Last Updated: August 26, 2026
Developed by Code Astra | Email: admin@codeastraa.com
Code Astra ("we", "our", or "us") develops mobile applications and software solutions. This Privacy Policy explains how information is collected, used, disclosed, and protected when you use our Al Quran application ("App") on Google Play.
This policy applies globally and includes specific provisions for users in the European Union (EU/EEA) under the General Data Protection Regulation (GDPR), users in the United Kingdom under UK GDPR, users in California (USA) under the California Consumer Privacy Act (CCPA/CPRA), and users in other jurisdictions with applicable privacy laws.
By installing or using our App, you acknowledge that you have read and agree to the practices described in this Privacy Policy. If you do not agree, please do not install or use the App.
1. Summary — What This App Does Not Do
For clarity, our App:
- Does not display advertisements
- Does not contain subscriptions or in-app purchases
- Does not request or access your location
- Does not request or access your camera, microphone, contacts, or photo library
- Does not require an account, login, or registration
- Does not sell or share your personal information
- Does not maintain user accounts or personal databases on our own servers
Your reading progress, bookmarks, goals, settings, and downloaded content are stored locally on your device only.
2. Information We Collect
2.1 Personal Information
Our App does not require users to create accounts or provide personal information directly. We do not intentionally collect personally identifiable information such as your name, home address, phone number, or email address, unless you voluntarily provide it when contacting us for support.
2.2 Non-Personal & Technical Information
To improve App functionality, performance, and stability, certain non-personal information is collected automatically through integrated Google Firebase services, including:
- Device model and manufacturer
- Operating system version
- Application version
- Language and locale preferences
- Country or region (derived from IP address, not stored as a precise location)
- App usage information and session data (screens viewed, features used, session duration)
- Diagnostic information and crash reports
- Performance metrics (app startup time, screen rendering, network request timing)
- A Firebase installation identifier (an app-scoped identifier used by Firebase services)
This information is collected in an aggregated or pseudonymized manner and is not used to directly identify individual users.
2.3 Data Stored Locally on Your Device
The following information is created and stored only on your device and is never transmitted to us or to any third party:
- Reading position, last-read page, and reading history
- Bookmarks and saved verses
- Daily reading goals and progress statistics
- Reading and display preferences (font size, script, theme, translation selection)
- Selected reciter and playback preferences
- Downloaded recitation audio files and downloaded content
- Daily reminder schedule and notification settings
This data is removed when you clear the App's data or uninstall the App.
2.4 Network Requests
The App connects to the internet to retrieve Quran text, translations, recitation audio, and related content. As with any internet request, the servers providing this content receive standard technical information such as your IP address, device type, and the resource requested. We do not log or retain this information ourselves.
3. Religious Content and Special Category Data
We are aware that under GDPR Article 9, information revealing religious or philosophical beliefs is treated as a special category of personal data.
We do not collect, infer, profile, or share any data about your religious beliefs, practices, or observance. We do not build user profiles, do not use your reading activity for advertising or marketing, and do not share reading, listening, or usage data with any advertising network or data broker. Analytics data is used only in aggregate to understand which App features are used and to improve them.
4. How We Use Information
Information collected through our App may be used to:
- Provide and maintain App functionality
- Deliver Quran text, translations, and audio recitation features
- Improve application performance, stability, and reliability
- Analyze aggregate feature usage to enhance user experience
- Diagnose crashes, fix bugs, and resolve technical issues
- Deliver local reading reminders that you have enabled
- Comply with legal obligations
We do not sell your personal information to third parties. We do not use data for purposes beyond what is disclosed in this Privacy Policy.
5. Legal Basis for Processing (GDPR / UK GDPR)
This section applies to users in the European Union (EU), European Economic Area (EEA), and United Kingdom (UK).
5.1 Consent — Article 6(1)(a) GDPR
We rely on your freely given, specific, informed, and unambiguous consent for:
- Analytics collection via Firebase Analytics
- Delivery of notifications (Android 13 and above requires your explicit permission)
You may withdraw your consent at any time through the App's in-app privacy settings or through your device settings. Withdrawal of consent does not affect the lawfulness of processing that occurred before withdrawal.
5.2 Legitimate Interests — Article 6(1)(f) GDPR
We process limited technical and diagnostic data based on our legitimate interests in:
- Maintaining and improving App stability (crash reporting via Firebase Crashlytics)
- Monitoring App performance metrics (Firebase Performance Monitoring)
We have assessed that these legitimate interests are not overridden by your rights and freedoms. You have the right to object to this processing (see Section 12).
5.3 Legal Obligation — Article 6(1)(c) GDPR
We may process data where required to comply with applicable legal obligations, such as responding to lawful requests from public authorities.
We do not rely on contract performance as a legal basis, as the App contains no paid features or purchases.
6. User Consent & Prominent Disclosure
In compliance with Google Play Developer Program Policies, we obtain your explicit consent before collecting optional analytics data.
Upon first launch of the App, you will be shown a clear in-app consent dialog that:
- Explains what data is collected and why, in plain language
- Is displayed before any optional data collection begins
- Requires an affirmative action (for example, tapping "Accept") to indicate consent
- Does not auto-dismiss or expire as a method of obtaining consent
- Does not interpret navigating away as consent
- Allows you to manage, update, or withdraw consent at any time
For EU/EEA/UK users, analytics collection remains disabled unless and until you provide consent. You may change your preference at any time in the App's privacy settings.
For users in other regions requiring consent (for example, Brazil under LGPD or South Korea under PIPA), equivalent consent mechanisms are applied as required by local law.
7. Notifications and Reminders
The App can send you local reminders to support your daily reading goal. These notifications are scheduled and generated entirely on your device.
- No notification content is sent from our servers, and we do not use a push notification service
- Reminder times and settings are stored locally on your device
- The App re-schedules your reminders after your device restarts, using the RECEIVE_BOOT_COMPLETED permission — this involves no data collection or transmission
- You can disable notifications at any time through the App settings or your device settings
8. App Permissions
We request only the permissions necessary to provide core functionality, in line with Google Play's principle of minimal data access.
| Permission | Purpose |
| INTERNET | Retrieving Quran text, translations, recitation audio, and content downloads |
| ACCESS_NETWORK_STATE | Detecting connectivity so downloads and playback behave correctly offline |
| POST_NOTIFICATIONS | Displaying the local daily reading reminders you enable (Android 13+) |
| RECEIVE_BOOT_COMPLETED | Re-scheduling your local reminders after the device restarts |
The App does not request location, camera, microphone, contacts, SMS, phone state, or external storage permissions.
All permissions can be managed and revoked through your device settings at any time. Declining the notification permission does not affect any other App functionality.
9. Third-Party Services & Data Processors
Our App integrates the following third-party service providers. Each processes data in accordance with its own privacy policy and, where applicable under GDPR, under a Data Processing Agreement (DPA). Where applicable, Google LLC acts as a data processor on our behalf.
| Service | Provider | Purpose | Legal Basis |
| Firebase Analytics | Google LLC | Aggregate usage analytics | Consent |
| Firebase Crashlytics | Google LLC | Crash and error reporting | Legitimate interests |
| Firebase Performance Monitoring | Google LLC | App performance metrics | Legitimate interests |
| Google Play Services | Google LLC | Core Android platform services | Legitimate interests |
| Google Play Asset Delivery | Google LLC | Delivery of Mushaf page image packs | Legitimate interests |
Firebase Analytics may collect device information, session duration, screen views, feature usage statistics, and general geographic region.
Firebase Crashlytics collects device type, OS version, App version, crash logs, stack traces, and application state at the time of a crash.
Firebase Performance Monitoring collects app startup times, network request performance, and screen rendering performance.
Google Play Asset Delivery is used to download the print-edition Mushaf page images packaged with the App. It does not collect personal data beyond standard download telemetry handled by Google Play.
Recitation audio and Quran text content are retrieved from content delivery servers. These servers receive standard request metadata (IP address, user agent, requested file) necessary to serve the content.
Useful links:
- Firebase Privacy Information: https://firebase.google.com/support/privacy
- Google Privacy Policy: https://policies.google.com/privacy
- Google Data Processing Terms (GDPR): https://business.safety.google/controllerterms/
10. Google Play Data Safety Section
In accordance with Google Play Developer Program Policies, we have accurately completed the Data Safety Form for this App in the Google Play Console. The Data Safety section displayed on the App's Play Store listing reflects the data collection, sharing, and security practices described in this Privacy Policy.
The Data Safety section and this Privacy Policy are kept consistent and updated whenever there are material changes to our data practices. We are responsible for the accuracy of the information provided, including data collected by third-party SDKs.
11. International Data Transfers
Google LLC, located at 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA, may process information on servers located outside your country of residence, including in the United States.
11.1 Transfers from the EU/EEA/UK
For users in the European Union, European Economic Area, or United Kingdom, transfers of personal data to countries without an adequacy decision are carried out under appropriate safeguards, including:
- Standard Contractual Clauses (SCCs) approved by the European Commission
- The EU-U.S. Data Privacy Framework, where applicable
Google LLC's data processing terms include Standard Contractual Clauses for international transfers. See Google's Data Processing Terms linked in Section 9.
11.2 Other Regions
For users in other regions, we take appropriate steps to ensure that international transfers comply with applicable data protection laws.
12. Data Retention
We do not maintain personal user databases on our own servers.
- Data collected by Firebase services is retained according to Google's data retention policies. Firebase Analytics data is configured with a retention period, after which user-level data is automatically deleted. Crashlytics retains crash reports for a limited period as defined by Google.
- Locally stored data (reading progress, bookmarks, goals, preferences, downloaded audio) remains on your device until you clear App data or uninstall the App.
- If you contact us by email, your communication may be retained for up to 2 years for support and legal purposes.
For EU/EEA/UK users: we retain data only for as long as necessary to fulfil the purposes described in this Policy or as required by applicable law. You may request deletion at any time (see Section 13).
For data processed by Google services, you can also use Google's privacy controls at https://myaccount.google.com/data-and-privacy.
13. Your Privacy Rights
13.1 Rights Under GDPR / UK GDPR (EU, EEA & UK Users)
- Right of Access (Article 15): Request a copy of the personal data we hold about you
- Right to Rectification (Article 16): Request correction of inaccurate or incomplete data
- Right to Erasure (Article 17): Request deletion of your personal data
- Right to Restriction of Processing (Article 18): Request that we limit how we process your data
- Right to Data Portability (Article 20): Receive your data in a structured, commonly used, machine-readable format
- Right to Object (Article 21): Object to processing based on legitimate interests
- Right to Withdraw Consent (Article 7(3)): Withdraw consent at any time without affecting the lawfulness of prior processing
- Right Not to be Subject to Automated Decision-Making (Article 22): We do not carry out solely automated decision-making producing legal or similarly significant effects
You also have the right to lodge a complaint with your local supervisory authority. A list of EU supervisory authorities is available at https://edpb.europa.eu/about-edpb/about-edpb/members_en
UK users may contact the Information Commissioner's Office (ICO) at https://ico.org.uk/make-a-complaint/
13.2 Rights Under CCPA / CPRA (California, USA Users)
- Right to Know: Request disclosure of the categories and specific pieces of personal information collected in the past 12 months
- Right to Delete: Request deletion of collected personal information, subject to certain exceptions
- Right to Correct: Request correction of inaccurate personal information
- Right to Opt-Out of Sale or Sharing: We do not sell or share personal information for cross-context behavioral advertising
- Right to Limit Use of Sensitive Personal Information: We do not collect or use sensitive personal information
- Right to Non-Discrimination: We will not discriminate against you for exercising your rights
To exercise your California privacy rights, contact us at admin@codeastraa.com with the subject line "California Privacy Request".
13.3 Rights Under Other Applicable Laws
- Brazil (LGPD): Rights to access, correction, deletion, portability, and information about sharing
- Canada (PIPEDA / Quebec Law 25): Rights to access and correction of personal information
- Australia (Privacy Act 1988): Rights to access and correct personal information
- South Korea (PIPA): Rights to access, correction, deletion, and suspension of processing
We will respond within the timeframe required by applicable law (generally 30 days for GDPR; 45 days for CCPA).
13.4 How to Submit a Request
Contact us at admin@codeastraa.com with:
- Your contact details
- The specific right you wish to exercise
- Sufficient information to identify your request (for example, device model and approximate date of installation)
Because the App does not use accounts, we may be unable to link technical data to an individual. Where we cannot identify you from the information provided, we may be unable to action a request, as permitted under GDPR Article 11. In such cases, clearing App data or uninstalling the App will remove all locally stored information.
For data processed by Google services, requests may also be submitted directly to Google at https://myaccount.google.com/data-and-privacy
14. Children's Privacy
Our App contains religious and educational content suitable for a general audience and may be used by families. The App does not display advertisements, does not contain in-app purchases, and does not collect personal information from any user, including children.
We do not knowingly collect, use, or share personal data from children. If you are a parent or guardian and believe your child has provided personal information through our App, please contact us at admin@codeastraa.com and we will take prompt steps to review and remove such information.
Where the App is made available to a child or mixed audience, we comply with the Google Play Families Policy and applicable children's privacy laws, including COPPA in the United States and the age-of-consent provisions of GDPR Article 8 in the EU/EEA.
Parents and guardians are encouraged to monitor their children's mobile application usage and use available parental controls on their devices.
15. Data Security
We implement reasonable administrative, technical, and organizational safeguards to help protect information processed through our App. All network communication uses encryption in transit (TLS/SSL). Third-party services we use implement their own industry-standard security measures.
Because the App stores your reading data locally rather than on our servers, the security of that data also depends on the security of your own device.
No method of transmission over the Internet or electronic storage is completely secure, and we cannot guarantee absolute security of your information.
In the event of a personal data breach likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours as required by GDPR Article 33, and affected users without undue delay where required under Article 34.
16. Identifiers and Similar Technologies
Our mobile App does not use browser cookies and does not use the Android Advertising ID (GAID).
Firebase services generate a Firebase installation ID, an app-scoped identifier used to associate analytics and crash reports with an installation of the App. This identifier is reset when you clear App data or uninstall the App, and is not shared with advertisers.
17. Data Protection Officer (DPO)
This section applies primarily to EU/EEA/UK users under GDPR Article 37.
As a small developer whose processing activities are limited in scope and do not involve large-scale monitoring or processing of special category data, we have assessed that the appointment of a formal Data Protection Officer is not currently mandatory. For any data protection concerns, inquiries, or to exercise your rights, you may contact us directly:
Privacy Contact: Code Astra Email: admin@codeastraa.com
We aim to respond to all data protection inquiries within 30 days as required by GDPR Article 12.
18. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, third-party services, or applicable laws. Changes become effective when the revised Privacy Policy is published at the URL provided in our App's Play Store listing.
For material changes, we will make reasonable efforts to notify users through in-app notices prior to or at the time the changes take effect. For EU/EEA/UK users, if a material change affects processing based on consent, we will request fresh consent where required by GDPR.
We encourage you to review this Privacy Policy periodically. Continued use of the App after any changes constitutes your acceptance of the updated Privacy Policy, where permitted by applicable law.
19. Contact Us
If you have questions, concerns, requests, or complaints regarding this Privacy Policy or our data practices, please contact us:
AccountName: Code Astra
Email: admin@codeastraa.com