Legal
Privacy Policy
This Privacy Policy explains how Apps Foundry Labs Ltd ("we", "us", "our") collects, uses, and protects your personal data when you use the Aya app and related services (together, the "Service").
Aya is a Muslim prayer companion. It helps you keep to your five daily prayers with accurate prayer times, a Qibla compass, private prayer tracking, a dhikr counter, and an optional private prayer circle called "Together". We have built Aya to be private by design, and this policy sets out exactly what that means in practice.
Apps Foundry Labs Ltd is the data controller for the purposes of the UK GDPR, the Data Protection Act 2018, the EU GDPR, the California Consumer Privacy Act as amended by the CPRA, and the Australian Privacy Act 1988.
1.Who We Are
The Service is operated by Apps Foundry Labs Ltd, a private limited company registered in England and Wales.
- Company: Apps Foundry Labs Ltd
- Company Number: 16288141
- Incorporated: 3 March 2025
- Company Type: Private limited company
- Nature of Business (SIC): 58290, Other software publishing
- Registered Address: Unit 7, 97 Western Road, Southall, England, UB2 5HN
- Contact: privacy@appsfoundrylabs.com
2.Information We Collect
We keep the data we collect to a minimum, and much of what Aya does happens entirely on your device. The categories below reflect what Aya actually collects.
(a) Information you provide
- Sign-in identifier: if you choose to use the optional "Together" feature, you sign in with your email address or through Apple or Google sign-in. We store a minimal account record consisting of an account identifier.
- Alias or term of address: a chosen name or affectionate term you use within your circle. We do not require your real name, date of birth, gender, or a profile photo.
- Circle invitations: invitations you create or accept to join a Together circle.
- Together message content: the reassurance and reminder messages you exchange within your circle. These are end-to-end encrypted on your device, so we store only ciphertext and cannot read their contents.
(b) Information collected automatically
- Device and diagnostic information: basic technical details such as device type, operating system version, and app version, along with crash and diagnostic reports that help us keep the app stable.
- Technical logs: standard server logs generated when your app communicates with our backend, used for security and to keep the Service running.
(c) Location: used on your device only
Your location is used only on your device to calculate accurate prayer times and the Qibla direction. Your location never leaves your device. It is never sent to our servers or to any third party.
(d) Prayer tracking: stored on your device
The prayers you log, your streaks, and any private reflection tags are stored locally on your device. This information is not required to leave your device to use Aya.
(e) Data we do not collect
- No biometric or face data. Aya does not collect selfies, photos, facial images, or any biometric identifiers of any kind.
- No precise location leaves your device. Location stays on your phone, as described above.
- No contacts upload. We do not read or upload your address book.
- No advertising trackers. Aya does not include third-party advertising or tracking software.
3.How We Use Your Data
We use the limited data we hold for the following purposes.
| Purpose | Explanation |
|---|---|
| Provide the Together feature | To create your account, deliver invitations, and route end-to-end encrypted messages between circle members. We route ciphertext without being able to read it. |
| Deliver notifications | To send content-blind push notifications so your app knows to fetch and decrypt new messages locally. The notification itself carries no readable message content. |
| Keep the Service secure and stable | To detect abuse, prevent fraud, diagnose crashes, and maintain the reliability of our systems. |
| Manage subscriptions | To confirm your "Aya Premium" entitlement through our payment processors so premium features are unlocked. |
| Support and communicate with you | To respond to your questions and to send essential service messages about your account. |
| Meet legal obligations | To comply with applicable laws and to respond to lawful requests where required. |
4.Legal Basis for Processing
Where the UK GDPR and EU GDPR apply, we rely on the following legal bases.
| Legal Basis | When we rely on it |
|---|---|
| Contract | To provide the account and Together features you ask us for, and to manage your subscription. |
| Legitimate interests | To keep the Service secure, prevent abuse, fix crashes, and improve reliability, balanced against your rights. |
| Consent | For optional features such as push notifications and, where required, diagnostic reporting. You can withdraw consent at any time. |
| Legal obligation | To comply with laws that apply to us, such as record keeping and responding to lawful requests. |
5.Sharing Your Data
We do not sell or rent your personal data. We share limited data only with the service providers (processors) we need to run Aya. Each provider handles data on our instructions and under a data processing agreement.
| Provider | Purpose |
|---|---|
| Google Firebase | Authentication, the Firestore database that stores encrypted Together data, Cloud Functions, and Hosting. |
| RevenueCat | Managing "Aya Premium" subscriptions and entitlement status. |
| Apple App Store | Processing payments for purchases made on Apple devices. |
| Google Play | Processing payments for purchases made on Android devices. |
We do not store your card or payment details ourselves. Purchases and entitlement status are handled by RevenueCat and the app stores. Because your Together messages are end-to-end encrypted, our processors only ever handle ciphertext for those messages and cannot read their contents.
We may also disclose data where required by law, to protect the rights and safety of our users or the public, or in connection with a business transfer such as a merger or acquisition.
6.International Data Transfers
Some of our processors operate outside the United Kingdom and the European Economic Area. Where personal data is transferred internationally, we make sure appropriate safeguards are in place, including one or more of the following:
- Transfers to countries that the UK or the EU has recognised as providing an adequate level of protection.
- The UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses.
- The EU Standard Contractual Clauses (SCCs) approved by the European Commission.
- Reliance on the EU-US Data Privacy Framework where a provider is certified under it.
You may contact us for more information about the safeguards that apply to any specific transfer.
7.Your Rights
Depending on where you live, you have some or all of the following rights over your personal data.
| Right | What it means |
|---|---|
| Access | Ask for a copy of the personal data we hold about you. |
| Correction | Ask us to correct data that is inaccurate or incomplete. |
| Deletion | Ask us to delete your account and associated personal data. |
| Withdraw consent | Withdraw any consent you have given, at any time, without affecting earlier processing. |
| Object or restrict | Object to, or ask us to restrict, certain processing of your data. |
| Portability | Receive your data in a portable, machine-readable format where this applies. |
| Non-discrimination (CCPA/CPRA) | Exercise your rights without receiving a different level of service. |
To exercise any of these rights, contact us at privacy@appsfoundrylabs.com. Please note that because Together messages are end-to-end encrypted, we cannot produce the readable content of those messages, as we never hold the keys to decrypt them.
8.Data Retention
We keep personal data only for as long as we need it for the purposes set out in this policy.
| Data | Retention period |
|---|---|
| Account record and alias | Kept while your account is active. Deleted after you close your account, subject to any legal retention. |
| Encrypted Together messages | Stored as ciphertext to deliver them to your circle, then removed in line with the feature's design and on account deletion. |
| Circle invitations | Kept while relevant to an active or pending circle, then removed. |
| Diagnostic and log data | Kept for a short period for security and stability, then deleted or anonymised. |
| Subscription and entitlement records | Kept as required by our payment processors and applicable law. |
Data stored locally on your device, such as your prayer tracking and location-based calculations, remains on your device and is removed when you delete the app or clear its data.
9.Data Security
We take the security of your data seriously and apply measures appropriate to the sensitivity of the data we hold.
- End-to-end encryption: within Together, your term of address and the reassurance and reminder messages between circle members are end-to-end encrypted using X25519 key exchange with XChaCha20-Poly1305. Our servers are server-blind and store only ciphertext, so they cannot read message contents. Messages are decrypted only inside the app on members' devices.
- Content-blind notifications: push notifications carry no readable message content. The app fetches and decrypts content locally.
- Encryption in transit: data exchanged with our backend is protected in transit using TLS.
- Access controls: our database uses security rules and access is limited to the small number of people who need it.
- Ongoing review: we review our systems and practices to keep them secure over time.
No system can be guaranteed to be completely secure, but we work hard to protect your data and to design features so that we hold as little sensitive data as possible.
10.Cookies and Similar Technologies
The Aya app itself does not use advertising cookies or third-party tracking software. Our marketing website may use a small number of essential and analytics cookies to keep the site working and to understand how it is used. Where required, we ask for your consent before setting non-essential cookies, and you can manage cookies through your browser settings.
11.Children
Aya is intended for a general audience and is suitable for all ages. We do not knowingly collect personal data from children under 13, or the equivalent minimum age in your region, without appropriate consent. If you believe a child has provided us with personal data without the necessary consent, please contact us and we will take steps to remove it.
12.Global Compliance
We design Aya to respect privacy laws across the regions where our users live.
United Kingdom and European Union
We comply with the UK GDPR, the Data Protection Act 2018, and the EU GDPR. You have the rights set out in Section 7, and you may contact our data protection point of contact at privacy@appsfoundrylabs.com.
California (CCPA and CPRA)
If you are a California resident, you have the right to know what personal data we collect, to request deletion, and to correct inaccurate data. We do not sell or share your personal data as those terms are defined under California law, and we will not discriminate against you for exercising your rights.
Australia
We handle personal information in line with the Australian Privacy Principles under the Privacy Act 1988.
13.Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes to Aya or to legal requirements. When we make material changes, we will update the "Last Updated" date at the top of this page and, where appropriate, notify you within the app. We encourage you to review this policy periodically.
14.Contact Us
If you have any questions about this policy or how we handle your data, please contact us.
- Apps Foundry Labs Ltd
- Unit 7, 97 Western Road, Southall, England, UB2 5HN
- Email: privacy@appsfoundrylabs.com
If you are in the United Kingdom and you are not satisfied with our response, you have the right to lodge a complaint with the Information Commissioner's Office (ICO) at https://ico.org.uk/make-a-complaint/. If you are in another region, you may contact your local data protection authority.