Privacy Policy

Last updated: July 19, 2026

Hafiz is a non-profit Quran memorization app. This policy explains what the app stores locally, what is sent to optional services, and how you can delete it.

Local religious and app data

By default, Quran reading history, bookmarks, memorization progress, khatmah goals and logs, recitation session history, settings, cached content, downloaded audio, auto-bookmarks, and successful local voice recordings remain on your device. They are stored using the app's local databases, preferences, files, or secure storage and are not sent to Hafiz merely because you use the app.

On-device Whisper voice verification processes the recording on the device. A successful recording may be retained locally so you can replay it. You can remove local data from the app's settings where available, clear the app's data, or uninstall the app.

Quran Foundation sign-in and cloud sync

Cloud features are optional. If you sign in with a Quran Foundation (Quran.com) account, Hafiz uses OAuth 2.0/OpenID Connect with PKCE and requests access for account identity and the enabled Quran Foundation features, such as bookmarks, collections, reading sessions, goals, streaks, activity, preferences, notes, posts, search, and content.

The authorization code is exchanged through Hafiz's configured HTTPS backend; the Quran Foundation client secret is not shipped in the app. Access, refresh, and ID tokens are stored in the device Keychain or Android secure storage. Depending on the features you use, Quran Foundation receives the account and cloud data needed to provide those features under its own privacy policy.

Signing out revokes the session when supported and removes local tokens. The app's cloud-sync settings also provide a delete-data action for supported Quran Foundation data. Quran Foundation controls data held in its service.

Voice verification services

Hafiz can use either on-device Whisper or the optional Qurani.ai QRC provider for recitation feedback. QRC receives live microphone audio and returns recitation feedback through its service; use the on-device provider if you do not want audio sent to that provider. Local recordings are not uploaded by the on-device Whisper path.

Firebase services

Hafiz disables Firebase ad storage, ad user data, and ad personalization signals. Firebase services are not used by Hafiz for advertising or cross-app tracking. Firebase may process technical identifiers and diagnostics as described in Google's privacy documentation.

Age Signals (Android only)

On Android, Google Play Age Signals is checked during app initialization when supported. The result is cached in memory for the current app session and used only to decide whether cloud sync or voice verification needs parental consent. Hafiz does not send the result to its servers, use it for analytics or advertising, or persist it as an account profile. An unavailable or unsupported result is not treated as a confirmed minor status.

Content delivery and third parties

Anonymous requests may be made to Quran Foundation content services and the EveryAyah CDN to load Quran text, translations, tafsir, recitations, or page images. These requests contain the resource being requested, not your local religious history. The app may link to third-party sites whose policies apply independently.

Retention, deletion, and contact

Local data remains until you delete it, clear app data, or uninstall. Tokens remain until sign-out, revocation, expiry, or deletion. Data held by Quran Foundation, Firebase, or QRC is retained under those providers' policies.

For privacy or deletion questions, contact motazhamada@gmail.com. You may also review the source at github.com/moatazhamada/HafizApp.


سياسة الخصوصية

آخر تحديث: 19 يوليو 2026

حافظ تطبيق غير ربحي لمساعدة المسلمين على حفظ القرآن. توضّح هذه السياسة ما يخزّنه التطبيق محليًا، وما يُرسل إلى الخدمات الاختيارية، وكيفية حذفه.

البيانات الدينية وبيانات التطبيق المحلية

افتراضيًا، تبقى على جهازك بيانات سجل القراءة، والإشارات المرجعية، وتقدم الحفظ، وأهداف وسجلات الختمة، وسجل جلسات التسميع، والإعدادات، والمحتوى المخزّن مؤقتًا، والصوتيات التي تم تنزيلها، والإشارات المرجعية التلقائية، والتسجيلات الصوتية المحلية الناجحة. تُخزّن هذه البيانات في قواعد بيانات التطبيق المحلية أو التفضيلات أو الملفات أو التخزين الآمن، ولا تُرسل إلى حافظ لمجرد استخدامك للتطبيق.

يعالج التحقق الصوتي باستخدام Whisper على الجهاز التسجيلَ على الجهاز. وقد يُحتفظ بالتسجيل الناجح محليًا لإعادة تشغيله. يمكنك حذف البيانات المحلية من إعدادات التطبيق حيثما يتاح ذلك، أو مسح بيانات التطبيق، أو إلغاء تثبيته.

تسجيل الدخول إلى مؤسسة القرآن والمزامنة السحابية

الميزات السحابية اختيارية. عند تسجيل الدخول بحساب مؤسسة القرآن (Quran.com)، يستخدم حافظ بروتوكول OAuth 2.0/OpenID Connect مع PKCE، ويطلب الوصول إلى هوية الحساب وميزات مؤسسة القرآن المفعّلة، مثل الإشارات المرجعية والمجموعات وجلسات القراءة والأهداف وسلاسل الإنجاز والنشاط والتفضيلات والملاحظات والمنشورات والبحث والمحتوى.

يتم تبادل رمز التفويض عبر خادم حافظ المهيأ باستخدام HTTPS؛ ولا يُضمّن سر عميل مؤسسة القرآن في التطبيق. تُخزّن رموز الوصول والتحديث والهوية في Keychain على iOS أو التخزين الآمن على Android. وبحسب الميزات التي تستخدمها، تستقبل مؤسسة القرآن بيانات الحساب والبيانات السحابية اللازمة لتقديم تلك الميزات وفقًا لـ سياسة الخصوصية الخاصة بها.

يؤدي تسجيل الخروج إلى إلغاء الجلسة عند دعم ذلك وإزالة الرموز المحلية. وتوفر إعدادات المزامنة السحابية إجراءً لحذف البيانات التي تدعمها مؤسسة القرآن. وتتحكم مؤسسة القرآن في البيانات الموجودة في خدمتها.

خدمات التحقق الصوتي

يمكن لحافظ استخدام Whisper على الجهاز أو مزود Qurani.ai QRC الاختياري للحصول على ملاحظات التلاوة. يستقبل QRC صوت الميكروفون المباشر ويعيد ملاحظات التلاوة عبر خدمته؛ استخدم مزود الجهاز إذا لم ترغب في إرسال الصوت إلى ذلك المزود. لا تُرفع التسجيلات المحلية عبر مسار Whisper على الجهاز.

خدمات Firebase

يعطّل حافظ تخزين الإعلانات وبيانات مستخدم الإعلانات وتخصيص الإعلانات في Firebase. ولا يستخدم حافظ خدمات Firebase للإعلانات أو التتبع عبر التطبيقات. قد تعالج Firebase معرّفات تقنية وبيانات تشخيصية وفقًا لـ وثائق الخصوصية من Google.

Age Signals (Android فقط)

على Android، يتم فحص Google Play Age Signals أثناء تهيئة التطبيق عند دعم ذلك. تُخزّن النتيجة في الذاكرة لجلسة التطبيق الحالية فقط، وتُستخدم لتحديد ما إذا كانت المزامنة السحابية أو التحقق الصوتي يحتاجان إلى موافقة ولي الأمر. لا يرسل حافظ النتيجة إلى خوادمه، ولا يستخدمها للتحليلات أو الإعلانات، ولا يحفظها كملف شخصي للحساب. لا تُعامل النتيجة غير المتاحة أو غير المدعومة على أنها دليل مؤكد على كون المستخدم قاصرًا.

تقديم المحتوى والجهات الخارجية

قد تُرسل طلبات مجهولة إلى خدمات محتوى مؤسسة القرآن وEveryAyah CDN لتحميل نص القرآن أو الترجمات أو التفاسير أو التلاوات أو صور الصفحات. تحتوي هذه الطلبات على المورد المطلوب، وليس على سجلّك الديني المحلي. وقد يحتوي التطبيق على روابط لمواقع خارجية تسري سياساتها بشكل مستقل.

الاحتفاظ والحذف والتواصل

تبقى البيانات المحلية حتى تحذفها أو تمسح بيانات التطبيق أو تلغي تثبيته. تبقى الرموز حتى تسجيل الخروج أو إلغائها أو انتهاء صلاحيتها أو حذفها. وتخضع البيانات لدى مؤسسة القرآن أو Firebase أو QRC لسياسات تلك الجهات.

للاستفسارات المتعلقة بالخصوصية أو الحذف، تواصل عبر motazhamada@gmail.com. ويمكنك أيضًا مراجعة المصدر على github.com/moatazhamada/HafizApp.