Istiqāmah · Habit Tracker

Privacy Policy

Last updated: June 2026

Our commitment: We treat your data — especially anything reflecting your faith — as a trust (amanah). We never sell it, share it with data brokers, or use it for advertising.

01

Who We Are

Istiqāmah (“Istiqāmah”, “we”, “us”, “our”) is a mobile app that helps you build and keep consistent worship habits — prayer, Qur'an, dhikr, and good deeds. It is developed and operated by MVP Matter.

For any privacy matter, contact us at contact@mvpmatter.com.

02

Data We Collect

Account Data

When you create an account or sign in via Apple or Google:

  • Your email address (or an Apple relay address)
  • Your name and a unique account identifier
  • Authentication tokens

Profile & Preferences

Your display name, a unique handle, app preferences (theme, reminder settings), and the answers you give during onboarding.

Habit & Progress Data

The habits you create and your daily completions, so your progress syncs across your devices.

Social Data

If you use the social features: your friendships, the circles you join, and shared habits. Other members can see your public profile (name, handle, avatar) and your aggregate progress within shared circles.

Location — On Device Only

If you enable prayer-time reminders, the app uses your device location to calculate accurate prayer times. Your coordinates are stored only on your device and are never sent to or stored on our servers.

Notifications

With your permission, the app schedules local notifications on your device for habit and prayer reminders. These are generated on-device — we do not operate a push-notification server.

03

How We Use Your Data

PurposeData UsedLegal Basis (GDPR)
Provide the appAccount, profile, habitsContract performance
Sync across devicesAll account-linked dataContract performance
Social featuresProfile, friendships, circlesContract performance
Calculate prayer timesLocation (on device only)Consent
Personalize experienceOnboarding responsesConsent
Legal obligationsAccount recordsLegal obligation

04

Third-Party Services

ServicePurposePrivacy Policy
SupabaseAuthentication & databasesupabase.com/privacy
Apple Sign-InAuthenticationapple.com/legal/privacy
Google Sign-InAuthenticationpolicies.google.com

We do not use third-party advertising or analytics trackers, and there are no in-app purchases or payment processors.

05

Data Sharing

✕ No data sold✕ No data brokers✕ No advertisers

We share data only in limited circumstances:

  • With members of circles you join — limited to your public profile and aggregate progress
  • With service providers listed above, solely to deliver the service
  • When required by law (valid legal process or government request)
  • In a business transfer (merger or acquisition) — we would notify you in advance

06

Data Retention

We keep your data until you delete it. When you delete your account, your personal data — profile, habits, completions, friendships, and circle memberships — is removed immediately and irreversibly.

07

Your Rights

GDPR Rights (EU / UK)

Access
Request a copy of your data
Rectification
Correct inaccurate data
Erasure
Delete your data
Portability
Export your data
Restriction
Limit processing
Object
Object to processing
Withdraw Consent
For location & onboarding data
Complain
To your local data authority

CCPA / CPRA Rights (California)

  • Right to know what data we collect and how it is used
  • Right to delete your personal information
  • Right to correct inaccurate information
  • We do not sell or share data for advertising
  • Right of non-discrimination for exercising your rights

To exercise any right, email contact@mvpmatter.com. We respond within 30 days.

08

Deleting Your Account

You can permanently delete your account at any time from within the app:

Settings → Delete account

This immediately and irreversibly removes your account and all associated data. For help, email contact@mvpmatter.com.

09

Children's Privacy

Istiqāmah is not directed at children under 13 (or 16 in the EU/UK). We do not knowingly collect data from children. If you believe we have, contact us and we will delete it.

10

Security

  • Encryption in transit (TLS/HTTPS) for all data sent to our servers
  • Row-Level Security — you can only access your own data
  • Secure authentication via email, Apple Sign-In, and Google Sign-In (OAuth 2.0)
  • No third-party advertising or analytics SDKs

11

Changes to This Policy

When we make material changes, we will update the “Last updated” date and, where appropriate, notify you in the app. Continued use after the effective date constitutes acceptance of the updated policy.


12

Contact Us

Privacy questions, requests, or concerns

contact@mvpmatter.com

Data requests fulfilled within 30 days