Privacy Policy
Effective date: 2026-08-14
What data Qurandia processes and why, how long it is kept, and why it is shared with nobody.
In short
We show no advertising, run no analytics or tracking tools, load no third-party script on our pages, and serve our fonts from our own server. We keep only the data the Service needs in order to work, and we never sell it or share it for marketing.
Data we process
If you browse without an account, only the preferences stored in cookies are processed. Once you register, the following data is processed:
- Account details: your name, your email address, your irreversibly hashed password, your interface language, your time zone, your daily study goal, your account role, and the times the account was created and last changed.
- Library: the verses, hadiths, roots and topics you save; the private notes you write (free text); the collections you create and their contents.
- Learning records: lessons completed, quiz answers and scores, flashcard states, review logs (including how long an answer took), daily study minutes and streak.
- Technical: session and preference cookies. On sign-in attempts your IP address is used only transiently to rate-limit brute-force attacks; it is not written to any persistent record.
What we never collect
None of the following is collected:
- Analytics, measurement or behavioural tracking data; advertising profiles.
- Location data, phone numbers, payment or financial information.
- A persistent IP or browser record of your visits.
- Social media connections or third-party sign-in.
Why we process it
We process your data only to create and maintain your account, to store your progress and everything you save, to remember your preferences, to compute your spaced-repetition schedule, and to keep your account secure.
Retention
Your account and content data are kept until you delete your account. When you do, every record attached to it is deleted permanently and at the same moment, at the database level.
Server error logs are kept for at most 14 days and then removed automatically. Password reset links are short-lived and expired ones are purged daily.
Sharing
Your data is never sold, rented or shared for marketing. Running the Service involves exactly two providers: the host on whose servers the data is stored, and Resend, the email provider that delivers password reset messages. Resend receives only your email address and the contents of that message, and it is based outside Türkiye.
Only authorised administrative staff can see account records (name and email) in the admin panel. Your notes and collections are not listed there.
We may have to comply with lawful, properly issued requests from competent authorities.
The only email we send you is a password reset link, and only when you request one; it is delivered through Resend. We send no newsletters, announcements or marketing email.
Security
Passwords are stored only as a strong hash and are never held in plain text anywhere. The site is served over HTTPS, the session cookie is not readable by browser scripts, and deleting an account requires re-entering your current password.
No method is absolutely secure, and we do not claim otherwise.
Children's privacy
The Service is not directed at children under 13 and we do not knowingly collect data from them. If we learn of such an account, we delete it.
Your rights
You can update your details on the settings page and permanently delete your account and all your data from the same page. For a copy of your data or any other request, write to [email protected].
Your statutory rights over your personal data are set out in detail in the Data Protection Notice.
Changes
This policy may be updated; the current text is always published on this page and the effective date is changed.
Questions: [email protected]