Privacy Policy
Effective 27 August 2026 · Version 1.0 · App version 1.0
Revak does not collect data about you. There is no account, no advertising, no analytics and no third-party tracker. This page describes what the app actually does, line by line — the engineering truth, not marketing copy.
In one sentence: your prayer log, dhikr counts, favourites and settings stay on your device. Nothing is sent to the developer. The only thing that leaves your device is a latitude and longitude sent to a public prayer-time API, plus the ordinary operating-system calls your device makes to Apple (Maps, iCloud, the App Store).
1. Who is responsible
The data controller under the GDPR, and the veri sorumlusu under Turkey's KVKK (Law No. 6698), is:
Cafer Karakaya — developer of Revak (independent developer)
Email: mihrab.feedback@icloud.com
App bundle identifier: com.caferkarakaya.mihrab
Revak has no server. The developer operates no database, keeps no user records and writes no logs about you.
2. What we do not collect
None of the following exists in the app. This is not a promise but a fact at the
code level, declared to Apple in the PrivacyInfo.xcprivacy manifest as
NSPrivacyTracking = false with an empty
NSPrivacyCollectedDataTypes list:
- Advertising networks, the advertising identifier (IDFA), any tracking prompt
- Analytics or product-measurement SDKs (Firebase, Amplitude, Mixpanel, etc.)
- Crash reporting services (Crashlytics, etc.)
- Attribution or conversion tracking (AppsFlyer, Adjust, etc.)
- Social SDKs, identity providers, single sign-on
- User accounts, email sign-up, phone numbers, profiles
- Contacts, photos, calendar, health data, microphone access
- Cookies, pixels, device fingerprinting
- Sale of data, sharing of data, transfer to data brokers
The app's only third-party dependency is adhan-swift (MIT-licensed, open source). It performs astronomical arithmetic only: it opens no network connection and reads nothing from your device.
3. What is processed, why, and on what legal basis
| Data | Purpose | Where it lives | Legal basis |
|---|---|---|---|
| Location (latitude/longitude) | Prayer times, Qibla bearing, nearby mosques, city name | On device; sent to Aladhan with prayer-time queries | Consent (iOS permission) — GDPR Art. 6(1)(a) |
| Camera feed (AR Qibla) | Overlaying the Qibla arrow on the live view | On screen only, never recorded | Consent (iOS permission) |
| Prayer/fasting log, dhikr counts, favourites, bookmarks | Letting you keep your own record | Device; your own iCloud if you turn sync on | Performance of a contract — Art. 6(1)(b) |
| Settings (method, adhan sound, theme, language, ± minute offsets) | Running the app the way you configured it | Device (App Group) | Performance of a contract |
| Subscription status | Unlocking Revak Plus features | With Apple; on device only as an on/off flag | Performance of a contract |
| Notification permission | Prayer reminders and the adhan alarm | Device | Consent (iOS permission) |
3.1 Location
The app requests when-in-use location only; it never tracks you in the background. If you decline, you can pick a city manually in Settings and the app works fully.
- For prayer times and the city name the requested accuracy is kilometre level, and updates only fire after about 2 km of movement.
- While the Qibla screen is open accuracy temporarily rises to ten metres and drops back when you leave. No screen leaves location running behind it.
- The city name is resolved with Apple's CLGeocoder. That is an operating-system call to Apple, governed by Apple's own privacy policy. The app makes it at most once a minute and never for movement under 3 km.
- Location is never uploaded to a server for storage, and no location history is kept.
3.2 Network: what goes to the Aladhan API
Prayer times are computed on your device first. The app works in airplane mode, with no signal, and during an API outage. The network is used only to reconcile that computation with a published source.
For that reconciliation, the following is sent to api.aladhan.com:
- Latitude and longitude (decimal degrees)
- The date, or a month and year
- Your chosen calculation method and school (for Asr)
No identifier, account, device ID, advertising ID, name, email or cookie is sent with the request. It is anonymous. As with any HTTPS request, Aladhan's server sees the originating IP address; that is a technical property of internet connectivity and is not under the app's control. Aladhan is an independent third party with its own privacy practices.
If you would rather it did not happen: choose a city in Settings instead of using location. Your device's own GPS coordinate is then never used; the request carries the general coordinate of the city you picked. Even in airplane mode, prayer times keep being computed by the on-device engine.
3.3 Nearby mosques
Mosque search uses Apple's MapKit local search; the searched region goes to Apple Maps and is governed by Apple's privacy policy. If you never open that screen, no such request is ever made.
3.4 Camera (AR Qibla)
AR Qibla uses ARKit. The camera feed is displayed on screen only: never recorded, never stored, never uploaded, and never sent to any image-processing service. The session ends when you leave the mode.
3.5 Notifications and alarms
Every reminder is local: scheduled on your device, fired by your device.
There is no push server. The app uses iOS 26's AlarmKit so the adhan can
sound in Silent mode and during Focus — also entirely on device. The app's
remote-notification background mode exists only for iCloud sync's silent
wake signals.
3.6 iCloud sync (optional, off by default)
With Revak Plus, your dhikr sessions, favourite hadiths, khatam progress and prayer/fasting log can be backed up to your own iCloud. This is off by default and is enabled in Settings.
- Data is written to Apple's CloudKit private database
(
iCloud.com.caferkarakaya.mihrab) and to NSUbiquitousKeyValueStore. - The private database belongs to your Apple Account. The developer cannot access, view or download it.
- If your subscription lapses, syncing stops and nothing is deleted — local and iCloud records stay exactly where they are.
- Turning sync off stops further writes. To remove what is already in iCloud, use iOS Settings → Apple Account → iCloud → Revak.
3.7 Purchases
Revak Plus subscriptions and the lifetime purchase run through Apple's StoreKit. Payment details go to Apple; the app never sees or stores card numbers, billing addresses or payment data. It asks Apple only whether a valid entitlement exists on this device and keeps that as an on/off flag in the App Group container. Through App Store Connect the developer sees only Apple's aggregated, anonymised sales reports.
3.8 Apple Watch
The phone-to-watch bridge is WatchConnectivity, and it carries settings, not results: coordinate, calculation method, school, source, per-prayer minute offsets, time zone. The watch recomputes the times itself. The transfer is between your two devices and passes through no server.
3.9 Shared khatam invitations
The shared khatam feature has no server. An invitation is just a short code describing the khatam, which you send yourself over WhatsApp, Messages or any other app. No central system tracks who claimed which juz; each device tracks only its own reading.
4. Sharing and international transfers
The developer does not share, sell or rent your personal data to anyone. The following are not "sharing" but service calls the app needs to function, and may constitute an international transfer under GDPR Chapter V and KVKK Art. 9:
| Recipient | What is sent | When |
|---|---|---|
| Aladhan (aladhan.com) | Latitude, longitude, date, method, school | When online and prayer times refresh |
| Apple — Location/Maps services | City-name lookup, mosque-search region | When a city name is needed; when the Mosques screen opens |
| Apple — iCloud/CloudKit | Only if you enabled sync: your logs and preferences | While sync is on |
| Apple — App Store / StoreKit | The purchase or restore transaction | When you buy or restore |
Calls to Apple are governed by Apple's privacy policy. Information may also be disclosed where legally required by a valid order from a court or public authority — though in practice the developer holds no data about you to disclose.
5. Retention
| Data | Retained | How to delete |
|---|---|---|
| On-device settings, logs, counters, caches | Until you delete them | Deleting the app removes all of it |
| Prayer-time cache (App Group) | About 60 days back, then pruned automatically | Deleting the app |
| Location (last fix held in memory) | Gone when the app quits; no history kept | Automatic |
| Records in iCloud | Until you delete them | iOS Settings → Apple Account → iCloud → Revak |
| Data on the developer's servers | — | There are no such servers |
6. Your rights
Under GDPR Arts. 15–22 and KVKK Art. 11 you have the right to know whether your data is processed, to obtain a copy, to have it corrected, erased or restricted, to data portability, to object to processing, to withdraw consent at any time, and to learn to whom data has been transferred.
In practice: because Revak keeps no server-side copy of your data, you exercise most of these rights directly and without asking anyone: your data is on your device, deleting the app deletes it, and any iCloud copy is under your Apple Account's control. If you still have a request or a question, write to mihrab.feedback@icloud.com and you will get a reply within 30 days.
You can withdraw permissions at any time in iOS Settings → Revak → Location / Camera / Notifications. The related feature switches off; the rest of the app keeps working.
You may lodge a complaint with your national data-protection authority in the EU/EEA or the UK, or with Turkey's Personal Data Protection Authority (kvkk.gov.tr).
7. Children
Revak is rated 4+ and contains no accounts, chat, user-generated content or advertising, so it collects no personal data from children — knowingly or otherwise. Because nothing is collected from any age group, no record exists that would need to be deleted.
8. Security
- All network traffic uses HTTPS.
- On-device data is protected by iOS file protection and app sandboxing, and is covered by device encryption when you have a passcode set.
- Any iCloud copy sits inside Apple's infrastructure behind your Apple Account authentication.
- Because the developer stores nothing, there is nothing at the developer to breach.
9. Changes to this policy
If the app's data behaviour changes, this page is updated and the effective date above is revised. A material change — such as beginning to process a new category of data — will also be announced inside the app. Previous versions of this page can be traced through the project's public repository history.
10. Contact
For any privacy question, request or complaint: mihrab.feedback@icloud.com. See also the Support page.