Privacy Policy
Effective August 11, 2026
The Hifz Project is a free Quran memorization app. We collect the minimum data needed to run the service, we don't show ads, and we don't sell your data. This page explains exactly what we store, who processes it, and how to erase it.
What we collect
- Account details. Your email address and display name, stored with our authentication provider, Supabase.
- Learning progress. Your cards, review history, preferences, and known surahs, the data that powers spaced repetition scheduling.
- Subscription status. If you subscribe to the voice add-on, we store your Stripe customer and subscription IDs so we know your plan is active. Your payment card details are held by Stripe and never touch our servers.
- Voice trial anti-abuse record. If you start a free voice trial, we store a normalized email-family key, the account's historical identifier, and the trial dates. We also create a keyed HMAC-SHA256 fingerprint of the network address used to activate it. The fingerprint is used only for a rolling 24-hour activation limit and is cleared by an hourly cleanup after that window (within about 25 hours). These records limit repeated trial activation by the same account, email family, or network.
- Usage and administrative ledgers. We retain transcription request timestamps and outcomes, automatic hadith-comparison timestamps and outcomes, and administrative email actions for up to 35 days. These records enforce usage and send limits and support short-term operational diagnosis. An administrative test-email entry can include its recipient address.
- Automated-email delivery ledger. To prevent overlapping jobs from sending the same digest or reminder twice, we retain the account identifier, email kind, claim/final state, and timestamps for up to 90 days. This service-only ledger does not contain the recipient address or message content.
Automated transcription and answer comparison
When you tap the microphone, your recording is sent to DeepInfra (running the whisper-large-v3 model) for transcription. The app does not save the recording after the transcription request. We log its timestamp and outcome for hourly abuse controls and monthly usage limits; that ledger is deleted after 35 days.
When you submit a typed meaning answer in a hadith review, the English reference meaning and your answer may also be sent to DeepInfra for automatic comparison. This is used to grade that answer; it does not include your account details. We retain the comparison request's timestamp and outcome for usage limits for up to 35 days, but not the answer text or reference meaning.
Classrooms
If you join a classroom with a teacher's invite code, that teacher can see your display name, email address, and learning progress (words learned, review counts, accuracy, last active) while you're a member. Leave the class at any time from the Classroom page and that visibility ends immediately. Teachers: your students see your class name only.
Email communications
Resend delivers service emails to the address on your account. Depending on your settings, these may include:
- Weekly progress digests. These use learning-progress totals such as reviews, accuracy, and words learned to summarize an active week. They are sent only after you explicitly enable them in Settings, and can be disabled there or from the unsubscribe link in an email.
- Review reminders. These use the number of reviews currently due to send an occasional reminder. They are enabled by default and can be disabled in Settings or from the unsubscribe link in an email.
- Service announcements. We may occasionally send news about the service. Each announcement includes an unsubscribe link.
Changing these preferences does not affect necessary account or billing emails.
Analytics
We use Vercel Web Analytics, which is anonymous and does not use cookies. It cannot identify you or track you across sites. We remove query strings and URL fragments before analytics events are sent, so confirmation, unsubscribe, and sign-in credentials in URLs are not included.
Quran content
Quran text comes from Quran.com's API. Audio is loaded from Quran Foundation and Islamic Network CDN hosts. These requests carry ordinary network information such as an IP address and browser details, but the app does not intentionally include your account or learning-progress content in them.
Third-party processors
These are the only services that process data on our behalf:
- Supabase, authentication and database (account and progress data).
- Stripe, payments and subscription billing.
- DeepInfra, voice transcription and automatic comparison of hadith meaning answers.
- Resend, delivery of account, billing, progress, reminder, and announcement emails.
- Cloudflare, Turnstile bot protection on authentication, email resend, password change, and destructive confirmation forms.
- Vercel, hosting and anonymous analytics.
- Sentry, optional error diagnostics; account identifiers and free-form sensitive fields are removed before events are sent.
- Google and Apple, process sign-in data only if you choose the corresponding social sign-in option.
Deleting your data
Before deleting your account, you must cancel any personal or classroom plan and wait for its paid period to end. You can then delete the account from Settings, under Danger Zone, which permanently erases your account and associated data from The Hifz Project. This cannot be undone. Stripe may retain transaction or billing records under its own data-retention practices.
One narrow exception: if your account used the free voice trial, we keep a minimal record of that (the normalized email-family key, historical account identifier, and trial dates, no name or learning data) after deletion so the one-trial limit cannot be reset by re-creating an account. The short-lived keyed network fingerprint may also remain until the hourly cleanup runs, but is cleared within about 25 hours of trial activation.
Changes
If we change this policy, we'll update this page and the effective date above.
Contact
Email us at support@thehifzproject.com, for privacy or data requests, include the email address on your account.