🌙 Noor — Privacy Policy

Last updated: 7 September 2026

Noor is an Islamic companion app (Quran, prayer times, Qibla, Hadith, Islamic calendar, nearby mosques, radio, an AI question feature, and a halal ingredient scanner). We built Noor to keep your data on your device. This policy explains the cases where data leaves it — including the ads that fund the free tier.

What stays on your device

What Noor collects, at a glance

This list matches Noor's App Store privacy label:

Accounts & backup

Having an account is optional — in guest mode none of your worship data is backed up anywhere. (Guest mode is not offline mode: ads, the halal scanner, Ask Noor, audio and the mosque search still reach the internet when you use them, as described throughout this policy.) An account exists so your data survives changing or reinstalling your phone:

On a new or reinstalled device, signing in restores your backed-up data automatically, and it merges — anything you have already recorded on the new device is kept rather than overwritten.

What we collect for an account: a user id; your email address if you sign up with email (Sign in with Apple lets you hide it behind Apple's private relay); and the backed-up data listed above. Your coordinates are not uploaded to your account, and your account data is not linked to advertising or used to target ads. Noor embeds no third-party analytics or attribution SDKs — no analytics company receives your usage from Noor. The only third-party SDKs in the app are the ad network (free tier only), the subscription-state provider, and crash reporting, each described in its own section below. To know which parts of the app are worth improving, Noor counts in aggregate how many times each screen and each feature is opened, and how long the app is on screen in total each day: plain daily numbers, with no user id, no account link and no device id, exactly like the scan counter described below. It does not record what you read or what you pray — no surah, no dhikr, no station, no note, and nothing that could be traced back to you. It also counts how visits end — which screen the visit ended on, roughly how far into setting Noor up this phone had got, and whether Noor was opened again within a week — as plain totals, so we can see what we are getting wrong before people give up on the app; and it labels those particular totals — together with the count of first launches, the count of times the subscription screen was shown, the count of barcode scans, and the count of barcode scans that found nothing — with the country your phone is set to (its region setting, not your location). It does count, in the same aggregate way, which named part of a screen was tapped (for example “the quick-actions grid on the Home screen”) and which screen was opened from which — from a fixed list of region names built into the app, never a position on your screen and never what the region contained. See Anti-abuse & aggregate counts below, and Diagnostics for crash reporting. The free tier does show ads, which are described in full under Advertising.

How it's protected: account data is stored with our database provider (Supabase), isolated per account by row-level security so only you can read it, and encrypted in transit and at rest.

Your control & retention: signing out stops this device from backing up any further; your existing backup stays until you remove it. You can permanently delete your account and all its server data from inside the app (Account → Delete account & data). We keep backed-up data only until you delete it.

Prayer logs reflect religious practice; we treat them as sensitive data. For a signed-in account we back them up automatically, solely to provide backup and restore, on the basis of the consent you give by signing in after the notice described above. Delete your account at any time to erase them from our servers.

Advertising (free tier)

The free tier of Noor is funded by ads, served by Google AdMob. They appear as a banner on some screens, and as an optional rewarded video you may choose to watch to unlock extra halal scans — a rewarded ad is shown only when you tap to watch one.

Google's own handling of ad data is governed by its policies — see Google Privacy & Terms and How Google uses information from apps that use its services.

Noor Plus & purchases

Subscriptions and the one-time ad-free purchase are processed by Apple through the App Store, and our subscription state is managed with RevenueCat. Your card details are handled by Apple and are not shown to or stored by us; we are told only whether an entitlement (Noor Plus / ad-free) is active. Purchases are attached to an anonymous purchase id, not to your worship data.

AI features: the Photo halal scan & Ask Noor

If you use the Photo mode of the halal scanner, the photo you take of an ingredient label is sent to our server and then to our AI provider (OpenRouter, which routes to Google Gemini) to read the ingredients and return a screening result. The image is processed to generate the result and is not stored by us; the resulting product verdict may be cached against the product's barcode so the next person does not need to scan it again. If you are signed in, the request carries your account token so the scan counts against your allowance, and our server records one anti-abuse row holding that identifier (or, for a guest, your purchase id or IP address) and the fact that an AI scan happened — not the photo and not the product. Do not photograph anything private.

After a Photo scan of a barcode we could not answer, Noor offers to add that reading to the shared product database. If you do, what is stored is: the barcode, the ingredient list as it was read from the label, your phone's own region setting as one of twelve country buckets (not your location — no GPS is read and nothing is worked out from your internet address), the first three digits of the barcode, which name the numbering organisation that issued it and say nothing about the product, and the verdict our rules engine derived from that text, with its reasons. The photograph itself is not stored — there is no image field on that path and no column that could hold one. Nothing identifies you: no account, no email, no device id, no IP address, no location and no scan history is stored with it, and the row is judged only on the label it carries. A Noor administrator reviews the reading, and if they approve it, it becomes the answer other people see when they scan that barcode. Because nothing links the row to you, it stays in the shared database indefinitely and cannot afterwards be found or withdrawn on your behalf — so please only send readings of ordinary retail packaging.

If you use Ask Noor (the AI question feature), the question you type is sent to our server together with the source passages Noor retrieved on your device, and on to the same AI provider so the answer can be written and checked against those sources. We send an app-generated random identifier with the request to enforce the free monthly limit. Your question text and the answer are not written to our logs — we keep only counters (how many requests, tokens, and refusals) with no user content and no identifier attached.

The Barcode and Text modes of the scanner do not send your photos to us.

Anti-abuse & aggregate counts

To keep the free halal scanner and Ask Noor running for everyone, our server keeps a few minimal, non-identifying records — none of which is analytics, advertising, or profiling:

Diagnostics (crashes & performance)

So that crashes can be fixed, Noor can report crash and performance diagnostics to Sentry. These reports contain the technical details of the failure — the error, a stack trace, the app version, and the device model and OS version. They are configured to carry no personally identifying request data, no screenshots, and no view hierarchy: the IP address is blanked, any signed-in user record is removed, and a scrubber strips fields naming your location, the product you scanned, or what you were reading before the report is sent. We do not attach your Quran reading, prayer log, questions or scans to a report; because a crash report captures the technical state at the moment of failure, we cannot promise that no fragment of what was on screen is ever included, which is why the scrubbing above runs on every report.

Promotional cards (our own, not ads)

Separately from the AdMob ads described above, Noor may occasionally show a promotional card inside the app (for example, highlighting a Noor feature or a seasonal reminder). These cards are authored by Noor's owner and delivered from our own server. They involve no ad network, no auction, no tracking, and no profiling. Showing a card requires no personal data from you and does not report back who saw it.

Third-party content you connect to directly

Noor streams and fetches Islamic content directly from third-party providers, so your device's IP address is visible to them when you use those features:

We do not control these providers' own data practices.

Who controls your data & your legal rights (UAE PDPL & GDPR)

Data controller: Noor is operated by the Noor team. For any privacy request or question, contact noorislamicapplication@gmail.com.

Legal bases we rely on: your consent for the optional account and for backing your data up to it — consent you give by signing in after the clear one-time notice that signing in backs up your prayer log, and which you can withdraw by signing out or deleting your account; our legitimate interest in preventing abuse of the free AI services (the guest rate limit and aggregate count above) and in reporting crashes so the app can be fixed; performing the service you request when you run a photo scan or ask a question; and, for advertising, your consent for personalized ads and any tracking identifier (granted or refused through the App Tracking Transparency and Google consent prompts, and withdrawable at any time in iOS Settings), with non-personalized ads shown on the basis of our legitimate interest in funding the free tier. You can also remove ads entirely with Noor Plus or the ad-free purchase.

Sensitive data: your prayer logs reflect religious practice. We treat them as sensitive and process them only for a signed-in account, solely to back up and restore them, on the basis of the consent you give by signing in after a clear one-time notice that this backup happens. As a guest they are not backed up and stay on your device. You can withdraw at any time by signing out (which stops further backup) or deleting your account (which erases the backup from our servers).

Under the UAE Personal Data Protection Law (Federal Decree-Law No. 45 of 2021) and, for users in the EU/EEA and UK, the GDPR, you have the right to:

To exercise any of these rights, email noorislamicapplication@gmail.com. Because guest use involves no account, most rights apply only once you have signed in and there is data linked to you.

Children

Noor does not knowingly collect personal information from children. No account or personal data is required to use it.

Changes

We may update this policy; material changes will be reflected on this page with a new date.

Contact

Questions? Email noorislamicapplication@gmail.com.

Noor · The app · FAQ · Terms · Support