Privacy Policy
Last updated: 24 July 2026
This Privacy Policy explains how Noor AI (“we”, “us”, “Noor”) handles your information when you use the Noor mobile app and this website (together, the “Service”). We built Noor to be private by design: you can begin using it with no account at all, and your most personal content is never used for advertising or sold.
1. Who we are
The data controller is Noor AI, based in Türkiye. For any privacy question or request, contact us at [email protected].
2. Guest mode vs. signed-in
You can use Noor as a guest, in which case your data (habits, prayers, dhikr, journal, mood, progress) is stored only on your device and is not sent to our servers. If you choose to sign in with Google, we create an account so your data can sync securely across devices and be backed up.
3. Information we collect
a) Account information
If you sign in with Google, we receive your email address, name and profile photo through our authentication provider (Supabase). Guests provide none of this.
b) Content you create
Habits, prayer records, dhikr counts, journal entries, mood, character (akhlaq) progress and, if you use it, messages you send to the in-app guidance assistant. For signed-in users this is stored on our backend so it can sync; for guests it stays on your device.
c) Location
Location is used to calculate accurate prayer times and, optionally, for prayer-time geofencing and travel (qasr) detection. Prayer times are computed on your device. We do not sell your location or use it for advertising. Geofencing/background location is optional and only active if you enable it.
d) Notifications
If you enable reminders, we store a push token so we can deliver prayer, dhikr and daily-content notifications.
e) Purchases
Premium subscriptions are handled by our payments partner (RevenueCat) and the app store. We receive your subscription status and expiry — never your card number.
f) Advertising (free users)
Free users may see ads served by Google AdMob, which may use device identifiers to show and measure ads. Premium users see no ads. We never share your journal, reflections, coach messages or location with ad networks.
g) Diagnostics
To fix crashes we use privacy-focused error reporting (Sentry). It is configured to strip personal data — we do not attach your identity, journal text or assistant messages to crash reports. Diagnostics are disabled entirely in development builds.
4. How we use your information
- To provide core features (prayer times, tracking, journaling, daily content, reminders).
- To sync and back up your data across your devices (signed-in users).
- To generate responses from the guidance assistant when you use it.
- To process subscriptions and unlock premium features.
- To keep the Service secure, prevent abuse, and fix crashes.
We do not sell your personal data, and we do not use your journal, reflections, location or assistant messages to build advertising profiles.
5. The guidance assistant (AI)
When you use the in-app guidance assistant, the messages you send are transmitted to our AI provider (DeepSeek) solely to generate a reply, and returned to you. Please don’t share highly sensitive personal information in these messages. The assistant offers general encouragement and is not a substitute for a qualified scholar and does not issue religious rulings (fatwa).
6. Service providers (subprocessors)
| Provider | Purpose |
|---|---|
| Supabase | Authentication, database, secure backup & sync |
| Google (Sign-In, AdMob, Play) | Login, advertising for free users, app distribution |
| RevenueCat | Subscription management |
| DeepSeek | AI responses for the guidance assistant |
| Sentry | Privacy-scrubbed crash diagnostics |
| Expo | Push notification delivery |
Each provider processes data only as needed to deliver its part of the Service.
7. Data retention
We keep your account data while your account is active. Guest data lives on your device until you delete the app or clear it. When you delete your account (see below), we remove your personal data from our systems, except where we must keep limited records to meet legal or accounting obligations.
8. Your rights
Depending on where you live (including under the GDPR), you may have the right to access, correct, export or delete your data, and to object to or restrict certain processing. You can delete your account and data at any time from within the app — see our Account & Data Deletion page — or by emailing [email protected].
9. Security
Data is encrypted in transit. Your login session is stored in your device’s secure keychain/keystore, not in plain storage. No method of transmission or storage is 100% secure, but we work to protect your information.
10. Children
Noor is not directed to children under 13 (or the minimum age in your country). We do not knowingly collect data from children. If you believe a child has provided us data, contact us and we will remove it.
11. International transfers
Our providers may process data in countries other than yours. Where required, we rely on appropriate safeguards for such transfers.
12. Changes
We may update this policy. Material changes will be reflected by the “Last updated” date above and, where appropriate, an in-app notice.
13. Contact
Questions or requests: [email protected].
