Privacy policy
Sahaar is a prayer time, imsakiye (Ramadan timetable) and Islamic calendar app. The app has no account, no ads, no trackers and no third-party analytics SDKs. This website is a separate thing, and it does use Google Analytics — see Website analytics. This page explains, in plain terms, the little that leaves your phone and everything that doesn’t.
A Turkish version of this policy is at sahaar.app/tr/gizlilik. If the two ever disagree, the English text governs for users outside Türkiye.
Who we are
Sahaar is made by Selçuk, an independent developer based in Türkiye, who is the data controller for the purposes of data protection law. Contact: contact@sahaar.app
Questions, requests or complaints: contact@sahaar.app. You will get a reply from a person, not a ticket system.
What we don’t collect
We do not collect, ask for or store any of the following:
- Your name, email address, phone number or any account — Sahaar has no sign-up.
- Your location. It never reaches our server.
- Your prayer records, Quran reading, qibla usage or any other record of your religious practice. This data is never sent to us, not even in anonymous or aggregated form. It is a category we have ruled out entirely, not one we happen not to use yet.
- Your payment details, card number or Apple Account.
- Advertising identifiers (IDFA), device identifiers, or any identifier that would let us recognise your phone across sessions.
- Your contacts, existing photos, health data, microphone or camera. Photos: the app can only add a picture — when you save a verse-sharing image card from the system share sheet — and never reads your photo library. Calendar: only when you tap “Add to Calendar” are prayer-time events written; when you tap “Remove exported events”, the app reads your calendar solely to find and delete the events Sahaar itself added — nothing else is touched, stored or sent.
Sahaar contains no third-party SDKs. No Firebase, no Crashlytics, no Sentry, no ad network, no attribution kit. The only external code in the app is Adhan, an open-source astronomical calculation library that runs entirely offline on your device. Adding any third-party SDK in future would require a documented decision and an update to this page.
This whole section is about the app on your phone. The pages you are reading now, on sahaar.app, are measured with Google Analytics; that measurement is described separately under Website analytics and is never linked to the app.
We do not sell, rent, share or trade data with anyone, because we do not hold data about you to sell.
What stays on your device
All of the following is stored on your iPhone. The app does not sync it to iCloud or to any server. If you wear an Apple Watch, your phone passes the watch a summary — about five weeks of prayer times, your city name (never coordinates), the Hijri date, the prayers you marked as prayed and your dhikr counts; Quran data is not included — and nothing goes through a server on the way. If you use iCloud Backup, iOS may include this data in your device backup like any other app data (see Apple services). We have no way to read any of it:
- Your location, whether you allowed the app to use your device location or picked a city by hand.
- Your calculation method, Asr shadow length, Hijri authority, minute adjustments and calibration preferences.
- Your alarm and notification settings for each prayer.
- Prayer records — the prayers you have marked as prayed — and what the app works out from them: your week and month view, completion rate and longest run of full days.
- Qibla and compass use.
- Quran reading: where you left off in each surah, the verses counted as read, how many verses you read each day, your bookmarks, reading plan goal and translation choice, and any surahs you download for offline listening.
Deleting the app deletes all of it from your phone. A copy inside an iCloud Backup of your device is managed by Apple under your Apple Account, not by us.
Anonymous counters
This is the one thing Sahaar sends to a server we control, and we want to be exact about it.
To know whether the app is understandable — how many people finish setup, how many reach the price screen, how many start a trial — the app sends anonymous counters to https://sahaar.app/olay.
The complete list of events
Nothing outside this list is ever sent:
| Event | Sent when |
|---|---|
onboarding_adim_1 … onboarding_adim_4 | You reach a step of first-run setup. These are internal step numbers: version 1.0 sends adim_1, then adim_2 and adim_3 together, and never sends adim_4 |
onboarding_bitti | You finish first-run setup |
paywall_goruldu | The subscription screen is shown |
deneme_basladi | Your 7-day Sahaar Pro trial starts |
satin_alma_yillik | You choose the annual plan (sent even when it starts with the free trial) |
satin_alma_aylik | You choose the monthly plan (sent even when it starts with the free trial) |
ilk_alarm_kuruldu | The first alarm is successfully scheduled on this device — sent once per device; carries no prayer name, time or count |
paywall_alarm | The Sahaar Pro screen was opened from an alarm setting (a second real alarm, sound or snooze) — only the category, never which prayer |
paywall_derinlik | The Sahaar Pro screen was opened from history, fine-tuning, export, dhikr or the Quran tab — only the category |
paywall_yuzey | The Sahaar Pro screen was opened from a Pro widget, Lock Screen countdown, Control Center or Watch — only the category |
pro_alarm_kuruldu | The first Pro alarm (a prayer other than Fajr) is successfully scheduled on this device — sent once per device; carries no prayer name, time or count |
The complete payload
Each event is a single small message containing exactly four fields:
{ "olay": "paywall_goruldu", "gun": "2026-09-15", "surum": "1.0", "ulke": "GB" }
That is: the event name, the calendar date, the app version, and a two-letter country code taken from your device’s region setting. Nothing else. No coordinates, no city, no prayer data, no device model, no identifier of any kind.
No IP address, no session, no cookie
The web server is configured not to log requests to this endpoint at all, so your IP address is never written to disk. The counter service itself logs nothing. There is no cookie, no session and no device ID, which means two events cannot be linked to each other, let alone to you. On the server, events are added straight into a single running total per day, event, app version and country — for example, “on 15 September 2026, version 1.0, GB, paywall_goruldu occurred 412 times”. The individual message is not kept.
Once a day at most
Each event is sent at most once per day per device, in the background, without waiting for a reply. If you are offline it is silently dropped. Counters are never worth an interruption.
How to turn it off
Open Settings › Privacy in the app and switch off Anonymous usage counters. Nothing is sent from that moment on, and no feature stops working.
Where the server is
The counter server is a machine we rent in Frankfurt, Germany (Akamai Connected Cloud / Linode), inside the EU. Only the developer has access to it.
Website analytics
Everything above is about the Sahaar app. This section is about sahaar.app, the website — the pages you are reading right now. They are two different things, and we keep them apart on purpose.
What we use
The website uses Google Analytics 4 (measurement ID G-RJE1S42NXE) to tell us which pages people read, roughly where in the world they come from, and which links they arrive by. We use it to decide what to write next. That is the only third party the website talks to; there are no ad networks, no social widgets, no session recorders, no A/B testing tools and no external fonts.
The EU, the UK and Switzerland: denied by default
The site runs Google Consent Mode v2. The three advertising signals — ad_storage, ad_user_data and ad_personalization — are denied everywhere in the world, whichever country you visit from: Sahaar runs no advertising, no remarketing and no conversion matching, so it has no use for them. The fourth signal, analytics_storage, depends on where you are: for visitors in the EU and the EEA, the United Kingdom and Switzerland it defaults to denied as well. Nothing on this site ever changes any of them to granted. In practice that means no cookie is written and no identifier is stored on your device; Google receives only a cookieless ping that carries no persistent ID, and part of the traffic reporting there is modelled rather than measured.
That is also why you are not being shown a cookie banner. We would rather collect less in Europe than interrupt every visitor with a consent dialogue.
Outside those countries only analytics_storage is granted, so Google Analytics measurement works in its usual, cookie-based way; the advertising signals stay denied there too.
IP addresses
Google Analytics 4 does not log or store individual IP addresses. Requests from visitors in the EU, Switzerland and the UK are handled on servers inside the EU, where the IP address is used only momentarily to derive a coarse location (country or city) and is then discarded — it is never written to disk and never appears in any report. A note on a detail you may look for: we do not set the old Universal Analytics anonymize_ip flag. GA4 ignores that parameter because it already applies the same protection by default, and we did not want to cite a setting that does nothing.
What this is not
- It is not in the app. The iOS app contains no Google code, no analytics SDK and no advertising SDK, and it never talks to Google Analytics.
- It is not linked to you. A visit to this website is never connected to your use of the app, to a purchase, to the anonymous counters described above, or to any account — there is no account.
- It does not change our App Store privacy label. That label describes what the app collects. Website measurement is not app data collection, so the declaration stays exactly as it is (see Anonymous counters).
How to opt out
Any content blocker or tracker blocker will stop the script, and the site works exactly the same without it — nothing on sahaar.app depends on analytics. Google also publishes a browser add-on at tools.google.com/dlpage/gaoptout. The site itself does not read Do Not Track or Global Privacy Control signals, so a blocker is the reliable option.
Legal basis, where this data counts as personal data at all: our legitimate interest in understanding how the site is used (GDPR Art. 6(1)(f)), balanced by denying storage access by default in the EU, the UK and Switzerland. Google acts as our processor for this measurement; see Google’s privacy terms.
Apple services
Some features work by talking to Apple, not to us. When they do, your data goes to Apple under Apple’s privacy policy, and we receive nothing.
Place names (CLGeocoder and MapKit)
To turn your coordinates into a place name — “Bodrum, Muğla” rather than a pair of numbers — the app asks Apple’s geocoding service. Your coordinates are sent to Apple for this. The same applies in reverse when you search for a city by name: your search text goes to Apple. This is a deliberate trade-off: it keeps a location database off our server and keeps you off it too. If you would rather not use it, pick your city from the built-in offline list instead of searching or using device location.
Weather (WeatherKit)
The weather card on the Today screen uses Apple WeatherKit, which means your coordinates are sent to Apple to fetch the local forecast. Attribution is shown in Settings › About. Weather is a convenience, not a prayer time input.
iCloud Backup
Sahaar does not use iCloud and has no cloud sync of its own — your settings and prayer records live on your device. If you have iCloud Backup switched on, iOS may include the app’s data in your device backup, exactly as it does for any other app. That backup is Apple’s, under your Apple Account; we cannot read it and have no key to it. The small plan record described under Purchases and the trial may be in that backup too, like any other app data; it holds no payment details. Your trial and subscription themselves live in your Apple Account, with Apple.
The App Store
Purchases and subscriptions are handled entirely by Apple using StoreKit 2. We never see your card, your Apple Account or your billing address. Your purchase status is verified on your device itself; no purchase information is sent to our server. Apple may share aggregate sales and subscription reports with us, which contain no personal data. Apple’s own handling of your purchase is covered by Apple’s privacy policy.
Notifications and alarms
Prayer alarms and notifications are scheduled locally on your device with AlarmKit and the local notification system. There is no push server, so no notification passes through us.
Calendar (EventKit)
“Add to Calendar” asks iOS for write-only calendar access and writes the selected month’s or Ramadan’s prayer times as events; your calendars are not read. “Remove exported events” asks for full access, only at that moment, and uses it solely to find and delete the events Sahaar itself added. Nothing from your calendar is stored in the app or sent anywhere. Both permissions can be withdrawn in iOS Settings › Privacy & Security › Calendars.
Prayer times, timetables and recitation
Prayer times are calculated on your device. The app uses the Adhan astronomical library plus, for Türkiye, our own calibration table, both bundled inside the app. The calculation itself never contacts a server, and the app works with no connection at all.
Sahaar shows you which calculation method and which Hijri authority produced the times you are looking at, and lets you change either. Sahaar is not affiliated with, endorsed by or acting on behalf of any religious authority, and does not claim to publish any authority’s official times.
Authority timetables. Where a religious authority publishes a yearly timetable for the city you selected (Singapore’s MUIS first), the app downloads that timetable from our own server once a month and labels it on screen (“MUIS timetable”). When a timetable is downloaded, the only thing sent to our server is the identifier of the selected city; your IP address is not logged. The request carries no account, no device identifier, no coordinates and no cookie — just a path such as muis/sg-singapore/2026 — and the web server is configured not to log it. If the download fails, the app falls back to calculation; you can also switch the timetable off entirely in Settings (“Calculation only, not the timetable”). For cities without a timetable, no request is made at all.
Quran recitation. The Quran text, translations and tafsir ship inside the app, so reading makes no request at all. When you play or download a recitation, the app fetches that surah’s audio file from our own server. The request names the audio file — a path such as kiraat/minsavi/018.mp3 — and nothing else; your IP address is not logged. It carries no account, no device identifier, no coordinates and no cookie, and the web server is configured not to log it, so which surah you listened to is not recorded anywhere. Downloaded surahs stay on your device until you delete them or the app. Once started, recitation keeps playing in the background — Home Screen, another app, Control Center, the Lock Screen — using the standard system audio session; this sends nothing beyond the one audio request already described.
Translation read aloud (Sahaar Pro). Tapping the speaker icon under a verse uses Apple’s on-device speech synthesis (AVSpeechSynthesizer) to read the translation in your voice from Settings › Accessibility › Spoken Content. This never contacts a server — nothing is streamed, downloaded or sent anywhere, by us or by Apple.
Verse sharing (Sahaar Pro). Tapping the share icon under a verse renders an image card — the verse translation, its reference and a source line — entirely on your device and opens the system share sheet. Nothing is uploaded to make the card. If you choose “Save Image” there, iOS adds that one picture to your photo library; Sahaar cannot read your existing photos, and no verse-sharing event reaches our server (see Anonymous counters: this is not one of the fourteen listed events).
Retention
- On your device: kept until you delete it in the app or delete the app.
- In an iCloud Backup of your device: kept by Apple under your Apple Account settings, if you use iCloud Backup.
- Anonymous counters: the daily totals are aggregate statistics with no personal data in them, so we keep them indefinitely to compare one season with the next. There is nothing in them that could be traced back to a person, including you.
- Emails you send us: kept in the developer’s mailbox for as long as needed to answer you, then deleted.
Your rights
If you are in the EU, the UK, Türkiye or anywhere with comparable law, you have the right to access your personal data, to have it corrected or erased, to restrict or object to its processing, and to receive it in a portable form.
Here is what that means in practice at Sahaar:
- We hold no personal data about you. No account, no identifier, no profile. So there is nothing to send you, correct, export or delete on request — and, more to the point, no way for us to find “your” data even if you asked us to.
- The anonymous counters cannot be traced to you. They contain no identifier and no IP address, and they are stored only as daily totals. Once a count has been added, there is no individual record left to remove. If you would rather not contribute to them, the switch in Settings › Privacy is the effective remedy, and it takes effect immediately.
- Your religious practice is never processed by us. Under Article 9 of the GDPR, data revealing religious belief is a special category. Sahaar’s prayer records are exactly that, which is why they are barred from ever being sent to us, anonymised or otherwise.
- Legal basis. To the extent the anonymous counters were ever treated as personal data, our basis would be legitimate interest (Article 6(1)(f)) in understanding whether the app is usable, balanced against a design that deliberately collects no identifier — and you can opt out at any time.
To exercise any right, or to ask us anything at all, write to contact@sahaar.app.
You also have the right to complain to a supervisory authority: the ICO in the UK, your national data protection authority in the EU, or the KVKK Authority in Türkiye.
California privacy rights
If you are a California resident, the CCPA as amended by the CPRA gives you rights over personal information. Applied to Sahaar:
- We do not sell or share your personal information, and we have not done so in the preceding twelve months. “Share” here has its CPRA meaning, including disclosure for cross-context behavioural advertising. Sahaar has no advertising of any kind, so there is nothing to opt out of and no “Do Not Sell or Share My Personal Information” link to click.
- Categories collected: none. We do not collect identifiers, commercial information, geolocation, biometric data, internet activity, inferences or sensitive personal information as those categories are defined by the CCPA. The anonymous counters described above are not linked or reasonably linkable to you or your device.
- Sensitive personal information: we do not collect it, and we therefore do not use or disclose it for any purpose that would trigger a right to limit its use.
- No financial incentives are offered in exchange for data, and we will never discriminate against you for exercising a privacy right. Turning off anonymous counters changes nothing about the app, free or Pro.
- Requests to know, delete or correct can be sent to contact@sahaar.app. Since we hold no personal information about you, our answer to a request to know will be that we hold none.
Children
Sahaar is not directed at children and we do not knowingly collect personal information from anyone, of any age. There is no account to create, no profile to fill in and no way for a child to disclose anything to us through the app. If you believe something has reached us in error, write to contact@sahaar.app and we will remove it.
Purchases and the trial
Sahaar is free to use. Sahaar Pro is an optional subscription (yearly or monthly) with a 7-day free trial, and the trial is Apple’s, not ours. You pick a plan on the purchase screen and confirm it on Apple’s sheet with a payment method; from there the trial and the subscription live in your Apple Account. Unless you cancel at least 24 hours before the trial ends, the plan you picked begins and Apple charges you. Cancelling is done in Settings › your name › Subscriptions.
The app keeps no receipt, card or payment details. It asks Apple whether an active plan exists on this device and when it expires, and keeps that answer — plan name, expiry date and the day it was last checked — on your phone. That way alarms and widgets keep working without asking the App Store every time you open the app. The record is never sent to us and never synced to iCloud; the only place it can turn up is your device backup, like any other app data (see Apple services). We never see your payment method, your card or your billing address. The only thing that reaches us is the anonymous deneme_basladi or satin_alma_… counter described above, which says an event happened and nothing about who it happened to.
If Pro lapses, nothing free stops: the Fajr alarm, notifications, the standard widgets and the Watch app keep working. Alarms on other prayers fall back to notifications, custom sounds and snooze return to the defaults, and Pro widgets show an invitation to Pro instead of content. Subscribing again restores Pro immediately, with your saved settings. Your prayer records are never deleted, at any point, for any billing reason.
Prices are $19.99 a year or $3.99 a month in the United States; Apple sets the local price elsewhere (₺349.99 a year in Türkiye). Both plans open the same Sahaar Pro, support Family Sharing and open with the 7-day trial. Billing, refunds and cancellations go through Apple, not through us.
Changes to this policy
If what the app does changes, this page changes first. We will update the “last updated” date at the top, and any change that widens what leaves your device — a new event, a new service, a new field — will be described in the app’s release notes as well, not buried here. We will never quietly start collecting something this page says we do not.
Effective date
This policy takes effect on the day Sahaar version 1.0 is released on the App Store, and applies to version 1.0 and later. Last updated 28 September 2026.
Contact: contact@sahaar.app