Privacy Policy
Last updated: July 19, 2026
Hafiz is a non-profit Quran memorization app. This policy explains what the app stores locally, what is sent to optional services, and how you can delete it.
Local religious and app data
By default, Quran reading history, bookmarks, memorization progress, khatmah goals and logs, recitation session history, settings, cached content, downloaded audio, auto-bookmarks, and successful local voice recordings remain on your device. They are stored using the app's local databases, preferences, files, or secure storage and are not sent to Hafiz merely because you use the app.
On-device Whisper voice verification processes the recording on the device. A successful recording may be retained locally so you can replay it. You can remove local data from the app's settings where available, clear the app's data, or uninstall the app.
Quran Foundation sign-in and cloud sync
Cloud features are optional. If you sign in with a Quran Foundation (Quran.com) account, Hafiz uses OAuth 2.0/OpenID Connect with PKCE and requests access for account identity and the enabled Quran Foundation features, such as bookmarks, collections, reading sessions, goals, streaks, activity, preferences, notes, posts, search, and content.
The authorization code is exchanged through Hafiz's configured HTTPS backend; the Quran Foundation client secret is not shipped in the app. Access, refresh, and ID tokens are stored in the device Keychain or Android secure storage. Depending on the features you use, Quran Foundation receives the account and cloud data needed to provide those features under its own privacy policy.
Signing out revokes the session when supported and removes local tokens. The app's cloud-sync settings also provide a delete-data action for supported Quran Foundation data. Quran Foundation controls data held in its service.
Voice verification services
Hafiz can use either on-device Whisper or the optional Qurani.ai QRC provider for recitation feedback. QRC receives live microphone audio and returns recitation feedback through its service; use the on-device provider if you do not want audio sent to that provider. Local recordings are not uploaded by the on-device Whisper path.
Firebase services
- Firebase Analytics receives app and feature interaction events and limited app-state properties used to understand and improve the product.
- Firebase Crashlytics receives crash reports, diagnostic logs, and device/app context to diagnose stability problems.
- Firebase Remote Config receives the app's request for configuration, such as minimum-version and feature-display values.
Hafiz disables Firebase ad storage, ad user data, and ad personalization signals. Firebase services are not used by Hafiz for advertising or cross-app tracking. Firebase may process technical identifiers and diagnostics as described in Google's privacy documentation.
Age Signals (Android only)
On Android, Google Play Age Signals is checked during app initialization when supported. The result is cached in memory for the current app session and used only to decide whether cloud sync or voice verification needs parental consent. Hafiz does not send the result to its servers, use it for analytics or advertising, or persist it as an account profile. An unavailable or unsupported result is not treated as a confirmed minor status.
Content delivery and third parties
Anonymous requests may be made to Quran Foundation content services and the EveryAyah CDN to load Quran text, translations, tafsir, recitations, or page images. These requests contain the resource being requested, not your local religious history. The app may link to third-party sites whose policies apply independently.
Retention, deletion, and contact
Local data remains until you delete it, clear app data, or uninstall. Tokens remain until sign-out, revocation, expiry, or deletion. Data held by Quran Foundation, Firebase, or QRC is retained under those providers' policies.
For privacy or deletion questions, contact motazhamada@gmail.com. You may also review the source at github.com/moatazhamada/HafizApp.