Effective August 31, 2026
Privacy Policy
AL‑Imam (com.viperdam.adhanlock) provides prayer times, adhan alerts, guided salah, Imam and Prayer Device dashboards, optional on-device pose coaching, and optional Prayer Circle synchronization.
Operator
The data controller and developer is Viperdam Limited. Contact viperotterdam@gmail.com for privacy and support requests.
Information kept on your device
The app can locally keep a selected prayer-time location, calculation preferences, Imam-protected settings, profiles, prayer assignments/history, progress, rewards, alarms, and active-session state. First-run setup asks only for a broad age range; it never requests or stores an exact birthdate. The broad range and Imam PIN stay local.
You can enter a prayer-time location manually instead of granting location permission. Latitude, longitude, precise location, and raw location-resolution diagnostics are not included in Prayer Circle cloud records.
Optional accounts and Prayer Circle
Core local prayer features do not require an account. Prayer Circle is off by default and is available only after the user explicitly enables cloud sharing. An Imam can then create or sign in to a Firebase account using email and password, and a Prayer Device installation can use anonymous Firebase Authentication. There is no Google sign-in. Prayer Circle never uses or receives the locally stored age range.
Authentication processes identifiers and security metadata such as an email when supplied, IP address, user agent, and Firebase UID. Prayer Circle can process an optional display name, account/pairing and registered-device identifiers, prayer assignments/removals, commands, delivery acknowledgements, completion events, Prayer Device-reported progress, and synchronization timestamps.
Prayer assignments, completions, and progress concern Islamic religious practice and can reveal religious beliefs. They are used only to authenticate/authorize the requested relationship, synchronize Prayer Circle, show delivery state, recover from offline operation, prevent replay/abuse, and provide deletion. They are not used for behavioral advertising.
Pairing invitations are random and short-lived. The service stores a cryptographic hash rather than the raw invitation value.
Camera and on-device pose processing
Camera access is used only while a guided prayer or camera-verification screen is visible. CameraX and MediaPipe calculate body landmarks on the device. AL‑Imam does not intentionally store or upload camera images, video, body landmarks, body measurements, or raw pose results.
Diagnostics, product Analytics, and configuration
After the local age step, AL‑Imam prominently explains Crashlytics, Performance Monitoring, Remote Config, and Firebase Google Analytics before any optional collection starts. The primary action enables the four presented services; a separate Continue without optional services action leaves all four off. Each has an independent switch under Settings → Privacy & data and can be turned off at any time. A previous per-service opt-out remains off after an app update. Advertising consent and Prayer Circle do not enable these services.
- Crashlytics: when enabled, processes stack traces, app/device/OS details, installation/session identifiers, and predefined diagnostic states. The app does not deliberately attach identity, religious/prayer, location, cloud-record, ad-response, camera, or pose data. Firebase publishes a 90-day retention period for crash traces and associated identifiers before deletion begins.
- Performance Monitoring: when enabled, processes timings, device/app/network information, response metadata, country derived from IP, and installation/session identifiers. Firebase publishes 30-day retention for IP-associated events and 60-day retention for installation-associated or de-identified data before deletion begins.
- Remote Config: when enabled, uses a Firebase installation identifier and request metadata to retrieve non-secret operational limits and emergency switches. It cannot authorize users, create accounts/pairings, assign prayers, grant ad rewards, or override local privacy choices.
- Firebase Google Analytics: when enabled, processes Firebase's automatic app engagement events and a limited set of setup, alarm-delivery, prayer-flow, on-device pose-stage, PIN-path, pairing/synchronization, and rewarded-ad outcome events. Firebase automatically associates event timing and app/device information. This measurement can show that a prayer workflow was started, completed, missed, or used pose/PIN verification, which can concern religious practice. AL‑Imam does not attach a prayer name, scheduled prayer time, prayer date, location, account/session identifier, pairing code, name, email, PIN, free text, camera data, body landmark, or raw model output. The only app-defined user property is the low-cardinality device role (Imam/organizer or Prayer Device/participant); the app does not set a Firebase Analytics user ID.
Turning Analytics off stops future app collection, resets the local Analytics identity and queued local measurement state, and prevents new custom events. It does not by itself erase information already aggregated or retained by Google under the configured Analytics retention controls. Analytics consent is separate from advertising consent: child-directed profiles keep advertising-storage, advertising-user-data, and ad-personalization signals denied.
Integrity and optional advertising
Firebase App Check and Google Play Integrity process app/device attestation and short-lived tokens for abuse prevention. They do not receive prayer camera data.
AL‑Imam contains rewarded video ads and one banner on the visible prayer-mode choice screen. Ads are optional at app level because local prayer features continue when an ad is disallowed or technically unavailable. If camera pose detection is selected, a video may appear before the camera. The camera opens only after Google reports an earned reward followed by dismissal, when local ad/consent policy provides an ad-free path, or if the ad cannot load/display for a genuine technical reason. Closing the video before the reward does not open CameraX or MediaPipe, and an earned grant is applied only once. The banner is removed while the Android keyguard is visible, the screen is off, the app is not resumed/focused, the PIN or camera screen is active, or ads are not authorized.
The local age band applies child, teen, or adult treatment before Mobile Ads starts. Under-9 and 9-12 profiles use child-directed, non-personalized treatment capped at G and Families-eligible sources. Teen requests use age-restricted treatment and are capped at PG. Adult requests are capped at PG and follow applicable advertising choices. High-engagement formats are disabled.
Google Mobile Ads can process IP/general location, app interactions, diagnostics, performance information, and device/account identifiers for ad delivery, measurement, security, and fraud prevention. The app removes Advertising ID and Android Ad Services identifier permissions, but the SDK can still process other identifiers. AL‑Imam does not send names, emails, Firebase UIDs, pairing/invitation codes, prayer identifiers, or session identifiers to AdMob.
Notifications and background work
The app uses notifications and user-granted exact alarms for time-sensitive prayer reminders. A visible foreground service can run only while an active guided prayer session requires recovery. Background work can retry pending Prayer Circle synchronization after connectivity returns.
Sharing, international processing, and security
Viperdam Limited does not sell personal information. Google and Firebase process information to provide Authentication, Firestore, App Check, diagnostics, product Analytics, operational configuration, Hosting, and optional advertising. Information can also be disclosed when legally required or needed to protect users, the app, or the public.
Firebase services can use global Google infrastructure; Firebase Authentication operates from United States data centers. Production traffic uses TLS, authenticated identities, Firestore rules, app attestation, and bounded payloads, but no system is completely secure.
Retention and deletion
Local-only information remains until you use a local reset where available, clear Android app storage, or uninstall AL‑Imam. Cloud profile, pairing, assignment, acknowledgement, completion, and progress information remains while the optional account/relationship is active or until deletion. Pairing invitations become unusable after 15 minutes. An expired invitation can remain in protected storage until the Prayer Device next replaces it or deletes the cloud account; it cannot be claimed after expiry.
Use Settings → Privacy & data → Delete cloud account and data. An email/password Imam must re-enter the account password before any destructive cloud write; an anonymous Prayer Device has no password. The flow then removes reachable Firestore records before the Firebase Auth account. If interrupted, reopen the screen and retry. See the public deletion instructions.
Cloud deletion does not remotely erase local-only records on another person's device. Each device owner must use a local reset where available, Android Clear storage, or uninstall. Secure service-provider backups and data needed for legal/security reasons can persist temporarily. Firebase publishes that deleted Authentication data is removed from live and backup systems within 180 days. Crashlytics, Performance, and Analytics records follow their product/configured retention controls and are not directly addressable by the app's Firebase UID because AL‑Imam does not set that UID as an Analytics or diagnostics user identifier.
Your choices and rights
You can use local prayer features without cloud linking; control Android access; choose whether to use rewarded features; reopen Google's advertising privacy options where available; independently control Crashlytics, Performance, Remote Config, and Analytics; unlink Prayer Devices; delete cloud account data; and erase local records separately. Depending on your region, you may request access, correction, deletion, restriction, portability, or objection by contacting viperotterdam@gmail.com.
Children and changes
The Play target audience includes ages 9-12, 13-15, 16-17, and adults. The listing does not target children under 9. Age assurance is used only for advertising safeguards; the resulting range stays on the device and is not a Firebase eligibility rule. Prayer Circle is off by default for everyone and requires its own explicit cloud-sharing choice. A parent or guardian should supervise a child's Android permissions, account choices, and cloud-sharing setup. The in-app cloud choice is not a legally verified parental-consent mechanism.
Material changes will update the effective date and, where required, request consent before new processing begins.
Contact
Viperdam Limited
viperotterdam@gmail.com
More information: Firebase privacy and security and Google Privacy Policy.