Skip to content
sahaar

Privacy policy

Sahaar for iOS · Effective with the release of version 1.0 · Last updated 28 September 2026 (verse read-aloud and verse sharing)

Sahaar is a prayer time, imsakiye (Ramadan timetable) and Islamic calendar app. The app has no account, no ads, no trackers and no third-party analytics SDKs. This website is a separate thing, and it does use Google Analytics — see Website analytics. This page explains, in plain terms, the little that leaves your phone and everything that doesn’t.

A Turkish version of this policy is at sahaar.app/tr/gizlilik. If the two ever disagree, the English text governs for users outside Türkiye.

Who we are

Sahaar is made by Selçuk, an independent developer based in Türkiye, who is the data controller for the purposes of data protection law. Contact: contact@sahaar.app

Questions, requests or complaints: contact@sahaar.app. You will get a reply from a person, not a ticket system.

What we don’t collect

We do not collect, ask for or store any of the following:

Sahaar contains no third-party SDKs. No Firebase, no Crashlytics, no Sentry, no ad network, no attribution kit. The only external code in the app is Adhan, an open-source astronomical calculation library that runs entirely offline on your device. Adding any third-party SDK in future would require a documented decision and an update to this page.

This whole section is about the app on your phone. The pages you are reading now, on sahaar.app, are measured with Google Analytics; that measurement is described separately under Website analytics and is never linked to the app.

We do not sell, rent, share or trade data with anyone, because we do not hold data about you to sell.

What stays on your device

All of the following is stored on your iPhone. The app does not sync it to iCloud or to any server. If you wear an Apple Watch, your phone passes the watch a summary — about five weeks of prayer times, your city name (never coordinates), the Hijri date, the prayers you marked as prayed and your dhikr counts; Quran data is not included — and nothing goes through a server on the way. If you use iCloud Backup, iOS may include this data in your device backup like any other app data (see Apple services). We have no way to read any of it:

Deleting the app deletes all of it from your phone. A copy inside an iCloud Backup of your device is managed by Apple under your Apple Account, not by us.

Anonymous counters

This is the one thing Sahaar sends to a server we control, and we want to be exact about it.

To know whether the app is understandable — how many people finish setup, how many reach the price screen, how many start a trial — the app sends anonymous counters to https://sahaar.app/olay.

The complete list of events

Nothing outside this list is ever sent:

EventSent when
onboarding_adim_1 … onboarding_adim_4You reach a step of first-run setup. These are internal step numbers: version 1.0 sends adim_1, then adim_2 and adim_3 together, and never sends adim_4
onboarding_bittiYou finish first-run setup
paywall_gorulduThe subscription screen is shown
deneme_basladiYour 7-day Sahaar Pro trial starts
satin_alma_yillikYou choose the annual plan (sent even when it starts with the free trial)
satin_alma_aylikYou choose the monthly plan (sent even when it starts with the free trial)
ilk_alarm_kurulduThe first alarm is successfully scheduled on this device — sent once per device; carries no prayer name, time or count
paywall_alarmThe Sahaar Pro screen was opened from an alarm setting (a second real alarm, sound or snooze) — only the category, never which prayer
paywall_derinlikThe Sahaar Pro screen was opened from history, fine-tuning, export, dhikr or the Quran tab — only the category
paywall_yuzeyThe Sahaar Pro screen was opened from a Pro widget, Lock Screen countdown, Control Center or Watch — only the category
pro_alarm_kurulduThe first Pro alarm (a prayer other than Fajr) is successfully scheduled on this device — sent once per device; carries no prayer name, time or count

The complete payload

Each event is a single small message containing exactly four fields:

{ "olay": "paywall_goruldu", "gun": "2026-09-15", "surum": "1.0", "ulke": "GB" }

That is: the event name, the calendar date, the app version, and a two-letter country code taken from your device’s region setting. Nothing else. No coordinates, no city, no prayer data, no device model, no identifier of any kind.

No IP address, no session, no cookie

The web server is configured not to log requests to this endpoint at all, so your IP address is never written to disk. The counter service itself logs nothing. There is no cookie, no session and no device ID, which means two events cannot be linked to each other, let alone to you. On the server, events are added straight into a single running total per day, event, app version and country — for example, “on 15 September 2026, version 1.0, GB, paywall_goruldu occurred 412 times”. The individual message is not kept.

Once a day at most

Each event is sent at most once per day per device, in the background, without waiting for a reply. If you are offline it is silently dropped. Counters are never worth an interruption.

How to turn it off

Open Settings › Privacy in the app and switch off Anonymous usage counters. Nothing is sent from that moment on, and no feature stops working.

Where the server is

The counter server is a machine we rent in Frankfurt, Germany (Akamai Connected Cloud / Linode), inside the EU. Only the developer has access to it.

Website analytics

Everything above is about the Sahaar app. This section is about sahaar.app, the website — the pages you are reading right now. They are two different things, and we keep them apart on purpose.

What we use

The website uses Google Analytics 4 (measurement ID G-RJE1S42NXE) to tell us which pages people read, roughly where in the world they come from, and which links they arrive by. We use it to decide what to write next. That is the only third party the website talks to; there are no ad networks, no social widgets, no session recorders, no A/B testing tools and no external fonts.

The EU, the UK and Switzerland: denied by default

The site runs Google Consent Mode v2. The three advertising signals — ad_storage, ad_user_data and ad_personalization — are denied everywhere in the world, whichever country you visit from: Sahaar runs no advertising, no remarketing and no conversion matching, so it has no use for them. The fourth signal, analytics_storage, depends on where you are: for visitors in the EU and the EEA, the United Kingdom and Switzerland it defaults to denied as well. Nothing on this site ever changes any of them to granted. In practice that means no cookie is written and no identifier is stored on your device; Google receives only a cookieless ping that carries no persistent ID, and part of the traffic reporting there is modelled rather than measured.

That is also why you are not being shown a cookie banner. We would rather collect less in Europe than interrupt every visitor with a consent dialogue.

Outside those countries only analytics_storage is granted, so Google Analytics measurement works in its usual, cookie-based way; the advertising signals stay denied there too.

IP addresses

Google Analytics 4 does not log or store individual IP addresses. Requests from visitors in the EU, Switzerland and the UK are handled on servers inside the EU, where the IP address is used only momentarily to derive a coarse location (country or city) and is then discarded — it is never written to disk and never appears in any report. A note on a detail you may look for: we do not set the old Universal Analytics anonymize_ip flag. GA4 ignores that parameter because it already applies the same protection by default, and we did not want to cite a setting that does nothing.

What this is not

How to opt out

Any content blocker or tracker blocker will stop the script, and the site works exactly the same without it — nothing on sahaar.app depends on analytics. Google also publishes a browser add-on at tools.google.com/dlpage/gaoptout. The site itself does not read Do Not Track or Global Privacy Control signals, so a blocker is the reliable option.

Legal basis, where this data counts as personal data at all: our legitimate interest in understanding how the site is used (GDPR Art. 6(1)(f)), balanced by denying storage access by default in the EU, the UK and Switzerland. Google acts as our processor for this measurement; see Google’s privacy terms.

Apple services

Some features work by talking to Apple, not to us. When they do, your data goes to Apple under Apple’s privacy policy, and we receive nothing.

Place names (CLGeocoder and MapKit)

To turn your coordinates into a place name — “Bodrum, Muğla” rather than a pair of numbers — the app asks Apple’s geocoding service. Your coordinates are sent to Apple for this. The same applies in reverse when you search for a city by name: your search text goes to Apple. This is a deliberate trade-off: it keeps a location database off our server and keeps you off it too. If you would rather not use it, pick your city from the built-in offline list instead of searching or using device location.

Weather (WeatherKit)

The weather card on the Today screen uses Apple WeatherKit, which means your coordinates are sent to Apple to fetch the local forecast. Attribution is shown in Settings › About. Weather is a convenience, not a prayer time input.

iCloud Backup

Sahaar does not use iCloud and has no cloud sync of its own — your settings and prayer records live on your device. If you have iCloud Backup switched on, iOS may include the app’s data in your device backup, exactly as it does for any other app. That backup is Apple’s, under your Apple Account; we cannot read it and have no key to it. The small plan record described under Purchases and the trial may be in that backup too, like any other app data; it holds no payment details. Your trial and subscription themselves live in your Apple Account, with Apple.

The App Store

Purchases and subscriptions are handled entirely by Apple using StoreKit 2. We never see your card, your Apple Account or your billing address. Your purchase status is verified on your device itself; no purchase information is sent to our server. Apple may share aggregate sales and subscription reports with us, which contain no personal data. Apple’s own handling of your purchase is covered by Apple’s privacy policy.

Notifications and alarms

Prayer alarms and notifications are scheduled locally on your device with AlarmKit and the local notification system. There is no push server, so no notification passes through us.

Calendar (EventKit)

“Add to Calendar” asks iOS for write-only calendar access and writes the selected month’s or Ramadan’s prayer times as events; your calendars are not read. “Remove exported events” asks for full access, only at that moment, and uses it solely to find and delete the events Sahaar itself added. Nothing from your calendar is stored in the app or sent anywhere. Both permissions can be withdrawn in iOS Settings › Privacy & Security › Calendars.

Prayer times, timetables and recitation

Prayer times are calculated on your device. The app uses the Adhan astronomical library plus, for Türkiye, our own calibration table, both bundled inside the app. The calculation itself never contacts a server, and the app works with no connection at all.

Sahaar shows you which calculation method and which Hijri authority produced the times you are looking at, and lets you change either. Sahaar is not affiliated with, endorsed by or acting on behalf of any religious authority, and does not claim to publish any authority’s official times.

Authority timetables. Where a religious authority publishes a yearly timetable for the city you selected (Singapore’s MUIS first), the app downloads that timetable from our own server once a month and labels it on screen (“MUIS timetable”). When a timetable is downloaded, the only thing sent to our server is the identifier of the selected city; your IP address is not logged. The request carries no account, no device identifier, no coordinates and no cookie — just a path such as muis/sg-singapore/2026 — and the web server is configured not to log it. If the download fails, the app falls back to calculation; you can also switch the timetable off entirely in Settings (“Calculation only, not the timetable”). For cities without a timetable, no request is made at all.

Quran recitation. The Quran text, translations and tafsir ship inside the app, so reading makes no request at all. When you play or download a recitation, the app fetches that surah’s audio file from our own server. The request names the audio file — a path such as kiraat/minsavi/018.mp3 — and nothing else; your IP address is not logged. It carries no account, no device identifier, no coordinates and no cookie, and the web server is configured not to log it, so which surah you listened to is not recorded anywhere. Downloaded surahs stay on your device until you delete them or the app. Once started, recitation keeps playing in the background — Home Screen, another app, Control Center, the Lock Screen — using the standard system audio session; this sends nothing beyond the one audio request already described.

Translation read aloud (Sahaar Pro). Tapping the speaker icon under a verse uses Apple’s on-device speech synthesis (AVSpeechSynthesizer) to read the translation in your voice from Settings › Accessibility › Spoken Content. This never contacts a server — nothing is streamed, downloaded or sent anywhere, by us or by Apple.

Verse sharing (Sahaar Pro). Tapping the share icon under a verse renders an image card — the verse translation, its reference and a source line — entirely on your device and opens the system share sheet. Nothing is uploaded to make the card. If you choose “Save Image” there, iOS adds that one picture to your photo library; Sahaar cannot read your existing photos, and no verse-sharing event reaches our server (see Anonymous counters: this is not one of the fourteen listed events).

Retention

Your rights

If you are in the EU, the UK, Türkiye or anywhere with comparable law, you have the right to access your personal data, to have it corrected or erased, to restrict or object to its processing, and to receive it in a portable form.

Here is what that means in practice at Sahaar:

To exercise any right, or to ask us anything at all, write to contact@sahaar.app.

You also have the right to complain to a supervisory authority: the ICO in the UK, your national data protection authority in the EU, or the KVKK Authority in Türkiye.

California privacy rights

If you are a California resident, the CCPA as amended by the CPRA gives you rights over personal information. Applied to Sahaar:

Children

Sahaar is not directed at children and we do not knowingly collect personal information from anyone, of any age. There is no account to create, no profile to fill in and no way for a child to disclose anything to us through the app. If you believe something has reached us in error, write to contact@sahaar.app and we will remove it.

Purchases and the trial

Sahaar is free to use. Sahaar Pro is an optional subscription (yearly or monthly) with a 7-day free trial, and the trial is Apple’s, not ours. You pick a plan on the purchase screen and confirm it on Apple’s sheet with a payment method; from there the trial and the subscription live in your Apple Account. Unless you cancel at least 24 hours before the trial ends, the plan you picked begins and Apple charges you. Cancelling is done in Settings › your name › Subscriptions.

The app keeps no receipt, card or payment details. It asks Apple whether an active plan exists on this device and when it expires, and keeps that answer — plan name, expiry date and the day it was last checked — on your phone. That way alarms and widgets keep working without asking the App Store every time you open the app. The record is never sent to us and never synced to iCloud; the only place it can turn up is your device backup, like any other app data (see Apple services). We never see your payment method, your card or your billing address. The only thing that reaches us is the anonymous deneme_basladi or satin_alma_… counter described above, which says an event happened and nothing about who it happened to.

If Pro lapses, nothing free stops: the Fajr alarm, notifications, the standard widgets and the Watch app keep working. Alarms on other prayers fall back to notifications, custom sounds and snooze return to the defaults, and Pro widgets show an invitation to Pro instead of content. Subscribing again restores Pro immediately, with your saved settings. Your prayer records are never deleted, at any point, for any billing reason.

Prices are $19.99 a year or $3.99 a month in the United States; Apple sets the local price elsewhere (₺349.99 a year in Türkiye). Both plans open the same Sahaar Pro, support Family Sharing and open with the 7-day trial. Billing, refunds and cancellations go through Apple, not through us.

Changes to this policy

If what the app does changes, this page changes first. We will update the “last updated” date at the top, and any change that widens what leaves your device — a new event, a new service, a new field — will be described in the app’s release notes as well, not buried here. We will never quietly start collecting something this page says we do not.

Effective date

This policy takes effect on the day Sahaar version 1.0 is released on the App Store, and applies to version 1.0 and later. Last updated 28 September 2026.

Contact: contact@sahaar.app