Skip to content
Qurandia

Privacy Policy

Effective date: 2026-08-14

What data Qurandia processes and why, how long it is kept, and why it is shared with nobody.

In short

We show no advertising, run no visitor analytics or behavioural profiling tools, and serve our fonts from our own server. The only third-party script on our pages is Sentry, the monitoring tool that lets us find software faults and performance problems; it is never used for advertising or profiling. Technical performance data is sent to it for every request, but that data is not tied to your account; your account identity is attached only to an error report. We keep only the data the Service needs in order to work, and we never sell it or share it for marketing.

Data we process

If you browse without an account, only the preferences stored in cookies are processed. Once you register, the following data is processed:

  • Account details: your name, your email address, your irreversibly hashed password, your interface language, your time zone, your daily study goal, your account role, and the times the account was created and last changed.
  • Library: the verses, hadiths, roots and topics you save; the private notes you write (free text); the collections you create and their contents.
  • Learning records: lessons completed, quiz answers and scores, flashcard states, review logs (including how long an answer took), daily study minutes and streak.
  • Technical: session and preference cookies. On sign-in attempts your IP address is used transiently to rate-limit brute-force attacks and is not written to our own records. Our monitoring tool (Sentry) receives technical performance data for every request: the request URL, how long it took, your browser and device details and your IP address; that record carries no account identity. When a software fault occurs, the error report additionally carries the data of the failing request and, if you are signed in, your account id, account role and email address; for faults in your browser it also carries a screen recording with form fields masked. Those records are kept for a limited period.

What we never collect

None of the following is collected:

  • Visitor analytics, measurement or behavioural tracking data; advertising profiles.
  • Location data, phone numbers, payment or financial information.
  • A persistent record of your visits tied to your account. Our monitoring tool receives a technical record of every request (its URL, how long it took, your IP address); those records carry no account identity and are deleted after a limited period.
  • Social media connections or third-party sign-in.

Why we process it

We process your data only to create and maintain your account, to store your progress and everything you save, to remember your preferences, to compute your spaced-repetition schedule, to keep your account secure, and to keep the Service running and fix software faults.

Retention

Your account and content data are kept until you delete your account. When you do, every record attached to it is deleted permanently and at the same moment, at the database level.

Server error logs are kept for at most 14 days and then removed automatically. Records in our error monitoring tool (Sentry) are kept for at most 90 days and deleted automatically afterwards. Password reset links are short-lived and expired ones are purged daily.

Sharing

Your data is never sold, rented or shared for marketing. Running the Service involves exactly three providers: the host on whose servers the data is stored; Resend, the email provider that delivers password reset messages; and Sentry, the monitoring provider that lets us find software faults and performance problems. Resend receives only your email address and the contents of that message. Sentry receives technical performance data for every request, without your account identity; when a fault occurs it also receives the information needed to fix it, together with your account identity if you are signed in. Both providers are based outside Türkiye; Sentry processes the data in the European Union (Frankfurt) region.

Only authorised administrative staff can see account records (name and email) in the admin panel. Your notes and collections are not listed there.

We may have to comply with lawful, properly issued requests from competent authorities.

Email

The only email we send you is a password reset link, and only when you request one; it is delivered through Resend. We send no newsletters, announcements or marketing email.

Security

Passwords are stored only as a strong hash and are never held in plain text anywhere. The site is served over HTTPS, the session cookie is not readable by browser scripts, and deleting an account requires re-entering your current password.

No method is absolutely secure, and we do not claim otherwise.

Children's privacy

The Service is not directed at children under 13 and we do not knowingly collect data from them. If we learn of such an account, we delete it.

Your rights

You can update your details on the settings page and permanently delete your account and all your data from the same page. For a copy of your data or any other request, write to [email protected].

Your statutory rights over your personal data are set out in detail in the Data Protection Notice.

Changes

This policy may be updated; the current text is always published on this page and the effective date is changed.

Questions: [email protected]

MA

· Verse

/

We only use cookies that are strictly necessary for the service to work and that remember your preferences. No analytics, advertising or tracking cookies.