Haslet
Privacy Policy
This policy explains how your personal data is processed when you use the Haslet mobile app (the “App”) and the haslet.frax.tr website. It is written with the EU General Data Protection Regulation (“GDPR”) and Türkiye’s Personal Data Protection Law No. 6698 (“KVKK”) in mind. If the Turkish version differs, the Turkish version prevails for users in Türkiye.
1. Controller
Alperen Sevinç (fraxlabs), Türkiye Email: [email protected]
You can write to this address with any question or request about your personal data.
2. In short
- You can use Haslet with all of its features without an account. In that case your worship records stay only on your phone; no personal data reaches us.
- Creating an account is optional and only serves to back up your records and sync them across devices.
- We show no ads, use no analytics or tracking tools, and never sell your data or share it for marketing.
- You can delete your account, or only your data, at any time from the app or at haslet.frax.tr/en/delete-account.
3. Data that stays on your device
The following is stored on your phone, never sent to our server, and deleted when you uninstall the app.
- Location and city: used to calculate prayer times and the qibla direction. Location is only read while the app is open and only for this calculation; it is never tracked in the background.
- Prayer-rug photos: if you turn on “Confirm with prayer rug” (“Seccade ile onay”), the reference photos you take are kept only on your device. The confirmation photo taken after a prayer is deleted right after it is compared with the reference; no photo is ever uploaded.
- App settings, theme preference, downloaded recitation audio.
- If you have no account: all of your prayer, missed-prayer (qada), fasting, menstrual, dhikr and Quran records.
4. Data stored on our server if you create an account
When you create an account, the following is stored on our server for backup and sync:
- Identity and contact: email address; if you sign in with Google, your Google account identifier (a number Google assigns to you — your password never reaches us).
- Profile: name (optional), date of birth, age of puberty, when you started praying and fasting, gender, menstrual cycle length, notification preferences.
- Worship records: prayer logs (on time / made up / missed), qada counters and plan, fasting logs, dhikr counts and history, Quran progress, bookmarks and saved verses.
- Menstrual records (only if you enter them).
- Consent record: the version and date of the explicit consent text you accepted.
- Security records: one-way hashes of session keys, keyed digests of sign-in and deletion codes (the codes themselves are not stored), server access logs (IP address, date and time, request path).
Contact form
If you use the contact form on haslet.frax.tr (with or without an account), your name, email address and message are sent by email to [email protected]; they are not stored in a database. To prevent abuse and spam, your IP address and email address are kept in server memory only as a counter, for at most 24 hours.
5. Purposes
- Creating your account and verifying your identity with an email code or Google.
- Backing up your records and syncing them across your devices.
- Sending service emails such as sign-in codes, new sign-in notices and deletion confirmations.
- Replying to messages you send through the contact form or by email.
- Keeping the service secure; preventing abuse, unauthorised access and code-guessing attempts.
- Meeting legal obligations and answering requests to exercise your rights.
6. Legal bases
Under the GDPR:
- Performance of a contract (Article 6(1)(b)).
- Legitimate interests — security, abuse prevention and replying to your messages (Article 6(1)(f)).
- Legal obligation (Article 6(1)(c)).
- Your explicit consent for special categories of data (Article 9(2)(a)).
Under the KVKK:
- Processing directly related to the establishment or performance of a contract (Art. 5/2-c).
- Our legitimate interest in security, abuse prevention and replying to your messages (Art. 5/2-f).
- Legal obligations (Art. 5/2-ç).
- Your explicit consent for special categories of personal data (Art. 6).
7. Special categories of data and explicit consent
Prayer, fasting and qada records may reveal your religious beliefs; menstrual records are health data. The GDPR calls these “special categories of personal data” and the KVKK “sensitive personal data”.
We process them on our server only if you accept the explicit consent text when creating an account. Without consent no account is created, but you can keep using the app with all of its features without one. You can withdraw consent at any time by deleting your data (see Section 10).
8. Recipients and third parties
We share your data only with the following parties, and only as far as the service requires:
- Oracle Cloud (Frankfurt, Germany): the cloud infrastructure hosting our server, acting as a processor that only stores your data.
- Google: only if you choose “Continue with Google”, for authentication. Google’s processing is governed by the Google Privacy Policy.
- islamic.network, quranicaudio.com and everyayah.com: Quran recitation and dua audio are streamed or downloaded from these services. The Quran text, translation and transliteration are built into the app. Requests only contain surah/verse numbers, never your personal data. As with any internet request, your IP address reaches their servers.
- Google Play and the App Store: the store you install from processes download and crash data under its own policies.
- Competent public authorities: only where required by law.
Emails are sent from our own mail server on the same infrastructure; no third-party email service is used.
9. International transfers
Our server is in Germany, so for users in the EU your data stays within the EU. For users in Türkiye, creating an account means your data is transferred abroad; this transfer is carried out in line with the safeguards set out in Article 9 of the KVKK.
10. Retention and deletion
- Account data: kept until your account is deleted. There is no separate time limit for inactive accounts; you can delete yours at any time.
- Sign-in and deletion codes: automatically deleted after at most 2 days. Codes requested for an address without an account are deleted within the same period; when an account is deleted, its codes are deleted immediately.
- Sessions: invalidated when you sign out, use “Sign out of all devices”, or delete your data.
- Server access logs: kept for a limited time for security.
- Contact messages: deleted from our mailbox at the latest 1 year after your request is resolved. If you want them deleted sooner, just write to [email protected].
How to delete:
- In the app: Settings → Delete my account (“Ayarlar → Hesabımı Sil”).
- On the web: haslet.frax.tr/en/delete-account — “Delete my account”, or “Delete only my data” while keeping the account.
Deletion is immediate and permanent. Deleted data drops out of any server backups within 30 days at the latest. Data on your phone is removed when you uninstall the app.
11. Security
All communication between the app and the server is encrypted (HTTPS/TLS). We use no passwords; you sign in with a one-time code sent to your email. Codes and session keys are stored only as one-way digests, never in plain text, and code attempts are rate-limited. You are notified by email every time your account is signed in to.
12. Your rights
Under the GDPR you have the right of access (Article 15), rectification (16), erasure (17), restriction of processing (18), data portability (20) and objection (21); the right to withdraw consent at any time; and the right to lodge a complaint with the data protection supervisory authority of your country. For portability, Settings → Create backup (“Yedek oluştur”) in the app exports all of your records as a file.
Under Article 11 of the KVKK you may learn whether your data is processed and request information about it, learn the purpose of processing and whether it is used accordingly, know the third parties it is transferred to, request correction, deletion or destruction and notification of these to third parties, object to results against you arising solely from automated analysis, and claim compensation for damage caused by unlawful processing.
How to apply: send your request from the email address registered to your account to [email protected]. We answer free of charge within 30 days at the latest. In Türkiye you may also complain to the Personal Data Protection Board.
13. Children
Children under 13 cannot create an account. Children using the app without an account keep their data only on their own device. Some EU countries set this age at up to 16; users below that age there need parental consent to create an account. If we learn that an account belongs to a child under 13, we delete it.
14. App permissions
- Location: for prayer times and qibla; only while the app is in use.
- Camera: only for “Confirm with prayer rug”; your photo library is never accessed.
- Notifications and alarms: for prayer-time reminders; notifications are created on your device.
You can revoke permissions at any time in your device settings; the related feature stops working, others are unaffected.
15. Changes
We may update this policy. The current version and date appear at the top of this page. You will be informed in the app or by email of significant changes; changes that require explicit consent will ask for your consent again.
16. Contact
Alperen Sevinç (fraxlabs) — [email protected]