Effective date: 3 August 2026 · Last updated: 17 August 2026
Prayer Lock (“the App”, “we”, “us”) is published by Zappsco. This policy explains what the App collects, why, where it goes, and what control you have over it.
Contact us at any time: hello@zappsco.com
1. Summary
- We do not sell your personal information, and we do not share it with data brokers or advertisers.
- The App contains no analytics software and no advertising software. We do not track you, and we collect no data about which screens you open or which features you use.
- The App requires an account. You sign in with Sign in with Apple, Google Sign-In, or an email address and password. We collect your name and email address, and nothing else about you as a person.
- The App requires an active subscription to reach its features. Your subscription is verified through RevenueCat and your app store; we never see your payment details.
- Your location is used only to calculate prayer times and Qibla direction. We do not store a location history.
- Your App Blocker selections never leave your device, on either platform.
- On Android, the App Blocker uses an Accessibility Service that reads only the package name of the app you bring to the foreground. It cannot and does not read what is on your screen. See §7.1.
- Your Tasbih (dhikr) history is saved to your account so it is available on your devices. It is stored on your device first and synced afterwards.
- You can delete your account, and everything in it, from inside the App — More → tap your profile card → Delete Account.
- We do not collect a phone number, contacts, photos, microphone audio, camera input, or health data.
2. Information we collect
2.1 Information you provide
Your account details. Creating an account requires:
| Data | How we get it | Why |
|---|---|---|
| Email address | You type it, or Apple/Google supply it | Identifying your account, signing you in, sending a password reset |
| Name | You type it, or Apple/Google supply it | Greeting you in the App |
| Password | You choose it (email sign-up only) | Signing you in. It is handled entirely by Firebase Authentication — we never see it or store it |
| Profile photo | Google or Apple supplies a URL, if your account has one | Showing your avatar. The image itself is fetched from the provider's servers and cached on your device |
If you sign in with Apple and choose Hide My Email, Apple gives us a private relay address instead of your real one. Everything works normally — we never ask for another address.
Apple supplies your name only on the first authorization. If you have signed in with Apple before, Apple sends no name, and the App simply shows the name it already has (or none).
Your Tasbih history. When you finish a counting session, the App records which dhikr you counted, how many, and when. This is saved to your device immediately and synced to your account so it appears on your other devices.
The onboarding screen asks for a first name so it can greet you during the introduction. That name is held in memory only, is not written to storage and never transmitted, and is gone as soon as onboarding finishes. It is separate from your account name.
Your settings — calculation method, madhab, manual city, theme, Arabic font size, translation visibility, notification and adhan preferences — are chosen by you and stored on your device only.
If you contact us by email, we receive whatever you choose to write to us.
2.2 Information collected automatically
| Data | Purpose | Leaves the device? |
|---|---|---|
| Approximate/precise location | Calculating prayer times and Qibla direction | Coordinates are sent to the prayer-times API, and to your device's geocoding provider to name your city (see §4, §5) |
| Device compass / motion data | Pointing the Qibla compass | No |
| Time zone | Scheduling the adhan and reminders at the correct local time | No |
| Package name of the foreground app (Android, App Blocker only) | Detecting that a blocked app was opened during a prayer window | No — see §7.1 |
| Crash diagnostics (stack traces, device model, OS version, app version) | Diagnosing crashes | Yes — Firebase Crashlytics. Deliberately not linked to your account: we never attach your user ID to a crash report |
| Purchase and subscription state | Determining whether your subscription is active | Yes — RevenueCat and your app store, identified by your account ID so your subscription follows you across devices |
| Tasbih session records (dhikr name, count, timestamp) | Showing your dhikr history across your devices | Yes — stored against your account in Firebase Firestore |
| Network requests for content | Downloading prayer times, Quran text, and hadith collections | Yes — the content providers in §4 receive the request and, unavoidably, your IP address |
The App contains no product-analytics SDK. We do not record which screens you view, which features you use, or how long you spend in the App. See §3.
2.3 Information that stays on your device
The following is stored locally and is never transmitted to us or anyone else:
- Your App Blocker selections — the apps (and, on iOS, app categories and web domains) you choose to restrict during prayer windows, plus whether blocking is enabled. On Android this is a local preferences file; on iOS it is an Apple-provided selection token held in the App’s own App Group container. Neither is transmitted, logged remotely, or attached to anything we send.
- Quran text, translations (English and Bengali), bookmarks, last-read position, and the local search index.
- Downloaded hadith collections, cached locally after their first download.
- Duas and dhikr, which ship inside the App and require no network at all.
- Cached prayer times (retained for roughly 30 days so the App works offline).
- The next-prayer data shared with the home-screen widget (see §8).
- Your Tasbih history, which is kept on the device as the primary copy and synced to your account afterwards.
- Your settings, listed in §2.1.
Uninstalling the App deletes all of this local data.
3. Analytics, advertising, and crash reporting
We do not use product analytics. The App contains no analytics SDK. We collect no behavioural data: no screen views, no feature-usage events, no session records, no user journeys, no profiling. We removed the analytics services the App previously included, and nothing replaced them.
We do not track you. The App performs no cross-app or cross-website tracking, contains no advertising or attribution software, does not access Apple’s advertising identifier (IDFA) or Android’s advertising ID, and shares no data with data brokers or advertising networks. Because the App does not track you, iOS does not show an App Tracking Transparency prompt — there is nothing to ask permission for. If that ever changes, we will update this policy first and request your permission through that system prompt before any tracking occurs.
We show no ads. The App contains no advertising SDK of any kind, and no part of the App is funded by advertising.
Crash reporting is the one diagnostic we keep. We use Firebase Crashlytics (Google) so that crashes can be found and fixed:
- It receives stack traces plus device model, OS version, and app version.
- It is not linked to your account. Although the App has accounts, we deliberately never attach your user identifier to a crash report, so crashes cannot be traced back to you.
- App Blocker data is never included, in any form.
- Crash reporting is disabled in development builds.
Session recording does not exist in the App. We do not record your screen.
4. Third parties who receive data
| Service | What it receives | Why |
|---|---|---|
| Firebase Authentication (Google) | Your email address, name, password (which we never see), and the Apple/Google sign-in token | Creating your account, signing you in, sending password-reset emails |
| Firebase Firestore (Google) | Your account profile and your Tasbih history | Storing your dhikr history so it is available across your devices |
| Firebase Crashlytics (Google) | Crash diagnostics, device and OS information — not linked to your account | Diagnosing crashes |
| Sign in with Apple (Apple) | Your Apple ID sign-in, and your name and email if you choose to share them | Signing you in. Choosing Hide My Email gives us only a relay address |
| Google Sign-In (Google) | Your Google account sign-in, name, email and profile photo | Signing you in |
| RevenueCat | Purchase receipts and your account ID | Determining whether your subscription is active, and carrying it across your devices |
| Apple App Store / Google Play | Payment details, handled entirely by them | Processing purchases, subscriptions, and offer-code redemptions |
| Aladhan API (api.aladhan.com) | Latitude and longitude, date, calculation method and madhab | Calculating prayer times |
| Your device's geocoding provider (Apple on iOS, Google Play services on Android) | Coordinates, when naming your city; or the city name you type, when converting it to coordinates | Showing a readable location and supporting manual location entry |
| Google user-content servers (googleusercontent.com and similar) | A request for your profile photo, if your account has one | Displaying your avatar |
| Al-Quran Cloud API (api.alquran.cloud) | No personal information | One-time download of Quran text and translations |
| jsDelivr CDN (cdn.jsdelivr.net) | No personal information | Downloading hadith collections (the open hadith-api dataset) |
Any service the App contacts over the internet necessarily sees your IP address and general request metadata, as is true of any network request. We do not use it for anything, and we do not receive it ourselves.
We never see your payment card details. All payments are processed by Apple or Google under their own terms and privacy policies.
Each of these providers processes data under their own privacy policy. We select them for the function described and do not authorise them to use your information for their own advertising.
We operate no servers of our own. There is no Prayer Lock backend. Every service above belongs to a third party, and everything else happens on your device.
5. Location, in detail
Location deserves its own section because it is the most sensitive thing the App touches.
- Location is requested only for prayer-time calculation and Qibla direction.
- We request “when in use” access. The App does not track you in the background and holds no background-location capability.
- Coordinates are sent to the Aladhan API to compute prayer times for your area, and the resulting times are cached on your device.
- Coordinates are also passed to your device’s own geocoding service (Apple or Google, depending on the platform) to turn them into a city name for display. If you type a city instead, that text is sent the same way to get coordinates back.
- We do not build or retain a location history. We do not store your coordinates on our servers — we do not operate servers that could store them. Only the most recent location you used is kept on your device, so prayer times work offline.
- You can decline location access and enter your city manually instead. Prayer times will still work.
- You can revoke location access at any time in your device settings.
- The Qibla compass also uses motion/magnetometer data. That data is read by the device and used on-screen; it is never transmitted.
6. Notifications
Prayer notifications and the adhan are local notifications scheduled on your device. The App does not use push notification servers, we hold no push token, and we do not send you remote messages. Nothing about your prayer schedule is transmitted to us.
- On Android the App requests permission to post notifications, to schedule exact alarms, and to run outside battery optimisation, solely so the adhan sounds at the correct moment.
- On iOS the App requests notification authorisation (alert + sound) and schedules local notifications that play an adhan sound bundled inside the App.
The App sends no marketing or promotional notifications.
7. App Blocker
The App Blocker restricts selected apps during prayer windows. It works differently on each platform, and both deserve a plain explanation.
7.1 Android — Accessibility Service
To know that you have opened a blocked app, the App uses an Accessibility Service, together with the “display over other apps” permission that lets it show the reminder screen.
Because accessibility permissions are powerful, here is exactly what ours does and does not do:
- It listens for a single event type — “a window came to the foreground”.
- From that event it reads only the package name of the app (for example
com.example.socialapp). - It is configured so that it cannot retrieve window content. It does not read text on your screen, form fields, messages, passwords, or anything you type. That capability is switched off at the system level, not merely unused.
- It acts only when you have enabled blocking and a prayer window is currently active. Outside those windows it does nothing.
- Nothing it observes is stored beyond the moment or transmitted anywhere. No usage log, no history, and nothing sent to us or any third party.
You grant this permission yourself through Android’s system settings, reached from an explicit in-app screen. The App never requests it silently, and you can revoke it at any time — blocking simply stops working.
Earlier versions of the App used Android’s Usage Access permission for the same purpose. That approach has been replaced by the Accessibility Service described above, which is more responsive and reads strictly less. The App no longer requests Usage Access at all.
7.2 iOS — Screen Time (Family Controls)
On iOS the App uses Apple’s Screen Time / Family Controls framework to shield selected apps, app categories, and web domains during prayer windows.
- Selection happens in Apple’s own picker. Because of how the framework works, the App never sees the identity of what you select — Apple keeps that private even from us. We receive only opaque tokens and a count.
- Those tokens are stored in the App’s private App Group container on your device and are handed back to Apple’s framework to apply the restriction.
- Enforcement and the shield screen run inside Apple-provided App Extensions on your device.
- Screen Time authorisation is requested only when you set up App Blocker, and can be revoked in iOS Settings at any time.
7.3 Both platforms
Your selections, and any signal the feature relies on, stay on your device. None of it is transmitted, logged remotely, stored in your account, or included in crash reports.
8. Home-screen widgets
The home-screen widget shows the next prayer and a countdown. To do this, the App writes the next-prayer name and time into shared local storage that the widget can read — an App Group container on iOS, and shared preferences on Android. This data stays on the device and contains nothing beyond prayer names and times.
9. Permissions the App may request
| Permission | Platform | Why | Optional? |
|---|---|---|---|
| Location (when in use) | Both | Prayer times and Qibla | Yes — enter your city manually instead |
| Notifications | Both | Adhan and prayer reminders | Yes — reminders stop |
| Motion / compass | iOS | Qibla compass (Android reads the magnetometer without a runtime permission) | Yes — the compass stops |
| Exact alarms, ignore battery optimisation | Android | Firing the adhan at the exact time | Yes — timing becomes unreliable |
| Accessibility Service | Android | Detecting a blocked app during a prayer window (§7.1) | Yes — App Blocker stops |
| Display over other apps | Android | Showing the prayer reminder screen | Yes — App Blocker stops |
| Screen Time / Family Controls | iOS | Shielding selected apps (§7.2) | Yes — App Blocker stops |
The App does not request camera, microphone, photo library, contacts, calendar, health, or background-location access.
Every permission above is requested through an explicit in-app prompt or screen, and every one can be revoked at any time in your device settings. The App degrades gracefully when a permission is missing — the affected feature stops, the rest continues.
10. Children
Prayer Lock is a general-audience app and is not directed at children under 13 (or the equivalent minimum age in your country). We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, contact hello@zappsco.com and we will delete it.
11. Data retention
- Your account and Tasbih history are retained until you delete your account (§12), at which point they are removed.
- Crash diagnostics are retained according to Firebase Crashlytics’ default retention period, after which they are deleted or aggregated. (There is no analytics data, because the App collects none.)
- Cached prayer times are retained on your device for about 30 days.
- Downloaded Quran and hadith content remains on your device until you delete the App.
- Local content and settings (bookmarks, last-read position, App Blocker selections, preferences) remain until you delete the App.
- Purchase records are held by Apple, Google, and RevenueCat under their own retention policies.
12. Your rights and choices
Depending on where you live, you may have the right to access, correct, export, restrict, or delete your personal information, and to object to certain processing. To exercise any of these, contact hello@zappsco.com.
Deleting your account. You can delete your account from inside the App: More → tap your profile card → Delete Account. You will be asked to confirm your identity first, because deletion is permanent. Deleting removes:
- your account and sign-in credentials from Firebase Authentication;
- your profile (name, email, photo);
- your entire Tasbih history, on our providers’ servers and on the device you delete from.
If you signed in with Apple, the App also revokes the Apple token issued to it, so Prayer Lock disappears from your Apple ID’s list of apps using Sign in with Apple.
This cannot be undone, and we do not keep a copy.
Signing out. More → tap your profile card → Sign Out ends the session on that device without deleting anything. Your subscription remains attached to the app store account you paid with, and your Tasbih history remains in your account.
Also note:
- Local data on your device (settings, bookmarks, App Blocker selections, cached prayer times and content) is removed by uninstalling the App.
- Purchase records held by Apple or Google, and the subscriber record held by RevenueCat, are governed by their policies and are not removed by deleting your account. Write to hello@zappsco.com to request deletion of the RevenueCat record.
- Deleting your account does not cancel your subscription, and does not entitle you to a refund. Cancel through your App Store or Google Play subscription settings before deleting, or you will continue to be billed.
- Uninstalling the App likewise does not cancel a subscription.
Withdrawing permissions. Every permission listed in §9 can be revoked at any time in your device settings. Prayer times fall back to manual location, and blocking simply stops.
13. Security
We use industry-standard measures to protect your information, including encryption in transit. We operate no backend of our own — the only servers involved are the third-party services listed in §4.
Your password is never seen or stored by us. Authentication is handled entirely by Firebase Authentication; we receive only a token confirming you signed in successfully.
Your account data is isolated by design. Your profile and Tasbih history are stored in Firebase Firestore under a path keyed to your own account identifier, governed by security rules that permit only your signed-in account to read or write them. No client can request another user’s data.
For your own protection, our password-reset flow never reveals whether an email address has an account with us — it responds the same way either way.
No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
14. Accounts on more than one platform
Prayer Lock’s iOS and Android builds currently authenticate against separate Firebase projects. In practice this means that if you install the App on both an iPhone and an Android phone, signing in with the same email or the same Google account creates two independent accounts, each with its own Tasbih history, and history does not sync between them. Your subscription is likewise tied to the app store you purchased from.
We intend to consolidate this. Until we do, the statement above is the accurate description of how the App behaves, and both accounts can be deleted independently using §12.
15. International transfers
Our service providers may process and store data in countries other than yours, including the United States. Where required, these transfers rely on appropriate safeguards such as the European Commission’s standard contractual clauses.
16. Changes to this policy
We may update this policy as the App changes. When we make a material change we will update the “Last updated” date above and, where the change is significant, give notice inside the App. Continuing to use the App after an update means you accept the revised policy.
17. Contact
Questions, requests, or complaints about privacy: