Privacy Policy
Vaktim Application
Data Controller: Soner Yılmaz (Vaktim application)
Contact: destek@vaktim.app
Last Updated: July 2026
1. Introduction
Soner Yılmaz, who operates the Vaktim application, values the privacy of user data. This policy explains what data is collected when you use the application, for what purposes it is used, and with which service providers it is shared. You may contact the data controller at destek@vaktim.app. For detailed information regarding the legal bases for the processing of personal data, the disclosure obligation, and your rights, please review this policy together with the Disclosure Notice (KVKK).
2. Categories of Data Collected
2.1 Account and Profile Data
- Email address
- Display name
- Avatar information
- Session and authentication records
2.2 Subscription and Premium Data
- Subscription status
- Technical records originating from the store or payment infrastructure
- Usage quota information
2.3 Optional Sync Data
If you enable the Sync feature and provide your explicit consent, the following data may be stored in the cloud environment in association with your account:
- Qur'an and supplication (dua) progress data
- Dhikr and salawat summary data
- Prayer tracking data and related summary statistics
- Favorite content references
- Badges, points, and similar gamification records
Because prayer tracking and Qur'an, supplication, dhikr, and salawat progress may reveal your religious belief, this data constitutes special categories of personal data within the meaning of Article 6 of the KVKK. The processing of this data in the cloud is based on your explicit consent. Any transfer abroad is based, for recipients covered by an adequacy decision, on the principles prescribed by the legislation; and, where no such decision exists, on appropriate safeguards such as a standard contract or an undertaking, and — because it involves special categories of data — your explicit consent is additionally obtained. Sync is off by default; this data is stored only if you enable Sync with your explicit consent, and you may withdraw your consent at any time.
2.4 Spiritual Guide Feature
When you use the Spiritual Guide (Manevi Rehber) feature, the messages you write and the limited conversation context necessary to generate a response are transmitted to the OpenAI infrastructure via Supabase Edge Functions.
These message contents are not part of the cross-device sync data set and are subject to a distinct, separate explicit consent that is independent of your sync consent. Your message content is transmitted to the OpenAI infrastructure (via Supabase edge) for the purpose of generating a response. The processing of the feature is based on your explicit consent; any transfer abroad, where there is no adequacy decision, is based on appropriate safeguards such as a standard contract or an undertaking, and additionally on your explicit consent. You may choose not to use this feature and may withdraw the consent you have given at any time.
With respect to this feature, OpenAI acts as an artificial intelligence service provider and recipient located abroad; additional explanations regarding its data processing practices may be found in its own policies and agreements.
2.5 ChatGPT / Vaktim MCP Integration
When you use Vaktim through ChatGPT, the text you ask ChatGPT to send to the Vaktim tools may be transmitted to the Vaktim MCP server in order to return Qur'an references, verse explanations, topic-based verse recommendations, context-based spiritual suggestions, or prayer times.
The Vaktim MCP tools are read-only. They do not create, update, or delete user account data. The MCP server may process metadata such as language, city name, Qur'an reference, the type of tool requested, and technical request information for the purposes of security, rate limiting, debugging, abuse prevention, and service reliability.
For prayer time requests made through ChatGPT, Vaktim does not request precise location; city-level information is sufficient. ChatGPT interactions are additionally subject to OpenAI's own privacy and data processing policies.
2.6 Data That Remains Only on the Device
- Qur'an and supplication notes
- Local copies of the chat history kept on the device
- The record of your full location history and search history
Note: The record of your search history is kept only on your device. However, at the moment you perform a location search, that query may be transmitted to the Google Maps/Places service via Supabase edge functions, as described in Section 5, in order to return results.
3. Purposes of Data Use
Your data may be used for the following purposes:
- Account creation and authentication
- Management of profile and application settings
- Cross-device synchronization
- Provision of premium services
- AI-supported response generation
- Management of the usage quota
- Security, error detection, and fulfillment of legal obligations
4. Third-Party Services
Vaktim relies on the following service providers to deliver its services. Because these providers are located abroad, the relevant data may be transferred abroad:
- Supabase Inc.: database, authentication, storage, and edge function infrastructure
- Amazon Web Services, Inc.: server services on which Supabase is hosted
- Cloudflare, Inc.: network security and content/file distribution
- Google LLC (Firebase and Google services): push notifications, product analytics when telemetry is enabled, remote configuration, Google Maps/Places (mosque map and location search), "Sign in with Google," and Google Play payment
- Apple Inc.: "Sign in with Apple" and App Store payment
- Sentry (Functional Software, Inc.): crash/error diagnostics with telemetry consent (European Union/Germany region)
- RevenueCat, Inc.: subscription and premium management
- OpenAI, L.L.C.: response generation within the scope of the Spiritual Guide and the ChatGPT/Vaktim MCP integration
These service providers have their own privacy policies and data processing practices.
Transfers that are mandatory for operating the service — such as account, authentication, infrastructure, and subscription — are based on the necessity for the performance of the contract. In this respect, the principal service providers are Supabase, Amazon Web Services, Cloudflare, Google/Firebase, Apple, Sentry, RevenueCat, and OpenAI. Since there is no adequacy decision regarding the recipient, these transfers are based on appropriate safeguards such as a standard contract or an undertaking, together with technical/administrative measures. For optional features involving special categories of data, such as Sync and the Spiritual Guide, your explicit consent is additionally obtained in addition to the appropriate safeguards.
5. Location Data
Location data is used primarily on the device to calculate prayer times and the qibla direction. When you use the location search or nearby mosque map feature, your search queries and the relevant coordinates may be transmitted to the Google Maps/Places service via Supabase edge functions; the map view is provided directly by Google Maps. The conversion between an address and coordinates (geocoding) is performed on the device, through the operating system's on-device component; this operation does not involve a separate transfer of personal data abroad.
6. Advertising and Analytics
Vaktim does not sell user data to third parties for the purpose of advertising sales or behavioral advertising, and does not collect an advertising ID. In-app product analytics (Firebase Analytics) and crash/error diagnostics (Sentry) operate only with your explicit consent and are off by default; you may turn this telemetry on or off at any time from the application settings and withdraw the consent you have given. Because these services are located abroad, if you enable telemetry, the relevant technical data may be transferred abroad with the appropriate safeguards prescribed by the legislation. Sentry crash/error data is processed in the European Union (Germany) region; Firebase Analytics data is processed on Google's infrastructure.
7. Retention and Deletion
Personal data is retained for the period necessary for the purpose for which it is processed and for the periods prescribed in the relevant legislation; upon the expiry of these periods, it is deleted, destroyed, or anonymized. Account data is retained for as long as the service relationship continues. Subscription records may be retained for the period prescribed by the relevant financial and tax legislation (currently ten years). Consent records may be kept for a reasonable period from the withdrawal of consent or the closure of the account, within the framework of the burden of proof. Sync data may be kept for as long as the Sync feature is active or until your deletion request is finalized. Disabling the Sync feature stops new data transfers; you may request the deletion of your existing data in the cloud via destek@vaktim.app.
8. Your Rights
You may submit your requests under Article 11 of the KVKK (including obtaining information, rectification, deletion, withdrawal of the consent you have given to processing/transfer, and objection) to destek@vaktim.app. For details of your rights and the application procedure, please refer to the Disclosure Notice (KVKK). In the event that your application is rejected, the response is found insufficient, or no response is given within the applicable period, you have the right to file a complaint with the Personal Data Protection Board.