meteo.com — Local weather snapshot displayed on the Today screen.
- nominatim.openstreetmap.org — Reverse-geocoder for the city-name label.
- cdn.jsdelivr.net — A small security manifest that keeps the app's certificate protections current.
No advertising identifier, no IDFA, no tracking
Fitra does not request or use the Apple Advertising Identifier (IDFA), does not implement App Tracking Transparency (ATT) prompts (because there is no tracking to authorise), and does not embed any analytics SDK that collects device fingerprints or behavioural signals. The app’s Privacy Manifest (PrivacyInfo.xcprivacy) declares Tracking = false and Tracking Domains = empty.
GDPR, CCPA, PIPEDA
Fitra does not process personal data in the GDPR/CCPA/PIPEDA sense — your data lives only on your device. There is no controller, no processor relationship, no cross-border transfer, no data-subject access request to fulfil because there is no copy of your data to access. If you want to exercise data-deletion rights anyway, deleting the app removes everything iOS stored on your behalf. Your iCloud backup may contain Fitra’s encrypted database; iOS handles deletion of those backups per your own iCloud settings.
Data retention
On-device data is retained until you delete it (either individually inside the app, or by uninstalling the app). We retain nothing on any server. Fitra’s content delivery network serves downloads only and keeps no logs tied to you.
Account deletion
Fitra has no account system; there is nothing to delete server-side.
Terms of use
The app is provided “as is” for personal worship and reference. Qurʾān text and translations are sourced from tanzil.net and quran.com; hadith corpora from sunnah.com and thaqalayn.net; all reproduced for educational and devotional use. Bundled adhan recordings: Masjid al-Ḥarām (Makkah) and Mishary Rashid Alafasy, plus two Shia recitations. Prayer-time calculations use the open-source adhan-dart library. Weather snapshots come from open-meteo.com.
Contact
Security or privacy concern: security@spidyops.com
General questions: ask@spidyops.com
Last updated 2026-07-22. This page mirrors what the app actually does today. If you spot a discrepancy, that is a bug — please tell us.