Privacy Policy
Last updated: 07.10.2026
Cumacı helps you keep track of the Fridays you pray at a mosque. This policy explains which personal data we process, why, for how long, and what rights you have under the EU General Data Protection Regulation (GDPR), the UK GDPR and the Swiss FADP. In short: no ads, no tracking, no third-party analytics, we never sell your data and we keep no location history.
1. Controller
The Cumacı app — developer: Yusuf Demir, Türkiye. Contact: [email protected]
2. What we process, why, and on which legal basis
| Data | Purpose | Legal basis |
|---|---|---|
| Account: the user identifier Sign in with Apple issues for this app, and a display name if you enter one. We do not store your email address. | Recognise your account and keep your data across devices. | Performance of a contract, Art. 6(1)(b) GDPR |
| Prayer records: which Friday, which mosque, arrival/verification time; excuses or "Friday time (at home)" declarations; streak, stamps, badges and cards; Friday sermon quiz answers; charity points (which mosque you sent how many points to) | Run the streak, mosque passport, badges and charity points. Because these data can reveal your religious beliefs, they are special category data. | Your explicit consent, given at first launch, Art. 9(2)(a) and Art. 6(1)(a) GDPR |
| Group (Cemaat), optional: the group you joined, the date you joined, "Call" notifications you sent or received | Show your group's shared streak and "this Friday" list. Group members see your name and whether you prayed that Friday. Mosque and time are shown only if Settings → Show my mosque in group is on. Excuses and special circumstances are never shown. If you block or report a member, that record (who, whom, reason, date) is kept for review; the reported person is not notified. | Explicit consent, Art. 9(2)(a) GDPR, given when you create or join a group; you can leave at any time |
| Location | Verify that you are at a mosque; show nearby mosques and prayer times. Details below. | Art. 6(1)(b) GDPR; for verification also Art. 9(2)(a) |
| Language and time zone | Show content and notifications in your language, and prayer times and Fridays in your local time. | Art. 6(1)(b) GDPR |
| Device data: device name, push notification token | Keep you signed in; send Friday reminders if you turn them on. | Art. 6(1)(b) GDPR |
| Purchases (if any): App Store transaction ID and subscription status | Recognise your subscription. Payment details never reach us; Apple handles payment. | Art. 6(1)(b) GDPR; statutory retention Art. 6(1)(c) |
| Technical logs: IP address, request time, error logs | Security of the service and fixing errors. Kept for at most 14 days. | Legitimate interest in a secure, working service, Art. 6(1)(f) GDPR |
How location is used
- At verification: when you tap "I'm at the mosque", your location is processed on your device. Only the distance to the mosque, the accuracy and the time are sent to our server. Your coordinates are not stored anywhere.
- Nearby mosques and prayer times: the app sends your approximate location with the request; the result is computed and the location is not stored.
- "Always" permission (optional): if you allow it, iOS monitors on your device when you arrive at mosques you have prayed at and counts your Friday automatically. Again only verification data (distance, accuracy, time) is sent. You can turn this off in iOS Settings at any time; the app works with "While Using".
- Friday reminder: the last known approximate location stays on your device only.
- We keep no location history.
What we do not process
Advertising identifiers, cross-app tracking, third-party analytics, contacts, photos, microphone. We do not sell your data or use it for advertising. There is no automated decision-making or profiling with legal or similarly significant effects (Art. 22 GDPR).
Do you have to provide data?
Sign-in is needed to use the app. Consent for prayer records is voluntary, but without it the streak features cannot work.
Mosque registration (imams and association board members)
If you fill in the "Register your mosque" form we process:
- your name, role and phone number;
- the association's name, registry number and IBAN;
- an optional document you upload.
Purpose: verify the association and pay the mosque's share of donations to it. The legal basis is the performance of the arrangement you request (Art. 6(1)(b) GDPR) and our legitimate interest in preventing fraud (Art. 6(1)(f)).
The IBAN and phone number are stored encrypted. They are never shown in the app or on public pages, and only authorised staff see them for verification and payment. Rejected applications are deleted 6 months after the decision. Approved ones are kept while the mosque stays registered; payment records are kept for the statutory period. Bank receipts of payments are published for transparency, with personal details redacted.
3. Recipients and processors
- Hetzner Online GmbH, Germany: servers and backups. Your data is stored in the EU. Processor under Art. 28 GDPR.
- Apple: Sign in with Apple, push notifications (APNs) and App Store purchases. Where data reaches Apple Inc. in the USA, the transfer relies on the EU–US Data Privacy Framework (adequacy decision, Art. 45 GDPR).
The controller is based in Türkiye and operates the service from there. Türkiye has no EU adequacy decision. Access from Türkiye is necessary to provide the service you asked for (Art. 49(1)(b) GDPR). For special category data it also relies on your explicit consent (Art. 49(1)(a) GDPR). We do not share your data with anyone else unless the law requires it.
4. How long we keep data
- As long as your account exists.
- When you delete your account, these are deleted immediately:
- your prayer records, streak, stamps, badges, cards and quiz answers;
- your group memberships;
- your name and Apple identifier.
- Charity points you already sent to a mosque remain in that mosque's total but are no longer linked to you.
- If a purchase or invoice record must be kept by law, only that record is kept, without your identity, for the statutory period.
- Technical logs: at most 14 days.
5. Your rights
Under the GDPR you have these rights:
- access (Art. 15);
- rectification (Art. 16);
- erasure (Art. 17);
- restriction of processing (Art. 18);
- data portability (Art. 20);
- objection to processing based on legitimate interests (Art. 21).
You can withdraw your consent at any time with effect for the future (Art. 7(3)).
- Delete your account: in the app, Settings → Delete my account. Deletion happens immediately and cannot be undone.
- Other requests: write to [email protected]. We reply free of charge within one month.
- Complaints: you can lodge a complaint with a supervisory authority (Art. 77). Usually this is the authority where you live, for example your state data protection authority in Germany, the Autoriteit Persoonsgegevens in the Netherlands, the CNIL in France or the ICO in the UK. See the list of EU authorities.
6. Security
Connections are encrypted with HTTPS. Your session token is stored in the iOS Keychain on your device. Server access is limited to authorised persons.
7. Changes
If we update this policy, we publish the new version on this page with its date and tell you about important changes in the app.
The Turkish version (Türkçe) also serves as the information notice under Turkish law (KVKK).