Skip to main content

Privacy Policy

Last updated : 26 avril 2026

1. Introduction

Quran & Prayer - Deen Coach (“the App”) is an Islamic mobile application developed by Wazmine, distributed worldwide via the Apple App Store and the Google Play Store. We are committed to protecting your privacy. This policy explains how we handle your data, regardless of your country of residence and the store from which you installed the App.

2. Core Principle: Offline-First

The App is designed with an offline-first approach. This means all essential features work without an internet connection and your data stays exclusively on your device.

3. Scope: Mobile Application and Website

This policy covers two distinct scopes that do not process data in the same way:

  • Mobile Application Quran & Prayer - Deen Coach: no collection, no account, no identifier. Everything stays on your device (see sections 4 to 6).
  • Website deencoach.app: no third-party cookies and no marketing tracker. Only one optional collection is possible: the email address for the newsletter, with double opt-in and one-click unsubscribe in every message (see section 7).

4. Data Collected by the Mobile Application

The mobile App does not collect any personal data.

  • No user account is required
  • No unique identifiers are generated
  • No browsing data is recorded
  • No third-party cookies are used
  • No analytics or marketing tracking tools are integrated
  • No advertisements are displayed

5. Local Storage

All your data (progress, favorites, settings, reading history) is stored only locally on your device in an encrypted SQLite database. This data is never transmitted to an external server.

6. Permissions Used

The App may request the following permissions:

  • Microphone: used only for the Quran recitation feature (voice coach) and voice search. Audio is never recorded or transmitted - it is processed in real-time on the device.
  • Location: used only for Qibla direction calculation and prayer times based on your position. Location is never stored or shared.
  • Notifications: used for prayer and adhkar reminders, configured by you. No promotional notifications are sent.
  • Storage: used for offline content downloads (Quran audio, content packs).

Each permission is requested when needed, with a clear explanation. You can deny any permission without affecting other features.

7. Website Newsletter (Optional Collection)

The deencoach.app website offers, on the /en/newsletter/ page, an entirely optional subscription to a sourced weekly reminder. You cannot be subscribed without having explicitly checked the consent box and confirmed via the link received by email (double opt-in).

  • Data processed: email address, technical submission timestamp, chosen language (FR / EN / AR).
  • Purpose: sending a sourced weekly reminder and major announcements (new versions of the App, religious events).
  • Legal basis: explicit consent (GDPR Art. 6 § 1.a), withdrawable at any time.
  • Retention: as long as you remain subscribed. Unsubscription is available in one click in every email; it leads to the deletion of your address at the sub-processor.
  • Immediate deletion on request: send a message to [email protected] and we will process the deletion within 30 days (usually much faster).
  • No resale, no profiling, no advertising. The email address is used exclusively to send the newsletter.

8. Sub-processors and Data Transfers

We deliberately limit the use of vendors. The two sub-processors below are the only parties to whom data related to the website may be entrusted. The mobile App uses no sub-processor.

EmailOctopus Ltd (United Kingdom)— newsletter delivery

  • Data processed: email address, timestamp, language, subscription status.
  • Purpose: store the subscriber list, send the weekly reminder, manage double opt-in and unsubscriptions.
  • Legal basis: performance of the service you explicitly requested (consent, GDPR Art. 6 § 1.a).
  • Processing location: United Kingdom. The UK is recognized as an adequate country by the European Commission since adequacy decision 2021/1772 of 28 June 2021. No additional mechanism (standard contractual clauses) is legally required for this transfer.
  • Email authentication: DKIM, SPF and DMARC configured on deencoach.app to prevent domain spoofing.
  • Vendor privacy policy: emailoctopus.com/privacy-policy

Cloudflare, Inc. (United States and global network)— website hosting, CDN, DNS and security

  • Data processed: IP address, user-agent, HTTP headers, request metadata. No marketing tracking cookies are placed.
  • Purposes: (1) serving the website pages via the CDN; (2) protecting against bots, spam and denial-of-service attacks (Bot Management, WAF, rate limiting); (3) logging network errors for operational reliability (Network Error Logging, Report-To header, configured to report failures only).
  • Legal basis: legitimate interest (GDPR Art. 6 § 1.f) — security, fraud prevention and reliability of a public online service. These processing activities qualify as strictly necessary security measures and do not serve commercial profiling or audience measurement.
  • Processing location: Cloudflare global network (Europe, United States, Asia, etc.). Cloudflare publishes standard contractual clauses for non-EU transfers.
  • Retention: in line with Cloudflare's policy (typically a few days to a few weeks for security logs).
  • Vendor privacy policy: cloudflare.com/privacypolicy

No other sub-processor is used. No Google Analytics, no Meta Pixel, no Intercom, no Sentry, no Hotjar, no marketing SDK, no third-party chat service. No cookie-based audience measurement tool is in place: any access statistics rely on aggregated Cloudflare server logs, without user identifiers.

9. Data Sharing

Apart from the two sub-processors listed in section 8, we do not share any data with third parties. No resale, no transfer, no exchange with data brokers.

10. Children's Data and Family Use

The App is suitable for family useand does not collect any data, including data of minors. In line with international regulations on children's data:

  • COPPA (United States, children < 13): no recording, no collection, no targeted advertising
  • GDPR Article 8 (EU, minors < 16): no consent needed because no data is processed
  • UK GDPR (United Kingdom, < 13): same posture
  • POPIA Section 35 (South Africa, < 18): no parental consent required because no processing

The App contains no content inappropriate for children and provides no unmoderated external links.

11. Security

Locally stored sensitive data is encrypted. No data is transmitted over the internet unless you explicitly download additional content (audio packs, etc.), in which case only the download request is made via HTTPS.

On the website side, the email address transmitted when subscribing to the newsletter travels over HTTPS (TLS 1.2 or 1.3) to the sub-processor EmailOctopus. No copy of the mailing list is kept on our infrastructure.

12. Your Rights by Jurisdiction

The mobile App collects no personal data: there is therefore nothing to access, modify or delete server-side. All your data is under your full control on your device and can be deleted at any time by uninstalling the App or via the “Clear my data” function in settings.

If you are subscribed to the website newsletter, you additionally have the following rights over your email address:

  • Access: obtain confirmation and a copy of the data concerning you.
  • Rectification: correct an incorrect email address.
  • Erasure: via the unsubscribe link in every email (immediate effect) or on simple request to [email protected].
  • Portability: receive your data in a structured, commonly used format.
  • Objection and restriction of processing at any time.
  • Withdrawal of consent: without justification, without affecting the lawfulness of prior processing.
  • Complaint to a supervisory authority (see list below by jurisdiction).

Depending on your place of residence, you have additional rights (for example the right not to be subject to automated decision-making, the right to refuse sale under CCPA / CPRA, etc.) that we respect by design since these processing activities are not in place. Major applicable laws and their regulators include:

Europe and Americas:

  • EU / EEA (GDPR): CNIL (France) and national authorities (BfDI Germany, AEPD Spain, Garante Italy, etc.)
  • United Kingdom (UK GDPR + Data Protection Act 2018): ICO
  • Switzerland (revised FADP 2023): FDPIC
  • United States - California (CCPA / CPRA): California Privacy Protection Agency (CPPA)
  • Canada (PIPEDA + provincial laws): Office of the Privacy Commissioner of Canada
  • Brazil (LGPD): ANPD

Francophone Africa and Maghreb:

  • Morocco (Law 09-08): CNDP
  • Tunisia (Law 2004-63): INPDP
  • Algeria (Law 18-07): ANPDP
  • Senegal (Law 2008-12): CDP
  • Ivory Coast (Law 2013-450): ARTCI
  • Benin (Law 2017-20): APDP
  • Burkina Faso (Law 010-2004): CIL
  • Mali (Law 2013-015): APDP Mali
  • Togo (Law 2019-014): IPDCP
  • Mauritania (Law 2017-020): ANRPDP
  • Cameroon (Law 2010/012 on Cybersecurity): ANTIC
  • Madagascar (Law 2014-038): CMIL
  • Chad, Niger, Gabon, Congo, DRC: applicable local laws

Anglophone Africa, South Africa and Egypt:

  • South Africa (POPIA): Information Regulator
  • Nigeria (NDPR / NDPA 2023): NDPC
  • Kenya (Data Protection Act 2019): ODPC
  • Ghana (Data Protection Act 2012): DPC Ghana
  • Egypt (Law 151/2020): Data Protection Center
  • Uganda (Data Protection and Privacy Act 2019): PDPO
  • Tanzania, Zambia, Zimbabwe, Botswana, Rwanda: applicable local laws

Asia, Middle East and Oceania:

  • Singapore (PDPA): PDPC
  • Australia (Privacy Act + APPs): OAIC
  • Japan (APPI): PPC
  • South Korea (PIPA): PIPC
  • UAE (Federal PDPL 2021 + DIFC, ADGM): UAE Data Office, DIFC Commissioner
  • Saudi Arabia (PDPL 2021): SDAIA
  • Qatar (Law 13/2016): NCSA
  • Bahrain (PDPL 2018): Personal Data Protection Authority
  • Turkey (KVKK): KVKK Authority

To exercise a right or ask a question, contact us at [email protected] or, for specific data protection requests, at [email protected]. Our response will be provided within the legal timelines applicable to your jurisdiction (generally 30 days for GDPR and most African legislation, 45 days for CCPA, 15 days for LGPD).

13. International Users and Transfers

The App is available worldwide via the App Store and Google Play (subject to local restrictions decided by Apple or Google). This privacy policy applies to all users, regardless of their jurisdiction.

Mobile App: no cross-border transfer. Your data stays on your device. The initial download via the stores is governed by Apple's and Google's policies.

Website deencoach.app: two limited transfers are possible, detailed in section 8.

  • If you subscribe to the newsletter, your email address is transmitted to EmailOctopus Ltd in the United Kingdom. The UK is recognized as an adequate country by the European Commission (decision 2021/1772).
  • Requests to the website transit through the global network of Cloudflare, Inc., which acts as host, CDN and security shield. Cloudflare publishes standard contractual clauses for non-EU transfers.

14. Distribution on Stores (Apple App Store and Google Play)

The App is distributed via Apple's and Google's official stores. When you install or update the App, these stores may collect their own data per their respective policies:

Apple App Store privacy labels and Google Play Data Safety: in line with the transparency requirements of both stores, we declare that the App collects no data, tracks no user, and uses no advertising identifier.

15. Changes

We may update this policy. Any changes will be posted on this page with an updated date. In case of substantial changes, we will update the App with a notification on the home screen. For the newsletter, any substantial change will be announced by email to subscribers.

16. Contact

For any questions about this privacy policy or to exercise a right provided by your local legislation, contact us:

Although Wazmine is not legally required to designate a Data Protection Officer (DPO) under GDPR Article 37 - since no personal data is processed at large scale - this dedicated address is provided to facilitate your data protection requests, regardless of your jurisdiction.