Skip to content
Murattal
How it worksPrivacySupport  ↗
Clarity, from the beginning

Privacy Policy

Your practice is personal. Here is how Murattal handles your information and the choices you have.

On this page
1. Who we are2. Scope3. Important information about Qur'an activity4. Data we collect5. Why we use data6. Content-only mode7. When we disclose data8. International transfers9. Retention10. Your choices and rights11. Withdrawing sensitive-data consent12. Account deletion13. Security14. Minimum age15. Changes to this notice16. Contact and complaints

Status: Current privacy notice

Effective date: 2026-09-07

1. Who we are

Murattal is a product operated by Mirza Ohranovic, an individual operator established in Bosnia and Herzegovina, with a postal and service address at N Smailagica, Sarajevo. Murattal is not a separately registered legal entity.

For privacy questions or requests, contact hello@murattallock.com.

No Data Protection Officer has been appointed. Privacy requests may be sent to hello@murattallock.com.

EU representative, if required: Not applicable.

UK representative, if required: Not applicable.

2. Scope

This notice explains how Murattal collects, uses, discloses, keeps, and deletes personal data when you use the Murattal iOS app, authentication services, API, support channels, and murattallock.com website.

Website visits

Our static website does not use analytics, advertising trackers, collection forms, or application cookies. Fonts and images are served from the website itself. Railway hosts the website and may log visitor IP addresses and request metadata for security and operational purposes. See Railway's Privacy Policy for information about Railway's handling of this data. Following an App Store or other external link takes you to a service governed by its own privacy notice.

Murattal is available only to people aged 16 or older.

3. Important information about Qur'an activity

Your Qur'an plan, selected passages, listening history, progress, streaks, reciter choices, and related inferences may reveal information about religious beliefs. We treat this information as sensitive personal data.

Before Murattal stores this activity in the cloud, we ask for separate and explicit consent. You can refuse and use content-only mode. You can withdraw consent later in Settings.

We do not sell this information, use it for advertising, share it for cross-context behavioral advertising, or use it to train machine-learning models.

4. Data we collect

Account and authentication data

  • email address;
  • display name, when supplied;
  • Sign in with Apple identifier and token metadata;
  • authentication method and account-linking state;
  • session token metadata, expiration, IP address, and user agent;
  • email OTP verification and delivery metadata.

Profile and configuration

  • locale and timezone;
  • age-assurance result and policy version;
  • declared country of residence;
  • onboarding answers;
  • plan settings, daily target, reset time, reminders, reciter, text, and translation.

Sensitive Qur'an activity, only with explicit consent

  • structured and voluntary listening sessions;
  • verse positions and playback checkpoints;
  • listening duration, play, pause, seek, foreground, and background events;
  • daily commitments and completion state;
  • structured Qur'an progress and free-listening resume position;
  • streak and daily activity totals;
  • signed unlock-grant metadata.

Emergency-unlock reason categories are not stored on our servers.

Subscriptions

Apple processes in-app payments. We use RevenueCat to manage purchases and paid feature access. RevenueCat receives the Murattal account identifier used to link your purchases, purchase and subscription information, and technical information processed by its SDK. Murattal receives subscription status, product identifiers, and entitlement dates. We do not receive your full payment-card details.

We keep records of RevenueCat's processing terms, locations, and retention controls. If the categories or purposes of this processing materially change, we will update this notice and provide any notice required by applicable law.

Location and prayer times

With your device permission, Murattal requests a location to calculate prayer times on your device. The prayer-time calculator does not send coordinates to an external prayer-time service. You can change location permission in iOS Settings.

Device and technical data

  • installation identifier;
  • device display name provided by you;
  • iOS, application, and operating-system versions;
  • request IDs, error codes, security events, and service-performance information.

Murattal does not send Apple Family Controls app-selection tokens to its servers. Those tokens remain in the iOS app and its protected app group.

Support and privacy requests

  • messages and files you choose to send to support;
  • request type, status, and timestamps for access, correction, export, withdrawal, and deletion requests.

5. Why we use data

Purpose Data Basis for EU and UK users
Create and secure an account Account, session, device, and security data Contract and legitimate interests in service security
Deliver email OTP Email and OTP delivery metadata Contract and legitimate interests in authentication security
Provide Qur'an content Account status, requested content, and technical request data Contract
Save plans, progress, history, and streaks Sensitive Qur'an activity Explicit consent, including GDPR Article 9(2)(a) where applicable
Verify daily listening and issue unlock grants Sensitive activity, device, commitment, and grant data Explicit consent and contract
Provide support Account, request, and voluntarily supplied support data Contract and legitimate interests
Prevent fraud and protect the service Authentication, device, request, and security data Legitimate interests and applicable legal obligations
Meet legal obligations and rights requests Account, privacy-request, and minimal audit data Legal obligation

Consent for sensitive Qur'an activity remains separate from acceptance of the Terms of Use. We reassess the applicable legal basis when we enter a new market or materially change a processing purpose.

6. Content-only mode

If you do not consent to sensitive cloud activity storage, you can use content-only mode. It allows authenticated Qur'an browsing and streaming but does not provide cloud plans, synced progress, cloud history, streaks, daily commitment verification, or server-issued unlock grants.

In content-only mode, we do not retain the requested chapter, verse, reciter, or query details in application logs.

7. When we disclose data

We disclose personal data only as needed to operate the service, meet legal duties, or protect users and the service.

Current and planned recipients include:

  • Railway for API, PostgreSQL, and public website hosting, including website access logs;
  • Resend for authentication OTP email;
  • Apple for Sign in with Apple and Apple platform services;
  • RevenueCat for subscription and entitlement management;
  • Quran Foundation for backend content requests that do not include a stable Murattal user identifier;
  • Sentry, for redacted reliability, crash, and security data;
  • professional advisers and authorities where disclosure is legally required.

When audio is streamed directly to your device, the audio delivery provider receives the network request, including your IP address and the requested audio resource. This also applies in content-only mode. The app's production HTTPS audio allowlist currently includes verses.quran.foundation and mirrors.quranicaudio.com.

The current register is described in Subprocessors and international transfers.

We do not sell personal data. We do not share personal data for cross-context behavioral advertising.

8. International transfers

The primary application and database region is in the EU. Some providers or their subprocessors may access or process data in the United States or other countries.

Murattal is operated from Bosnia and Herzegovina. The operator accesses account, support, and operational data from there to run the service, respond to requests, and provide support.

Where required, we use mechanisms such as adequacy decisions, the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum, and supplementary technical and organizational measures.

EU hosting does not guarantee that every support, control-plane, email, or provider operation occurs only inside the EU.

9. Retention

Key periods are:

  • raw listening events: 30 days, then aggregation and deletion;
  • expired authentication metadata: 30 days;
  • email OTP rows: within 24 hours after expiry;
  • Qur'an Foundation content cache: no more than seven days without written permission;
  • unlock grants: validity period plus 30 days;
  • successful outbox records: 30 days;
  • audit and security events: 12 months, minimized and pseudonymized;
  • account data, plans, progress, and daily totals: while the account is active;
  • live account deletion: within 30 days;
  • backup expiry after deletion: within 90 days.

The complete schedule is in Data retention and deletion policy.

10. Your choices and rights

Depending on where you live, you may have rights to:

  • access personal data;
  • correct inaccurate data;
  • receive a portable copy;
  • delete personal data and your account;
  • withdraw consent;
  • object to or restrict certain processing;
  • limit use or disclosure of sensitive personal information;
  • appeal a denied request;
  • complain to a privacy regulator;
  • receive equal service and pricing when exercising privacy rights, subject to lawful feature limitations caused by the requested deletion or withdrawal.

Use Settings to access, export, withdraw consent, or delete your account. You may also contact hello@murattallock.com.

We target a substantive response within 30 calendar days. We may request information needed to verify identity. We will not ask for more information than necessary.

11. Withdrawing sensitive-data consent

Withdrawal stops new sensitive cloud processing, revokes active server-backed unlock grants, switches the account to content-only mode, and starts deletion of stored sensitive activity. Live sensitive activity is deleted within 30 days and backup copies expire within 90 days.

Withdrawing sensitive-data consent does not automatically delete the authentication account. You can separately delete the entire account.

Withdrawing consent does not cancel an Apple subscription. Paid features that depend on stored Qur'an activity, such as app locking, streaks, and khatm planning, stop working until you grant consent again. You can manage or cancel a subscription in your Apple account settings.

12. Account deletion

You can initiate account deletion in the iOS app. We immediately block account use, revoke sessions and active grants, and start the deletion workflow. Sign in with Apple authorization is revoked when technically available.

We delete or irreversibly de-identify live account data within 30 days. Encrypted backups expire within 90 days and are not used for ordinary processing. If a backup is restored, completed deletion requests are replayed before the restored system serves users.

We retain only a minimal deletion receipt and short restoration tombstone as described in the retention policy, unless law requires a specific protected record.

13. Security

We use safeguards including TLS, encryption at rest provided by managed infrastructure, least-privilege access, secret management, audit logging, dependency review, rate limits, signed unlock grants, and tested backup and deletion procedures.

No service can guarantee absolute security. Contact hello@murattallock.com if you believe your account or data has been compromised.

14. Minimum age

Murattal is not offered to anyone under 16. We use an age gate and may introduce additional privacy-preserving age assurance when required. If we learn that an account belongs to someone under 16, we will freeze and delete it through the underage-account remediation process.

15. Changes to this notice

We will update this notice when our practices or legal obligations materially change. For material changes involving sensitive data, we will provide prominent notice and request new consent when required.

16. Contact and complaints

Privacy contact: hello@murattallock.com

Postal address: N Smailagica, Sarajevo

EU representative: Not applicable.

UK representative: Not applicable.

You may also complain to the privacy or data-protection authority where you live.

Murattal
A daily pause. A deeper connection.
Privacy PolicyTerms & ConditionsSupport