Privacy Policy — amalog

Last updated: 25 September 2026

amalog is a Muslim planner app. This policy explains what the app does with your information. The short version: everything stays on your device unless you switch something on. There is no advertising, and the app you install carries no third-party analytics or tracking SDKs. The website counts page views through Cloudflare Web Analytics, which sets no cookie and follows nobody from one site to the next — it is described under Third parties below.

What we collect

Nothing, unless you turn it on. Your tasks, routines, prayer log, money and everything else you enter stay on your device — we have no way to see them, and no server holds them.

Four things can leave, and every one of them is off until you choose it. Each has its own section below:

What the usage counts contain

What they never contain

The counts are stored by us on Cloudflare and are used to see which parts of amalog are worth improving — which tools are opened, which are ignored, and whether people come back. They are never sold, and never shared with anyone.

We look at them in aggregate: totals per day, which tools rose or fell over the last week, and how many installs are new against returning. Nothing in that view is per-person, and these counts could not support a per-person view even if we wanted one — they carry no name, no contact detail, and nothing you typed.

These usage counts are kept apart from accounts, described below, and are not joined to them. Turning usage reporting on does not tell us who you are, and making an account does not start usage reporting.

If you make an account

You do not need one. amalog works completely without an account, and always will — an account exists for one reason, which is to carry your planner to a second device. Everything below applies only if you choose to make one.

What we store when you sign in:

What we store when you switch syncing on:

A copy of your planner — the same tasks, prayer log, ledger entries and settings listed below — so a second device can read it. It is stored as one block of text, and this service never opens it: nothing on our side reads, indexes, or reports on what is inside, and the admin dashboard has no way to view it. Syncing is separate from having an account, and off unless you turn it on.

What we never store: a password, or a phone number. There is no password to leak, because signing in is always done through Google or through a single-use code emailed to you. Signing in by text message was considered and deliberately left out — a phone number is a heavier piece of information to hold than an address, and nothing here asks for one.

Deleting it. Deleting your account in the app removes the account, the sign-in methods, every device session and the synced copy of your planner from our database. They are deleted, not marked as deleted. The copy on your own device stays, and the app carries on working without an account.

Sign-in emails are delivered by Resend, which sees only the address the code goes to. Google sees a sign-in the same way it does on any site with a Google button.

If you connect with other people

Also optional, also off until you use it, and separate again from syncing. You can ignore this entirely and the rest of amalog is unchanged.

Nobody can find you. There is no search by name, no search by email or number, and no suggested contacts. Two people connect only when one shows the other an eight-character code. If you have given your code to someone you would rather not have, you can replace it — the old one stops working and your existing connections are unaffected.

What we store: your code, a display name if you choose one, who you are connected to, the messages you send those people, and anything you post to them. Posts reach only accounts you have accepted; nothing here is public, and there is no page anywhere that shows a stranger's posts.

Messages are not end-to-end encrypted. We are saying so plainly rather than implying otherwise: they are stored on our server, and we could read them if we chose to. We do not, and nothing in the admin dashboard can open a conversation — but "we choose not to" is a weaker promise than mathematics, and you should know which one you have. Do not send anything through here that you would not send through an ordinary messaging app.

Blocking. Blocking someone stops their messages reaching you, removes the conversation, and prevents them adding you again. They are not told. They see what someone sees who was never connected to you.

Reporting. You can report a person, a message or a post. A report keeps a copy of what was reported, taken when you report it, so that deleting the message afterwards does not erase the evidence. Reports are read by whoever runs amalog.

What we deliberately do not collect: whether you have read a message, whether you are typing, and when you were last online. Each of those tells one person where another one is and what they are doing, and none of them is worth that.

Deleting. Deleting your account removes your code, your name, your connections, your messages and your posts. Reports you made about other people are kept but no longer say who made them; reports about you are deleted with the account.

Data stored on your device

All of it is written to your device's local app storage. Deleting the app, or using Reset all data in Profile, removes it permanently.

Location

amalog asks for location permission so it can calculate accurate prayer times and the qibla direction. Those calculations run on your device, and the coordinates are cached locally so the app works offline. You can refuse the permission — the app then falls back to the last stored location.

The app asks your device for the most precise location it can give, and keeps it exact rather than rounded, so the district name and the nearest mosque are right for where you actually stand.

Where your coordinates do go.

The anonymous usage counts never contain your location. Prayer times, the qibla and the mosque search all run on your device and work with the network switched off.

Notifications

Prayer reminders are scheduled locally by your device. No push server is involved, so no device token is created or shared.

Downloading a recitation

The Quran text is built into the app and is read with no network at all. Audio is not: it is too large to ship with the app, so a recitation is downloaded when you ask for one, surah by surah, from the Islamic Network content network.

That download is the only time anything about your reading leaves the device, it happens only when you tap the download button, and what it reveals is which surah you asked to download — not what you read, not where you stopped, and nothing about you. amalog sends no account, no identifier and no location with it; the request is an ordinary file download and carries what any download carries, your IP address among it. The audio is never streamed. Once a surah is on your device it plays with the network off, and playing it tells nobody anything. You can delete a downloaded recitation from the reader at any time.

Weather

The weather card asks Open-Meteo and Google's weather service — through our own service, so neither sees your IP address — for the forecast where you are, and for a ring of points around you so it can say which direction rain is coming from. Your coordinates are the only thing sent, they are sent only to fetch that forecast, and no account or key is involved. The last reading is kept on the device so the card still works offline.

Steps

The health card reads your phone's step counter. Steps are counted on the device, stored on the device, and never transmitted — not in the usage counts, not anywhere. On iOS this needs the motion permission, the same one the qibla compass uses.

Photographing a meal

The health card can estimate the calories in a meal from a photograph. This is the one feature that sends something the camera saw off your device, so it is described plainly rather than folded into a list.

It happens only when you tap it. Nothing is captured in the background, and the rest of the health card — steps, distance, the meals you have already logged — needs no network at all. Taking the photo needs the camera permission, or the photo library permission if you pick an existing picture; refuse either and only this one feature stops working.

What happens to the photo. It is sent to a service we run ourselves on Cloudflare, where a vision model looks at it once and returns a guess: the name of the dish, a calorie number, and how confident it is. The photo is not stored — not in our database, not in a log, not as a file. The request runs the model and the image is gone with it. Nothing about you is sent with it: no account, no name, no location, and nothing else from the app.

What is kept, and where. Only the answer — the dish name, the calorie estimate and the confidence — and it is kept on your device, in your food log. We never see your food log. The photograph itself is never saved by amalog anywhere, on the device or off it.

It is an estimate, not a measurement. Portion size and how something was cooked are guessed from a picture. Treat the number as a rough figure, and do not use it as nutritional or medical advice.

Third parties

The app contains no third-party analytics, tracking, or advertising SDKs. Prayer times are computed on-device with the open-source adhan library — no network request is made to fetch them. If you switch on usage counts, they go to a service we run ourselves on Cloudflare; no other company receives anything.

The website is measured, the app is not. Pages served at amalogmuslim.com — this one included — report a page view to Cloudflare Web Analytics: the address of the page, where you arrived from, and how long it took to load. Your country and browser are read from the request by Cloudflare, which is serving the page to you in any case. It stores nothing on your device: no cookie, no identifier that outlives the page, and nothing that could recognise you on another site or on a later visit. The iOS and Android apps never load this website's pages, so none of it reaches them.

These are every other request the app can make, and what each one reveals. None of them carries an account, an identifier, or anything you have typed into amalog — but any request to another company shows that company your IP address, so they are listed rather than summarised.

Finding a mosque near you needs none of these. Your position is read on the device and the mosques are already inside the app, so the search itself runs with the network switched off; only the photographs above are fetched, and only when shown.

Children

amalog is not directed at children, and nothing in it is designed to appeal to them in particular. It asks for no age, so it cannot tell how old anyone is, and it does not knowingly collect information from a child.

Used without an account — which is how the app works by default — nothing a child entered would reach us, because it never leaves the device. The parts that do collect anything are the ones described above: an account, syncing, connecting with other people, the calorie estimate, and the anonymous usage counts. Every one of them is off until someone switches it on.

If you believe a child has given us information through an account, write to the address below and we will delete the account and everything stored with it.

Changes

If this policy changes, the updated version will be posted at this address with a new date at the top.

Contact

Questions about this policy: [email protected]