Privacy Policy

Vaktim Application

Data Controller: Soner Yılmaz (Vaktim application)
Contact: destek@vaktim.app
Last Updated: July 2026

1. Introduction

Soner Yılmaz, who operates the Vaktim application, values the privacy of user data. This policy explains what data is collected when you use the application, for what purposes it is used, and with which service providers it is shared. You may contact the data controller at destek@vaktim.app. For detailed information regarding the legal bases for the processing of personal data, the disclosure obligation, and your rights, please review this policy together with the Disclosure Notice (KVKK).

2. Categories of Data Collected

2.1 Account and Profile Data

2.2 Subscription and Premium Data

2.3 Optional Sync Data

If you enable the Sync feature and provide your explicit consent, the following data may be stored in the cloud environment in association with your account:

Because prayer tracking and Qur'an, supplication, dhikr, and salawat progress may reveal your religious belief, this data constitutes special categories of personal data within the meaning of Article 6 of the KVKK. The processing of this data in the cloud is based on your explicit consent. Any transfer abroad is based, for recipients covered by an adequacy decision, on the principles prescribed by the legislation; and, where no such decision exists, on appropriate safeguards such as a standard contract or an undertaking, and — because it involves special categories of data — your explicit consent is additionally obtained. Sync is off by default; this data is stored only if you enable Sync with your explicit consent, and you may withdraw your consent at any time.

2.4 Spiritual Guide Feature

When you use the Spiritual Guide (Manevi Rehber) feature, the messages you write and the limited conversation context necessary to generate a response are transmitted to the OpenAI infrastructure via Supabase Edge Functions.

These message contents are not part of the cross-device sync data set and are subject to a distinct, separate explicit consent that is independent of your sync consent. Your message content is transmitted to the OpenAI infrastructure (via Supabase edge) for the purpose of generating a response. The processing of the feature is based on your explicit consent; any transfer abroad, where there is no adequacy decision, is based on appropriate safeguards such as a standard contract or an undertaking, and additionally on your explicit consent. You may choose not to use this feature and may withdraw the consent you have given at any time.

With respect to this feature, OpenAI acts as an artificial intelligence service provider and recipient located abroad; additional explanations regarding its data processing practices may be found in its own policies and agreements.

2.5 ChatGPT / Vaktim MCP Integration

When you use Vaktim through ChatGPT, the text you ask ChatGPT to send to the Vaktim tools may be transmitted to the Vaktim MCP server in order to return Qur'an references, verse explanations, topic-based verse recommendations, context-based spiritual suggestions, or prayer times.

The Vaktim MCP tools are read-only. They do not create, update, or delete user account data. The MCP server may process metadata such as language, city name, Qur'an reference, the type of tool requested, and technical request information for the purposes of security, rate limiting, debugging, abuse prevention, and service reliability.

For prayer time requests made through ChatGPT, Vaktim does not request precise location; city-level information is sufficient. ChatGPT interactions are additionally subject to OpenAI's own privacy and data processing policies.

2.6 Data That Remains Only on the Device

Note: The record of your search history is kept only on your device. However, at the moment you perform a location search, that query may be transmitted to the Google Maps/Places service via Supabase edge functions, as described in Section 5, in order to return results.

3. Purposes of Data Use

Your data may be used for the following purposes:

4. Third-Party Services

Vaktim relies on the following service providers to deliver its services. Because these providers are located abroad, the relevant data may be transferred abroad:

These service providers have their own privacy policies and data processing practices.

Transfers that are mandatory for operating the service — such as account, authentication, infrastructure, and subscription — are based on the necessity for the performance of the contract. In this respect, the principal service providers are Supabase, Amazon Web Services, Cloudflare, Google/Firebase, Apple, Sentry, RevenueCat, and OpenAI. Since there is no adequacy decision regarding the recipient, these transfers are based on appropriate safeguards such as a standard contract or an undertaking, together with technical/administrative measures. For optional features involving special categories of data, such as Sync and the Spiritual Guide, your explicit consent is additionally obtained in addition to the appropriate safeguards.

5. Location Data

Location data is used primarily on the device to calculate prayer times and the qibla direction. When you use the location search or nearby mosque map feature, your search queries and the relevant coordinates may be transmitted to the Google Maps/Places service via Supabase edge functions; the map view is provided directly by Google Maps. The conversion between an address and coordinates (geocoding) is performed on the device, through the operating system's on-device component; this operation does not involve a separate transfer of personal data abroad.

6. Advertising and Analytics

Vaktim does not sell user data to third parties for the purpose of advertising sales or behavioral advertising, and does not collect an advertising ID. In-app product analytics (Firebase Analytics) and crash/error diagnostics (Sentry) operate only with your explicit consent and are off by default; you may turn this telemetry on or off at any time from the application settings and withdraw the consent you have given. Because these services are located abroad, if you enable telemetry, the relevant technical data may be transferred abroad with the appropriate safeguards prescribed by the legislation. Sentry crash/error data is processed in the European Union (Germany) region; Firebase Analytics data is processed on Google's infrastructure.

7. Retention and Deletion

Personal data is retained for the period necessary for the purpose for which it is processed and for the periods prescribed in the relevant legislation; upon the expiry of these periods, it is deleted, destroyed, or anonymized. Account data is retained for as long as the service relationship continues. Subscription records may be retained for the period prescribed by the relevant financial and tax legislation (currently ten years). Consent records may be kept for a reasonable period from the withdrawal of consent or the closure of the account, within the framework of the burden of proof. Sync data may be kept for as long as the Sync feature is active or until your deletion request is finalized. Disabling the Sync feature stops new data transfers; you may request the deletion of your existing data in the cloud via destek@vaktim.app.

8. Your Rights

You may submit your requests under Article 11 of the KVKK (including obtaining information, rectification, deletion, withdrawal of the consent you have given to processing/transfer, and objection) to destek@vaktim.app. For details of your rights and the application procedure, please refer to the Disclosure Notice (KVKK). In the event that your application is rejected, the response is found insufficient, or no response is given within the applicable period, you have the right to file a complaint with the Personal Data Protection Board.

© 2026 Vaktim. All rights reserved.