Refqa
Privacy Policy
Last updated 20 August 2026
The short version
Refqa has no user accounts, no sign-in, and no server of its own. It does not build a profile of you, does not show ads, and contains no advertising or analytics trackers.
One thing does leave your device, and you should know about it: your location is sent to the prayer-times service (AlAdhan) to calculate accurate times for where you are. You are told this, in the app, before it ever asks for the permission.
Your voice is only ever sent anywhere if you explicitly say yes. The recitation check runs on your device by default; on phones that cannot do that, the app asks — once, in plain words — whether you want to use Google's speech service instead, and you can change that answer at any time in Settings.
If the app crashes, a technical report of the failure is sent to our error tracker (Sentry) so it can be fixed. Your location is stripped out of those reports before they leave the device, and they carry no identifier for you.
Everything else — your bookmarks, streaks, dhikr counts, and settings — stays on your phone.
Who we are
Refqa is an Islamic companion app offering prayer times, qibla direction, the Qur'an, Hadith, du'as, dhikr counting, and recitation practice.
Contact: hussein.mohamed.software@gmail.com
No accounts, no backend
Refqa has no registration, no login, and no Refqa-operated server. We do not have a database of users, because there are no users to have. Nothing you do in the app is associated with an identity, because the app never establishes one.
Location
What: Your device's approximate or precise coordinates (latitude and longitude), and altitude where your device reports it.
Why: To calculate prayer times for your position and to point the qibla compass toward the Kaaba. Both are meaningless without knowing where you are.
When: Only while you are using a feature that needs it — the prayer times screen or the qibla compass. Refqa does not track your location in the background, and does not request "always" location access.
Stored? No. Your coordinates are used to make the calculation and then discarded; they are never written to your device's storage. What is saved on your device is the resulting prayer timetable — the times themselves — so the app still works offline. The prayer-times service echoes your coordinates back in its reply, and Refqa removes them before saving that reply, which an automated test enforces. A saved timetable does imply a general area, but your coordinates themselves are not kept.
Shared? Yes — with one service. Your latitude and longitude are sent to
the AlAdhan prayer-times API (api.aladhan.com) with each request, because that
is how the service calculates times for your position. AlAdhan is operated by a
third party under its own privacy policy — see
https://aladhan.com/privacy-policy. Your coordinates are not sent to anyone
else.
When your device is offline, or the service is unreachable, Refqa calculates prayer times entirely on your device and your location is not transmitted at all.
Your control: Location permission is optional and requested only when you first open a feature that needs it. You can decline or revoke it in your device settings at any time. If you do, prayer times and qibla will not work, but the rest of the app is unaffected.
Microphone and speech recognition (تسميع)
What: Audio from your microphone, while you are actively recording a recitation in the Tasmee (recitation-check) feature.
Why: To transcribe what you recited so it can be compared against the text of the verse and marked correct or incorrect.
When: Only while you have deliberately started listening by tapping the microphone button on that screen. The microphone is not accessed anywhere else in the app, and never in the background.
Shared? Only if you have explicitly allowed it. By default, no.
Refqa does not perform speech recognition itself; it asks your operating system's built-in recognizer to do it. Every attempt is made in on-device mode first, which keeps the audio on your phone.
Many phones cannot recognise Arabic on-device — the attempt simply fails. When that happens, Refqa asks you, in a dialog, whether it may instead send that recording to Google's speech service to transcribe it. The dialog says so in those words. If you decline, nothing is sent and the feature reports that it is unavailable on your device. If you allow it, the recording is sent — and only then — for that attempt and future ones.
Your control: the answer is remembered and is fully revocable at Settings › Recitation check mode, which offers three choices:
- Ask me first (the default) — try on-device, ask before anything is sent.
- Allow online checking — try on-device, fall back to Google without asking again.
- This device only — never send audio anywhere, accepting that the feature will not work on phones without offline Arabic.
Microphone permission is separate, optional, and requested only when you first use Tasmee. Decline it and every other part of the app works normally.
Stored? No. The audio is never recorded to a file and never saved by Refqa, and only the resulting text is held briefly in memory to grade the verse, then discarded when you leave the screen. Where you have allowed online checking, what Google does with the audio it receives is governed by Google's own privacy policy, not this one.
Notifications
Refqa sends you the adhan at prayer times, optional salawat reminders, and an optional streak reminder.
All notifications are generated locally on your device. Refqa has no push notification service: there is no Firebase Cloud Messaging, no push token, and no server that can send you anything. Your device schedules them from times it calculated itself, and they work with no internet connection.
Refqa uses exact alarms so the adhan sounds at the true prayer time rather than being delayed by battery optimisation. This is a scheduling permission; it collects nothing.
Notification permission is optional and revocable in your device settings.
Crash reporting
Refqa uses Sentry (https://sentry.io) to report crashes and errors so they can be fixed. What is sent is a technical description of the failure: the error, a stack trace, and device/OS details such as model, OS version, and app version.
Deliberately not sent:
- Your location. Coordinates are stripped from every report before it leaves the device, including from network URLs and error messages that would otherwise contain them. This is enforced in code and covered by automated tests.
- Your IP address, which Sentry is explicitly configured not to collect.
- Screenshots or screen contents, which are disabled.
- Any identifier for you, since the app has none to send.
- Your voice or any audio.
Routine network failures (being offline, a timeout) are not reported at all.
Sentry processes this data on our behalf under its own privacy policy — https://sentry.io/privacy/.
Update and maintenance checks
Refqa asks Google's Firebase Remote Config one question when it starts: is this version still supported, and is the app currently available? That is what lets a critical fix be made mandatory, and lets the app be paused if something is seriously wrong with it.
The request carries no account, no location, and nothing you have done in the app. Like any internet request it reveals your IP address, and Firebase gives the installation a random identifier so the request can be answered. Three things are worth stating plainly:
- No Google Analytics. The Firebase project is configured without it, and no analytics or measurement SDK ships in the app.
- Nothing about you is sent. The app asks a question; it does not report.
- It is never required. If the check fails — you are offline, or the service cannot be reached — the app opens normally and withholds nothing.
Firebase processes this under Google's own privacy policy — https://firebase.google.com/support/privacy.
What is stored on your device
All of this stays on your phone, is never uploaded, and is not visible to us:
- Bookmarks and reading position
- Streaks, daily goals, challenges, and achievement progress
- Dhikr (tasbih) counts
- Settings: language, chosen reciter, font size, adhan and reminder preferences
- Cached content: Qur'an text, hadith, du'as, tafsir, and the prayer timetable, so the app works offline
Deleting it: Uninstalling Refqa deletes all of it permanently. There is no copy anywhere else, so there is nothing for you to request from us and nothing for us to delete on your behalf.
Third-party services Refqa contacts
Refqa fetches content from these services. As with any internet request, each necessarily sees your IP address and the content you requested. Only AlAdhan receives your coordinates.
| Service | Purpose | Receives your location? |
|---|---|---|
AlAdhan (api.aladhan.com) |
Prayer times, qibla, hijri dates | Yes |
AlQuran.cloud (api.alquran.cloud) |
Qur'an text and verse audio | No |
MP3Quran (mp3quran.net) |
Reciter catalogue and audio | No |
Qurango (backup.qurango.net) |
Live radio station audio | No |
RadioJar (stream.radiojar.com) |
Live radio station audio | No |
quran.com (api.quran.com) |
Tafsir and verse text | No |
jsDelivr (cdn.jsdelivr.net) |
Hadith collections | No |
Sunnah.com (api.sunnah.com) |
Hadith (when configured) | No |
| Google / Apple speech services | Recitation transcription — only after on-device recognition fails and you allow it | No (receives the recording, not your location) |
Sentry (sentry.io) |
Crash and error reports | No (stripped) |
Firebase Remote Config (firebaseremoteconfig.googleapis.com) |
Update and maintenance checks | No |
Advertising and analytics
Refqa contains no advertising and no analytics or tracking SDKs. We do not measure your usage, do not build a profile, and do not sell or share data with anyone for advertising. There is no data broker relationship of any kind.
Firebase Remote Config, described above, is a configuration service and not an analytics one: the Firebase project is created with Google Analytics switched off, and no measurement SDK is bundled with the app.
Children
Refqa is suitable for all ages and is not directed at children specifically. It does not knowingly collect personal information from anyone, of any age, because it does not collect personal information at all.
Your rights
Because Refqa holds no personal data on any server, most data-protection rights (access, correction, deletion, portability) have nothing to act on. Your data is already, and only, in your hands: it is on your device, and uninstalling the app erases it.
For data held by the third parties listed above, contact them directly under their own policies.
Changes to this policy
If this policy changes materially, the updated version will be published here with a new "last updated" date, at its permanent home: https://husseinmohamed99.github.io/privacy/refqa/
Contact
Questions about this policy, or about your data, go to hussein.mohamed.software@gmail.com.
This page mirrors the privacy policy bundled inside the app under Settings → Privacy, which is rendered from the same source text.
رِفقة
سياسة الخصوصية
آخر تحديث ٢٠ أغسطس ٢٠٢٦
الخلاصة في سطور
رِفقة مفيهاش حسابات، ولا تسجيل دخول، ولا سيرفر خاص بيها. مش بتعمل لك ملف شخصي، ومفيهاش إعلانات ولا أي أدوات تتبّع أو تحليلات.
فيه حاجة واحدة بتطلع من جهازك، ومن حقك تعرفها: مكانك بيتبعت لخدمة مواقيت الصلاة (AlAdhan) عشان تحسب المواقيت الصح في المكان اللي إنت فيه. والتطبيق بيقول لك كده، جوّه التطبيق، قبل ما يطلب الإذن من الأصل.
صوتك مش بيطلع من جهازك غير لو إنت قلت أيوه بنفسك. التحقّق من التلاوة بيشتغل على جهازك افتراضيًا؛ والتليفونات اللي مش قادرة على كده، التطبيق يسألك — مرة واحدة، وبكلام واضح — تحب تستخدم خدمة الكلام من Google بدالها، وتقدر تغيّر إجابتك في أي وقت من الإعدادات.
ولو التطبيق وقع، بيتبعت تقرير فني بالمشكلة لأداة تتبّع الأعطال بتاعتنا (Sentry) عشان تتصلّح. موقعك بيتشال من التقارير دي قبل ما تسيب الجهاز، ومفيش فيها أي حاجة تدل عليك.
وأي حاجة تانية — محفوظاتك، سلاسلك، عدّاد التسبيح، وإعداداتك — بتفضل على تليفونك.
إحنا مين
رِفقة تطبيق رفيق للمسلم في يومه: مواقيت الصلاة، اتجاه القبلة، القرآن، الحديث، الأدعية، عدّاد الذِّكر، وتسميع التلاوة.
للتواصل: hussein.mohamed.software@gmail.com
لا حسابات ولا سيرفر
مفيش تسجيل، ولا تسجيل دخول، ولا سيرفر بتشغّله رِفقة. مش عندنا قاعدة بيانات مستخدمين، لأن مفيش مستخدمين من الأصل. أي حاجة بتعملها في التطبيق مش مربوطة بأي هوية، لأن التطبيق أصلاً مش بيعمل لك هوية.
الموقع
إيه اللي بياخده: إحداثيات جهازك التقريبية أو الدقيقة (خط الطول وخط العرض)، والارتفاع لو جهازك بيبلّغ بيه.
ليه: عشان يحسب مواقيت الصلاة في مكانك، ويلفّ بوصلة القبلة ناحية الكعبة. الاتنين مش لهم أي معنى من غير ما نعرف إنت فين.
إمتى: بس وإنت فاتح ميزة محتاجاه — شاشة مواقيت الصلاة أو بوصلة القبلة. رِفقة مش بتتابع مكانك في الخلفية، ومش بتطلب إذن موقع "دايمًا".
بيتخزّن؟ لأ. إحداثياتك بتُستخدم في الحساب وبعدها ترمي، وعمرها ما بتتكتب في مساحة التخزين بتاعة جهازك. اللي بيتحفظ فعلاً على جهازك هو جدول المواقيت الناتج — الأوقات نفسها — عشان التطبيق يفضل شغّال بدون نت. خدمة المواقيت بتردّ وهي مرجّعة إحداثياتك في الرد، ورِفقة بتشيلها قبل ما تحفظ الرد ده، وفيه اختبار أوتوماتيكي بيفرض الكلام ده. الجدول المحفوظ فيه دلالة على منطقتك بشكل عام، بس الإحداثيات نفسها مش بتتحفظ.
بيتشارك؟ أيوه — مع خدمة واحدة. خط الطول وخط العرض بيتبعتوا لواجهة
مواقيت الصلاة AlAdhan (api.aladhan.com) مع كل طلب، لأن ده الطريقة اللي بيها
الخدمة تحسب مواقيتك. AlAdhan بيشغّلها طرف تالت وليها سياسة خصوصية خاصة بيها —
شوف https://aladhan.com/privacy-policy. وإحداثياتك مش بتتبعت لأي حد تاني.
ولو جهازك مقطوع من النت، أو الخدمة مش شغّالة، رِفقة بتحسب مواقيت الصلاة على جهازك بالكامل وموقعك مش بيتبعت خالص.
إنت المتحكّم: إذن الموقع اختياري ومش بيتطلب غير أول مرة تفتح ميزة محتاجاه. تقدر ترفضه أو تسحبه من إعدادات جهازك في أي وقت. لو عملت كده، مواقيت الصلاة والقبلة مش هيشتغلوا، بس باقي التطبيق مش هيتأثر بحاجة.
الميكروفون والتعرّف على الكلام (تسميع)
إيه اللي بياخده: الصوت من الميكروفون، وإنت بتسجّل تلاوتك فعليًا في ميزة التسميع.
ليه: عشان يحوّل اللي قريته لنص، فيتقارن بنص الآية ويتحدّد صح ولا غلط.
إمتى: بس بعد ما تبدأ الاستماع بنفسك بضغطة على زر الميكروفون في الشاشة دي. الميكروفون مش بيُستخدم في أي مكان تاني في التطبيق، ولا في الخلفية أبدًا.
بيتشارك؟ بس لو إنت سمحت بكده صريح. افتراضيًا، لأ.
رِفقة نفسها مش هي اللي بتتعرّف على الكلام؛ هي بتطلب من أداة التعرّف المدمجة في نظام تشغيل جهازك تعمل كده. وكل محاولة بتبدأ على الجهاز الأول، وده اللي بيخلّي الصوت عندك على تليفونك.
في تليفونات كتير مش قادرة تتعرّف على العربية على الجهاز — المحاولة بتفشل وخلاص. ولما ده يحصل، رِفقة تسألك في رسالة: تسمح تبعت التسجيل ده لخدمة الكلام من Google تحوّله لنص؟ والرسالة بتقول كده بالحرف. لو رفضت، مفيش حاجة بتتبعت والميزة بتقول لك إنها مش متاحة على جهازك. ولو سمحت، التسجيل بيتبعت — ومش قبل كده — للمحاولة دي واللي بعدها.
إنت المتحكّم: إجابتك بتتحفظ، وتقدر تغيّرها بالكامل من الإعدادات › طريقة التحقّق من التلاوة، وفيها تلات اختيارات:
- اسألني أولاً (الافتراضي) — جرّب على الجهاز، واسأل قبل ما تبعت أي حاجة.
- السماح بالتحقّق عبر الإنترنت — جرّب على الجهاز، ولو فشل روح لـ Google من غير سؤال تاني.
- على هذا الجهاز فقط — مش هيتبعت صوت لأي مكان أبدًا، مع إنك عارف إن الميزة مش هتشتغل على التليفونات اللي مفيهاش عربية بدون نت.
إذن الميكروفون منفصل، واختياري، ومش بيتطلب غير أول مرة تستخدم التسميع. ولو رفضته، كل حاجة تانية في التطبيق شغّالة عادي.
بيتخزّن؟ لأ. الصوت عمره ما بيتسجّل في ملف ولا بتحفظه رِفقة، والنص الناتج بس هو اللي بيقعد شوية في الذاكرة عشان يصحّح الآية، وبعدها يرمي لما تسيب الشاشة. ولو سمحت بالتحقّق عبر الإنترنت، اللي Google بتعمله بالصوت اللي بيوصلها بيحكمه سياسة الخصوصية بتاعتها، مش السياسة دي.
الإشعارات
رِفقة بتبعت لك الأذان في مواقيت الصلاة، وتذكير اختياري بالصلاة على النبي، وتذكير اختياري بالمواظبة.
كل الإشعارات بتتولّد محليًا على جهازك. رِفقة مفيهاش خدمة إشعارات دفع خالص: مفيش Firebase Cloud Messaging، ولا رمز دفع، ولا سيرفر يقدر يبعت لك أي حاجة. جهازك هو اللي بيجدولها من مواقيت حسبها بنفسه، وهي شغّالة من غير أي اتصال بالإنترنت.
ورِفقة بتستخدم منبّهات مضبوطة بالثانية عشان الأذان يرفع في وقته الحقيقي مش يتأخّر بسبب توفير البطارية. ده إذن جدولة، ومش بياخد أي بيانات.
إذن الإشعارات اختياري، وتقدر تسحبه من إعدادات جهازك.
تقارير الأعطال
رِفقة بتستخدم Sentry (https://sentry.io) عشان تبلّغ عن الأعطال والأخطاء فتتصلّح. واللي بيتبعت هو وصف فني للمشكلة: الخطأ، وتتبّع المكدّس، وتفاصيل الجهاز والنظام زي الموديل وإصدار النظام وإصدار التطبيق.
واللي مش بيتبعت بقصد:
- موقعك. الإحداثيات بتتشال من كل تقرير قبل ما يسيب الجهاز، وكمان من روابط الشبكة ورسايل الخطأ اللي كانت هتحتويها. ده مفروض في الكود ومغطّى باختبارات أوتوماتيكية.
- عنوان الـ IP بتاعك، وSentry مضبوطة صريح إنها متجمّعوش.
- صور الشاشة أو محتوى الشاشة، ودي معطّلة.
- أي حاجة تدل عليك، لأن التطبيق مش عنده حاجة زي كده يبعتها من الأصل.
- صوتك أو أي تسجيل صوتي.
ومشاكل الشبكة العادية (إنك مقطوع من النت، أو انتهاء المهلة) مش بيتبلّغ عنها خالص.
Sentry بتعالج البيانات دي بالنيابة عننا تحت سياسة الخصوصية الخاصة بيها — https://sentry.io/privacy/.
فحص التحديثات والصيانة
رِفقة بتسأل خدمة Firebase Remote Config من Google سؤال واحد أول ما تفتح: النسخة دي لسه مدعومة؟ والتطبيق شغّال دلوقتي؟ ده اللي بيخلّينا نقدر نفرض تحديث مهم، ونقدر نوقف التطبيق مؤقتًا لو فيه حاجة غلط بجد.
الطلب ده مش شايل حساب، ولا موقع، ولا أي حاجة إنت عملتها في التطبيق. وزي أي طلب على الإنترنت، بيبان منه عنوان الـ IP بتاعك، وFirebase بتدّي النسخة المثبّتة معرّف عشوائي عشان تقدر ترد على الطلب. وفيه تلات حاجات تستاهل نقولها بوضوح:
- مفيش Google Analytics. مشروع Firebase متظبّط من غيرها، ومفيش أي أداة تحليلات أو قياس شايلها التطبيق.
- مفيش حاجة عنك بتتبعت. التطبيق بيسأل سؤال، مش بيبلّغ عنك.
- مش شرط أبدًا. لو الفحص فشل — إنت مقطوع من النت، أو الخدمة مش موجودة — التطبيق بيفتح عادي ومش بيمنع عنك أي حاجة.
Firebase بتعالج ده تحت سياسة الخصوصية الخاصة بـ Google — https://firebase.google.com/support/privacy.
اللي متخزّن على جهازك
كل ده بيفضل على تليفونك، عمره ما بيترفع لحد، وإحنا مش شايفينه:
- المحفوظات وموضع القراءة
- السلاسل، والأهداف اليومية، والتحديات، وتقدّم الإنجازات
- عدّاد الذِّكر (المِسبحة)
- الإعدادات: اللغة، القارئ اللي اخترته، حجم الخط، وتفضيلات الأذان والتذكير
- المحتوى المحفوظ: نص القرآن، والحديث، والأدعية، والتفسير، وجدول المواقيت، عشان التطبيق يشتغل بدون نت
تحب تحذفه؟ لو حذفت رِفقة من جهازك، كل ده يروح نهائي. مفيش نسخة منه في أي مكان تاني، فمفيش حاجة تطلبها مننا ولا حاجة نحذفها لك.
خدمات خارجية رِفقة بتتواصل معاها
رِفقة بتجيب المحتوى من الخدمات دي. وزي أي طلب على الإنترنت، كل واحدة منها بتشوف بالضرورة عنوان الـ IP بتاعك والمحتوى اللي طلبته. وAlAdhan بس هي اللي بيوصلها إحداثياتك.
| الخدمة | الغرض | بيوصلها موقعك؟ |
|---|---|---|
AlAdhan (api.aladhan.com) |
مواقيت الصلاة، والقبلة، والتواريخ الهجرية | أيوه |
AlQuran.cloud (api.alquran.cloud) |
نص القرآن وصوت الآيات | لا |
MP3Quran (mp3quran.net) |
قائمة القُرّاء والتلاوات | لا |
Qurango (backup.qurango.net) |
بث الإذاعات المباشر | لا |
RadioJar (stream.radiojar.com) |
بث الإذاعات المباشر | لا |
quran.com (api.quran.com) |
التفسير ونص الآيات | لا |
jsDelivr (cdn.jsdelivr.net) |
مجموعات الحديث | لا |
Sunnah.com (api.sunnah.com) |
الحديث (لما يكون مضبوط) | لا |
| خدمات الكلام من Google / Apple | تحويل التلاوة لنص — بس بعد ما التعرّف على الجهاز يفشل و إنت توافق | لا (بيوصلها التسجيل، مش موقعك) |
Sentry (sentry.io) |
تقارير الأعطال والأخطاء | لا (بتتشال) |
Firebase Remote Config (firebaseremoteconfig.googleapis.com) |
فحص التحديثات والصيانة | لا |
الإعلانات والتحليلات
رِفقة مفيهاش إعلانات ومفيهاش أي أدوات تحليلات أو تتبّع. إحنا مش بنقيس استخدامك، ومش بنعمل لك ملف شخصي، ومش بنبيع بيانات ولا بنشاركها مع أي حد للإعلانات. ومفيش أي علاقة بأي وسيط بيانات بأي شكل.
وFirebase Remote Config اللي فوق دي خدمة إعدادات، مش خدمة تحليلات: مشروع Firebase متعمل وGoogle Analytics مقفولة، ومفيش أي أداة قياس متحطّة في التطبيق.
الأطفال
رِفقة مناسبة لكل الأعمار، ومش موجّهة للأطفال بالتحديد. وهي مش بتجمع بيانات شخصية من أي حد، في أي عمر، لأنها مش بتجمع بيانات شخصية من الأصل.
حقوقك
لأن رِفقة مش ماسكة أي بيانات شخصية على أي سيرفر، أغلب حقوق حماية البيانات (الوصول، والتصحيح، والحذف، ونقل البيانات) مش لاقية حاجة تشتغل عليها. بياناتك أصلاً — وبس — في إيدك: هي على جهازك، ولو حذفت التطبيق تتمسح.
وبالنسبة للبيانات اللي عند الأطراف التالتة المذكورة فوق، كلّمهم مباشرة تحت سياساتهم.
تغييرات على السياسة
لو السياسة دي اتغيّرت تغيير جوهري، النسخة المحدّثة هتُنشر هنا بتاريخ "آخر تحديث" جديد، في بيتها الدائم: https://husseinmohamed99.github.io/privacy/refqa/
للتواصل
أي سؤال عن السياسة دي، أو عن بياناتك، ابعته على hussein.mohamed.software@gmail.com.
تعكس هذه الصفحة سياسة الخصوصية المرفقة داخل التطبيق ضمن الإعدادات ← الخصوصية، وهي معروضة من نفس النص المصدري.