← Back to Home
Privacy Policy
Last updated: September 10, 2026
1. Introduction
This Privacy Policy explains how we ("we," "our," or "us," the developer of the Quran AI (AI Quran Reader) mobile application, the "App") collect, use, and share information when you use the App, available on the Apple App Store and on Google Play (Android package com.skiestech.aiquran). By downloading, installing, or using the App, you acknowledge that you have read and understood this Privacy Policy. If you do not agree, please do not use the App.
Who we are: Appskies is the developer and data controller responsible for your personal data. You can contact us at Salih Kanat Sk., Özlem Apt. D:2, Girne/KKTC, Mersin 10, Türkiye, or by email at appskiesltd@gmail.com.
2. Information We Collect
2.1 Information You Provide
The App does not require you to create an account. You can use it with an automatically generated anonymous identifier, and we do not collect a username or password. You may optionally provide:
- Email address (optional): If you choose to enter it during onboarding or when contacting us, we use it to send you relevant updates and reply to support requests. On iOS, the App stores an onboarding email in our Firebase database and a local support-reply cache; it does not forward newly submitted emails to subscription or attribution providers. On Android, an onboarding email is kept on your device only and is not written to Firebase or sent to subscription or attribution providers. You can skip this — the App works fully without it.
- Support communications: The content of messages you send us for support or feedback, together with basic diagnostic details you agree to attach (app version, device model, OS version, language, and subscription status).
- AI assistant input: The messages you type into the in-app AI assistant, which are sent to our AI service provider to generate a response (see §9).
- Referral information: Earlier App versions may have associated referral credits and the history of promo codes used with your anonymous app identifier.
- Preferences & reading progress: Your settings, bookmarks, reading goals, and Khatmah/tracking progress, stored on your device.
Anonymous sign-in: Firebase anonymous sign-in assigns a pseudonymous identifier (a Firebase UID), rather than creating a named account. On Android, Firebase App Check uses Google Play Integrity to attest requests from the App.
2.2 Information Collected Automatically
- Device information: Device model, operating system and version, language and region settings, and device identifiers such as the Identifier for Vendors (IDFV). With your permission (see §4), we also access the Identifier for Advertisers (IDFA).
- Usage & analytics data: How you interact with the App — features used, screens viewed, and session information — to understand and improve the App.
- Diagnostic & crash data: Crash reports and technical logs used to diagnose and fix problems.
- Location: If you grant location permission, the App uses your device location to calculate local prayer times and the Qibla direction. The App sends a derived city/country to its prayer-time content provider rather than your raw coordinates. Advertising and attribution providers may also infer an approximate location from network or device signals, subject to your choices and their policies.
- Purchase information: Records of in-app purchases and subscriptions, where offered. Payment is processed by the relevant app store (Apple App Store or Google Play); we do not receive your payment card details.
2.3 Information We Do NOT Collect
- We do not access your contacts, calendar, photos, or other personal files.
- We do not collect payment card information — all payments are processed by the relevant app store (Apple App Store or Google Play).
2.4 Information About Religious Beliefs
Questions you type and your worship and reading records may reveal your religious beliefs. Your worship and reading records are kept on your device. AI questions are sent only when you ask a question in the assistant, including when you select a suggested question (see §9).
3. How We Use Your Information
- Service delivery: To provide and maintain the App's features — Quran reading, Athkar, Duas, prayer times, Qibla, the AI assistant, and Ramadan tools.
- Personalization: To tailor content and settings to your preferences.
- Purchases: To process and restore your subscriptions and in-app purchases, where these features are offered.
- Communication: To send technical notices and respond to your support requests.
- Analytics & improvement: To understand usage and improve the App.
- Advertising: To display and measure ads, including — with your permission — personalized ads (see §4).
- Safety & legal: To detect and prevent fraud or abuse and to comply with applicable law.
4. Advertising and App Tracking Transparency (ATT)
Platform note: This section applies to the iOS version of the App. The Android version currently includes no advertising, attribution or analytics SDKs, shows no ads, and does not access the Android advertising ID; the App Tracking Transparency (ATT) prompt and the IDFA described below are iOS-only.
The free version of the App shows advertisements through Unity LevelPlay (ironSource). The App also uses AppsFlyer to measure installs and sessions. These providers may process device identifiers, ad interactions, usage data, IP-derived approximate location, and related technical information to deliver and measure advertising and attribution. When the IDFA or cross-company data is used, Apple treats this as "tracking."
Before starting these advertising and attribution SDKs, we show Apple's App Tracking Transparency (ATT) prompt and pass your choice to the advertising system:
- If you allow tracking: the providers may access the IDFA to personalize and measure ads and attribute installs.
- If you do not allow tracking: the App does not grant access to the IDFA. You may still see contextual or non-personalized ads, and attribution may use Apple's privacy-preserving mechanisms or other non-IDFA signals permitted by the platform.
You can change ATT permission in iOS Settings › Privacy & Security › Tracking. Users with an active premium (ad-free) subscription are not shown ads. Firebase Analytics and Crashlytics are used for first-party product analytics and diagnostics; they are not used by us to track you across other companies' apps or websites.
5. Legal Basis for Processing (EEA/UK Users)
- Contract: Processing necessary to provide the App and its features.
- Legitimate interests: Improving and securing the App, where not overridden by your rights.
- Consent: For advertising/tracking and other activities that rely on your permission; you may withdraw consent at any time.
- Legal obligation: Where processing is required to comply with the law.
6. Data Retention
- On-device data (preferences, bookmarks, reading progress) remains on your device and is removed when you delete the App.
- Optional email, referral records, and Firebase guest account: On iOS, these are retained until you use Settings › Delete My Data (where available in your installed version) or ask us to delete them. The authenticated in-app flow removes the app-owned Firestore email record, referral credits and used promo-code history; queues a best-effort removal request for any email attribute an earlier App version sent to RevenueCat; deletes the Firebase Authentication guest account; and clears the locally cached email. RevenueCat's public SDK does not provide provider-side confirmation for that attribute request, so contact us at the address in §13 if you require confirmed provider deletion. A new Firebase guest session is then created so the App can continue operating. On Android, request deletion of your Firebase guest account and associated app-held data by emailing appskiesltd@gmail.com; the onboarding email remains on your device only.
- AI usage counters: On Android, each daily AI usage counter in Firestore is set to expire approximately 72 hours after its last update and is automatically removed through an enabled time-to-live (TTL) policy. These counters contain usage metadata only, not your question or reply text.
- Subscription continuity: Deleting the Firebase guest account does not cancel a subscription through the Apple App Store or Google Play. Where RevenueCat manages a subscription, it retains a pseudonymous subscriber identifier and purchase/subscription history so paid access and purchase restoration continue to work. Newly submitted emails are not sent to RevenueCat.
- Interrupted deletion recovery: On iOS, the App temporarily stores the deletion phase and old anonymous Firebase identifier on your device so an interrupted account deletion can finish on the next launch. After Firebase confirms account deletion, this recovery state is removed when a fresh guest session is created; it is not uploaded as a deletion receipt. If Firebase invalidates the local session without confirming server-side account deletion, the App conservatively keeps the old anonymous identifier on the device as a support reference, clearly reports that deletion is unconfirmed, and restores a separate usable guest session.
- Analytics/diagnostic data is retained for a limited period in accordance with our providers' policies and, where applicable, in aggregated or de-identified form.
- Transaction and subscription records are retained by the relevant app store (Apple or Google Play), RevenueCat where used, and us as needed to provide purchase access, restore purchases, prevent fraud, and meet financial, tax, or other legal obligations.
7. Data Storage and Security
We use reputable cloud infrastructure (Google Firebase) and apply industry-standard safeguards, including encryption of data in transit using TLS. No method of transmission or storage is completely secure, but we work to protect your information with appropriate measures.
8. Sharing and Disclosure
We do not sell your personal information. We share information only as follows: with the service providers listed in §9 to operate the App; when required by law or legal process; to protect our rights, users, or the public; in connection with a business transfer; or with your consent.
9. Third-Party Services
The App uses the following third-party services, each governed by its own privacy policy:
- Apple — app distribution, in-app purchases, and subscriptions.
- Google Play — app distribution and, where offered, in-app purchases and subscriptions.
- Google Firebase — anonymous authentication and app configuration. On iOS, Firebase also stores your optional email and referral records and provides analytics and crash reporting. On Android, Firebase hosts the AI callable and daily usage counters and provides App Check (Google Play Integrity) for request attestation; it does not store your onboarding email.
- Unity LevelPlay (ironSource) and its demand partners — advertising delivery and measurement (see §4).
- AppsFlyer — install and session attribution (see §4).
- RevenueCat — subscription management and related pseudonymous analytics, where used. The current App does not send newly submitted email addresses to RevenueCat. On iOS, for an email sent by an earlier version, the authenticated in-app flow queues a best-effort removal request through the RevenueCat SDK; because the SDK does not expose provider-side confirmation, contact us if you require confirmed provider deletion.
- OpenAI — processes the messages you send to the in-app AI assistant to generate responses. On iOS, AIProxy relays these requests to OpenAI.
- Content providers — public APIs used to deliver prayer-time calculations and Quran recitation/text content.
AI Assistant Data
On Android, your current message is sent to our Firebase HTTPS callable aiChat in the us-central1 region, which calls OpenAI on the server with your message and a server-side instruction. On iOS, your current message is sent through AIProxy to OpenAI. We do not attach your email, location, purchase data, past chat history, or Firebase UID to the request sent to OpenAI; anything you include in the current message itself is sent as part of that message.
On Android, questions are sent only when you ask a question in the assistant. This includes selecting a suggested question. On Android, our server records a daily usage counter linked to your pseudonymous Firebase UID and operational metadata (request outcome, model, input character count, token counts, and latency), but does not record the message or reply text.
OpenAI states that data submitted through its API is not used to train its models unless you opt in, and that limited abuse-monitoring logs may be retained, normally for up to 30 days, with exceptions described in its API data-usage policy. These logs may include message and reply content. On Android, our OpenAI requests set store: false to limit application-state retention; this does not disable OpenAI's abuse-monitoring logs.
10. Your Privacy Rights
Depending on your location, you may have the right to access, correct, or delete your personal data, to object to or restrict certain processing, to data portability, and to withdraw consent. Because the App does not use traditional accounts, most of your data is either stored on your device or associated with an anonymous identifier.
EEA/UK Users (GDPR)
Where the GDPR applies, your rights include:
- Access: Request access to and a copy of your personal data.
- Rectification: Ask us to correct inaccurate or incomplete personal data.
- Erasure: Request deletion of your personal data.
- Restriction: Ask us to restrict processing of your personal data.
- Portability: Request your data in a structured, commonly used, machine-readable format and its transfer to another controller where applicable.
- Objection: Object to processing of your personal data, including for direct marketing.
- Withdraw consent: Withdraw consent at any time where processing relies on it, without affecting the lawfulness of processing before withdrawal.
- Complaint: Lodge a complaint with a data-protection supervisory authority.
California Residents (CCPA/CPRA)
Where the CCPA/CPRA applies, your rights include:
- Know: Request information about the personal information we collect, use, and disclose, including a copy of that information.
- Delete: Request deletion of your personal information.
- Correct: Ask us to correct inaccurate personal information.
- Opt out: Opt out of the sale or sharing of your personal information.
You can exercise these rights by emailing appskiesltd@gmail.com. We will not discriminate against you for exercising your privacy rights.
Deletion and Other Requests
In-app deletion: On iOS, if your installed version includes Settings › Delete My Data, use it to delete your optional app-owned cloud email, referral credits and used promo-code history, your Firebase Authentication guest account, and the locally cached email. The authenticated App deletes its own Firestore records, queues and attempts to sync a best-effort RevenueCat request to remove any legacy email attribute, deletes the current anonymous Firebase account, and creates a new guest session so the App remains usable. RevenueCat's SDK does not expose provider-side confirmation of that attribute request; contact us at the address in §13 if you require confirmed removal by the provider. If interrupted, the App retains an on-device recovery phase until the operation finishes. If Firebase removes the local credential without confirming server-side account deletion, the App does not claim success: it retains the old anonymous identifier on the device as the support reference shown to you and restores a separate guest session.
Android deletion: On Android, request deletion of your Firebase guest account and associated app-held data by emailing appskiesltd@gmail.com. On Android, there is no in-app account-deletion option.
What deletion does not remove: Deleting app-held data or your Firebase guest account does not delete the pseudonymous RevenueCat subscriber identifier or purchase history held by your app store (Apple or Google Play) or RevenueCat, where used, for subscription access and restoration; it does not cancel a store subscription or erase preferences and reading progress stored only on your device. Delete the App to remove that on-device data, and manage or cancel subscriptions through the store where you purchased them.
Additional requests and earlier app versions: Contact us at the address in §13 if the in-app option is not present, if you want assistance, or if you need to request deletion from a service provider. Providers may retain limited transaction, security, fraud-prevention, or legal-compliance records under their own policies and applicable law. EEA/UK users (GDPR) and California residents (CCPA/CPRA) have the additional rights described by those laws, including the right to lodge a complaint with a supervisory authority (EEA/UK) and the right to opt out of "sale"/"sharing" (California); we honor recognized opt-out signals where applicable.
11. Children's Privacy
The App is not directed to children under 13 (or the minimum age required in your jurisdiction), and we do not knowingly collect personal information from them. If you believe a child has provided us information, contact us and we will delete it.
12. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be reflected by updating the "Last updated" date above and, where appropriate, through an in-app notice.
13. Contact Us
If you have questions about this Privacy Policy or your data, contact us at:
appskiesltd@gmail.com.