AyahFlow Privacy Policy
Last updated: 2026-09-02
1. Controller and scope
The controller is Alessandro Brüning, BRUNIQO, Katharina-Bräckeler-Str. 4a, 41462 Neuss, Germany. Contact support@bruniqo.de for privacy questions. This policy covers the planned first AyahFlow release for iPhone, iPad, and Apple Watch and the related support, privacy, and product-information pages.
2. Accountless first release
The first release does not provide AyahFlow account creation, Sign in with Apple, the source-bound assistant, or assistant credits. It contains no advertising, cross-app tracking, or third-party analytics. The app does not send Quran reading activity, prayer history, notes, bookmarks, precise locations, or family information to BRUNIQO. Optional telemetry, sensitive-place modes, and family features remain disabled.
3. Data stored on the device
AyahFlow stores settings, reading continuation, private goals, bookmarks, notes, reminder state, and intro state in the app container or appropriate local Apple storage. The key protecting Quran notes is held in Keychain. Data for the Widget and Watch is shared through an App Group or Apple's local device communication as a coordinate-free prayer and reading projection. BRUNIQO cannot access this local content.
You can remove local content in the relevant app areas. Deleting the app removes its container according to iOS behavior; information in Apple system services or backups can remain subject to Apple's own retention and deletion controls. Back up important private material before reinstalling.
4. Location, alarms, and notifications
Location permission is requested only when you explicitly calculate a local prayer schedule or open the Qibla compass. The coordinate is used in memory for that calculation and is neither persistently stored by AyahFlow nor sent to BRUNIQO. If permission is denied, manual settings and other core functions remain available.
Alarm and notification permission is requested only for reminders you choose to enable. Scheduling and delivery use Apple system services on your devices. You can revoke permissions at any time in system settings.
5. App Store and historical Apple entitlements
The first release offers no in-app purchases, subscriptions, lifetime products, or credit packs and starts no purchase flow. AyahFlow may locally evaluate Apple-verified historical entitlement data so that earlier access is recognized automatically and expiry or revocation is represented accurately; no Restore Purchases control is shown for this purpose. Apple independently processes App Store download, Apple Account, and any earlier billing data under its own privacy terms. BRUNIQO may receive aggregated storefront and download reports in App Store Connect; those reports do not contain AyahFlow Quran notes, prayer activity, or precise location data.
6. Support requests
If you voluntarily send email, we process the sender address, message, technical details, and attachments to answer the request. Depending on the request, the legal basis is Article 6(1)(b) GDPR or our legitimate interest in safe, reliable support under Article 6(1)(f) GDPR. Do not send passwords, Apple credentials, complete private notes, or precise locations. Support data is deleted when it is no longer needed for resolution and traceable defect handling, subject to mandatory legal retention duties.
7. Visiting these webpages
When a page is requested, the web server processes technically necessary connection data such as IP address, timestamp, requested URL, status code, transferred volume, referrer, and browser identifier. This supports delivery, abuse detection, and system security under Article 6(1)(f) GDPR. Nginx rotates logs daily and retains no more than 14 archived rotations in addition to the current log file. These pages set no marketing or analytics cookies and load no third-party trackers.
Contracted hosting and infrastructure providers may receive access to necessary operational data as processors. Data is not disclosed for advertising or profiling.
8. Recipients, international context, and security
App content stays within the local Apple device environment in the described release. Apple independently processes App Store purchases, system permissions, device communication, and any Apple backups you enable under its own terms. BRUNIQO does not sell personal data. Access to support or server data is limited to people who need it for operation and support.
9. Your rights
Where BRUNIQO processes personal data from a support request or website visit, the GDPR may provide rights of access, rectification, erasure, restriction, portability, and objection. Consent can be withdrawn for future processing. You may also complain to a data protection supervisory authority. We may request proportionate identity evidence before disclosing or changing personal data.
10. Changes
We will update this policy before enabling any new account, assistant, telemetry, family, or sensitive-location data flow. The dated version published here is authoritative. Source code prepared for a future feature does not activate that data flow.