Last updated: 7 September 2026
Hurma is a mobile app that teaches you to read the Qur’an. This policy explains what data is processed when you use the app.
When you create an account:
If you choose to sign in with Apple or Google, we receive only your email address and (if you chose to share it) your name from those providers.
After registration you are asked to complete your profile:
This information is saved to your account. Age is asked so the app can enforce its 13-year age limit.
So you can pick up where you left off, the following is saved to your account:
So the app works without an internet connection, it keeps a copy of the above on your device. If you delete the app, that copy is deleted too.
If you want to invite friends, the app asks permission to access your contacts. If you decline, the app keeps working exactly as before.
If you grant permission:
The app has a weekly and an all-time leaderboard. Other signed-in users can see your display name and your XP there. Your email address, surname, age and gender are not shown on the leaderboard.
If you do not want your name shown, you can change it from the profile screen.
The app offers an optional hurma+Premium subscription (monthly or yearly; the yearly plan may include a free trial). Payment is processed through the Apple App Store; your card details never reach us.
We use the RevenueCat service to verify subscription status. RevenueCat receives a user identifier generated by the app and App Store purchase information (transaction and subscription state); if you have an account, that identifier is matched to it. This data is processed solely to verify your subscription and unlock premium access; it is never used for advertising or tracking.
So we can see where the app helps and where you get stuck, we collect anonymous usage statistics. These records stay on our own server (Supabase); they are not sent to any analytics company such as Google Analytics, Firebase or Facebook SDK. The events that go to TikTok for ad measurement are separate and are described at the end of this section.
What is recorded is only this:
What is not recorded: your name, email address, password, any text you type into the app, your contacts, your location, your advertising identifier (IDFA), or anything that could identify you across other apps or websites. These records are never used for advertising, profiling or tracking, and are never shared with anyone.
If you have an account, the statistics are linked to it, so that one person’s two devices are not counted as two users.
To switch it off: go to Profile and turn off Usage statistics. From that moment no new records are created, and the records collected from your device so far are deleted from the server. They are also deleted when you delete your account.
We advertise Hurma on TikTok. So we can see which ads actually lead to installs and subscriptions, the app contains the TikTok Business SDK. It sends TikTok the following: that the app was opened, the onboarding was completed, a lesson was finished, a free trial or subscription started, and the purchase amount; plus technical details such as device model, operating system version, app version and language.
Your advertising identifier (IDFA) is used only if you allow it. iOS shows a one-time “allow tracking” prompt for this. If you decline, no advertising identifier goes to TikTok; measurement then happens through Apple’s privacy-preserving SKAdNetwork, without identifying you. You do not have to allow it; the app works exactly the same.
Your name, email, lessons or anything you type never go to TikTok. While the Profile → Usage statistics switch is off, no events are sent to TikTok either. How TikTok handles this data: https://www.tiktok.com/legal/privacy-policy
We do not access or collect any of the following:
The app contains no ad-serving SDK. The only third-party measurement tool is the TikTok ad measurement described in section 5; for that reason iOS asks for tracking permission (App Tracking Transparency) once, and you can decline. For the anonymous usage statistics we collect ourselves, see section 5 as well.
Your location is accessed only to calculate prayer times, and only if you grant permission. Your location is not sent to our servers; it is passed to the prayer-time service that performs the calculation (see section 8). Granting it is optional — you can type your city in instead.
| Purpose | Data |
|---|---|
| So you can sign in to your account | Email, password |
| So your progress is not lost and returns when you change device | XP, streak, completed sections |
| To offer you suitable review exercises | Words you struggled with |
| To send you a daily reminder notification | Notification preference, device notification token |
| To display the leaderboard | Display name, XP |
| To enforce the 13-year age limit | Age |
| To calculate prayer times | The city you select (or your location, if you allowed it) |
| To improve the app and see where you get stuck | Anonymous usage statistics (section 5; can be switched off in Profile) |
| To measure the effect of our ad campaigns | App events and technical device details; your advertising identifier if you allowed it (TikTok, section 5) |
The legal basis for this processing is the performance of the service agreement between us, and your explicit consent (for notifications, contacts access and location).
Your account and progress data are stored on Supabase infrastructure. Supabase only hosts data on our behalf; it does not use your data for its own purposes. The database is protected by row-level security (RLS): each user can access only their own record. For the leaderboard, only the display name and score fields are exposed to other users.
Email delivery (password reset, address verification) is handled through Brevo; only your email address is passed to that service.
The app streams letter and verse audio at playback time from these two sources. The audio is never downloaded, copied or redistributed:
kuran.diyanet.gov.tr — publicly available alphabet (letter and vowel-mark) recordings of the Presidency of Religious Affairs of Türkiye (Diyanet)audio.qurancdn.com — Quran Foundation; verse recitation and word-by-word pronunciation. Hurma is a registered developer with Quran Foundation and operates under its developer terms.When an audio file is played, those servers see your device’s IP address, as with any internet request. No information about your account is sent to those servers.
Prayer times are calculated through api.aladhan.com (Aladhan). If you granted location permission your coordinates are sent to that service; if you did not, only the name of the city you selected is sent.
For the temperature and weather effect on the personalisation screen we use api.open-meteo.com, and for city search geocoding-api.open-meteo.com (Open-Meteo); those receive only coordinates or the city name you are searching for.
Neither service requires an account. The requests we send them carry no name, e-mail, account or anything else that identifies you — as with any internet request, they see your device’s IP address.
For ad measurement, the events listed in section 5 are passed to TikTok (TikTok Technology Limited). The advertising identifier is sent only if you allowed tracking on iOS.
Apart from this, we share your data with no third party. Sharing may occur only where legally required (a court order, for example).
Daily reminders are scheduled locally on your device. If you have an account, your device notification token is stored against that account — it is used solely to send you notifications, is processed for no other purpose, and is shared with no one. You can turn notifications off from the app’s settings or from your phone’s settings.
You can delete your account from inside the app at any time:
Profile → Delete my account
Once you confirm, your account, your progress and all your records are permanently deleted. This cannot be undone.
You may also request deletion by writing to the email address below.
Your data is kept for as long as your account remains open. When you delete your account, the data is deleted immediately; clearing it from backups may take up to 30 days.
The app is intended for users aged 13 and over. Age is asked during registration. Users under 13 should use the app under parental supervision; we do not knowingly collect data from anyone under 13. If we become aware of such a record, we delete the data.
You have the right to access, correct and delete your data, and to object to its processing. To exercise these rights, please contact us at the address below.
If this policy changes, we will update this page and change the “last updated” date. For significant changes, we will also inform you inside the app.
For questions:
Email: numangrsy@gmail.com
Hurma is an independent app. It has no official affiliation with the Presidency of Religious Affairs (Diyanet); the audio recordings are taken from the Presidency’s publicly available alphabet materials.