Privacy Policy
Last updated: August 31, 2026
NoorPause ("we", "our", "the app") is a mindful pause and family screen-time app built around short Islamic reflections, prayer times and Qibla, the Qur'an, and dhikr. This Privacy Policy explains what data we collect, why we collect it, and the choices you have about it.
The service is operated by Khalifa Khalifa, based in Ontario, Canada, who acts as the data controller for the personal data described here. Contact: support@imanlock.com.
1. Data we collect
1.1 Account data
- Email address — used to identify your account. If you sign in with Apple and choose "Hide My Email," we only receive Apple's private relay address.
- Display name — what other family members see if you link accounts. You can edit this any time.
- Apple user identifier — a stable opaque ID Apple gives us when you use Sign in with Apple. Used to match you to your account on subsequent logins. We do not receive your Apple ID password.
- Profile image (optional) — only if you upload one. Profile photos are stored with our hosting provider (Supabase) at a long, randomized web address so the app and your linked family members can display them; the address is not listed or discoverable, but anyone who has the exact link can view the photo, so choose your photo accordingly. Your photo's stored file is deleted when you replace it or delete your account.
Using NoorPause without an account. You can read the Qur'an and see prayer times without creating an account. In that mode we collect none of the account data above and none of the app activity below — there is no account to attach it to. Prayer-time calculation happens on your device, and your location is never sent to our servers (see section 1.5).
1.2 App activity
- Pause schedules you create — time windows, themes, days of the week.
- Pause completions and emergency unlocks — to compute your streak and family overview. This covers every emergency unlock, whether it was used during a pause, to leave a Qur'an reading-goal gate early, or to end an ad-hoc pause. If you type a short reason when using one, that text is stored and, for a linked child, shown to the linked parent.
- Notification preferences — whether reminders are enabled, what time the daily recap fires. Notifications are scheduled locally on your device; we do not use remote push and do not collect push tokens.
- Qur'an reading time — how long you spend reading the Qur'an in the app, so we can show your daily total and reading streak. For a linked child, this daily total is also shown to their parent.
- Qur'an reading goal — if a parent assigns a linked child a daily Qur'an reading goal, we store that goal (a number of minutes) with the family link so the child's app can apply it; the parent can change or remove it at any time. You can also set a daily reading goal for yourself, which is stored with your own account and is yours to change or remove.
- Timezone — your device's timezone identifier, so streaks and daily statistics are counted against your real local day.
- Server logs — like virtually all online services, our servers keep short-lived technical logs (such as IP address, request path, and timestamps) for security and to diagnose failures.
Kept on your device only (never sent to our servers): your custom dhikr entries, your prayer-calculation preferences, your Qur'an recitation recordings (section 1.8), your Hadith Library reading position and bookmarks, your Qur'an reading layout and appearance choices, and everything in section 1.6 below.
1.3 Subscription data
- Subscription status — handled by Apple and RevenueCat (our subscription processor). We do not see your payment card details.
- Feedback & Ideas posts (optional, Premium) — if you post on the feedback board, we store your post's title, details, votes, and review status with your account. Approved posts are visible to other signed-in users without your name, email, or any identifying details — only you and we can see which posts are yours. Votes are likewise never shown to anyone with your identity. The board is not available on child accounts.
1.4 Family accounts
If you create a parent account and link a child, both accounts are stored under our family-controls model. The linked parent can see the child's account details (display name, email address, and profile photo if one was uploaded) together with the child's pause completion and Qur'an reading-time data, as described in section 7. Parents are responsible for obtaining appropriate consent from their child before linking.
1.5 Location (optional)
If you enable Location, NoorPause uses your device's approximate location to calculate accurate prayer times for your city and to point the Qibla compass toward the Kaaba. This happens on your device only — your coordinates are not sent to, or stored on, our servers, and your location is never tracked in the background. You can turn Location off at any time in iOS Settings; prayer times and Qibla simply won't be available until you re-enable it.
1.6 Screen Time and app-blocking data (stays on your device)
App blocking is built on Apple's Screen Time frameworks (Family Controls and Device Activity), which are designed so that this data never reaches us:
- We cannot see which apps you block. When you select apps to shield, iOS gives NoorPause only opaque tokens — Apple deliberately does not reveal app names or identities to us.
- Your app selection and blocking configuration are stored on your device (in the app's protected container) and are never transmitted to our servers.
- We receive no usage data about other apps — not what you use, when, or for how long.
- What our servers do see is only what is described in section 1.2: the pause events inside NoorPause itself (schedules, completions, emergency unlocks).
This is both our policy and a technical guarantee enforced by Apple's frameworks and their developer rules for Screen Time APIs.
1.7 Halal Scanner photos (processed, never stored)
The Halal Scanner lets you photograph a food ingredient label and checks each ingredient against our database of published halal-certifier guidance. When you submit a photo:
- The photo is processed, not kept. It is sent over an encrypted connection to our server and forwarded to Anthropic (the provider of the Claude AI model), which transcribes the printed ingredient list. The photo is handled in memory only — we do not save it on our servers, and it is never added to any library or profile.
- The AI only reads the label. The transcription is matched against our own reviewed rulings database on our server; the AI does not decide halal status. Anthropic processes the photo as our service provider, does not use it to train its models under its commercial API terms, and may retain API inputs briefly for abuse and safety monitoring before deletion under those terms.
- What we store is only a daily counter (your account ID, the date, and how many scans you used) to enforce the daily scan limit fairly, plus an anonymous list of ingredient names our database did not recognize. For each unrecognized ingredient, that list keeps the ingredient name as printed on the label, its normalized form, and how often and when it has been seen — nothing else. It is never linked to your account, your photo, or any individual scan, and we use it solely to research those ingredients and add verified rulings for them to the database.
- Choose photos with care. Please photograph the product label only — avoid including people or personal documents in the frame.
1.8 Qur'an recitation recordings (stay on your device)
The Qur'an reader lets you record yourself reciting so you can listen back and review your memorization. This feature is built to keep your voice private:
- The microphone is used only while you choose to record — recording starts when you tap the microphone button and stops when you tap stop.
- Recordings never leave your device. The audio files, and the timing analysis the app derives from them (where you paused while reciting), are stored only in the app's storage on your phone. They are never uploaded to our servers or to anyone else — the app contains no upload path for them.
- No speech recognition, no transcript. The app does not transcribe or interpret your words; it only measures timing.
- Not visible to parents. A linked parent cannot hear, see, or count a child's recitation recordings.
- You are in control. Delete any recording in the app (My Recitations), or delete the app to remove them all.
2. What we do NOT collect
- We do not access, read, or store the contents of any other apps on your device.
- We do not track your location in the background, store your coordinates on our servers, or share location data with anyone — it is used only momentarily, on your device, to compute prayer times and Qibla when you enable it.
- We do not collect contacts or microphone data. The Qur'an reader's recitation recorder uses the microphone only while you choose to record, and those recordings stay on your device — they are never transmitted to us or anyone else (section 1.8). The only photos that ever leave your device are the optional profile photo you upload and the label photos you choose to submit to the Halal Scanner — the latter are processed transiently and never stored by us (see section 1.7).
- We do not sell your data to third parties.
- We do not use third-party advertising trackers.
3. How we use your data
- To authenticate you and keep you signed in.
- To generate your pause schedule and notifications.
- To compute streaks, completion rates, and the family overview.
- To grant access to premium features after a successful subscription purchase.
- To calculate prayer times and the Qibla direction on your device (only if you enable Location).
- To show your Qur'an reading time and streak, and — for a linked child — to share that daily total with their parent.
- To transcribe ingredient-label photos you submit to the Halal Scanner, return the results, and enforce the daily scan limit.
- To research ingredients our halal database did not recognize (using only the anonymous unrecognized-ingredient list described in section 1.7) so verified rulings can be added for them.
- To improve the app (e.g., diagnose crashes or failed API calls).
4. Third-party services
We use a small number of service providers (processors) to run NoorPause. We do not use advertising networks, analytics SDKs, or data brokers. Each provider has its own privacy policy:
These providers process data only on our instructions to provide their service to us. We may also disclose data if required by law, or to protect the rights, safety, or property of our users or others.
4A. Legal bases (EEA/UK users)
Where the GDPR or UK GDPR applies, we rely on the following legal bases:
- Performance of a contract — account data, schedules, completions, subscription status: everything needed to provide the app you signed up for.
- Legitimate interests — security, fraud prevention, service diagnostics (e.g., short-lived server logs), and improving reliability, balanced against your rights.
- Consent — optional features you switch on, such as Location for prayer times (processed on-device only), the optional profile photo, and each label photo you choose to submit to the Halal Scanner. You can withdraw consent at any time.
- Explicit consent for data revealing religious beliefs — NoorPause is an Islamic practice app, so the activity records stored with your account (for example pause schedules and completions built around Islamic reflections, Qur'an reading time and goals, emergency-unlock records, and your Halal Scanner usage counter) may reveal your religious beliefs, which are special-category data under Article 9 of the GDPR and UK GDPR. We process these records on the basis of your explicit consent (Article 9(2)(a)), which the app asks for in a separate step when you create your account — and, for accounts created before this step existed, the first time you open the app after it was introduced. Your consent is recorded with a timestamp and the policy version you agreed to. We use these records only to provide the features described in this policy — never for advertising or profiling, and never disclosed beyond the processors listed in section 4. For a linked child, the linking parent or guardian can give this consent on the child's behalf when linking; otherwise the child is asked in the same way when they next open the app. You can withdraw consent at any time by deleting your account (Settings → Delete Account) or emailing support@imanlock.com; withdrawal does not affect the lawfulness of processing that already happened. Because these records are inseparable from having an account, withdrawing consent means we can no longer provide the signed-in features — you can still read the Qur'an and see prayer times without an account, in which case none of this data is collected (section 1.1).
- Parental consent — the family features of a child account operate under the consent of the linking parent or guardian (see section 7). Before linking, we hold only the child's basic account data, on the contract basis above, and no family feature operates.
5. Data storage and security
Your data is stored on Supabase (PostgreSQL) in a private database with row-level access controls. All transmission uses HTTPS (TLS 1.2+). Passwords are hashed and never stored in plain text. Apple Sign in tokens are validated server-side and never logged.
6. Your rights
- Access: the app shows you the substance of the data we hold about you (Settings → Profile, Logs, Performance). You can also request a complete copy of your personal data — including anything not shown in the app, such as short-lived server logs — by emailing us; we respond within 30 days.
- Delete: you can delete your account in the app (Settings → scroll to the bottom → Delete Account). Deletion takes effect immediately: your sign-in is permanently revoked and we remove the information that identifies you — your email address, name, Apple identifier, pairing code, and profile photo, including the stored image file — together with the free-text content stored about you, such as emergency-unlock reasons, review notes, and any nickname saved for you. Remaining activity records (for example, counts of completed pauses and daily reading minutes) are kept only in de-identified form, no longer connected to your name, email address, or any other identifying information, and are used solely for aggregate statistics. You can also email us at support@imanlock.com with any deletion request or question.
- Export: contact us and we will export your data in JSON within 30 days.
- Withdraw consent: stop using the app and request deletion at any time.
7. Children's privacy
A child account is a separate sign-in that a parent or legal guardian links to their own NoorPause account by entering the pairing code shown on the child's device. We treat the parent's deliberate act of linking as verifiable parental consent for the family features. A parent or legal guardian must create, or directly supervise the creation of, any account for a child under 13 and should link it promptly; if we learn that a child under 13 has an account that no parent or guardian has linked, we will disable or delete it. Until an account is linked, no family feature operates and no information about the child is visible to anyone else.
A child account is a full NoorPause account, so it involves the same account data (section 1.1) and app activity data (section 1.2) as any other account: the email address and the password or Apple sign-in identifier used to sign the child in, a display name, an optional profile photo if one is uploaded, the device timezone, notification preferences, and the short-lived technical server logs described in section 1.2. In addition, the family features use: the pairing code generated for linking, pause schedules and completions, streaks, daily Qur'an reading time, the daily Qur'an reading goal if their parent assigns one, and any emergency-unlock reason the child types. We collect nothing from a child beyond what sections 1.1, 1.2, and this section describe. The Feedback & Ideas board is not available on child accounts — a child cannot post to it or see it, and no child data is involved in it.
What the linked parent can see about a child: the child's display name and the email address on the child's account (shown so the parent can recognize which account is linked), the child's profile photo if one was uploaded, any nickname the parent sets for the child, pause completions and misses, streaks, completion history, daily Qur'an reading minutes and the reading goal the parent set, and emergency unlocks (including the typed reason). Parents cannot see the contents of a child's other apps, the child's location, the child's recitation recordings, or anything outside the NoorPause features listed here.
- We show no advertising to anyone, including children, and we never sell or share children's data.
- A parent may review a child's data in the app, unlink the child at any time, or request deletion of the child's data at support@imanlock.com.
- We do not require a child to disclose more information than is reasonably necessary to use the features.
If a parent unlinks a child, or the parent's own account is deleted, Family Mode ends for that child: the former parent no longer has access to the child's activity, and the child's account continues as a standalone account under this policy. Unlinking does not by itself delete the child's account or data. A parent may ask us to delete the child's account and data before or when unlinking, and either the parent or the child may request deletion at any time in the app or at support@imanlock.com.
If you believe we have collected information from a child without proper consent, contact us and we will delete it.
8. Data retention
We retain your data for as long as your account is active. When you delete your account, the identifying information and free-text content described in section 6 are removed from live systems immediately; residual copies in encrypted backups are overwritten in the normal backup cycle shortly after. De-identified activity records that can no longer be connected to you may be retained for aggregate statistics. Anonymized aggregate statistics (e.g., total number of pauses completed) may be retained for product analytics. Halal Scanner photos are not retained at all (see section 1.7); daily scan counters are routine account data covered by the rules above. The anonymous unrecognized-ingredient list (section 1.7) contains no personal data and is not linked to any account, so it is unaffected by account deletion; entries are removed once the ingredient has been researched and added to our database.
9. International transfers
Our service providers host data in the United States. When personal data of users in the EEA, UK, Canada, or elsewhere is processed there, we rely on the safeguards our providers offer for international transfers (including data-processing agreements and, where applicable, Standard Contractual Clauses or equivalent mechanisms). Wherever your data is processed, this policy applies to it.
9A. Your regional rights
- EEA & UK (GDPR/UK GDPR): you have the rights of access, rectification, erasure, restriction, portability, and objection, and the right to withdraw consent at any time. You may also lodge a complaint with your local supervisory authority (or the UK ICO).
- California (CCPA/CPRA): we do not sell personal information and do not share it for cross-context behavioural advertising. You have the rights to know, delete, correct, and to non-discrimination for exercising your rights.
- Canada (PIPEDA): you may request access to and correction of your personal information, and may complain to the Office of the Privacy Commissioner of Canada.
- Quebec (Law 25): in addition to your PIPEDA rights, you have rights of access and rectification, the right to withdraw consent, the right to receive computerized personal information we hold about you in a structured, commonly used technological format (data portability), and, where applicable, the right to request that dissemination of your personal information cease. You may complain to the Commission d'accès à l'information du Québec. Your personal information may be stored and processed outside Quebec as described in section 9. Requests go to the person in charge of the protection of personal information named in section 11.
To exercise any right, use the in-app tools (section 6) or email support@imanlock.com; we respond within 30 days and may need to verify your identity first.
10. Changes to this policy
If we make material changes, we will update the "Last updated" date at the top and, where appropriate, notify you in-app. Continued use of NoorPause after a change constitutes acceptance.
11. Contact
For privacy questions, deletion requests, or data exports, email us at support@imanlock.com.
Person in charge of the protection of personal information (Privacy Officer): Khalifa Khalifa, reachable at support@imanlock.com. He is responsible for ensuring compliance with this policy and applicable privacy law, and for handling access, correction, deletion, portability, and complaint requests.
© 2026 NoorPause. All rights reserved.