Most of what you do in Tahajjud+ stays on your device. The few things that don't are listed below, explicitly.
These are stored only in local app storage on your phone and are never sent to any server unless you explicitly enable cloud sync:
If you choose to sign in with Apple ID or Google, the following sync to Google Firestore across your devices:
Only you can read your private entries. Firestore security rules enforce this at the server level — even our team cannot read what you write. Sign out at any time to stop syncing.
Letters to Allah are not synced to the cloud by default — they remain on your device.
If you sign in with Apple, we receive an opaque Apple user identifier and (only if you choose to share it) your name. With Google sign-in we receive your email address and display name. We use these only to authenticate you across devices — they are never shown to anyone else and never used for marketing.
Some features are intentionally public when you opt in:
If you tap "Publish" on the Dua Wall, your dua text appears anonymously to other users, along with an optional self-reported country flag if you've set one. We store your Firebase user ID server-side to enforce rate limits and respond to reports — but it is never displayed alongside the dua.
When you tap Ameen or Pray for on a community dua, we record an idempotency marker (your user ID + the dua ID) in Firestore so the count can't be inflated. This marker is not shown to anyone. You can undo an Ameen or Pray, which deletes your marker.
If you tap Report on a dua, we store the report (your user ID + the dua ID + auto-hide threshold) so moderators can review. Reporters are never disclosed to the author.
If you reply to a dua or a Tahajjud Story, your reply text, the name you choose to show (or "Anonymous"), and an optional country flag are visible to everyone who views that thread. We store your Firebase user ID server-side to enforce spacing between replies and to respond to reports — it is never displayed. If the original author hearts your reply, that's shown as a small badge; no account information is disclosed by this.
The Leaderboard is entirely opt-in — nobody appears on it unless they choose a nickname and tap Join. If you join, your nickname, an optional self-reported country (shown as a flag), and your dhikr, Qur'an-reading, and Tahajjud counts become publicly visible and ranked against other participants, both weekly and all-time, worldwide or filtered by country. Your real name, account, or any other app content is never shown alongside your leaderboard entry. Leaving the Leaderboard deletes your entry entirely — nothing lingers.
The app may occasionally show you a local notification when your own rank crosses a milestone (like reaching the Top 10). This is calculated entirely on your device from your own data and involves no additional data collection or transmission.
If you tap "I'm praying now" on the Global Map, a single anonymous dot appears at your approximate city level. We store only a rounded latitude/longitude (imprecise enough to cover a several-kilometre radius) and a UTC timestamp — no user ID, name, or precise coordinates are stored. The dot disappears automatically after 24 hours and cannot be traced back to you.
If you choose to also pin a published dua to the map (a separate opt-in step when publishing), that same rounded, city-level location is shown alongside the dua's pin for 24 hours, tappable by other users — still with no name or account information attached.
Stories you submit through "Share Your Story" go to a moderation queue. If approved, they appear in the community feed under whatever author name you entered ("Anonymous", a first name, etc.) — never your account information.
The Mosque Timetable feature lets you photograph your mosque's printed prayer schedule so the app can use those times instead of the calculated ones.
The photo is sent to Anthropic's Claude API for text extraction — this is the only time an image leaves your device in this feature.
The extracted times are saved locally on your device. You can remove them at any time in Settings → Prayer Times → Mosque Timetable.
You can optionally protect your private writings (Letters to Allah, the Night Journal) with biometric authentication. When enabled, iOS prompts you for Face ID or Touch ID before opening these screens.
The biometric match happens entirely inside iOS's Secure Enclave. We never receive your fingerprint or face data — we only receive a boolean "yes/no" from the operating system.
Tahajjud+ uses push notifications for:
You can disable any notification in iOS Settings → Tahajjud+ → Notifications.
If you enable Bedtime Intelligence in Settings, we read your past 14 days of sleep duration from Apple Health to suggest an optimal bedtime for Tahajjud.
This data is processed entirely on your device. Your raw sleep timestamps are never transmitted to our servers, to any analytics service, or to anyone. Computation happens in the app; the result (a suggested bedtime) is shown only to you.
We request location access to calculate accurate prayer times and Qibla direction for your area. Your coordinates are processed on your device. We do not transmit your location to our servers.
You can disable location at any time in iOS Settings → Tahajjud+ → Location. The app will then ask you to set a manual location.
When the app crashes, we send anonymized crash details to Sentry so we can fix the bug. This includes:
We explicitly do NOT send: the content of your journal entries, letters, dua text, or any spiritual content. Our code filters these out before transmission. We also do not send your name, email, or location.
We use PostHog (EU-hosted, Frankfurt) to track anonymous events so we know which features are used and where we can improve. Events include things like: prayer logged, Quran tab opened, tasbeeh session completed, dua played, tab switched, paywall viewed.
We explicitly do NOT track: which specific verses you read, the content of your journal or letters, what duas you publish or search for, your name, email, precise location, or any personal content whatsoever. All events are tied only to a random anonymous identifier — never to your account or identity.
Data is stored in the EU and subject to GDPR. To opt out, email us — we will add your anonymous ID to a deny-list within 5 business days.
Premium subscriptions are processed by Apple's App Store. We never see your credit card or Apple ID password. We use RevenueCat as middleware to verify your subscription status — RevenueCat sees anonymized purchase receipts.
Manage or cancel subscriptions in iOS Settings → Apple ID → Subscriptions.
Quran translations and audio recitations are fetched from public APIs:
These APIs receive HTTP requests for surah numbers. They do not receive any of your personal data.
Uninstall the app, or in iOS Settings → Tahajjud+ → "Delete App."
Settings → Sync & Cloud → "Delete My Account" permanently deletes all your Firestore data and signs you out. We process within 30 days.
Email us at tahajjud.letters@gmail.com — we'll add your anonymous ID to a deny-list. An in-app toggle is on the roadmap.
Email us with the email tied to your account. We respond within 30 days.
Tahajjud+ does not knowingly collect personal information from children under the age of 13. If you believe a child has provided us with personal data, please contact us and we will delete it.
We update this policy when we change what we collect. Major changes are announced in-app with a banner you must acknowledge before continuing. Minor wording changes are posted here with a new "Last updated" date.
Questions, requests, or concerns:
tahajjud.letters@gmail.com