Privacy
Your privacy in MyIman
What this app collects, why it collects it, and what you can ask us to delete.
This policy explains how the developer of MyIman: Dhikr Dua Prayer Watch handles information when you use the app and its support pages. For questions, access requests or deletion requests, use the MyIman support form.
Your daily practice
Your saved duas, named collections, routines, counters, reading position, prayer and fasting journal, preferences and downloaded audio are stored on your device. MyIman does not upload this practice history to its assisted-search service. Your device's backup and transfer settings may separately apply to app data. Shared-device users and anyone with access to your unlocked device may be able to see your saved practice.
Prayer calculations use the location you enter or choose. Location permission is optional; you can enter a place and coordinates manually. Coordinates are saved locally for prayer times and Qibla. The compass uses device sensors while you use it. Notifications are scheduled on your device. Home-screen widgets display a local summary of your practice and prayer settings.
Optional assisted search
Assisted search is off until you agree to its disclosure. When you use it, your description, chosen time allowance and a selection of our sourced dua catalogue are sent to the MyIman service and OpenRouter, which routes the request to an AI model provider. Do not include names, contact details or other sensitive information in your description. The service selects entries from the existing library; it does not generate scripture or religious rulings.
Requests require OpenRouter's zero-data-retention routing and disallow provider data collection for training. The routing policy can include temporary in-memory processing and caching. See OpenRouter's data policy. MyIman does not store your submitted description on its server or put it in analytics or crash reports. A pending description may remain locally so you can retry an interrupted request.
Firebase Authentication creates an anonymous service identity for protected requests; this is an account identifier, even though you do not supply a name, password or contact address. Firebase App Check and Apple or Google attestation help verify the app. These services process device, app, network and attestation information. Our service also uses an installation identifier, its public signing key, request identifiers, timestamps and usage records to protect your account, limit abuse and control AI costs. Network providers necessarily process your IP address.
You can turn assisted search off in Settings → Privacy & data. This stops new requests and clears the local search; it cannot recall a request already sent. The offline library and main practice features remain available. Reporting an assisted result sends its request identifier and the reason you select, without your original description.
Usage and crash choices
Usage analytics and crash reports have separate switches in Settings → Privacy & data and are off by default. If enabled, Google Analytics processes app interactions, device and app information and app-instance identifiers. Our custom events describe features and workflow steps, without prayer text, journal entries, saved coordinates or assisted-search descriptions. Platform SDKs may also record automatic events, including purchase-related activity.
If you enable crash reporting, Firebase Crashlytics receives technical crash traces, app and device information and installation identifiers to help us diagnose failures. Turning a switch off stops that collection and clears unsent reports or resets local analytics data as applicable; it does not immediately recall information already processed by the provider. MyIman does not use advertising identifiers, sell personal information or use this information for targeted ads. See Firebase's privacy information.
Purchases and services you open
Apple or Google handles payments and subscriptions under its own policies. MyIman reads native purchase and subscription status to unlock optional Plus features and restore valid purchases. We do not receive your payment-card details. Cancel or manage a subscription through the store; deleting app data or an assisted-search account does not cancel store billing.
Streaming or downloading recitation connects to MP3Quran's servers, which receive the requested audio and network information. See MP3Quran's policy. Opening a mosque search sends the search or coordinates shown on screen to your chosen maps provider. Sharing passes the selected text or card to the app you choose. Those providers then handle information under their own policies. These actions require your choice.
The app checks locally whether WhatsApp is installed to decide whether to offer a first-launch rating invitation. It does not read WhatsApp messages or contacts. Store review invitations use the platform review service. Hosted introductions, legal pages and the public API use Cloudflare delivery, which processes network and request information to serve and protect these resources.
Retention and deletion
Local practice remains until you remove it, delete personal data or remove the app, subject to your device's backup settings. In Settings → Privacy & data, choose Delete personal data to remove saved practice, reminders, downloaded audio and assisted-search data. If an anonymous service account exists, deletion requires an internet connection and also requests its deletion from Firebase. If interrupted, the app retains the minimum recovery information and offers a retry. Theme, completed introduction and review-invitation preferences are retained, as are valid store purchases and reviewer access.
Server records of assisted requests and results expire after 30 days, and result reports and cost reservations after 90 days. Request replay records expire after one day and short-term abuse-control records after two days. Cleanup runs on service startup and hourly; an outage can delay it. Confirmed account deletion removes associated active service records earlier.
Limited security records remain after deletion to reject captured requests and prevent a deleted identity from being restored: a retired installation identifier and a hash of the anonymous account identifier. Its public key remains while deletion is unfinished and for up to 30 days after confirmed deletion. These records do not contain your search description or results. Existing cost reservations and short-term abuse records retain their stated expiry periods. Technical service logs contain fixed operation/error details rather than your submitted text.
Firebase and other providers apply their own deletion and retention procedures. Firebase states that removal of authentication information from its live and backup systems can take up to 180 days after account deletion, and that Crashlytics starts removing crash data after 90 days. Support messages are stored and used to answer and resolve your request; request their deletion through the same support form. We may retain information where needed to meet legal obligations or resolve a dispute, and will explain applicable limits when responding to a request.
Requests and questions
You can request access, correction or deletion through the MyIman support form, including without reinstalling the app. Identify MyIman and describe the information or issue. We may need additional information to confirm ownership of an anonymous service account; never send a password or payment details. We cannot remotely erase information that exists only on a device we cannot access.
Service providers may process information outside your country. We use encrypted connections and access controls, but no system can guarantee absolute security. If local law gives you additional privacy rights or a right to complain to a data-protection authority, those rights are unaffected. We do not ask for children's personal details; contact support if you believe a child has submitted such information. Material changes to these practices will be reflected here and, when needed, in the app's choices and disclosures.