1. Overview
This policy covers the Masaruna app on iPhone and Android, and this website. It is written to be read, not to be agreed to unread — if any part of it is unclear, the address at the end reaches a person.
Masaruna is built to hold as little of your data as it can. The app runs on your phone: you take on commitments, record your days and receive reminders with no connection at all, and without ever signing in to anything.
It is not, however, device-only, and this is the part worth reading slowly. The first time you open the app it asks one question — whether this is a first time, or a record you are restoring — and either answer creates an account for this phone as soon as it has a connection. For a first time that account is unnamed: no email, no password, nothing attached to it, and no way for anyone but this phone to reach it. It exists so that your record can come back to you. Section 5 says what is in it, how long it lasts, and how to remove it.
Beyond that copy, the only thing that reaches a server is a group you joined, so a few people you trust can witness that you kept your day.
2. Information we collect
What the app holds about you is small enough to list:
- Your commitments, the days you kept them, and any stretches you paused.
- Commitments you write yourself: the title and description you gave them, which no group ever sees.
- Your preferences: language, appearance, reminder times, prayer-time method, and the name the app greets you by.
- An approximate location, if you turn on prayer reminders — kept on your phone and never sent to us.
- Your email address, if you choose to link an Apple or Google account so your record can be restored later.
Location deserves its own sentence. Prayer times are computed on your phone, and the coordinate they are computed from never leaves it: the fix is rounded to about a kilometre — far coarser than a street, and still exact for a prayer time — and stored on the device alone. To tell which country's calculation convention to follow, the app asks your operating system to name the country at that coordinate; that request is answered by Apple or Google under their own privacy policies.
We do not collect your contacts, your photos, a precise location, an advertising identifier, or a fingerprint of your device. The app contains no analytics service, no crash reporting service and no advertising code of any kind. There is nothing in it that reports what you do back to us.
3. How we use it
To draw your own screens, and nothing beyond that. What you recorded becomes today's list, the calendar behind a commitment, the reminder that arrives at the time you set, and the copy that comes back to you when you open the app on a new phone.
We do not sell your data. We do not share it with advertisers, and we do not use it to build a profile of you. Your backup is not read, mined or analysed; it exists so that a lost phone is not a lost year.
If you link an account, the email address is used to tell you which account holds your record. Nothing is ever sent to it — there is no newsletter and no marketing mail.
4. Groups & sharing
A group is the one place where another person sees something of yours, and what they see is deliberately narrow: for each commitment the group carries, whether you kept it today. A yes or a no.
Nothing else about that commitment travels — not the days you set it on, not the time you are reminded, not your history before today, and not the commitments you keep outside the group. Commitments you wrote yourself are never witnessed at all; only the app's own library can be added to a group. There is no leaderboard and no streak for anyone else to read.
The name shown beside you belongs to that membership, not to your account. You choose it when you join, so you can go by one name among family and another in a study circle. In a public group there is no name at all — presence there is counted, never attributed.
Groups live on the server, so being in one means having an account. An unnamed one is enough: unless you link Apple or Google, that account is reachable from your phone alone.
5. Data storage
The primary copy is on your phone, in a database inside the app, protected by the phone's own storage protections. Delete the app and that copy goes with it.
The server copy carries your commitments, the days you kept them, your pauses and your preferences. Two things are never in it: the location your prayer times are computed from, and the queue your phone keeps its own reminders in. It is held with Supabase, our database and authentication provider, and it travels encrypted and is stored encrypted. Which rows belong to whom is enforced in the database itself: every read of your record is filtered to your account before the query runs, rather than by the app remembering to ask nicely.
An unnamed account — the one a first launch creates — is swept on a timer, because nothing but your own phone can ever reach it: if no device has opened it for ninety days, it is deleted from the server, record and all. Your phone's copy is untouched by that, and it is offered up again the next time the app has an account to offer it to.
Linking Apple or Google attaches a credential to that same account, which is what lets a second phone reach it. A linked account is never swept: it is yours, and it stays until you remove it.
6. Your rights
Your record is in your hands more directly than most policies can offer, because it is on your phone. Everything the app holds about you is visible in the app, and every part of it can be changed or removed there — a commitment, a day, a name, a preference.
Settings holds a Backup screen, and that screen is where the server side is governed: whether a copy is kept at all, which account holds it, and a row that removes it. Removing it leaves your phone's copy alone, and deleting the app removes that one.
Depending on where you live you may have further rights over your data — to ask for a copy of it, to object to how it is handled, or to complain to a regulator. Write to us and we will help you exercise them.
7. Children's privacy
Masaruna is made for a general audience and is not directed at children under 13. We do not knowingly collect personal information from a child, and the app is built so that there is very little to collect from anyone.
If you are a parent or guardian and believe a child has given us something, write to us and we will remove it.
8. Changes to this policy
When this policy changes, the date at the top changes with it, and this page always carries the current version.
A change that matters — a new kind of information, or a new place an existing one goes — is said in the app as well. A promise that quietly narrows on a page nobody reloads is not a promise.
9. Contact us
Questions about this policy, or about anything the app holds, reach a person at the address below.