Deen Over Dunya
TermsSupportGet the app

On this page

Information collectedPlanner AIHow it is usedStorage & securityService providersYour choicesRetentionChildrenContact

Privacy Policy

Last updated: September 4, 2026

Deen Over Dunya is built to collect only the information needed to operate the app and understand whether the website is useful. We do not sell personal information, serve advertisements, or use advertising trackers.

This policy explains how Deen Over Dunya (“we,” “our,” or “the app”) handles information when you use the iPhone and iPad app or visit this website. Some features described below, including remote Planner AI and Deen Pro, may depend on your app version, account, region, and release configuration.

Information we collect

  • Account information: Your email address, account identifier, and your name when Apple provides it during Sign in with Apple. Sign-in is required for the current release.
  • Content you create: Reading and listening progress, bookmarks, habits, routines, goals, projects, reminders, journal entries, prayer history, settings, and other content you choose to save. This information may be stored locally and linked to your account when synchronized.
  • Planner AI content: When you press Send in optional remote Planner AI, we process your current message (up to 2,000 characters), the selected local date and UTC offset, bucketed commitment, open-time, Inbox, and active-plan counts, typed planning state, and the context categories, date range, and limits you approved. We do not automatically send conversation history or prior assistant responses, exact open windows, stored calendar or Planner titles, workspace data, memories, notes, locations, attendees, attachments, provider names, native identifiers, prayer names, prayer-completion history, or sacred journal content. If you approve planning context, the model may request at most one bounded on-device availability or prayer-boundary read. Only necessary intervals return, under random per-turn aliases that expire locally. Anything you deliberately type is still part of your message.
  • Planner AI safety identifier: Our server also sends OpenAI a pseudonymous identifier derived from your account ID using a secret-key hash, for safety and abuse prevention. It can link requests from the same account but does not disclose your raw account ID or email address. It is not an advertising identifier.
  • Location: Coarse or precise location when you allow it for prayer-time calculations or Qibla. We use location for these functions, not for advertising or cross-app tracking.
  • Connected calendars: Calendar events only when you grant device-calendar permission, connect Google Calendar, or add a private iCalendar subscription link. Imported content may be linked to your account when synchronization is enabled. OAuth credentials and subscription links are stored encrypted.
  • Notification preferences: Prayer reminders and optional Planner check-ins are scheduled locally on your device. Planner check-ins are opt-in and use generic Lock Screen text. The app does not send us a push token for these local notifications.
  • Screen Time selections: Personal Protection uses Apple Family Controls and Screen Time frameworks. Apple provides privacy-preserving selections; your browsing history, Screen Time passcode, and general app-usage history are not sent to our servers.
  • Optional diagnostics: If you turn on Share Diagnostics, Sentry processes crash and reliability information to help us resolve problems. Crash reports may be associated with your account. Diagnostics are not used for advertising or tracking.
  • Purchases and entitlements: If you use Deen Pro or have an earlier App Store entitlement, we process limited StoreKit transaction, product, subscription status, renewal, expiry, refund, and entitlement information to provide and restore access. Apple handles payment credentials; we do not receive your full payment-card information.
  • Usage and reliability: Planner fair-use counters and allowlisted events such as feature, operation, outcome, and context help enforce limits, measure whether Apply and Undo work, and protect the service. Planner telemetry does not contain prompts, responses, titles, calendar content, tool arguments, tool results, or proposals. Token counts, latency, route, outcome, error code, pricing version, and estimated service cost may be stored without Planner content.
  • Website analytics: Cloudflare Web Analytics measures page performance and visits without advertising cookies. Our first-party download funnel records only the page category, broad App Store button placement, broad device and viewport classes, and a broad referral category such as direct, search, AI, social, or internal. It does not send account identifiers, advertising identifiers, full page URLs or query strings, raw referrer URLs, or persistent user IDs. The site uses optional browser session storage to avoid counting the same tab repeatedly and to keep a broad referral category for up to 30 minutes; it does not create a persistent visitor identifier.

How Planner AI works

Remote Planner AI is optional and requires current consent for each installation. Before sending, the app shows a summary derived from the exact prepared request. Deen Over Dunya sends it to OpenAI through our authenticated Supabase server function only after you press Send. A local check-in may prepare composer text but cannot transmit it. You may choose Minimal context, the default bounded Planning context, or narrower Custom context; increasing access requires a new choice.

The model may ask a question or return a typed draft. It has no Apply, database, calendar-write, messaging, completion, or deletion capability. Nothing changes from a response alone. Native app code resolves temporary references, refreshes current calendar and prayer truth, validates the draft, shows the consequences, and requires you to tap Apply. Eligible changes create a receipt and exact Undo while that receipt remains current.

Our OpenAI Responses request sets store to false and excludes provider-hosted tools and provider-stored conversation history. Remote processing fails closed unless a current operational attestation binds the dedicated OpenAI project, nonsecret key fingerprint, approved model snapshots, reviewer, and expiry to a project approved and configured for Zero Data Retention. Project or key changes invalidate that attestation. OpenAI’s current API data-controls documentation describes these controls and their limits. No system can promise absolute security.

How we use information

  • Provide Quran, prayer, Qibla, planning, routine, Rawabit, widget, and personal protection features.
  • Authenticate accounts and synchronize account-linked content across devices when Auto Sync is enabled.
  • Interpret an optional Planner request, return a reviewable proposal or clarification, enforce fair-use limits, and restore subscription access.
  • Calculate prayer information and Qibla when location permission is granted.
  • Import events from the calendars and read-only subscription feeds you select.
  • Investigate crashes and reliability issues when Share Diagnostics is enabled.
  • Measure content-free product reliability and website usefulness.
  • Protect the service, prevent abuse, and meet legal obligations.

Storage and security

App information is stored locally on your device. When Auto Sync is enabled, account-linked content is stored using Supabase and protected with account authorization and row-level security policies. You can turn Auto Sync off in Settings.

No system can guarantee absolute security. We use reasonable technical and organizational safeguards appropriate to the information and service, and we limit collection where information is not needed.

Service providers

  • Supabase: authentication, database, encrypted calendar connection storage, account-linked synchronization, entitlement and usage enforcement, and the server boundary for Planner AI.
  • OpenAI: processes the bounded Planner AI request and returns a typed response when you enable and use remote Planner AI.
  • Apple: Sign in with Apple, StoreKit purchases and subscriptions, device location, calendars configured on your device, local notifications, and Family Controls / Screen Time frameworks.
  • Google: Google Calendar authorization and read-only calendar access when you connect Google Calendar directly.
  • Sentry: optional crash reporting and reliability diagnostics only when Share Diagnostics is enabled.
  • Cloudflare: website delivery, security, privacy-first Web Analytics, and storage of coarse first-party website funnel events.

These providers process information under their own terms and privacy practices. We require service providers acting for us to protect information consistently with their role and applicable obligations. We do not provide personal information to advertising networks.

Your choices and rights

Depending on where you live, you may have rights to access, correct, export, or delete personal information. In the app, go to Settings → Privacy & Compliance → Data Rights to manage your data and account.

  • Decline remote Planner AI and keep using manual planning, capture, Inbox, forms, editing, scheduling, and Undo.
  • Withdraw consent for this device or revoke all of your devices; withdrawal cancels active requests and does not queue a resend.
  • Choose Minimal, Planning, or narrower Custom context before each prepared request.
  • Turn local Planner check-ins off or change their quiet hours and daily cap.
  • Turn Auto Sync off in Settings.
  • Disconnect Google Calendar or any subscription feed in Calendar Integrations.
  • Revoke location, device-calendar, notification, or Screen Time permissions in iOS Settings.
  • Turn Share Diagnostics off at any time.
  • Export your data or initiate permanent account and associated cloud-data deletion.

Retention and deletion

Account-linked content is retained while your account remains active or as needed to provide the service. The Planner AI backend does not retain prompts, responses, proposals, tool arguments, or tool results. It retains only content-free device-consent state and bounded quota, idempotency-lease, billing, security, latency, token, model, prompt-version, and outcome metadata. Content-free Planner AI audit rows are retained for 90 days, fair-use windows for 14 months, and daily subscription revenue evidence for 25 months. Optional crash reports are retained for up to 90 days and other optional usage diagnostics for up to 30 days. Coarse first-party website funnel events are retained for three months.

The applicable OpenAI controls are described in How Planner AI works. Some operational records may be retained longer when reasonably required for security, fraud prevention, subscription disputes, financial reporting, or legal compliance.

Account deletion removes associated cloud data after the request is processed, subject to limited lawful retention. Local proposals, receipts, history, and other device information may remain until the app’s local data is cleared or the app is removed.

Children’s privacy

Deen Over Dunya is not directed to children under 13, and we do not knowingly collect personal information from children under 13. The current Personal Protection feature is for managing selected apps on your own device; it does not provide child-device monitoring or remote family supervision.

International processing

Our service providers may process information in countries other than the one where you live. Where required, we rely on appropriate safeguards for cross-border processing.

Changes to this policy

We may update this policy as the app or legal requirements change. We will post the revised date here and provide additional notice in the app or by email when a change is material and notice is required.

Contact

Questions, privacy requests, or concerns can be sent to deenoverdunya.ca@gmail.com.

© 2026 Deen Over Dunya · Home · About · Terms · Support