Privacy policy
Effective 3 October 2026
In short. Moazzin has no ads, no analytics, no tracking and no user accounts (only mosque admins sign in, on this website). Prayer times, the Qibla, the Hijri date, alerts, your tracker and your mosques are worked out and stored on your device. A few features go online when you use them, and this page lists every one. We do not sell or share personal data for advertising, and we never will.
Moazzin (the app and moazzin.com) is made and run by Hassan Ansari, an individual developer in India. “We”, “us” and “our” on these pages mean him. Write to [email protected] about anything on this page.
On your device
Everything below stays on your phone, tablet, watch or computer. We cannot see it.
- Location. Your position is used on the device to calculate prayer times and the Qibla direction. Saved places are stored in the app. If you turn on Silent at my mosque, the phone watches the areas around your mosques (geofencing), which needs location “all the time”; that also runs on the device only and never syncs to other devices.
- Your data. Settings, saved places, the prayer log and qaza, reminders, your mosques and their jama'at times, Tasbih counts, Quran bookmarks and reading position, Listen favourites and calendar events.
- Alerts. Adhan and reminder notifications are scheduled by the device itself. There is no push-notification service and no device token.
- Widgets, Apple Watch, CarPlay and Android Auto read the same data on the device.
- Camera and photos. Used only when you scan a mosque board or a pairing code. A board photo is kept in memory while you review it and then dropped.
- Prayer focus (if you turn it on) uses the phone's Screen Time (iPhone) or usage access (Android) to pause the apps you pick. The list of apps stays on the device.
- Downloads. Quran packs and recitations you download are stored on the device.
When the app goes online
Each of these sends a normal internet request, so the receiving server sees your IP address and the address of the file or service asked for. Apart from what is listed, nothing about you is sent.
| What | When | Goes to | What is sent |
|---|---|---|---|
App switches (/config.json) and a server check (/healthz) | At launch on iPhone and Android, and at most every 6 hours after | Our server | Nothing beyond the request. The answer says whether Prayer focus may run. |
| Quran translation and tafseer packs | When you open the packs screen or download one | Our server | The file asked for |
| Public Quran catalogues | Only if you browse them | api.alquran.cloud (translations); cdn.jsdelivr.net or raw.githubusercontent.com (tafseer) | The file asked for |
| Recitations (Listen) | When you open Listen (the list, at most daily) and when you play or download | Our server (the list); cdn.islamic.network (audio) | The file asked for |
| Find mosques nearby | When you search | Our server, which asks Google Places or OpenStreetMap | A point rounded to about 100 m and a search radius. No name, no ID. |
| Scan a mosque board | Only after you agree, each time you scan | Our server, then Ollama Cloud (see below) | The photo, without its file details, and a random code |
| Map on the “Drop a pin” screen | While that screen is open | Apple Maps (iPhone, iPad, Mac) or Google Maps (Android) | The map area you view, as map tile requests |
| Suggested mosque name (“I'm at the mosque now”) | When you tap it and no nearby mosque matches | Apple (iPhone, iPad, Mac) or Google (Android, through the phone's built-in geocoder) | Your current position, to look up the area's name |
| iCloud sync | Only if you turn it on (Apple devices) | Your own private iCloud database at Apple | Your synced data (see below) |
| Supporter purchase | Only if you buy | Apple App Store or Google Play | Handled by the store |
Find mosques nearby
The phone rounds its position to three decimal places (about 100 m) before sending it. Our server asks Google Places (from the server, with our key, so Google does not see your IP address) or, as a fallback, the OpenStreetMap Overpass service. Our server keeps answers in memory for up to 7 days (Google) or 1 day (OpenStreetMap), keyed by the rounded point, so the next search nearby is answered from the cache. The cache is not linked to you and is lost on every restart. To limit abuse, the server counts requests per IP address per day, using a shortened one-way hash of the address, in memory only.
Syncing your devices
- Local sync (any devices on the same Wi-Fi): after you pair two devices with a QR code, they exchange your data directly and encrypted. It never passes through our server. Each paired device's key is kept in the system keychain or keystore.
- iCloud (Apple devices on the same Apple ID, if you turn it on): your data is stored in your own private iCloud database, under Apple's terms and privacy policy. We cannot read it. Apple wakes the app with a silent notification when another device changes something; the app never sees or sends a push token.
- Location permissions, geofencing, Prayer focus, downloads and your Supporter purchase never sync.
Backups
- On Android, the system may back up the app's settings file to your Google account (Android Auto Backup) and copy it to a new phone. Downloads and alarm state are excluded.
- On Apple devices, the app's data is included in your device or iCloud backup under Apple's settings.
- A backup file you export from More › Backup is yours. We never receive it.
Links and sharing
- Shared mosque links (
moazzin.com/m/#…) carry the mosque's details after the#, which browsers never send to a server. Opening one sends us only the page request. - Timetable, store and website links open in your browser and are covered by that site's policy.
Feedback by email
“Send feedback” opens your own mail app with a message to [email protected]. You see the whole message first and can remove any line (app version, system, language, calculation method, and, for wrong times, your city, primary mosque and today's times). Moazzin sends nothing itself. We receive what you send, including your email address, and use it only to reply and fix problems.
Scanning a mosque board
The board scan reads jama'at times from a photo so you don't have to type them. It is optional and asks your permission once before the first scan.
- What is sent: the photo (a JPEG of at most 1600 pixels) and a random 20-character code created on your device. No location, name or account. The details a camera stores inside a photo file (such as where and when it was taken, or the phone model) are removed on your device and again on our server, so they never reach the AI model.
- Our server passes the photo to Ollama Cloud and returns the times. It does not store or log the photo. It logs only the result status, how long it took, which models read it and their token counts. The random code and your IP address are hashed and counted in memory to apply a daily limit (10 scans per code), and the counts are cleared every day.
- Ollama Cloud. The photo is read by open AI models (such as Gemma and Mistral) run by Ollama (Ollama, Inc., United States) through its cloud API at ollama.com. A low-cost model reads it first; only if that reading looks uncertain does another model read it again, so each photo is read one to four times (usually once). Ollama says it processes prompts and responses only to answer the request, does not store or log them and never trains on them. It runs models with partners, which it calls “model inference providers” and does not name; it says it requires them not to log, keep or train on the data. Ollama hosts mainly in the United States and may route requests to Europe or Singapore. See Ollama's privacy policy and Ollama Cloud.
- Please photograph only the board. Keep people, faces and anything personal out of the frame.
- The times are read by AI and can be wrong. You always check them before they are saved.
If you don't want a photo to leave your device, don't use the scan; you can type the times instead.
The website (moazzin.com)
- No analytics, no ads and no third-party requests. Pages load nothing from other sites.
- Two cookies only (below):
mz_placefor everyone, and a sign-in cookie for mosque admins. Both are strictly functional, so there is no cookie banner. mz_placeholds the page of the city you last opened (for example/pk/karachi), not your location or coordinates. Purpose: open your city directly when you visit moazzin.com. First-party, kept for 1 year, never shared. Your browser sends it to our server with each request so the server can redirect the home page; we don't log or store it. To clear it, choose “Forget” on the home page or clear cookies in your browser settings.- Your choices (Asr, Isha, language), up to six recent cities and whether you closed the “Get the app” bar are kept in your browser's local storage. They never leave your device; clearing your browser's site data removes them.
- A small offline helper (service worker) keeps the offline page and the last city page you opened in your browser's cache.
- “Use my location” runs in your browser and only picks the nearest city from a list in the page. Your position is not sent to us.
- Mosque pages show the times a mosque publishes, not who published them.
Mosque admins
People who publish a mosque's times sign in on this website at /admin. They join only by invitation and sign in with a passkey: no email address, phone number or password is asked for. For them we keep:
- the name the inviter typed (a first name or nickname is fine), the role and the mosque or city it covers, and who invited them;
- for each device: the passkey's public key and its counter (your fingerprint or face never leaves your device), a device type such as “iPhone” worked out from the browser (the browser string itself is not kept), when it was added and last used;
- a sign-in cookie (
mz_admin, only on/admin, HttpOnly, Secure, SameSite=Strict, 30 days) and a hashed copy of its token; - a history of what was done (for example “published Isha 8:15 PM”), with the name of who did it, plus drafts and invitations (the invitee's name, stored with a hashed one-time token that expires after 7 days);
- request counts per IP address, hashed and in memory, to slow down guessing.
When you paste a short map link to set a pin, our server follows that link (for example on maps.app.goo.gl) to read the coordinates; the map service sees our server, not you. The pin preview is drawn from OpenStreetMap tiles fetched by our server. “Use my location” on the pin form uses your browser's location only to fill in the pin.
When an admin is removed, their sign-in sessions and passkeys are deleted at once and the account is marked as removed. Their name stays in that mosque's history so committees can see who changed what. You can ask us to replace your name in the history with “former admin”, unless we need it to deal with a complaint or a legal duty. Admins must be 18 or older; see the mosque guidelines.
Our server and its logs
Our server and its database run on Railway (Railway Corporation, United States) in its Singapore region. Our own code logs, for each request, only the method, the path (never the query string) and the status, with one-time invite codes cut out. The nearby search adds the source, cache hit and time; the scan adds status, time, the models used and their token counts; errors add the path and the technical error.
The server for AI assistants (/mcp) is logged the same way: method, path and status, never what was asked. Coordinates sent to it are rounded to about 1 km before use, and requests are counted per network, in memory under a one-way hash, to limit abuse.
Railway's own platform also records request logs, which include your IP address, the address requested and your browser or app identifier. These are kept for 30 days and then deleted. We use them only to keep the service running and to deal with abuse. See Railway's privacy policy.
Who receives data
- Railway hosts our server and database (service provider).
- Ollama reads board photos you choose to scan (see above).
- Google: Places search from our server (rounded point only); on Android, the Google Maps map and the phone's geocoder; Android backups and Google Play purchases, under Google's own policies.
- Apple: Apple Maps, the geocoder, iCloud, device backups and App Store purchases, under Apple's own policies.
- OpenStreetMap services: the Overpass API (rounded point, from our server) and map tiles for the admin pin preview (from our server).
- Islamic Network / AlQuran.cloud, jsDelivr and GitHub serve Quran audio and texts you choose to play or download.
- Authorities, only where the law requires it and after checking the request is lawful.
Apple's and Google's own services (maps, geocoding, iCloud, backups, stores) act under their own privacy policies, which also apply to you as their user.
How long data is kept
| Data | Kept |
|---|---|
| Data in the app | On your device until you delete it or uninstall the app |
| Nearby search cache | In memory, up to 7 days, lost on restart; not linked to you |
| Rate-limit counters (hashed IP, hashed scan code) | In memory, cleared daily and on restart |
| Board photos | Not stored by us; Ollama says it doesn't store them either |
| Our application logs and Railway's request logs | Up to 30 days |
| Mosque admin accounts | While you are an admin; passkeys and sessions are deleted on removal; your name in history as above |
| Published mosque times and their history | While the mosque publishes, and as a record afterwards |
| Emails to us | As long as needed to help you, then deleted; on request sooner |
Why we may use it (legal bases)
- India (DPDP Act 2023): data you give us voluntarily for a specific purpose (a search, a scan, an email, an admin account) is used for that purpose only; where we ask for consent, as for the board scan, you can withdraw it at any time.
- EU and UK GDPR: to provide what you asked for (searches, scans, packs, the admin service); our legitimate interest in keeping the service secure and working (logs, rate limits); your consent for the board scan; and legal obligations.
Countries data goes to
Our server is in Singapore. Board photos go to Ollama, mainly in the United States and sometimes in Europe or Singapore. Ollama, Google, Apple, Railway, jsDelivr and GitHub may process requests in the United States and other countries. For the board scan, we tell you before the first scan and ask for your agreement. For other providers we rely on their standard safeguards (such as standard contractual clauses) where the law requires them.
Your rights
Depending on where you live, you can ask us to tell you what personal data we hold about you, correct it, delete it, stop or limit using it, give you a copy, or withdraw your consent. Under India's DPDP Act you can also nominate someone to act for you if you die or cannot act. Most of your data is only on your device, so we usually hold nothing that can be linked to you; mosque admins and people who emailed us are the exception. See how to delete your data.
Write to [email protected]. We reply within 30 days (sooner where the law requires). We may ask you to confirm the request comes from you, for example from the same email address or admin sign-in. If you are unhappy with our answer you can complain to the Data Protection Board of India, your EU data protection authority, the UK Information Commissioner's Office, or your state authority in the US.
Children
Moazzin is for everyone, including children, and it has no accounts, ads or tracking. We don't knowingly collect personal data from children. Children should ask a parent before using the board scan or emailing us. Mosque admins must be 18 or older. If you think a child has sent us personal data, write to us and we will delete it.
Security
All connections use HTTPS. Admin sign-in uses passkeys; tokens are stored only as hashes. Local sync is end-to-end encrypted between your devices. No system is perfectly secure; if a breach affects your personal data, we will tell you and the authorities as the law requires.
California and other US states
We do not sell or “share” personal information, do not use it for targeted advertising or profiling, and do not use sensitive information beyond providing the feature you asked for. In the last 12 months we have handled only the categories described above (IP addresses and request details, approximate location for nearby searches, photos you scan, admin names and device details, and emails you send). You have the rights described above and will not be treated differently for using them.
Changes
When this policy changes we update this page and its date. If a change matters, for example a new kind of data going online, the app will tell you before it happens.
Contact and grievances
Hassan Ansari, Moazzin, India. Email [email protected]. He is also the grievance officer for India's IT Rules 2021 and the DPDP Act; see how grievances are handled.