Privacy Policy

iTafakkur — by eDrop

Effective date: 2 May 2026  ·  Last updated: 2 May 2026

1. Who we are

iTafakkur (the "App") is published by Syed Altaf Hussain, an individual developer operating under the brand eDrop, based in the Kingdom of Saudi Arabia. We are the data controller for the information described in this policy.

For any privacy question, contact us at support@itafakkur.com. We aim to respond within 7 days.

2. Summary (the short version)

3. Data we collect

3.1 Information you provide

3.2 Information collected automatically

4. How we use your data

PurposeLegal basis (GDPR)
Provide the core app features (chat, journal, habits, prayer times, Qibla, dhikr, study paths)Contract
Authenticate you and keep your session aliveContract
Calculate prayer times and Qibla based on your locationConsent (location)
Send you prayer-time reminders if you enable notificationsConsent
Generate AI responses for your chat questions and journal promptsContract
Respond to your support requestsLegitimate interest
Detect and prevent abuse (rate-limiting daily chat quota)Legitimate interest

5. Third-party services we use

iTafakkur relies on a small number of trusted services to deliver core features. Each receives the minimum data needed for its function. We have reviewed the privacy practices of each service and do not share data beyond what they require to operate.

ServicePurposeData sent
SupabaseDatabase, authentication, storageAccount info, in-app content, auth tokens
OpenAIAI chat responses, journal prompts, content translationsYour chat messages and prompt content (no personal identifiers attached)
AladhanPrayer times, Hijri date conversionYour latitude / longitude coordinates
Quran.com APIVerse translations in your languageVerse reference (e.g. "2:286"), language code
IslamCan.comStreaming Azaan recordingsYour IP address (standard for any web request)
Apple Sign InOptional sign-in methodEmail + name (only when you choose to sign in with Apple)
Google OAuthOptional sign-in methodEmail + name (only when you choose to sign in with Google)
Microsoft OAuthOptional sign-in methodEmail + name (only when you choose to sign in with Microsoft)
RailwayBackend hosting (US)API request data in transit (encrypted via HTTPS)

6. Where your data is stored

Your account and in-app content are stored on Supabase's servers (currently in the United States). Your data is encrypted in transit (TLS) and at rest (Supabase manages disk encryption). Backups are retained by Supabase per their standard policy.

AI processing (OpenAI) happens in the United States and Europe, depending on routing. OpenAI does not use API content to train its models per their enterprise terms, which our backend uses.

7. How long we keep your data

8. Your rights

You have the right to:

To exercise any of these rights, email support@itafakkur.com.

9. Children's privacy

iTafakkur is rated 4+ on the App Store / Everyone on Google Play. We do not knowingly collect data from children under 13 (or under 16 in the EU) without verifiable parental consent. If you believe a child has provided us with personal data without parental consent, contact support@itafakkur.com and we will delete it promptly.

10. Security

We use industry-standard security measures including TLS 1.3 for all data in transit, asymmetric (ES256) JWT authentication, row-level security on the database, and credential rotation on a regular schedule. No system is perfectly secure, but we apply best-in-class practices and will notify affected users within 72 hours of any confirmed breach affecting their personal data.

11. Changes to this policy

We may update this policy as the App evolves (new features, new third-party services, regulatory changes). When we make material changes, we will update the "Last updated" date above and, where significant, notify you in-app on next launch. Continued use of the App after a change constitutes acceptance.

12. Contact

Syed Altaf Hussain
eDrop / iTafakkur
Kingdom of Saudi Arabia

Email: support@itafakkur.com

13. Governing law

This policy is governed by the laws of the Kingdom of Saudi Arabia, without prejudice to mandatory consumer protection rights you may have under your local law (e.g. GDPR if you are in the EU/UK, CCPA if you are in California).