🌙 Noor — Privacy Policy
Last updated: 7 September 2026
Noor is an Islamic companion app (Quran, prayer times, Qibla, Hadith, Islamic calendar, nearby mosques, radio, an AI question feature, and a halal ingredient scanner). We built Noor to keep your data on your device. This policy explains the cases where data leaves it — including the ads that fund the free tier.
What stays on your device
- Prayer times and Qibla are computed on your device, from your coordinates, and those coordinates are not sent to Noor's servers to produce them. Two features do send your position onward, and only while you use them: Nearby Mosques sends your device's coordinates to public OpenStreetMap (Overpass) endpoints to run the "mosques around this point" query, and the city name shown in the app comes from your operating system's own geocoder. We deliberately do not round the coordinates before the mosque query, because rounding was dropping the mosque nearest to you. We do not store your location on our servers, and mosque results are cached on your device.
- Your prayer tracking, bookmarks, favourites, reading progress, scan history, and settings are stored on your device. The list of what you have scanned is kept on your device and is not backed up to an account; the individual scan itself does leave, because looking a product up requires sending its barcode — see AI features and Anti-abuse & aggregate counts. The rest leaves your device only if you sign in: when you have an account, Noor automatically backs your prayer log (and favourites, bookmarks, and settings) up to that account so they survive a reinstall or a new phone — see Accounts & backup below. As a guest with no account, none of that worship data is backed up anywhere.
- Noor works fully in guest mode with no account. In guest mode we collect no names, emails, or contacts. Guest mode still shows ads in the free tier — see Advertising for exactly what the ad network receives.
What Noor collects, at a glance
This list matches Noor's App Store privacy label:
- Name and email address — only if you create an account (Sign in with Apple can hide your email behind Apple's private relay).
- User ID — the account identifier, and an app-generated random identifier used to rate-limit the free AI features.
- Worship content and other user content — prayer log, favourites, bookmarks, settings; backed up to your account automatically once you sign in, and not backed up at all for a guest with no account. Because prayer logs reflect religious practice, we treat them as sensitive data (see Accounts & backup).
- AI questions and scan photos — the question you type into Ask Noor, and the ingredient-label photo you take in the halal scanner, are sent to be answered (see AI features).
- Purchases and product interaction — whether you own Noor Plus or the ad-free purchase, and basic in-app interaction needed to run those features. Product interaction also covers the anonymous daily counts of how often each screen and feature is opened and of how long the app is on screen each day, described under Anti-abuse & aggregate counts; those counts are not linked to you and are not used for tracking.
- Device identifier, coarse location, and advertising data — handled by the ad network in the free tier only (see Advertising). The coarse location there is derived by Google from your IP address. Noor's own servers do not receive or store your coordinates; the one place your coordinates leave the device is the mosque search described above, which sends them to public OpenStreetMap endpoints.
- Crash and performance diagnostics — see Diagnostics.
Accounts & backup
Having an account is optional — in guest mode none of your worship data is backed up anywhere. (Guest mode is not offline mode: ads, the halal scanner, Ask Noor, audio and the mosque search still reach the internet when you use them, as described throughout this policy.) An account exists so your data survives changing or reinstalling your phone:
- Guest, no account: your worship data — including your prayer log — stays on your device. It is not uploaded, and it is lost if you delete the app, because there is no account to hold a backup.
- Signed in (with Apple, or an email + password): Noor automatically backs up your prayer log, favourites, bookmarks, and settings to your account and keeps them in step across your devices. There is no separate switch to turn on — signing in is what turns backup on, so you don't silently lose a year of prayers when you move phones. We tell you this in a clear one-time notice when you first sign in.
On a new or reinstalled device, signing in restores your backed-up data automatically, and it merges — anything you have already recorded on the new device is kept rather than overwritten.
What we collect for an account: a user id; your email address if you sign up with email (Sign in with Apple lets you hide it behind Apple's private relay); and the backed-up data listed above. Your coordinates are not uploaded to your account, and your account data is not linked to advertising or used to target ads. Noor embeds no third-party analytics or attribution SDKs — no analytics company receives your usage from Noor. The only third-party SDKs in the app are the ad network (free tier only), the subscription-state provider, and crash reporting, each described in its own section below. To know which parts of the app are worth improving, Noor counts in aggregate how many times each screen and each feature is opened, and how long the app is on screen in total each day: plain daily numbers, with no user id, no account link and no device id, exactly like the scan counter described below. It does not record what you read or what you pray — no surah, no dhikr, no station, no note, and nothing that could be traced back to you. It also counts how visits end — which screen the visit ended on, roughly how far into setting Noor up this phone had got, and whether Noor was opened again within a week — as plain totals, so we can see what we are getting wrong before people give up on the app; and it labels those particular totals — together with the count of first launches, the count of times the subscription screen was shown, the count of barcode scans, and the count of barcode scans that found nothing — with the country your phone is set to (its region setting, not your location). It does count, in the same aggregate way, which named part of a screen was tapped (for example “the quick-actions grid on the Home screen”) and which screen was opened from which — from a fixed list of region names built into the app, never a position on your screen and never what the region contained. See Anti-abuse & aggregate counts below, and Diagnostics for crash reporting. The free tier does show ads, which are described in full under Advertising.
How it's protected: account data is stored with our database provider (Supabase), isolated per account by row-level security so only you can read it, and encrypted in transit and at rest.
Your control & retention: signing out stops this device from backing up any further; your existing backup stays until you remove it. You can permanently delete your account and all its server data from inside the app (Account → Delete account & data). We keep backed-up data only until you delete it.
Prayer logs reflect religious practice; we treat them as sensitive data. For a signed-in account we back them up automatically, solely to provide backup and restore, on the basis of the consent you give by signing in after the notice described above. Delete your account at any time to erase them from our servers.
Advertising (free tier)
The free tier of Noor is funded by ads, served by Google AdMob. They appear as a banner on some screens, and as an optional rewarded video you may choose to watch to unlock extra halal scans — a rewarded ad is shown only when you tap to watch one.
- Non-personalized by default. Every ad request Noor makes is marked non-personalized unless you have explicitly allowed tracking. Non-personalized ads are chosen from general context, not from a profile of you.
- Personalized ads only with your consent. On iOS you will see Apple's App Tracking Transparency prompt, and, where required by law, Google's consent (UMP) form. Only if you grant permission do ads become personalized and use your device's advertising identifier (IDFA). Declining changes nothing else in the app, and you can change your mind at any time in iOS Settings → Privacy & Security → Tracking.
- What the ad network receives: your device's advertising identifier (only with your consent), your IP address — from which Google derives an approximate, coarse location — and ad interaction data such as ad impressions, taps, and rewarded-video completions. Noor passes no location coordinates and no keywords drawn from your worship data into an ad request.
- Your worship data is not used for ad targeting. Your prayer log, bookmarks, Quran reading, AI questions, and scan history are not shared with an ad network and are not used to select an ad. Ads are limited to content rated no higher than Google's "PG" — parental guidance — and never to "T" (teen) or "MA" (mature) advertising, and Noor is not directed to children.
- We do not sell your personal data and we operate no ad exchange, data broker relationship, or cross-app profile of our own.
- Measuring our own ad campaigns, in aggregate. When we advertise Noor itself, we measure how those campaigns performed using Apple's privacy-preserving attribution, which is built into iOS. Once per install, the app asks iOS for an opaque attribution token and sends it to our server, which exchanges it with Apple for the campaign facts of that install. That token is not your advertising identifier and not a device id, it requires no tracking permission, and we do not store or log it. From Apple's reply we keep two things — which of our campaigns it was, and whether it was a first install — and add 1 to a weekly total. Beyond that opaque token, which we neither store nor log, no identifier reaches us — not your advertising identifier, not a device id, not an account link. No per-install record is kept, so what we hold is a count, and the result cannot be linked to you or to any other person, or joined to anything you do in Noor.
- You can remove ads. Noor Plus, or the one-time ad-free purchase, removes the banner ads — when you own either, the banner is not even requested, so no ad request is made for it.
Google's own handling of ad data is governed by its policies — see Google Privacy & Terms and How Google uses information from apps that use its services.
Noor Plus & purchases
Subscriptions and the one-time ad-free purchase are processed by Apple through the App Store, and our subscription state is managed with RevenueCat. Your card details are handled by Apple and are not shown to or stored by us; we are told only whether an entitlement (Noor Plus / ad-free) is active. Purchases are attached to an anonymous purchase id, not to your worship data.
AI features: the Photo halal scan & Ask Noor
If you use the Photo mode of the halal scanner, the photo you take of an ingredient label is sent to our server and then to our AI provider (OpenRouter, which routes to Google Gemini) to read the ingredients and return a screening result. The image is processed to generate the result and is not stored by us; the resulting product verdict may be cached against the product's barcode so the next person does not need to scan it again. If you are signed in, the request carries your account token so the scan counts against your allowance, and our server records one anti-abuse row holding that identifier (or, for a guest, your purchase id or IP address) and the fact that an AI scan happened — not the photo and not the product. Do not photograph anything private.
After a Photo scan of a barcode we could not answer, Noor offers to add that reading to the shared product database. If you do, what is stored is: the barcode, the ingredient list as it was read from the label, your phone's own region setting as one of twelve country buckets (not your location — no GPS is read and nothing is worked out from your internet address), the first three digits of the barcode, which name the numbering organisation that issued it and say nothing about the product, and the verdict our rules engine derived from that text, with its reasons. The photograph itself is not stored — there is no image field on that path and no column that could hold one. Nothing identifies you: no account, no email, no device id, no IP address, no location and no scan history is stored with it, and the row is judged only on the label it carries. A Noor administrator reviews the reading, and if they approve it, it becomes the answer other people see when they scan that barcode. Because nothing links the row to you, it stays in the shared database indefinitely and cannot afterwards be found or withdrawn on your behalf — so please only send readings of ordinary retail packaging.
If you use Ask Noor (the AI question feature), the question you type is sent to our server together with the source passages Noor retrieved on your device, and on to the same AI provider so the answer can be written and checked against those sources. We send an app-generated random identifier with the request to enforce the free monthly limit. Your question text and the answer are not written to our logs — we keep only counters (how many requests, tokens, and refusals) with no user content and no identifier attached.
The Barcode and Text modes of the scanner do not send your photos to us.
Anti-abuse & aggregate counts
To keep the free halal scanner and Ask Noor running for everyone, our server keeps a few minimal, non-identifying records — none of which is analytics, advertising, or profiling:
- Aggregate scan count. We increment a single daily number of how many halal scans happen in total (for example, "scans today"). That counter carries no user id, no account link, no device id, and no record of what you scanned — it is just a number. Separately, each AI photo scan writes one anti-abuse row holding an identifier (your account id, your anonymous purchase id, or your IP address) and the scan type. It records that a scan happened, not what you scanned.
- Aggregate screen and feature counts. So we know which parts of Noor are used and which are dead weight, the app keeps a small tally on your device — "the Quran hub was opened 3 times, the radio was played once" — and sends the totals to our own server about once a day. What is stored is literally a table of (name, date, hour, phone type, country, number) — where “phone type” is only the word iPhone or Android, so we can tell whether a change helped on one and not the other. The names come from a fixed list built into the app and re-checked on the server, so a name can only be a screen, a feature, or one of the two time totals described in the next bullet — not a surah, an āyah, a dhikr, a radio station, a product, a question, or anything you typed. The phone type comes from a list of exactly two words, checked the same way, so it can never become your phone’s model, its operating-system version, or anything else about your device. The country is your phone’s own region setting — the country you picked when you set the phone up. It is not your location: no GPS is read and no map service is asked, and it is not worked out from your internet address either. It is matched against a fixed list of eleven country codes built into the app and re-checked on the server — Türkiye, Indonesia, Malaysia, Pakistan, India, Egypt, Saudi Arabia, the United Arab Emirates, Morocco, Iraq and the United States — and if your country is not on that list, or your phone does not say, the word sent is simply “other”. There is exactly one exception, and it happens once. On the single occasion Noor reports your first launch, it sends your country as your phone has it set rather than reduced to that list of eleven, so that we can see which countries people are downloading Noor in — including the Gulf countries that were previously all recorded as “other”. That is the only count that keeps it: every other count you ever send, on every other day, carries the eleven-country list exactly as before, and our server reduces anything else to “other” before storing it, whatever your phone said. And it is attached only to the visit-ending counts described in the next bullet and to four further counts — the count of first launches, the count of times the Noor Plus subscription screen was shown, the count of barcode scans, and the count of barcode scans that found no product — so we can see which countries Noor is worth paying for in, and which countries we are failing to answer. The last two are plain totals of scans and of scans that came back empty, kept in the same country so that “how often do we fail to answer here” can be worked out at all: neither of them carries the barcode, the product, or anything you scanned. It is never attached to what you read, played or prayed. For two of these counts — the count of first launches and the count of app openings — we also keep the hour of the day, as one of 24 whole-hour buckets in UTC, so we can see when in the day people arrive and when Noor is busiest. The hour is kept only where the country is one of the eleven above, or where your phone did not say: a first launch from anywhere else is kept by date alone, with no hour at all, so that a count from a country where Noor has very few users can never be narrowed to an hour as well. It is a whole hour and nothing finer: no minutes, no seconds, and no clock time attached to anything you did. Every other count keeps the date alone, and which two counts may carry an hour is a fixed list of two names built into the app, re-checked on the server, and enforced by the database itself. There is no user id, no account link, no device id, and no session record, and we do not keep the IP address of the request. Because there is no identifier of any kind, these numbers cannot be traced back to you, joined to your account, or used to build a profile, and they are not used for advertising. They stay on our own infrastructure; no analytics company receives them.
- Aggregate time in the app. Two further numbers go into that same (name, date, phone type, country, number) table: how many times Noor was brought to the screen that day, and how many seconds in total it spent on screen. Dividing one by the other tells us the average length of a visit, which is how we know whether a change made Noor more useful or merely more confusing. Both are daily totals added up on your device before anything is sent: no individual visit's start, end or length ever leaves your phone, so there is no record of when you use Noor — only how much, on which date, added to everyone else's. As with the counts above there is no user id, no account link and no device id, and both totals are capped on the device, so a phone with a wrong clock cannot report more than a day.
- Aggregate touch regions and screen order. So we know which parts of a screen are worth their place and which screens should sit next to each other, the same daily tally also counts which named region of a screen was tapped and which screen was opened from which — for example “the quick-actions grid, 41 times today” or “Home to the Qur’an, 118 times today”. The region names come from the same fixed list built into the app and re-checked on the server: a region is named for its role on the screen (“the play control”, “a list row”), never for what it contained, so a name can never be a surah, an āyah, a radio station, a product, or anything you typed. We do not record where on the screen you touched — no coordinates, no pixel positions, no gesture paths, ever. Only one step of screen order is counted, as a total (“Home to the Qur’an”) added to everyone else’s; no path through the app, and no record of any individual visit, ever leaves your phone. As with every other count above there is no user id, no account link and no device id.
- Aggregate visit endings. Most people who stop using an app simply delete it, and Apple never tells us who — so to learn what we are getting wrong, the same daily tally counts how visits end. When a visit ends, the app adds one to five totals: which screen the visit ended on — the one last on the display — how far into setting Noor up this phone had got (whether it had finished the introduction, whether prayer times were working, whether alerts were on), how old the installation is and which visit of its life this was — both as broad bands, never an exact date or number — and whether anything had gone wrong during it. Then, if Noor is opened again within a week, it adds one to a matching “came back” total. Subtracting the second from the first tells us how many visits that ended in a given way were never followed by another one, which is the closest anyone can honestly get to “why did people stop” without following individuals around. And that is the point: nothing follows an individual. These are totals added to everyone else’s, on a date, with no user id, no account link, no device id and no record of any single visit — no start time, no end time, no order, no path, and nothing that says which person any of it came from.
- Free-tier limits on the AI features. Ask Noor and the AI scan have a free monthly allowance. To count it we use the app-generated random identifier described above, which is tied to your app install — not to your name, account, or device hardware.
- Guest rate limit. If you use these features without signing in, we apply a per-day limit per network address to stop automated abuse of the free AI service. This uses a short-lived daily counter keyed to your IP address, used only to enforce that limit — not to identify you, track you across apps, or build a profile. Signed-in users are identified by their account token instead, and this IP counter does not apply to them.
Diagnostics (crashes & performance)
So that crashes can be fixed, Noor can report crash and performance diagnostics to Sentry. These reports contain the technical details of the failure — the error, a stack trace, the app version, and the device model and OS version. They are configured to carry no personally identifying request data, no screenshots, and no view hierarchy: the IP address is blanked, any signed-in user record is removed, and a scrubber strips fields naming your location, the product you scanned, or what you were reading before the report is sent. We do not attach your Quran reading, prayer log, questions or scans to a report; because a crash report captures the technical state at the moment of failure, we cannot promise that no fragment of what was on screen is ever included, which is why the scrubbing above runs on every report.
Promotional cards (our own, not ads)
Separately from the AdMob ads described above, Noor may occasionally show a promotional card inside the app (for example, highlighting a Noor feature or a seasonal reminder). These cards are authored by Noor's owner and delivered from our own server. They involve no ad network, no auction, no tracking, and no profiling. Showing a card requires no personal data from you and does not report back who saw it.
Third-party content you connect to directly
Noor streams and fetches Islamic content directly from third-party providers, so your device's IP address is visible to them when you use those features:
- Quran translations & tafsir — the Quran API (jsDelivr), Quran.com; recitation audio — everyayah.com, mp3quran.net and archive.org, or Noor's own storage when we serve the recitation ourselves. The Arabic Quran text itself is bundled inside the app and read offline (no network request).
- Reciters & radio — mp3quran.net, archive.org, Radio Browser, and the broadcasters' streams
- Hadith — the fawazahmed0 Hadith API (jsDelivr)
- Nearby mosques — OpenStreetMap / Overpass (public mirrors, queried in parallel so one slow mirror does not mean "no mosques"). This is the one feature that sends your position off the device. It sends your device's coordinates as they are — we do not round them, because rounding was dropping the mosque nearest to you — and it is used only to run the "mosques around this point" query, with no account or device identifier attached.
- Barcode lookups — Open Food Facts
- Ads in the free tier — Google AdMob (see Advertising)
We do not control these providers' own data practices.
Who controls your data & your legal rights (UAE PDPL & GDPR)
Data controller: Noor is operated by the Noor team. For any privacy request or question, contact noorislamicapplication@gmail.com.
Legal bases we rely on: your consent for the optional account and for backing your data up to it — consent you give by signing in after the clear one-time notice that signing in backs up your prayer log, and which you can withdraw by signing out or deleting your account; our legitimate interest in preventing abuse of the free AI services (the guest rate limit and aggregate count above) and in reporting crashes so the app can be fixed; performing the service you request when you run a photo scan or ask a question; and, for advertising, your consent for personalized ads and any tracking identifier (granted or refused through the App Tracking Transparency and Google consent prompts, and withdrawable at any time in iOS Settings), with non-personalized ads shown on the basis of our legitimate interest in funding the free tier. You can also remove ads entirely with Noor Plus or the ad-free purchase.
Sensitive data: your prayer logs reflect religious practice. We treat them as sensitive and process them only for a signed-in account, solely to back up and restore them, on the basis of the consent you give by signing in after a clear one-time notice that this backup happens. As a guest they are not backed up and stay on your device. You can withdraw at any time by signing out (which stops further backup) or deleting your account (which erases the backup from our servers).
Under the UAE Personal Data Protection Law (Federal Decree-Law No. 45 of 2021) and, for users in the EU/EEA and UK, the GDPR, you have the right to:
- Access the personal data we hold about you;
- Rectify inaccurate data (e.g. your display name or email);
- Delete your account and all its server data — available directly in the app (Account → Delete account & data), or by emailing us;
- Portability / export — request a copy of your synced data in a portable format;
- Withdraw consent at any time — sign out to stop further backup on a device, or delete your account to erase the backup from our servers;
- Object or restrict certain processing, and lodge a complaint with your data-protection authority (in the UAE, the UAE Data Office).
To exercise any of these rights, email noorislamicapplication@gmail.com. Because guest use involves no account, most rights apply only once you have signed in and there is data linked to you.
Children
Noor does not knowingly collect personal information from children. No account or personal data is required to use it.
Changes
We may update this policy; material changes will be reflected on this page with a new date.
Contact
Questions? Email noorislamicapplication@gmail.com.
Noor ·
The app ·
FAQ ·
Terms ·
Support