← Back to Home

Privacy Policy

Effective date: 2026-04-30

Service Provider: Treffas AB (Lavettvägen 2B, Sundbyberg 17459, Sweden)

Contact: [email protected]

This Privacy Policy describes how Treffas AB ("we", "us", "our") handles your information when you use the SalahMode mobile application ("the App") on Android and iOS (including iPadOS).

We built SalahMode to be a private, ad-free prayer companion. We collect the minimum data necessary to make the App work, we never sell or share your personal data with advertisers, and we never use your data for tracking across other apps or websites.


1. Summary (the short version)

  • Your location is used to calculate prayer times and Qibla direction. It stays on your device or, when you use the optional mosque finder, is sent as an anonymous query to OpenStreetMap. We never link location to your identity.
  • Your purchases (subscriptions, Founding Supporter) are processed by Google Play (Android) or Apple (iOS). We see anonymous purchase status via RevenueCat — never your Google account, Apple ID, name, email, or payment details.
  • Anonymous usage events (e.g. when the paywall opens, when you complete a prayer log) are sent to Firebase Analytics so we can improve the App. These events are not linked to your identity.
  • No tracking. We don't use IDFA, advertising identifiers, or share data with advertisers.
  • No ads. Ever.
  • Your rights under GDPR (if you're in the EU): access, rectification, deletion, portability, objection, and the right to lodge a complaint with your data protection authority. See Section 9.

2. What data we collect

2.1 Location data (precise + coarse)

  • Why: to calculate the five daily prayer times for your location and to point the Qibla compass toward Makkah.
  • How: via your device's standard location service, only when you grant permission.
  • Stored where: primarily on your device. When you use the optional mosque finder, your location is sent as an anonymous query to OpenStreetMap's Overpass API to retrieve nearby mosques.
  • Linked to identity: No.
  • Lawful basis (GDPR): consent (Article 6(1)(a)) — you explicitly grant location permission, and you can revoke it any time in your device's Settings.

2.2 Purchase history

  • Why: to know whether you have an active Premium subscription or Founding Supporter purchase, so the App can unlock the right features.
  • How: Google Play (on Android) or Apple (on iOS) processes your purchase. RevenueCat (our subscription state service) reports the entitlement status to the App using an anonymous app user identifier.
  • Stored where: Google's servers (under your Google account) or Apple's servers (under your Apple ID), RevenueCat's servers (anonymous), and your device.
  • Linked to identity: Yes — Google and Apple tie purchases to your store account by design. We never see your Google account or Apple ID, but the linkage exists.
  • Lawful basis (GDPR): performance of contract (Article 6(1)(b)) — necessary to deliver the Premium features you purchased.

2.3 Anonymous usage events (Firebase Analytics)

  • Why: to understand which features are used and improve the App.
  • What's sent: events such as app_open, screen_view, paywall_viewed, purchase_started. Includes anonymous app instance ID, device model, OS version, app version, country (coarse), and app session length. Never includes your name, email, contacts, photos, or messages.
  • Stored where: Google Cloud (United States, with EU-US Data Privacy Framework safeguards).
  • Linked to identity: No.
  • Lawful basis (GDPR): legitimate interest (Article 6(1)(f)) — improving the App for all users. You can disable this in your device's system settings (iOS Settings → Privacy & Security → Analytics & Improvements, or Android Settings → Privacy → Ads / Usage & diagnostics).

2.4 Crash and performance data

  • Why: to detect crashes and performance regressions so we can fix them.
  • What's sent: crash stack traces, app launch time, hang rate, energy use. Aggregate, anonymous.
  • Linked to identity: No.
  • Lawful basis (GDPR): legitimate interest.

2.5 What we DO NOT collect

  • Name, email address, phone number, or postal address (we have no account system)
  • Photos, contacts, calendar, microphone, or camera
  • Health data, biometric data, or sensitive personal data
  • IDFA (iOS) or Google Advertising ID (Android), or any cross-app identifiers
  • Browsing history outside the App
  • Data from other apps you use

3. Third-party services

We use the following third-party services. Each has its own privacy policy:

ServicePurposeWhat they receivePrivacy policy
Google LLC (Google Play)Play Store distribution, Google Play Billing, push notification infrastructure (Android)Your purchase records (under your Google account), device infopolicies.google.com/privacy
Apple Inc.App Store distribution, In-App Purchase processing, push and local notifications (iOS)Your purchase records (under your Apple ID), device infoapple.com/legal/privacy
RevenueCat, Inc.Subscription state synchronizationAnonymous app user identifier, purchase entitlement statusrevenuecat.com/privacy
Google LLC (Firebase Analytics)Anonymous app usage analyticsApp events, anonymous app instance ID, device model, OS versionfirebase.google.com/support/privacy
OpenStreetMap Foundation (Overpass API)Mosque finder map data (only used if you open the mosque finder feature)Anonymous location queryopenstreetmap.org/copyright

We do not use Facebook, Amplitude, Mixpanel, or any advertising SDK.


4. International data transfers

Some third-party services (notably Firebase Analytics, Google Play, Apple, RevenueCat) process data on servers located outside the European Economic Area, primarily in the United States.

For transfers from the EU/EEA to the US, we rely on:

  • The EU-US Data Privacy Framework for Google (Play and Firebase), Apple, and RevenueCat where they are certified
  • Standard Contractual Clauses (SCCs) approved by the European Commission as a fallback

You can request more information about transfer safeguards by emailing [email protected].


5. Data retention

  • On-device data (your settings, prayer logs, location cache): kept on your device until you delete the App.
  • Anonymous analytics events: retained by Google for up to 14 months by default.
  • Purchase records: retained by Google Play, Apple, and RevenueCat for the duration required by tax law and audit (typically 6–7 years).
  • Crash logs: retained for diagnostic purposes for up to 12 months.

You can request deletion of any data we hold at any time — see Section 9.


6. Children's privacy

SalahMode is rated 4+ and contains no objectionable content, but it is not specifically designed for children. We do not knowingly collect personal data from children under 13 (or 16, depending on your jurisdiction). If you believe we may have inadvertently collected such data, please contact [email protected] and we will delete it promptly.


7. Security

We use industry-standard practices to protect data:

  • All network requests use HTTPS / TLS encryption.
  • We do not run our own backend servers, so we have no centralized database that could be breached.
  • On-device sandbox protections (iOS Keychain on iOS, Android Keystore and scoped storage on Android) apply automatically to data stored on your device.

No method of electronic storage is 100% secure, but we minimize risk by collecting as little data as possible.


8. No cross-app tracking

SalahMode does not track you across other apps or websites on any platform.

  • iOS: we do not request permission via Apple's App Tracking Transparency (ATT) prompt because we have no need for the IDFA or any cross-app identifier.
  • Android: we do not request the Google Advertising ID (AAID) and we do not include any advertising or attribution SDKs.

9. Your rights (GDPR and similar laws)

If you're in the European Economic Area, the United Kingdom, Switzerland, or another jurisdiction with comparable privacy law, you have the following rights regarding your personal data:

  • Right of access — request a copy of the data we hold about you
  • Right of rectification — correct inaccurate data
  • Right of erasure ("right to be forgotten") — delete your data
  • Right of restriction — limit how we process your data
  • Right of data portability — receive your data in a portable format
  • Right to object — object to processing based on legitimate interest
  • Right to withdraw consent — for any processing based on consent

To exercise any of these rights, email [email protected]. We will respond within 30 days.

If you believe we have violated your privacy rights, you can lodge a complaint with your national data protection authority. In Sweden, this is Integritetsskyddsmyndigheten (IMY) at imy.se.

You also have the right under California law (CCPA/CPRA) to know what personal information is collected, request deletion, and not be discriminated against for exercising these rights. SalahMode does not sell or share personal information for cross-context behavioral advertising.


10. Changes to this policy

We may update this Privacy Policy from time to time. The "Effective date" at the top reflects the most recent revision. Material changes will be communicated through the App or via the App Store listing. Continued use of the App after changes are published constitutes acceptance of the revised policy.


11. Contact us

For privacy questions, data subject requests, or anything else:

Treffas AB
Lavettvägen 2B
Sundbyberg 17459, Sweden
Email: [email protected]
Web: salahmode.com