All legal docs
Mizan · Legal

Privacy Policy

Last updated: August 29, 2026

Who we are

Mizan is developed and published by Shinka, an independent software studio based in Canada. This Privacy Policy describes the information the App processes, the information it does not process, and the choices available to you. Questions regarding this policy may be directed to the contact address provided below.

Email: [email protected]

What stays on your device

Mizan keeps a complete local record of your worship activity so the app can be useful across sessions. None of the following is ever transmitted anywhere by us. There is no server for it to go to.

  • Prayer completion marks and your prayer streak
  • Tasbih / dhikr counts and any custom counter targets you set
  • Journal entries, stored encrypted on your device and optionally locked behind Face ID or Touch ID
  • Quran memorization progress and your spaced-repetition (SRS) review schedule
  • Your Garden’s growth state, derived entirely from your own worship activity
  • Quran bookmarks and reading positions
  • App settings: calculation method, madhhab, notification preferences, theme, and language
  • Your display name and avatar choice. The name field is entirely optional, stored only on your device, and is never transmitted anywhere. It exists only so the app can greet you.

Location

Mizan requests location access using the “When In Use” authorization only. Mizan never asks for, and cannot use, “Always” location access. Your coordinate is used exclusively to (1) compute accurate prayer times for where you are and (2) compute the compass bearing to the Kaaba for the Qibla screen. Both calculations run entirely on your device using open astronomical formulas built into the app. Your coordinate is never transmitted to us. We have no server to send it to, and no analytics pipeline that would carry it anywhere else.

You can revoke location access at any time in iOS Settings → Privacy & Security → Location Services → Mizan. Without it, Mizan falls back to your last known fix. On a brand-new install with no fix at all, it uses a neutral placeholder location (Makkah) so the app never shows a confidently wrong city.

Apple’s reverse geocoding

When Mizan shows a city name next to your prayer times (for example “Toronto, ON”) instead of raw coordinates, it asks Apple’s geocoding service to translate your coordinate into a place name: a request that leaves the device and reaches Apple. This is a first-party Apple system service built into iOS (not a Mizan server and not a third-party SDK we added), and that request is governed by Apple’s own privacy policy, not this one. If the request fails (for example, offline or throttled), Mizan simply shows your coordinates instead; nothing else in the app depends on it.

The Qibla compass

The Qibla screen reads your device’s compass heading through iOS’s own compass service to draw a live compass pointing toward the Kaaba. Mizan collects no motion, fitness, or activity data. That heading is processed entirely on your device and is never recorded, logged, stored, or sent anywhere. Compass accuracy depends on your device’s calibration and on nearby magnetic interference (metal, magnets, some car mounts); Mizan cannot correct for interference it cannot detect. See the Terms of Service for the related accuracy disclaimer.

Notifications

Adhan (prayer-time) reminders and other in-app alerts are scheduled locally by iOS itself. Mizan computes every time on your device and simply hands it to iOS to fire at the right moment. There is no push-notification server and nothing is sent over the network to make this work. You can disable notifications at any time in iOS Settings → Notifications → Mizan.

Calendar

If, and only if, you tap Add to Calendar on a Hijri event, Mizan asks iOS for permission to add that single event to your device’s calendar; that path never reads your existing events. The optional action that adds a whole year’s major events at once asks for full calendar access instead, and reads only the events on those dates, solely so the same event is not added twice; nothing it reads is stored or sent anywhere. You can also export a year of Hijri dates as an .ics file through the iOS share sheet, which needs no calendar permission at all. Calendar access can be revoked at any time in iOS Settings → Privacy & Security → Calendars → Mizan.

The only network requests Mizan makes

Mizan works fully offline for prayer times, Qibla, tasbih, journal, memorization, and bundled Quran/hadith text. Every network request the app makes is listed below, and each is limited to a single named service:

  • Non-bundled Quran translations: fetched over HTTPS from api.alquran.cloud, once per surah/translation, then cached on your device so it isn’t fetched again. What that service can see: your IP address and which surah/edition you requested, the same as opening any web page. No account, no cookie set by us.
  • Recitation audio: streamed from everyayah.com, and for a small number of recitations that are defective there, from mp3quran.net. What those CDNs can see: your IP address and which audio file you requested, the same as streaming any public audio file in Safari.
  • Spoken meaning (meâl) audio: streamed from Diyanet’s public server (webdosya.diyanet.gov.tr) for Turkish, and from everyayah.com for English, only when you play a meaning aloud. Those servers see your IP address and which file you requested, nothing more.
  • Apple speech recognition: only while the Recite (follow-along) feature is actively listening. See the dedicated section below.
  • Apple reverse geocoding: Apple’s own servers, described above, governed by Apple’s privacy policy, not ours.

We do not run analytics on any of these requests, and we never receive logs from Tanzil.net, alquran.cloud, everyayah.com, or mp3quran.net. The standard web request metadata visible to those services (IP address, timestamp) is the same as it would be for any website you visit. We have no identifier to link that traffic back to a specific person, because we never collect one.

Widgets, Live Activities & Apple Watch

Home Screen and Lock Screen widgets, and the prayer-time Live Activity, compute directly on your device from the same local prayer-time engine as the app. They make no network calls of their own.

If you use the Apple Watch companion app, prayer, Qibla, and tasbih data are synced device-to-device using Apple’s own Watch sync, a private channel directly between your iPhone and your paired Watch. That sync never touches any Shinka infrastructure (we have none) or any third party.

Siri & Shortcuts

Mizan exposes a small number of voice and Shortcuts actions (for example, “what’s the next prayer”) through Apple’s Siri and Shortcuts system. When you invoke one, Apple’s on-device processing decides which action to run and hands control to Mizan locally on your device. Mizan never receives or sees your voice recording, and no request leaves your device to fulfill one of these actions.

Backups & exports

Mizan includes an optional, user-initiated Export backup feature that writes a single file to a location you choose. You may protect that file with your own passphrase; if you do, the file is encrypted with strong, industry-standard encryption derived from that passphrase. We never see, store, or transmit your passphrase. The file also carries an integrity check, so a corrupted or tampered backup is detected and refused on import rather than silently corrupting your data.

Because your settings are stored on the device, they are also included automatically in your own encrypted iPhone or iCloud backup if you have device backup turned on in iOS Settings. That backup is between you and Apple. Mizan itself pushes nothing to iCloud and runs no cloud storage of its own.

Live recitation recognition (Recite)

In a memorization session, in the Qur’an reader, and in the muṣḥaf you can tap the microphone so Mizan follows along while you recite. Recitation follow is the only feature that uses the microphone, and it listens only from the moment you tap it until you stop it or leave the screen.

The audio is passed to Apple’s own speech recognition (Arabic). Where your device and language support it, Mizan requests on-device recognition, and the audio never leaves your iPhone. Where on-device recognition is unavailable, Apple processes the audio on its servers under Apple’s privacy policy, the same path any dictation in iOS takes. iOS states this itself in the permission dialog before you ever grant it.

Mizan never records your recitation to a file, never stores the audio or the recognized text, and never transmits either to us or to anyone else. While you recite, only the running match exists in memory: which verse you are on and how many words in. What is kept afterwards is only the outcome, which verses you completed today, the same kind of on-device record as marking a verse read by scrolling past it, counted toward your khatm and daily goal and never sent anywhere. You can revoke either permission at any time in iOS Settings → Privacy & Security → Microphone (or Speech Recognition) → Mizan; the rest of the app keeps working without it.

Prayer lock & Screen Time

The prayer lock can block apps you choose during a prayer window. To do that it uses Apple’s Screen Time frameworks (Family Controls), which require your explicit permission the first time.

Which apps you pick is chosen inside Apple’s own picker, and iOS never tells Mizan what you selected. The app receives an opaque token it cannot read, and stores that token on your device only. Mizan cannot see which apps you have, cannot see how you use them, and cannot read anything about your Screen Time history.

A lock always ends by itself when its window closes, and you can end one early at any time from inside Mizan. Records of your locks (when, which prayer, how it ended) stay on your device like everything else. Screen Time permission can be revoked in iOS Settings → Screen Time.

What Mizan does not do

  • No user accounts, no sign-in, no “premium” tier
  • No analytics SDKs of any kind: no Firebase, Mixpanel, Amplitude, or similar
  • No crash reporters: no Crashlytics, Sentry, Bugsnag, or similar
  • No advertising and no ad networks of any kind
  • No cross-app tracking and no advertising identifier (IDFA) use. Mizan never shows an App Tracking Transparency prompt because it has nothing to track you for
  • No HealthKit, Contacts, Photos, or Camera access. Mizan never requests those permissions. (The microphone is used, but only for the Recite feature described above, and only while it is listening.)
  • No third-party SDKs of any kind beyond the named services above
  • No sale or sharing of personal information, to anyone, ever. We cannot sell what we never receive

Children

Mizan does not knowingly collect personal information from anyone, including children under the age of 13 (or the equivalent minimum age in your jurisdiction). There are no accounts, no chat, no user-generated content shared with others, and no mechanism by which a child (or anyone) submits personal information to us through the app. If you believe a child has provided information to us in a way that contradicts this policy, email us at the address below and we will investigate and delete it promptly, though the app’s design makes this scenario very unlikely in the first place.

Your rights

Because no personal data is transmitted to or stored by us, there is no remote copy of your information for us to access, correct, export, or delete on your behalf. Deleting the app from your device (or clearing its data in iOS Settings) deletes everything Mizan stores about you, instantly and completely. The one exception is anything you deliberately wrote out of the app and into somewhere else, such as Hijri events you added to your own calendar or a backup file you exported. Those stay where you put them and are yours to delete. By design, rather than by request, this satisfies the substance of:

  • The EU General Data Protection Regulation (GDPR) and the UK GDPR: rights of access, rectification, erasure, portability, and objection
  • The California Consumer Privacy Act as amended by the CPRA: rights to know, delete, and correct, and to opt out of sale or sharing (there is nothing to sell or share)
  • Turkey’s Law on the Protection of Personal Data (KVKK)
  • Canada’s Personal Information Protection and Electronic Documents Act (PIPEDA): Shinka is based in Canada

If your jurisdiction’s law gives you a right this page hasn’t described correctly, email us. We will do our best to help, though structurally there is very little for us to act on beyond confirming this policy’s accuracy.

Security

  • Journal entries are stored encrypted, with the key protected by your device’s own secure hardware
  • The optional Face ID / Touch ID check is performed by iOS itself. Mizan receives only a yes/no result, never any biometric data
  • All of Mizan’s on-device data lives inside Apple’s app sandbox, isolated from other apps on your device
  • Every network request described above travels over HTTPS

Changes to this policy

We may update this policy as the app changes. The “Last updated” date at the top of this page will change whenever we do, and material changes will be reflected here and, where appropriate, called out in the app’s release notes. Continued use of Mizan after a change means you accept the updated policy.

Contact

Questions, concerns, or requests about this policy, or about anything Mizan does with information related to you, can be sent to [email protected] at any time.

See also: Support · Terms